Contributed By Global Law Office
The rapid proliferation of artificial intelligence in China has become a defining force reshaping the cloud computing landscape. In August 2025, the State Council issued the Opinions on Deepening the Implementation of the “AI+” Action, explicitly promoting innovative businesses of “Model-as-a-Service” and “Agent-as-a-Service”. With the huge daily consumption of AI tokens in 2026, cloud service providers are pivoting from traditional resource provision to agentic cloud paradigms, where agents, rather than humans, are becoming the primary consumers of cloud resources. This shift introduces novel legal challenges in data processing and cross-border transfers, which are addressed throughout this chapter in the context of existing and emerging PRC regulations.
Data Privacy Regulations Applicable to Cloud Computing in China
In the area of data and privacy regulation, PRC law currently has the following major sources:
At the national level, the Cyber Security Law of the PRC (CSL), the Data Security Law of the PRC (DSL) and the Personal Information Protection Law of the PRC (PIPL) are the fundamental laws regulating data and privacy issues, which are applicable to cloud computing and relevant data processing activities in the PRC.
Those three national laws are implemented mainly by administrative regulations, rules and regulatory documents issued by the competent regulatory governmental agencies. For example, the Measures on Assessing the Security of Cloud Computing Services specify the security requirements of the Cyber Security Law and the Data Security Law in scenarios where the cloud computing services are provided to the administration agencies, the operators of Critical Information Infrastructure (CII) and the party offices.
In addition, the national standards, which are compulsory and recommended, play an important role in implementing those three laws from the perspective of technical, organisational and law-fulfilling measures. The compulsory standards establish the minimum requirements for legal compliance, while the recommended standards showcase best practices. For example, the Information security technology – Security guidance for cloud computing service (GB/T 31167-2023) provides recommendations and guidance on security management and technical measures to protect data on the cloud through its life cycle. Another national standard, the Cybersecurity technology – Assessment method for security capability of cloud computing service (GB/T 34942-2025), came into effect on 1 February 2026 and provides recommendations and guidance for cloud computing service providers or third-party agencies on assessing the security risk of the cloud computing service.
There is also a national standard, Information technology – Cloud computing – General requirements of AI cloud service (GB/T 46350-2025), which came into effect on 1 February 2026. It is China’s first national standard dedicated to AI cloud services and provides guidance for the design, development, deployment, use and evaluation of AI cloud services. This standard establishes an AI cloud service capability framework and specifies requirements for AI cloud service infrastructure, model development, model services and AI application development.
Another unique security requirement applicable to cloud services hosted in China is the Multi-Layer Protection Scheme (MLPS). MLPS is a requirement imposed in accordance with Article 23 of the CSL and focuses on the infrastructure security of the cloud service that facilitates the protection of the data and personal information processed in the cloud service.
Definition of Personal Data and Sensitive Data
In this guide, personal data and personal information, sensitive data and sensitive personal information are used interchangeably, with the same meaning.
According to Article 4 of the PIPL, personal data refers to all types of information of identified or identifiable individuals recorded in electronic or other means, excluding anonymous information.
According to Article 28 of the PIPL, sensitive personal data refers to personal data, the leakage or illegal use of which could easily result in damage to the dignity of an individual, or harm to personal body and property, including biometric information, religion, specific identities, medical and health information, financial accounts, location tracking data, as well as the personal data of minors under the age of 14.
Requirements for Processing Personal Data in the Cloud
The data processor under the PIPL is the counterpart of the data controller under the GDPR, and the processing contractor of a data processor is the counterpart of the data processor under the GDPR. As it is inevitable to distinguish the data controller and the data processor in the cloud environment, for convenience of non-PRC readers, the GDPR terms “data controller” and “data processor” are used in this guide in response to the questions about PRC law.
Therefore, in this article, “data controller” refers to the “personal information processor” that can autonomously decide the purpose and method of processing data under the PRC law, and “data processor” refers to the “processing contractor” that is processing data upon the request of the controller.
Chinese laws and regulations do not provide special requirements for processing personal data in the cloud, which is subject to the same requirements provided in the PIPL for processing personal data in general.
Under the PIPL, the primary requirement for processing personal data is consent or separate consent. There are also legally defined exceptional processing scenarios where no consent or separate consent is required.
Consent and the requirement
Under Article 13 of the PIPL, processing personal data should have a proper legal basis, including consent, or other legal bases that may allow for consent to be waived, as illustrated below. To ensure informed consent is obtained, before processing their personal data, a controller must inform individuals truthfully, accurately and fully of the following information in a prominent way and in clear and plain language:
In addition, according to Article 21 of the Regulation on Network Data Security Management (RNDSM), if the processed data is network data, then the data controller must specify in the form of a checklist the purpose, method and type of personal information to be collected and provided to other network data controllers. If the personal data of minors under the age of 14 is processed, then a special notice or processing rule specific for these minors shall be provided.
Separate consent and the requirement
Under the PIPL, there are several processing activities that require separate consents, including processing sensitive personal data, cross-border transfers of personal data, providing personal data to another data controller, publicly disclosing personal data, etc.
While the PIPL itself lacks a precise definition of “separate consent”, practical guidance can be found in the recommended national standard GB/T 42574-2023 (Information security technology – Implementation guidelines for notices and consent in personal information processing), which is also supported by the “Q&A on Personal Information Protection Policies and Regulations” issued by the Chinese authorities in July 2026. This standard clarifies that separate consent signifies a specific, explicit agreement given by the individual solely for a particular processing activity concerning their personal data. Crucially, it does not encompass blanket consent given for multiple processing purposes simultaneously.
Exceptional consent-waiving processing
In addition to consent, the PIPL allows data controllers to process personal data based on several alternative legal grounds:
Under these processing conditions, consent (including the separate consent) can be waived.
Obligations for Data Controllers and Processors in the Cloud Environment
Under PRC law, data controllers should undertake primary legal responsibilities regarding processing personal data, and data processors shall provide necessary assistance for compliance. That is because, in cloud services, data controllers are the customers (cloud tenants or platform users), and their technical capability to comply with the law will be subject to the technical limit provided by the cloud service providers (as data processor).
Data controller’s obligations
According to the PIPL, data controllers using cloud services are subject to the following key obligations.
In the cloud environment, data controllers may expect data processors to provide data compliance measures or offer the technical mechanisms or flexibility to allow them to implement such measures independently. Therefore, cloud service providers, as data processors, may need to understand and anticipate such potential requirements in advance.
Data processor’s obligations
Data processors, usually the cloud service providers, are responsible for processing personal data on behalf of data controllers. Their obligations should be geared toward supporting the controller’s compliance efforts and ensuring data protection standards are upheld, including the following.
The CSL, DSL and PIPL provide a general framework for cross-border data transfers. In addition to those three fundamental laws, the Provisions on Promoting and Regulating Cross-Border Data Flows have been in effect since March 2024, further facilitating the cross-border transfer of personal data and other types of data outside of China. These laws apply to cross-border data transfers in the cloud environment as well.
According to the above laws, data controllers should undertake the legal obligation concerning cross-border data transfers in the cloud, and data processors should comply with data controllers’ instructions concerning cross-border transfers (for example, the instruction of not transferring personal data outside of China).
The key PRC law requirements with respect to cross-border data transfers can be summarised as follows.
Cloud providers as data processors must collaborate with data controllers to ensure that the data transfer arrangements meet Chinese regulatory requirements. This involves aligning cloud security protocols with Chinese standards and providing support for assessments that should be completed by the data controller under the regulatory mechanism. Data controllers are advised to include specific clauses in their contracts with cloud service providers to address cross-border data transfer obligations. Please see 3. Data Ownership and Control for more detail.
Chinese data privacy laws do not impose penalties specifically for data controllers and data processors in the cloud environment. In practice, the penalties vary depending on the role of the legal entities. The following penalties are applicable to each role under Chinese laws and regulations.
Penalties for Data Controllers
Data controllers bear primary responsibility for ensuring the legality, security and transparency of personal data processing activities. The penalties for non-compliance include administrative penalties, civil liabilities and criminal liabilities in severe cases.
Penalties for Data Processors
Data processors, usually cloud service providers, are responsible for processing personal data according to the instructions of the data controllers. Processors can also face significant penalties for non-compliance.
Security Measures Required by PRC Law for Data Stored in the Cloud
The security of the cloud computing environment is jointly safeguarded by cloud service providers and their customers. The CSL requires network operators to take security measures to protect the security of the cloud and services derived from it that are hosted in China, as well as the data stored in the cloud.
The PIPL requires personal data controllers to take technical measures to ensure the security of personal data. Legal requirements in the PIPL apply to processing activities of personal data stored in the cloud, which are summarised below.
The Measures on Assessing the Security of Cloud Computing Services stipulate measures that cloud service providers should comply with when providing services to the government and party offices, and the operators of CII. Article 3 of the Measures provides that the security assessment of such cloud services should concentrate on, inter alia:
In addition, there are a few recommended national standards concerning cloud computing services that specify security measures for cloud services. For example, the standard Information Security Technology – Security Capability Requirements for Cloud Computing Services (GB/T 31168-2023) highlights the security technical measures that cloud service providers need to deploy. There are 11 types of security measures in total:
The goal of those measures is to ensure the confidentiality, integrity and availability of data stored in the cloud.
Encryption Standards for Data in Transit and at Rest in the Cloud
According to the standard GB/T 31168-2023, cloud service providers should implement encryption measures to ensure the security of data in transit and at rest in the cloud. The standard recommends that cloud service providers take communication encryption and signature verification measures in compliance with the Chinese national encryption management regulations.
However, if the cloud services are intended to support the administration agencies, the operators of CII and the party offices, such cloud services must adopt the encryption technologies recognised by the Chinese government to comply with the Administration Measures of Commercial Encryption (revised in 2023).
Access Controls in the Cloud Environment
According to the above laws and national standards, cloud service providers should identify and authenticate personnel, processes and devices before allowing them access to the cloud computing platform, and should restrict the operations they can perform and the functions they can use. For example, the national standard GB/T 31168-2023 recommends different levels of access control measures, depending on the importance of the business and sensitivity of the data. Cloud service providers can adopt proper access control measures, depending on the importance of the business and sensitivity of the data, as well as contractual requirements of the cloud customers.
As a general requirement, cloud service providers are recommended to identify and recognise the users of their information systems and implement multi-factor authentication for privileged account network access. As an enhanced requirement, for example, when data stored on the cloud is critical and sensitive, cloud service providers are recommended to:
If the data on the cloud is very sensitive, and the associated business operations are critically important, as an advanced requirement, cloud service providers are recommended to:
Handling of Security Accidents and Breaches in the Cloud
According to the CSL, PIPL, RNDSM and Administrative Measures on Data Security in the Fields of Industry and Information Technology, cloud service providers should develop emergency response plans for the cloud computing platforms, and conduct regular drills to ensure the availability of critical information resources in emergencies. In detail, cloud service providers should establish an emergency response plan, and should track, record and report incidents to the relevant personnel. Cloud service providers should also have disaster recovery capabilities and establish necessary back-up and recovery facilities and mechanisms to support the continuity plan of customers’ businesses.
When a data security incident occurs, cloud service providers should promptly carry out emergency response measures according to the emergency response plan. Upon completion of incident handling, a summary report should be prepared within the specified timeframe.
Data Ownership and Control in Cloud Agreements
As a basic principle in a typical cloud business, data in the cloud is owned and controlled by the cloud service customers, unless otherwise agreed. The cloud service providers and the cloud service customers are recommended to specify the following in the cloud agreement.
Data Subjects’ Rights Over Their Data
In the cloud environment, personal data subjects have rights to their personal data as defined in the PIPL, including the right to know and the right to decide how their personal data is processed, unless otherwise provided by the laws and regulations.
Specifically, data subjects have the rights to:
Data Subjects’ Exercise of Rights to Access, Rectify or Delete Their Data
Data subjects need to submit their requests directly to the controller. The PIPL requires the data controller to establish a convenient mechanism for accepting and processing requests from personal data subjects in a timely manner.
In the cloud environment, cloud service customers may need support from cloud service providers to fulfil the data subjects’ requests concerning their personal data; for example, the right to access, rectify and delete their personal data stored in the cloud. Therefore, in the cloud agreement, the cloud service customer and the cloud service provider may specify the mechanism and procedures to deal with the personal data subjects’ requests in detail, as well as Standard Operation Procedures (SOP) that must be followed by both parties.
Article 45 of the PIPL provides data subjects with a data portability right: where an individual requests to transfer their personal data to a personal data controller designated by them that meets the conditions stipulated by the CAC, the personal data controller shall provide a way for the transfer. Article 25 of the RNDSM further stipulates that the network data controller shall provide channels for third parties that are designated by the data subject to access or obtain relevant personal information if certain conditions are met. However, the PIPL and its relevant laws have not provided details regarding how to respond to the data portability request in the cloud.
To ensure that the right to data portability is respected, both the cloud customer and the cloud service provider are advised to clearly define in the cloud agreement how such requests will be handled.
The general legal requirement provided in the PIPL concerning data retention and deletion applies to processing in the cloud.
Conducting thorough due diligence is crucial to ensuring compliance with Chinese laws and regulations, particularly those related to data security, cybersecurity and personal information protection. The following is a short, high-level checklist for basic due diligence based on applicable Chinese legal requirements.
A cloud service agreement is critical to ensuring data protection in the cloud environment, and may include the following data protection requirements. Details regarding data processing can be found in 4.3 Data Processing Agreements and the Cloud.
Article 21 of the PIPL provides the necessary coverage of a data processing agreement (DPA), which should include:
According to the above law, national standards and mainstream market practice in the PRC, a well-structured DPA should define the responsibilities of both parties. DPAs are typically structured in a cloud business in the PRC as follows.
The recommended national standard GB/T 31167-2023 Information security technology – Security guidance for cloud computing services in its Article 9 provides guidance on how to determine proper exit strategies and data migration in practice, including the following.
The CSL, DSL and PIPL stipulate reporting obligations in the event of data breaches. In addition to these general legal requirements, the CAC (China’s data protection regulator) further refines specific reporting requirements through its regulatory rules. There are two sets of different requirements regarding personal data breaches and cybersecurity incidents, which are detailed below.
Personal Data Breaches
In the event of personal data breaches, the PIPL requires the personal data controller to notify the competent authorities in a timely manner. This enables the authorities to understand the situation at the outset and take accurate and effective regulatory measures. The specific matters to be reported are detailed in 5.3 Notifying Data Breaches.
According to Article 66 of the PIPL, personal data controllers failing to fulfil reporting obligations will be subject to administrative penalties. The penalties start with orders to rectify, warnings, confiscation of illegal gains, and orders to suspend or terminate relevant application services; refusal to correct will result in fines of up to CNY1 million. For more severe violations, higher fines may be imposed, along with suspension of business operations or revocation of relevant business licences or permits.
Cybersecurity Incidents
The CAC released the Measures for the Administration of National Cybersecurity Incident Reporting (the “Reporting Measures”) in September 2025, which came into effect on 1 November 2025 and clarify the reporting procedures and requirements in the event of cybersecurity incidents.
The Reporting Measures stipulate that network operators failing to report cybersecurity incidents as required may face legal liabilities under related laws or administrative regulations, which could include orders to rectify, warnings and fines. If competent authorities consider the circumstances severe, heavy fines or even business suspension/termination may be imposed. However, the Reporting Measures also provide that liability may be exempted or mitigated accordingly if a company has taken reasonable and necessary protective measures to minimise the harm of data breaches, dealt with the data breach according to its emergency response plan and proactively reported as required.
Article 10 of the RNDSM also stipulates that network products and services provided by a network data controller shall comply with the compulsory requirements of the relevant national standards. If there is any risk such as security defect or vulnerability, the network data controller shall take remedial measures forthwith, notify users in a timely manner and report the same to the relevant competent authority. If there is any harm to the national security or public interest caused by the security defect or vulnerability, the network data controller shall also report it to the relevant competent authority within 24 hours. The above reporting obligation also applies to cloud service providers and cloud service users.
The CSL requires network operators to formulate emergency response plans for cybersecurity incidents. When the incident happens, network operators must immediately activate the emergency response plans, take remedial measures and report to the competent authorities.
Therefore, for cloud service providers and customers, developing an emergency response plan is crucial for investigations and remediation upon a data breach that occurred in the cloud. Please see 2.1 Data Security and the Cloud and 4.1 Due Diligence for more information regarding data breaches.
Notification Obligations Under the PIPL
Article 57 of the PIPL sets out a general notification mechanism, which includes the following two aspects.
Notifying personal data subjects and regulatory authorities
As a default rule under the PIPL, the personal data controller has the obligation to notify affected subjects and authorities. Notification to the authorities is mandatory, whereas notification to the personal data subjects is not.
Article 57 provides that if the personal data controllers take measures that can effectively prevent harm from the breach, they can be exempt from notifying the affected personal data subjects, unless specifically required by the authorities. The PIPL does not explicitly define a clear threshold for when notification becomes necessary, nor does it outline specific timelines for such notifications.
Information to be notified
The notification should include information such as:
Key Considerations
It is important to note that the above is only a high-level legal requirement provided by the PIPL. In practice, regulators may request more extensive information based on their working rules and specific cases. Cloud service customers may want to consider the following in handling data breach notification matters:
Please see 1.2 Data Privacy and Cross-Border Transfers.
PRC law does not have a generally applicable and absolute data localisation requirement. However, the CSL, DSL and PIPL impose localisation requirements on certain specific types of data, and outline the administrative requirements for cross-border transfers of such data.
Data localisation requirements have a direct effect on the compliance of cloud computing services. The slow and ambiguous identification of Important Data raises concerns regarding data transfers in and out of the PRC. Cloud service providers and users need to have a data compliance strategy in place that allows them to address the concern of data localisation requirements in the PRC.
Among cross-border data transfers, it is not uncommon for legal systems or judicial procedures of different jurisdictions to clash. For instance, in cross-border litigation, a US governmental agency may require a company in China to present data information in its routine regulatory check or special investigation. However, under the DSL and PIPL, submitting personal information or data stored in China to foreign law enforcement authorities is subject to prior approval from the competent Chinese regulatory authority. The approval process in China may be complex and time-consuming, making it difficult to meet the demands of the foreign law enforcement authority in a timely fashion. The conflicts of laws between different jurisdictions may therefore increase compliance costs and legal risks for multinational companies.
Addressing such an issue requires clear understanding of the nature and type of the data request from the foreign authority, and the scope and procedure of the PRC data cross-border approval. Although potentially complex and time-consuming, successful resolution involves collaboration between PRC counsel well-versed in Chinese law and foreign counsel familiar with the requesting country’s law enforcement procedures.
In China, the personal data processing compliance audit was introduced in the PIPL in 2021, and regulatory requirements related to it have been gradually taking shape since then. On 1 May 2025, the Administrative Measures for Compliance Audits of Personal Information Protection (the “Audit Measures”) came into effect, which apply to personal data processing activities conducted by personal data controllers in all scenarios, including cloud-based processing.
In May 2025, the National Information Security Standardisation Technical Committee issued the Practical Guidelines for Cybersecurity Standards Practices – Requirements for Compliance Audits of Personal Information Protection (TC260-PG-20255A) (the “Guideline”), which provide details on conducting the audit in practice.
The national recommended standard Data security technology – Personal information Protection Compliance Audit Requirements (the “Standard”) was issued in December 2025 and came into effect on 1 July 2026, providing more comprehensive and practical guidance based on the Audit Measures.
The Simplified Measures for Personal Data Protection by Small-Scale Personal Information Processors came into effect on 1 September 2026, and clarify that compliance audits shall be conducted at least every five years for “Small-Scale Personal Information Processors” (SSPIPs – ie, personal data controllers that process personal data of fewer than 100,000 individuals). Such an audit can be completed by using the “Self-Checklist for Personal Data Protection Compliance Audit by Small-Scale Personal Information Processors”, which reduces the compliance audits burden of the SSPIP.
Cloud service providers and cloud service customers should comply with the above in their personal data processing once they become final and effective. The key aspects of personal information protection compliance audits in the Audit Measures and the Standard are as follows.
Occurrence of Compliance Audit
As an independent supervisory mechanism to confirm and ascertain a personal data controller is processing personal data in accordance with the law, a compliance audit is mandatory. Companies that process personal data are required to conduct audits on a regular basis (every two years for personal data controllers that process personal data of more than 10,000,000 individuals, and every five years for SSPIPs). Audits can be performed internally by the company itself or by engaging third-party professional agencies.
In addition, if the regulatory authorities find that there is a significant risk in the processing of personal data or if a personal data breach occurs, the authorities may require the personal data controller to engage a third-party agency for a compliance audit. This is a type of audit process triggered by regulators.
A compliance audit generally involves several processes, including audit preparation, audit implementation, audit reporting, issue rectification and archive management.
Key Areas of Compliance Audit
The scope of a compliance audit can be very broad, covering almost all aspects of personal data processing activities and the obligations provided by the PIPL. Key areas include but are not limited to the following:
Independence, Fairness and Comprehensiveness of Compliance Audit
The Standard and the Guideline provide an essential guide to understanding and complying with the principles of independence, fairness and comprehensiveness of a compliance audit, covering aspects such as the audit process, implementation management, evidence management, qualifications of auditors, etc.
In terms of evidence management, the Standard requires that the audited party must ensure the authenticity, completeness and validity of the evidence provided. Only evidence that meets both formal and substantive requirements can be accepted and used in the audit report.
Implementation of Compliance Audit Findings and Recommendations
The Standard and the Guideline highlight that, once the audit report is completed and delivered, the audited party should address the identified issues within a specified timeframe. Auditors have the right to confirm the status of rectification.
Penalties for Non-Compliance
Personal data controllers who fail to conduct compliance audits as required or who improperly perform such audits will be subject to administrative penalties under Article 66 of the PIPL. In cases where the violation is even more severe and constitutes a crime, criminal liability may also be imposed.
36th Floor
Shanghai One ICC
No 999 Middle Huaihai Road
Xuhui District
Shanghai 200031
China
+86 21 2310 8288
+86 21 2310 8299
vincentwang@glo.com.cn www.glo.com.cn