---
title: "CAC's 15 September 2026 Enforcement Typical Cases (执法典型案例) — Ten Cases, and the Four That Change How You Test"
author: "DCC Editorial"
published: 2026-09-16T10:00:00.000Z
url: https://datacompliancechina.com/posts/cac-enforcement-cases-september-2026/
description: "On 15 September 2026 the Cyberspace Administration of China (国家网信办) published ten enforcement typical cases (执法典型案例) across cybersecurity, data security and personal information protection. Six are the familiar perimeter failures — weak passwords, unpatched vulnerabilities, unauthorized-access holes, an app forcing unnecessary permissions. Four are new, and they are the ones that should change how compliance teams test: a Chongqing property company fined for running facial recognition on 5,000+ customers for marketing without separate consent, apparently the first public penalty to turn directly on PIPL Article 26; a Shanghai company fined for exporting personal information through a Windows desktop client with no data-export security assessment; a Sichuan company's WeChat mini-program ordered offline for failing to add explicit and implicit labels to AI-generated content; and a Jiangsu company warned for running two websites as an \"API relay station\" (API中转站) over third-party LLM APIs without a security assessment. DCC tables all ten from the CAC notice and reads the four against PIPL, the Cross-Border Data Flows Provisions, the AI Content Labeling Measures and the 2018 Security Assessment Provisions."
tags: ["enforcement", "cac", "typical-cases", "facial-recognition", "pipl-article-26", "cross-border-data", "ai-labeling", "security-assessment", "mini-program", "api-relay-station"]
laws_cited: ["pipl", "csl", "dsl", "network-data-security-regulations", "cross-border-data-flows-provisions", "deep-synthesis-provisions", "ai-content-labeling-measures", "genai-services-interim-measures", "public-opinion-security-assessment-provisions"]
domains: ["enforcement", "personal-information", "ai-governance", "cross-border"]
account: "data-he-gui"
original_title: "网信办执法通报值得关注的信息"
original_author: "数据何规"
original_publication: "数据何规 WeChat Official Account"
original_url: "https://mp.weixin.qq.com/s/hq1JCSHLJJVZVtgQ-_vVSA"
source_language: "zh"
---

> **Source: Data Compliance China** — https://datacompliancechina.com/posts/cac-enforcement-cases-september-2026/ · China data law, translated and annotated for overseas counsel. Cite as: Data Compliance China, "CAC's 15 September 2026 Enforcement Typical Cases (执法典型案例) — Ten Cases, and the Four That Change How You Test", https://datacompliancechina.com/posts/cac-enforcement-cases-september-2026/
> *Editor's Note — DCC.*
>
> CAC enforcement batches usually reward a quick skim and no more. Weak
> passwords, unpatched vulnerabilities, an unencrypted transmission — the
> categories repeat year to year, and a foreign compliance team can read the
> list, confirm its own scanning programme covers the same ground, and move
> on. Six of the ten cases in the 15 September 2026 batch are exactly that.
>
> Four are not. Taken together they show CAC's testing tier reaching past the
> policy layer and into specific product decisions: what the cameras in your
> lobby are actually *used for*, what your **Windows desktop client** uploads
> and where it lands, whether an AI label survives a user pressing *export*,
> and whether calling somebody else's model API makes you the regulated
> provider. None of these is visible in a privacy policy review. All four
> require someone to open the product and look.
>
> This brief tables all ten cases from the CAC notice, then reads the four in
> detail. The selection of those four — and the framing of why they matter to
> operating companies — follows the analysis published by
> **数据何规**; the case facts are as stated in the CAC notice.

## What CAC published

On **15 September 2026** the Cyberspace Administration of China (国家网信办)
released a batch of **ten enforcement typical cases** (执法典型案例) in the
areas of cybersecurity, data security and personal information protection —
[the notice is published on CAC's own 网信中国
channel](https://mp.weixin.qq.com/s/S-f_K96o3axIYZtxT5sAdQ). The cases were
brought by cyberspace administration departments nationwide under the
[Cybersecurity Law](/laws/csl/), the [Data Security Law](/laws/dsl/), the
[Personal Information Protection Law](/laws/pipl/) and the [Network Data
Security Management Regulations](/laws/network-data-security-regulations/).

CAC's own framing lists the conduct categories covered: webpage tampering,
planting malicious programs, data leaks, personal information leaks, unlawful
collection and use of personal information, unlawful export of personal
information, failure to implement AI-generated content labeling requirements,
and launching new technologies and new applications without the required
assessment.

This is now a recognisable annual fixture: CAC ran a comparable mid-September
batch in 2025, under nearly the same title. The value of the series is not the
penalties, which are mostly unquantified in the public text — and which, as
[DCC's read of 392 published penalty
decisions](/posts/dsl-27-45-pipl-51-66-392-penalty-decisions-2024-2026/) found,
land on a warning far more often than a fine — but the **categories**: the batch
is the clearest public statement of what CAC's own testing tier is currently
looking for.

## The ten cases

| # | Respondent | What happened | Cited instruments | Outcome |
|---|---|---|---|---|
| 1 | Shanghai electronics co. | A weak password on the portal website's back-end administrator account was left in place from 2020 onward, and brute-force attempts against the system went undetected. In April 2026 the site's source files were injected with malicious code and search results surfaced large volumes of seriously unlawful and harmful information. The company did not activate its emergency plan, take remedial measures, or report to the competent department. | CSL | Ordered to rectify; fine |
| 2 | Beijing network technology co. | An employee (surnamed Liu) who had worked on an "assistant" application (≈350,000 users), aggrieved over the renewal of his labour contract, implanted a malicious program before leaving in order to collect promotion fees. Installed users found the browser homepage, search and bookmarks redirecting to promotion links. The company was lax in managing both the application and its staff. | CSL | Ordered to rectify; fine; the employee referred to public security organs on suspicion of criminal conduct |
| 3 | Anhui data industry co. | A "digital archive management system" was built on an open-source Elasticsearch version carrying an unauthorized-access vulnerability, and test data was not deleted once development testing finished. 2,400+ internal files — audit reports, contracts and meeting minutes — were stolen, including MLPS assessment reports and project-approval and budget-estimate documents. | CSL · DSL · Network Data Security Regulations | Ordered to rectify; warning; fine on the company and on the directly responsible person in charge |
| 4 | Henan hospital | A weak-password vulnerability in the physical-examination system allowed medical records to be retrieved. After the local CAC office ordered a full rectification, re-inspection found the firewall, intrusion-prevention system, vulnerability scanner, log audit system, database audit system and bastion host had **all** lapsed on expired licences, and terminals still carried 700 vulnerabilities, including 73 exploitable high-risk ones — the leak risk had not been eliminated. | CSL · DSL · Network Data Security Regulations | Ordered to rectify; warning; fine on the company and the responsible person; referred to the health authority |
| 5 | Guangdong software technology co. | A "box" hardware product had an unauthorized-access vulnerability: a console on port 4000 could be reached without login authentication to view vehicle status information. Personal information was transmitted without encryption when users bound the product to a WeChat official account. | CSL · PIPL · Network Data Security Regulations | Ordered to rectify; warning |
| 6 | Zhejiang information technology co. | A sports-management App required users to grant location, phone and storage permissions in a single bundle when starting the running function, justified as "preventing cheating"; a user who refused could not use the function. No differentiated option was offered for different usage scenarios, and other means of achieving the processing purpose were available — collection and use of unnecessary personal information beyond the proper scope. | PIPL · Network Data Security Regulations | Ordered to rectify; warning |
| **7** | **Chongqing property company** | **10+ image-collection devices installed on office premises; 5,000+ items of customer facial information collected and stored, used for customer identity recognition and for matching-based marketing with intermediary agencies. Customers were not told truthfully, accurately and completely of the purpose, method and use, and no separate consent was obtained.** | **PIPL · Network Data Security Regulations** | **Ordered to rectify; warning; fine** |
| **8** | **Shanghai technology co.** | **Since 2022, its Windows desktop application collected — beyond the necessary scope — users' host configuration, usage duration and operating-system information, and transmitted that, together with the name, mobile number, email, date of birth and password entered at registration, to data centres outside China. No data-export security assessment had been declared.** | **PIPL · Cross-Border Data Flows Provisions** | **Ordered to rectify; fine** |
| **9** | **Sichuan technology co.** | **Its WeChat mini-program offered AI text chat and image generation but added no explicit label to AI-generated and synthetic content, no implicit label in file metadata (attribute information, service provider name or code, content number), and no explicit label on exported content; it had also not carried out the required security assessment.** | **Deep Synthesis Provisions · AI Content Labeling Measures · Security Assessment Provisions** | **Mini-program ordered offline** |
| **10** | **Jiangsu technology co. ltd.** | **Two websites operated as an "API relay station" (API中转站), calling the interfaces of multiple large-model products to provide chat and Q&A services, without carrying out the required security assessment — presenting content-security risk.** | **GenAI Interim Measures · Security Assessment Provisions** | **Ordered to rectify; responsible persons dealt with strictly; warning** |

The bolded four are the subject of the rest of this brief.

## 1. Facial recognition used for marketing — PIPL Article 26 arrives in practice

**Case 7.** A Chongqing property company installed more than ten image-collection
devices around its office premises and built up over 5,000 items of customer
facial information. The purpose was not security. It was **customer identity
recognition and matching-based marketing** with intermediary agencies — in
plain terms, working out which broker a walk-in visitor belonged to, and
attributing the commission accordingly.

CAC found the company had not informed customers truthfully, accurately and
completely of the purpose, method and use of the collection, and had collected,
stored and used facial information **without separate consent** (单独同意). The
local cyberspace office ordered rectification and imposed a warning and a fine.

**Why it matters.** [PIPL Article 26](/laws/pipl/) is short and has been
under-enforced:

> Image capturing and personal identification equipment installed in public
> places shall be necessary for maintaining public security, comply with the
> relevant provisions of the State, and conspicuous prompting signs shall be
> set up. An individual's personal image and personal identification
> information collected may only be used for the purpose of maintaining public
> security and shall not be used for any other purpose, except with the
> individual's separate consent.

The structure is a default plus an exception: public-place cameras are for
**public security**, full stop — unless the individual has given **separate
consent** to something else. The original commentary describes this as the
first publicly reported penalty it has seen turning directly on Article 26,
and that reading looks right: earlier facial-recognition enforcement has
generally run through the sensitive-personal-information consent rules or
consumer-protection law rather than Article 26's purpose limitation.

The operational point is the one companies tend to miss. The lobby camera is
usually installed lawfully, for security. The violation happens later, when
somebody notices the footage could also power attribution analytics, and the
**purpose changes without the consent basis changing with it**. Real estate,
retail and luxury are the obvious exposures: any deployment where facial
recognition drives customer identification, channel attribution or marketing
analytics needs to be re-papered against Article 26, not against general
consent language.

For how the "necessary for maintaining public security" limb is meant to be
operationalized, see [Hong Yanqing's four-element necessity
framework](/posts/public-place-frt-necessity-framework/); for the filing
threshold and the seven specific duties that attach once facial recognition is
in production, see [the FRT Application
Measures](/posts/compliance-talker-frt-application-measures-impact/).

## 2. Cross-border enforcement is not confined to apps and mini-programs

**Case 8.** A Shanghai technology company had, since 2022, used its **Windows
desktop application** to collect host configuration, usage duration and
operating-system information from users of its hardware products — beyond the
minimum scope necessary to achieve the processing purpose — and transmitted
that information, together with the name, mobile number, email address, date of
birth and password supplied at registration, to data centres outside China. It
had not declared a **data-export security assessment**. Ordered to rectify;
fined.

**Why it matters.** Two things, neither of which is about the size of the fine.

**The regulated surface is wider than the app store.** Almost every
cross-border enforcement action discussed in the China market to date has
involved a mobile app or a mini-program, and testing programmes have followed
that shape. This case is a **PC client**. Desktop software, installer-bundled
telemetry agents and hardware companion applications sit inside the same
personal-information perimeter, and a compliance programme scoped to "our apps"
will not see them.

**Device and usage telemetry counts.** Host configuration, session duration and
OS version are exactly the fields engineering teams classify as product
analytics rather than personal information. Bundled with a registered identity
and shipped to an overseas data centre, CAC treated them as personal
information collected beyond the necessary scope and exported without the
required assessment. If your architecture includes overseas data centres,
offshore log shipping or client-side telemetry, the inventory cannot stop at
name and phone number.

Read alongside [Ctrip's ¥10 million cross-border
fine](/posts/ctrip-cross-border-data-fine-necessity-doctrine/) — the first
publicly quantified cross-border penalty — the direction is consistent: the
[Cross-Border Data Flows Provisions](/laws/cross-border-data-flows-provisions/)
relaxed the *thresholds* for routine export, and enforcement has concentrated
on **necessity** and on transfers that never went through any mechanism at all.

## 3. AI labeling failures can cost you the product, not a fine

**Case 9.** A Sichuan technology company ran a WeChat mini-program offering AI
text chat and image generation. CAC found it had added:

- **no explicit label** (显式标识) to AI-generated and synthetic content;
- **no implicit label** (隐式标识) in file metadata — the production-element
  information comprising attribute information, the service provider's name or
  code, and the content number;
- **no explicit label on exported content**, where an export function was
  offered;

and had not implemented the required security assessment, presenting
content-security risk. The outcome was not a fine. The mini-program was
**ordered offline**.

**Why it matters.** The [AI Content Labeling
Measures](/laws/ai-content-labeling-measures/) took effect on 1 September 2025,
and this is labeling moving into real enforcement with a consequence that
skips straight past money to availability. Three specifics deserve attention:

1. **The implicit label is a real obligation, not a nice-to-have.** Article 4
   of the Measures requires metadata carrying attribute information, provider
   name or code, and content number. It is invisible in the UI, which means it
   is invisible to the kind of review that consists of opening the product and
   looking for the words "AI generated".
2. **Labels must survive export.** The Measures expressly extend to download,
   copy and export functions. A product that renders a watermark on screen but
   emits a clean file on export is non-compliant at precisely the moment the
   content leaves the platform.
3. **Labeling and security assessment travel together.** The case was charged
   under the [Deep Synthesis
   Provisions](/laws/deep-synthesis-provisions/) and the Labeling Measures
   *and* the [2018 Security Assessment
   Provisions](/laws/public-opinion-security-assessment-provisions/).

In short: AI labeling is not satisfied by something that *looks* present in the
product. It has to be implemented to the rule — in the metadata, and in the
file the user walks away with.

## 4. "We just call somebody else's API" is not a compliance position

**Case 10.** A Jiangsu technology company operated two websites as an **"API
relay station"** (API中转站), calling the interfaces of multiple large-model
products to provide chat and Q&A services to the public. It had not carried out
the required security assessment. CAC ordered rectification, directed that the
responsible persons be dealt with strictly, and issued a warning.

**Why it matters.** This is the case with the widest reach, because the
architecture is everywhere: relay stations, wrapper apps, model-aggregation
platforms, and the large population of products whose entire AI capability is a
call to somebody else's endpoint.

The assumption those products run on is that AI compliance duties belong to the
upstream model vendor — *we do not train anything, we just proxy*. Case 10 says
the question is not who trained the model but **who is providing a generative
AI service to the public**. If that is you, you re-run the analysis on your own
account.

Two honest qualifications, which the original commentary also draws:

- This does **not** mean every product calling a large-model API must complete a
  security assessment. The duty in [Article 17 of the GenAI Interim
  Measures](/laws/genai-services-interim-measures/) attaches to services with
  **public opinion attributes or social mobilization capacity**, and for some
  products large-model filing (大模型登记) is the applicable route instead.
- What the case does establish is narrower and still significant: **relaying an
  API does not, by itself, transfer the application-layer AI compliance
  obligations upstream.**

Both case 9 and case 10 were charged in part under the [2018 Provisions on the
Security Assessment of Internet Information Services with Public Opinion
Attributes or Social Mobilization
Capacity](/laws/public-opinion-security-assessment-provisions/) — an instrument
long treated as a content-governance formality. Neither the GenAI Measures nor
the Deep Synthesis Provisions contain their own assessment procedure; the
triggers, the report contents and the filing channel all live in the 2018 rule.
It is worth reading in full, particularly Article 7: where the trigger is a
launch or a new function, the report must be filed **before** the service goes
live.

## What the batch signals

**Enforcement has moved into the implementation layer.** The through-line
across all four cases is that none of them could be found by reading a
document. What the cameras are used for; what the desktop client uploads and
where it lands; whether the exported file carries a label; whether the thing
behind the chat box is a third party's API — these are questions answered by
opening the product, not by reviewing a privacy policy or a records-of-processing
register.

**The perimeter is wider than the app.** A Windows client, a WeChat
mini-program and two websites account for three of the four cases. Compliance
programmes scoped to mobile apps are scoped to the wrong surface.

**Purpose creep is the recurring failure mode.** Case 7 is lawful collection
turned to an unlawful use. Case 8 is telemetry legitimately collected for
product purposes, bundled with identity data and shipped offshore. In neither
case was the initial decision obviously wrong; in both, the purpose moved and
the legal basis did not move with it.

**Old instruments are being picked up for new products.** The 2018 Security
Assessment Provisions were written for forums and public accounts. In this
batch they were applied to an AI mini-program and to two LLM relay websites. A
rule that has been dormant in your jurisdictional map is not the same as a rule
that has been repealed.

---

**Sources.**

- **Primary.** Cyberspace Administration of China,
  *国家网信办发布近期网络安全、数据安全、个人信息保护等领域执法典型案例*,
  网信中国, 15 September 2026 —
  [original](https://mp.weixin.qq.com/s/S-f_K96o3axIYZtxT5sAdQ). All ten case
  descriptions, cited instruments and outcomes above are translated from this
  notice.
- **Commentary.** *网信办执法通报值得关注的信息*, 数据何规, 16 September 2026 —
  [original](https://mp.weixin.qq.com/s/hq1JCSHLJJVZVtgQ-_vVSA). The selection
  of cases 7–10 as the four most consequential for operating companies, and the
  framing of why, follow this piece.

Translations and all commentary are DCC's.

— Not legal advice.
