China — Cybersecurity Law, as amended 2025 (网络安全法)
China's foundational cybersecurity statute, first amended by the NPC Standing Committee decision of 28 October 2025 (in force 1 January 2026). The amendment renumbered the articles — cite the new numbering.
Statute text is Chinese (the authentic language); this README is curation.
Applicability to EdTech
- MLPS (网络安全等级保护制度) (第二十三条, formerly 第二十一条): every network operator in China — a hosted platform serving Chinese schools included — must implement the multi-level protection scheme's baseline duties (security policies, access controls, logging retained ≥ six months, encryption/backup of important data).
- CII data localisation (第三十九条, formerly 第三十七条): critical-information-infrastructure operators must store personal information and important data in-country, with CAC security assessment for necessary exports. Education can be designated CII — if a large education authority customer is a CIIO, their vendor stack inherits the constraint.
- The 2025 amendment also raised penalty ceilings and added AI-governance support provisions (README-level note; extract on demand).
Contents
| Document | Covers |
|---|---|
| DENGJI-BAOHU-YU-BENDIHUA.md | 第二十三条 (等级保护), 第三十九条 (关键信息基础设施数据本地化) — 2025 修正后编号 |
Enforcement
CAC, 公安部 (MPS runs MLPS), and sector regulators.
Related
Sources
Meta
Statute text in DENGJI-BAOHU-YU-BENDIHUA.md is reproduced verbatim in Chinese from the CAC republication of the 中国人大网 consolidated amended text by tools/cac-cn/build_cn.py; verify detects silent edits, future amendments must be found via the NPC database.