From Principle to Procedure
For five years, China's data security regime has rested on a paradox: the Data Security Law (2021) and the Network Data Security Management Regulations required "important data handlers" to assess and report on their own risk, but never specified how often, through whom, or in what form. On June 18, 2026, the Cyberspace Administration of China (CAC), the Ministry of Industry and Information Technology, and the Ministry of Public Security jointly closed that gap, issuing the Measures for Network Data Security Risk Assessment (Order No. 24), which took effect August 20, 2026 (CAC). It is the first dedicated operational rulebook for the assessment duty: important data handlers must now run a comprehensive self- or third-party risk assessment at least once a year and file the report with their sector regulator within 20 working days of completion (CAC announcement; Hunton Andrews Kurth). General data handlers face a lighter, voluntary three-year cadence.
The Case for the Rule
Regulators deserve real credit here, and it would be dishonest to pretend otherwise. A principle-based duty with no procedure attached is worse than either a clear rule or no rule at all — it lets enforcement become arbitrary, since any company can be told after the fact that its informal self-check didn't count. By specifying scope (every system holding a copy of the data, aggregation risk, third-party processing boundaries, and — explicitly — AI-related data risk), cadence, and a filing deadline, Order No. 24 gives compliance officers something concrete to build a program around. CAC also visibly softened the rule between the December 2025 draft and the June 2026 final text: the filing window was doubled from 10 to 20 working days, a mandatory standardized reporting template was dropped in favor of sector-specific formats, and assessment institutions' quasi-whistleblower reporting duties were removed (Geopolitechs analysis). That is a regulator responding to comment-period feedback rather than ignoring it — a genuinely pro-innovation instinct, and one U.S. and EU rulemakers don't always match.
Where the Predictability Runs Out
But procedural clarity is not the same as substantive clarity, and the Measures leave the single hardest question — what counts as "important data" in the first place — essentially where they found it. The regulation never defines the term itself; it points back to sector catalogs that different ministries are still publishing unevenly, years after the Data Security Law demanded them (Digital Policy Alert). A firm now has a hard annual deadline and a 20-day filing clock attached to a classification it may not be able to determine with confidence. That is the worst combination for a compliance officer: precise obligations bolted onto an imprecise trigger. A company that under-classifies its data risks a retroactive enforcement finding under the Data Security Law and the Network Data Security Management Regulations, which Article 22 of the Measures explicitly invokes for non-compliance (CAC); a company that over-classifies to be safe absorbs a compliance cost it may not owe.
The Real Compliance Cost
The assessment-vendor provisions compound this. Firms may self-assess or hire a third-party institution, but the same institution cannot perform a company's assessment more than three years running, and provincial regulators retain discretion to mandate certified assessors for high-risk processing or after a security incident (Hunton). That is a reasonable anti-capture safeguard in isolation. Stacked on an annual cycle, a 20-day filing window, and an undefined classification trigger, it means multinational firms operating in China now need to plan for recurring assessor turnover, three years of mandatory documentation retention, and a compliance calendar that resets every twelve months — all before the underlying "what is important data" question is settled. For smaller and mid-sized data processors without in-house counsel fluent in Chinese administrative law, that recurring cost is a real barrier to entry, not a marginal one.
The Proportionate Path Forward
China is not wrong to want an auditable process behind its data-localization regime; the U.S. and EU both impose their own risk-assessment duties (SEC cyber-disclosure rules, GDPR Article 35 DPIAs), and a rule with teeth is more legitimate than a vague one enforced selectively. But proportionate regulation means matching the certainty of the trigger to the certainty of the deadline. CAC softened the how of compliance this cycle — deadlines, templates, whistleblower duties. The next test of whether this regime is genuinely calibrated to risk, rather than to control, is whether the ministries move with equal urgency to finish and publish the sector-by-sector important-data catalogs that the entire Measures depend on. Until then, foreign and domestic firms alike are being asked to hit a hard annual deadline aimed at a target regulators haven't finished drawing.