The Law on Cryptography in China

David Kemp

The new law encourages and creates incentives for scientific and technical research in the field of encryption and protects the intellectual property of cryptographic technologies and methods. The new rules emphasize the need to educate specialists in the field of cryptography. In accordance with them, people who make a huge contribution to this area will be encouraged.

Specifics of the Law "On Cryptography" in China

The legislative act distinguishes three types of cryptography: “basic”, “generally accepted” and “commercial”. The state will strictly regulate the standards of the first two types. With their use, state secrets and confidential state information will be protected.

Confidential information owned by the state and sent to the data transmission networks, as well as all information systems, will use the algorithms of generally accepted and basic encryption. If there are risks related to the algorithms used, appropriate measures should be taken immediately. The new legislation provides for the organization of control over compliance with data encryption. In 2019, 383,000 officials were punished for violating regulations in China. 

Commercial cryptography will be used to protect information about individuals and legal entities. They will be allowed to use these algorithms under the new legislation.

Authorities motivate research, the implementation of scientific developments and academic exchange in the field of commercial cryptography. The provision of services, scientific research, export, and commercial sales should not harm national security and the interests of society, infringe on the interests of other people and violate their rights. The article “Regulation of cryptocurrency in Asia” describes the laws in force in other Asian countries.

Prohibitions of the Law "On Cryptography"

Existing legislation prohibits government agencies and officials from requiring confidential information about algorithms, and also instructs them to keep trade secrets that are entrusted to them.

In the text of the law, you can find a section on legal liability for illegal actions that are associated with cryptography. For example, when stealing other people's information that is encrypted, punishment is provided. It is also imposed for the use of cryptography for actions that violate applicable law and state security, the interests of citizens and society. Responsibility for breaking a cryptographic protection system has been established. Punishment will be applied when fixing risks that are associated with generally accepted and basic cryptographic protection when actions to eliminate the danger were not taken.

The Law "On Cryptography" has two main directions: the promotion of developments in the field of cryptography and the punishment for committing illegal actions.