Source — DCC.
数据合规行政处罚案例汇总(2024–2026,截至2026年6月3日) — a compilation of 392 published administrative penalty decisions (行政处罚决定书) resting on the Data Security Law and the Personal Information Protection Law, drawn from the 北大法宝 / pkulaw decision database. Decisions published January 2024 – June 3, 2026: 261 in 2024, 117 in 2025, 14 through June 3, 2026. Each record carries the citation chain (执法依据), penalty types (处罚种类), issuing authority, locality, and the basic facts of the case (基本事实) — a paragraph describing what the inspection found before naming the article breached.
Articles most frequently cited, by number of decisions:
Article Provision Decisions Share DSL Art. 45 Penalty — data security protection duties 192 49.0% DSL Art. 27 Whole-process management system; training; technical measures 173 44.1% PIPL Art. 66 Penalty — unlawful processing / protection duties 169 43.1% PIPL Art. 51 Security measures for personal information handlers 50 12.8% DSL Art. 29 Risk monitoring, remediation, incident reporting 34 8.7% PIPL Art. 10 Prohibition on unlawful processing 27 6.9% DSL Art. 30 Periodic risk assessment by important-data handlers 23 5.9% PIPL Art. 71 Route to public-security administrative punishment 18 4.6% PIPL Art. 2 Protection of personal information rights 18 4.6% PSAPL Art. 42 Public-security offences incl. privacy infringement 18 4.6% CSL Art. 59 Penalty — security-protection duties 16 4.1% PIPL Art. 13 Lawful basis for processing 12 3.1% PIPL Art. 17 Notice obligations 12 3.1% CSL Art. 21 MLPS security-protection duties 10 2.6% Of the 392 decisions, 203 rest on the Data Security Law, 189 on the PIPL, and 24 also cite the Cybersecurity Law. PSAPL is the Public Security Administration Punishments Law (治安管理处罚法).
The short version
Across 392 Data Security Law and PIPL penalty decisions spanning two and a half years:
| Outcome | Decisions | Share |
|---|---|---|
| Warning + public criticism (警告、通报批评) | 292 | 74.5% |
| Fine + confiscation (罚款、没收) | 65 | 16.6% |
| Administrative detention (行政拘留) | 18 | 4.6% |
| Other statutory penalties | 14 | 3.6% |
| Licence-tier or business-restriction measures | 2 | 0.5% |
Exact shares: warning + public criticism 74.5%, fine + confiscation 16.6%, administrative detention 4.6%, other statutory penalties 4.1%.
And on who imposes them: 361 of 392 (92%) came from public security organs. Four came from Cyberspace Administration offices. One came from a telecommunications administration.
The single most consequential negative finding: zero of these 392 decisions cited PIPL Articles 38–42 — the cross-border transfer provisions that consume the largest share of most overseas China compliance budgets.
1. A remarkably narrow citation chain
PSAPL is the Public Security Administration Punishments Law (治安管理处罚法). Counts are per decision and non-exclusive.
The statutory basis for Chinese data enforcement is, in practice, far narrower than the two statutes’ breadth suggests. As the citation table above shows, two duty–penalty pairings carry the entire file:
- DSL Article 27 → Article 45, in 173 decisions. Article 27 requires a whole-process data security management system, data-security education and training, and corresponding technical measures. Article 45 ¶1 directs the authority to order corrections and issue a warning, and provides that it may impose a fine of RMB 50,000–500,000 on the entity plus RMB 10,000–100,000 on the responsible person.
- PIPL Article 51 → Article 66, in 50 decisions. Article 51 requires internal management systems, classified handling, encryption or de-identification, properly scoped operating permissions, training, and a security-incident contingency plan. Article 66 ¶1 likewise leads with rectification and a warning, with confiscation and fines following.
Two things follow. First, the enforcement question is overwhelmingly did you build the controls, not did you have a lawful basis: Article 51 and DSL Article 27 together account for 223 decisions, while lawful-basis and notice questions (PIPL Arts. 13 and 17) account for 24 between them. Second, the warning default is statutory. Both DSL Article 45 ¶1 and PIPL Article 66 ¶1 lead with rectification and a warning and make the fine discretionary — which is precisely why 74.5% of these decisions end there.
The detention exception is a single raid. The 18 detention decisions are not obligations cases at all; they run through PIPL Article 71, which routes violations constituting public-security administration offences to punishment under the Public Security Administration Punishments Law. And they are far more concentrated than the count suggests: 17 of the 18 are members of one telephone-fraud studio, all penalized by the Shifeng District bureau of the Zhuzhou Municipal Public Security Bureau, Hunan. Each participant had been recruited into the same studio to impersonate bank staff by telephone and harvest the details of people interested in credit cards — between roughly 1,000 and 5,805 records each, with illegal gains of RMB 7,466 to RMB 29,194 — and each drew five days’ detention (ten for one participant) under PIPL Articles 2 and 71 together with Article 42 of the Public Security Administration Punishments Law. Several were not executed: one participant was a minor, one was pregnant or nursing, one had the term offset against criminal detention already served.
The eighteenth is unrelated: a privacy infringement in Nansha District, Guangzhou (January 17, 2025), also ten days’ detention, on PIPL Articles 2, 10 and 71.
The lesson is one to carry into any read of this data. The detention line in the outcome table looks like a 4.6% enforcement pattern; it is one police operation against one workshop, plus a single unrelated case. This is the conduct track described in the companion CSL brief appearing in its PIPL form — and at this sample size it is a reminder that counts in a published-decision corpus can be an artifact of one raid rather than a measure of anything national.
2. What the inspectors actually find
The fact narratives are the most useful part of the file, because they record what the inspection found rather than which article it breached. The recurring findings across 392 decisions:
| Finding in the decision text | Decisions |
|---|---|
| No data-security education and training conducted | 58 |
| Personal information stored unencrypted | 35 |
| Substantial data-breach risk identified | 32 |
| Weak-password or high-risk vulnerability on a login | 24 |
| MLPS grading or assessment not completed | 12 |
| No incident contingency plan | 11 |
| Log retention shorter than six months | 7 |
Keyword matches against the 基本事实 field; read as a floor, since the same failure may be described in different words.
None of these is a novel or sophisticated failure. They are the items enumerated in DSL Article 27 and PIPL Article 51, checked one by one: is there a written whole-process management system, is there a named responsible person, are technical measures in place, are logs kept six months, is data classified and encrypted, have permissions been properly scoped, has training happened.
The sectoral concentration follows from who gets swept in a local inspection campaign:
| Sector (from decision text) | Decisions |
|---|---|
| Schools and education providers | 49 |
| Hotels | 30 |
| Property-management companies | 29 |
| Hospitals and clinics | 22 |
| Banking and finance | 18 |
Non-exclusive: a decision naming both a school and its property manager counts in both.
Three decisions worth reading closely, all on the DSL Article 27 → Article 45 chain or its PIPL equivalent:
- A hotel in Dongying, Shandong was warned for guest Wi‑Fi with no real-identity authentication, no network-behavior auditing, no log retention, and unencrypted guest personal information — four enumerated items failed at once, cited under CSL Articles 21, 25 and 59 together with DSL Articles 27 and 45. Outcome: warning plus a rectification deadline.
- A property-management company in Yanggu County, Shandong held owner records (names, mobile numbers, addresses, WeChat IDs and avatars) in a management system with no access controls, no audit logging, and no approval step for data export. Outcome: warning plus rectification.
- A hospital in Shen County, Shandong stored patient records in the tens of thousands (the exact figure is redacted in the published decision) — names, ID numbers, addresses, treatment items and fees — with no security measures, no management system, and a weak-password high-risk vulnerability on the system login. Outcome: warning.
The instructive point is how modest the triggering facts are. None of these involved a breach, a complaint, or a transfer. In each, the finding was that the controls did not exist — which is all DSL Article 27 requires the inspector to establish. The geography confirms the campaign pattern: 36 of the 392 decisions came from Wen’an County, Hebei alone, out-producing Beijing (13), Shanghai (13), Chongqing (13) and Shenzhen (8). Read those counts with care, though — Shifeng District, Zhuzhou contributes 17, and as Section 1 showed, all 17 are one workshop raid rather than an inspection sweep.
3. What moves a case off the warning default
Because the obligations track defaults to a warning, the operative question is what escalates it. In this data the answer is consistent, and it is not what most risk models assume: failure to rectify within the deadline.
The two most severe outcomes in the file:
- Yongzhou No. 4 People’s Hospital (Hunan, August 7, 2025) — the hospital’s website failed data-security protection duties over sensitive personal information and did not retain logs for the required six months; it then failed to complete rectification within the deadline set by the public security authority. Result: an RMB 80,000 fine plus licence-tier measures (暂扣许可证件、降低资质等级、吊销许可证件), citing CSL Article 21(3), DSL Articles 27 and 29, and the Hunan provincial cybersecurity regulations.
- Yibo Education Technology Group (Lanzhou, April 22, 2025) — an Elasticsearch database exposed without authentication, holding 19,278,695 records (10.32 GB), including 4,997 un-de-identified sensitive personal records, with log retention under 180 days. Result: RMB 50,000 plus the full business-restriction set — restricted operations, suspension of business, closure, and occupational restriction.
Note the asymmetry: 19.28 million exposed records drew RMB 50,000, while missed rectification at a hospital drew RMB 80,000 and licence consequences. In the published record, procedural defiance is punished more reliably than scale of exposure. That is what DSL Article 45 and PIPL Article 66 are drafted to do — both make the fine conditional on refusal to rectify or resulting consequences — and it is how the discretion is actually exercised.
One further calibration point. Where DSL Article 45 fines were imposed, the amounts recoverable from the narratives run from RMB 10,000 to RMB 110,000 with a median of RMB 50,000 — precisely the statutory floor of Article 45 ¶1’s RMB 50,000–500,000 band. Agencies that decline the discretionary fine decline it entirely; agencies that impose it anchor at the minimum. The RMB 10,000 figures are the separate limb of the same paragraph: fines on the responsible individual.
4. When CAC takes a data case, the officer pays too
Only four of the 392 decisions came from Cyberspace Administration offices — but they are disproportionately instructive, because three are Jiaozuo, Henan hospitals and every one imposes a dual penalty, on the entity and on the responsible officer personally:
| Entity | Facts | Penalty |
|---|---|---|
| Jiaozuo Maternal & Child Health Hospital (Mar 17, 2025) | WeChat account exposing 370,000+ patient records (names, ID numbers, mobile numbers); 358 high-risk vulnerabilities across website and business systems | RMB 150,000 on the hospital + RMB 10,000 on the officer in charge |
| Mengzhou Minsheng Hospital (Mar 31, 2025) | WeChat service account leak exposing 600,000+ patient records | RMB 50,000 + RMB 10,000 on the officer |
| Bo’ai County People’s Hospital (May 20, 2025) | Failure to perform data-security protection duties | RMB 50,000 + RMB 10,000 on the officer |
All three cite DSL Articles 27 and 29 through Article 45. Individual officer liability is not an afterthought in CAC data enforcement — it is standard, and it is the limb of Article 45 ¶1 that agencies reach for once they have decided to fine at all. Compare the 2025 Cybersecurity Law amendment’s expansion of the dual-penalty system, which generalizes exactly this posture across the statute.
The contrast with the public-security majority is also worth noting. Police inspections in this file produce warnings; the four CAC decisions produce fines, officer liability, or — at Yongzhou — licence measures. A change in the identity of the inspecting authority is a better predictor of a monetary outcome than any fact about the data.
5. The cross-border blank
One negative finding deserves its own section, because it inverts the priority order of most overseas China compliance programs.
Across 392 Data Security Law and PIPL penalty decisions spanning two and a half years:
- Zero cited PIPL Articles 38–42 — the cross-border transfer provisions operationalized by the Provisions on Promoting and Regulating Cross-border Data Flows, the Measures for the Security Assessment of Data Export, and the Standard Contract Measures.
- Three cited Articles 55–56, the personal information protection impact assessment duties.
- One decision in the entire file mentions data export at all.
- 23 cited DSL Article 30, the periodic risk-assessment duty on important-data handlers.
This does not mean cross-border transfer carries no risk. The rules bind, the security assessment and standard contract filing regimes are actively administered, and the Ctrip decision shows what a genuine cross-border enforcement action looks like when one arrives. What the data shows is that cross-border enforcement operates through a different channel — CAC assessment and filing review, handled centrally and largely unpublished as penalty decisions — while the published penalty record is almost entirely local police enforcement of domestic security housekeeping.
For a compliance team allocating finite attention, the asymmetry is worth sitting with. The regime most likely to generate your first Chinese enforcement contact is not the one that consumes most of your budget. It is a district public security bureau checking whether you have a named data-security officer, six months of logs, encrypted storage, a scoped access-control matrix, an export-approval step, a contingency plan, and a training record — the DSL Article 27 duties that 173 of these 392 decisions turn on, and the PIPL Article 51 duties behind another 50.
The corollary for the 23 Article 30 decisions is that important-data obligations are being enforced, if thinly — see DCC on important-data handler self-identification and annual assessment.
Method, and what these numbers are not
Source. An in-house compilation of published Chinese administrative penalty decisions resting on the Data Security Law and the PIPL, drawn from the 北大法宝 / pkulaw decision database: 392 decisions published January 2024 – June 3, 2026.
Counting. All article and penalty counts are DCC’s, computed from the
执法依据 citation strings, the 处罚种类 field, and keyword analysis of the
基本事实 fact narratives. Counts are per decision, non-exclusive — a
decision citing both DSL Article 27 and Article 29 is counted under each, and a
narrative mentioning both unencrypted storage and a weak password is counted
under each, so shares sum above 100%.
Sector and finding tallies in Sections 2 come from keyword matching against the fact narratives, not from a coded field. They are reliable as a floor and should be read as “at least this many,” since a decision may describe the same failure in different words.
Fine amounts. This compilation has no amount column. The figures in Section 3 were extracted from the narrative text — 24 recoverable figures across 65 fined decisions — and are illustrative, not a complete tally. The RMB 50,000 median should be read as a pattern in the recoverable subset, not a population statistic.
Limits — please read these before citing. Every number describes published decisions only, and Chinese publication practice for administrative penalties is uneven across regions and levels; the concentration in Wen’an County reflects a combination of real enforcement intensity and local disclosure practice. At n=392, single operations distort categories: 17 of the 18 detention decisions are one workshop raid in Zhuzhou, so the detention share is not a national pattern, and locality counts should be checked for clustering before being read as enforcement intensity. The year-on-year counts (261 in 2024, 117 in 2025, 14 through June 3, 2026) are not a measured decline in enforcement — later periods are heavily affected by publication lag, and the 2026 figure is far too thin to support any trend claim. The “zero cross-border decisions” finding is a statement about this published penalty corpus, not about cross-border enforcement activity as a whole, which Section 5 explains runs through an unpublished channel.
Related on DCC: the companion brief on 6,214 Cybersecurity Law penalty decisions — including how the 2025 amendment renumbered the statute and deleted its own personal-information penalty — the 2025 CSL amendment, and the MIIT public-naming track that runs parallel to these penalty decisions.
— Not legal advice.