Skip to content
DCC · DATA COMPLIANCE CHINA China data law, for overseas counsel.
§ TAG · ENFORCEMENT

Filed under enforcement

Every brief tagged "enforcement".

  • § 01 · ENFORCEMENT

    公安部网安局 Publishes 10 Typical Cases of Infringing Citizens' Personal Information — Insiders, Order Decryption, and Article 253a in Practice

    On 11 August 2026 the MPS Cyber Security Bureau (公安部网安局) published ten typical cases (典型案例) of the crime of infringing upon citizens' personal information, brought under the Clean Net special campaign (净网专项行动). Across the batch: 123 suspects, more than 9.6 million items of personal information, and roughly 23.6 million yuan in case value. The striking feature is not the volume but the access route — in at least half the cases the data came out through someone with legitimate access: an employee, a planted hire, a service vendor, a hotel partner, or a school and hospital staffer. This DCC brief translates all ten fact patterns, sets them against Criminal Law Article 253a and the 2017 PI Criminal Interpretation thresholds, and draws out what the batch signals for companies whose exposure runs through their own staff and vendors.

    enforcement · criminal-liability · mps
  • § 02 · ENFORCEMENT

    What the Data Inspectors Actually Find

    An empirical read of 392 Chinese data-compliance administrative penalty decisions published between January 2024 and June 3, 2026, resting on the Data Security Law and the Personal Information Protection Law. Four findings for overseas counsel. First, the routine outcome is not a fine: 74.5% of decisions ended in a warning and public criticism, 16.6% carried a fine, and 92% were issued by public security organs rather than the Cyberspace Administration. Second, the citation chain is remarkably narrow — DSL Article 27 via Article 45 (173 decisions) and PIPL Article 51 via Article 66 (50 decisions) carry the file, and what inspectors find are the enumerated basics: no training record (58), unencrypted personal information (35), weak passwords (24), MLPS grading not completed (12), no contingency plan (11), log retention under six months (7). Third, what moves a case off the warning default is failure to rectify within the deadline, not scale of exposure: 19.28 million exposed records drew RMB 50,000, while a hospital that missed its rectification deadline drew RMB 80,000 plus licence-tier measures — and where DSL Article 45 fines are imposed, they anchor at the RMB 50,000 statutory floor. Fourth, in all 392 decisions, zero cited PIPL Articles 38–42, the cross-border transfer provisions, and only three cited the impact-assessment duties in Articles 55–56.

    enforcement · dsl · pipl
  • § 03 · ENFORCEMENT

    What the Cybersecurity Law Actually Costs

    An empirical read of 6,214 Cybersecurity Law administrative penalty decisions published between January 1, 2025 and July 1, 2026. Three findings for overseas counsel. First, the enforcement machine is police-led and district-level: 98.3% of decisions come from public security organs, 61% from county and district bureaus, and the Cyberspace Administration appears four times in 6,214 cases. Second, the statute runs two tracks that behave oppositely — the obligations track (Arts. 21 and 25 via Art. 59) ends in a warning 94–95% of the time and fines roughly one case in forty, while the conduct track (Art. 27 via Art. 63, Art. 44 via Art. 64) detains or fines in essentially every case, because Art. 59 makes the fine conditional on refusal to rectify while Art. 64 ¶2 mandates one to ten times illegal gains. Third, the money is trivial and top-heavy: RMB 179.35 million total, of which the single Kuaishou penalty is 66.4%, leaving a median fine of RMB 1,800 across the remaining 1,923 fined decisions, and 69% of decisions carry no monetary penalty at all. Plus the transition trap: the 2025 amendment renumbered every article above — 'Article 27' now means the opposite thing — and deleted the CSL's own personal-information penalty, the provision behind 20.4% of all enforcement, referring it out under new Article 71.

    enforcement · csl · csl-2025-amendment
  • § 04 · ENFORCEMENT

    MIIT Public-Naming Bulletin 2026 Batch 4 (Total Batch 57): 32 Apps and SDKs Cited for PI Violations, Excessive Permission Demands, and SDK Disclosure Failures

    On July 2, 2026, MIIT's Information & Communications Administration Bureau issued its fourth public-naming bulletin of 2026 (total Batch 57), citing 32 apps and SDKs for infringing user rights — unlawful and beyond-scope collection of personal information, forced/frequent/excessive permission demands, frequent self-starting and chained starting, uncloseable and redirect-abusing information windows, and inadequate SDK information disclosure. The batch runs under the same 2026 CAC + MIIT + MPS special campaign as the earlier CAC notification and Shanghai takedown covered in DCC's enforcement tracker, on the same rectify-or-face-disposition pathway. DCC transcribes the full 32-entry list from the bulletin's attached image table. The profile: a mobility-and-transport long tail (ride-hailing driver apps, EV charging, bus-information tools) alongside recognizable names — Neta Auto's app, PetroChina Kunlun's charging app, NetDragon's fortune-telling app, iFlyPlus — plus two WeChat mini-programs, multiple Apple App Store listings, one developer named twice, and three SDKs, one of which (闪登 SDK) drew four separate findings including the headline SDK-disclosure failure.

    enforcement · miit · app-compliance
  • § 05 · ENFORCEMENT

    From Naming to Takedown: Shanghai Pulls 46 Apps That Missed the Rectification Window

    On June 24, 2026 the Shanghai Communications Administration (上海市通信管理局, the MIIT's directly-administered local communications authority) issued a notification ordering the takedown of 46 apps and SDKs that, after public naming and a rectification window, still had not fixed user-rights and personal-information violations. DCC reads it as the next rung on the enforcement ladder above the CAC's 30-app naming notification: same 2026 CAC + MIIT + MPS special campaign, but the local communications-administration tier converting an unrectified naming into an operative sanction — removal from distribution, with further measures flagged (suspension of access, administrative penalty, inclusion in the telecom-business bad-record list). The legal basis is PIPL, the Cybersecurity Law, the Telecom Regulations, and the Telecom and Internet User PI Protection Provisions. The 46-app list — transcribed here from the notice's attached image — is almost entirely Shanghai-registered long-tail O2O lifestyle apps (moving, housekeeping and cleaning, pet services, local travel agencies, community group-buy food, fitness and restaurants), and several operators appear with multiple apps taken down at once. DCC's read for overseas counsel: the provincial communications administrations are where a missed rectification window becomes a removed app, and the takedown tier sweeps the small-operator long tail, not just big nationals.

    enforcement · app-compliance · miit
  • § 06 · ENFORCEMENT

    Ctrip's ¥10 Million Fine: China's First Publicly Disclosed Cross-Border Data Penalty — and the 'Necessity' Doctrine Behind Four Cases

    In June 2026 Shanghai's cyberspace authority fined Shanghai Ctrip Commerce ¥10 million for unlawfully exporting personal information without implementing data-export security-assessment requirements — the first time a Chinese cross-border data penalty amount has been made public. DCC reads the fine against the three earlier Shanghai / MPS cross-border cases compiled by HexCode in 数据何规 (a hotel company that exported fields the CAC assessment had rejected, a property company that exported accommodation and financial-account data with no approval at all, and the Dior breach case) to surface the doctrine all four share: building a CRM or central-reservation system offshore does not make the bulk transfer of customer PI to headquarters 'necessary,' so it cannot escape the security-assessment / standard-contract / certification gate or PIPL's separate-consent and individual-notification requirements. The enforcement gradient — the assessment-rejected exporter was fined while the no-approval exporter was only warned — signals that subjective culpability is weighing on penalty severity.

    enforcement · cross-border-data · pipl
§ SUBSCRIBE

The Monday brief.

One short email every Monday. New briefs on Chinese data-compliance rules from the previous week, with the source law cited.

Opt-in only. Unsubscribe anytime by replying "unsubscribe" to any issue.

SUPPORT DCC

Keep the publication free to read. Suggested support is $19.99, or choose your own amount.

Support →