Editor’s Note — DCC.
CAC enforcement batches usually reward a quick skim and no more. Weak passwords, unpatched vulnerabilities, an unencrypted transmission — the categories repeat year to year, and a foreign compliance team can read the list, confirm its own scanning programme covers the same ground, and move on. Six of the ten cases in the 15 September 2026 batch are exactly that.
Four are not. Taken together they show CAC’s testing tier reaching past the policy layer and into specific product decisions: what the cameras in your lobby are actually used for, what your Windows desktop client uploads and where it lands, whether an AI label survives a user pressing export, and whether calling somebody else’s model API makes you the regulated provider. None of these is visible in a privacy policy review. All four require someone to open the product and look.
This brief tables all ten cases from the CAC notice, then reads the four in detail. The selection of those four — and the framing of why they matter to operating companies — follows the analysis published by 数据何规; the case facts are as stated in the CAC notice.
What CAC published
On 15 September 2026 the Cyberspace Administration of China (国家网信办) released a batch of ten enforcement typical cases (执法典型案例) in the areas of cybersecurity, data security and personal information protection — the notice is published on CAC’s own 网信中国 channel. The cases were brought by cyberspace administration departments nationwide under the Cybersecurity Law, the Data Security Law, the Personal Information Protection Law and the Network Data Security Management Regulations.
CAC’s own framing lists the conduct categories covered: webpage tampering, planting malicious programs, data leaks, personal information leaks, unlawful collection and use of personal information, unlawful export of personal information, failure to implement AI-generated content labeling requirements, and launching new technologies and new applications without the required assessment.
This is now a recognisable annual fixture: CAC ran a comparable mid-September batch in 2025, under nearly the same title. The value of the series is not the penalties, which are mostly unquantified in the public text — and which, as DCC’s read of 392 published penalty decisions found, land on a warning far more often than a fine — but the categories: the batch is the clearest public statement of what CAC’s own testing tier is currently looking for.
The ten cases
| # | Respondent | What happened | Cited instruments | Outcome |
|---|---|---|---|---|
| 1 | Shanghai electronics co. | A weak password on the portal website’s back-end administrator account was left in place from 2020 onward, and brute-force attempts against the system went undetected. In April 2026 the site’s source files were injected with malicious code and search results surfaced large volumes of seriously unlawful and harmful information. The company did not activate its emergency plan, take remedial measures, or report to the competent department. | CSL | Ordered to rectify; fine |
| 2 | Beijing network technology co. | An employee (surnamed Liu) who had worked on an “assistant” application (≈350,000 users), aggrieved over the renewal of his labour contract, implanted a malicious program before leaving in order to collect promotion fees. Installed users found the browser homepage, search and bookmarks redirecting to promotion links. The company was lax in managing both the application and its staff. | CSL | Ordered to rectify; fine; the employee referred to public security organs on suspicion of criminal conduct |
| 3 | Anhui data industry co. | A “digital archive management system” was built on an open-source Elasticsearch version carrying an unauthorized-access vulnerability, and test data was not deleted once development testing finished. 2,400+ internal files — audit reports, contracts and meeting minutes — were stolen, including MLPS assessment reports and project-approval and budget-estimate documents. | CSL · DSL · Network Data Security Regulations | Ordered to rectify; warning; fine on the company and on the directly responsible person in charge |
| 4 | Henan hospital | A weak-password vulnerability in the physical-examination system allowed medical records to be retrieved. After the local CAC office ordered a full rectification, re-inspection found the firewall, intrusion-prevention system, vulnerability scanner, log audit system, database audit system and bastion host had all lapsed on expired licences, and terminals still carried 700 vulnerabilities, including 73 exploitable high-risk ones — the leak risk had not been eliminated. | CSL · DSL · Network Data Security Regulations | Ordered to rectify; warning; fine on the company and the responsible person; referred to the health authority |
| 5 | Guangdong software technology co. | A “box” hardware product had an unauthorized-access vulnerability: a console on port 4000 could be reached without login authentication to view vehicle status information. Personal information was transmitted without encryption when users bound the product to a WeChat official account. | CSL · PIPL · Network Data Security Regulations | Ordered to rectify; warning |
| 6 | Zhejiang information technology co. | A sports-management App required users to grant location, phone and storage permissions in a single bundle when starting the running function, justified as “preventing cheating”; a user who refused could not use the function. No differentiated option was offered for different usage scenarios, and other means of achieving the processing purpose were available — collection and use of unnecessary personal information beyond the proper scope. | PIPL · Network Data Security Regulations | Ordered to rectify; warning |
| 7 | Chongqing property company | 10+ image-collection devices installed on office premises; 5,000+ items of customer facial information collected and stored, used for customer identity recognition and for matching-based marketing with intermediary agencies. Customers were not told truthfully, accurately and completely of the purpose, method and use, and no separate consent was obtained. | PIPL · Network Data Security Regulations | Ordered to rectify; warning; fine |
| 8 | Shanghai technology co. | Since 2022, its Windows desktop application collected — beyond the necessary scope — users’ host configuration, usage duration and operating-system information, and transmitted that, together with the name, mobile number, email, date of birth and password entered at registration, to data centres outside China. No data-export security assessment had been declared. | PIPL · Cross-Border Data Flows Provisions | Ordered to rectify; fine |
| 9 | Sichuan technology co. | Its WeChat mini-program offered AI text chat and image generation but added no explicit label to AI-generated and synthetic content, no implicit label in file metadata (attribute information, service provider name or code, content number), and no explicit label on exported content; it had also not carried out the required security assessment. | Deep Synthesis Provisions · AI Content Labeling Measures · Security Assessment Provisions | Mini-program ordered offline |
| 10 | Jiangsu technology co. ltd. | Two websites operated as an “API relay station” (API中转站), calling the interfaces of multiple large-model products to provide chat and Q&A services, without carrying out the required security assessment — presenting content-security risk. | GenAI Interim Measures · Security Assessment Provisions | Ordered to rectify; responsible persons dealt with strictly; warning |
The bolded four are the subject of the rest of this brief.
1. Facial recognition used for marketing — PIPL Article 26 arrives in practice
Case 7. A Chongqing property company installed more than ten image-collection devices around its office premises and built up over 5,000 items of customer facial information. The purpose was not security. It was customer identity recognition and matching-based marketing with intermediary agencies — in plain terms, working out which broker a walk-in visitor belonged to, and attributing the commission accordingly.
CAC found the company had not informed customers truthfully, accurately and completely of the purpose, method and use of the collection, and had collected, stored and used facial information without separate consent (单独同意). The local cyberspace office ordered rectification and imposed a warning and a fine.
Why it matters. PIPL Article 26 is short and has been under-enforced:
Image capturing and personal identification equipment installed in public places shall be necessary for maintaining public security, comply with the relevant provisions of the State, and conspicuous prompting signs shall be set up. An individual’s personal image and personal identification information collected may only be used for the purpose of maintaining public security and shall not be used for any other purpose, except with the individual’s separate consent.
The structure is a default plus an exception: public-place cameras are for public security, full stop — unless the individual has given separate consent to something else. The original commentary describes this as the first publicly reported penalty it has seen turning directly on Article 26, and that reading looks right: earlier facial-recognition enforcement has generally run through the sensitive-personal-information consent rules or consumer-protection law rather than Article 26’s purpose limitation.
The operational point is the one companies tend to miss. The lobby camera is usually installed lawfully, for security. The violation happens later, when somebody notices the footage could also power attribution analytics, and the purpose changes without the consent basis changing with it. Real estate, retail and luxury are the obvious exposures: any deployment where facial recognition drives customer identification, channel attribution or marketing analytics needs to be re-papered against Article 26, not against general consent language.
For how the “necessary for maintaining public security” limb is meant to be operationalized, see Hong Yanqing’s four-element necessity framework; for the filing threshold and the seven specific duties that attach once facial recognition is in production, see the FRT Application Measures.
2. Cross-border enforcement is not confined to apps and mini-programs
Case 8. A Shanghai technology company had, since 2022, used its Windows desktop application to collect host configuration, usage duration and operating-system information from users of its hardware products — beyond the minimum scope necessary to achieve the processing purpose — and transmitted that information, together with the name, mobile number, email address, date of birth and password supplied at registration, to data centres outside China. It had not declared a data-export security assessment. Ordered to rectify; fined.
Why it matters. Two things, neither of which is about the size of the fine.
The regulated surface is wider than the app store. Almost every cross-border enforcement action discussed in the China market to date has involved a mobile app or a mini-program, and testing programmes have followed that shape. This case is a PC client. Desktop software, installer-bundled telemetry agents and hardware companion applications sit inside the same personal-information perimeter, and a compliance programme scoped to “our apps” will not see them.
Device and usage telemetry counts. Host configuration, session duration and OS version are exactly the fields engineering teams classify as product analytics rather than personal information. Bundled with a registered identity and shipped to an overseas data centre, CAC treated them as personal information collected beyond the necessary scope and exported without the required assessment. If your architecture includes overseas data centres, offshore log shipping or client-side telemetry, the inventory cannot stop at name and phone number.
Read alongside Ctrip’s ¥10 million cross-border fine — the first publicly quantified cross-border penalty — the direction is consistent: the Cross-Border Data Flows Provisions relaxed the thresholds for routine export, and enforcement has concentrated on necessity and on transfers that never went through any mechanism at all.
3. AI labeling failures can cost you the product, not a fine
Case 9. A Sichuan technology company ran a WeChat mini-program offering AI text chat and image generation. CAC found it had added:
- no explicit label (显式标识) to AI-generated and synthetic content;
- no implicit label (隐式标识) in file metadata — the production-element information comprising attribute information, the service provider’s name or code, and the content number;
- no explicit label on exported content, where an export function was offered;
and had not implemented the required security assessment, presenting content-security risk. The outcome was not a fine. The mini-program was ordered offline.
Why it matters. The AI Content Labeling Measures took effect on 1 September 2025, and this is labeling moving into real enforcement with a consequence that skips straight past money to availability. Three specifics deserve attention:
- The implicit label is a real obligation, not a nice-to-have. Article 4 of the Measures requires metadata carrying attribute information, provider name or code, and content number. It is invisible in the UI, which means it is invisible to the kind of review that consists of opening the product and looking for the words “AI generated”.
- Labels must survive export. The Measures expressly extend to download, copy and export functions. A product that renders a watermark on screen but emits a clean file on export is non-compliant at precisely the moment the content leaves the platform.
- Labeling and security assessment travel together. The case was charged under the Deep Synthesis Provisions and the Labeling Measures and the 2018 Security Assessment Provisions.
In short: AI labeling is not satisfied by something that looks present in the product. It has to be implemented to the rule — in the metadata, and in the file the user walks away with.
4. “We just call somebody else’s API” is not a compliance position
Case 10. A Jiangsu technology company operated two websites as an “API relay station” (API中转站), calling the interfaces of multiple large-model products to provide chat and Q&A services to the public. It had not carried out the required security assessment. CAC ordered rectification, directed that the responsible persons be dealt with strictly, and issued a warning.
Why it matters. This is the case with the widest reach, because the architecture is everywhere: relay stations, wrapper apps, model-aggregation platforms, and the large population of products whose entire AI capability is a call to somebody else’s endpoint.
The assumption those products run on is that AI compliance duties belong to the upstream model vendor — we do not train anything, we just proxy. Case 10 says the question is not who trained the model but who is providing a generative AI service to the public. If that is you, you re-run the analysis on your own account.
Two honest qualifications, which the original commentary also draws:
- This does not mean every product calling a large-model API must complete a security assessment. The duty in Article 17 of the GenAI Interim Measures attaches to services with public opinion attributes or social mobilization capacity, and for some products large-model filing (大模型登记) is the applicable route instead.
- What the case does establish is narrower and still significant: relaying an API does not, by itself, transfer the application-layer AI compliance obligations upstream.
Both case 9 and case 10 were charged in part under the 2018 Provisions on the Security Assessment of Internet Information Services with Public Opinion Attributes or Social Mobilization Capacity — an instrument long treated as a content-governance formality. Neither the GenAI Measures nor the Deep Synthesis Provisions contain their own assessment procedure; the triggers, the report contents and the filing channel all live in the 2018 rule. It is worth reading in full, particularly Article 7: where the trigger is a launch or a new function, the report must be filed before the service goes live.
What the batch signals
Enforcement has moved into the implementation layer. The through-line across all four cases is that none of them could be found by reading a document. What the cameras are used for; what the desktop client uploads and where it lands; whether the exported file carries a label; whether the thing behind the chat box is a third party’s API — these are questions answered by opening the product, not by reviewing a privacy policy or a records-of-processing register.
The perimeter is wider than the app. A Windows client, a WeChat mini-program and two websites account for three of the four cases. Compliance programmes scoped to mobile apps are scoped to the wrong surface.
Purpose creep is the recurring failure mode. Case 7 is lawful collection turned to an unlawful use. Case 8 is telemetry legitimately collected for product purposes, bundled with identity data and shipped offshore. In neither case was the initial decision obviously wrong; in both, the purpose moved and the legal basis did not move with it.
Old instruments are being picked up for new products. The 2018 Security Assessment Provisions were written for forums and public accounts. In this batch they were applied to an AI mini-program and to two LLM relay websites. A rule that has been dormant in your jurisdictional map is not the same as a rule that has been repealed.
Sources.
- Primary. Cyberspace Administration of China, 国家网信办发布近期网络安全、数据安全、个人信息保护等领域执法典型案例, 网信中国, 15 September 2026 — original. All ten case descriptions, cited instruments and outcomes above are translated from this notice.
- Commentary. 网信办执法通报值得关注的信息, 数据何规, 16 September 2026 — original. The selection of cases 7–10 as the four most consequential for operating companies, and the framing of why, follow this piece.
Translations and all commentary are DCC’s.
— Not legal advice.