China's data compliance legal framework is composed of three foundational laws: the Cybersecurity Law (CSL, effective June 1, 2017), the Data Security Law (DSL, effective September 1, 2021), and the Personal Information Protection Law (PIPL, effective November 1, 2021). These three laws require enterprises to establish distinct security and compliance officer roles: the Cybersecurity Officer, the Data Security Officer, and the Personal Information Protection Officer. Although these roles may involve overlapping responsibilities in practice, their legal basis, scope of application, and competency requirements differ. Accurately understanding the relationships and distinctions among them is fundamental for enterprises to build a compliant organizational structure.
Cybersecurity Officer: Basic Requirements of the Cybersecurity Law
Article 21 of the Cybersecurity Law stipulates that network operators shall designate a cybersecurity officer to implement cybersecurity protection responsibilities. This is the requirement with the broadest coverage among the three roles—all network operators must designate a cybersecurity officer, with no scale threshold restrictions. The core responsibilities of the cybersecurity officer include: formulating internal security management systems and operational procedures, designating personnel responsible for cybersecurity protection; implementing technical measures to prevent cybersecurity threats such as computer viruses, network attacks, and network intrusions; implementing technical measures to monitor and record network operational status and cybersecurity incidents, and retaining relevant network logs for no less than six months as required; and implementing measures such as data classification, backup of important data, and encryption. For critical information infrastructure operators, Article 34 of the Cybersecurity Law further requires the establishment of specialized security management bodies and security management officers, as well as conducting security background checks on these officers and personnel in key positions.
Data Security Officer: Special Requirements under the Data Security Law
Article 27 of the *Data Security Law* requires that data processing activities must strengthen risk monitoring, and remedial measures must be taken immediately upon discovering risks such as data security defects or vulnerabilities. Articles 44 and 45 further specify that processors handling important data must designate a data security officer and establish a management body to fulfill data security protection responsibilities. The trigger for this requirement is an enterprise processing "important data," rather than simply meeting a scale threshold. The definition of important data is based on the *Data Security Law* and the important data catalogs issued by various industry regulatory authorities, typically covering data closely related to national security, economic operations, social stability, public health, and safety. The core responsibilities of the data security officer focus on security governance throughout the entire data lifecycle, including data classification and grading, identification and cataloging of important data, data security risk assessments, cross-border data transfer security management, and emergency response to data security incidents.
Personal Information Protection Officer: Privacy Requirements under PIPL
Article 52 of the Personal Information Protection Law (PIPL) requires personal information processors handling personal information exceeding the threshold specified by the national cyberspace administration to designate a personal information protection officer. The current regulatory threshold is processing personal information of more than 1 million individuals. The responsibilities of the personal information protection officer are more focused on the field of privacy protection, including: supervising the compliance of personal information processing activities, formulating and maintaining privacy policies, managing data subject rights requests, conducting personal information protection impact assessments (PIA), organizing privacy training, and serving as a liaison with the cyberspace administration. Compared to the previous two roles, the PIPO places greater emphasis on protecting the rights and interests of data subjects and establishing privacy compliance processes, with skill requirements leaning more toward legal compliance and privacy governance.
Comparison of Skill Emphasis Among the Three Roles
- ›Cybersecurity Lead – Technical Security Focus: Network Architecture Security, Penetration Testing, Security Operations (SOC), Classified Protection Compliance, Emergency Response, Security Audit Technical Capabilities ---ITEM--- Data Security Lead – Data Governance Focus: Data Classification and Grading, Data Lifecycle Management, Encryption and Masking Technologies, Cross-Border Data Transfer Management, Critical Data Identification, Data Security Risk Assessment ---ITEM--- Personal Information Protection Lead – Privacy Protection Focus: Interpretation of Privacy Laws and Regulations, Privacy Impact Assessment (PIA), Consent Management Mechanism Design, Data Subject Rights Response, Cross-Border Data Transfer Compliance, Privacy Policy Development and Review
Can one person hold multiple roles simultaneously?
From a legal perspective, current regulations do not explicitly prohibit one individual from holding multiple roles. In practice, many small and medium-sized enterprises indeed assign one executive to handle the responsibilities of two or even three roles simultaneously. However, from the standpoint of compliance best practices, such consolidation of roles is not ideal for three reasons. First, the skill requirements differ significantly: the cybersecurity officer needs a strong technical background, the data security officer requires expertise in data governance, and the PIPO must possess robust legal and privacy compliance capabilities. Few individuals can master all three areas simultaneously. Second, there are potential conflicts of interest: for instance, the cybersecurity officer may lean toward collecting more log data to enhance security monitoring, while the PIPO must restrict data collection based on the principle of data minimization. Third, workload and liability risks: with the 2026 Cybersecurity Law amendments significantly raising the upper limits for fines, personal liability risks have increased substantially. Assuming multiple responsibilities exposes individuals to higher operational risks and compliance pressures.
Recommended Configuration for Enterprises of Different Scales
- ›Small enterprises (processing information of fewer than 1 million individuals): A technical executive may concurrently serve as the cybersecurity officer and data security officer, supplemented by an external privacy legal advisor. ---ITEM--- Medium-sized enterprises (processing information of 1 million to 10 million individuals): It is recommended to establish at least two independent positions—one cybersecurity officer responsible for technical security, and one PIPO concurrently handling data security duties. ---ITEM--- Large enterprises and critical information infrastructure operators: Three independent positions should be established, each supported by a professional team, with a cross-departmental coordination mechanism to ensure effective collaboration among the three roles. ---ITEM--- Branches of multinational enterprises in China: Additional consideration must be given to the reporting relationships and responsibility boundaries between the Chinese PIPO and the group's global DPO, ensuring compliance with local Chinese regulatory requirements while aligning with the group's global privacy governance framework.
The key to building a collaborative mechanism.
Regardless of the organizational structure adopted by an enterprise, efficient collaboration among the three roles is key to the effective operation of the compliance system. It is recommended that enterprises establish a regular joint meeting system to clarify the division of responsibilities and collaboration processes among the roles in critical scenarios such as data breach incident response, new business data processing assessments, and regulatory inspection handling. Additionally, a unified compliance management platform should be established to enable the sharing of security incidents, compliance risks, and data governance information, thereby avoiding information silos and redundant efforts. Enterprises should also integrate the priorities of the three roles into their annual compliance plans, ensuring that security protection, data governance, and privacy compliance are advanced in a coordinated manner to form a cohesive overall effort.



