Skip to content
DCC · DATA COMPLIANCE CHINA China data law, for overseas counsel.
§ LAW · NETWORK IDENTITY AUTHENTICATION MEASURES (MPS ORDER NO. 173)

Measures for the Administration of National Network Identity Authentication Public Services.

国家网络身份认证公共服务管理办法

Promulgated by: Ministry of Public Security, with the concurrence of the Cyberspace Administration of China, the Ministry of Civil Affairs, the Ministry of Culture and Tourism, the National Health Commission, and the National Radio and Television Administration. Document No.: MPS Order No. 173 (公安部令第173号). Adopted at the 1st Executive Meeting of the Ministry of Public Security on 27 February 2025. Promulgated 19 May 2025. Effective 15 July 2025. 16 articles.

DCC note. This entry is a structural summary of the Measures prepared from the promulgated Chinese text as published by the CAC, not a full translation — the article-level renderings below describe each provision rather than translate it. Defined terms and the operative platform obligations are given in the original Chinese alongside DCC’s English. A full translation is pending.


What the scheme is

The Measures establish a state-operated identity authentication layer sitting between individuals and internet platforms. Rather than each platform collecting and storing identity-document data to satisfy its real-name verification duties, a platform can call the national public service platform and receive a verification result.

Two credentials carry the scheme (Article 2):

  • 网号 — “network number”: an identity symbol corresponding to a natural person’s identity information, composed of letters and digits, and containing no plaintext identity information (不含明文身份信息的网络身份符号).
  • 网证 — “network credential”: the authentication credential that carries the network number together with the holder’s non-plaintext identity information.

The design goal is to break the link between “verifying who a user is” and “holding the documents that prove it.”

Article map

Art.Subject
1Purpose and legal basis — the trusted digital identity strategy, grounded in the CSL, DSL and PIPL
2Definitions — the public service, 网号, 网证
3Competent authorities — MPS and CAC, with the other four departments within their remits
4Eligibility — voluntary application by holders of a valid legal identity document; parental consent required below 14, parental supervision at 14–17
5Use for real-name registration and verification; consent conditions for minors under 14
6Promotion by government bodies and key sectors, while preserving existing and alternative authentication methods — no mandatory substitution
7Platform integration and user parity — see below
8Minimum disclosure — the platform receives only the verification result unless document data is genuinely required
9Limits on the public-service platform’s own collection; separate consent for sensitive personal information; deletion on request
10Age-bracket indicators may be supplied to platforms to support their minors- and elderly-protection duties
11Notice and transparency through the user agreement — identity and contact of the operator, purpose, method, categories, retention period, and rights procedures
12Security management, and domestic storage of important data and personal information; security assessment for outbound transfer; incident response and reporting
13Commercial cryptography must comply with national cryptography administration requirements
14Penalties — breaches of Articles 7–9, 11 and 12 are penalised under the CSL, DSL and PIPL, enforced by public security and cyberspace authorities; criminal liability where applicable; official dereliction addressed separately
15Scope of eligible identity documents — PRC resident identity card, passports for Chinese citizens abroad, Hong Kong/Macao and Taiwan travel permits and residence permits, and foreign permanent residence identity cards
16Effective 15 July 2025

The three provisions that bind platforms

Article 7 — no double collection, and no penalty for declining. Where a user has been authenticated through the network number or network credential, the platform must not require the user to provide plaintext identity information separately (不得要求用户另行提供明文身份信息), except where a law provides otherwise or the user consents. Equally, a platform must not degrade service for users who choose not to use the scheme. Both halves matter: the first caps what an integrating platform may collect, the second stops the scheme from becoming compulsory through commercial pressure.

Article 8 — verification result, not the document. Where a platform does not need to retain identity-document information, it receives only the result of the check. Where document information genuinely is required, only the minimum necessary is passed, following the user’s authorisation, and the platform may not process it beyond that purpose or disclose it onward absent a legal requirement.

Article 12 — localisation. Important data and personal information processed by the public-service platform must be stored within China (应当在境内存储), with a security assessment required before any outbound transfer.

Why it matters

Article 7 is the provision to watch. Chinese law requires real-name verification across a wide range of services, and the conventional way to satisfy it — every platform collecting and retaining identity-document data — produces exactly the concentration of identity records that the criminal cases in DCC’s coverage keep drawing on. The MPS’s own batch of ten typical personal-information crime cases leads with two rings whose entire business was harvesting and reselling real-name online accounts; that market exists only because platforms hold the underlying identity data. A state authentication layer is the structural answer to that specific failure mode, and the pairing of enforcement releases with promotion of the platform is deliberate.

For overseas-invested platforms the open questions are practical rather than doctrinal: whether integration will remain genuinely voluntary as Article 6 promises, how Article 7’s bar on separate plaintext collection interacts with KYC and anti-fraud duties under the Anti-Telecom and Online Fraud Law, and what the age-bracket disclosure in Article 10 means for minors-protection compliance under the Minors Online Protection Regulations.


Source: 国家网络身份认证公共服务管理办法, 公安部令第173号, published by the Cyberspace Administration of China, 23 May 2025. Original. Summarised and annotated by DCC.

§ RELATED LAWS

See also.

§ COMMENTARY

Briefs on this law.

1 brief references this law.

  • § 01 · ENFORCEMENT

    公安部网安局 Publishes 10 Typical Cases of Infringing Citizens' Personal Information — Insiders, Order Decryption, and Article 253a in Practice

    On 11 August 2026 the MPS Cyber Security Bureau (公安部网安局) published ten typical cases (典型案例) of the crime of infringing upon citizens' personal information, brought under the Clean Net special campaign (净网专项行动). Across the batch: 123 suspects, more than 9.6 million items of personal information, and roughly 23.6 million yuan in case value. The striking feature is not the volume but the access route — in at least half the cases the data came out through someone with legitimate access: an employee, a planted hire, a service vendor, a hotel partner, or a school and hospital staffer. This DCC brief translates all ten fact patterns, sets them against Criminal Law Article 253a and the 2017 PI Criminal Interpretation thresholds, and draws out what the batch signals for companies whose exposure runs through their own staff and vendors.

    enforcement · criminal-liability · mps
§ SUBSCRIBE

The Monday brief.

One short email every Monday. New briefs on Chinese data-compliance rules from the previous week, with the source law cited.

Opt-in only. Unsubscribe anytime by replying "unsubscribe" to any issue.

SUPPORT DCC

Keep the publication free to read. Suggested support is $19.99, or choose your own amount.

Support →