Skip to content
DCC · DATA COMPLIANCE CHINA China data law, for overseas counsel.
§ BRIEFINGS · PAGE 03

Every brief.

The full run, most recent first.

  • § 13 · ENFORCEMENT

    What the Data Inspectors Actually Find

    An empirical read of 392 Chinese data-compliance administrative penalty decisions published between January 2024 and June 3, 2026, resting on the Data Security Law and the Personal Information Protection Law. Four findings for overseas counsel. First, the routine outcome is not a fine: 74.5% of decisions ended in a warning and public criticism, 16.6% carried a fine, and 92% were issued by public security organs rather than the Cyberspace Administration. Second, the citation chain is remarkably narrow — DSL Article 27 via Article 45 (173 decisions) and PIPL Article 51 via Article 66 (50 decisions) carry the file, and what inspectors find are the enumerated basics: no training record (58), unencrypted personal information (35), weak passwords (24), MLPS grading not completed (12), no contingency plan (11), log retention under six months (7). Third, what moves a case off the warning default is failure to rectify within the deadline, not scale of exposure: 19.28 million exposed records drew RMB 50,000, while a hospital that missed its rectification deadline drew RMB 80,000 plus licence-tier measures — and where DSL Article 45 fines are imposed, they anchor at the RMB 50,000 statutory floor. Fourth, in all 392 decisions, zero cited PIPL Articles 38–42, the cross-border transfer provisions, and only three cited the impact-assessment duties in Articles 55–56.

    enforcement · dsl · pipl
  • § 14 · ENFORCEMENT

    What the Cybersecurity Law Actually Costs

    An empirical read of 6,214 Cybersecurity Law administrative penalty decisions published between January 1, 2025 and July 1, 2026. Three findings for overseas counsel. First, the enforcement machine is police-led and district-level: 98.3% of decisions come from public security organs, 61% from county and district bureaus, and the Cyberspace Administration appears four times in 6,214 cases. Second, the statute runs two tracks that behave oppositely — the obligations track (Arts. 21 and 25 via Art. 59) ends in a warning 94–95% of the time and fines roughly one case in forty, while the conduct track (Art. 27 via Art. 63, Art. 44 via Art. 64) detains or fines in essentially every case, because Art. 59 makes the fine conditional on refusal to rectify while Art. 64 ¶2 mandates one to ten times illegal gains. Third, the money is trivial and top-heavy: RMB 179.35 million total, of which the single Kuaishou penalty is 66.4%, leaving a median fine of RMB 1,800 across the remaining 1,923 fined decisions, and 69% of decisions carry no monetary penalty at all. Plus the transition trap: the 2025 amendment renumbered every article above — 'Article 27' now means the opposite thing — and deleted the CSL's own personal-information penalty, the provision behind 20.4% of all enforcement, referring it out under new Article 71.

    enforcement · csl · csl-2025-amendment
  • § 15 · PERSONAL-INFORMATION

    China Writes PIPL a Small-Business Exit Ramp: The Simplified Measures for Small Personal Information Handlers

    On 22 July 2026 the CAC and the Ministry of Public Security jointly issued Order No. 25, the Provisions on Simplified Personal Information Protection Measures for Small Personal Information Handlers, effective 1 September 2026. It is the first instrument to make PIPL's obligations formally proportionate: a handler processing the personal information of fewer than 100,000 people gets a three-item processing-rules template it can satisfy with a posted notice, notice discharged through those published rules alone, consent inferred from voluntary provision of necessary information, compliance audit cut to once every five years — or waived entirely if certified — and a one-page impact assessment. Article 8 lets a handler operating solely through a network platform drop its own rules, notice, audit and assessment altogether, riding on the platform's. Article 10 extends the cross-border exemption architecture to small handlers, with important data carved out. Articles 18 and 19 make no-penalty and mitigated-penalty outcomes mandatory rather than discretionary. DCC reads it for overseas counsel whose Chinese counterparties, franchisees, merchants and portfolio companies sit under the 100,000-person line — and explains why the threshold, not the relief, is the thing to watch.

    personal-information · pipl · small-business
  • § 16 · DATA-ASSETS

    Two Registrations, One Word: China's New Data-Asset Standards and the Line Between 登记 and 登记

    On 2 July 2026 China issued two national standards for data as an asset — GB/T 47949-2026 (classification and codes) and GB/T 47950-2026 (registration guidance) — both effective 1 September 2026. They give data assets a fixed place in the asset-classification code system (block A0806020000, including a first-ever asset code for AI-training multimodal data measured in tokens) and a step-by-step model for putting data on an organization's own books. The trap for overseas counsel is the word 登记 (registration): these MOF/SAC standards register data as an asset internally, while the National Data Administration's Data Property Rights Registration Work Guide (Trial), finalized 1 July 2026, registers rights in data externally through a certificated institution. Same word, two regimes, two artifacts, two purposes. This DCC brief separates them, reads the two standards for what they require, and explains why the 入表 (balance-sheet entry) vs 确权 (rights confirmation) distinction keeps tripping up data-asset deals.

    data-assets · data-property-rights · data-registration
  • § 17 · GENERATIVE-AI

    Which of the Ten Duties Actually Bites: Cheng Xiao on Fault and Statutory Duty for Generative-AI Providers

    In a Political Science and Law Tribune article, Tsinghua professor Cheng Xiao (程啸) resets how Chinese courts should reason from a generative-AI provider's statutory duties to civil fault. His thesis: tort liability here is fault-based under Civil Code Art. 1165(1); 'duty of care' is not a separate element but the objective reasonable-person standard in AI dress. Crucially, not every breach of a statutory duty is fault. Negative duties (do not infringe) collapse into the 'infringement of rights' element and prove nothing about fault; only breach of an affirmative statutory duty can ground fault — and only where the duty aims to protect individuals, the plaintiff is within its protected class, and the harmed interest is within its protected scope. Applying that filter to the ten affirmative duties in the Generative AI Interim Measures, Cheng sorts them into result-based and method-based obligations, sets out five factors for judging the method-based ones, and criticizes two court rulings that grounded fault on a labeling or risk-warning duty in copyright cases the duty was never meant to protect against.

    generative-ai · tort-liability · duty-of-care
  • § 18 · TRANSPORT

    Five Grades of Data, One Reporting Spine: The Ministry of Transport's Data Security Measures

    On June 18, 2026 the Ministry of Transport issued the Measures for Data Security Management in Transport (交科技规〔2026〕3号), effective July 1, 2026 — 41 articles that complete the sector build-out of the Data Security Law for highways, waterways and comprehensive transport. The full text reached the public record in July through an academic-society WeChat repost rather than the ministry's own site. DCC reads the Measures around four load-bearing features: a five-grade classification ladder that splits general data into Grades 3/2/1 and pulls Grade-3 general data into the hard transmission-protection net alongside important and core data; an annual risk-assessment duty that extends beyond important-data handlers to any processor holding personal information on 10 million or more people, dated the same day as the national Network Data Security Risk Assessment Measures but effective 50 days earlier; an AI clause requiring pre-deployment evaluation of corpora, training data and algorithm explainability, plus a default ban on training on entrusted data; and a single reporting spine that routes filings through provincial transport authorities to MOT, with a direct line for central transport SOEs. Storage follows the sector pattern: localization for transport-authority personal information and CIIO-collected data, MLPS Level 3 for important-data systems, Level 4 or CII protection for core data, and security-assessed cloud services only.

    transport · mot · important-data
§ SUBSCRIBE

The Monday brief.

One short email every Monday. New briefs on Chinese data-compliance rules from the previous week, with the source law cited.

Opt-in only. Unsubscribe anytime by replying "unsubscribe" to any issue.

SUPPORT DCC

Keep the publication free to read. Suggested support is $19.99, or choose your own amount.

Support →