§ GLOSSARY
The terminology.
680 terms across 12 categories. The canonical translation table DCC uses for every brief — the long-term moat of this publication.
680 terms
Data Types .
数据类型
| 中文 | English |
|---|---|
| 数据 | data |
| 原始数据 | raw data / primary data NDA Common Data Terms Batch 1 (2024) uses "primary data" |
| 衍生数据 | derived data |
| 网络数据 | network data introduced as a defined term by the Network Data Security Regulation |
| 训练数据 | training data GenAI Measures Art 7 |
| 数据资源 | data resources Gov Data Sharing Regulations usage |
| 数据产品和服务 | data products and services NDA Common Data Terms Batch 1 § 5 |
| 元数据 | metadata |
| 结构化数据 | structured data |
| 半结构化数据 | semi-structured data |
| 非结构化数据 | unstructured data |
| 个人信息 | personal information |
| 敏感个人信息 | sensitive personal information |
| 儿童个人信息 | personal information of children |
| 未成年人个人信息 | personal information of minors |
| 生物识别信息 | biometric information |
| 人脸信息 | facial information SPC FRT Interpretation core term |
| 重要数据 | important data |
| 核心数据 | core data |
| 国家核心数据 | national core data |
| 一般数据 | general data |
| 公共数据 | public data |
| 政务数据 | government data |
| 企业数据 | enterprise data |
| 数据资产 | data assets |
| 数据要素 | data elements |
| 重要数据目录 | catalogue of important data |
Data Processing & Compliance Management .
数据处理与合规管理
| 中文 | English |
|---|---|
| 处理 | processing |
| 数据处理 | data processing / data handling NDA Batch 1 uses "data handling" (collect / store / use / process / transmit / provide / publish) |
| 数据处理活动 | data processing activities |
| 数据处理者 | data processor / data handler DSL term (generic) — "data handler" in CAC and NDA translations |
| 网络数据处理者 | network data handler Network Data Security Regulation term |
| 个人信息处理者 | personal information handler PIPL Article 73 — DO NOT render as "data controller" |
| 个人 | the individual / the individual concerned PIPL's preferred rights-holder term, not "personal information subject" |
| 受托处理者 | entrusted processor |
| 受托数据处理者 | commissioned data handler / trustee data processor NDA Batch 1 § 10 uses "commissioned data handler" |
| 数据治理 | data governance |
| 数据流通 | data circulation / data flow NDA Batch 1 § 11 uses "data circulation"; "data flow" common in cross-border context (not GDPR-style "data flow") |
| 委托处理 | entrusted processing |
| 共同处理 | joint processing |
| 公开披露 | public disclosure |
| 转让 | transfer |
| 共享 | sharing |
| 个人信息主体 | personal information subject Pre-PIPL standard term; PIPL itself uses "个人" (individual) |
| 数据主体 | data subject GDPR vocabulary; preserve if the source author chose it, do not back-fit onto PIPL |
| 单独同意 | separate consent |
| 明示同意 | explicit consent |
| 一揽子同意 | bundled consent SPC FRT Interpretation Art 4 — invalid consent pattern |
| 告知 | notice |
| 知情同意 | informed consent |
| 实名核验 | real-name verification Deep Synthesis / GenAI / Algo Rec triple requirement |
| 真实身份信息 | real identity information |
| 个人信息保护影响评估 | Personal Information Protection Impact Assessment (PIPIA) PIPL Arts 55–56 render verbally as "impact assessment on personal information protection" |
| 风险评估 | risk assessment |
| 数据安全风险评估 | data security risk assessment |
| 自评估 | self-assessment term used across CBDT pathways |
| 安全事件 | security incident |
| 个人信息安全事件 | personal information security incident |
| 网络安全事件 | cybersecurity incident |
| 数据安全事件 | data security incident |
| 应急预案 | emergency response plan |
| 应急响应 | emergency response |
| 自动化决策 | automated decision-making |
| 用户画像 | user profiling |
| 精准营销 | targeted marketing |
| 去标识化 | de-identification |
| 匿名化 | anonymization |
| 脱敏 | de-sensitization narrower than 去标识化/匿名化 — masking-style treatment used e.g. in the NEA energy-data classification guide's downgrade rule |
| 最小必要 | minimum necessary |
| 合法、正当、必要 | lawful, legitimate, and necessary |
| 数据治理 | data governance |
| 数据安全 | data security |
| 数据分类分级 | data classification and grading also rendered "classified and hierarchical protection of data" in regulations |
| 分类分级保护 | classified and hierarchical protection |
| 合规审计 | compliance audit |
| 个人信息保护合规审计 | personal information protection compliance audit |
| 小型个人信息处理者 | small personal information handler <100,000 people; Order No. 25 Art 2 |
| 简化措施 | simplified measures |
| 个人信息处理规则 | personal information processing rules |
| 服务管理单位 | service-management unit parks / industrial bases / commercial properties, Order No. 25 Art 5 |
| 不予处罚 | no penalty imposed Order No. 25 Art 18 — mandatory, not discretionary |
| 从轻或者减轻处罚 | lighter or mitigated penalty Order No. 25 Art 19 |
| 初次违法 | first-time violation |
| 提示函 | reminder letter regulatory measure paired with 约谈 where no penalty is imposed |
| 抽查评估 | spot-check assessment |
| 自查表 | self-check table |
| 备查 | for future reference / on file |
| 个人信息保护负责人 | person in charge of personal information protection |
| 专门机构 | specialized agency third-party PI-audit body under the 2025 Audit Measures |
| 专门安全管理机构 | specialized security management body CIIO obligation under CII Regulations Art 14-15 |
| 履行个人信息保护职责的部门 | authorities performing duties of personal information protection |
| 保护机构 | protection authority informal shorthand used in the Audit Measures |
| 保护工作部门 | protection authority CII Regulations usage |
| 主管部门 | competent authority |
| 监督管理部门 | supervisory authority |
| 重要互联网平台服务 | important Internet platform services PIPL Art 58 — large-platform obligation trigger |
| 党政机关 | Party and government organs |
| 企事业单位 | enterprises and public institutions |
| 公共服务 | public services |
| 公益事业 | public welfare |
| 公开招标 | public bidding |
| 邀请招标 | invited bidding |
| 数据安全主体责任 | primary responsibility for data security |
| 实施方案 | implementation plan |
| 行政权力 | administrative power |
| 市场支配地位 | market dominant position |
| 排除、限制竞争 | exclude or restrict competition |
| 网络平台运营者 | network platform operator |
| 网络平台 | network platform |
| 社会责任报告 | social responsibility report |
| 网络产品和服务 | network products and services |
| 网络安全服务机构 | cybersecurity service agency |
| 安全保密协议 | security confidentiality agreement |
| 三道防线 | three lines of defense financial-sector governance term; NFRA cybersecurity draft (2026) drafting principle |
| 第一责任人 | first person responsible NFRA cybersecurity draft Art 7 — institution's principal officer |
Cross-Border Data Flow .
数据出境
| 中文 | English |
|---|---|
| 数据出境 | cross-border data transfer PIPL itself uses the verbal "provide personal information outside the territory of the PRC" |
| 数据跨境流动 | cross-border data flows |
| 跨境提供个人信息 | cross-border provision of personal information |
| 跨境处理 | cross-border processing |
| 境外接收方 | overseas recipient |
| 数据出境安全评估 | Data Export Security Assessment PIPL renders verbally as "security evaluation organized by the CAC" — 评估 is rendered both as "assessment" and "evaluation" |
| 安全评估 | security assessment |
| 出境安全评估 | outbound security assessment |
| 评估申报 | assessment declaration / declaration for security assessment |
| 评估通过 | passing the security assessment |
| 评估结果通知书 | Assessment Result Notice CAC document conveying which PI data items cleared / were rejected for export |
| 违法出境 | unlawful cross-border transfer (of data) enforcement-notice phrasing, e.g. 违法出境个人信息 |
| 未落实评估要求 | failure to implement assessment requirements distinct from 未通过评估 (failure to pass) — transferred outside the cleared scope |
| 个人信息出境标准合同 | Standard Contract for Cross-Border Transfer of Personal Information |
| 个人信息出境标准合同备案 | Personal Information Standard Contract Filing |
| 标准合同 | Standard Contract |
| 个人信息保护认证 | Personal Information Protection Certification |
| 认证 | certification CAC Cross-border Provisions sometimes render 认证 as "authentication" — both are in circulation |
| 认证机构 | certification body new under the 2026 PI Outbound Certification Measures |
| 认证证书 | certification certificate |
| 认证标志 | certification mark |
| 备案 | filing |
| 负面清单 | negative list |
| 白名单 | whitelist |
| 数据本地化 | data localization |
| 本地存储 | local storage |
| 出海 | overseas expansion |
| 自由贸易试验区 | pilot free trade zone (FTZ) introduced by the 2024 Cross-border Provisions Art 6 negative-list mechanism |
| 自贸区 | pilot free trade zone (FTZ) |
| 属地管辖 | territorial jurisdiction the test under GenAI Measures Art 2: are the service recipients in China? |
| 免予申报 | exempt from declaration CBDT Provisions Arts 4-6 — removes the FILING, never the underlying duty |
| 穿透认定 | look-through determination characterizing a nominally export-only service as domestic provision |
| 地域隔离 | geographic isolation blocking domestic access — a precondition of the export-only filing exemption |
| 出海版本 | overseas version |
Data Property Rights & Trading .
数据产权与交易
| 中文 | English |
|---|---|
| 数据产权 | Data Property Rights |
| 数据产权登记 | Data Property Rights Registration |
| 数据持有权 | Right to Hold Data |
| 数据使用权 | Right to Use Data |
| 数据经营权 | Right to Operate Data |
| 数据交易 | data trading |
| 交易主体 | trading subjects |
| 交易标的 | subject matter of transaction |
| 数据交易机构 | data trading institution |
| 场内数据交易 | on-exchange data trading |
| 数据场内交易 | on-exchange data trading NDA Batch 2 § 9 — synonym for 场内数据交易 |
| 场外数据交易 | off-exchange data trading |
| 数据场外交易 | off-exchange data trading NDA Batch 2 § 10 — synonym for 场外数据交易 |
| 数据撮合 | data matching |
| 数据交易撮合 | data trading matching NDA Batch 2 § 11 |
| 第三方专业服务机构 | third-party professional service institutions |
| 数据第三方专业服务机构 | data third-party professional service institution NDA Batch 2 § 12 |
| 第三方法律服务机构 | third-party legal service institutions |
| 数据要素市场化配置 | market-oriented allocation of data elements NDA Batch 1 § 7 |
| 公共数据资源 | public data resources |
| 授权运营 | authorized operation |
| 实施机构 | implementing institution |
| 运营机构 | operating institution |
| 登记机构 | registration institution |
| 登记主体 | registrant |
| 登记申请人 | registration applicant |
| 登记凭证 | registration certificate |
| 赋码 | code issuance |
| 数据基础制度 | fundamental data system |
| 一体化数据市场 | integrated data market |
| 数据要素市场 | data factor market |
| 数据流通服务机构 | data circulation service institution |
| 隐私计算 | privacy computing |
| 政务数据共享 | government data sharing |
| 数据描述 | data description |
| 数据来源 | data source |
| 数据存证 | data evidence preservation |
| 数据指纹 | data fingerprint |
| 数据水印 | data watermark |
| 数据入表 | data balance-sheet entry |
| 数据资产化 | data assetization |
| 数据资产资本化 | data asset capitalization |
| 异议 | objection |
| 异议处理 | objection handling |
| 初次登记 | initial registration |
| 转让登记 | transfer registration |
| 变更登记 | change registration |
| 续期登记 | renewal registration |
| 注销登记 | deregistration |
| 续期 | renewal |
| 注销 | deregistration |
| 权利限制 | rights limitation |
| 多源数据 | multi-source data |
| 衍生创造 | derivative creation |
| 自动化程序 | automated procedures |
| 公共气象数据 | public meteorological data |
| 开发机构 | development institution CMA meteorological AO measures Art. 3 — third tier below 实施机构/运营机构 |
| 气象数据身份标识 | meteorological-data identity tag AI Meteorological Services Measures Art. 8; trading gate in CMA AO measures Art. 22 |
| 气象数据流通监管平台 | meteorological data circulation supervision platform |
| 数源单位 | data-source unit consent required before non-department data enters an AO catalogue |
| 政府指导价 | government-guided pricing |
| 运营服务费 | operation service fee |
| 公益优先 | public-interest priority AO principle shared by the national Specifications and the CMA measures |
| 谁投入、谁贡献、谁受益 | who invests, who contributes, who benefits Data 20 Articles returns-distribution principle |
| 数据资产确认 | data asset confirmation GB/T 47950 § 3.2 |
| 数据资产信息卡 | data asset card GB/T 47950 § 3.3 |
| 数据资产登记 | data asset registration GB/T 47950 § 3.4 |
| 数据资产台账 | data asset register GB/T 47950 § 3.5 — a ledger, NOT a "registry" |
| 数据资产备查簿 | data asset subsidiary record GB/T 47950 § 3.6 — for assets not yet confirmable |
| 资产台账 | asset register |
| 备查簿 | subsidiary record |
| 初始登记 | initial registration GB/T 47950 § 7.2 (cf. 初次登记 in the NDA guide) |
| 无形资产 | intangible assets |
| 资产原值 | original value of the asset |
| 摊销 | amortization |
| 累计摊销 | accumulated amortization |
| 残值率 | residual value rate |
| 净值 | net value |
| 会计账簿 | accounting books |
| 记账凭证 | accounting voucher |
| 原始凭证 | original voucher |
| 会计科目 | accounting subject |
| 清查 | inventory-taking |
| 权属信息 | ownership information |
| 流通类型 | circulation type |
| 共享类型 | sharing type |
| 开放类型 | openness type |
| 处置 | disposal |
| 线分类法 | line classification method |
| 门类 | division |
| 大类 | major class |
| 中类 | medium class |
| 小类 | minor class |
| 细类 | sub-class |
| 收容项 | catch-all item |
| 计量单位 | unit of measure |
| 标记语言数据 | markup-language data |
| 标记分隔数据 | delimiter-separated data |
| 日志文件数据 | log-file data |
| 复合文档数据 | compound-document data |
| 空间关系数据 | spatial-relationship data |
| 人工智能训练多模态数据 | AI-training multimodal data GB/T 47949 code A0806020307 |
| 词元 | token |
| 商业秘密 | trade secret |
| 技术秘密 | technical secret |
| 经营秘密 | business secret |
| 三性 | the three elements of a trade secret — the AUCL definition requires all three |
| 非公知性 | not generally known |
| 秘密性 | secrecy |
| 保密性 | confidentiality |
| 价值性 | commercial value |
| 保密措施 | confidentiality measures |
| 相应保密措施 | corresponding confidentiality measures AUCL standard — reasonable, not airtight |
| 保密协议 | confidentiality agreement |
| 秘点 | secret point the specific delimited content claimed as secret |
| 载体 | carrier the medium holding a trade secret, distinct from its content |
| 不侵权承诺书 | undertaking of non-infringement |
| 技术贡献率 | technical contribution rate the share of infringer profit attributable to the secret |
Key Laws & Regulations .
法律法规
| 中文 | English |
|---|---|
| 网络安全法 | Cybersecurity Law (CSL) |
| 数据安全法 | Data Security Law (DSL) |
| 个人信息保护法 | Personal Information Protection Law (PIPL) |
| 个保法 | Personal Information Protection Law (PIPL) |
| 民法典 | Civil Code |
| 反电信网络诈骗法 | Anti-Telecom and Online Fraud Law |
| 国家安全法 | National Security Law |
| 外商投资法 | Foreign Investment Law |
| 反垄断法 | Anti-Monopoly Law |
| 密码法 | Cryptography Law |
| 生物安全法 | Biosecurity Law |
| 种子法 | Seed Law |
| 粮食安全保障法 | Food Security Guarantee Law |
| 海南自由贸易港法 | Hainan Free Trade Port Law |
| 未成年人保护法 | Law on the Protection of Minors 2020 revision added the Network Protection chapter |
| 未成年人学校保护规定 | Provisions on the Protection of Minors by Schools MOE Order No. 50 |
| 网络数据安全管理条例 | Regulation on Network Data Security Management State Council Decree No. 790 — official rendering uses singular "Regulation" |
| 关键信息基础设施安全保护条例 | Security Protection Regulations for Critical Information Infrastructure State Council Decree No. 745 |
| 未成年人网络保护条例 | Regulations on the Protection of Minors in Cyberspace State Council Decree No. 766 |
| 政务数据共享条例 | Regulations on the Sharing of Government Data State Council Decree No. 809 |
| 数据出境安全评估办法 | Measures for the Security Assessment of Data Export CAC Decree No. 11 |
| 促进和规范数据跨境流动规定 | Provisions on Promoting and Regulating Cross-border Data Flows CAC Decree No. 16 — note "Cross-border" (lowercase b) in official translation |
| 个人信息出境标准合同办法 | Measures on the Standard Contract for the Outbound Transfer of Personal Information CAC Decree No. 13, effective 2023-06-01 |
| 个人信息出境标准合同备案指南 | Guide to the Filing of the Standard Contract for Outbound Transfer of Personal Information CAC procedural guide accompanying SCC Measures |
| 个人信息出境认证办法 | Measures for the Certification of the Cross-border Provision of Personal Information CAC + SAMR Order No. 20, effective 2026-01-01 |
| 个人信息保护认证实施规则 | Implementation Rules for Personal Information Protection Certification |
| 个人信息保护合规审计管理办法 | Administrative Measures for Personal Information Protection Compliance Audits CAC Decree No. 18, effective 2025-05-01 |
| 个人信息安全规范 | Personal Information Security Specification |
| 网络安全审查办法 | Cybersecurity Review Measures CAC + 12-agency Decree No. 8 |
| 网络数据安全风险评估办法 | Measures for Network Data Security Risk Assessment CAC + MIIT + MPS Order No. 24, effective 2026-08-20 |
| 外商投资安全审查办法 | Measures for the Security Review of Foreign Investments NDRC + MOFCOM Decree No. 37 |
| 互联网信息服务算法推荐管理规定 | Provisions on the Administration of Algorithmic Recommendation Services for Internet Information Services CAC + 3 Decree No. 9 |
| 互联网信息服务管理办法 | Administrative Measures for Internet Information Services State Council, foundational ICP regulation (2000, revised 2011, 2024) |
| 人工智能拟人化互动服务管理暂行办法 | Interim Measures for the Management of AI Anthropomorphic Interaction Services CAC + 4-agency Order No. 21, effective 2026-07-15 |
| 生成式人工智能服务管理暂行办法 | Interim Measures for the Management of Generative Artificial Intelligence Services CAC + 6 Decree No. 15 |
| 互联网信息服务深度合成管理规定 | Provisions on the Administration of Deep Synthesis of Internet Information Services CAC + 2 Order No. 12 |
| 人工智能生成合成内容标识办法 | Measures for the Labeling of AI-Generated and Composed Content CAC + 3 Guo Xin Ban Tong Zi [2025] No. 2 |
| 银行业保险业网络安全管理办法 | Measures for the Administration of Cybersecurity in the Banking and Insurance Sectors NFRA draft for public consultation, July 2026 |
| 金融业网络安全管理办法 | Measures for the Administration of Cybersecurity in the Financial Sector draft for public consultation, July 2026 — companion instrument to the NFRA banking/insurance draft |
| 智能体规范应用与创新发展实施意见 | Implementation Opinions on the Standardized Application and Innovative Development of AI Agents CAC + NDRC + MIIT, 2026-05-08 |
| 北京市关于加快智能体引领发展的若干措施 | Several Measures of Beijing Municipality on Accelerating Agent-Led Development 京发改〔2026〕1185号, four municipal bodies, issued 2026-07-21 |
| 最高人民法院关于审理使用人脸识别技术处理个人信息相关民事案件适用法律若干问题的规定 | Provisions of the Supreme People's Court on Several Issues Concerning the Application of Law in the Trial of Civil Cases Involving the Use of Facial Recognition Technology to Process Personal Information |
| 反不正当竞争法 | Anti-Unfair Competition Law (AUCL) |
| 出口管制法 | Export Control Law |
| 中华人民共和国出口管制法 | Export Control Law of the PRC |
| 中国禁止出口限制出口技术目录 | Catalogue of Technologies Prohibited or Restricted from Export in China |
| 管制物项 | controlled items Export Control Law — expressly includes SERVICES |
| 临时管制 | temporary control |
| 电信条例 | Telecommunications Regulations |
| 电信业务分类目录 | Catalogue of Telecommunications Services 2015 edition — B11 = IDC, B12 = Internet resource collaboration (cloud) |
| 外商投资准入特别管理措施(负面清单) | Special Administrative Measures for Foreign Investment Access (Negative List) |
| 外商投资电信企业管理规定 | Provisions on the Administration of Foreign-Invested Telecommunications Enterprises |
| 固定资产投资项目节能审查办法 | Measures for the Energy-Conservation Review of Fixed-Asset Investment Projects NDRC Order No. 2 of 2023 |
Regulators & Authorities .
监管机构
| 中文 | English |
|---|---|
| 国家互联网信息办公室 | Cyberspace Administration of China (CAC) |
| 国家网信办 | Cyberspace Administration of China (CAC) |
| 网信办 | Cyberspace Administration of China (CAC) |
| 中央网信办 | Office of the Central Cyberspace Affairs Commission |
| 网络安全审查办公室 | Cybersecurity Review Office |
| 国家数据局 | National Data Administration (NDA) |
| 国务院 | State Council |
| 工信部 | Ministry of Industry and Information Technology (MIIT) |
| 公安部 | Ministry of Public Security (MPS) |
| 公安部网络安全保卫局 | Cyber Security Protection Bureau of the Ministry of Public Security |
| 公安部网安局 | MPS Cyber Security Bureau the bureau's own short form, used on its WeChat channel |
| 网安部门 | cyber-security police provincial/municipal 网安总队/支队 — the operational units named in MPS case releases |
| 国家网络身份认证公共服务平台 | National Network Identity Authentication Public Service Platform |
| 国家网络身份认证公共服务管理办法 | Measures for the Administration of National Network Identity Authentication Public Services MPS Order No. 173, effective 2025-07-15 |
| 网号 | network number letters-and-digits identity symbol carrying no plaintext identity information |
| 网证 | network credential credential carrying the 网号 plus non-plaintext identity information |
| 明文身份信息 | plaintext identity information what an integrating platform may NOT separately demand (Order 173 Art. 7) |
| 身份核验 | identity verification |
| 实名认证 | real-name verification |
| 可信数字身份 | trusted digital identity |
| 国家安全部 | Ministry of State Security (MSS) |
| 国家市场监督管理总局 | State Administration for Market Regulation (SAMR) |
| 国家发展和改革委员会 | National Development and Reform Commission (NDRC) |
| 发改委 | National Development and Reform Commission (NDRC) |
| 教育部 | Ministry of Education (MOE) |
| 科学技术部 | Ministry of Science and Technology (MOST) |
| 科技部 | Ministry of Science and Technology (MOST) |
| 财政部 | Ministry of Finance (MOF) |
| 商务部 | Ministry of Commerce (MOFCOM) |
| 中国人民银行 | People's Bank of China (PBOC) |
| 国家金融监督管理总局 | National Financial Regulatory Administration (NFRA) |
| 金融监管总局 | National Financial Regulatory Administration (NFRA) |
| 国家广播电视总局 | State Administration of Radio and Television (NRTA) |
| 中国证券监督管理委员会 | China Securities Regulatory Commission (CSRC) |
| 证监会 | China Securities Regulatory Commission (CSRC) |
| 国家保密局 | State Secrecy Administration (SSA) |
| 国家密码管理局 | State Cryptography Administration (SCA) |
| 中国信通院 | China Academy of Information and Communications Technology (CAICT) |
| 全国信息安全标准化技术委员会 | National Information Security Standardization Technical Committee (TC260) |
| 最高人民法院 | Supreme People's Court (SPC) |
| 最高人民检察院 | Supreme People's Procuratorate (SPP) |
| 人民法院 | People's Court |
| 人民检察院 | People's Procuratorate |
Cybersecurity & Critical Information Infrastructure .
| 中文 | English |
|---|---|
| 网络 | network |
| 网络运营者 | network operator |
| 关键信息基础设施 | critical information infrastructure (CII) |
| 关键信息基础设施运营者 | critical information infrastructure operator (CIIO) |
| 运营者 | operator CII Regulations shorthand |
| 关键信息基础设施认定 | identification of critical information infrastructure |
| 关键信息基础设施识别 | identification of critical information infrastructure |
| 网络安全等级保护制度 | Multi-Level Protection Scheme (MLPS) |
| 等级保护 | Multi-Level Protection Scheme (MLPS) |
| 网络安全审查 | cybersecurity review |
| 安全审查 | security review |
| 国家安全审查 | national security review |
| 数据安全审查 | data security review DSL Art 24 regime — landed via the 2021 Cybersecurity Review Measures revision; decisions final |
| 外商投资安全审查 | foreign investment security review |
| 网络数据安全风险评估 | network data security risk assessment |
| 总体国家安全观 | holistic approach to national security official rendering of Xi-era national-security doctrine |
| 事前审查 | ex-ante review |
| 海外上市 | overseas listing Cybersecurity Review Measures Art 7 — listing-trigger |
| 供应链安全 | supply chain security |
| 网络安全 | cybersecurity |
| 网络空间 | cyberspace |
| 主权 | sovereignty |
| 网络主权 | cyber sovereignty |
AI & Algorithms .
| 中文 | English |
|---|---|
| 人工智能 | artificial intelligence (AI) |
| 生成式人工智能 | generative artificial intelligence |
| 生成式人工智能服务 | generative AI services |
| 生成式人工智能服务提供者 | generative AI service provider |
| 深度合成 | deep synthesis |
| 深度合成服务 | deep synthesis services |
| 深度合成服务提供者 | deep synthesis service provider |
| 深度合成技术 | deep synthesis technology |
| 算法 | algorithm |
| 算法服务 | algorithmic services |
| 算法推荐 | algorithmic recommendation |
| 算法推荐服务 | algorithmic recommendation services |
| 算法推荐服务提供者 | algorithmic recommendation service provider |
| 算法备案 | algorithm filing |
| 算法安全评估 | algorithm security assessment |
| 个性化推荐 | personalized recommendation |
| 不合理差别待遇 | unreasonable differential treatment Algo Rec Provisions Art 21 — anti-price-discrimination |
| 大数据杀熟 | algorithmic price discrimination against existing users informal but ubiquitous Chinese-public term |
| 人工智能生成合成内容 | AI-generated and composed content |
| 显式标识 | visible label / explicit label Labeling Measures — user-facing |
| 隐式标识 | implicit label metadata / watermark |
| 显著标识 | prominent label Deep Synthesis Provisions usage |
| 数字水印 | digital watermark |
| 内容元数据 | content metadata |
| 内容生态治理 | content ecosystem governance |
| 拟人化互动服务 | anthropomorphic interaction services AI Anthropomorphic Interaction Measures Art 2 — sustained emotional interaction simulating a natural person |
| 拟人化互动服务提供者 | anthropomorphic interaction service provider |
| 未成年人模式 | minors' mode mandatory under Anthropomorphic Interaction Measures Art 14 |
| 虚拟亲密关系 | virtual intimate relationships banned for minors — virtual family members / romantic partners |
| 情感依赖 | emotional dependence Anthropomorphic Interaction Measures Art 8 — 诱导情感依赖 = inducing emotional dependence |
| 人脸识别 | facial recognition |
| 人脸识别技术 | facial recognition technology |
| 人脸验证 | facial verification |
| 模型幻觉 | model hallucination Cheng Xiao (2026) — plausible-looking but false/nonsensical AI output |
| 内容标识义务 | generated-content labeling obligation GenAI Interim Measures Art 12 — result-based obligation |
| 内容准确性与可靠性义务 | content accuracy and reliability obligation GenAI Interim Measures Art 4(5) — method-based obligation |
| 智能体 | AI agent / agent "AI agent" on first mention, then "agent" |
| 智能体引领发展 | agent-led development Beijing Agent Measures title term |
| 驾驭层 | harness layer Beijing Agent Measures Art 2 — the engineering layer that steers the model |
| 驾驭层工程 | harness-layer engineering |
| 上下文工程 | context engineering |
| 任务持久化 | task persistence |
| 长程任务 | long-horizon task |
| 超长程任务 | ultra-long-horizon task |
| 工具调用 | tool calling |
| 多智能体协作 | multi-agent collaboration |
| 多智能体协同 | multi-agent collaboration |
| 群体智能 | swarm intelligence |
| 世界模型 | world model |
| 长上下文 | long context |
| 在线学习 | online learning |
| 持续学习 | continual learning |
| 自主进化 | self-evolution |
| 长期记忆 | long-term memory |
| 智能体技能市场 | agent skill marketplace |
| 智能体软件商店 | agent software store |
| 前沿部署工程师 | forward-deployed engineer (FDE) Beijing Agent Measures — the 驻场共创 delivery model |
| 驻场共创 | on-site co-creation |
| 标杆场景 | benchmark scenario |
| 人工智能操作系统 | AI operating system |
| 科学智能助手 | AI-for-science assistant |
| 自主实验室 | autonomous laboratory |
| 原生人工智能软件 | AI-native software |
| 数据飞轮 | data flywheel |
| 词元经济 | Token (词元) economy Beijing Agent Measures Art 6 writes "Token(词元)经济" |
| Token即服务 | Token-as-a-Service |
| 智能体即服务 | Agent-as-a-Service |
| 结果即服务 | Results-as-a-Service |
| 单位有效任务成本 | cost per valid completed task Hong Yanqing (2026) — (model+tool, review, retry, expected-risk costs) ÷ tasks meeting quality and closing the loop |
| 有效任务 | valid task quality- and risk-corrected — excludes tasks "completed" via rework, over-broad access, or skipped approvals |
| 智能生产资料 | intelligent means of production Hong Yanqing (2026) — what Tokens meter, as against the value of intelligent products |
| 价值计费 | value-based billing |
| 按结果计费 | outcome-based billing |
| 一人公司 | one-person company (OPC) Beijing Agent Measures Art 5 official gloss for OPC |
| 人工智能增强型单人创业 | AI-augmented solo entrepreneurship |
| 可信委托 | trusted delegation Hong Yanqing (2026) — delegation, not generation, as the unit of agent security |
| 人在回路 | human in the loop |
| 人在环路 | human in the loop variant spelling; AnJie Broad (2026) writes 人在环路 |
| 人工接管 | human takeover |
| 分级分类监管 | graded-and-categorized regulation order follows the Chinese 分级分类; cf. 数据分类分级 above |
| 可信沙箱 | trusted sandbox |
| 靶场 | security range 安全靶场 — adversarial-testing environment |
| 以模治模 | using models to govern models Beijing Agent Measures Art 7 coinage |
| 首购首用 | first-purchase, first-use government/SOE early-procurement mechanism |
| 数据中台 | data middle platform |
| 智能终端 | smart terminal |
| 工具辅助 | tool assistance |
| 环节嵌入 | step embedding |
| 有界闭环 | bounded closed loop |
| 端到端编排 | end-to-end orchestration |
| 原生重构 | native restructuring |
| 模型即服务 | Model-as-a-Service (MaaS) |
| 大模型备案 | large-model filing |
| 大模型登记 | large-model registration |
| 应报尽报 | report everything that ought to be reported the precautionary line taken by some local CAC offices on 大模型登记 |
| 技术中立 | technology neutrality NOT a defense for an API relay under GenAI Measures Art 22(2) |
| 开放权重 | open weights weights downloadable; says nothing about the licence terms |
| 开源代码 | open-source code |
| 自部署模型 | self-deployed model |
| 底座模型 | base model |
| 基座模型 | base model |
| 二次开发 | further development alongside 微调/训练 — the acts that trigger 大模型备案 |
| 微调 | fine-tuning |
| API中转 | API relay |
| 中转站 | relay station |
Enforcement, Procedure & Liability .
执法、程序与责任
| 中文 | English |
|---|---|
| 约谈 | regulatory interview (yuetan) PIPL Art 64 renders this simply as "interview" with a legal representative |
| 检察建议 | procuratorial recommendation procuratorate-issued compliance recommendation to an institution |
| 诉前检察建议 | pre-litigation procuratorial recommendation |
| 法治副校长 | rule-of-law vice principal school legal-education mechanism staffed by judges/prosecutors/lawyers |
| 网络欺凌 | cyberbullying |
| 网络霸凌 | cyberbullying |
| 网络沉迷 | internet addiction Minors Online Protection Regulations chapter heading term |
| 网络素养 | internet literacy |
| 名誉权 | right to reputation |
| 隐私权 | right to privacy |
| 补充责任 | supplementary liability Civil Code Art 1201 — school liability for third-party injury |
| 表白墙 | 'confession wall' account unofficial school-named social account |
| 责令整改 | order to rectify |
| 责令改正 | order to make corrections |
| 行政处罚 | administrative penalty |
| 行政处分 | administrative sanction |
| 罚款 | fine |
| 没收违法所得 | confiscation of illegal gains |
| 通报批评 | public criticism |
| 下架 | removal from app stores |
| 暂停业务 | suspension of business |
| 吊销许可证 | revocation of business permit / license |
| 信用档案 | credit archives |
| 民事责任 | civil liability |
| 刑事责任 | criminal liability |
| 侵犯公民个人信息罪 | crime of infringing upon citizens' personal information Criminal Law Art. 253a |
| 公民个人信息 | citizens' personal information the CRIMINAL-law term of art; not interchangeable with PIPL's 个人信息 |
| 情节严重 | serious circumstances Art. 253a sentencing tier 1 — up to 3 years |
| 情节特别严重 | particularly serious circumstances Art. 253a sentencing tier 2 — 3 to 7 years |
| 从重处罚 | heavier punishment Art. 253a ¶2 — for info obtained in the course of duties or services |
| 采取刑事强制措施 | subjected to criminal compulsory measures pre-indictment coercion (detention/arrest/bail) — earliest stage |
| 移送起诉 | transferred for prosecution police hand the file to the procuratorate for examination |
| 提起公诉 | public prosecution initiated the procuratorate has indicted — latest of the three stages |
| 侦破 | cracked (a case) police-release verb for a solved case; no charging decision implied |
| 扩线 | expanding investigative leads |
| 涉案金额 | amount involved in the case the case's total transaction value — NOT the same as 违法所得 |
| 违法所得 | illegal gains the offender's actual profit; the figure the RMB 5,000 threshold in the |
| 净网专项行动 | Clean Net special campaign the recurring MPS anti-cybercrime enforcement campaign |
| 黑灰产 | black and grey market |
| 黑灰产业链 | black-and-grey industry chain |
| 内鬼 | insider lit. "inside ghost" — an employee who leaks or sells data they access on the job |
| 社工库 | social-engineering database aggregated leaked-data lookup service, commonly "SGK" |
| 查档 | record lookup paid query against a social-engineering database |
| 订单解密 | order decryption re-identifying masked e-commerce order data (phone number, delivery address) |
| 精准推销 | targeted marketing |
| 精准营销 | targeted marketing |
| 行踪轨迹 | whereabouts and tracks a 50-item threshold category under the PI Criminal Interpretation Art. 5(III) |
| 开房记录 | hotel check-in records |
| 实名网络账号 | real-name online account |
| 跑分 | payment-settlement laundering running illicit funds through recruited real-name accounts |
| 帮凶 | accomplice |
| 公益诉讼 | public-interest litigation |
| 侵权 | infringement / tort |
| 侵权责任 | tort liability |
| 过错 | fault umbrella term covering 故意 (intent) and 过失 (negligence) |
| 故意 | intent |
| 过失 | negligence |
| 过错责任 | fault-based liability Civil Code Art 1165(1) general clause |
| 无过错责任 | no-fault liability aka strict liability; must be expressly provided by statute |
| 过错推定 | presumption of fault Civil Code Art 1165(2) — rebuttable |
| 违法视为过错 | unlawfulness deemed as fault non-rebuttable — breach of a statutory duty conclusively establishes fault |
| 注意义务 | duty of care objective 'reasonable person' fault standard, not a separate liability element in PRC law |
| 作为义务 | affirmative duty a legal duty to act; only its breach can ground fault |
| 不作为义务 | negative duty a duty not to infringe; folds into the 'infringement of rights' element, cannot ground fault |
| 方式性义务 | method-based obligation obligation of means (obligation de moyens) — judged by whether due care was taken, not by outcome |
| 结果性义务 | result-based obligation obligation of result (obligation de résultat) — judged by whether the required outcome was achieved |
| 保护性法律 | protective statute German Schutzgesetz — a rule aimed at protecting specific individuals, not only the public interest |
| 民事权益 | civil rights and interests |
| 人格权益 | personality rights and interests |
| 肖像权 | right to one's likeness |
| App违法违规收集使用个人信息 | illegal or excessive collection and use of personal information by apps |
| 通报 | notification (public enforcement bulletin) CAC/MIIT public-naming document type — distinct from 通知 (notice/circular) |
| 账号注销 | account cancellation app user-account exit right; 认定方法 final category & CAC 2026 testing priority |
| 小程序 | mini-program in-platform apps (WeChat/Alipay/Douyin) — expressly within CAC app-testing perimeter |
| 举证责任 | burden of proof |
| 证明责任 | burden of proof |
| 举证责任分配 | allocation of the burden of proof |
| 举证责任转移 | shifting of the burden of proof |
| 举证责任倒置 | reversal of the burden of proof |
| 初步证据 | prima facie evidence |
| 举证妨碍 | obstruction of proof refusal to produce evidence in one's control; grounds an adverse inference |
| 高度盖然性 | high degree of probability the PRC civil standard of proof |
| 实质性相似 | substantial similarity |
| 实质相同 | substantially identical |
| 合法来源 | lawful source the defendant's standard rebuttal in a misappropriation claim |
| 现场勘验 | on-site inspection |
| 律师调查令 | lawyer's investigation order court order authorizing counsel to collect evidence from a third party |
| 惩罚性赔偿 | punitive damages |
| 合理开支 | reasonable expenses enforcement costs recoverable on top of damages |
| 典型案例 | typical case SPC-published exemplar; persuasive, not binding precedent |
| 非法获取计算机信息系统数据罪 | crime of illegally obtaining data from a computer information system Criminal Law Art. 285 |
| 非法控制计算机信息系统罪 | crime of illegally controlling a computer information system Criminal Law Art. 285 |
| 提供侵入、非法控制计算机信息系统程序、工具罪 | crime of providing programs or tools for intruding into or illegally controlling computer information systems Art. 285(3) |
| 帮助信息网络犯罪活动罪 | crime of aiding information network criminal activities Criminal Law Art. 287-2 |
| 超越授权访问 | access exceeding authorization SPP Guiding Case No. 36: exceeding authorization IS intrusion |
| 网络不正当竞争 | online unfair competition |
| 指导性案例 | guiding case SPP/SPC — courts and procuratorates SHALL refer to these (应当参照); |
| 兜底条款 | catch-all provision |
| 安全港 | safe harbor |
| 无证经营 | unlicensed operation |
Document Types & Regulatory Format .
文件类型与立法体例
| 中文 | English |
|---|---|
| 法律 | law (NPC / NPCSC enactment) |
| 行政法规 | administrative regulation (State Council) |
| 部门规章 | departmental rule (ministerial) |
| 规范性文件 | normative document |
| 国家标准 | national standard |
| 推荐性国家标准 | recommended national standard (GB/T) |
| 强制性国家标准 | mandatory national standard (GB) |
| 司法解释 | judicial interpretation |
| 决定 | decision (e.g., NPC amendment decision) |
| 通知 | notice / circular |
| 指引 | guideline |
| 指南 | guide / guidelines |
| 主席令 | Presidential Decree |
| 国务院令 | State Council Decree |
| 暂行办法 | interim measures |
| 管理办法 | administrative measures |
| 管理规定 | administrative provisions |
| 实施细则 | implementation rules |
| 实施条例 | implementing regulation |
| 征求意见稿 | draft for public consultation |
| 修正 | amendment |
| 修订 | revision |
| 印发 | issuance / promulgation |
Data Economy, Industry & Infrastructure .
数据经济、产业与基础设施
| 中文 | English |
|---|---|
| 数字经济 | digital economy |
| 数字技术 | digital technology |
| 数字基础设施 | digital infrastructure |
| 数字产业化 | digital industrialization NDA Batch 1 § 16 |
| 产业数字化 | industrial digitalization NDA Batch 1 § 17 |
| 数字经济高质量发展 | high-quality development of the digital economy NDA Batch 1 § 18 |
| 数字消费 | digital consumption NDA Batch 1 § 19 |
| 产业互联网 | Industrial Internet NDA Batch 1 § 20 |
| 城市全域数字化转型 | citywide digital transformation NDA Batch 1 § 21 |
| 东数西算工程 | East Data and West Computing project NDA Batch 1 § 22 |
| 高速数据网 | high-speed data network NDA Batch 1 § 23 |
| 全国一体化算力网 | integrated national computing-power network NDA Batch 1 § 24 |
| 数据产业 | data industry NDA Batch 2 § 13 |
| 数据标注产业 | data labeling industry NDA Batch 2 § 14 |
| 数字产业集群 | digital industry cluster NDA Batch 2 § 15 |
| 可信数据空间 | trusted data space NDA Batch 2 § 16 |
| 数据使用控制 | data use control NDA Batch 2 § 17 |
| 数据基础设施 | data infrastructure NDA Batch 2 § 18 |
| 算力 | computing power |
| 算力调度 | computing-power scheduling NDA Batch 2 § 19 |
| 算力池化 | computing-power pooling NDA Batch 2 § 20 |
| 算力资源池 | computing-power resource pool |
| 智算中心 | intelligent computing center |
| 人工智能算力中心 | AI computing center |
| 算力中心 | computing center |
| 互联网数据中心 | Internet Data Center (IDC) |
| 互联网资源协作服务 | Internet resource collaboration services Telecom Catalogue B12 — i.e. cloud services |
| 算力即服务 | Compute-as-a-Service |
| 算力租用 | computing-power rental |
| 机柜租赁 | cabinet rental |
| 算力券 | computing-power voucher |
| 运力券 | transport voucher |
| 增值电信业务 | value-added telecommunications services |
| 基础电信业务 | basic telecommunications services |
| 增值电信业务经营许可证 | Value-Added Telecommunications Business License |
| 国际数据通信业务 | international data communications services |
| 国际通信出入口局 | international communications gateway |
| 通信管理局 | provincial Communications Administration |
| 节能审查 | energy-conservation review |
| 电源使用效率 | power usage effectiveness (PUE) |
| 吨标准煤 | metric tons of standard coal |
| 能耗替代指标 | energy-consumption substitution quota |
| 绿电交易 | green power trading |
| 余热回收 | waste-heat recovery |
| 核准 | government approval the heavier track; contrast 备案 (filing) |
| 公安联网备案 | public-security network filing |
| 智能投顾 | robo-advisory |
| 医疗器械 | medical device |
| 国家药品监督管理局 | National Medical Products Administration (NMPA) |
Privacy-Enhancing & Data Engineering Technologies .
隐私计算与数据工程技术
| 中文 | English |
|---|---|
| 隐私保护计算 | privacy-protective computation NDA Batch 1 § 35; also "privacy computing" (隐私计算) |
| 安全多方计算 | secure multi-party computing NDA Batch 1 § 36 |
| 联邦学习 | federated learning NDA Batch 1 § 37 |
| 可信执行环境 | trusted execution environment (TEE) NDA Batch 1 § 38 |
| 密态计算 | cryptographic computing NDA Batch 1 § 39 |
| 区块链 | blockchain NDA Batch 1 § 40 |
| 智能合约 | smart contract |
| 同态加密 | homomorphic encryption |
| 混淆电路 | confusion circuit / garbled circuit |
| 不经意传输 | oblivious transfer / inadvertent transmission |
| 秘密分享 | secret sharing |
| 数据分析 | data analysis |
| 数据挖掘 | data mining |
| 数据可视化 | data visualization |
| 数据仓库 | data warehouse |
| 数据湖 | data lake |
| 湖仓一体 | integration of lake and warehouse / data lakehouse |