Law / China

China

29 of 33 named instruments researched to a stage, across all six areas of law we track: 29 in force. As of 20 September 2026.

When they take effect28 of 29 carry a date, 1 does not. Earlier is before 2014.
Before 2014: 1 instrument (1 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 1 instrument (1 in force) 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 14 instruments (14 in force) 2022: 0 instruments 2023: 4 instruments (4 in force) 2024: 2 instruments (2 in force) 2025: 4 instruments (4 in force) 2026: 2 instruments (2 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 6
  2. Privacy law 8
  3. Scraping law 4
  4. Cybersecurity law 4
  5. Age gating law 4
  6. News aggregation law 3

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law6 instruments, 6 in force

Research summary (402 words)

China runs the most mature output-labeling regime among the jurisdictions in this batch, layered across four Cyberspace Administration of China (CAC) instruments issued between 2022 and 2026, all in effect as of 14 August 2026.

The 2022 Deep Synthesis Provisions established the first labeling duty for synthesized media; the 2023 Generative AI Interim Measures cross-reference it for generative AI specifically at Article 12 (not Article 7, which governs training-data lawfulness and sits outside this topic); the 2025 Measures for Labeling AI-Generated Synthetic Content, effective 1 September 2025 and backed by the mandatory national standard GB 45438-2025, unified explicit (user-visible) and implicit (metadata and watermark) labeling duties across five content modalities and added a platform-side duty to check uploaded content for labels; and the 2026 Interim Measures for the Administration of Anthropomorphic Interactive Services of Artificial Intelligence, effective 15 July 2026, requires providers of AI companion or emotionally-interactive services to take effective measures reminding users they are interacting with an AI system rather than a natural person, at first use, at each login, and whenever the system detects signs of user over-reliance.

GB 45438-2025 is treated as a technical annex to the 2025 Measures rather than a separate instrument here, because its text is served only by a commercial standards reseller, not by an official standards-body page. Anti-Unfair Competition Law (2025) Article 13 and Interim Measures Article 7 carry no AI-output-labeling content; each is numerically coincident with an unrelated provision inside these labeling instruments.

Two of those instruments carry a second duty recorded separately below: Article 14 of the Generative AI Measures requires a provider that discovers illegal content its service produced to stop generating and transmitting it, eliminate it, rectify the model, and report to the relevant competent authority, and to keep records and report where it discovers a user engaged in illegal activity; Article 10 of the Deep Synthesis Provisions requires a provider that discovers illegal or undesirable information to take disposal measures, keep records, and report promptly to the cyberspace administration department and the relevant competent authority.

Both are timed by the standard 及时 (promptly) rather than by a number of days or hours, and the duty on a provider that discovers a user's illegal activity under Article 14 carries no timing standard at all. The Interim Measures for the Administration of Anthropomorphic Interactive Services, read in full, carry no comparable duty to report a discovered violation to an authority.

AI governance

Interim Measures for the Management of Generative AI Services, Article 14

Interim Measures for the Management of Generative AI Services (生成式人工智能服务管理暂行办法), 2023, Art. 14official CAC notice, read and confirmed directly, including the Article 14 text

In force since 15 August 2023. Binds public and private bodies.

What this law does

Article 14 of the Interim Measures for the Management of Generative AI Services requires a provider that discovers illegal content to promptly stop generating it, stop transmitting it, eliminate it, carry out rectification such as retraining the model, and report to the relevant competent authority.

The article separately requires a provider that discovers a user has used the service for illegal activity to warn, restrict, suspend, or terminate that user's access, preserve relevant records, and report to the relevant competent authority, and it states no promptness standard for that second reporting duty.

Both duties name only the relevant competent authority as addressee, without naming the Cyberspace Administration of China by title, and this reporting duty is distinct from the content-labeling duty the same Act imposes at Article 12.

What it requires

Provisions on the Administration of Deep Synthesis Internet Information Services, Article 10

Provisions on the Administration of Deep Synthesis Internet Information Services (互联网信息服务深度合成管理规定) issued by CAC, MIIT and MPS, 2022, Art. 10official CAC notice, read and confirmed directly, including the Article 10 text

In force since 10 January 2023. Binds public and private bodies.

What this law does

Article 10 of the Provisions on the Administration of Deep Synthesis Internet Information Services requires a deep synthesis service provider to strengthen its management of deep synthesis content, review users' input data and synthesis output by technical or manual means, build a database of features for identifying illegal and undesirable information, and record and retain the related network logs.

Where the provider discovers illegal or undesirable information, the article requires it to take disposal measures and preserve relevant records in accordance with law, and to promptly report the discovery to the cyberspace administration department and the relevant competent authority, while separately taking measures such as warning, restricting features, suspending service, or closing the account against the user responsible.

Only the reporting step in that sentence carries the word 'promptly' in the text; the disposal and record-preservation steps that precede it carry no separate promptness standard of their own.

What it requires

AI transparency

Interim Measures for the Administration of Anthropomorphic Interactive Services of Artificial Intelligence, Article 18

Interim Measures for the Administration of Anthropomorphic Interactive Services of Artificial Intelligence (人工智能拟人化互动服务管理暂行办法) 2026, Art. 18official CAC notice, confirmed directly, including the Article 18 text

In force 70 days, effective 15 July 2026. Binds private bodies.

What this law does

Providers of anthropomorphic AI interactive services, products that simulate a human personality and engage in emotionally-styled conversation, must take effective measures to remind users that they are interacting with an AI service rather than a natural person, at first use and at re-login, and must dynamically re-notify users through a prominent method such as a pop-up when the system detects signs of over-reliance or addiction, or when continuous use exceeds two hours.

This is narrower than a general bot-disclosure duty: it reaches only anthropomorphic, companion-style AI interaction services, not every chatbot or AI-assisted tool. Issued jointly by the Cyberspace Administration of China, the National Development and Reform Commission, the Ministry of Industry and Information Technology, the Ministry of Public Security, and the State Administration for Market Regulation on 10 April 2026, finalized from a 27 December 2025 public-comment draft.

What it requires

Interim Measures for the Management of Generative AI Services, Article 12

Interim Measures for the Management of Generative AI Services (生成式人工智能服务管理暂行办法), 2023, Art. 12official CAC notice, quoted directly for both the effective date and the Article 7 versus Article 12 distinction

In force since 15 August 2023. Binds public and private bodies.

What this law does

Providers of generative AI services to the Chinese public must label generated content such as images and video in accordance with the Deep Synthesis Provisions' Article 16 and 17 labeling rules. This is a cross-reference duty binding generative-AI providers specifically to the general deep-synthesis labeling regime, not a freestanding labeling standard of its own.

Article 7 of the same instrument governs training-data lawfulness and has no labeling content; it is training-data territory outside this topic's scope, correcting an earlier derivation that had cited it here.

What it requires

Measures for Labeling AI-Generated Synthetic Content

Measures for Labeling AI-Generated Synthetic Content (国信办通字〔2025〕2号), issued by CAC, MIIT, MPS and NRTA, 2025, Arts. 4-5official CAC notice, confirmed directly

In force since 1 September 2025. Binds public and private bodies.

What this law does

Internet information service providers must add an explicit, user-perceptible marker to AI-generated or AI-synthesized text, image, audio, video, and virtual-scene content, and must embed an implicit, machine-readable identifier in file metadata carrying generation attributes and the provider's name or code. Content-distribution platforms must check incoming content for labels and add a risk prompt to unlabeled or suspected-generated content.

No person or organization may maliciously delete, alter, forge, or conceal a required label. The accompanying mandatory national standard GB 45438-2025 sets the technical parameters for both label types and takes effect the same date; no official standards-body URL for GB 45438-2025 is available independent of a commercial reseller, so it is described here rather than authored as its own instrument.

What it requires

Provisions on the Administration of Deep Synthesis Internet Information Services, Articles 16 and 17

Provisions on the Administration of Deep Synthesis Internet Information Services (互联网信息服务深度合成管理规定) issued by CAC, MIIT and MPS, 2022, Arts. 16-17official CAC notice, read and confirmed directly, including the Article 16 and Article 17 text

In force since 10 January 2023. Binds public and private bodies.

What this law does

Deep-synthesis service providers must apply a technical measure to label content generated or edited using their service without interfering with normal use, and retain log information as required.

Where a listed category of service could cause public confusion, simulated dialogue or writing, synthesized or altered voice, face generation or face-swap, or immersive simulated-scene generation, the provider must apply a prominent label alerting the public to the deep-synthesis nature of the content. This is the earliest of China's four labeling instruments and is the one the 2023 Generative AI Interim Measures cross-references.

What it requires

Privacy law8 instruments, 8 in force

Research summary (190 words)

China's Personal Information Protection Law (PIPL, in Chinese the Ge Ren Xin Xi Bao Hu Fa) has been continuously in force since 1 November 2021 as a comprehensive omnibus regime binding both private and public-sector processors, built on enumerated lawful bases, heightened separate-consent duties for a defined class of sensitive personal information that expressly includes biometric identifiers, individual and public-interest civil remedies under a burden of proof shifted onto the processor, and multi-agency enforcement with fines of up to 5 percent of annual revenue.

A dedicated 2025 CAC/Ministry of Public Security regulation adds detailed facial-recognition-specific duties (separate consent, on-device storage, a ban on facial recognition as the sole verification method); no comparably dedicated voiceprint statute exists, so voiceprint remains covered only by PIPL's general biometric category, though a January 2026 CAC draft not yet finalized would extend on-device-storage rules to fingerprint and voiceprint alongside facial data.

Cross-border transfer was tightened by PIPL itself in 2021 and then substantially relaxed by volume-based exemptions in a 2024 CAC regulation, so that most ordinary transfers today clear with no mechanism at all and only large-scale or critical-infrastructure exports face the full security assessment.

Biometric privacy

Provisions on Security Management of Facial Recognition Technology Application

人脸识别技术应用安全管理办法 issued jointly by the Cyberspace Administration of China and the Ministry of Public Security, signed 13 March 2025, effective 1 June 2025official CAC-published regulation text

In force since 1 June 2025. Binds public and private bodies.

What this law does

China's first dedicated facial-recognition regulation requires voluntary, explicit, separately-obtained consent before capturing facial information, with guardian consent for a minor under 14, and requires using the method with the least impact on individual rights available.

It mandates that facial data be stored on the collecting device rather than transmitted over the internet absent a legal exception or separate consent, caps retention at the minimum necessary period, bars facial recognition as the sole identity-verification method wherever another method exists, bans facial recognition devices inside private spaces within public venues such as hotel rooms and changing rooms, and requires a processor holding facial data on 100,000 or more people to file with the provincial cyberspace authority.

No comparably dedicated voiceprint regulation exists; a January 2026 CAC draft for public comment would extend this same on-device-storage approach to fingerprint and voiceprint data, but it had not been finalized as of the date shown and is not authored as its own instrument here. Article 2 carves facial-recognition R&D and algorithm-training activities out of the Measures' scope, so the duties below bind deployment and use, not model training (第二条: 不适用本办法的规定).

What it requires

Breach notification

Personal Information Protection Law, Data Breach Notification

PIPL Art. 57official CAC-published full Chinese statutory text

In force since 1 November 2021. Binds public and private bodies.

What this law does

Upon discovering an actual or possible leak, tampering, or loss of personal information, a handler must immediately take remedial measures and notify both the department responsible for personal information protection and the affected individuals, with the notice covering the categories of information involved, the cause, possible harm, remedial measures, mitigation steps for individuals, and the handler's contact information.

Individual notice may be omitted where remedial measures can be shown to effectively prevent harm, unless the supervisory department requires notice anyway. The statute requires action taken immediately rather than setting a fixed numeric deadline such as 72 hours.

What it requires

Comprehensive regime

Personal Information Protection Law of the PRC, General Processing Rules and Lawful Bases

PIPL Arts. 1-23, 33-37; adopted by the Standing Committee of the 13th National People's Congress, 20 August 2021; effective 1 November 2021official CAC-published full Chinese statutory text

In force since 1 November 2021. Binds public and private bodies.

What this law does

China's omnibus personal-data statute (Ge Ren Xin Xi Bao Hu Fa, Personal Information Protection Law) requires a lawful basis, most commonly informed consent, before processing personal information, and otherwise contract necessity, statutory duty, public-interest journalism, information the individual or another lawfully disclosed, or another legal ground.

It imposes purpose-limitation and data-minimization duties, requires a handler that entrusts processing to a third party to supervise that processor's activity under an agreement, and assigns joint and several liability among two or more processors who jointly decide a shared processing purpose and method. Chapter II, Section 3 (Arts. 33-37) extends parallel duties to state organs, so the Act binds government processors as well as private ones.

What it requires

Cross border transfer

Personal Information Protection Law, Cross-Border Transfer

PIPL Arts. 38-40official CAC-published full Chinese statutory text

In force since 1 November 2021. Binds public and private bodies.

What this law does

Article 38 requires one of a CAC-organized security assessment, personal-information-protection certification, a CAC standard contract, or another state-recognized mechanism before transferring personal information outside China, plus assurance the overseas recipient meets PIPL's protection standard. Article 39 requires advance notice naming the recipient and purpose and separate consent.

Article 40 requires domestic storage for critical information infrastructure operators and above-threshold handlers, with export gated on a security assessment. The 2024 CAC Provisions on Promoting and Regulating Cross-Border Data Flows (a separate instrument) substantially relax these mechanisms by transfer volume.

What it requires

Provisions on Promoting and Regulating Cross-Border Data Flows

促进和规范数据跨境流动规定, issued by the Cyberspace Administration of China, effective 22 March 2024official CAC promulgation notice for the Provisions

In force since 22 March 2024. Binds public and private bodies.

What this law does

This CAC regulation relaxes PIPL Article 38's cross-border transfer mechanisms by transfer volume, recited in the CAC promulgation notice. Exporting under 100,000 individuals' non-sensitive personal information in a year, or a listed necessary-business category such as contract performance, cross-border human-resources management, or emergency protection of life or property, needs no security assessment, standard contract, or certification at all.

Exporting 100,000 to under 1,000,000 individuals' non-sensitive personal information, or under 10,000 individuals' sensitive personal information, needs a standard contract or certification. Exporting 1,000,000 or more individuals' non-sensitive personal information, or 10,000 or more individuals' sensitive personal information, or any export by a critical information infrastructure operator, needs the full CAC security assessment. Free trade zones may adopt their own negative lists further narrowing what requires a mechanism.

What it requires

Data subject rights

Personal Information Protection Law, Individual Rights and Automated Decision-Making

PIPL Arts. 24, 44-50, 55(2)official CAC-published full Chinese statutory text

In force since 1 November 2021. Binds public and private bodies.

What this law does

Individuals have the right to know about and decide on processing, and to limit or refuse it (Art. 44), the right to access and copy their data including portability to another handler under state conditions (Art. 45), the right to correction or completion (Art. 46), the right to deletion in enumerated circumstances with cessation of active processing as a fallback where deletion is technically infeasible (Art. 47), and the right to an explanation of processing rules (Art. 48).

Article 50 requires a convenient exercise mechanism, a reasoned explanation for any refusal, and permits a court suit if a request is unreasonably denied.

Article 24 separately requires transparent, non-discriminatory treatment of automated-decision-making results, prohibits unreasonable differential pricing, requires a non-personalized option or opt-out where automated decisions push marketing, and gives an individual a right to explanation and to refuse a decision made solely by automated means where it has a major effect on their rights, with Article 55(2) requiring a personal-information-protection impact assessment before deploying automated decision-making.

What it requires

Enforcement supervision

Personal Information Protection Law, Supervision and Legal Liability

PIPL Arts. 60-71official CAC-published full Chinese statutory text

In force since 1 November 2021. Binds public and private bodies.

What this law does

The Cyberspace Administration of China leads coordination, with sectoral State Council departments and their local counterparts supervising within their own scope; investigative powers include interviews, record examination, on-site inspection, and, with approval, seizure of equipment.

Ordinary violations draw a warning, confiscation of gains, and service suspension, escalating on non-correction to fines up to RMB 1,000,000 for the entity and RMB 10,000 to 100,000 for the responsible individual; grave violations draw fines up to RMB 50,000,000 or 5 percent of the prior year's revenue, possible business suspension or license revocation, individual fines of RMB 100,000 to 1,000,000, and a bar on serving as a director, supervisor, senior manager, or protection officer of a related enterprise.

A handler that cannot prove itself free of fault bears civil compensation liability, and procuratorates and designated organizations may bring public-interest suits over mass violations.

What it requires

Sensitive categories

Personal Information Protection Law, Sensitive Personal Information

PIPL Arts. 28-32official CAC-published full Chinese statutory text

In force since 1 November 2021. Binds public and private bodies.

What this law does

Article 28 defines sensitive personal information as information whose leak or misuse would easily harm dignity or personal or property safety, expressly including biometric identification information (covering both faceprint and voiceprint as instances of the same category) alongside religious belief, specific identity, medical health, financial accounts, and location tracking, and extends automatically to a minor's information under 14.

Article 29 requires separate, explicit consent before processing any sensitive personal information, layered on top of the general lawful-basis requirement, Article 30 requires advance notice of necessity and impact, and Article 31 requires guardian consent for a minor's data. The biometric definition carries no exclusion for an identifier extracted from an existing photo, video, or audio recording.

What it requires

Scraping law4 instruments, 4 in force

Research summary (232 words)

China has no single scraping statute. The strongest and most current authority is the 2025 revision of the Anti-Unfair Competition Law, effective October 15, 2025, which added a purpose-built clause against obtaining or using another business's data by fraud, coercion, or defeating technical access controls, codifying a decade of case law that had reached the same result under the law's older general clause.

Outside that, the Personal Information Protection Law permits processing personal information a person has already made public, within a reasonable scope and subject to opt-out, and the Copyright Law's closed list of exceptions has no text-and-data-mining item, so no codified basis exists for training on copyrighted scraped content. China has no sui generis database right; compilation copyright and the unfair-competition clause do that work instead.

The computer-intrusion provisions of the Criminal Law, Arts. 285 and 286, remain unread against official primary text: eight URLs across five official domains (npc.gov.cn, flk.npc.gov.cn, spp.gov.cn, court.gov.cn, mps.gov.cn) serve only JavaScript shells or server errors, never a CAPTCHA, so that instrument stays secondary-sourced here. robots.txt carries no independent statutory weight; a national technical standard said to accompany the 2023 Generative AI Interim Measures reportedly requires respecting a target site's robots.txt for AI training data collection, but its binding status was not independently confirmed and it is not recorded as its own instrument here.

As a unitary jurisdiction, China has no subnational divergence to research.

Computer misuse

Criminal Law, Arts. 285-286 (unauthorized computer intrusion and system destruction)

Criminal Law of the People's Republic of China, Arts. 285, 286Lawinfochina/PKULAW English translation (secondary publisher)

In force. Binds public and private bodies.

What this law does

Article 285(1) criminalizes intrusion into state-affairs, defense, or advanced-science computer systems; Art. 285(2), added by the 2009 Amendment VII, reaches intrusion into other systems, or other technical means, to obtain their data or illegally control them, where the circumstances are serious; Art. 286 criminalizes destroying a computer system's function, data, or programs.

These target circumvention and intrusion, not mere collection of what a system already makes public, and no top-level case construing authorization as narrowly as the United States' Van Buren was found for a scraping fact pattern.

This instrument is secondary-sourced only: official primary text was sought at eight URLs across five official domains (npc.gov.cn, flk.npc.gov.cn, spp.gov.cn, court.gov.cn, mps.gov.cn), and every one serves either a JavaScript shell, a server error, or (at flk.npc.gov.cn) a single-page app whose article text loads by a client-side mechanism; no CAPTCHA appears anywhere.

This is a confirmed access-tier gap, not a finding about the law, and it must not be presented as verified against primary text.

What it requires

Personal data

Personal Information Protection Law, Arts. 13(6) and 27 (processing already-public personal information)

Personal Information Protection Law of the People's Republic of China, Arts. 13(6), 27official text, Cyberspace Administration of China (cac.gov.cn)

In force since 1 November 2021. Binds public and private bodies.

What this law does

Article 27 permits a personal information handler to process, within a reasonable scope, personal information an individual has disclosed themselves or that is otherwise lawfully public, unless the individual has expressly declined; processing that has a significant impact on the individual still needs separate consent.

Article 13(6) states the same ground as a general lawful basis for processing, functioning as China's analog to General Data Protection Regulation (GDPR) Art. 6(1)(f), with its own reasonable-scope ceiling and opt-out rather than a legitimate-interest balancing test.

The 2023 Generative AI Interim Measures additionally require a lawful source for AI training data, which for personal information means satisfying this Article 27 basis; that measure's own robots.txt-related technical standard is not independently confirmed and is not recorded as its own instrument here.

What it requires

Unfair competition

Anti-Unfair Competition Law, 2025 revision, Article 13 (data scraping and technical circumvention clause)

Anti-Unfair Competition Law of the People's Republic of China (as amended 2025), Art. 13official text, China National Intellectual Property Administration (cnipa.gov.cn)

In force 11 months, effective 15 October 2025. Binds private bodies.

What this law does

The third paragraph of the amended Article 13 prohibits a business operator from obtaining or using, by fraud, coercion, or by evading or destroying technical management measures, data lawfully held by another business operator, where doing so harms that operator's lawful rights and interests and disrupts market competition order. This is China's first purpose-built statutory scraping clause and took effect October 15, 2025, with no reported case applying it yet.

It codifies the result courts had already reached under the law's older general clause: Beijing IP Court held in Sina Weibo v. Maimai (Dec.

2016, secondary-sourced) that reusing API data after a partnership ended was unfair competition under a triple-authorization principle, and Shanghai Pudong New Area People's Court held in Hantao (Dianping) v. Baidu (26 May 2016, secondary-sourced) that spidering reviews into a competing product was an unfair substantive substitute for the source's own product.

What it requires

Cybersecurity law4 instruments, 4 in force

Research summary (835 words)

China's product-security and cyber-resilience law rests on the Cybersecurity Law of the People's Republic of China, substantively amended by a decision of the Standing Committee of the National People's Congress adopted October 28, 2025 and promulgated the same day by Presidential Order No. 61, with the amended text in force since January 1, 2026, read together with the Data Security Law, in force since September 1, 2021.

Article 24 of the amended Cybersecurity Law binds a provider of a network product or service, a role a manufacturer or software distributor occupies and distinct from the broader network-operator classification the same law also uses, to meet the mandatory requirements of the applicable national standard, refrain from embedding a malicious program, and, on discovering a security defect or vulnerability, immediately take remedial measures, notify affected users, and report to the competent authority, while providing continuous security maintenance for the product's or service's stated support period; the statute states no numeric clock for that notice, only immediacy.

Articles 27 and 29 of the Data Security Law impose a parallel, sector-neutral pair of duties on any organization or individual engaging in a data-processing activity: a full-process data-security management system with staff education and training (Article 27), and a duty to strengthen risk monitoring, remediate a discovered data-security defect or vulnerability immediately, and, on an actual data-security incident, take disposal measures and notify users and the competent authority (Article 29), again with no numeric clock in the text.

Article 30 of the same law additionally requires a processor of important data (an official classification of data whose compromise could harm national security, the economy, or public health and safety, not an activity a developer declares) to conduct a periodic risk assessment of its data-processing activities and file the report with the competent authority; because that duty attaches to the important-data classification rather than to any activity in the corpus vocabulary, it is not flagged as its own instrument here.

Two further regimes bind by a classification the vocabulary cannot express and are recorded here rather than flagged.

The Cybersecurity Law's own classified-protection system (Article 23, referred to in practice as the multi-level protection scheme and implemented in more technical detail by the national standard GB/T 22239-2019, colloquially 'MLPS 2.0') and its critical-information-infrastructure operator provisions (Articles 33 to 41, elaborated by the Regulation on the Security Protection of Critical Information Infrastructure, State Council Order No. 745, approved April 27, 2021 and effective September 1, 2021) both bind a network operator or a critical-information-infrastructure operator by classification, so neither is raised as an instrument.

A standalone administrative regulation intended to elevate the classified-protection system above departmental-rule status, the Regulation on the Classified Protection of Cybersecurity, has been in drafting since the Ministry of Public Security's 2018 public-comment draft; secondary reporting places it on the State Council's legislative-preparation list for both 2025 and 2026, but no promulgated text was located, so it remains unenacted.

The National Cybersecurity Incident Reporting Measures (国家网络安全事件报告管理办法, "Measures for the Administration of National Cybersecurity Incident Reporting"), issued by the Cyberspace Administration of China on September 11, 2025 and in force since November 1, 2025, supply the operative reporting clock once an incident occurs, and are raised below as their own instrument.

They bind a network operator, meaning any organization that owns or manages a network or provides services over one, so the instrument flags every activity and every role rather than a narrower class and states that scope condition in its first duty line.

The Regulation on Network Data Security Management (State Council Order No. 790, adopted August 30, 2024, in force since January 1, 2025) elaborates the Data Security Law's important-data duties, requiring a network data processor to identify and file important data against a catalogue, designate a data-security officer and a managing body, and, as an important-data processor, complete an annual risk assessment; this summary draws on the Cyberspace Administration of China's own published account of the Regulation, since the Regulation's own text serves only a JavaScript shell, and the same account's provisions on personal information and cross-border data flow are this jurisdiction's privacy row rather than repeated here.

China's breach-notification duty for personal information sits at Article 57 of the Personal Information Protection Law, already this jurisdiction's privacy row. An unauthorized-access or system-destruction offense against a network sits at Articles 285 and 286 of the Criminal Law, already this jurisdiction's scraping row (the computer_misuse family) and not a security-topic presence on its own.

Enforcement of the duties described here is administrative only, by the competent department with jurisdiction over the network operator or the product or service provider, coordinated nationally by the Cyberspace Administration of China; neither the Cybersecurity Law nor the Data Security Law creates a distinct private right of action, though both preserve an injured party's ordinary civil claim for damages caused by a violation, and a breach that also constitutes a crime, most sharply a violation of the national core data management system under Data Security Law Article 45, can draw criminal liability.

Product security requirements

Cybersecurity Law, Network Product and Service Security Duties

Cybersecurity Law of the People's Republic of China (as amended by the Decision of October 28, 2025, effective January 1, 2026), Art. 24Official consolidated text

In force 9 months, effective 1 January 2026. Binds private bodies.

What this law does

A provider of a network product or service must ensure the product or service meets the mandatory requirements of the relevant national standard and must not embed a malicious program in it. On discovering that its product or service has a security defect, vulnerability, or other risk, the provider must immediately take remedial measures and, as provided, promptly notify users and report to the competent authority.

The provider must continuously maintain the product's or service's security and must not terminate that maintenance within the period fixed by regulation or agreed with the user. Where the product or service collects user information, the provider must disclose that collection and obtain consent, and, where personal information is involved, comply with this Law's and the Personal Information Protection Law's rules on personal information.

An ordinary violation draws a corrective order, a warning, and a fine of 50,000 to 500,000 yuan if the provider refuses to correct or the violation endangers network security, with a further escalation, cross-referenced from Article 61's third paragraph, of 500,000 to 2,000,000 yuan for causing a large-scale data leak or the loss of a local function of critical information infrastructure, and 2,000,000 to 10,000,000 yuan where critical information infrastructure loses a primary function.

What it requires

Security baseline statutes

Data Security Law, Data Security Protection Obligations

Data Security Law of the People's Republic of China, Art. 27Official statute text, cac.gov.cn (sourced to Xinhua News Agency), Data Security Law of the People's Republic of China

In force since 1 September 2021. Binds private bodies.

What this law does

Any organization or individual engaging in a data-processing activity must, under the law and administrative regulations, establish and improve a full-process data-security management system, organize data-security education and training, and take the technical measures and other necessary measures appropriate to keep the data secure.

Where a data-processing activity is conducted using the internet or another information network, this data-security duty applies on top of, not instead of, the network operator's classified-protection duty under the Cybersecurity Law. A processor of important data must designate a person responsible for data security and a managing body, and implement that responsibility.

An ordinary violation draws a corrective order and a warning, escalating to a fine of 50,000 to 500,000 yuan, with a further escalation to 500,000 to 2,000,000 yuan for refusing to correct or causing a large-scale data leak or another serious consequence; a violation of the separate national core data management system carries its own, heavier fine of 2,000,000 to 10,000,000 yuan and can draw criminal liability, but that heavier tier is not this duty.

What it requires

Vulnerability and incident reporting

Data Security Law, Risk Monitoring and Incident Reporting Duty

Data Security Law of the People's Republic of China, Art. 29Official statute text, cac.gov.cn (sourced to Xinhua News Agency), Data Security Law of the People's Republic of China

In force since 1 September 2021. Binds private bodies.

What this law does

Any organization or individual engaging in a data-processing activity must strengthen risk monitoring and, on discovering a data-security defect, vulnerability, or other risk, immediately take remedial measures. On an actual data-security incident, the organization or individual must immediately take disposal measures, promptly notify affected users as provided, and report the incident to the competent authority.

The statute sets no numeric deadline for that notice or report, only immediacy and promptness; the National Cybersecurity Incident Reporting Measures set an operative reporting clock for such an incident, but bind by a network-operator classification recorded in the jurisdiction summary rather than raised as an instrument here.

The penalties for a violation are the same tiered fines as this jurisdiction's Data Security Law data-security-program row, since Article 45 punishes a failure under Articles 27, 29, and 30 together.

What it requires

National Cybersecurity Incident Reporting Measures

Measures for the Administration of National Cybersecurity Incident Reporting (Cyberspace Administration of China, issued September 11, 2025) Arts. 2, 4, 5, 8, 9, 12, 14Official text

In force 11 months, effective 1 November 2025. Binds public and private bodies.

What this law does

A network operator that builds or operates a network, or provides a service through a network, within the territory of China must report a cybersecurity incident under these Measures. These Measures define a network operator as the owner, manager, or network service provider of a network.

These Measures also define a cybersecurity incident as an event that, due to human causes, a network attack, a network vulnerability or hidden danger, a hardware or software defect or malfunction, force majeure, or another factor, harms a network or information system or the data and business applications within it and has a negative impact on the state, society, or the economy.

On discovering or becoming aware of an incident involving its own unit, a network operator must grade the incident against the annexed National Cybersecurity Incident Classification and Grading Guide and report only where the grade is relatively major or above. Where the incident involves critical information infrastructure, the operator must report to the sector's protection-work department and to the public security organ within 1 hour of discovering or becoming aware of it.

A network operator that is a department of a central or state organ, or a directly affiliated unit of one, must report to its own department's cyberspace affairs unit within 2 hours. Every other network operator must report to the cyberspace administration department of its own province within 4 hours.

A major or especially major incident escalates further between the government bodies that received the operator's report, up to the national cyberspace administration, without imposing any additional step on the reporting operator itself.

A network operator must require, by contract, any organization or individual providing it network-security or system-operation-and-maintenance services to promptly report to it any cybersecurity incident that provider discovers through monitoring, and to assist the operator's own reporting under these Measures.

Within 30 days of completing disposal of a relatively major incident or above, the operator must submit a summary report on the incident's cause, its emergency response, the harm caused, accountability, remediation, and lessons learned, through the same channel used for the original report.

A failure to report as required draws a penalty under other law, and reporting late, missing a report, or filing a false or concealed report that causes major harm draws a heavier penalty on the operator and its responsible persons. An operator that took reasonable and necessary protective measures, disposed of the incident under its emergency plan, effectively reduced the incident's impact, and reported it as required may be treated leniently or not held accountable at all.

A report involving a state secret follows the rules of the relevant department instead of the general channel described here.

What it requires

Age gating law4 instruments, 4 in force

Research summary (138 words)

China regulates minors' internet and gaming access through a layered regime anchored in the 2020 revision of the Law on the Protection of Minors (Chinese: 未成年人保护法, effective June 1, 2021), which requires online game, livestreaming, audio-video and social platforms to build in time, permission and spending management functions for minors, and bars livestreaming anchor accounts for anyone under 16.

The State Council's Regulations on the Protection of Minors in Cyberspace (Chinese: 未成年人网络保护条例, State Council Order No. 766, effective January 1, 2024) implement a mandatory minor mode across these services with age-tiered spending caps and age-appropriate rating disclosure.

The National Press and Publication Administration separately caps minors' online game time at one hour a day, only between 20:00 and 21:00 on Fridays, Saturdays, Sundays and legal holidays, under a 2021 notice tied to a national real-name anti-addiction verification system.

Age-appropriate design code

国家新闻出版署《关于进一步严格管理 切实防止未成年人沉迷网络游戏的通知》(NPPA Notice on Further Strict Management to Effectively Prevent Minors from Becoming Addicted to Online Games)

国新出发〔2021〕14号 (Guo Xin Chu Fa [2021] No. 14)official notice text, National Press and Publication Administration (NPPA) portal

In force since 1 September 2021. Binds private bodies.

What this law does

Limits all online game service providers to offering minors no more than one hour of game time per day, only between 20:00 and 21:00 on Fridays, Saturdays, Sundays and legal holidays, with no game service to minors at any other time. Requires every online game account to be registered under a real identity linked to the National Press and Publication Administration's national anti-addiction real-name verification system, and bans guest-mode access.

Note and primary source

未成年人保护法 (Law on the Protection of Minors), Chapter 5 Network Protection, Articles 74-75

未成年人保护法 (Law on the Protection of Minors) 2020 Revision, adopted 2020-10-17 by the Standing Committee of the 13th National People's Congress, Arts. 74-75official consolidated text, Cyberspace Administration of China (CAC) portal

In force since 1 June 2021. Binds private bodies.

What this law does

Requires providers of online games, livestreaming, audio-video and social networking services to build in time management, permission management and spending management functions for minor users, and requires online game providers to use a unified national electronic identity system to verify that game accounts are registered under the user's real identity, with no game service offered to minors between 22:00 and 08:00.

Note and primary source

未成年人网络保护条例 (Regulations on the Protection of Minors in Cyberspace), State Council Order No. 766

国务院令第766号, 未成年人网络保护条例 (State Council Order No. 766, Regulations on the Protection of Minors in Cyberspace), Chapter 5, Arts. 39-49official text, State Council Gazette, mirrored on the Cyberspace Administration of China (CAC) portal

In force since 1 January 2024. Binds private bodies.

What this law does

Implementing regulation requiring game, livestream, audio-video and social platforms to provide a minor mode limiting usage time, functions and content per national standards, to reasonably cap single and cumulative spending by minors by age band, to prevent traffic-driven inducements such as fan voting campaigns aimed at minors, and to display age-appropriate ratings prominently at download and login.

Note and primary source

Social media and minors

未成年人保护法 (Law on the Protection of Minors), Article 76, livestreaming anchor account age floor

未成年人保护法 (Law on the Protection of Minors), 2020 Revision, Art. 76official consolidated text, Cyberspace Administration of China (CAC) portal

In force since 1 June 2021. Binds private bodies.

What this law does

Bars livestreaming service providers from issuing a livestreaming anchor (content creator) account to anyone under 16, and requires providers to obtain a parent or guardian's consent and verify identity before issuing an anchor account to a 16 or 17 year old.

Note and primary source

News aggregation law3 instruments, 3 in force

Research summary (298 words)

China has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; a general copyright exception and a content-licensing regime specific to online news together govern an aggregator's reproduction of news content.

Article 5(2) of the Copyright Law (2020 revision) excludes 单纯事实消息 (pure factual news items) from copyright protection outright, and Article 24(2)-(4) separately lets any person quote a published work for comment, unavoidably reproduce or quote a published work when reporting news, or reprint another outlet's already-published current-affairs commentary on political, economic, or religious questions absent a rights-holder reservation; none of these exceptions is capped at a headline-length or short-extract threshold, and no reported Chinese decision applies them to a systematic news aggregator as opposed to traditional press reporting.

Separately, the Cyberspace Administration of China's Provisions on the Administration of Internet News Information Services (2017) require a government licence before any organisation may operate a service that gathers, republishes, or platforms news information, and Article 15 conditions any reprinting of another outlet's news on sourcing it from a state-approved list of news units and crediting the original source, author, and title, a duty distinct from and additional to copyright law.

The State Council's Regulation on the Protection of the Right to Network Dissemination of Information (2013 revision) gives a search-or-link service provider a safe harbour from damages once it disconnects a link on a rights-holder's written notice, unless it knew or should have known the linked content was infringing, through the same notice-and-counter-notice procedure that governs a hosting provider's own safe harbour.

China has no compelled platform-to-publisher bargaining regime, no recognised hot-news or misappropriation doctrine distinct from ordinary unfair-competition law, and no machine-readable text-and-data-mining opt-out mechanism; as a unitary jurisdiction, it has no subnational divergence to research. English renderings of the quoted Chinese text below are unofficial.

Linking and framing

Regulation on the Protection of the Right to Network Dissemination of Information, linking safe harbour and notice-and-takedown (Arts. 14-17, 23)

Regulation on the Protection of the Right to Network Dissemination of Information State Council Order No. 468 (2006), as amended 2013, Arts. 14-17, 23official text, Ministry of Justice National Administrative Regulations Database (xzfg.moj.gov.cn)

In force since 1 July 2006. Binds public and private bodies.

What this law does

Article 23 gives a network service provider that offers a search or link service a safe harbour from damages liability once, on receiving a rights holder's written notice, it disconnects the link to the allegedly infringing work, unless it knew or should have known that the linked work was infringing, in which case it bears joint infringement liability.

That safe harbour runs through the same notice-and-counter-notice mechanism the Regulation gives a hosting provider under Article 22: Article 14 requires a rights holder's takedown notice to name the rights holder, identify the work and its network address, and include preliminary proof of infringement; Article 15 requires the provider to act on it immediately, forwarding the notice to the party that supplied the material; and Articles 16-17 let that party submit a written counter-statement to have the material or link restored, after which the rights holder may not issue a further notice over the same material.

The Regulation was promulgated by State Council Order No. 468 on 18 May 2006 and amended by a State Council decision dated 30 January 2013; the currently effective text's own commencement article states an effective date of 1 July 2006. No reported Chinese decision applies Article 23 specifically to a news aggregator's display of links to third-party journalism, as opposed to file-hosting or search-engine link cases generally.

Note and primary source

Provisions on the Administration of Internet News Information Services, licensing and reprint sourcing duties (Arts. 5-6, 11, 15)

Provisions on the Administration of Internet News Information Services Cyberspace Administration of China Order No. 1 (2017), Arts. 5-6, 11, 15official text, Cyberspace Administration of China (cac.gov.cn)

In force since 1 June 2017. Binds public and private bodies.

What this law does

Article 5 requires any organisation providing an internet news information service to the public, including a news-reprinting service or a news-dissemination platform service, to first obtain an internet news information service licence, and bans operating such a service without one or beyond its scope.

Article 6 conditions that licence on the applicant being a legal person lawfully established within China, having a PRC-citizen principal officer and editor-in-chief, and maintaining dedicated editorial, content-review, and technical-security staff and systems; an entity applying specifically to gather and publish news must itself be a news organisation or a unit under a news-and-propaganda department's supervision.

Article 11 requires a licensed provider to appoint an editor-in-chief who bears overall responsibility for its news content and to register that person with the cyberspace administration.

Article 15 conditions any reprinting of news information on sourcing it only from central news organisations or provincial-level and above news organisations within a state-designated list, on crediting the original source, author, original headline, and editor, on not distorting the original headline's meaning or the news content, on keeping the source traceable, and on separately complying with copyright law.

This is a licensing and content-control regime enforced by the Cyberspace Administration of China, distinct from and additional to the Copyright Law's own exceptions, and no equivalent duty runs to an aggregator that only links to, rather than reprints, another outlet's news.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.