Skip to content
DCC · DATA COMPLIANCE CHINA China data law, for overseas counsel.
§ 090 · ENFORCEMENT

What the Data Inspectors Actually Find

392 Data Security Law and PIPL penalty decisions, January 2024 – June 2026: DSL Article 27 → 45 in 173 cases, PIPL Article 51 → 66 in 50. Warnings in 74.5%, fines in 16.6%, 92% issued by public security organs — and not one citing PIPL Articles 38–42 on cross-border transfer.

An empirical read of 392 Chinese data-compliance administrative penalty decisions published between January 2024 and June 3, 2026, resting on the Data Security Law and the Personal Information Protection Law. Four findings for overseas counsel. First, the routine outcome is not a fine: 74.5% of decisions ended in a warning and public criticism, 16.6% carried a fine, and 92% were issued by public security organs rather than the Cyberspace Administration. Second, the citation chain is remarkably narrow — DSL Article 27 via Article 45 (173 decisions) and PIPL Article 51 via Article 66 (50 decisions) carry the file, and what inspectors find are the enumerated basics: no training record (58), unencrypted personal information (35), weak passwords (24), MLPS grading not completed (12), no contingency plan (11), log retention under six months (7). Third, what moves a case off the warning default is failure to rectify within the deadline, not scale of exposure: 19.28 million exposed records drew RMB 50,000, while a hospital that missed its rectification deadline drew RMB 80,000 plus licence-tier measures — and where DSL Article 45 fines are imposed, they anchor at the RMB 50,000 statutory floor. Fourth, in all 392 decisions, zero cited PIPL Articles 38–42, the cross-border transfer provisions, and only three cited the impact-assessment duties in Articles 55–56.

Source — DCC.

数据合规行政处罚案例汇总(2024–2026,截至2026年6月3日) — a compilation of 392 published administrative penalty decisions (行政处罚决定书) resting on the Data Security Law and the Personal Information Protection Law, drawn from the 北大法宝 / pkulaw decision database. Decisions published January 2024 – June 3, 2026: 261 in 2024, 117 in 2025, 14 through June 3, 2026. Each record carries the citation chain (执法依据), penalty types (处罚种类), issuing authority, locality, and the basic facts of the case (基本事实) — a paragraph describing what the inspection found before naming the article breached.

Articles most frequently cited, by number of decisions:

ArticleProvisionDecisionsShare
DSL Art. 45Penalty — data security protection duties19249.0%
DSL Art. 27Whole-process management system; training; technical measures17344.1%
PIPL Art. 66Penalty — unlawful processing / protection duties16943.1%
PIPL Art. 51Security measures for personal information handlers5012.8%
DSL Art. 29Risk monitoring, remediation, incident reporting348.7%
PIPL Art. 10Prohibition on unlawful processing276.9%
DSL Art. 30Periodic risk assessment by important-data handlers235.9%
PIPL Art. 71Route to public-security administrative punishment184.6%
PIPL Art. 2Protection of personal information rights184.6%
PSAPL Art. 42Public-security offences incl. privacy infringement184.6%
CSL Art. 59Penalty — security-protection duties164.1%
PIPL Art. 13Lawful basis for processing123.1%
PIPL Art. 17Notice obligations123.1%
CSL Art. 21MLPS security-protection duties102.6%

Of the 392 decisions, 203 rest on the Data Security Law, 189 on the PIPL, and 24 also cite the Cybersecurity Law. PSAPL is the Public Security Administration Punishments Law (治安管理处罚法).

The short version

Across 392 Data Security Law and PIPL penalty decisions spanning two and a half years:

OutcomeDecisionsShare
Warning + public criticism (警告、通报批评)29274.5%
Fine + confiscation (罚款、没收)6516.6%
Administrative detention (行政拘留)184.6%
Other statutory penalties143.6%
Licence-tier or business-restriction measures20.5%
The routine outcome is a warning, not a fine — all 392 decisions by penalty type.
Warning + public criticism Fine + confiscation Administrative detention Other statutory penalties
All 392 decisions All 392 decisions — warning + public criticism: 75% of 392 decisions 75% All 392 decisions — fine + confiscation: 17% of 392 decisions 17% All 392 decisions — administrative detention: 5% of 392 decisions All 392 decisions — other statutory penalties: 4% of 392 decisions n=392

Exact shares: warning + public criticism 74.5%, fine + confiscation 16.6%, administrative detention 4.6%, other statutory penalties 4.1%.

And on who imposes them: 361 of 392 (92%) came from public security organs. Four came from Cyberspace Administration offices. One came from a telecommunications administration.

The single most consequential negative finding: zero of these 392 decisions cited PIPL Articles 38–42 — the cross-border transfer provisions that consume the largest share of most overseas China compliance budgets.

1. A remarkably narrow citation chain

A narrow citation chain — the ten most-cited articles, by number of decisions.
DSL Art. 45 DSL Article 45: cited in 192 of 392 decisions (49.0%) 192 DSL Art. 27 DSL Article 27: cited in 173 of 392 decisions (44.1%) 173 PIPL Art. 66 PIPL Article 66: cited in 169 of 392 decisions (43.1%) 169 PIPL Art. 51 PIPL Article 51: cited in 50 of 392 decisions (12.8%) 50 DSL Art. 29 DSL Article 29: cited in 34 of 392 decisions (8.7%) 34 PIPL Art. 10 PIPL Article 10: cited in 27 of 392 decisions (6.9%) 27 DSL Art. 30 DSL Article 30: cited in 23 of 392 decisions (5.9%) 23 PIPL Art. 71 PIPL Article 71: cited in 18 of 392 decisions (4.6%) 18 PSAPL Art. 42 PSAPL Article 42: cited in 18 of 392 decisions (4.6%) 18 PIPL Art. 2 PIPL Article 2: cited in 18 of 392 decisions (4.6%) 18

PSAPL is the Public Security Administration Punishments Law (治安管理处罚法). Counts are per decision and non-exclusive.

The statutory basis for Chinese data enforcement is, in practice, far narrower than the two statutes’ breadth suggests. As the citation table above shows, two duty–penalty pairings carry the entire file:

  • DSL Article 27 → Article 45, in 173 decisions. Article 27 requires a whole-process data security management system, data-security education and training, and corresponding technical measures. Article 45 ¶1 directs the authority to order corrections and issue a warning, and provides that it may impose a fine of RMB 50,000–500,000 on the entity plus RMB 10,000–100,000 on the responsible person.
  • PIPL Article 51 → Article 66, in 50 decisions. Article 51 requires internal management systems, classified handling, encryption or de-identification, properly scoped operating permissions, training, and a security-incident contingency plan. Article 66 ¶1 likewise leads with rectification and a warning, with confiscation and fines following.

Two things follow. First, the enforcement question is overwhelmingly did you build the controls, not did you have a lawful basis: Article 51 and DSL Article 27 together account for 223 decisions, while lawful-basis and notice questions (PIPL Arts. 13 and 17) account for 24 between them. Second, the warning default is statutory. Both DSL Article 45 ¶1 and PIPL Article 66 ¶1 lead with rectification and a warning and make the fine discretionary — which is precisely why 74.5% of these decisions end there.

The detention exception is a single raid. The 18 detention decisions are not obligations cases at all; they run through PIPL Article 71, which routes violations constituting public-security administration offences to punishment under the Public Security Administration Punishments Law. And they are far more concentrated than the count suggests: 17 of the 18 are members of one telephone-fraud studio, all penalized by the Shifeng District bureau of the Zhuzhou Municipal Public Security Bureau, Hunan. Each participant had been recruited into the same studio to impersonate bank staff by telephone and harvest the details of people interested in credit cards — between roughly 1,000 and 5,805 records each, with illegal gains of RMB 7,466 to RMB 29,194 — and each drew five days’ detention (ten for one participant) under PIPL Articles 2 and 71 together with Article 42 of the Public Security Administration Punishments Law. Several were not executed: one participant was a minor, one was pregnant or nursing, one had the term offset against criminal detention already served.

The eighteenth is unrelated: a privacy infringement in Nansha District, Guangzhou (January 17, 2025), also ten days’ detention, on PIPL Articles 2, 10 and 71.

The lesson is one to carry into any read of this data. The detention line in the outcome table looks like a 4.6% enforcement pattern; it is one police operation against one workshop, plus a single unrelated case. This is the conduct track described in the companion CSL brief appearing in its PIPL form — and at this sample size it is a reminder that counts in a published-decision corpus can be an artifact of one raid rather than a measure of anything national.

2. What the inspectors actually find

The fact narratives are the most useful part of the file, because they record what the inspection found rather than which article it breached. The recurring findings across 392 decisions:

Finding in the decision textDecisions
No data-security education and training conducted58
Personal information stored unencrypted35
Substantial data-breach risk identified32
Weak-password or high-risk vulnerability on a login24
MLPS grading or assessment not completed12
No incident contingency plan11
Log retention shorter than six months7
What the inspectors actually find — recurring findings across the 392 decision narratives.
No training conducted No training conducted: found in 58 of 392 decisions 58 PI stored unencrypted PI stored unencrypted: found in 35 of 392 decisions 35 Data-breach risk identified Data-breach risk identified: found in 32 of 392 decisions 32 Weak password / high-risk vuln Weak password / high-risk vuln: found in 24 of 392 decisions 24 MLPS grading not completed MLPS grading not completed: found in 12 of 392 decisions 12 No incident contingency plan No incident contingency plan: found in 11 of 392 decisions 11 Log retention under six months Log retention under six months: found in 7 of 392 decisions 7

Keyword matches against the 基本事实 field; read as a floor, since the same failure may be described in different words.

None of these is a novel or sophisticated failure. They are the items enumerated in DSL Article 27 and PIPL Article 51, checked one by one: is there a written whole-process management system, is there a named responsible person, are technical measures in place, are logs kept six months, is data classified and encrypted, have permissions been properly scoped, has training happened.

The sectoral concentration follows from who gets swept in a local inspection campaign:

Sector (from decision text)Decisions
Schools and education providers49
Hotels30
Property-management companies29
Hospitals and clinics22
Banking and finance18
Who gets swept — sector concentration across the 392 decisions.
Schools & education Schools & education: 50 of 392 decisions 50 Hotels Hotels: 30 of 392 decisions 30 Property management Property management: 29 of 392 decisions 29 Hospitals & clinics Hospitals & clinics: 22 of 392 decisions 22 Banking & finance Banking & finance: 18 of 392 decisions 18

Non-exclusive: a decision naming both a school and its property manager counts in both.

Three decisions worth reading closely, all on the DSL Article 27 → Article 45 chain or its PIPL equivalent:

  • A hotel in Dongying, Shandong was warned for guest Wi‑Fi with no real-identity authentication, no network-behavior auditing, no log retention, and unencrypted guest personal information — four enumerated items failed at once, cited under CSL Articles 21, 25 and 59 together with DSL Articles 27 and 45. Outcome: warning plus a rectification deadline.
  • A property-management company in Yanggu County, Shandong held owner records (names, mobile numbers, addresses, WeChat IDs and avatars) in a management system with no access controls, no audit logging, and no approval step for data export. Outcome: warning plus rectification.
  • A hospital in Shen County, Shandong stored patient records in the tens of thousands (the exact figure is redacted in the published decision) — names, ID numbers, addresses, treatment items and fees — with no security measures, no management system, and a weak-password high-risk vulnerability on the system login. Outcome: warning.

The instructive point is how modest the triggering facts are. None of these involved a breach, a complaint, or a transfer. In each, the finding was that the controls did not exist — which is all DSL Article 27 requires the inspector to establish. The geography confirms the campaign pattern: 36 of the 392 decisions came from Wen’an County, Hebei alone, out-producing Beijing (13), Shanghai (13), Chongqing (13) and Shenzhen (8). Read those counts with care, though — Shifeng District, Zhuzhou contributes 17, and as Section 1 showed, all 17 are one workshop raid rather than an inspection sweep.

3. What moves a case off the warning default

Because the obligations track defaults to a warning, the operative question is what escalates it. In this data the answer is consistent, and it is not what most risk models assume: failure to rectify within the deadline.

The two most severe outcomes in the file:

  • Yongzhou No. 4 People’s Hospital (Hunan, August 7, 2025) — the hospital’s website failed data-security protection duties over sensitive personal information and did not retain logs for the required six months; it then failed to complete rectification within the deadline set by the public security authority. Result: an RMB 80,000 fine plus licence-tier measures (暂扣许可证件、降低资质等级、吊销许可证件), citing CSL Article 21(3), DSL Articles 27 and 29, and the Hunan provincial cybersecurity regulations.
  • Yibo Education Technology Group (Lanzhou, April 22, 2025) — an Elasticsearch database exposed without authentication, holding 19,278,695 records (10.32 GB), including 4,997 un-de-identified sensitive personal records, with log retention under 180 days. Result: RMB 50,000 plus the full business-restriction set — restricted operations, suspension of business, closure, and occupational restriction.

Note the asymmetry: 19.28 million exposed records drew RMB 50,000, while missed rectification at a hospital drew RMB 80,000 and licence consequences. In the published record, procedural defiance is punished more reliably than scale of exposure. That is what DSL Article 45 and PIPL Article 66 are drafted to do — both make the fine conditional on refusal to rectify or resulting consequences — and it is how the discretion is actually exercised.

One further calibration point. Where DSL Article 45 fines were imposed, the amounts recoverable from the narratives run from RMB 10,000 to RMB 110,000 with a median of RMB 50,000 — precisely the statutory floor of Article 45 ¶1’s RMB 50,000–500,000 band. Agencies that decline the discretionary fine decline it entirely; agencies that impose it anchor at the minimum. The RMB 10,000 figures are the separate limb of the same paragraph: fines on the responsible individual.

4. When CAC takes a data case, the officer pays too

Only four of the 392 decisions came from Cyberspace Administration offices — but they are disproportionately instructive, because three are Jiaozuo, Henan hospitals and every one imposes a dual penalty, on the entity and on the responsible officer personally:

EntityFactsPenalty
Jiaozuo Maternal & Child Health Hospital (Mar 17, 2025)WeChat account exposing 370,000+ patient records (names, ID numbers, mobile numbers); 358 high-risk vulnerabilities across website and business systemsRMB 150,000 on the hospital + RMB 10,000 on the officer in charge
Mengzhou Minsheng Hospital (Mar 31, 2025)WeChat service account leak exposing 600,000+ patient recordsRMB 50,000 + RMB 10,000 on the officer
Bo’ai County People’s Hospital (May 20, 2025)Failure to perform data-security protection dutiesRMB 50,000 + RMB 10,000 on the officer

All three cite DSL Articles 27 and 29 through Article 45. Individual officer liability is not an afterthought in CAC data enforcement — it is standard, and it is the limb of Article 45 ¶1 that agencies reach for once they have decided to fine at all. Compare the 2025 Cybersecurity Law amendment’s expansion of the dual-penalty system, which generalizes exactly this posture across the statute.

The contrast with the public-security majority is also worth noting. Police inspections in this file produce warnings; the four CAC decisions produce fines, officer liability, or — at Yongzhou — licence measures. A change in the identity of the inspecting authority is a better predictor of a monetary outcome than any fact about the data.

5. The cross-border blank

One negative finding deserves its own section, because it inverts the priority order of most overseas China compliance programs.

Across 392 Data Security Law and PIPL penalty decisions spanning two and a half years:

This does not mean cross-border transfer carries no risk. The rules bind, the security assessment and standard contract filing regimes are actively administered, and the Ctrip decision shows what a genuine cross-border enforcement action looks like when one arrives. What the data shows is that cross-border enforcement operates through a different channel — CAC assessment and filing review, handled centrally and largely unpublished as penalty decisions — while the published penalty record is almost entirely local police enforcement of domestic security housekeeping.

For a compliance team allocating finite attention, the asymmetry is worth sitting with. The regime most likely to generate your first Chinese enforcement contact is not the one that consumes most of your budget. It is a district public security bureau checking whether you have a named data-security officer, six months of logs, encrypted storage, a scoped access-control matrix, an export-approval step, a contingency plan, and a training record — the DSL Article 27 duties that 173 of these 392 decisions turn on, and the PIPL Article 51 duties behind another 50.

The corollary for the 23 Article 30 decisions is that important-data obligations are being enforced, if thinly — see DCC on important-data handler self-identification and annual assessment.

Method, and what these numbers are not

Source. An in-house compilation of published Chinese administrative penalty decisions resting on the Data Security Law and the PIPL, drawn from the 北大法宝 / pkulaw decision database: 392 decisions published January 2024 – June 3, 2026.

Counting. All article and penalty counts are DCC’s, computed from the 执法依据 citation strings, the 处罚种类 field, and keyword analysis of the 基本事实 fact narratives. Counts are per decision, non-exclusive — a decision citing both DSL Article 27 and Article 29 is counted under each, and a narrative mentioning both unencrypted storage and a weak password is counted under each, so shares sum above 100%.

Sector and finding tallies in Sections 2 come from keyword matching against the fact narratives, not from a coded field. They are reliable as a floor and should be read as “at least this many,” since a decision may describe the same failure in different words.

Fine amounts. This compilation has no amount column. The figures in Section 3 were extracted from the narrative text — 24 recoverable figures across 65 fined decisions — and are illustrative, not a complete tally. The RMB 50,000 median should be read as a pattern in the recoverable subset, not a population statistic.

Limits — please read these before citing. Every number describes published decisions only, and Chinese publication practice for administrative penalties is uneven across regions and levels; the concentration in Wen’an County reflects a combination of real enforcement intensity and local disclosure practice. At n=392, single operations distort categories: 17 of the 18 detention decisions are one workshop raid in Zhuzhou, so the detention share is not a national pattern, and locality counts should be checked for clustering before being read as enforcement intensity. The year-on-year counts (261 in 2024, 117 in 2025, 14 through June 3, 2026) are not a measured decline in enforcement — later periods are heavily affected by publication lag, and the 2026 figure is far too thin to support any trend claim. The “zero cross-border decisions” finding is a statement about this published penalty corpus, not about cross-border enforcement activity as a whole, which Section 5 explains runs through an unpublished channel.

Related on DCC: the companion brief on 6,214 Cybersecurity Law penalty decisions — including how the 2025 amendment renumbered the statute and deleted its own personal-information penalty — the 2025 CSL amendment, and the MIIT public-naming track that runs parallel to these penalty decisions.

— Not legal advice.

— Not legal advice.


§ SUBSCRIBE

The Monday brief.

One short email every Monday. New briefs on Chinese data-compliance rules from the previous week, with the source law cited.

Opt-in only. Unsubscribe anytime by replying "unsubscribe" to any issue.

SUPPORT DCC

Keep the publication free to read. Suggested support is $19.99, or choose your own amount.

Support →