Filed under api-relay-station
Every brief tagged "api-relay-station".
- § 01 · ENFORCEMENT
CAC's 15 September 2026 Enforcement Typical Cases (执法典型案例) — Ten Cases, and the Four That Change How You Test
On 15 September 2026 the Cyberspace Administration of China (国家网信办) published ten enforcement typical cases (执法典型案例) across cybersecurity, data security and personal information protection. Six are the familiar perimeter failures — weak passwords, unpatched vulnerabilities, unauthorized-access holes, an app forcing unnecessary permissions. Four are new, and they are the ones that should change how compliance teams test: a Chongqing property company fined for running facial recognition on 5,000+ customers for marketing without separate consent, apparently the first public penalty to turn directly on PIPL Article 26; a Shanghai company fined for exporting personal information through a Windows desktop client with no data-export security assessment; a Sichuan company's WeChat mini-program ordered offline for failing to add explicit and implicit labels to AI-generated content; and a Jiangsu company warned for running two websites as an "API relay station" (API中转站) over third-party LLM APIs without a security assessment. DCC tables all ten from the CAC notice and reads the four against PIPL, the Cross-Border Data Flows Provisions, the AI Content Labeling Measures and the 2018 Security Assessment Provisions.