First announced: Adopted by the Standing Committee of the National People’s Congress in 2025; key amendments effective January 1, 2026.
Submitted by: NYBACS Compliance Desk
What changed
The amendments expand obligations for network operators and critical information infrastructure (CII) entities. They increase fines, clarify data-localization requirements, strengthen personal-information protections and mandate stricter cybersecurity risk management. Authorities now have broader investigative and enforcement authority.
Who’s affected
Technology providers, SaaS operators, manufacturers with connected devices, cross-border businesses transferring data from China, cloud providers and multinational companies with Chinese subsidiaries.
Immediate actions
• Conduct data-mapping and localization review.
• Update cybersecurity incident reporting protocols.
• Review cross-border data transfer mechanisms.
• Assess AI systems against national security/data standards.
Practical notes & timeline
Primary amendments take effect January 1, 2026. Sector-specific implementing regulations may follow. Businesses should monitor CAC (Cyberspace Administration of China) notices for guidance.



