Filed under typical-cases
Every brief tagged "typical-cases".
- § 01 · ENFORCEMENT
CAC's 15 September 2026 Enforcement Typical Cases (执法典型案例) — Ten Cases, and the Four That Change How You Test
On 15 September 2026 the Cyberspace Administration of China (国家网信办) published ten enforcement typical cases (执法典型案例) across cybersecurity, data security and personal information protection. Six are the familiar perimeter failures — weak passwords, unpatched vulnerabilities, unauthorized-access holes, an app forcing unnecessary permissions. Four are new, and they are the ones that should change how compliance teams test: a Chongqing property company fined for running facial recognition on 5,000+ customers for marketing without separate consent, apparently the first public penalty to turn directly on PIPL Article 26; a Shanghai company fined for exporting personal information through a Windows desktop client with no data-export security assessment; a Sichuan company's WeChat mini-program ordered offline for failing to add explicit and implicit labels to AI-generated content; and a Jiangsu company warned for running two websites as an "API relay station" (API中转站) over third-party LLM APIs without a security assessment. DCC tables all ten from the CAC notice and reads the four against PIPL, the Cross-Border Data Flows Provisions, the AI Content Labeling Measures and the 2018 Security Assessment Provisions.
- § 02 · ENFORCEMENT
公安部网安局 Publishes 10 Typical Cases of Infringing Citizens' Personal Information — Insiders, Order Decryption, and Article 253a in Practice
On 11 August 2026 the MPS Cyber Security Bureau (公安部网安局) published ten typical cases (典型案例) of the crime of infringing upon citizens' personal information, brought under the Clean Net special campaign (净网专项行动). Across the batch: 123 suspects, more than 9.6 million items of personal information, and roughly 23.6 million yuan in case value. The striking feature is not the volume but the access route — in at least half the cases the data came out through someone with legitimate access: an employee, a planted hire, a service vendor, a hotel partner, or a school and hospital staffer. This DCC brief translates all ten fact patterns, sets them against Criminal Law Article 253a and the 2017 PI Criminal Interpretation thresholds, and draws out what the batch signals for companies whose exposure runs through their own staff and vendors.