Back to Insights
Data securityData regulationsPersonal information protectionCompliance 2025-08-13

Hubei’s Data Regulations Take Effect on October 1, 2025

Hubei Province, China, has issued data regulations covering processing responsibilities, security governance, data transactions and emergency response, effective October 1, 2025.

Hubei Province, China, has published data regulations that will take effect on October 1, 2025. They aim to regulate data processing, protect data-related rights and security, promote data circulation and use, and support the development of Digital Hubei. This article translates the selected provisions summarized in the Chinese source, not the complete legal text.

The regulations were developed under China’s Data Security Law, Cybersecurity Law, Personal Information Protection Law and other applicable laws and administrative regulations, taking account of conditions in Hubei. The source highlights the following data security provisions.

Duties of online platform service providers

Article 17: Online platform service providers must establish sound mechanisms for information review, monitoring and early warning, emergency response, complaints and reports. They must fulfill their legal obligations for data security and personal information protection.

Security of data circulation and transactions

Article 41: Data transaction platforms and professional data service organizations must create a secure, trusted and convenient environment for transactions and services. They must improve service processes, information disclosure and internal management, and take effective steps to protect data, state secrets, trade secrets, personal information, privacy and intellectual property.

Data security governance

Article 49: Governments at county level and above, together with relevant departments, must build a collaborative governance system involving government, businesses and society, and establish sound data security management arrangements.

Public administration and service organizations must protect data within their systems and sectors under the guidance of public security, state security, cyberspace, data and other relevant authorities.

Responsibilities of data handlers

Article 50: Data handlers bear primary responsibility for data security.

They must establish lifecycle management, record processing activities throughout the process, strengthen technical safeguards, and provide disaster recovery and backups for important systems and data, ensuring secure and traceable processing.

Article 51: Public administration and service organizations must maintain routine data security operations, strictly implement China’s data classification and graded-protection system, and apply differentiated safeguards.

Handlers of important data must designate responsible personnel and management bodies, process data according to the rules, conduct regular risk assessments, and submit assessment reports to the competent authorities as required by law.

Processing that involves state secrets, trade secrets or personal information must follow the relevant legal and regulatory provisions.

Emergency response mechanisms

Article 52: Governments at county level and above must establish data security emergency response mechanisms in accordance with national requirements.

Public administration and service organizations must prepare response plans, conduct security monitoring, risk assessments and exercises, and promptly address identified risks and weaknesses.

Source: Hubei Provincial Data Bureau. These are provisions in the Chinese provincial context, not general requirements for organizations in every jurisdiction.