Key practical points:
• The regulations require protection measures for personal and important data across their full lifecycle.
• Data processors must disclose collection and use rules and obtain consent where needed.
• They set controls on transferring data outside China, especially personal and important data.
• Large platforms have extra duties of transparency and protection of users and minors.
• Security incidents and data breaches must be reported and affected people notified within deadlines.
• They apply to foreign companies that process data of users in China.
💬 General consulting
Regulations on the Administration of Network Data Security · Yalla China
网络数据安全管理条例 / Regulations on the Administration of Network Data Security
Enacted: 2024-09-24 ✅ Effective: 2025-01-01
📝 Overview
These regulations detail how network data must be processed and protected, implementing the Cybersecurity, Data Security, and Personal Information Protection laws. Issued by the State Council, effective 1 January 2025.
This is general information only, not legal advice. For your specific case, consult a licensed lawyer.
📜 The law text / key provisions
💬 Practical reading
💬 This is a general reading/opinion for orientation — not the official legal text nor legal advice.
If your company collects data of users in China, review your consent, collection, and cross-border transfer policies to comply with these recent regulations. Prepare a plan to report any breach. This is general orientation, not legal advice.
📎 Official source
State Council / gov.cn
🕒 Updated: 16 March 2026
