China has introduced significant amendments to its Cybersecurity Law (CSL), which took effect on 1 January 2026. The revisions expand the law’s scope, raise penalties and bring it into closer alignment with China’s broader data governance framework with direct implications for foreign-invested companies operating in or with China.
The most substantial update since 2017
The amended CSL builds on the foundational legislation enacted in 2017 and represents the most significant revision since that time. Several new provisions broaden what falls within the law’s remit, while others tighten existing obligations around network security, data handling and critical infrastructure protection. Together, these changes mark a clear shift towards more active and wide-reaching enforcement.
Closer alignment with personal information rules
The amendments reinforce the relationship between the CSL and China’s Personal Information Protection Law (PIPL), as well as the Civil Code. Network operators are now explicitly required to comply with these laws when processing personal information. This brings cybersecurity and personal data obligations into a single, more consistent compliance framework, one built around data minimisation, purpose limitation, transparency and consent.
A revised and more immediate penalty structure
One of the most consequential changes for businesses is the overhaul of the penalty regime. The previous requirement for an initial warning before fines could be imposed has been removed in many cases, allowing regulators to act without that preliminary step. Penalties are now tiered according to the severity of the violation, as summarised below.
| Violation type | Previous fine (network operators) | Amended fine (network operators) | Previous fine (CIIOs) | Amended fine (CIIOs) |
|---|---|---|---|---|
| First-time violation | Warning/order to correct | RMB 10,000 – 50,000 | Warning/order to correct | RMB 50,000 – 100,000 |
| Refusal to correct | RMB 10,000 – 100,000 | RMB 50,000 -500,000 | RMB 100,000 – 1,000,000 | Unchanged |
| Responsible individuals | RMB 5,000 – 50,000 | RMB 10,000 – 100,000 | RMB 10,000 – 100,000 | Unchanged |
| Serious consequences (e.g. large-scale data leak) | None | RMB 500,000 – 2,000,000 (entity); RMB 50,000 – 200,000 (individual) | None | RMB 500,000 – 2,000,000 (entity); RMB 50,000 – 200,000 (individual) |
| Particularly serious consequences (e.g. major CII loss) | None | RMB 2,000,000 – 10,000,000 (entity); RMB 200,000 – 1,000,000 (individual) | None | RMB 2,000,000 – 10,000,000 (entity); RMB 200,000 – 1,000,000 (individual) |
In line with China’s Administrative Penalty Law, the amendments also introduce provisions for leniency. Minor, first-time violations that are promptly corrected and cause no harmful consequences may attract reduced or waived penalties. Cooperation with investigations and proactive remediation can also be taken into account.
Extraterritorial reach now extended
Perhaps the most significant development for foreign businesses is the expansion of the CSL’s extraterritorial scope. The amendments now cover overseas organisations and individuals whose activities are deemed to endanger China’s cybersecurity and cause serious consequences within the People’s Republic of China (PRC). This empowers PRC authorities to investigate offshore entities and impose sanctions, including asset freezes. Companies without a direct physical presence in China but whose operations affect its digital ecosystem now fall within scope.
New provisions for artificial intelligence
A new article in the revised CSL explicitly outlines state support for AI research and development, covering foundational research, key technologies such as algorithms and essential infrastructure including training data resources and computing capacity. Alongside this support, the amendments introduce expectations around AI ethical norms, risk monitoring and security supervision. Foreign companies involved in AI development or services are expected to embed compliance into the design process and establish risk-monitoring and emergency-response mechanisms. Any AI activities that involve personal information or important data are also subject to China’s data security requirements and cross-border data transfer rules.










