Skip to content
DCC · DATA COMPLIANCE CHINA China data law, for overseas counsel.
§ 089 · ENFORCEMENT

What the Cybersecurity Law Actually Costs

6,214 CSL penalty decisions, January 2025 – July 2026: Article 21/25 → 59 ends in a warning 94% of the time, Article 27 → 63 in detention 84%, Article 44 → 64 in a fine 97%. RMB 179.35 million total, 66% of it a single Kuaishou penalty — and the 2025 amendment renumbers all three chains.

An empirical read of 6,214 Cybersecurity Law administrative penalty decisions published between January 1, 2025 and July 1, 2026. Three findings for overseas counsel. First, the enforcement machine is police-led and district-level: 98.3% of decisions come from public security organs, 61% from county and district bureaus, and the Cyberspace Administration appears four times in 6,214 cases. Second, the statute runs two tracks that behave oppositely — the obligations track (Arts. 21 and 25 via Art. 59) ends in a warning 94–95% of the time and fines roughly one case in forty, while the conduct track (Art. 27 via Art. 63, Art. 44 via Art. 64) detains or fines in essentially every case, because Art. 59 makes the fine conditional on refusal to rectify while Art. 64 ¶2 mandates one to ten times illegal gains. Third, the money is trivial and top-heavy: RMB 179.35 million total, of which the single Kuaishou penalty is 66.4%, leaving a median fine of RMB 1,800 across the remaining 1,923 fined decisions, and 69% of decisions carry no monetary penalty at all. Plus the transition trap: the 2025 amendment renumbered every article above — 'Article 27' now means the opposite thing — and deleted the CSL's own personal-information penalty, the provision behind 20.4% of all enforcement, referring it out under new Article 71.

Source — DCC.

网络安全法处罚案例汇总(2025–2026,截至2026年7月1日) — a compilation of 6,214 published administrative penalty decisions (行政处罚决定书) resting on the Cybersecurity Law, drawn from the 北大法宝 / pkulaw decision database. Decisions published January 1, 2025 – July 1, 2026: 3,780 county/district level, 2,432 municipal, 2 provincial. Each record carries the citation chain (执法依据), penalty types (处罚种类), issuing authority, locality, and total monetary penalty (罚没总金额).

Articles most frequently cited, by number of decisions:

ArticleProvisionDecisionsShare
Art. 59Penalty — security-protection duties2,67343.0%
Art. 21MLPS security-protection duties2,50140.2%
Art. 25Cybersecurity incident contingency plan2,21435.6%
Art. 63Penalty — endangering network security1,30721.0%
Art. 64Penalty — personal information1,26720.4%
Art. 27Endangering network security; intrusion tools1,26520.4%
Art. 44Stealing or illegally selling personal information1,20219.3%
Art. 67Penalty — unlawful websites and groups5128.2%
Art. 46Websites and communication groups for unlawful activity4907.9%
Art. 47Platform duty over user-published content1602.6%
Art. 68Penalty — failure to stop prohibited information1592.6%
Art. 61Penalty — real-identity verification1141.8%
Art. 24Real-identity verification1011.6%

Article numbers are pre-amendment (2017) numbering, which covers 95% of the corpus. The 2025 amendment renumbered all of them, effective January 1, 2026; the mapping is at Section 4.

The short version

Overseas compliance programs for China are built largely around the instruments that generate headlines: the CAC’s app campaigns, cross-border transfer assessments, the PIPL’s RMB 50 million ceiling. The published Cybersecurity Law enforcement record points somewhere else almost entirely.

Across 6,214 decisions in eighteen months:

  • 98.3% were issued by public security organs (公安机关). The Cyberspace Administration appears four times.
  • 61% came from county and district bureaus, not provincial or municipal ones. Two decisions in eighteen months came from a provincial-level authority.
  • 69% carried no monetary penalty whatsoever.
  • Total money: RMB 179.35 million — of which a single penalty against Kuaishou is 66.4%. Strip it out and 1,923 fined decisions share RMB 60.25 million, at a median of RMB 1,800.

That is the shape of the thing. What follows is why it takes that shape, and which parts of it the 2025 amendment has just rearranged.

1. Two tracks, and they behave nothing alike

The most useful structural fact in this data is that the Cybersecurity Law runs two enforcement tracks that share a statute and share almost nothing else. Sorting the 6,214 decisions by the substantive article cited makes the split immediate.

The obligations track — failures of security housekeeping by an operator:

Substantive articleConductCasesSharePenalty article
Art. 21MLPS security-protection duties2,50140.2%Art. 59
Art. 25Cybersecurity incident contingency plan2,21435.6%Art. 59
Art. 47Platform duty over user-published content1602.6%Art. 68
Art. 24Real-identity verification1011.6%Art. 61

The conduct track — affirmative wrongdoing, usually by an individual:

Substantive articleConductCasesSharePenalty article
Art. 27Endangering network security; supplying intrusion tools1,26520.4%Art. 63
Art. 44Stealing or illegally selling personal information1,20219.3%Art. 64
Art. 46Websites and communication groups for unlawful activity4907.9%Art. 67

Now the outcomes. The same articles, read by what actually happened:

ArticleCasesWarningDetentionFineCases finedMedian fineLargest fine
Art. 21 (MLPS)2,50194%0%4%54 (2.2%)RMB 10,000RMB 662,800
Art. 25 (contingency plan)2,21495%0%3%42 (1.9%)RMB 5,000RMB 50,000
Art. 47 (platform content)16097%0%2%2RMB 12,525RMB 25,000
Art. 27 (endangering)1,2650%84%15%450RMB 1,100RMB 15,000,000
Art. 44 (PI theft/sale)1,2020%3%97%1,165RMB 1,500RMB 230,000
Art. 46 (unlawful groups)4900%98%2%105RMB 10,384RMB 5,000,000
Two tracks, two opposite outcome distributions — share of decisions by penalty type, for the six busiest conduct→penalty chains.
Warning + public criticism Fine + confiscation Administrative detention Other statutory penalties
Art. 21 → 59 MLPS duties Art. 21 → 59 MLPS duties — warning + public criticism: 94% of 2,501 decisions 94% Art. 21 → 59 MLPS duties — fine + confiscation: 4% of 2,501 decisions Art. 21 → 59 MLPS duties — administrative detention: 0% of 2,501 decisions Art. 21 → 59 MLPS duties — other statutory penalties: 2% of 2,501 decisions n=2,501 Art. 25 → 59 contingency plan Art. 25 → 59 contingency plan — warning + public criticism: 95% of 2,214 decisions 95% Art. 25 → 59 contingency plan — fine + confiscation: 3% of 2,214 decisions Art. 25 → 59 contingency plan — administrative detention: 0% of 2,214 decisions Art. 25 → 59 contingency plan — other statutory penalties: 2% of 2,214 decisions n=2,214 Art. 47 → 68 platform content Art. 47 → 68 platform content — warning + public criticism: 97% of 160 decisions 97% Art. 47 → 68 platform content — fine + confiscation: 2% of 160 decisions Art. 47 → 68 platform content — other statutory penalties: 1% of 160 decisions n=160 Art. 27 → 63 hacking / tools Art. 27 → 63 hacking / tools — warning + public criticism: 0% of 1,265 decisions Art. 27 → 63 hacking / tools — fine + confiscation: 15% of 1,265 decisions 15% Art. 27 → 63 hacking / tools — administrative detention: 84% of 1,265 decisions 84% Art. 27 → 63 hacking / tools — other statutory penalties: 1% of 1,265 decisions n=1,265 Art. 44 → 64 stealing PI Art. 44 → 64 stealing PI — warning + public criticism: 0% of 1,202 decisions Art. 44 → 64 stealing PI — fine + confiscation: 97% of 1,202 decisions 97% Art. 44 → 64 stealing PI — administrative detention: 3% of 1,202 decisions Art. 44 → 64 stealing PI — other statutory penalties: 0% of 1,202 decisions n=1,202 Art. 46 → 67 unlawful groups Art. 46 → 67 unlawful groups — fine + confiscation: 2% of 490 decisions Art. 46 → 67 unlawful groups — administrative detention: 98% of 490 decisions 98% Art. 46 → 67 unlawful groups — other statutory penalties: 0% of 490 decisions n=490

Pre-amendment article numbering. Percentages are shares of decisions citing that article; a decision citing two articles appears in both rows. Full counts in the tables above and below.

Two clean, opposite distributions. The obligations track produces a warning in 94–97% of cases and reaches for money in roughly one case in forty. The conduct track detains or fines in essentially every case and never issues a bare warning.

This is not agency temperament; it is the statute. Article 59 of the Cybersecurity Law makes the fine conditional: the authority orders rectification and issues a warning, and a fine of RMB 10,000–100,000 follows only where the operator refuses to rectify or the failure causes consequences such as harm to cybersecurity. For a first inspection finding, the statutory default genuinely is a warning. Article 64 ¶2, by contrast, directs confiscation of illegal gains plus a fine of one to ten times those gains — which is exactly why 97% of Article 44 cases carry a fine and why the median is only RMB 1,500: the multiplier is applied to the modest sums these individuals actually earned. And Article 63 opens with detention, with the fine merely permitted alongside it.

The practical translation for a company: the article you are exposed to determines the kind of consequence you face, far more than the seriousness of your conduct does. An operator with a badly run network sits on a track whose statutory first move is a warning. An employee selling a customer list sits on a track whose statutory first move is confiscation and a gains multiple, or detention. Compliance programs routinely conflate these and price both as “fine risk.” Neither is priced correctly that way.

2. The money is trivial, and almost all of it is one case

Of 6,214 decisions, 4,290 (69%) record no monetary penalty. The 1,924 that do total RMB 179,354,795.

The distribution is the finding:

Penalty bandFined decisions
Under RMB 1,000633
RMB 1,000 – 10,000755
RMB 10,000 – 50,000384
RMB 50,000 – 100,00072
RMB 100,000 – 1,000,00070
RMB 1,000,000 and above10
Where the money actually lands — the 1,924 fined decisions by penalty band.
Under RMB 1,000 Under RMB 1,000: 633 fined decisions 633 RMB 1,000 – 10,000 RMB 1,000 – 10,000: 755 fined decisions 755 RMB 10,000 – 50,000 RMB 10,000 – 50,000: 384 fined decisions 384 RMB 50,000 – 100,000 RMB 50,000 – 100,000: 72 fined decisions 72 RMB 100,000 – 1 million RMB 100,000 – 1 million: 70 fined decisions 70 RMB 1 million and above RMB 1 million and above: 10 fined decisions 10

Ten decisions in eighteen months crossed RMB 1 million. 4,290 further decisions carry no monetary penalty and are not shown.

Ten decisions in eighteen months crossed RMB 1 million. The largest, by an order of magnitude, is the Beijing CAC’s RMB 119.1 million penalty against Beijing Kuaishou Technology (February 6, 2026) — 66.4% of all money in the dataset, and one of only four CAC decisions in it. Second is RMB 15 million, from a county-level public security bureau in Weifang. Remove Kuaishou and the median fine across the remaining 1,923 is RMB 1,800.

One penalty is two-thirds of all money in the corpus.
Kuaishou — RMB 119.1m All 1,923 other fined decisions — RMB 60.25m
All monetary penalties Kuaishou, Beijing CAC, Feb 6 2026 — RMB 119.1 million, 66.4% of all money 66% the other 1,923 fined decisions combined — RMB 60.25 million, 33.6% 34% n=1,924

Total RMB 179.35 million across 1,924 fined decisions. Median of the non-Kuaishou remainder: RMB 1,800.

Read that against the RMB 50 million / 5%-of-turnover ceiling that dominates overseas risk memos, and the gap is the point. The ceiling is real and occasionally used — but it describes a regime that operates, in the published record, four orders of magnitude below it. The routine consequence of Cybersecurity Law enforcement is not a fine. It is a warning on the record, an order to rectify against a deadline, and — under amended Article 72 — a credit archive entry that is made public. For CII operators the same obligations track runs through the Security Protection Regulations for Critical Information Infrastructure, and the underlying classification duties now sit in GB/T 43697-2024 on data classification and grading and the Regulation on Network Data Security Management.

3. Enforcement is a district-level, campaign-shaped activity

The issuing-authority breakdown is stark:

AuthorityDecisions
Public security organs (公安机关)6,110 (98.3%)
Other / unclassified92
Financial regulators (PBOC, NFRA)6
Cyberspace Administration (网信办)4
Market regulation (SAMR)2

And by level: 3,780 county/district, 2,432 municipal, 2 provincial.

The geography is more revealing still. The 6,214 decisions come from 582 distinct localities, but the top ten account for 30% of them:

LocalityDecisions
Zhanjiang, Guangdong521
Shantou, Guangdong417
Jinan, Shandong176
Rui’an, Zhejiang134
Shenzhen, Guangdong129
Longyan, Fujian116

Meanwhile 169 localities produced exactly one decision. Zhanjiang alone issued more Cybersecurity Law penalties in eighteen months than every provincial-level authority in China combined, by a factor of 260.

This is not a picture of uniform national enforcement. It is a picture of local campaigns (专项行动): a municipal or district bureau runs an inspection sweep across hotels, clinics, or property-management companies in its area, issues several hundred warnings over a few months, and the count subsides. The compliance implication is uncomfortable but actionable — for the obligations track, your exposure depends heavily on which district your systems sit in and whether its bureau is mid-campaign. It is a local-inspection risk far more than a national-regulator risk.

What those inspections actually find — the recurring technical failures, the sectors that get swept, and what moves a case off the warning default — is the subject of the companion brief on the 392 DSL and PIPL decisions, where the decision narratives are detailed enough to read finding by finding.

4. The 2025 amendment renumbered all of it

Anyone planning to use this data operationally needs to handle a discontinuity. The 2025 amendment to the Cybersecurity Law, adopted October 28, 2025 and effective January 1, 2026, renumbered the articles. Every citation in Sections 1–3 above is pre-amendment numbering. The mapping for the provisions that matter:

Conduct (2017)→ (2025)Penalty (2017)→ (2025)
Art. 21 — MLPS dutiesArt. 23Art. 59Art. 61
Art. 25 — contingency planArt. 27Art. 59Art. 61
Art. 27 — endangering network securityArt. 29Art. 63Art. 66
Art. 44 — stealing/selling PIArt. 46Art. 64Art. 71
Art. 46 — unlawful sites/groupsArt. 48Art. 67Art. 68
Art. 24 — real-identity verificationArt. 26Art. 61Art. 64
Art. 47 — platform content dutyArt. 49Art. 68Art. 69

The collision is vicious and worth stating plainly: “Article 27” means opposite things in the two versions. Pre-amendment, Article 27 is the hacking and intrusion-tools prohibition — 84% administrative detention. Post-amendment, Article 27 is the incident contingency plan requirement — 95% warning. A citation of “CSL Article 27” without a version is unreadable. Likewise “Article 59,” the workhorse penalty provision behind 43% of all enforcement in this dataset, is in the amended text a provision about emergencies and production-safety accidents, and imposes nothing at all.

The dataset lets us watch the transition happen. Classifying each decision by which numbering system its citation chain is internally consistent with:

Month publishedNew-numbering decisionsTotalShare
Through Dec 202505,4160%
Jan 20266414843%
Feb 20263728613%
Mar 20265011145%
Apr 2026469747%
May 2026638277%
Jun 2026487366%
The renumbering transition — share of decisions citing post-amendment article numbers, by month of publication.
100% 50% 0% Dec 2025: 0 of 468 decisions use post-amendment numbering (0%) 0% Dec 2025 n=468 Jan 2026: 64 of 148 decisions use post-amendment numbering (43%) 43% Jan 2026 n=148 Feb: 37 of 286 decisions use post-amendment numbering (13%) 13% Feb n=286 Mar: 50 of 111 decisions use post-amendment numbering (45%) 45% Mar n=111 Apr: 46 of 97 decisions use post-amendment numbering (47%) 47% Apr n=97 May: 63 of 82 decisions use post-amendment numbering (77%) 77% May n=82 Jun: 48 of 73 decisions use post-amendment numbering (66%) 66% Jun n=73

Not one decision uses post-amendment numbering before the January 1, 2026 effective date. Monthly totals (n) fall sharply across 2026, substantially a publication-lag artifact — see the method note.

Not one decision uses the new numbering before the amendment’s effective date, and the share climbs to roughly two-thirds by mid-2026 — but old-numbering decisions keep issuing throughout. That is expected rather than sloppy: conduct completed before January 1, 2026 is adjudicated under the law in force when it occurred.

The trap is downstream of it. 437 decisions in this dataset are labelled as the “(2025 Amendment)” version by the database while citing pre-amendment article numbers. The version tag on a case record is not evidence of which text was applied; only the article numbers, read against the conduct described, will tell you. For anyone building citation-based monitoring, benchmarking, or precedent research on Chinese enforcement data, that is the single most expensive thing to get wrong right now — and it will stay a live problem for as long as pre-2026 conduct keeps moving through the system.

5. The deletion: the busiest personal-information penalty is gone

The renumbering is mechanical. One change is not.

Old Article 64 was the Cybersecurity Law’s self-contained personal-information penalty — including the ¶2 formula (confiscation plus one to ten times illegal gains) that drove 1,267 decisions, 20.4% of all enforcement in this dataset, making it the second-busiest penalty provision in the file.

In the amended text there is no equivalent. New Article 71 instead refers these matters out. For rights-infringement, it provides that where a person infringes personal information rights and interests in violation of Article 24 ¶3 and Articles 43 to 45, “handling and punishment shall be carried out in accordance with relevant laws and administrative regulations.” And for theft and unlawful sale specifically, where a person violates Article 46 (old Article 44) and the circumstances do not constitute a crime, “the public security authorities shall impose punishment in accordance with relevant laws and administrative regulations.”

So the Cybersecurity Law has stopped supplying its own answer for the largest category of personal-information enforcement it was carrying, and now points elsewhere — to the PIPL for rights-infringement, and to public-security administration law for theft and sale. What it no longer supplies is the fine formula: the one-to-ten-times-illegal-gains multiplier that this data shows being applied 1,165 times.

Where that multiplier now comes from — whether the revised Public Security Administration Punishments Law (also effective January 1, 2026) reproduces it, whether PIPL Article 66 absorbs these cases, or whether the practical result is a shift in the outcome mix — is not something this dataset can answer yet. The 2026 case volume is too thin, and pre-2026 conduct still moving through the system masks the transition. It is the thing to watch across the second half of 2026, and DCC will return to it when there is enough post-January data to test. If PIPL Article 66 absorbs these cases, the fine ceiling rises substantially and the calculation changes; if public-security law absorbs them, the RMB 1,500 median likely persists.

Alongside this, the amendment’s broader penalty increases and its expansion of the dual-penalty system to individual officers are covered in DCC’s brief on the 2025 amendment itself.

Method, and what these numbers are not

Source. An in-house compilation of published Chinese administrative penalty decisions resting on the Cybersecurity Law, drawn from the 北大法宝 / pkulaw decision database: 6,214 decisions published January 1, 2025 – July 1, 2026 (3,780 county/district, 2,432 municipal, 2 provincial).

Counting. All article and penalty counts are DCC’s, computed from the 执法依据 citation strings and the 处罚种类 field. Counts are per decision, non-exclusive — a decision citing both Article 21 and Article 25 is counted under each, so column shares sum above 100%. Penalty percentages are shares of decisions citing that article.

Numbering normalization. Because the 2025 amendment renumbered the statute, raw article tallies mix two schemes. Each decision was classified by which scheme its conduct→penalty pairings are internally consistent with (e.g. {21, 25} → 59 is pre-amendment; {23, 27} → 61 is post-amendment), falling back to the database’s version label on a tie. 5,876 decisions resolved to pre-amendment numbering, 309 to post-amendment, 29 unresolved. The result is validated by the fact that no post-amendment classification appears before January 2026. All article numbers in Sections 1–3 are stated in pre-amendment numbering, which covers 95% of the corpus; Section 4 gives the mapping.

Money. The compilation’s 罚没总金额 field is a combined figure for fines and confiscation, recorded in 万元 (RMB 10,000 units) and converted here. 4,365 decisions carry a value in that field, of which 2,441 are zero; 1,849 decisions have no value recorded and are treated as no recorded monetary penalty. The 69% “no monetary penalty” figure therefore includes both explicit zeros and blanks, and should be read as an upper bound on the non-monetary share.

Limits — please read these before citing. Every number describes published decisions only. Chinese publication practice for administrative penalties is uneven across regions and levels, so the geographic concentration in Section 3 reflects a combination of real enforcement intensity and differing disclosure practice; a locality with one published decision has not necessarily issued one. Monthly totals decline across 2026 in this compilation, which is at least partly a publication-lag artifact rather than a measured drop in enforcement, and no trend claim should be read into it. Fine medians on the conduct track are depressed by the gains-multiplier structure and should not be read as an agency’s view of severity. Nothing here forecasts how the amended statute will be applied; Section 5 flags the open question rather than answering it.

Related on DCC: the companion brief on 392 DSL and PIPL penalty decisions, the 2025 CSL amendment and its penalty increases, and the MIIT public-naming track that runs parallel to these penalty decisions.

— Not legal advice.

— Not legal advice.


§ SUBSCRIBE

The Monday brief.

One short email every Monday. New briefs on Chinese data-compliance rules from the previous week, with the source law cited.

Opt-in only. Unsubscribe anytime by replying "unsubscribe" to any issue.

SUPPORT DCC

Keep the publication free to read. Suggested support is $19.99, or choose your own amount.

Support →