
What foreign companies need to know
China now has one of the strictest regimes in the world for reporting cybersecurity incidents, and new reporting rules are likely to bring fresh compliance challenges for multinationals operating in the country. In this article, Alex Roberts, Yang Fan and Tiantian Ke outline the latest reporting rules and the steps companies need to take to maintain compliance.
The Cyberspace Administration of China (CAC) has introduced a new regime for cybersecurity reporting, which took effect on 1st November 2025. This comprises the new Administrative Measures for National Cybersecurity Incident Reporting, accompanied by the Cybersecurity Incident Grading Guide (Reporting Measures).[1] A dedicated reporting platform is now available for firms to facilitate online reporting.
The finalised Reporting Measures came in less than one week after a foreign company was sanctioned for non-compliance with China’s cross-border data transfer requirements, following the company’s disclosure in May that a cybersecurity breach resulted in unauthorised access to customer data in China.[2]
Organisations operating in China should take immediate action to assess their data breach reporting protocols and processes to ensure they meet the stringent reporting timelines in the event of a data breach.
Cybersecurity incidents classified according to four tiers
Consistent with the original draft consultation, the Reporting Measures classify cybersecurity incidents into four tiers based on their impact on national security, social order, economic activity and the public interest: ‘general (一般)’, ‘relatively severe (较大)’, ‘severe (重大)’ and ‘particularly severe (特别重大)’.
The Reporting Measures impose stringent reporting timelines and procedures for incidents classified as ‘relatively severe’ and above. An incident may be considered ‘relatively severe’, for example, if it involves the loss, theft, tampering, or falsification of important data or a large volume of personal information that poses a serious threat to national security and social stability.
The Reporting Measures do not explicitly state whether ‘general’ incidents must be reported. It remains unclear if these lower-level incidents are exempt or if they will be subject to a more relaxed reporting timeline pending further clarification from the regulator. In any event, organisations in regulated industries such as financial services must also pay attention to industry-specific rules.
Who must report a cybersecurity incident?
This will depend on the nature of an organisation’s business:
- Network operator: The legal obligation to make a report rests with the network operator. This refers to the entity that builds, operates, or provides services through electronic networks within mainland China and aligns with the definition of a network operator in the Cybersecurity Law (CSL). In essence, businesses operating in China will broadly be subject to these reporting requirements.
- Information technology services providers: The Reporting Measures require network operators to contractually oblige their third-party vendors, such as cybersecurity service or system maintenance providers to notify them of any incidents promptly and provide all necessary assistance within the reporting process.
- Overseas businesses: While the Reporting Measures do not explicitly create direct extra-territorial liability for offshore businesses processing data originating from China, overseas businesses may still be indirectly affected in several ways. An offshore service provider may be contractually required to promptly report to its customers in China and assist them to fulfil their reporting obligations. In particular, offshore recipients are contractually bound to notify their Chinese partners of a data breach under standard contractual clauses (SCCs). However, although the use of ‘network operator’ implies that the primary jurisdictional scope of the Reporting Measures remains consistent with the CSL—focussing mainly on networks within mainland China—given that the Reporting Measures implement the CSL, the Data Security Law and the Personal Information Protection Law (PIPL), offshore businesses can still be subject to the extra-territorial application of the PIPL.
This regime places increased importance on vendor due diligence and sound contractual governance. Multinational enterprises should carefully review their vendor contracts and incident response plans to ensure these obligations are clearly addressed and that their suppliers are prepared to meet the compliance requirements in practice.
How should reports be made?
The Reporting Measures map out different reporting channels and the required timeline in the event of relatively severe, severe, or particularly severe incidents:

Source: Linklaters.
A reporting flowchart
Following the Reporting Guidelines’ grading criteria, in the event of any relatively severe, severe, or particularly severe cybersecurity incidents, network operators must operate according to the following procedures:

Source: Linklaters.
Are there benefits to reporting a cybersecurity incident?
The Reporting Measures include provisions that, at the discretion of the regulatory authorities, reduce or exempt a network operator’s liability if the network operator adopts reasonable and necessary protective measures and promptly reports incidents to the authorities.
To benefit from potential exemptions, organisations should establish a comprehensive cybersecurity handling and emergency response plan.[3]
What next?
- Industry and sector-specific reporting rules and guidelines: Financial institutions should be aware of the People’s Bank of China cybersecurity reporting rules, effective 1st August 2025, which introduce very tight timelines.[4] For significant incidents, these rules mandate a brief report within one hour and a detailed report within 24 hours, highlighting the need for rapid response capabilities. In parallel, a non-binding practice guide has also been released for generative artificial intelligence services, outlining methods for incident classification and emergency response. Both developments highlight the growing regulatory focus on creating specific security frameworks for high-risk sectors.
- Increased regulatory enforcement: Recent actions from regulators, such as the publication of typical enforcement cases in September 2025, signal a clear trend towards stricter enforcement of data security laws.[5] This demonstrates that authorities are actively monitoring compliance and are prepared to penalise organisations that fail to meet their legal obligations. Additionally, the amendments to the CSL, which took effect on 1st January 2026, have further strengthened enforcement mechanisms and expanded regulatory powers, underscoring the authorities’ commitment to robust oversight.[6]
Key takeaways for multinationals
In light of these developments, multinationals operating in China should take proactive steps to ensure compliance and mitigate regulatory risks. Companies should:
- Review and update incident response plans: The Reporting Measures include provisions that may reduce or exempt liability for network operators that adopt reasonable and necessary protective measures and promptly report incidents. Organisations should develop and maintain a robust cybersecurity incident handling and emergency response plan to position themselves to benefit from these potential exemptions. Existing incident response plans and policies should be updated to reflect the latest Reporting Measures, including the stringent one-, two- or four-hour initial reporting timelines, where applicable, to enable rapid assessment and escalation when an incident occurs.
- Strengthen vendor due diligence and contract management: Review contractual arrangements with external vendors. Contracts should clearly specify reporting timelines, notification obligations and cooperation mechanisms to facilitate compliance with the Reporting Measures.
- Implement robust pre-incident preparation more broadly: A serious cyber incident can be a traumatic experience requiring significant decisions to be made immediately against a background of potentially incomplete and inaccurate information, and the more that can be done to prepare for and practise a response, the less painful the experience will be.
- Monitor industry-specific reporting requirements and prepare for heightened regulatory enforcement: Organisations in regulated sectors, such as financial services, should pay close attention to sector-specific cybersecurity reporting rules, which may impose additional or more stringent obligations. In response to recent regulatory actions signalling a clear trend towards stricter oversight, organisations should ensure that their compliance frameworks are sufficiently robust to mitigate increased regulatory scrutiny and should conduct regular internal assessments to identify and address any gaps.
By taking these measures, organisations can better position themselves to navigate China’s evolving cybersecurity landscape.
Note:
A previous version of this article appeared on the Linklaters website.
Alex Roberts is a partner and head of China technology, media and telecommunications (TMT) and privacy at Linklaters.
Yang Fan is a solicitor specialising in TMT cybersecurity and data protection at Linklaters.
Tiantian Ke is an associate at Zhao Sheng Law Firm, Linklaters’ joint operation in mainland China, specialising in TMT, cybersecurity and data protection.
Linklaters operates at the forefront of all major practice
areas and sectors, providing innovative, commercial solutions to its clients’
most complex corporate, finance and contentious matters. The firm has a leading
presence in the Greater China Region and offers high-quality legal advice in
Hong Kong, English and US law.
[1] National Cybersecurity Incident Reporting Management Measures, Cyberspace Administration of China, 15th September 2025, viewed 30th March 2026, <https://www.cac.gov.cn/2025-09/15/c_1759583017717009.htm>
[2] Langley, M., Dior Confirms Data Breach Exposing Chinese Customer Information, Security Daily Review, 15th May 2025, viewed 30th March 2026, <https://dailysecurityreview.com/security-spotlight/dior-confirms-data-breach-exposing-chinese-customer-information/>
[3] Cyber Security Handbook Version 2: The Essential Handbook for In-house Counsel, Linklaters, March 2026, viewed 1st April 2026, <https://edge.sitecorecloud.io/linklaterslbf57-linklatersx7ccc-linklatersxf9f5-394d/media/digital-marketing-image-library/files/04_client-services/data-and-cyber/linklaters—cybersecurity-handbook-update—march-2026—digital.pdf>
[4] People’s Bank of China Cybersecurity Reporting Rules,State Council,1st August 2025,viewed 30th March 2026, <https://www.gov.cn/gongbao/2025/issue_12186/202507/content_7034092.html>
[5] The Cyberspace Administration of China has released recent typical cases of law enforcement related to network security, data security, and personal information protection, Internet Information China, 16th September 2025, viewed 30th March 2026, <https://mp.weixin.qq.com/s/-EfW7ImfLGJI_ihc970I9A>
[6] China’s 2025 Cybersecurity Law amendments: Enhanced penalties, expanded extraterritorial application, and AI governance, Linklaters, 4th November 2025, viewed 30th March 2026, <https://techinsights.linklaters.com/post/102lrz5/chinas-2025-cybersecurity-law-amendments-enhanced-penalties-expanded-extraterr>

Recent Comments