Every brief.
The full run, most recent first.
- § 13 · PERSONAL-INFORMATION
China Writes PIPL a Small-Business Exit Ramp: The Simplified Measures for Small Personal Information Handlers
On 22 July 2026 the CAC and the Ministry of Public Security jointly issued Order No. 25, the Provisions on Simplified Personal Information Protection Measures for Small Personal Information Handlers, effective 1 September 2026. It is the first instrument to make PIPL's obligations formally proportionate: a handler processing the personal information of fewer than 100,000 people gets a three-item processing-rules template it can satisfy with a posted notice, notice discharged through those published rules alone, consent inferred from voluntary provision of necessary information, compliance audit cut to once every five years — or waived entirely if certified — and a one-page impact assessment. Article 8 lets a handler operating solely through a network platform drop its own rules, notice, audit and assessment altogether, riding on the platform's. Article 10 extends the cross-border exemption architecture to small handlers, with important data carved out. Articles 18 and 19 make no-penalty and mitigated-penalty outcomes mandatory rather than discretionary. DCC reads it for overseas counsel whose Chinese counterparties, franchisees, merchants and portfolio companies sit under the 100,000-person line — and explains why the threshold, not the relief, is the thing to watch.
- § 14 · DATA-ASSETS
Two Registrations, One Word: China's New Data-Asset Standards and the Line Between 登记 and 登记
On 2 July 2026 China issued two national standards for data as an asset — GB/T 47949-2026 (classification and codes) and GB/T 47950-2026 (registration guidance) — both effective 1 September 2026. They give data assets a fixed place in the asset-classification code system (block A0806020000, including a first-ever asset code for AI-training multimodal data measured in tokens) and a step-by-step model for putting data on an organization's own books. The trap for overseas counsel is the word 登记 (registration): these MOF/SAC standards register data as an asset internally, while the National Data Administration's Data Property Rights Registration Work Guide (Trial), finalized 1 July 2026, registers rights in data externally through a certificated institution. Same word, two regimes, two artifacts, two purposes. This DCC brief separates them, reads the two standards for what they require, and explains why the 入表 (balance-sheet entry) vs 确权 (rights confirmation) distinction keeps tripping up data-asset deals.
- § 15 · GENERATIVE-AI
Which of the Ten Duties Actually Bites: Cheng Xiao on Fault and Statutory Duty for Generative-AI Providers
In a Political Science and Law Tribune article, Tsinghua professor Cheng Xiao (程啸) resets how Chinese courts should reason from a generative-AI provider's statutory duties to civil fault. His thesis: tort liability here is fault-based under Civil Code Art. 1165(1); 'duty of care' is not a separate element but the objective reasonable-person standard in AI dress. Crucially, not every breach of a statutory duty is fault. Negative duties (do not infringe) collapse into the 'infringement of rights' element and prove nothing about fault; only breach of an affirmative statutory duty can ground fault — and only where the duty aims to protect individuals, the plaintiff is within its protected class, and the harmed interest is within its protected scope. Applying that filter to the ten affirmative duties in the Generative AI Interim Measures, Cheng sorts them into result-based and method-based obligations, sets out five factors for judging the method-based ones, and criticizes two court rulings that grounded fault on a labeling or risk-warning duty in copyright cases the duty was never meant to protect against.
- § 16 · TRANSPORT
Five Grades of Data, One Reporting Spine: The Ministry of Transport's Data Security Measures
On June 18, 2026 the Ministry of Transport issued the Measures for Data Security Management in Transport (交科技规〔2026〕3号), effective July 1, 2026 — 41 articles that complete the sector build-out of the Data Security Law for highways, waterways and comprehensive transport. The full text reached the public record in July through an academic-society WeChat repost rather than the ministry's own site. DCC reads the Measures around four load-bearing features: a five-grade classification ladder that splits general data into Grades 3/2/1 and pulls Grade-3 general data into the hard transmission-protection net alongside important and core data; an annual risk-assessment duty that extends beyond important-data handlers to any processor holding personal information on 10 million or more people, dated the same day as the national Network Data Security Risk Assessment Measures but effective 50 days earlier; an AI clause requiring pre-deployment evaluation of corpora, training data and algorithm explainability, plus a default ban on training on entrusted data; and a single reporting spine that routes filings through provincial transport authorities to MOT, with a direct line for central transport SOEs. Storage follows the sector pattern: localization for transport-authority personal information and CIIO-collected data, MLPS Level 3 for important-data systems, Level 4 or CII protection for core data, and security-assessed cloud services only.
- § 17 · MINORS-PROTECTION
The School Is Not a Bystander: Three Model Cases on Schools' Duties in Minors' Online Protection
Minors' online protection is usually framed as a job for parents and platforms. Three model cases — a Guangzhou Internet Court judgment on defamation in a parent–school WeChat group, a Supreme People's Procuratorate case where procuratorial recommendations pushed a school to build bullying-control systems after a privacy video spread, and a Zhejiang case where a predator used an unauthorized school-named 'confession wall' account to reach students — show Chinese courts and procuratorates deliberately pulling schools into the frame. JunHe's education team distills the school's three statutory functions: internet-literacy education (Minors Protection Law Arts. 64 and 70, Online Protection Regulations Art. 16), cyberbullying prevention and response (Minors Protection Law Art. 39; School Protection Provisions Art. 21), and internet-addiction intervention (Minors Protection Law Art. 71; Regulations Art. 40). The liability stack for schools that do nothing: administrative correction orders and sanctions under Regulations Art. 51, plus civil supplementary liability under Civil Code Art. 1201. Four recommendations follow: documented literacy and AI-content-discrimination education, a staffed-up 'rule-of-law vice principal' mechanism, a full discover–stop–report–handle bullying protocol, and compliance with device-management and anti-addiction requirements. With 196 million minor netizens at 97.3% penetration, the authors argue schools are the 'main battlefield' whether they like it or not.
- § 18 · SECURITY-REVIEW
One Company, Four Reviews: JunHe Maps China's Security-Review 'Matrix' in the Security-First Era
With the Measures for Network Data Security Risk Assessment (Order No. 24) in place, China's security-review architecture has four operating pillars: foreign investment security review (NDRC + MOFCOM), cybersecurity review (CAC + 12 departments), data export security assessment (CAC), and the new normalized network data security risk assessment (CAC coordination + sectoral authorities). JunHe lawyer Chen Sijia walks each regime through the same five questions — who reviews, what is reviewed, when review is triggered, and with what legal consequences — and lands on two points overseas counsel should not miss. First, the four regimes differ in kind: the first three are ex-ante, admission-style reviews with veto power, while the risk assessment is an annual, improvement-oriented 'physical exam.' Second, review decisions are effectively final — the mainstream view treats them as final administrative acts with no administrative reconsideration or litigation available — so cooperation during the review is the only real strategy. A closing lifecycle walkthrough shows how a single AI-model company can trip all four lines in sequence: FDI review at fundraising, cybersecurity review at GPU procurement, export assessment at model training, cybersecurity review again at foreign listing, and the annual risk assessment as a standing duty.