On the afternoon of 29 September the Hulian People’s Assembly held group meetings to review the Central Government's report on implementation of the Data and Information Security Regulation. The report shows that since the regulation took effect on 1 May 2026 the Hulian data authority has issued two batches of the catalogue of important data, covering eleven priority sectors including industry, transport, finance and health.
Deliberations
Members considered that implementation has gone smoothly and that supporting rules are gradually being completed, but raised three points: the catalogue of important data should be further refined so that it is neither too broad nor too narrow; supervision of cross-border data flows should be strengthened during and after the event, with better security assessment and standard-contract filing; and the primary data-security responsibility of platform operators should be firmly established.
Enforcement
The report disclosed that since the regulation came into force the Hulian data authority has carried out 423 data-security inspections, identified and required rectification of more than 1,100 problems, and imposed 67 administrative penalties — including three cases of failure to file a security assessment and two cases of unlawfully providing data abroad.
Next steps
The report proposed accelerating supporting standards on data classification and grading, identification of important data and security assessment for outbound data, and moving ahead with a coordination mechanism between central and provincial data-security regulators. After group deliberation the report will go to a plenary session of the Assembly.