Back to Insights
Financial securityData securityCybersecurityCompliance 2025-08-12

China’s Financial Infrastructure Oversight Measures Take Effect October 1

The People’s Bank of China and the China Securities Regulatory Commission have issued financial infrastructure oversight measures, effective October 1, 2025, including network and data safeguards.

China’s Measures for the Supervision and Administration of Financial Infrastructure will take effect on October 1, 2025. They seek to coordinate oversight and development planning and support safe, efficient financial operations. This article translates selected network and data security provisions summarized in the Chinese source, rather than providing a complete or authoritative legal translation.

The People’s Bank of China and the China Securities Regulatory Commission recently issued the measures. The source identifies Chinese banking, cybersecurity, data security, personal information protection and critical information infrastructure legislation among their legal foundations.

The measures apply to infrastructure such as financial asset registration and custody systems, clearing and settlement systems, trading facilities, trade repositories, important payment systems and core credit-reporting systems. Relevant provisions include the following.

Technical systems and management mechanisms

Article 15 requires financial infrastructure operators to establish sound technical systems and management mechanisms, including:

  1. Compliance with necessary technical specifications, communication procedures and standards.
  2. System-failure response and disaster-recovery mechanisms, with appropriate data protection and backups. Disaster-recovery centers must be located within the People’s Republic of China.
  3. Effective cybersecurity management. Systemically important financial infrastructure must also implement the requirements of laws and administrative regulations concerning critical information infrastructure protection.
  4. Complete data storage management. Personal information and important data collected or generated during operations within the People’s Republic of China must be stored domestically. Where cross-border provision is genuinely needed for business, the relevant national requirements must be met.

Data security management

Article 18 requires operators to strengthen data security management and assume primary responsibility for it. They must establish effective internal management and accountability arrangements and protect participants’ business data, related materials and other data generated while delivering services.

The provision calls for protection against destruction, unlawful theft and unlawful use of data and prohibits infringement of personal information rights. Where laws, administrative regulations or the relevant financial infrastructure authorities have specific data-processing rules, those rules apply.

Contingency plans

Article 22 requires comprehensive contingency plans for extreme circumstances that may affect sustained, stable operations. Examples include major epidemics, natural disasters, abnormal financial market fluctuations, external shocks, cybersecurity incidents and data security incidents.

Plans must specify the corresponding response measures and coordinate effectively with contingency plans for other connected financial infrastructures, helping maintain secure and stable financial markets.

Source: People’s Bank of China website. The geographic and regulatory scope described here is China; these provisions are not presented as rules for every country.