Source — DCC.
网络安全法处罚案例汇总(2025–2026,截至2026年7月1日) — a compilation of 6,214 published administrative penalty decisions (行政处罚决定书) resting on the Cybersecurity Law, drawn from the 北大法宝 / pkulaw decision database. Decisions published January 1, 2025 – July 1, 2026: 3,780 county/district level, 2,432 municipal, 2 provincial. Each record carries the citation chain (执法依据), penalty types (处罚种类), issuing authority, locality, and total monetary penalty (罚没总金额).
Articles most frequently cited, by number of decisions:
Article Provision Decisions Share Art. 59 Penalty — security-protection duties 2,673 43.0% Art. 21 MLPS security-protection duties 2,501 40.2% Art. 25 Cybersecurity incident contingency plan 2,214 35.6% Art. 63 Penalty — endangering network security 1,307 21.0% Art. 64 Penalty — personal information 1,267 20.4% Art. 27 Endangering network security; intrusion tools 1,265 20.4% Art. 44 Stealing or illegally selling personal information 1,202 19.3% Art. 67 Penalty — unlawful websites and groups 512 8.2% Art. 46 Websites and communication groups for unlawful activity 490 7.9% Art. 47 Platform duty over user-published content 160 2.6% Art. 68 Penalty — failure to stop prohibited information 159 2.6% Art. 61 Penalty — real-identity verification 114 1.8% Art. 24 Real-identity verification 101 1.6% Article numbers are pre-amendment (2017) numbering, which covers 95% of the corpus. The 2025 amendment renumbered all of them, effective January 1, 2026; the mapping is at Section 4.
The short version
Overseas compliance programs for China are built largely around the instruments that generate headlines: the CAC’s app campaigns, cross-border transfer assessments, the PIPL’s RMB 50 million ceiling. The published Cybersecurity Law enforcement record points somewhere else almost entirely.
Across 6,214 decisions in eighteen months:
- 98.3% were issued by public security organs (公安机关). The Cyberspace Administration appears four times.
- 61% came from county and district bureaus, not provincial or municipal ones. Two decisions in eighteen months came from a provincial-level authority.
- 69% carried no monetary penalty whatsoever.
- Total money: RMB 179.35 million — of which a single penalty against Kuaishou is 66.4%. Strip it out and 1,923 fined decisions share RMB 60.25 million, at a median of RMB 1,800.
That is the shape of the thing. What follows is why it takes that shape, and which parts of it the 2025 amendment has just rearranged.
1. Two tracks, and they behave nothing alike
The most useful structural fact in this data is that the Cybersecurity Law runs two enforcement tracks that share a statute and share almost nothing else. Sorting the 6,214 decisions by the substantive article cited makes the split immediate.
The obligations track — failures of security housekeeping by an operator:
| Substantive article | Conduct | Cases | Share | Penalty article |
|---|---|---|---|---|
| Art. 21 | MLPS security-protection duties | 2,501 | 40.2% | Art. 59 |
| Art. 25 | Cybersecurity incident contingency plan | 2,214 | 35.6% | Art. 59 |
| Art. 47 | Platform duty over user-published content | 160 | 2.6% | Art. 68 |
| Art. 24 | Real-identity verification | 101 | 1.6% | Art. 61 |
The conduct track — affirmative wrongdoing, usually by an individual:
| Substantive article | Conduct | Cases | Share | Penalty article |
|---|---|---|---|---|
| Art. 27 | Endangering network security; supplying intrusion tools | 1,265 | 20.4% | Art. 63 |
| Art. 44 | Stealing or illegally selling personal information | 1,202 | 19.3% | Art. 64 |
| Art. 46 | Websites and communication groups for unlawful activity | 490 | 7.9% | Art. 67 |
Now the outcomes. The same articles, read by what actually happened:
| Article | Cases | Warning | Detention | Fine | Cases fined | Median fine | Largest fine |
|---|---|---|---|---|---|---|---|
| Art. 21 (MLPS) | 2,501 | 94% | 0% | 4% | 54 (2.2%) | RMB 10,000 | RMB 662,800 |
| Art. 25 (contingency plan) | 2,214 | 95% | 0% | 3% | 42 (1.9%) | RMB 5,000 | RMB 50,000 |
| Art. 47 (platform content) | 160 | 97% | 0% | 2% | 2 | RMB 12,525 | RMB 25,000 |
| Art. 27 (endangering) | 1,265 | 0% | 84% | 15% | 450 | RMB 1,100 | RMB 15,000,000 |
| Art. 44 (PI theft/sale) | 1,202 | 0% | 3% | 97% | 1,165 | RMB 1,500 | RMB 230,000 |
| Art. 46 (unlawful groups) | 490 | 0% | 98% | 2% | 105 | RMB 10,384 | RMB 5,000,000 |
Pre-amendment article numbering. Percentages are shares of decisions citing that article; a decision citing two articles appears in both rows. Full counts in the tables above and below.
Two clean, opposite distributions. The obligations track produces a warning in 94–97% of cases and reaches for money in roughly one case in forty. The conduct track detains or fines in essentially every case and never issues a bare warning.
This is not agency temperament; it is the statute. Article 59 of the Cybersecurity Law makes the fine conditional: the authority orders rectification and issues a warning, and a fine of RMB 10,000–100,000 follows only where the operator refuses to rectify or the failure causes consequences such as harm to cybersecurity. For a first inspection finding, the statutory default genuinely is a warning. Article 64 ¶2, by contrast, directs confiscation of illegal gains plus a fine of one to ten times those gains — which is exactly why 97% of Article 44 cases carry a fine and why the median is only RMB 1,500: the multiplier is applied to the modest sums these individuals actually earned. And Article 63 opens with detention, with the fine merely permitted alongside it.
The practical translation for a company: the article you are exposed to determines the kind of consequence you face, far more than the seriousness of your conduct does. An operator with a badly run network sits on a track whose statutory first move is a warning. An employee selling a customer list sits on a track whose statutory first move is confiscation and a gains multiple, or detention. Compliance programs routinely conflate these and price both as “fine risk.” Neither is priced correctly that way.
2. The money is trivial, and almost all of it is one case
Of 6,214 decisions, 4,290 (69%) record no monetary penalty. The 1,924 that do total RMB 179,354,795.
The distribution is the finding:
| Penalty band | Fined decisions |
|---|---|
| Under RMB 1,000 | 633 |
| RMB 1,000 – 10,000 | 755 |
| RMB 10,000 – 50,000 | 384 |
| RMB 50,000 – 100,000 | 72 |
| RMB 100,000 – 1,000,000 | 70 |
| RMB 1,000,000 and above | 10 |
Ten decisions in eighteen months crossed RMB 1 million. 4,290 further decisions carry no monetary penalty and are not shown.
Ten decisions in eighteen months crossed RMB 1 million. The largest, by an order of magnitude, is the Beijing CAC’s RMB 119.1 million penalty against Beijing Kuaishou Technology (February 6, 2026) — 66.4% of all money in the dataset, and one of only four CAC decisions in it. Second is RMB 15 million, from a county-level public security bureau in Weifang. Remove Kuaishou and the median fine across the remaining 1,923 is RMB 1,800.
Total RMB 179.35 million across 1,924 fined decisions. Median of the non-Kuaishou remainder: RMB 1,800.
Read that against the RMB 50 million / 5%-of-turnover ceiling that dominates overseas risk memos, and the gap is the point. The ceiling is real and occasionally used — but it describes a regime that operates, in the published record, four orders of magnitude below it. The routine consequence of Cybersecurity Law enforcement is not a fine. It is a warning on the record, an order to rectify against a deadline, and — under amended Article 72 — a credit archive entry that is made public. For CII operators the same obligations track runs through the Security Protection Regulations for Critical Information Infrastructure, and the underlying classification duties now sit in GB/T 43697-2024 on data classification and grading and the Regulation on Network Data Security Management.
3. Enforcement is a district-level, campaign-shaped activity
The issuing-authority breakdown is stark:
| Authority | Decisions |
|---|---|
| Public security organs (公安机关) | 6,110 (98.3%) |
| Other / unclassified | 92 |
| Financial regulators (PBOC, NFRA) | 6 |
| Cyberspace Administration (网信办) | 4 |
| Market regulation (SAMR) | 2 |
And by level: 3,780 county/district, 2,432 municipal, 2 provincial.
The geography is more revealing still. The 6,214 decisions come from 582 distinct localities, but the top ten account for 30% of them:
| Locality | Decisions |
|---|---|
| Zhanjiang, Guangdong | 521 |
| Shantou, Guangdong | 417 |
| Jinan, Shandong | 176 |
| Rui’an, Zhejiang | 134 |
| Shenzhen, Guangdong | 129 |
| Longyan, Fujian | 116 |
Meanwhile 169 localities produced exactly one decision. Zhanjiang alone issued more Cybersecurity Law penalties in eighteen months than every provincial-level authority in China combined, by a factor of 260.
This is not a picture of uniform national enforcement. It is a picture of local campaigns (专项行动): a municipal or district bureau runs an inspection sweep across hotels, clinics, or property-management companies in its area, issues several hundred warnings over a few months, and the count subsides. The compliance implication is uncomfortable but actionable — for the obligations track, your exposure depends heavily on which district your systems sit in and whether its bureau is mid-campaign. It is a local-inspection risk far more than a national-regulator risk.
What those inspections actually find — the recurring technical failures, the sectors that get swept, and what moves a case off the warning default — is the subject of the companion brief on the 392 DSL and PIPL decisions, where the decision narratives are detailed enough to read finding by finding.
4. The 2025 amendment renumbered all of it
Anyone planning to use this data operationally needs to handle a discontinuity. The 2025 amendment to the Cybersecurity Law, adopted October 28, 2025 and effective January 1, 2026, renumbered the articles. Every citation in Sections 1–3 above is pre-amendment numbering. The mapping for the provisions that matter:
| Conduct (2017) | → (2025) | Penalty (2017) | → (2025) |
|---|---|---|---|
| Art. 21 — MLPS duties | Art. 23 | Art. 59 | Art. 61 |
| Art. 25 — contingency plan | Art. 27 | Art. 59 | Art. 61 |
| Art. 27 — endangering network security | Art. 29 | Art. 63 | Art. 66 |
| Art. 44 — stealing/selling PI | Art. 46 | Art. 64 | Art. 71 |
| Art. 46 — unlawful sites/groups | Art. 48 | Art. 67 | Art. 68 |
| Art. 24 — real-identity verification | Art. 26 | Art. 61 | Art. 64 |
| Art. 47 — platform content duty | Art. 49 | Art. 68 | Art. 69 |
The collision is vicious and worth stating plainly: “Article 27” means opposite things in the two versions. Pre-amendment, Article 27 is the hacking and intrusion-tools prohibition — 84% administrative detention. Post-amendment, Article 27 is the incident contingency plan requirement — 95% warning. A citation of “CSL Article 27” without a version is unreadable. Likewise “Article 59,” the workhorse penalty provision behind 43% of all enforcement in this dataset, is in the amended text a provision about emergencies and production-safety accidents, and imposes nothing at all.
The dataset lets us watch the transition happen. Classifying each decision by which numbering system its citation chain is internally consistent with:
| Month published | New-numbering decisions | Total | Share |
|---|---|---|---|
| Through Dec 2025 | 0 | 5,416 | 0% |
| Jan 2026 | 64 | 148 | 43% |
| Feb 2026 | 37 | 286 | 13% |
| Mar 2026 | 50 | 111 | 45% |
| Apr 2026 | 46 | 97 | 47% |
| May 2026 | 63 | 82 | 77% |
| Jun 2026 | 48 | 73 | 66% |
Not one decision uses post-amendment numbering before the January 1, 2026 effective date. Monthly totals (n) fall sharply across 2026, substantially a publication-lag artifact — see the method note.
Not one decision uses the new numbering before the amendment’s effective date, and the share climbs to roughly two-thirds by mid-2026 — but old-numbering decisions keep issuing throughout. That is expected rather than sloppy: conduct completed before January 1, 2026 is adjudicated under the law in force when it occurred.
The trap is downstream of it. 437 decisions in this dataset are labelled as the “(2025 Amendment)” version by the database while citing pre-amendment article numbers. The version tag on a case record is not evidence of which text was applied; only the article numbers, read against the conduct described, will tell you. For anyone building citation-based monitoring, benchmarking, or precedent research on Chinese enforcement data, that is the single most expensive thing to get wrong right now — and it will stay a live problem for as long as pre-2026 conduct keeps moving through the system.
5. The deletion: the busiest personal-information penalty is gone
The renumbering is mechanical. One change is not.
Old Article 64 was the Cybersecurity Law’s self-contained personal-information penalty — including the ¶2 formula (confiscation plus one to ten times illegal gains) that drove 1,267 decisions, 20.4% of all enforcement in this dataset, making it the second-busiest penalty provision in the file.
In the amended text there is no equivalent. New Article 71 instead refers these matters out. For rights-infringement, it provides that where a person infringes personal information rights and interests in violation of Article 24 ¶3 and Articles 43 to 45, “handling and punishment shall be carried out in accordance with relevant laws and administrative regulations.” And for theft and unlawful sale specifically, where a person violates Article 46 (old Article 44) and the circumstances do not constitute a crime, “the public security authorities shall impose punishment in accordance with relevant laws and administrative regulations.”
So the Cybersecurity Law has stopped supplying its own answer for the largest category of personal-information enforcement it was carrying, and now points elsewhere — to the PIPL for rights-infringement, and to public-security administration law for theft and sale. What it no longer supplies is the fine formula: the one-to-ten-times-illegal-gains multiplier that this data shows being applied 1,165 times.
Where that multiplier now comes from — whether the revised Public Security Administration Punishments Law (also effective January 1, 2026) reproduces it, whether PIPL Article 66 absorbs these cases, or whether the practical result is a shift in the outcome mix — is not something this dataset can answer yet. The 2026 case volume is too thin, and pre-2026 conduct still moving through the system masks the transition. It is the thing to watch across the second half of 2026, and DCC will return to it when there is enough post-January data to test. If PIPL Article 66 absorbs these cases, the fine ceiling rises substantially and the calculation changes; if public-security law absorbs them, the RMB 1,500 median likely persists.
Alongside this, the amendment’s broader penalty increases and its expansion of the dual-penalty system to individual officers are covered in DCC’s brief on the 2025 amendment itself.
Method, and what these numbers are not
Source. An in-house compilation of published Chinese administrative penalty decisions resting on the Cybersecurity Law, drawn from the 北大法宝 / pkulaw decision database: 6,214 decisions published January 1, 2025 – July 1, 2026 (3,780 county/district, 2,432 municipal, 2 provincial).
Counting. All article and penalty counts are DCC’s, computed from the
执法依据 citation strings and the 处罚种类 field. Counts are per decision,
non-exclusive — a decision citing both Article 21 and Article 25 is counted
under each, so column shares sum above 100%. Penalty percentages are shares of
decisions citing that article.
Numbering normalization. Because the 2025 amendment renumbered the statute, raw article tallies mix two schemes. Each decision was classified by which scheme its conduct→penalty pairings are internally consistent with (e.g. {21, 25} → 59 is pre-amendment; {23, 27} → 61 is post-amendment), falling back to the database’s version label on a tie. 5,876 decisions resolved to pre-amendment numbering, 309 to post-amendment, 29 unresolved. The result is validated by the fact that no post-amendment classification appears before January 2026. All article numbers in Sections 1–3 are stated in pre-amendment numbering, which covers 95% of the corpus; Section 4 gives the mapping.
Money. The compilation’s 罚没总金额 field is a combined figure for fines
and confiscation, recorded in 万元 (RMB 10,000 units) and converted here. 4,365
decisions carry a value in that field, of which 2,441 are zero; 1,849
decisions have no value recorded and are treated as no recorded monetary
penalty. The 69% “no monetary penalty” figure therefore includes both explicit
zeros and blanks, and should be read as an upper bound on the non-monetary
share.
Limits — please read these before citing. Every number describes published decisions only. Chinese publication practice for administrative penalties is uneven across regions and levels, so the geographic concentration in Section 3 reflects a combination of real enforcement intensity and differing disclosure practice; a locality with one published decision has not necessarily issued one. Monthly totals decline across 2026 in this compilation, which is at least partly a publication-lag artifact rather than a measured drop in enforcement, and no trend claim should be read into it. Fine medians on the conduct track are depressed by the gains-multiplier structure and should not be read as an agency’s view of severity. Nothing here forecasts how the amended statute will be applied; Section 5 flags the open question rather than answering it.
Related on DCC: the companion brief on 392 DSL and PIPL penalty decisions, the 2025 CSL amendment and its penalty increases, and the MIIT public-naming track that runs parallel to these penalty decisions.
— Not legal advice.