惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
大猫的无限游戏
大猫的无限游戏
博客园 - 聂微东
Jina AI
Jina AI
The Cloudflare Blog
V
Visual Studio Blog
博客园_首页
量子位
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 【当耐特】
爱范儿
爱范儿
博客园 - 三生石上(FineUI控件)
小众软件
小众软件
博客园 - 司徒正美
阮一峰的网络日志
阮一峰的网络日志
Last Week in AI
Last Week in AI
V
V2EX
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 叶小钗
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
WordPress大学
WordPress大学
宝玉的分享
宝玉的分享
T
Tailwind CSS Blog
博客园 - Franky

Privacy & Cybersecurity Law Blog

EU Cyber Resilience Act Reporting Obligations Take Effect for Manufacturers Delaware Expands State Privacy Law Dutch DPA Fines Uber Over Automated Decisions Affecting Drivers European Commission Designates ChatGPT, Reddit, and Roblox Under the Digital Services Act Court Approves Meta Settlement With 29 States Over Alleged Harms to Children and Teens FTC Proposes Enforcement Policy Statement on Personalized Pricing New Jersey Enacts the Kids Code Act with Privacy-by-Default and Safety-by-Design Obligations White House Memorandum Establishes Framework for Government-Directed Private-Sector Cyber Operations FTC, California and Utah Sue Telehealth Company Hims & Hers for Deceptive and Unlawful Privacy Practices CalPrivacy Settles with Two Data Brokers over Registration Failures and Privacy Violations New York Attorney General Releases Final Rules for SAFE for Kids Act EDPB Adopts Guidelines on Anonymous Data, Web Scraping, and Blockchain China Publishes Official Q&A on Administrative Policies for Cross-Border Data Transfers Hawaii Enacts AI Companion Disclosure and Safety Law EDPB Calls for Review of EU-U.S. Data Privacy Framework After U.S. Supreme Court Decision on FTC Independence CNIL Issues FAQs on Recommendation for Tracking Pixels in Emails European Commission Issues Guidance on the Cyber Resilience Act European Commission Issues EU AI Act Transparency Guidelines EU Digital Omnibus on AI Enters Into Force Connecticut AG Leads Multistate Settlement With 23andMe Over 2023 Data Breach CalPrivacy Targets Gig Economy Tech Platforms in First CCPA Compliance Audit New Jersey Adopts New Data Broker Registration Regime and Sensitive Data Sale and Licensing Restrictions CISA Plans to Finalize Cyber Incident Reporting Regulations in September 2026 Illinois Governor Signs Frontier AI Model Law New Hampshire Amends the NHDPA to Prohibit the Sale of Children’s Personal Data Canada’s Proposed Social Media Ban for Children and Chatbot Regulation: Bill C-34’s Impact on Platforms European Commission Unveils Cybersecurity and AI Action Plan European Commission Refers Four Member States to CJEU Over NIS2 Transposition Delays EDPB Opens Public Consultation on New Personal Data Breach Notification Template European Commission Advances New Proposal to Expand Cloud Capacity and AI Infrastructure
China Issues New Rules on Cyberspace Security Inspection
2026-09-02 · via Privacy & Cybersecurity Law Blog

China Issues New Rules on Cyberspace Security Inspection

On August 6, 2026, the Ministry of Public Security of the People’s Republic of China (“MPS”) promulgated the Measures for Public Security Organs’ Supervision and Inspection of Cyberspace Security (the “New Rules on Cyberspace Inspection”). The New Rules on Cyberspace Inspection will take effect October 1, 2026, and replace the 2018 Provisions on Internet Security Supervision and Inspection by Public Security Organs, which are simultaneously repealed.

The main provisions include the following:

  • Consolidation and modernization of the police’s authority to inspect compliance with China’s cybersecurity, data security, and personal information protection regime. This brings MPS’ enforcement practice closer into alignment with the Cybersecurity Law, the Data Security Law, the Personal Information Protection Law, the Critical Information Infrastructure (“CII”) Protection Regulation and the Network Data Security Management Regulation.
  • Regulation of parties including Internet service providers, public Internet access venues, network operators and their contractors, CII operators, providers of network products and services, and data and personal data handlers. Entities that have previously experienced cybersecurity or data security incidents, or that have been subject to administrative penalties for failing to fulfill their statutory obligations regarding cybersecurity, data security, or information security and that have not made the required corrections, will be subject to priority oversight and inspection.
  • Establishment of two inspection processes: online monitoring and on-site inspections. (1) Online monitoring covers network patrols, information-review capability testing, and vulnerability scanning. It can be conducted without disrupting normal business operations, though capability testing requires three working days’ advance notice. Prefecture-level and higher public security organs may also carry out remote technical testing, including vulnerability probing and penetration testing, against network facilities outside CII. This is subject to three days’ notice, and there must be no disruption to normal operations. The findings must be shared with the same-level cyberspace administration and relevant industry regulator. (2) By contrast, on-site inspections are reserved for county-level and higher authorities in the jurisdiction where the network operator is based. On-site inspections must involve at least two officers presenting police credentials and a written inspection notice. These inspections are capped at one routine visit per year for MLPS Level 3-and-above networks and CII operators.
  • Conduct by MPS and its local counterparts of supervisory inspections to verify compliance with statutory obligations regarding cybersecurity, data security, and information security.
    • The inspection will focus on the following aspects: (1) network access filing; (2) internal security management systems; (3) retention of user registration and log data; (4) multi-level protection scheme compliance; (5) CII safeguards; (6) technical defenses against intrusion and malware; (7) remediation of known vulnerabilities; (8) content controls; (9) algorithm recommendation governance, (10) data and personal information protection; and (11) cooperation with police on national security, counter-terrorism, and criminal investigations.
  • A heightened, targeted inspection regime applicable to operators connected to major security-guarantee events, focusing on contingency planning, risk assessment, and incident reporting.
  • Based on the New Rules on Cyberspace Inspection, police engagement of qualified third-party technical service providers, but under police direction only. Such providers must be subject to confidentiality requirements and undergo background vetting, and no fees may be charged to inspected entities. Inspection records must generally be signed by both the inspecting officer and the responsible person of the entity being inspected, with any objections noted.
  • Where risks are identified that do not constitute an actual violation, police issuance of advisory letters to the entity or its industry regulator. At the provincial level, they may also issue public advisories that do not name specific targets. More serious risks will result in escalation to government leadership. For cybersecurity or data security incidents, there is also the possibility of a formal interview with the entity’s legal representative or responsible person.
  • Provisions for reciprocal accountability, which expose both police personnel and any engaged technical contractors involved to disciplinary or criminal liability for misconduct such as unauthorized data access, disclosure of trade secrets or personal information, or abuse of inspection powers.
Subscribe

Recent Posts

Categories

Tags

Archives