China Clarifies Data Risk Assessment Rules and Reporting for Key Handlers
The Cyberspace Administration of China details certification avenues for assessors and submission procedures for important data handlers.

The Brief
Why it matters
China context
Editor's View
What to watch
- Initial filings of annual risk assessment reports by important data processors to provincial cyberspace offices.
- The publication of the first batch of certified third-party data security risk assessment agencies.
- Potential sector-specific reporting templates issued by relevant line ministries.
Key Takeaways
- 1The Measures for Cybersecurity Data Risk Assessment took effect with targeted implementation guidance from the national cyberspace authority.
- 2Assessment institutions can seek certification via designated entities that have registered rules with the national accreditation regulator.
- 3Important data processors must file risk assessment reports within 20 working days of annual assessment completion.
- 4Provincial and national cyberspace offices serve as the designated reporting channels when sector-specific authorities are unclear.
Sources
- 《网络数据安全风险评估办法》实施有关事项答记者问 — Cyberspace Administration of China · 8/20/2026