Three Years of China's Data Security Law: A Compliance Retrospective
The People's Republic of China's Data Security Law (DSL) took effect on September 1, 2021, and has just marked its third anniversary. Together with the Cybersecurity Law and the Personal Information Protection Law, it forms the "three pillars" of China's cyber and data security regime. Drawing on Halocent's three years of hands-on experience delivering compliance advisory and technical implementation to 200+ enterprise and government clients, this article distills the key paths — and the common pitfalls — of enterprise data-security programs.
1. A three-year retrospective: from "reading the law" to "everyday operations"
2021–2022 was the "read the statute" phase — most organizations were still asking, "Are we even a data handler?" 2023 brought a wave of enabling regulations: the Cross-Border Data Transfer Security Assessment Measures, the Interim Measures for Generative AI Services, and sector-specific "Important Data Identification Guidelines". By 2024–2025, data security has moved from being a "compliance project" to a set of "everyday operational muscles".
Enterprises that landed compliance successfully all share three traits: treat data as an asset, treat security as a capability, treat compliance as cross-functional collaboration.
2. Five compliance pitfalls we see most often
- Treating data classification as a one-off task — real compliance requires revisiting classification across the full data lifecycle, at least every six months.
- Overlooking "Important Data" identification — it isn't only state-owned enterprises that hold Important Data; large-scale user data, or data affecting national security or macroeconomic stability, can also qualify.
- Treating cross-border transfer assessment as a one-shot filing — any change (data type, recipient, purpose) can require re-assessment or even re-filing.
- Confusing log retention with compliance — raw log storage isn't enough; you need searchability, correlation, and evidentiary integrity.
- A "paper" Data Security Officer — the law explicitly requires one, but many companies appoint someone in name only, without budget or authority.
3. Halocent's six-step landing method
Step 1 — Objectives alignment & data-asset inventory
Align with Business, Legal, and IT on compliance objectives (MLPS grading, sector-specific, IPO readiness, etc.) and produce a living data-asset inventory covering type, origin, storage location, access path, and lifecycle.
Step 2 — Data classification & grading
Combine DSL requirements with sector guidance (financial, healthcare, automotive, industrial) to reach at least a four-tier classification: public / internal / sensitive / core, each with clear rules on encryption, masking, access control, and retention.
Step 3 — Important Data identification & filing
Business and Security jointly assess whether Important Data exists, produce an identification report, and file with local regulators plus annual re-review.
Step 4 — Technical controls
Encryption (at rest + in transit), key management (KMS / HSM), identity & access (IAM + MFA + least privilege), centralized logging with SIEM/SOAR, and production-to-test / analytics masking pipelines.
Step 5 — Organization & processes
Named Data Security Officer, cross-functional data-security committee, incident-response process (including notification duties), and standardized supply-chain data-processing agreement templates.
Step 6 — Continuous operations & drills
A red-vs-blue exercise or tabletop drill every quarter, and a full annual re-assessment. Halocent's monthly-subscription service covers exactly this operational layer — our SOC team runs it jointly with the client's IT so compliance never becomes "something we remembered when the certificate expired".
Field insight: across 42 data-security compliance engagements Halocent delivered in the past two years, 76% of compliance gaps were concentrated in "data-flow visibility" and "fine-grained access control." Investing 20% of the budget in these two areas usually resolves 80% of the risk.
4. Three things to watch over the next 12 months
- AI data compliance — provenance of training data, labelling of generated content, cross-border-AI data-processing disclosures.
- Supply-chain data security — joint-and-several liability for data processors is tightening; vendor agreements and security assessments will be a top audit priority.
- The data-elements market — as data-market policy matures, data registration, trusted data spaces, and privacy-preserving computation will become new growth areas.
5. Closing thoughts
Three years on, the Data Security Law is no longer "new regulation" — it's part of the daily rhythm. What actually benefits companies is not passing a single assessment, but internalizing data security as a default capability of the business. Halocent is here as your long-term partner to help turn every risk into an opportunity for your business to run steadier.
← Back to News & Insights