Cyberspace Administration of China
CAC
China
China's principal regulator for personal information protection, data security and cross-border data transfers.
- Jurisdiction (head office)
China
- Scope covered
- People's Republic of China (mainland)
- Type
- Internet / data regulator
- GRC discipline
- Data protection & privacy
- Statutory / official basis
- Personal Information Protection Law (PIPL, 2021); Data Security Law 2021; Cybersecurity Law 2017
- Status
- Current — verified June 2026
Not a GPA member; included as a major authority. Sectoral regulators (MIIT, MPS) share enforcement.
This is a curated reference entry maintained by VulaPri, verified against official sources. Spotted something out of date? Tell us →
