Data Newsletter| Cybersecurity Law Revision Progresses With Expected Hike In Penalties

Published date08 January 2026
Law FirmLusheng Law Firm
AuthorLusheng Law Firm

'Takeaways'

  • In September, China concluded an administrative penalty case related to personal information protection, once again underscoring the importance of compliance with cross-border data transfer requirements and personal information protection impact assessments. The public security cyber department found that a company providing foundational datasets for AI training failed to conduct personal information protection impact assessment before processing sensitive biometric data such as facial information. The company was penalized and ordered to rectify the issue.
  • The National People's Congress launched the third round of public consultation on the Draft Amendment to the Cybersecurity Law. The draft largely aligns with the version released by the Cyberspace Administration of China in March and proposes a significant increase in the maximum penalties for violations of cybersecurity obligations. If adopted, the maximum fine for enterprises could reach RMB 10 million.
  • In addition, the Measures for the Management of National Cybersecurity Incident Reports were issued in September and will take effect on November 1. Depending on the severity level of the incident, enterprises must report to the relevant authorities within 1 to 4 hours.

'Regulatory Highlights'

Cyberspace Administration of China (CAC) Issues the Measures on the Management of National Cybersecurity Incident Reports

The Measures will take effect on November 1, 2025. Under these rules, network operators in China must report cybersecurity incidents based on their severity classification. For incidents involving Critical Information Infrastructure (CII), reports must be submitted to the protection department and public security authorities within 1 hour. Central and state government departments and their directly affiliated units must report to cyberspace administration office of their respective departments within 2 hours. Other network operators must report to the provincial-level cyberspace administration within 4 hours. If an incident is deemed major or particularly severe, the relevant departments must also escalate the report to the national cyberspace administration or even the public security department of the State Council within a specified timeframe.

The Measures do not directly specify penalties for failure to report but state that violations will be handled under applicable laws and administrative regulations. Also, where delayed, omitted, falsified, or concealed reports result in serious consequences, enterprises and responsible individuals will face aggravated penalties.
Currently, Article 57 of the Personal Information Protection Law establishes a data breach notification regime, with maximum penalties of RMB 50 million or 5% of the previous year's revenue for general violations of personal information protection obligations. Article 45 of the Data Security Law sets a maximum fine of RMB 2 million for failure to report, which may rise to RMB 10 million if core data is involved.

Currently, the cyberspace authorities have opened six types of cybersecurity incident reporting channels, including the 12387 cybersecurity incident reporting hotline, website, WeChat mini-program, WeChat official account, email, and fax, for network operators, social organizations, and individuals to report security incidents.

The National People's Congress Launches the Third Round of Public Consultation on the Amendment Draft to Cybersecurity Law

Following the second public consultation by the CAC in March this year, on September 12, the National People's launched a 30-day public consultation on the third draft amendment to the Cybersecurity Law. This revision primarily focuses on the legal liability provisions (Articles 59 to 75), with several adjustments made based on the previous draft. Overall, the amendment reflects a balanced approach to enforcement: while significantly increasing the...

Get this document and AI-powered insights with a free trial of vLex and Vincent AI

Get Started for Free

Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant

  • Access comprehensive legal content with no limitations across vLex's unparalleled global legal database

  • Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength

  • Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities

  • Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting

vLex

Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant

  • Access comprehensive legal content with no limitations across vLex's unparalleled global legal database

  • Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength

  • Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities

  • Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting

vLex

Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant

  • Access comprehensive legal content with no limitations across vLex's unparalleled global legal database

  • Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength

  • Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities

  • Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting

vLex

Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant

  • Access comprehensive legal content with no limitations across vLex's unparalleled global legal database

  • Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength

  • Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities

  • Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting

vLex

Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant

  • Access comprehensive legal content with no limitations across vLex's unparalleled global legal database

  • Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength

  • Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities

  • Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting

vLex

Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant

  • Access comprehensive legal content with no limitations across vLex's unparalleled global legal database

  • Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength

  • Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities

  • Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting

vLex