China has ordered local organisations to conduct annual reviews of the data they hold, so they can apply proper protections as defined on a new three-tier classification scale.
The order addresses confusing omissions in China's new data protection law which, as we
reported upon its introduction, called for companies to define data as "core" or "important" and protect it accordingly – without defining those terms.
A
document [PDF] issued yesterday does define the terms.
"Important" data has been defined as having potential to harm national security if it falls into the wrong hands, or cause major production problems across multiple industries within China. Machine translation of the document suggests the definition of "important" also covers AI technology, and details of China's polar, deep sea, and space exploration programs.
"Core" data covers all of the above, but loss of such material would be less disruptive to Chinese security and industry than would be the case for "Important" data.
The new document requires Chinese organisations to self-assess their data and decide what belongs in each bucket, then apply lifecycle management to ensure their classification efforts are up to date. Annual reviews will help things along.