Data & Cybersecurity

Practical compliance under China’s personal information, data security and cybersecurity framework.

Organisations operating in China must handle personal information and important data under the Personal Information Protection Law (PIPL), Data Security Law (DSL), Cybersecurity Law (CSL) and related CAC measures. We translate those requirements into operational programmes for domestic and multinational businesses.

  • Gap assessments and privacy audits
  • Privacy policies, consent language, personal information protection impact assessments and processing inventories
  • Training and awareness for boards and operations teams
  • Cyber incident readiness, reporting and regulator engagement
  • Cross-border transfers using CAC security assessment, standard contracts or certification routes
  • Important-data analysis, data classification and multi-level protection scheme coordination

We advise clients in finance, telecoms, health, technology and e-commerce. The aim is simple: avoid fines, disruption and reputational harm while still letting the business use data well.

Instruct this desk