The People's Bank of China promulgated its Measures for Administration of Data Security in PBoC Business Areas on 1 May 2025, establishing a comprehensive set of data security obligations applicable to all entities conducting activities regulated by the central bank. The new rules take effect on 30 June 2025, giving the industry a two-month implementation window to align their systems and processes with the requirements.

The measures extend the PBoC's data security oversight to payment organisations, anti-money laundering reporting entities, and other institutions operating within the central bank's regulatory perimeter. The issuance represents the latest step in China's ongoing effort to build a coherent legal framework governing how sensitive financial data is handled, stored, and shared across the country's financial system.

SCOPE AND REGULATORY COVERAGE

The measures apply broadly to any entity conducting business that falls within PBoC's supervisory remit, capturing not only commercial banks but also the large universe of licensed payment companies, financial infrastructure operators, and AML-designated institutions. This wide scope reflects the PBoC's view that data security risks do not respect institutional boundaries and that a patchwork approach to oversight would leave meaningful gaps.

China's financial data security regulatory architecture has been taking shape across several interconnected pieces of legislation, including the Data Security Law and the Personal Information Protection Law, which established baseline requirements for data handling across all industries. The PBoC's sector-specific measures build on that foundation by adding prescriptions tailored to the particular characteristics of financial services data, including transaction records, customer identification information, and credit histories.

For payment organisations — many of which handle hundreds of millions of transactions and vast pools of personal financial information — the measures introduce formal obligations around data classification, access control, incident reporting, and cross-border data transfer. These requirements will require affected entities to review their existing data governance frameworks and potentially invest in upgraded technical and organisational controls ahead of the June deadline.

CONTEXT WITHIN CHINA'S REGULATORY AGENDA

The issuance of the data security measures comes against a backdrop of heightened regulatory attention to the technology and data practices of China's financial services industry. Regulators have over recent years examined the data collection practices of large fintech platforms, imposed restrictions on the transfer of financial data outside China's borders, and required companies to obtain specific approvals before processing certain categories of sensitive personal information.

For foreign-owned financial institutions and international payment networks operating in China, the new measures add to the compliance obligations they must navigate alongside existing rules on data localisation and cross-border data flows. The two-month lead time before the 30 June effective date means that compliance teams at affected institutions will need to move quickly to conduct gap assessments and prioritise remediation efforts.

The PBoC has not publicly detailed the enforcement penalties for non-compliance, but the broader Chinese regulatory environment for data security has increasingly involved significant fines and, in some cases, suspension of business activities. Institutions subject to the measures will be expected to demonstrate readiness by the effective date, and the central bank is likely to incorporate data security compliance into its routine supervisory examination processes going forward.