Skip to main content
China’s amended Cybersecurity Law and its key changes for foreign businesses

China’s amended Cybersecurity Law and its key changes for foreign businesses.

Written by ,
 1 April 2026.

China has introduced significant amendments to its Cybersecurity Law (CSL), which took effect on 1 January 2026. The revisions expand the law’s scope, raise penalties and bring it into closer alignment with China’s broader data governance framework with direct implications for foreign-invested companies operating in or with China.

The most substantial update since 2017

The amended CSL builds on the foundational legislation enacted in 2017 and represents the most significant revision since that time. Several new provisions broaden what falls within the law’s remit, while others tighten existing obligations around network security, data handling and critical infrastructure protection. Together, these changes mark a clear shift towards more active and wide-reaching enforcement.

Closer alignment with personal information rules

The amendments reinforce the relationship between the CSL and China’s Personal Information Protection Law (PIPL), as well as the Civil Code. Network operators are now explicitly required to comply with these laws when processing personal information. This brings cybersecurity and personal data obligations into a single, more consistent compliance framework, one built around data minimisation, purpose limitation, transparency and consent.

A revised and more immediate penalty structure

One of the most consequential changes for businesses is the overhaul of the penalty regime. The previous requirement for an initial warning before fines could be imposed has been removed in many cases, allowing regulators to act without that preliminary step. Penalties are now tiered according to the severity of the violation, as summarised below.

Violation typePrevious fine (network operators)Amended fine (network operators)Previous fine (CIIOs)Amended fine (CIIOs)
First-time violationWarning/order to correctRMB 10,000 – 50,000Warning/order to correctRMB 50,000 – 100,000
Refusal to correctRMB 10,000 – 100,000RMB 50,000 -500,000RMB 100,000 – 1,000,000Unchanged
Responsible individualsRMB 5,000 – 50,000RMB 10,000 – 100,000RMB 10,000 – 100,000Unchanged
Serious consequences (e.g. large-scale data leak)NoneRMB 500,000 – 2,000,000 (entity); RMB 50,000 – 200,000 (individual)NoneRMB 500,000 – 2,000,000 (entity); RMB 50,000 – 200,000 (individual)
Particularly serious consequences (e.g. major CII loss)NoneRMB 2,000,000 – 10,000,000 (entity); RMB 200,000 – 1,000,000 (individual)NoneRMB 2,000,000 – 10,000,000 (entity); RMB 200,000 – 1,000,000 (individual)

In line with China’s Administrative Penalty Law, the amendments also introduce provisions for leniency. Minor, first-time violations that are promptly corrected and cause no harmful consequences may attract reduced or waived penalties. Cooperation with investigations and proactive remediation can also be taken into account.

Extraterritorial reach now extended

Perhaps the most significant development for foreign businesses is the expansion of the CSL’s extraterritorial scope. The amendments now cover overseas organisations and individuals whose activities are deemed to endanger China’s cybersecurity and cause serious consequences within the People’s Republic of China (PRC). This empowers PRC authorities to investigate offshore entities and impose sanctions, including asset freezes. Companies without a direct physical presence in China but whose operations affect its digital ecosystem now fall within scope.

New provisions for artificial intelligence

A new article in the revised CSL explicitly outlines state support for AI research and development, covering foundational research, key technologies such as algorithms and essential infrastructure including training data resources and computing capacity. Alongside this support, the amendments introduce expectations around AI ethical norms, risk monitoring and security supervision. Foreign companies involved in AI development or services are expected to embed compliance into the design process and establish risk-monitoring and emergency-response mechanisms. Any AI activities that involve personal information or important data are also subject to China’s data security requirements and cross-border data transfer rules.


Contact our teams for expert support and further information about corporate governance in China to ensure you are compliant in the market.

Maxime Van ‘t Klooster, Partner, m.vantklooster@acclime.com
Christophe Marquis, Director, Shanghai, c.marquis@acclime.com


About Acclime.

Acclime is a leading professional services firm providing integrated corporate services, fund administration, accounting, tax and advisory solutions across Asia-Pacific and the Middle East. With over 2,000 professionals operating as one unified firm across 18 markets, Acclime serves a diverse range of private clients, regional enterprises, multinationals, funds and family offices. The firm combines deep market knowledge, cross-border expertise and industry-leading tech-enablement to help clients navigate complex regulatory environments, scale their operations and achieve their strategic objectives at every stage of success.

Written by
More from the author(s)