---
title: "What the Data Inspectors Actually Find"
author: "DCC Editorial"
published: 2026-07-30T02:00:00.000Z
url: https://datacompliancechina.com/posts/dsl-27-45-pipl-51-66-392-penalty-decisions-2024-2026/
description: "An empirical read of 392 Chinese data-compliance administrative penalty decisions published between January 2024 and June 3, 2026, resting on the Data Security Law and the Personal Information Protection Law. Four findings for overseas counsel. First, the routine outcome is not a fine: 74.5% of decisions ended in a warning and public criticism, 16.6% carried a fine, and 92% were issued by public security organs rather than the Cyberspace Administration. Second, the citation chain is remarkably narrow — DSL Article 27 via Article 45 (173 decisions) and PIPL Article 51 via Article 66 (50 decisions) carry the file, and what inspectors find are the enumerated basics: no training record (58), unencrypted personal information (35), weak passwords (24), MLPS grading not completed (12), no contingency plan (11), log retention under six months (7). Third, what moves a case off the warning default is failure to rectify within the deadline, not scale of exposure: 19.28 million exposed records drew RMB 50,000, while a hospital that missed its rectification deadline drew RMB 80,000 plus licence-tier measures — and where DSL Article 45 fines are imposed, they anchor at the RMB 50,000 statutory floor. Fourth, in all 392 decisions, zero cited PIPL Articles 38–42, the cross-border transfer provisions, and only three cited the impact-assessment duties in Articles 55–56."
tags: ["enforcement", "dsl", "pipl", "penalties", "statistics", "dsl-article-27", "dsl-article-45", "pipl-article-51", "pipl-article-66", "pipl-article-71", "cross-border", "public-security", "dual-penalty"]
laws_cited: ["dsl", "pipl", "csl", "network-data-security-regulations", "public-security-video-image-system-regulations", "cross-border-data-flows-provisions", "data-export-security-assessment-measures", "personal-info-standard-contract-measures"]
domains: ["enforcement", "data-security", "personal-information"]
source_language: "en"
---

> **Source: Data Compliance China** — https://datacompliancechina.com/posts/dsl-27-45-pipl-51-66-392-penalty-decisions-2024-2026/ · China data law, translated and annotated for overseas counsel. Cite as: Data Compliance China, "What the Data Inspectors Actually Find", https://datacompliancechina.com/posts/dsl-27-45-pipl-51-66-392-penalty-decisions-2024-2026/
> *Source — DCC.*
>
> **数据合规行政处罚案例汇总（2024–2026，截至2026年6月3日）** — a compilation of
> **392 published administrative penalty decisions** (行政处罚决定书) resting on
> the **Data Security Law** and the **Personal Information Protection Law**,
> drawn from the **北大法宝 / pkulaw** decision database. Decisions published
> **January 2024 – June 3, 2026**: 261 in 2024, 117 in 2025, 14 through June 3,
> 2026. Each record carries the citation chain (执法依据), penalty types
> (处罚种类), issuing authority, locality, and the basic facts of the case
> (基本事实) — a paragraph describing what the inspection found before naming
> the article breached.
>
> **Articles most frequently cited**, by number of decisions:
>
> | Article | Provision | Decisions | Share |
> |---|---|---|---|
> | DSL Art. 45 | Penalty — data security protection duties | 192 | 49.0% |
> | DSL Art. 27 | Whole-process management system; training; technical measures | 173 | 44.1% |
> | PIPL Art. 66 | Penalty — unlawful processing / protection duties | 169 | 43.1% |
> | PIPL Art. 51 | Security measures for personal information handlers | 50 | 12.8% |
> | DSL Art. 29 | Risk monitoring, remediation, incident reporting | 34 | 8.7% |
> | PIPL Art. 10 | Prohibition on unlawful processing | 27 | 6.9% |
> | DSL Art. 30 | Periodic risk assessment by important-data handlers | 23 | 5.9% |
> | PIPL Art. 71 | Route to public-security administrative punishment | 18 | 4.6% |
> | PIPL Art. 2 | Protection of personal information rights | 18 | 4.6% |
> | PSAPL Art. 42 | Public-security offences incl. privacy infringement | 18 | 4.6% |
> | CSL Art. 59 | Penalty — security-protection duties | 16 | 4.1% |
> | PIPL Art. 13 | Lawful basis for processing | 12 | 3.1% |
> | PIPL Art. 17 | Notice obligations | 12 | 3.1% |
> | CSL Art. 21 | MLPS security-protection duties | 10 | 2.6% |
>
> Of the 392 decisions, 203 rest on the Data Security Law, 189 on the PIPL, and
> 24 also cite the Cybersecurity Law. **PSAPL** is the Public Security
> Administration Punishments Law (治安管理处罚法).

## The short version

Across 392 Data Security Law and PIPL penalty decisions spanning two and a half
years:

| Outcome | Decisions | Share |
|---|---|---|
| Warning + public criticism (警告、通报批评) | 292 | 74.5% |
| Fine + confiscation (罚款、没收) | 65 | 16.6% |
| Administrative detention (行政拘留) | 18 | 4.6% |
| Other statutory penalties | 14 | 3.6% |
| Licence-tier or business-restriction measures | 2 | 0.5% |

<figure class="dcc-fig">
<figcaption class="dcc-fig__cap">The routine outcome is a warning, not a fine — all 392 decisions by penalty type.</figcaption>
<div class="dcc-fig__legend">
<span class="dcc-fig__key"><span class="dcc-fig__swatch dcc-fig__swatch--1"></span>Warning + public criticism</span>
<span class="dcc-fig__key"><span class="dcc-fig__swatch dcc-fig__swatch--2"></span>Fine + confiscation</span>
<span class="dcc-fig__key"><span class="dcc-fig__swatch dcc-fig__swatch--3"></span>Administrative detention</span>
<span class="dcc-fig__key"><span class="dcc-fig__swatch" style="background:var(--dcc-fig-track)"></span>Other statutory penalties</span>
</div>
<svg viewBox="0 0 700 38" role="img" aria-label="Outcome mix by article, share of decisions">
<text class="dcc-fig-lab" x="186" y="23.4" text-anchor="end">All 392 decisions</text>
<path class="dcc-fig-b1" d="M524.37 4.00H200.00A4 4 0 0 0 196.00 8.00V30.00A4 4 0 0 0 200.00 34.00H524.37Z"><title>All 392 decisions — warning + public criticism: 75% of 392 decisions</title></path>
<text class="dcc-fig-inval dcc-fig-on-1" x="361.2" y="23.2" text-anchor="middle">75%</text>
<path class="dcc-fig-b2" d="M526.37 4.00H597.66V34.00H526.37Z"><title>All 392 decisions — fine + confiscation: 17% of 392 decisions</title></path>
<text class="dcc-fig-inval dcc-fig-on-2" x="563.0" y="23.2" text-anchor="middle">17%</text>
<path class="dcc-fig-b3" d="M599.66 4.00H617.96V34.00H599.66Z"><title>All 392 decisions — administrative detention: 5% of 392 decisions</title></path>
<path class="dcc-fig-track" d="M619.96 4.00H634.00A4 4 0 0 1 638.00 8.00V30.00A4 4 0 0 1 634.00 34.00H619.96Z"><title>All 392 decisions — other statutory penalties: 4% of 392 decisions</title></path>
<text class="dcc-fig-tick" x="647" y="23.4">n=392</text>
</svg>
<p class="dcc-fig__note">Exact shares: warning + public criticism 74.5%, fine + confiscation 16.6%, administrative detention 4.6%, other statutory penalties 4.1%.</p>
</figure>

And on who imposes them: **361 of 392 (92%)** came from public security organs.
**Four** came from Cyberspace Administration offices. One came from a
telecommunications administration.

The single most consequential negative finding: **zero** of these 392 decisions
cited PIPL Articles 38–42 — the cross-border transfer provisions that consume
the largest share of most overseas China compliance budgets.

## 1. A remarkably narrow citation chain

<figure class="dcc-fig">
<figcaption class="dcc-fig__cap">A narrow citation chain — the ten most-cited articles, by number of decisions.</figcaption>
<svg viewBox="0 0 700 277" role="img" aria-label="Most-cited articles by number of decisions">
<text class="dcc-fig-lab" x="140" y="16.9" text-anchor="end">DSL Art. 45</text>
<path class="dcc-fig-track" d="M150.00 4.00H634.00A4 4 0 0 1 638.00 8.00V17.00A4 4 0 0 1 634.00 21.00H150.00Z" opacity="0.55"/>
<path class="dcc-fig-b2" d="M150.00 4.00H634.00A4 4 0 0 1 638.00 8.00V17.00A4 4 0 0 1 634.00 21.00H150.00Z"><title>DSL Article 45: cited in 192 of 392 decisions (49.0%)</title></path>
<text class="dcc-fig-val" x="647" y="16.9">192</text>
<text class="dcc-fig-lab" x="140" y="44.9" text-anchor="end">DSL Art. 27</text>
<path class="dcc-fig-track" d="M150.00 32.00H634.00A4 4 0 0 1 638.00 36.00V45.00A4 4 0 0 1 634.00 49.00H150.00Z" opacity="0.55"/>
<path class="dcc-fig-b2" d="M150.00 32.00H585.71A4 4 0 0 1 589.71 36.00V45.00A4 4 0 0 1 585.71 49.00H150.00Z"><title>DSL Article 27: cited in 173 of 392 decisions (44.1%)</title></path>
<text class="dcc-fig-val" x="647" y="44.9">173</text>
<text class="dcc-fig-lab" x="140" y="72.9" text-anchor="end">PIPL Art. 66</text>
<path class="dcc-fig-track" d="M150.00 60.00H634.00A4 4 0 0 1 638.00 64.00V73.00A4 4 0 0 1 634.00 77.00H150.00Z" opacity="0.55"/>
<path class="dcc-fig-b2" d="M150.00 60.00H575.54A4 4 0 0 1 579.54 64.00V73.00A4 4 0 0 1 575.54 77.00H150.00Z"><title>PIPL Article 66: cited in 169 of 392 decisions (43.1%)</title></path>
<text class="dcc-fig-val" x="647" y="72.9">169</text>
<text class="dcc-fig-lab" x="140" y="100.9" text-anchor="end">PIPL Art. 51</text>
<path class="dcc-fig-track" d="M150.00 88.00H634.00A4 4 0 0 1 638.00 92.00V101.00A4 4 0 0 1 634.00 105.00H150.00Z" opacity="0.55"/>
<path class="dcc-fig-b2" d="M150.00 88.00H273.08A4 4 0 0 1 277.08 92.00V101.00A4 4 0 0 1 273.08 105.00H150.00Z"><title>PIPL Article 51: cited in 50 of 392 decisions (12.8%)</title></path>
<text class="dcc-fig-val" x="647" y="100.9">50</text>
<text class="dcc-fig-lab" x="140" y="128.9" text-anchor="end">DSL Art. 29</text>
<path class="dcc-fig-track" d="M150.00 116.00H634.00A4 4 0 0 1 638.00 120.00V129.00A4 4 0 0 1 634.00 133.00H150.00Z" opacity="0.55"/>
<path class="dcc-fig-b2" d="M150.00 116.00H232.42A4 4 0 0 1 236.42 120.00V129.00A4 4 0 0 1 232.42 133.00H150.00Z"><title>DSL Article 29: cited in 34 of 392 decisions (8.7%)</title></path>
<text class="dcc-fig-val" x="647" y="128.9">34</text>
<text class="dcc-fig-lab" x="140" y="156.9" text-anchor="end">PIPL Art. 10</text>
<path class="dcc-fig-track" d="M150.00 144.00H634.00A4 4 0 0 1 638.00 148.00V157.00A4 4 0 0 1 634.00 161.00H150.00Z" opacity="0.55"/>
<path class="dcc-fig-b2" d="M150.00 144.00H214.62A4 4 0 0 1 218.62 148.00V157.00A4 4 0 0 1 214.62 161.00H150.00Z"><title>PIPL Article 10: cited in 27 of 392 decisions (6.9%)</title></path>
<text class="dcc-fig-val" x="647" y="156.9">27</text>
<text class="dcc-fig-lab" x="140" y="184.9" text-anchor="end">DSL Art. 30</text>
<path class="dcc-fig-track" d="M150.00 172.00H634.00A4 4 0 0 1 638.00 176.00V185.00A4 4 0 0 1 634.00 189.00H150.00Z" opacity="0.55"/>
<path class="dcc-fig-b2" d="M150.00 172.00H204.46A4 4 0 0 1 208.46 176.00V185.00A4 4 0 0 1 204.46 189.00H150.00Z"><title>DSL Article 30: cited in 23 of 392 decisions (5.9%)</title></path>
<text class="dcc-fig-val" x="647" y="184.9">23</text>
<text class="dcc-fig-lab" x="140" y="212.9" text-anchor="end">PIPL Art. 71</text>
<path class="dcc-fig-track" d="M150.00 200.00H634.00A4 4 0 0 1 638.00 204.00V213.00A4 4 0 0 1 634.00 217.00H150.00Z" opacity="0.55"/>
<path class="dcc-fig-b2" d="M150.00 200.00H191.75A4 4 0 0 1 195.75 204.00V213.00A4 4 0 0 1 191.75 217.00H150.00Z"><title>PIPL Article 71: cited in 18 of 392 decisions (4.6%)</title></path>
<text class="dcc-fig-val" x="647" y="212.9">18</text>
<text class="dcc-fig-lab" x="140" y="240.9" text-anchor="end">PSAPL Art. 42</text>
<path class="dcc-fig-track" d="M150.00 228.00H634.00A4 4 0 0 1 638.00 232.00V241.00A4 4 0 0 1 634.00 245.00H150.00Z" opacity="0.55"/>
<path class="dcc-fig-b2" d="M150.00 228.00H191.75A4 4 0 0 1 195.75 232.00V241.00A4 4 0 0 1 191.75 245.00H150.00Z"><title>PSAPL Article 42: cited in 18 of 392 decisions (4.6%)</title></path>
<text class="dcc-fig-val" x="647" y="240.9">18</text>
<text class="dcc-fig-lab" x="140" y="268.9" text-anchor="end">PIPL Art. 2</text>
<path class="dcc-fig-track" d="M150.00 256.00H634.00A4 4 0 0 1 638.00 260.00V269.00A4 4 0 0 1 634.00 273.00H150.00Z" opacity="0.55"/>
<path class="dcc-fig-b2" d="M150.00 256.00H191.75A4 4 0 0 1 195.75 260.00V269.00A4 4 0 0 1 191.75 273.00H150.00Z"><title>PIPL Article 2: cited in 18 of 392 decisions (4.6%)</title></path>
<text class="dcc-fig-val" x="647" y="268.9">18</text>
</svg>
<p class="dcc-fig__note">PSAPL is the Public Security Administration Punishments Law (治安管理处罚法). Counts are per decision and non-exclusive.</p>
</figure>

The statutory basis for Chinese data enforcement is, in practice, far narrower
than the two statutes' breadth suggests. As the citation table above shows, two
duty–penalty pairings carry the entire file:

- **[DSL Article 27 → Article 45](/laws/dsl/)**, in 173 decisions. Article 27 requires a
  whole-process data security management system, data-security education and
  training, and corresponding technical measures. Article 45 ¶1 directs the
  authority to order corrections and issue a warning, and provides that it
  **may** impose a fine of RMB 50,000–500,000 on the entity plus
  RMB 10,000–100,000 on the responsible person.
- **[PIPL Article 51 → Article 66](/laws/pipl/)**, in 50 decisions. Article 51 requires
  internal management systems, classified handling, encryption or
  de-identification, properly scoped operating permissions, training, and a
  security-incident contingency plan. Article 66 ¶1 likewise leads with
  rectification and a warning, with confiscation and fines following.

Two things follow. First, the enforcement question is overwhelmingly *did you
build the controls*, not *did you have a lawful basis*: Article 51 and DSL
Article 27 together account for 223 decisions, while lawful-basis and notice
questions (PIPL Arts. 13 and 17) account for 24 between them. Second, the
warning default is statutory. Both DSL Article 45 ¶1 and PIPL Article 66 ¶1
lead with rectification and a warning and make the fine discretionary — which
is precisely why 74.5% of these decisions end there.

**The detention exception is a single raid.** The 18 detention decisions are not
obligations cases at all; they run through **PIPL Article 71**, which routes
violations constituting public-security administration offences to punishment
under the Public Security Administration Punishments Law. And they are far more
concentrated than the count suggests: **17 of the 18 are members of one
telephone-fraud studio**, all penalized by the Shifeng District bureau of the
Zhuzhou Municipal Public Security Bureau, Hunan. Each participant had been
recruited into the same studio to impersonate bank staff by telephone and
harvest the details of people interested in credit cards — between roughly
1,000 and 5,805 records each, with illegal gains of RMB 7,466 to RMB 29,194 —
and each drew five days' detention (ten for one participant) under PIPL
Articles 2 and 71 together with Article 42 of the Public Security
Administration Punishments Law. Several were not executed: one participant was
a minor, one was pregnant or nursing, one had the term offset against criminal
detention already served.

The eighteenth is unrelated: a privacy infringement in Nansha District,
Guangzhou (January 17, 2025), also ten days' detention, on PIPL Articles 2, 10
and 71.

The lesson is one to carry into any read of this data. The detention line in
the outcome table looks like a 4.6% enforcement pattern; it is one police
operation against one workshop, plus a single unrelated case. This is the
conduct track described in the [companion CSL
brief](/posts/csl-6214-penalty-decisions-articles-59-63-64-2025-2026/)
appearing in its PIPL form — and at this sample size it is a reminder that
counts in a published-decision corpus can be an artifact of one raid rather
than a measure of anything national.

## 2. What the inspectors actually find

The fact narratives are the most useful part of the file, because they record
what the inspection found rather than which article it breached. The recurring
findings across 392 decisions:

| Finding in the decision text | Decisions |
|---|---|
| No data-security education and training conducted | 58 |
| Personal information stored unencrypted | 35 |
| Substantial data-breach risk identified | 32 |
| Weak-password or high-risk vulnerability on a login | 24 |
| MLPS grading or assessment not completed | 12 |
| No incident contingency plan | 11 |
| Log retention shorter than six months | 7 |

<figure class="dcc-fig">
<figcaption class="dcc-fig__cap">What the inspectors actually find — recurring findings across the 392 decision narratives.</figcaption>
<svg viewBox="0 0 700 193" role="img" aria-label="Recurring inspection findings">
<text class="dcc-fig-lab" x="206" y="16.9" text-anchor="end">No training conducted</text>
<path class="dcc-fig-track" d="M216.00 4.00H634.00A4 4 0 0 1 638.00 8.00V17.00A4 4 0 0 1 634.00 21.00H216.00Z" opacity="0.55"/>
<path class="dcc-fig-b2" d="M216.00 4.00H634.00A4 4 0 0 1 638.00 8.00V17.00A4 4 0 0 1 634.00 21.00H216.00Z"><title>No training conducted: found in 58 of 392 decisions</title></path>
<text class="dcc-fig-val" x="647" y="16.9">58</text>
<text class="dcc-fig-lab" x="206" y="44.9" text-anchor="end">PI stored unencrypted</text>
<path class="dcc-fig-track" d="M216.00 32.00H634.00A4 4 0 0 1 638.00 36.00V45.00A4 4 0 0 1 634.00 49.00H216.00Z" opacity="0.55"/>
<path class="dcc-fig-b2" d="M216.00 32.00H466.66A4 4 0 0 1 470.66 36.00V45.00A4 4 0 0 1 466.66 49.00H216.00Z"><title>PI stored unencrypted: found in 35 of 392 decisions</title></path>
<text class="dcc-fig-val" x="647" y="44.9">35</text>
<text class="dcc-fig-lab" x="206" y="72.9" text-anchor="end">Data-breach risk identified</text>
<path class="dcc-fig-track" d="M216.00 60.00H634.00A4 4 0 0 1 638.00 64.00V73.00A4 4 0 0 1 634.00 77.00H216.00Z" opacity="0.55"/>
<path class="dcc-fig-b2" d="M216.00 60.00H444.83A4 4 0 0 1 448.83 64.00V73.00A4 4 0 0 1 444.83 77.00H216.00Z"><title>Data-breach risk identified: found in 32 of 392 decisions</title></path>
<text class="dcc-fig-val" x="647" y="72.9">32</text>
<text class="dcc-fig-lab" x="206" y="100.9" text-anchor="end">Weak password / high-risk vuln</text>
<path class="dcc-fig-track" d="M216.00 88.00H634.00A4 4 0 0 1 638.00 92.00V101.00A4 4 0 0 1 634.00 105.00H216.00Z" opacity="0.55"/>
<path class="dcc-fig-b2" d="M216.00 88.00H386.62A4 4 0 0 1 390.62 92.00V101.00A4 4 0 0 1 386.62 105.00H216.00Z"><title>Weak password / high-risk vuln: found in 24 of 392 decisions</title></path>
<text class="dcc-fig-val" x="647" y="100.9">24</text>
<text class="dcc-fig-lab" x="206" y="128.9" text-anchor="end">MLPS grading not completed</text>
<path class="dcc-fig-track" d="M216.00 116.00H634.00A4 4 0 0 1 638.00 120.00V129.00A4 4 0 0 1 634.00 133.00H216.00Z" opacity="0.55"/>
<path class="dcc-fig-b2" d="M216.00 116.00H299.31A4 4 0 0 1 303.31 120.00V129.00A4 4 0 0 1 299.31 133.00H216.00Z"><title>MLPS grading not completed: found in 12 of 392 decisions</title></path>
<text class="dcc-fig-val" x="647" y="128.9">12</text>
<text class="dcc-fig-lab" x="206" y="156.9" text-anchor="end">No incident contingency plan</text>
<path class="dcc-fig-track" d="M216.00 144.00H634.00A4 4 0 0 1 638.00 148.00V157.00A4 4 0 0 1 634.00 161.00H216.00Z" opacity="0.55"/>
<path class="dcc-fig-b2" d="M216.00 144.00H292.03A4 4 0 0 1 296.03 148.00V157.00A4 4 0 0 1 292.03 161.00H216.00Z"><title>No incident contingency plan: found in 11 of 392 decisions</title></path>
<text class="dcc-fig-val" x="647" y="156.9">11</text>
<text class="dcc-fig-lab" x="206" y="184.9" text-anchor="end">Log retention under six months</text>
<path class="dcc-fig-track" d="M216.00 172.00H634.00A4 4 0 0 1 638.00 176.00V185.00A4 4 0 0 1 634.00 189.00H216.00Z" opacity="0.55"/>
<path class="dcc-fig-b2" d="M216.00 172.00H262.93A4 4 0 0 1 266.93 176.00V185.00A4 4 0 0 1 262.93 189.00H216.00Z"><title>Log retention under six months: found in 7 of 392 decisions</title></path>
<text class="dcc-fig-val" x="647" y="184.9">7</text>
</svg>
<p class="dcc-fig__note">Keyword matches against the 基本事实 field; read as a floor, since the same failure may be described in different words.</p>
</figure>

None of these is a novel or sophisticated failure. They are the items
enumerated in DSL Article 27 and PIPL Article 51, checked one by one: is there
a written whole-process management system, is there a named responsible person,
are technical measures in place, are logs kept six months, is data classified
and encrypted, have permissions been properly scoped, has training happened.

The sectoral concentration follows from who gets swept in a local inspection
campaign:

| Sector (from decision text) | Decisions |
|---|---|
| Schools and education providers | 49 |
| Hotels | 30 |
| Property-management companies | 29 |
| Hospitals and clinics | 22 |
| Banking and finance | 18 |

<figure class="dcc-fig">
<figcaption class="dcc-fig__cap">Who gets swept — sector concentration across the 392 decisions.</figcaption>
<svg viewBox="0 0 700 137" role="img" aria-label="Sector concentration">
<text class="dcc-fig-lab" x="170" y="16.9" text-anchor="end">Schools &amp; education</text>
<path class="dcc-fig-track" d="M180.00 4.00H634.00A4 4 0 0 1 638.00 8.00V17.00A4 4 0 0 1 634.00 21.00H180.00Z" opacity="0.55"/>
<path class="dcc-fig-b2" d="M180.00 4.00H634.00A4 4 0 0 1 638.00 8.00V17.00A4 4 0 0 1 634.00 21.00H180.00Z"><title>Schools &amp; education: 50 of 392 decisions</title></path>
<text class="dcc-fig-val" x="647" y="16.9">50</text>
<text class="dcc-fig-lab" x="170" y="44.9" text-anchor="end">Hotels</text>
<path class="dcc-fig-track" d="M180.00 32.00H634.00A4 4 0 0 1 638.00 36.00V45.00A4 4 0 0 1 634.00 49.00H180.00Z" opacity="0.55"/>
<path class="dcc-fig-b2" d="M180.00 32.00H450.80A4 4 0 0 1 454.80 36.00V45.00A4 4 0 0 1 450.80 49.00H180.00Z"><title>Hotels: 30 of 392 decisions</title></path>
<text class="dcc-fig-val" x="647" y="44.9">30</text>
<text class="dcc-fig-lab" x="170" y="72.9" text-anchor="end">Property management</text>
<path class="dcc-fig-track" d="M180.00 60.00H634.00A4 4 0 0 1 638.00 64.00V73.00A4 4 0 0 1 634.00 77.00H180.00Z" opacity="0.55"/>
<path class="dcc-fig-b2" d="M180.00 60.00H441.64A4 4 0 0 1 445.64 64.00V73.00A4 4 0 0 1 441.64 77.00H180.00Z"><title>Property management: 29 of 392 decisions</title></path>
<text class="dcc-fig-val" x="647" y="72.9">29</text>
<text class="dcc-fig-lab" x="170" y="100.9" text-anchor="end">Hospitals &amp; clinics</text>
<path class="dcc-fig-track" d="M180.00 88.00H634.00A4 4 0 0 1 638.00 92.00V101.00A4 4 0 0 1 634.00 105.00H180.00Z" opacity="0.55"/>
<path class="dcc-fig-b2" d="M180.00 88.00H377.52A4 4 0 0 1 381.52 92.00V101.00A4 4 0 0 1 377.52 105.00H180.00Z"><title>Hospitals &amp; clinics: 22 of 392 decisions</title></path>
<text class="dcc-fig-val" x="647" y="100.9">22</text>
<text class="dcc-fig-lab" x="170" y="128.9" text-anchor="end">Banking &amp; finance</text>
<path class="dcc-fig-track" d="M180.00 116.00H634.00A4 4 0 0 1 638.00 120.00V129.00A4 4 0 0 1 634.00 133.00H180.00Z" opacity="0.55"/>
<path class="dcc-fig-b2" d="M180.00 116.00H340.88A4 4 0 0 1 344.88 120.00V129.00A4 4 0 0 1 340.88 133.00H180.00Z"><title>Banking &amp; finance: 18 of 392 decisions</title></path>
<text class="dcc-fig-val" x="647" y="128.9">18</text>
</svg>
<p class="dcc-fig__note">Non-exclusive: a decision naming both a school and its property manager counts in both.</p>
</figure>

Three decisions worth reading closely, all on the DSL Article 27 → Article 45
chain or its PIPL equivalent:

- A **hotel in Dongying, Shandong** was warned for guest Wi‑Fi with no
  real-identity authentication, no network-behavior auditing, no log retention,
  and unencrypted guest personal information — four enumerated items failed at
  once, cited under [CSL](/laws/csl/) Articles 21, 25 and 59 together with DSL
  Articles 27 and 45. Outcome: warning plus a rectification deadline.
- A **property-management company in Yanggu County, Shandong** held owner
  records (names, mobile numbers, addresses, WeChat IDs and avatars) in a
  management system with **no access controls, no audit logging, and no
  approval step for data export**. Outcome: warning plus rectification.
- A **hospital in Shen County, Shandong** stored patient records in the tens of
  thousands (the exact figure is redacted in the published decision) — names,
  ID numbers, addresses, treatment items and fees — with no security measures,
  no management system, and a **weak-password high-risk vulnerability on the
  system login**. Outcome: warning.

The instructive point is how modest the triggering facts are. None of these
involved a breach, a complaint, or a transfer. In each, the finding was that
the controls did not exist — which is all DSL Article 27 requires the inspector
to establish. The geography confirms the campaign pattern: 36 of the 392
decisions came from Wen'an County, Hebei alone, out-producing Beijing (13),
Shanghai (13), Chongqing (13) and Shenzhen (8). Read those counts with care,
though — Shifeng District, Zhuzhou contributes 17, and as Section 1 showed, all
17 are one workshop raid rather than an inspection sweep.

## 3. What moves a case off the warning default

Because the obligations track defaults to a warning, the operative question is
what escalates it. In this data the answer is consistent, and it is not what
most risk models assume: **failure to rectify within the deadline**.

The two most severe outcomes in the file:

- **Yongzhou No. 4 People's Hospital** (Hunan, August 7, 2025) — the hospital's
  website failed data-security protection duties over sensitive personal
  information and **did not retain logs for the required six months**; it then
  **failed to complete rectification within the deadline set by the public
  security authority**. Result: an **RMB 80,000** fine plus licence-tier
  measures (暂扣许可证件、降低资质等级、吊销许可证件), citing CSL Article 21(3),
  DSL Articles 27 and 29, and the Hunan provincial cybersecurity regulations.
- **Yibo Education Technology Group** (Lanzhou, April 22, 2025) — an
  Elasticsearch database exposed without authentication, holding **19,278,695
  records (10.32 GB)**, including 4,997 un-de-identified sensitive personal
  records, with log retention under 180 days. Result: RMB 50,000 plus the full
  business-restriction set — restricted operations, suspension of business,
  closure, and occupational restriction.

Note the asymmetry: 19.28 million exposed records drew RMB 50,000, while missed
rectification at a hospital drew RMB 80,000 and licence consequences. In the
published record, **procedural defiance is punished more reliably than scale of
exposure**. That is what DSL Article 45 and PIPL Article 66 are drafted to do —
both make the fine conditional on refusal to rectify or resulting consequences
— and it is how the discretion is actually exercised.

One further calibration point. Where DSL Article 45 fines were imposed, the
amounts recoverable from the narratives run from RMB 10,000 to RMB 110,000 with
a **median of RMB 50,000** — precisely the statutory floor of Article 45 ¶1's
RMB 50,000–500,000 band. Agencies that decline the discretionary fine decline
it entirely; agencies that impose it anchor at the minimum. The RMB 10,000
figures are the separate limb of the same paragraph: fines on the responsible
individual.

## 4. When CAC takes a data case, the officer pays too

Only four of the 392 decisions came from Cyberspace Administration offices —
but they are disproportionately instructive, because three are Jiaozuo, Henan
hospitals and **every one imposes a dual penalty**, on the entity *and* on the
responsible officer personally:

| Entity | Facts | Penalty |
|---|---|---|
| Jiaozuo Maternal & Child Health Hospital (Mar 17, 2025) | WeChat account exposing 370,000+ patient records (names, ID numbers, mobile numbers); 358 high-risk vulnerabilities across website and business systems | RMB 150,000 on the hospital + **RMB 10,000 on the officer in charge** |
| Mengzhou Minsheng Hospital (Mar 31, 2025) | WeChat service account leak exposing 600,000+ patient records | RMB 50,000 + **RMB 10,000 on the officer** |
| Bo'ai County People's Hospital (May 20, 2025) | Failure to perform data-security protection duties | RMB 50,000 + **RMB 10,000 on the officer** |

All three cite DSL Articles 27 and 29 through Article 45. Individual officer
liability is not an afterthought in CAC data enforcement — it is standard, and
it is the limb of Article 45 ¶1 that agencies reach for once they have decided
to fine at all. Compare the 2025 Cybersecurity Law amendment's [expansion of
the dual-penalty
system](/posts/compliance-talker-csl-2025-amendment-ai-and-penalties/), which
generalizes exactly this posture across the statute.

The contrast with the public-security majority is also worth noting. Police
inspections in this file produce warnings; the four CAC decisions produce
fines, officer liability, or — at Yongzhou — licence measures. A change in the
identity of the inspecting authority is a better predictor of a monetary
outcome than any fact about the data.

## 5. The cross-border blank

One negative finding deserves its own section, because it inverts the priority
order of most overseas China compliance programs.

Across **392** Data Security Law and PIPL penalty decisions spanning two and a
half years:

- **Zero** cited PIPL Articles 38–42 — the cross-border transfer provisions
  operationalized by the [Provisions on Promoting and Regulating Cross-border
  Data Flows](/laws/cross-border-data-flows-provisions/), the [Measures for the
  Security Assessment of Data Export](/laws/data-export-security-assessment-measures/),
  and the [Standard Contract Measures](/laws/personal-info-standard-contract-measures/).
- **Three** cited Articles 55–56, the personal information protection impact
  assessment duties.
- **One** decision in the entire file mentions data export at all.
- **23** cited DSL Article 30, the periodic risk-assessment duty on
  important-data handlers.

This does not mean cross-border transfer carries no risk. The rules bind, the
security assessment and standard contract filing regimes are actively
administered, and the [Ctrip
decision](/posts/ctrip-cross-border-data-fine-necessity-doctrine/) shows what a
genuine cross-border enforcement action looks like when one arrives. What the
data shows is that cross-border enforcement operates through **a different
channel** — CAC assessment and filing review, handled centrally and largely
unpublished as penalty decisions — while the published penalty record is almost
entirely local police enforcement of domestic security housekeeping.

For a compliance team allocating finite attention, the asymmetry is worth
sitting with. The regime most likely to generate your first Chinese enforcement
contact is not the one that consumes most of your budget. It is a district
public security bureau checking whether you have a named data-security officer,
six months of logs, encrypted storage, a scoped access-control matrix, an
export-approval step, a contingency plan, and a training record — the [DSL
Article 27 duties](/laws/dsl/) that 173 of these 392 decisions turn on, and the
[PIPL Article 51 duties](/laws/pipl/) behind another 50.

The corollary for the 23 Article 30 decisions is that important-data
obligations are being enforced, if thinly — see DCC on
[important-data handler self-identification and annual
assessment](/posts/important-data-handler-self-identification-annual-assessment/).

## Method, and what these numbers are not

**Source.** An in-house compilation of published Chinese administrative penalty
decisions resting on the Data Security Law and the PIPL, drawn from the 北大法宝
/ pkulaw decision database: 392 decisions published January 2024 – June 3,
2026.

**Counting.** All article and penalty counts are DCC's, computed from the
`执法依据` citation strings, the `处罚种类` field, and keyword analysis of the
`基本事实` fact narratives. Counts are **per decision, non-exclusive** — a
decision citing both DSL Article 27 and Article 29 is counted under each, and a
narrative mentioning both unencrypted storage and a weak password is counted
under each, so shares sum above 100%.

**Sector and finding tallies** in Sections 2 come from keyword matching against
the fact narratives, not from a coded field. They are reliable as a floor and
should be read as "at least this many," since a decision may describe the same
failure in different words.

**Fine amounts.** This compilation has **no amount column**. The figures in
Section 3 were extracted from the narrative text — 24 recoverable figures
across 65 fined decisions — and are illustrative, not a complete tally. The
RMB 50,000 median should be read as a pattern in the recoverable subset, not a
population statistic.

**Limits — please read these before citing.** Every number describes
**published** decisions only, and Chinese publication practice for
administrative penalties is uneven across regions and levels; the concentration
in Wen'an County reflects a combination of real enforcement intensity *and*
local disclosure practice. At n=392, **single operations distort categories**:
17 of the 18 detention decisions are one workshop raid in Zhuzhou, so the
detention share is not a national pattern, and locality counts should be
checked for clustering before being read as enforcement intensity. The
year-on-year counts (261 in 2024, 117 in 2025,
14 through June 3, 2026) are **not** a measured decline in enforcement — later
periods are heavily affected by publication lag, and the 2026 figure is far too
thin to support any trend claim. The "zero cross-border decisions" finding is a
statement about this published penalty corpus, not about cross-border
enforcement activity as a whole, which Section 5 explains runs through an
unpublished channel.

Related on DCC: the [companion brief on 6,214 Cybersecurity Law penalty
decisions](/posts/csl-6214-penalty-decisions-articles-59-63-64-2025-2026/) —
including how the 2025 amendment renumbered the statute and deleted its own
personal-information penalty — the [2025 CSL
amendment](/posts/compliance-talker-csl-2025-amendment-ai-and-penalties/), and
the [MIIT public-naming
track](/posts/miit-2026-batch-4-32-app-public-naming/) that runs parallel to
these penalty decisions.

— Not legal advice.
