Chapter III Network Operation Security

Article 39

Permalink

Translation Notice

This is an unofficial English translation prepared for general informational purposes only. It does not constitute legal advice. In case of any discrepancy, the official Chinese text published by the competent authority shall prevail.

本文为非官方英文翻译,仅供一般信息参考,不构成法律意见。如与主管机关发布的中文正式文本不一致,以中文正式文本为准。

Chinese Original

第三十九条 关键信息基础设施的运营者在中华人民共和国境内运营中收集和产生的个人信息和重要数据应当在境内存储。因业务需要,确需向境外提供的,应当按照国家网信部门会同国务院有关部门制定的办法进行安全评估;法律、行政法规另有规定的,依照其规定。

Translation Status

Site reference translation is in editorial review for this article. The Chinese original above is the controlling official text; do not treat this status note as a translation.

Plain English Note

Site explanation only. Not part of the translation.

Article 39 is part of the CSL critical information infrastructure framework and should be read with CII protection, security review, and annual assessment requirements.

  • critical information infrastructure
  • personal information
  • important data
  • security assessment
  • Cyberspace Administration of China
  • cross-border data transfer

Related rules: Critical Information Infrastructure Security Protection Regulation; Measures for Security Assessment of Cross-border Data Transfer

Related standards: GB/T 22239; GB/T 28448

Source reference: CSL Article 39. Source authority: Cyberspace Administration of China publication; source text from the Standing Committee of the National People's Congress. Effective version: 2026-01-01 amended effective version. Amendment status: amended by 2025-10-28 amendment decision; current official text uses article-number gaps. Last verified: 2026-05-20. Last updated: 2026-05-20. Official source.

Source Reference

Official source

Last updated: 2026-05-20. Last verified: 2026-05-20. Independent reference only. Chinese text shall prevail.