Skip to content
DCC · DATA COMPLIANCE CHINA China data law, for overseas counsel.
§ BRIEFINGS · PAGE 01

Every brief.

The full run, most recent first.

  • § 01 · COMPUTE-CENTERS

    One Machine Room, Five Regulatory Identities: MaaS Compliance for China's AI Compute Centers

    AnJie Broad partners Cai Hang and Yao Ting and associate Liu Zeqiang argue that the IDC-era compliance checklist no longer fits the AI compute center. Their thesis: one machine room now carries five regulatory identities at once — domestic IDC operator, cross-border AI service provider, service exporter under the Export Control Law, supplier of self-deployed model capability, and responsible entity for the agents it ships — each with its own logic, and each transmitting obligations to the others. The brief works through value-added telecom licensing (B11/B12), energy-conservation review and PUE caps, the continuing duties under the Regulation on Network Data Security Management (State Council Decree No. 790), the token-export exemptions in CAC Decree No. 16 and what they do not exempt, the territorial limits of the GenAI Interim Measures, the Export Control Law catch-all, the unsettled line between large-model filing (备案) and large-model registration (登记), open-weight license trigger clauses, and the criminal exposure that follows an agent's tool calls under Criminal Law Article 285.

    compute-centers · intelligent-computing-center · maas
  • § 02 · ENFORCEMENT

    公安部网安局 Publishes 10 Typical Cases of Infringing Citizens' Personal Information — Insiders, Order Decryption, and Article 253a in Practice

    On 11 August 2026 the MPS Cyber Security Bureau (公安部网安局) published ten typical cases (典型案例) of the crime of infringing upon citizens' personal information, brought under the Clean Net special campaign (净网专项行动). Across the batch: 123 suspects, more than 9.6 million items of personal information, and roughly 23.6 million yuan in case value. The striking feature is not the volume but the access route — in at least half the cases the data came out through someone with legitimate access: an employee, a planted hire, a service vendor, a hotel partner, or a school and hospital staffer. This DCC brief translates all ten fact patterns, sets them against Criminal Law Article 253a and the 2017 PI Criminal Interpretation thresholds, and draws out what the batch signals for companies whose exposure runs through their own staff and vendors.

    enforcement · criminal-liability · mps
  • § 03 · PERSONAL-INFORMATION

    China Finishes the Other End of PIPL: The Draft Provisions for Large Personal Information Handlers, Read Against Order No. 25

    On 7 August 2026 the CAC published the Provisions on Personal Information Protection for Large Personal Information Handlers (Draft for Comment), consolidating its September 2025 supervision-committee draft and its November 2025 large-network-platform draft into one 50-article instrument, with comments due 7 September 2026. DCC has translated the full text and reads it against CAC/MPS Order No. 25, the small-handler regime published sixteen days earlier — because the pair is the story. Three shifts matter most. The subject changes from 'large network platform' to 'large personal information handler,' and the old registered-user and monthly-active-user tests give way to a three-factor test starting at 10 million data subjects, which reaches banks, insurers, carriers, hospitals and automakers that never thought of themselves as platforms. Designation is declared rather than automatic: a qualifying handler must self-declare through its provincial CAC and the national CAC publishes a public list, which puts the burden of self-identification on the company. And the obligations that follow are structural rather than procedural — absolute domestic storage under Article 13, a nationality requirement for data center controllers under Article 14, a protection officer drawn from management with a direct reporting line to the provincial CAC, and a supervision committee that is not a committee of the board. DCC sets out the full comparison table, the designation trap, and what the newly visible middle band means for foreign-invested subsidiaries.

    personal-information · pipl · large-platforms
  • § 04 · METEOROLOGICAL-DATA

    The CMA Keeps the Keys: China's First Sectoral Rules for Public Meteorological Data Authorized Operation

    In March 2026 the Office of the China Meteorological Administration issued the Measures for the Administration of the Authorized Operation of Public Meteorological Data (Trial) — 公共气象数据授权运营管理办法(试行), Qi Ban Fa [2026] No. 23 — the first complete sector-specific implementation of the NDRC/NDA authorized-operation framework inside a national vertical system that DCC has recorded. DCC has translated the full 39-article text. The design departs from the national baseline in one consistent direction: control. Operating terms are capped at three years against the national five; operating institutions pass a provincial review, a CMA maturity assessment and the CMA's own 'three majors and one large' deliberation before they may even bid; downstream developers become a third catalogued and supervised tier; nobody but an implementing institution may sub-authorize data, even disguised as cooperative development; and no product trades without a CMA-issued meteorological-data identity tag registered on the CMA's circulation supervision platform. Read against the National Data Administration's Data Property Rights Registration Work Guide — whose public-data clause lets products formed through authorized operation take property-rights registration and circulate as certificated market assets — the meteorological version keeps the development right inside the system: what a market entity gets is a term-limited, contract-based service role inside CMA infrastructure, not a registrable right over what it builds.

    meteorological-data · public-data · authorized-operation
  • § 05 · TRADE-SECRETS

    When You Cannot Compare the Code: The SPC's RMB 166 Million Centrifuge Case and How to Prove Data Misappropriation Without the Defendant's Data

    AnJie Broad partner Li Yanying reads (2022)最高法知民终1592号, the 'centrifuge case' — selected as one of the SPC's 2025 typical anti-unfair-competition cases on 8 September 2025 — for what it teaches about the burden of proof when the misappropriated asset is data. The plaintiffs never obtained the defendants' software or dataset, never decompiled anything, and never ran a substantial-similarity comparison. Instead they exploited the input-output character of software: enter the claimed impeller basic-stage data into their own program along with performance figures taken from the defendants' published product literature, and the output matched. Under AUCL Article 39(2)(i) that was enough to shift the burden, and the defendants' refusal to permit on-site inspection or produce design files converted into an adverse inference. DCC adds the correction the commentary omits: the SPC did not protect the software as a trade secret at all — the plaintiffs failed to delimit its secret points, so it was rejected on the not-generally-known element, and only the dataset was protected. The software was the measuring instrument, not the asset. For overseas counsel holding datasets in China, this is the enforcement route that actually carries damages, and the case is a lesson in how to delimit a claim before you file.

    trade-secrets · technical-secret · burden-of-proof
  • § 06 · AI-AGENTS

    Tokens Meter Input, Not Value: Hong Yanqing on Beijing's Agent Measures (Part 4 of 4)

    Part 4, closing Hong Yanqing's commentary on the Several Measures of Beijing Municipality on Accelerating Agent-Led Development (北京市关于加快智能体引领发展的若干措施, 京发改〔2026〕1185号). The Measures' Article 6 proposes a Token (词元) economy — Token-as-a-Service, Agent-as-a-Service, Results-as-a-Service, and a shift from billing by Token consumption to value-based billing; Article 8 funds 'Token factories' and Token vouchers. Hong draws the line the policy still needs: Tokens measure the consumption of intelligent means of production, not the value of intelligent products. Tokenization differs across models; a task's full cost includes tool calls, memory storage, human review, and failed retries; and Token volume has no fixed ratio to task value — so treating Token throughput as industrial performance rewards long contexts, loops, and retries. His alternative is a five-layer evidence chain (resource input → system capability → valid task results → process results → enterprise and social value), a cost-per-valid-completed-task formula that counts review, retries, and expected risk losses, and an attribution discipline of pre-launch baselines and phased pilots. Outcome billing must be corrected for quality and risk — narrow metrics make customer-service agents rush calls and procurement agents chase price cuts, and vendors can cream-skim easy tasks while humans absorb the hard residue — so projects with unstable task boundaries should blend base, resource, and performance fees rather than jump to pure Results-as-a-Service. Different policy objects need different-layer metrics, mapped onto Part 3's five maturity levels, and fiscal support should pass staged evidence gates: prototypes may fail, pilots must beat baselines in real business, demonstrations must replicate at acceptable cost, and commercial-stage projects must survive subsidy taper — with prompt exit for projects that stop producing new evidence.

    ai-agents · beijing · token-economy
§ SUBSCRIBE

The Monday brief.

One short email every Monday. New briefs on Chinese data-compliance rules from the previous week, with the source law cited.

Opt-in only. Unsubscribe anytime by replying "unsubscribe" to any issue.

SUPPORT DCC

Keep the publication free to read. Suggested support is $19.99, or choose your own amount.

Support →