HomeFounders News › Regulations
Regulations China Jun 18, 2026

China's Network Data Security Risk Assessment Measures take effect Aug 20, 2026

China's Network Data Security Risk Assessment Measures take effect Aug 20, 2026

China's Cyberspace Administration (CAC), MIIT and Ministry of Public Security jointly issued the Measures for Network Data Security Risk Assessment on June 18, 2026, effective August 20, 2026. Handlers of 'important data' must conduct a risk assessment at least once a year and file the report with authorities within 20 working days of completion; all other data handlers are encouraged to self-assess at least once every three years. Regulators can order rectification and suspend data processing if unacceptable risks are found and not fixed.

Why this matters for founders

Any China startup handling large volumes of user or business data (SaaS, fintech, consumer apps) should map now whether its datasets qualify as 'important data', and if so budget for an annual internal risk assessment plus a 20-working-day report filing under the new rules.

Source: Hunton Andrews Kurth (Privacy & Cybersecurity Law Blog)

Related updates

More that helps you.

Get briefs like this tuned to you.

In the app, Founder Briefs are personalized to your country, industry and stage, and you can save the ones that matter.

See plans →
FoundersCheckList.AI app
Founders using FoundersCheckList.AI