China Issues New Rules on Cyberspace Security Inspection
4 Minute Read
September 2, 2026
On August 6, 2026, the Ministry of Public Security of the People’s Republic of China (“MPS”) promulgated the Measures for Public Security Organs’ Supervision and Inspection of Cyberspace Security (the “New Rules on Cyberspace Inspection”). The New Rules on Cyberspace Inspection will take effect October 1, 2026, and replace the 2018 Provisions on Internet Security Supervision and Inspection by Public Security Organs, which are simultaneously repealed.
The main provisions include the following:
- Consolidation and modernization of the police’s authority to inspect compliance with China’s cybersecurity, data security, and personal information protection regime. This brings MPS’ enforcement practice closer into alignment with the Cybersecurity Law, the Data Security Law, the Personal Information Protection Law, the Critical Information Infrastructure (“CII”) Protection Regulation and the Network Data Security Management Regulation.
- Regulation of parties including Internet service providers, public Internet access venues, network operators and their contractors, CII operators, providers of network products and services, and data and personal data handlers. Entities that have previously experienced cybersecurity or data security incidents, or that have been subject to administrative penalties for failing to fulfill their statutory obligations regarding cybersecurity, data security, or information security and that have not made the required corrections, will be subject to priority oversight and inspection.
- Establishment of two inspection processes: online monitoring and on-site inspections. (1) Online monitoring covers network patrols, information-review capability testing, and vulnerability scanning. It can be conducted without disrupting normal business operations, though capability testing requires three working days’ advance notice. Prefecture-level and higher public security organs may also carry out remote technical testing, including vulnerability probing and penetration testing, against network facilities outside CII. This is subject to three days’ notice, and there must be no disruption to normal operations. The findings must be shared with the same-level cyberspace administration and relevant industry regulator. (2) By contrast, on-site inspections are reserved for county-level and higher authorities in the jurisdiction where the network operator is based. On-site inspections must involve at least two officers presenting police credentials and a written inspection notice. These inspections are capped at one routine visit per year for MLPS Level 3-and-above networks and CII operators.
- Conduct by MPS and its local counterparts of supervisory inspections to verify compliance with statutory obligations regarding cybersecurity, data security, and information security.
- The inspection will focus on the following aspects: (1) network access filing; (2) internal security management systems; (3) retention of user registration and log data; (4) multi-level protection scheme compliance; (5) CII safeguards; (6) technical defenses against intrusion and malware; (7) remediation of known vulnerabilities; (8) content controls; (9) algorithm recommendation governance, (10) data and personal information protection; and (11) cooperation with police on national security, counter-terrorism, and criminal investigations.
- A heightened, targeted inspection regime applicable to operators connected to major security-guarantee events, focusing on contingency planning, risk assessment, and incident reporting.
- Based on the New Rules on Cyberspace Inspection, police engagement of qualified third-party technical service providers, but under police direction only. Such providers must be subject to confidentiality requirements and undergo background vetting, and no fees may be charged to inspected entities. Inspection records must generally be signed by both the inspecting officer and the responsible person of the entity being inspected, with any objections noted.
- Where risks are identified that do not constitute an actual violation, police issuance of advisory letters to the entity or its industry regulator. At the provincial level, they may also issue public advisories that do not name specific targets. More serious risks will result in escalation to government leadership. For cybersecurity or data security incidents, there is also the possibility of a formal interview with the entity’s legal representative or responsible person.
- Provisions for reciprocal accountability, which expose both police personnel and any engaged technical contractors involved to disciplinary or criminal liability for misconduct such as unauthorized data access, disclosure of trade secrets or personal information, or abuse of inspection powers.
Search
Recent Posts
Categories
- Behavioral Advertising
- Centre for Information Policy Leadership
- Children’s Privacy
- Cyber Insurance
- Cybersecurity
- Enforcement
- European Union
- Events
- FCRA
- Financial Privacy
- General
- Health Privacy
- Identity Theft
- Information Security
- International
- Marketing
- Multimedia Resources
- Online Privacy
- Security Breach
- U.S. Federal Law
- U.S. State Law
- Workplace Privacy
Tags
- Aaron P. Simpson
- Accountability
- Adequacy
- Advertisement
- Advertising
- Age Appropriate Design Code
- Age Verification
- Alabama
- American Privacy Rights Act
- Anna Pateraki
- Anonymization
- Anti-terrorism
- APEC
- Apple Inc.
- Argentina
- Arkansas
- Article 29 Working Party
- Artificial Intelligence (AI)
- Attorney General
- Audit
- Australia
- Austria
- Automated Decisionmaking
- Baltimore
- Bankruptcy
- Belgium
- Biden Administration
- Big Data
- Binding Corporate Rules
- Biometric Data
- Blockchain
- Bojana Bellamy
- Brazil
- Brexit
- British Columbia
- Brittany Bacon
- Brussels
- Business Associate Agreement
- BYOD
- California
- CalPrivacy
- CAN-SPAM
- Canada
- Cayman Islands
- CCPA
- CCTV
- Centre for Information Policy Leadership (CIPL)
- Chatbot
- Children’s Online Privacy Protection Act (COPPA)
- Chile
- China
- Chinese Taipei
- Christopher Graham
- CIPA
- Class Action
- Clinical Trial
- Cloud
- Cloud Computing
- CNIL
- Colombia
- Colorado
- Committee on Foreign Investment in the United States
- Commodity Futures Trading Commission
- Compliance
- Computer Fraud and Abuse Act
- Congress
- Connecticut
- Consent
- Consent Order
- Consumer Protection
- Consumer Rights
- Cookies
- COPPA
- Coronavirus/COVID-19
- Council of Europe
- Council of the European Union
- Court of Justice of the European Union
- CPPA
- CPRA
- Credit Monitoring
- Credit Report
- Criminal Law
- Critical Infrastructure
- Croatia
- Cross-Border Data Flow
- Cross-Border Data Transfer
- Cyber Attack
- Cybersecurity
- Cybersecurity and Infrastructure Security Agency
- Data Breach
- Data Brokers
- Data Controller
- Data Localization
- Data Minimization
- Data Privacy Framework
- Data Processor
- Data Protection Act
- Data Protection Authority
- Data Protection Impact Assessment
- Data Protection Officer
- Data Security
- Data Transfer
- David Dumont
- David Vladeck
- Deceptive Trade Practices
- Delaware
- Denmark
- Department of Commerce
- Department of Defense
- Department of Health and Human Services
- Department of Homeland Security (DHS)
- Department of Justice
- Department of the Treasury
- Design
- Digital Markets Act
- District of Columbia
- Do Not Call
- Do Not Track
- Dobbs
- Dodd-Frank Act
- DORA
- DPIA
- E-Privacy
- E-Privacy Directive
- Ecuador
- Ed Tech
- Edith Ramirez
- Electronic Communications Privacy Act
- Electronic Privacy Information Center
- Electronic Protected Health Information
- Elizabeth Denham
- Employee Monitoring
- Encryption
- ENISA
- EU Data Protection Directive
- EU General Data Protection Regulation (GDPR)
- EU Member States
- European Commission
- European Data Protection Board
- European Data Protection Supervisor
- European Parliament
- European Union
- Facial Recognition Technology
- FACTA
- Fair Credit Reporting Act
- Fair Information Practice Principles
- Federal Aviation Administration
- Federal Bureau of Investigation
- Federal Communications Commission
- Federal Data Protection Act
- Federal Trade Commission
- FERC
- Financial Data
- FinTech
- Florida
- Food and Drug Administration
- Foreign Intelligence Surveillance Act
- France
- Franchise
- Fred Cate
- Freedom of Information Act
- Freedom of Speech
- Fundamental Rights
- GDPR
- Genetic Data
- Geofencing
- Geolocation
- Geolocation Data
- Georgia
- Germany
- Global Privacy Assembly
- Global Privacy Enforcement Network
- Gramm Leach Bliley Act
- Grok
- Hacker
- Hawaii
- Health Data
- HIPAA
- HITECH Act
- Hong Kong
- House of Representatives
- Hungary
- Illinois
- India
- Indiana
- Indonesia
- Information Commissioners Office
- Information Sharing
- Insurance Provider
- Internal Revenue Service
- International Association of Privacy Professionals
- International Commissioners Office
- Internet
- Internet of Things
- Iowa
- IP Address
- Ireland
- Israel
- Italy
- Jacob Kohnstamm
- Japan
- Jason Beach
- Jay Rockefeller
- Jenna Rode
- Jennifer Stoddart
- Jersey
- Jessica Rich
- John Delionado
- John Edwards
- Kentucky
- Korea
- Large Language Model
- Latin America
- Laura Leonard
- Law Enforcement
- Lawrence Strickling
- Legislation
- Liability
- Lisa Sotto
- Litigation
- Location-Based Services
- London
- Louisiana
- Madrid Resolution
- Maine
- Malaysia
- Maryland
- Massachusetts
- Meta
- Mexico
- Michigan
- Microsoft
- Minnesota
- Missouri
- Mobile
- Mobile App
- Mobile Device
- Montana
- Morocco
- MySpace
- Natascha Gerlach
- National Institute of Standards and Technology
- National Labor Relations Board
- National Science and Technology Council
- National Security
- National Security Agency
- National Telecommunications and Information Administration
- Nebraska
- NEDPA
- Netherlands
- Nevada
- New Hampshire
- New Jersey
- New Mexico
- New York
- New Zealand
- Nigeria
- Ninth Circuit
- North Carolina
- North Dakota
- North Korea
- Norway
- Obama Administration
- OCPA
- OECD
- Office for Civil Rights (OCR)
- Office of Foreign Assets Control
- Ohio
- Oklahoma
- Online Behavioral Advertising
- Online Privacy
- Opt-In Consent
- Opt-Out
- Oregon
- Outsourcing
- Pakistan
- Parental Consent
- Payment Card
- PCI DSS
- Penalty
- Pennsylvania
- Personal Data
- Personal Health Information
- Personal Information
- Personally Identifiable Information
- Peru
- Philippines
- Poland
- PRISM
- Privacy
- Privacy and Information Security Law
- Privacy By Design
- Privacy Notice
- Privacy Policy
- Privacy Rights
- Privacy Rule
- Privacy Shield
- Profiling
- Protected Health Information
- Purpose Limitation
- Ransomware
- Record Retention
- Red Flags Rule
- Rhode Island
- Richard Thomas
- Right to Be Forgotten
- Right to Privacy
- Risk Assessment
- Risk-Based Approach
- ROSCA
- Rosemary Jay
- Russia
- Safe Harbor
- Salesforce
- Sanctions
- Schrems
- Scott Kimpel
- SECURE Data Act
- Securities and Exchange Commission
- Security Rule
- Senate
- Sensitive Data
- Serbia
- Service Provider
- Singapore
- Smart Grid
- Smart Metering
- Social Media
- Social Security Number
- South Africa
- South Carolina
- South Dakota
- South Korea
- Spain
- Spyware
- Standard Contractual Clauses
- State Attorneys General
- Steven Haas
- Stick With Security Series
- Stored Communications Act
- Student Data
- Supreme Court
- Surveillance
- Surveillance Pricing
- Sweden
- Switzerland
- Taiwan
- Targeted Advertising
- Telecommunications
- Telemarketing
- Telephone Consumer Protection Act
- Tennessee
- Terry McAuliffe
- Texas
- Text Message
- Thailand
- Transparency
- Transportation Security Administration
- Trump Administration
- United Arab Emirates
- United Kingdom
- United States
- Unmanned Aircraft Systems
- Uruguay
- Utah
- Vermont
- Video Privacy Protection Act
- Video Surveillance
- Virginia
- Viviane Reding
- Washington
- Whistleblowing
- Wireless Network
- Wiretap
- ZIP Code