Every brief.
The full run, most recent first.
- § 31 · IMPORTANT-DATA
Are You Caught by the Annual Assessment? TRIMPS's Self-Identification Guide for 'Important-Data Handlers'
With the Network Data Security Risk Assessment Measures (Order No. 24) taking effect August 20, 2026, the annual risk-assessment duty stops being a principle and becomes a hard calendar event — but only for 'important-data handlers' (重要数据处理者). DCC's summary of a self-identification guide from the Data Security R&D Center of the Ministry of Public Security's Third Research Institute (公安部三所 / TRIMPS), author Lü Mingxuan, walks the threshold test the institution that helps draft the standards wants processors to run before the clock starts. There are three independent gates, any one of which puts you in: (1) you process data meeting the 'important data' definition under Article 62 of the Network Data Security Management Regulation; (2) the deeming rule — you process the personal information of more than 10 million people, which pulls you into the important-data duties of Regulation Arts. 30 and 32 regardless of whether you hold any 'important data'; or (3) your data sits on a regional, departmental, or sectoral important-data catalogue. Entrusted processors inherit the duty from an important-data-handler client; CIIO status and important-data-handler status are separate, intersecting tests; and identifying important data runs through GB/T 43697-2024 Appendix G's 18 factors plus the applicable catalogues. The guide then lays out the operating requirements once you are in: annual mandatory assessment plus trigger-based instant assessments, a stacked PIPIA for the 10-million-PI cohort, three-year report retention, and submission within 20 working days. DCC's read for overseas counsel: classification is the gate, the 10-million-PI deeming rule is the trap for consumer businesses with no 'important data' at all, and the self-ID needs to happen now.
- § 32 · DATA-ECONOMY
Li Yang: Why 'Data Rights-Confirmation' Is a Category Error — Dynamic Data Can't Be a Registration Object, and AUCL Article 13 Is the Better Path
DCC's summary of an opinion piece by Li Yang (李扬), professor at China University of Political Science and Law, arguing that the whole project of 'data rights-confirmation' (数据确权) — and the data-IP registration pilots run under it — rests on a category error. In Chinese IP law, 'confirmation' (确权) is the authoritative validation of an already-existing right, and it presupposes three things data lacks: a determinate object, defined rights content, and clear boundaries. Civil Code Art. 127 only defers the question; 'data IP' is a policy concept, not a legal one; and data is co-produced by many parties, so registration proves who submitted data, not who owns it. Li Yang's sharpest move is the dynamic-object problem: registration regimes (real estate, IP, equity) require a persistently stable object, but data's value lives in continuous updating, so the data at registration is never the data in dispute — and blockchain/hash/timestamp '存证' only fix a historical snapshot, never the living data stream, confusing proof-of-existence with object-identification. He concludes that registration's real functions are evidentiary and publicity/transaction-support — not rights-confirmation — and that data governance should move from rights-confirmation to interest-protection, from static-rights thinking to dynamic-competition thinking, protecting commercial-data interests under Article 13 of the Anti-Unfair Competition Law. DCC's read for overseas counsel, against the data-IP registration regime and the Beijing Internet Court's first AUCL Article 13 ruling.
- § 33 · ANTI-UNFAIR-COMPETITION
How the Beijing Internet Court Found a Platform 'Lawfully Held' Its Data Under the New AUCL Article 13 — and Where It Meets the 'Right to Hold Data'
The Beijing Internet Court's 30 April 2026 judgment — the first published application of the data clause (Article 13) of the 2025-revised Anti-Unfair Competition Law, effective 15 October 2025 — turns on one threshold question: did the plaintiff platform 'lawfully hold' (合法持有) the scraped career data? DCC walks through exactly how the court got to 'yes', step by step: the data originated as personal information collected with user consent under the platform's Service Agreement and Privacy Policy (no unlawful processing on record); the operator's build-and-run investment aggregated scattered records into a dataset with standalone economic value; and that dataset is the foundational input for the platform's matching business and competitive advantage. From those three findings the court derives its operative definition — data lawfully collected/stored/used, formed through substantial investment, and capable of generating business benefit or competitive advantage — and holds that the defendant's crawler-and-resale scheme, circumventing login and access controls, was unfair competition (¥200,000 + ¥30,000-plus in costs). The brief then takes up the doctrinal question: does Article 13's 'lawfully held data' correspond to the 'right to hold data' (数据持有权) in the Data 20 Articles' three-rights framework? The answer is a functional yes — the court is enforcing the holding right's purely defensive content, exactly as Hong Yanqing's analysis predicted AUCL Article 13 would — but not a doctrinal one: it builds a competition-tort interest on investment and lawful sourcing, deliberately sidestepping any claim that data is a typed property right. DCC's case brief for overseas counsel, drawn against the earlier AUCL Article 2 general-clause data cases.
- § 34 · GBT-35273
From Consent to Governance: What the 2026 Draft Revision of GB/T 35273 Changes Against the 2020 Standard
On June 17, 2026 the National Cybersecurity Standardization Technical Committee (TC260), with CESI as drafting lead, released for public comment a systematic revision of GB/T 35273 — China's most-cited personal-information standard, the de-facto 'small PIPL.' The draft retitles the standard from 'Information Security Technology' to 'Data Security Technology' and expands its normative references from one standard to eight. DCC reads the revision as a role change, not a clause count: the standard moves from a consent-and-notice manual into a governance-capability framework. The substantive increments against GB/T 35273-2020: a new Chapter 5 importing PIPL Article 13's seven lawful bases as a standalone chapter with hard boundaries on each (contract-necessity, HR, public-disclosure) plus an evidence-chain duty; a sensitive-PI redefinition aligned to PIPL Article 28 with a new aggregation rule (multiple items that together meet the threshold are treated as sensitive as a whole); a formal 'separate consent' definition (3.7) with a negative list; a new eighth basic principle, 'quality assurance' (Chapter 4(f)); dedicated AI clauses on the collection side (6.7), in minimum-necessity (6.1 d–f), in aggregation/training (8.4), and a new generative-AI use clause (8.5.4) with output review and a 15-working-day deletion SLA; a unified-account-system clause (8.6) aimed at one-account-many-products groups; a terminal/IoT collection clause (6.8); a wholly new Chapter 11 on overseas-jurisdiction determination and conflict handling; and a systematized internal-control chapter (13) covering the person in charge of personal information protection, working body, processing-activity records, impact assessment, and a GB/T 46903-anchored compliance audit. Subject-rights response time tightens from 30 days to 15 working days. Clause numbers are from the comment draft and are not final; formal release is expected after 2027.
- § 35 · RISK-ASSESSMENT
From Principle to Running System: How the Network Data Security Risk Assessment Measures Operationalize the Data Security Law
On June 18, 2026 the CAC, MIIT and the Ministry of Public Security jointly issued the Measures for Network Data Security Risk Assessment as Order No. 24, effective August 20, 2026. The 25-article rule adds no new substantive duty; it turns the Data Security Law's open-ended 'conduct risk assessment' obligation into an executable, verifiable, trigger-able governance system. DCC reads it as a three-tier standing model plus an event-driven escalation layer: important-data handlers must assess every year (general-data handlers are encouraged to every three), retain the report for three years and submit it within 20 working days; sectoral competent authorities run annual inspection plans filed by end-January; the national cyberspace administration consolidates and cross-shares reports with telecom, public-security and state-security departments; and where a high-risk finding or a breach of important data or large-scale personal information appears, regulators can compel assessment by a certified institution and order the operator to cease processing important data. The four institutional increments over the DSL: an annual mandatory action, networked multi-department supervision, a three-track assessment structure, and dynamic event-triggered oversight.
- § 36 · PUBLIC-DATA
Guangdong Prices the Public-Data Operator Like a Utility: Inside the Province's Authorized-Operation Price-Management Measures
On 12 May 2026 the Guangdong DRC and the Guangdong Administration of Government Services and Data issued the Guangdong Province Public Data Resource Authorized-Operation Price Management Measures — one of the first provincial implementations of the national NDRC/NDA price-formation notice (发改价格〔2025〕65号). The 20-article rule prices the 'public-data operation service fee' (公共数据运营服务费) with a regulated-utility toolkit: government-guided pricing, a maximum permitted revenue equal to operating cost + permitted profit + tax, and a permitted profit rate capped at the prior-year 10-year treasury yield plus no more than 6 percentage points. DCC reads the full text (carried by 数据行者X) against the Guangdong DRC's official interpretation (carried by 砖济咨询) to draw out what overseas counsel needs: this is cost-of-service, rate-of-return regulation imported into the data-element market, with periodic resets every three years, a ±10% annual adjustment band, mandatory cost separation, and a carve-out keeping public-governance and public-welfare data 'conditionally free.'