TLDR; Below is the English-translated version of China’s Cybersecurity Law (网络安全法), adopted November 7, 2016 by the Standing Committee of the National People’s Congress and amended October 28, 2025.
The Cybersecurity Law is the foundational statute governing how networks are built, operated, and secured in mainland China. It establishes the multi-level protection scheme (MLPS, or “graded protection”) that every network operator must meet, imposes stricter obligations and data-localization rules on operators of critical information infrastructure, and sets baseline rules for handling personal information. Much of China’s later data regime descends from it — the Data Security Law, the Personal Information Protection Law (PIPL), and the Cybersecurity Review Measures all build on the framework laid down here — so any international business running a site, app, or service that reaches users in China should confirm with qualified counsel how its arrangements map to these requirements.
Cybersecurity Law of the People’s Republic of China (Adopted November 7, 2016 by the Standing Committee of the 12th National People’s Congress; amended by the Decision of the Standing Committee of the 14th National People’s Congress of October 28, 2025)
Chapter I — General Provisions
Article 1. This Law is formulated in order to ensure cybersecurity, safeguard sovereignty in cyberspace and national security and the public interest of society, protect the lawful rights and interests of citizens, legal persons, and other organizations, and promote the healthy development of the informatization of the economy and society.
Article 2. This Law applies to the construction, operation, maintenance, and use of networks within the territory of the People’s Republic of China, as well as to the supervision and administration of cybersecurity.
Article 3. Cybersecurity work adheres to the leadership of the Communist Party of China, implements the holistic view of national security, coordinates development and security, and advances the building of the country’s strength in cyberspace.
Article 4. The State persists in attaching equal importance to cybersecurity and informatization development; it follows the policy of active use, scientific development, management in accordance with law, and ensuring security; it advances the construction of network infrastructure and interconnection, encourages innovation in and application of network technology, supports the cultivation of cybersecurity talent, establishes and improves the cybersecurity safeguard system, and raises the capacity for cybersecurity protection.
Article 5. The State formulates and continuously improves the cybersecurity strategy, specifies the basic requirements and main objectives for ensuring cybersecurity, and sets forth cybersecurity policies, work tasks, and measures for key areas.
Article 6. The State takes measures to monitor, defend against, and handle cybersecurity risks and threats originating both within and outside the territory of the People’s Republic of China, to protect critical information infrastructure from attack, intrusion, interference, and sabotage, to punish unlawful and criminal activities on networks in accordance with law, and to safeguard the security and order of cyberspace.
Article 7. The State advocates honest, trustworthy, healthy, and civilized network conduct, promotes the dissemination of the core socialist values, takes measures to raise the cybersecurity awareness and level of the whole of society, and fosters a sound environment in which the whole of society participates jointly in promoting cybersecurity.
Article 8. The State actively carries out international exchange and cooperation in such areas as cyberspace governance, the research and development of network technology and the formulation of standards, and combating unlawful and criminal activities on networks; it promotes the building of a peaceful, secure, open, and cooperative cyberspace and the establishment of a multilateral, democratic, and transparent network governance system.
Article 9. The national cyberspace administration department is responsible for the overall coordination of cybersecurity work and related supervision and administration work. The telecommunications authority of the State Council, the public security department, and other relevant organs are responsible, within the scope of their respective duties, for cybersecurity protection and supervision and administration work in accordance with this Law and the provisions of relevant laws and administrative regulations.
The cybersecurity protection and supervision and administration duties of the relevant departments of local people’s governments at or above the county level shall be determined in accordance with the relevant provisions of the State.
Article 10. In carrying out business and service activities, network operators must comply with laws and administrative regulations, respect social morality, observe commercial ethics, be honest and trustworthy, perform their cybersecurity protection obligations, accept the supervision of the government and of society, and bear social responsibility.
Article 11. Those who construct or operate networks or provide services through networks shall, in accordance with the provisions of laws and administrative regulations and the mandatory requirements of national standards, take technical measures and other necessary measures to ensure the secure and stable operation of networks, respond effectively to cybersecurity incidents, prevent unlawful and criminal activities on networks, and preserve the integrity, confidentiality, and availability of network data.
Article 12. Network-related industry organizations shall, in accordance with their charters, strengthen industry self-discipline, formulate codes of conduct for cybersecurity, guide their members in strengthening cybersecurity protection, raise the level of cybersecurity protection, and promote the healthy development of the industry.
Article 13. The State protects the right of citizens, legal persons, and other organizations to use networks in accordance with law, promotes the popularization of network access, raises the level of network services, provides secure and convenient network services to society, and ensures the lawful, orderly, and free flow of network information.
Any individual or organization using a network shall abide by the Constitution and laws, observe public order, and respect social morality; they must not endanger cybersecurity, and must not use networks to engage in activities that endanger national security, honor, and interests, that incite subversion of the state power or the overthrow of the socialist system, that incite the splitting of the country or undermine national unity, that advocate terrorism or extremism, that advocate ethnic hatred or ethnic discrimination, that disseminate violent, obscene, or pornographic information, that fabricate or disseminate false information so as to disrupt economic order and social order, or that infringe upon the reputation, privacy, intellectual property, and other lawful rights and interests of others.
Article 14. The State supports the research and development of network products and services conducive to the healthy growth of minors, punishes in accordance with law activities that use networks to endanger the physical and mental health of minors, and provides a secure and healthy network environment for minors.
Article 15. Any individual or organization has the right to report conduct endangering cybersecurity to the cyberspace administration, telecommunications, public security, and other departments. The department receiving a report shall handle it promptly in accordance with law; where the matter does not fall within the duties of that department, it shall be promptly transferred to the department empowered to handle it.
The relevant departments shall keep confidential the relevant information of the person making the report and shall protect that person’s lawful rights and interests.
Chapter II — Support and Promotion of Cybersecurity
Article 16. The State establishes and improves the system of cybersecurity standards. The standardization administrative authority of the State Council and other relevant departments of the State Council shall, in accordance with their respective duties, organize the formulation and timely revision of national standards and industry standards concerning cybersecurity management as well as the security of network products, services, and operation.
The State supports enterprises, research institutions, institutions of higher education, and network-related industry organizations in participating in the formulation of national standards and industry standards for cybersecurity.
Article 17. The State Council and the people’s governments of provinces, autonomous regions, and municipalities directly under the Central Government shall engage in overall planning, increase investment, support key cybersecurity technology industries and projects, support the research, development, and application of cybersecurity technology, promote secure and trustworthy network products and services, protect the intellectual property of network technology, and support enterprises, research institutions, institutions of higher education, and the like in participating in national cybersecurity technology innovation projects.
Article 18. The State advances the building of a socialized cybersecurity service system and encourages relevant enterprises and institutions to carry out security services such as cybersecurity certification, testing, and risk assessment.
Article 19. The State encourages the development of technologies for the security protection and utilization of network data, promotes the opening of public data resources, and advances technological innovation and economic and social development.
Article 20. The State supports research on the fundamental theories of artificial intelligence and the research and development of key technologies such as algorithms, advances the construction of infrastructure such as training-data resources and computing power, improves ethical norms for artificial intelligence, strengthens risk monitoring and assessment and security oversight, and promotes the application and healthy development of artificial intelligence.
The State supports innovation in cybersecurity management methods and the use of new technologies such as artificial intelligence to raise the level of cybersecurity protection.
Article 21. People’s governments at all levels and their relevant departments shall organize and carry out regular cybersecurity publicity and education, and shall guide and urge relevant units to do a good job of cybersecurity publicity and education.
The mass media shall conduct targeted cybersecurity publicity and education for society.
Article 22. The State supports enterprises and education and training institutions such as institutions of higher education and vocational schools in carrying out cybersecurity-related education and training, in cultivating cybersecurity talent through a variety of means, and in promoting the exchange of cybersecurity talent.
Chapter III — Security of Network Operations
Section 1 — General Provisions
Article 23. The State implements a cybersecurity multi-level protection scheme. Network operators shall, in accordance with the requirements of the cybersecurity multi-level protection scheme, perform the following security protection obligations, so as to safeguard networks from interference, sabotage, or unauthorized access and to prevent network data from being leaked, stolen, or tampered with:
(1) formulating internal security management systems and operating procedures, determining the persons responsible for cybersecurity, and implementing cybersecurity protection responsibilities;
(2) taking technical measures to guard against computer viruses, network attacks, network intrusions, and other conduct endangering cybersecurity;
(3) taking technical measures to monitor and record the operational status of the network and cybersecurity incidents, and retaining the relevant network logs for no less than six months in accordance with regulations;
(4) taking measures such as the classification of data and the backup and encryption of important data;
(5) other obligations provided for by laws and administrative regulations.
Article 24. Network products and services shall conform to the mandatory requirements of the relevant national standards. Providers of network products and services must not install malicious programs; upon discovering that their network products or services have risks such as security defects or vulnerabilities, they shall immediately take remedial measures and, in accordance with regulations, promptly inform users and report to the relevant competent department.
Providers of network products and services shall provide continuous security maintenance for their products and services; they must not terminate the provision of security maintenance within the period prescribed by regulations or agreed upon by the parties.
Where network products or services have the function of collecting user information, their providers shall expressly notify users and obtain their consent; where users’ personal information is involved, they shall also comply with this Law and the provisions of relevant laws and administrative regulations on the protection of personal information.
Article 25. Critical network equipment and specialized cybersecurity products may be sold or provided only after they have been certified as secure by a qualified institution, or have passed security testing that meets the requirements, in accordance with the mandatory requirements of the relevant national standards. The national cyberspace administration department, together with the relevant departments of the State Council, formulates and publishes a catalog of critical network equipment and specialized cybersecurity products, and promotes the mutual recognition of security certification and security testing results so as to avoid duplicate certification and testing.
Article 26. Where network operators handle network access or domain-name registration services for users, handle the formalities for connecting fixed-line telephones, mobile telephones, and the like to the network, or provide users with services such as information publication or instant messaging, they shall, when entering into an agreement with the user or confirming the provision of the service, require the user to provide genuine identity information. Where a user does not provide genuine identity information, the network operator must not provide the user with the relevant services.
The State implements a strategy of trustworthy network identity, supports the research and development of secure and convenient electronic identity authentication technology, and promotes mutual recognition among different forms of electronic identity authentication.
Article 27. Network operators shall formulate emergency response plans for cybersecurity incidents, and shall promptly handle security risks such as system vulnerabilities, computer viruses, network attacks, and network intrusions; when an incident endangering cybersecurity occurs, they shall immediately activate the emergency response plan, take corresponding remedial measures, and report to the relevant competent department in accordance with regulations.
Article 28. The conduct of activities such as cybersecurity certification, testing, and risk assessment, and the release to the public of cybersecurity information such as that on system vulnerabilities, computer viruses, network attacks, and network intrusions, shall comply with the relevant provisions of the State.
Article 29. No individual or organization may engage in activities endangering cybersecurity, such as unlawfully intruding into another person’s network, interfering with the normal functioning of another person’s network, or stealing network data; may provide programs or tools specifically used for engaging in activities endangering cybersecurity, such as intruding into networks, interfering with the normal functioning of networks and their protective measures, or stealing network data; or, knowing that another person is engaging in activities endangering cybersecurity, may provide that person with assistance such as technical support, advertising and promotion, or payment settlement.
Article 30. Network operators shall provide technical support and assistance to public security organs and state security organs in their activities to safeguard national security and investigate crimes in accordance with law.
Article 31. The State supports cooperation among network operators in such areas as the collection, analysis, notification, and emergency handling of cybersecurity information, so as to enhance the security safeguard capabilities of network operators.
The relevant industry organizations shall establish and improve cybersecurity protection norms and collaboration mechanisms for their industry, strengthen the analysis and assessment of cybersecurity risks, regularly issue risk warnings to their members, and support and assist their members in responding to cybersecurity risks.
Article 32. Information obtained by the cyberspace administration department and the relevant departments in the performance of their cybersecurity protection duties may be used only for the needs of safeguarding cybersecurity and must not be used for any other purpose.
Section 2 — Security of the Operation of Critical Information Infrastructure
Article 33. The State, on the basis of the cybersecurity multi-level protection scheme, implements key protection for critical information infrastructure in important industries and fields such as public communications and information services, energy, transportation, water conservancy, finance, public services, and e-government, as well as other critical information infrastructure that, once destroyed, rendered nonfunctional, or subjected to data leakage, might seriously endanger national security, the national economy and people’s livelihood, or the public interest. The specific scope of critical information infrastructure and the measures for its security protection shall be formulated by the State Council.
The State encourages network operators other than those of critical information infrastructure to participate voluntarily in the critical information infrastructure protection system.
Article 34. In accordance with the division of duties prescribed by the State Council, the departments responsible for the security protection of critical information infrastructure shall separately prepare and organize the implementation of security plans for the critical information infrastructure of their respective industries and fields, and shall guide and supervise the work of protecting the operational security of critical information infrastructure.
Article 35. The construction of critical information infrastructure shall ensure that it has the performance to support stable and continuous business operation, and shall ensure that security technology measures are planned, built, and put into use simultaneously.
Article 36. In addition to the provisions of Article 23 of this Law, operators of critical information infrastructure shall also perform the following security protection obligations:
(1) establishing a specialized security management body and a person responsible for security management, and conducting security background checks on that person and on personnel in key positions;
(2) regularly conducting cybersecurity education, technical training, and skills assessment for practitioners;
(3) carrying out disaster-recovery backups of important systems and databases;
(4) formulating emergency response plans for cybersecurity incidents and conducting drills on a regular basis;
(5) other obligations provided for by laws and administrative regulations.
Article 37. Where an operator of critical information infrastructure procures network products and services that may affect national security, the procurement shall pass a national security review organized by the national cyberspace administration department together with the relevant departments of the State Council.
Article 38. When an operator of critical information infrastructure procures network products and services, it shall, in accordance with regulations, enter into a security and confidentiality agreement with the provider, specifying the obligations and responsibilities for security and confidentiality.
Article 39. Personal information and important data collected and generated by operators of critical information infrastructure in the course of their operations within the territory of the People’s Republic of China shall be stored within the territory. Where, due to business needs, it is genuinely necessary to provide such information or data outside the territory, a security assessment shall be conducted in accordance with the measures formulated by the national cyberspace administration department together with the relevant departments of the State Council; where laws or administrative regulations provide otherwise, those provisions shall apply.
Article 40. Operators of critical information infrastructure shall, by themselves or by entrusting a cybersecurity service institution, conduct at least once a year a test and assessment of the security of their networks and of the risks that may exist, and shall submit the circumstances of the test and assessment and the improvement measures to the relevant department responsible for the security protection of critical information infrastructure.
Article 41. The national cyberspace administration department shall coordinate the relevant departments in taking the following measures for the security protection of critical information infrastructure:
(1) conducting spot-check testing of the security risks of critical information infrastructure, putting forward improvement measures, and, where necessary, entrusting a cybersecurity service institution to test and assess the security risks existing in the network;
(2) regularly organizing operators of critical information infrastructure to conduct cybersecurity emergency drills, so as to raise their level of response to cybersecurity incidents and their capacity for coordination and cooperation;
(3) promoting the sharing of cybersecurity information among the relevant departments, operators of critical information infrastructure, and relevant research institutions, cybersecurity service institutions, and the like;
(4) providing technical support and assistance for the emergency handling of cybersecurity incidents and the restoration of network functions, and the like.
Chapter IV — Network Information Security
Article 42. Network operators shall strictly keep confidential the user information they collect, and shall establish and improve a system for the protection of user information.
Where network operators process personal information, they shall comply with this Law and the provisions of laws and administrative regulations such as the “Civil Code of the People’s Republic of China” and the “Personal Information Protection Law of the People’s Republic of China.”
Article 43. Network operators collecting and using personal information shall abide by the principles of lawfulness, legitimacy, and necessity; shall make public their rules for collection and use; shall expressly state the purposes, means, and scope of the collection and use of information; and shall obtain the consent of the persons whose information is collected.
Network operators must not collect personal information unrelated to the services they provide, must not collect or use personal information in violation of the provisions of laws and administrative regulations or of the agreement between the two parties, and shall process the personal information they retain in accordance with the provisions of laws and administrative regulations and with their agreement with users.
Article 44. Network operators must not leak, tamper with, or damage the personal information they collect; without the consent of the person whose information is collected, they must not provide personal information to others. However, this does not apply to information that has been processed such that a specific individual cannot be identified and the information cannot be restored.
Network operators shall take technical measures and other necessary measures to ensure the security of the personal information they collect and to prevent the information from being leaked, damaged, or lost. When the leakage, damage, or loss of personal information occurs or may occur, they shall immediately take remedial measures and, in accordance with regulations, promptly inform users and report to the relevant competent department.
Article 45. Where an individual discovers that a network operator has collected or used the individual’s personal information in violation of the provisions of laws or administrative regulations or of the agreement between the two parties, the individual has the right to demand that the network operator delete the individual’s personal information; where the individual discovers that the personal information collected or stored by the network operator contains errors, the individual has the right to demand that the network operator make corrections. The network operator shall take measures to delete or correct the information.
Article 46. No individual or organization may steal or obtain by other unlawful means personal information, or unlawfully sell or unlawfully provide personal information to others.
Article 47. Departments that bear cybersecurity supervision and administration duties in accordance with law, and their staff, must strictly keep confidential the personal information, privacy, and commercial secrets that they become aware of in the performance of their duties, and must not leak, sell, or unlawfully provide such information to others.
Article 48. Every individual and organization shall be responsible for their conduct in using networks, and must not establish websites or communication groups used for unlawful or criminal activities such as committing fraud, imparting criminal methods, or making or selling prohibited goods or controlled items, and must not use networks to publish information involving the commission of fraud, the making or selling of prohibited goods or controlled items, or other unlawful or criminal activities.
Article 49. Network operators shall strengthen the management of information published by their users; upon discovering information the publication or transmission of which is prohibited by laws or administrative regulations, they shall immediately stop the transmission of that information, take disposal measures such as elimination to prevent the information from spreading, preserve the relevant records, and report to the relevant competent department.
Article 50. The electronic information sent, and the application software provided, by any individual or organization must not install malicious programs and must not contain information the publication or transmission of which is prohibited by laws or administrative regulations.
Providers of electronic-information-sending services and providers of application-software-download services shall perform security management obligations; where they know that a user of theirs has engaged in conduct provided for in the preceding paragraph, they shall stop providing services, take disposal measures such as elimination, preserve the relevant records, and report to the relevant competent department.
Article 51. Network operators shall establish a system for complaints and reports regarding network information security, shall publicize information such as the means of making complaints and reports, and shall promptly accept and handle complaints and reports concerning network information security.
Network operators shall cooperate with the supervision and inspection carried out in accordance with law by the cyberspace administration department and the relevant departments.
Article 52. Where the national cyberspace administration department and the relevant departments, in performing their network information security supervision and administration duties in accordance with law, discover information the publication or transmission of which is prohibited by laws or administrative regulations, they shall require network operators to stop the transmission, take disposal measures such as elimination, and preserve the relevant records; with respect to such information originating outside the territory of the People’s Republic of China, they shall notify the relevant institutions to take technical measures and other necessary measures to block its dissemination.
Chapter V — Monitoring, Early Warning, and Emergency Response
Article 53. The State establishes a system for cybersecurity monitoring and early warning and for information notification. The national cyberspace administration department shall coordinate the relevant departments in strengthening the collection, analysis, and notification of cybersecurity information, and shall uniformly release cybersecurity monitoring and early-warning information in accordance with regulations.
Article 54. The departments responsible for the security protection of critical information infrastructure shall establish and improve cybersecurity monitoring, early-warning, and information-notification systems for their respective industries and fields, and shall submit cybersecurity monitoring and early-warning information in accordance with regulations.
Article 55. The national cyberspace administration department coordinates the relevant departments in establishing and improving cybersecurity risk-assessment and emergency-response working mechanisms, formulating emergency response plans for cybersecurity incidents, and organizing drills on a regular basis.
The departments responsible for the security protection of critical information infrastructure shall formulate emergency response plans for cybersecurity incidents in their respective industries and fields, and shall organize drills on a regular basis.
Emergency response plans for cybersecurity incidents shall grade cybersecurity incidents according to factors such as the degree of harm and the scope of impact after an incident occurs, and shall prescribe the corresponding emergency disposal measures.
Article 56. When the risk of a cybersecurity incident increases, the relevant departments of people’s governments at or above the provincial level shall, in accordance with the prescribed authority and procedures and based on the characteristics of the cybersecurity risk and the harm it may cause, take the following measures:
(1) requiring the relevant departments, institutions, and personnel to promptly collect and report relevant information and to strengthen the monitoring of cybersecurity risks;
(2) organizing the relevant departments, institutions, and professionals to analyze and assess cybersecurity risk information and to predict the likelihood of an incident, its scope of impact, and its degree of harm;
(3) issuing cybersecurity risk warnings to society and releasing measures to avoid or mitigate the harm.
Article 57. When a cybersecurity incident occurs, the emergency response plan for cybersecurity incidents shall be immediately activated, the cybersecurity incident shall be investigated and assessed, network operators shall be required to take technical measures and other necessary measures to eliminate security hazards and prevent the harm from expanding, and warning information relevant to the public shall be promptly released to society.
Article 58. Where the relevant departments of people’s governments at or above the provincial level, in performing their cybersecurity supervision and administration duties, discover that a network has a relatively large security risk or that a security incident has occurred, they may, in accordance with the prescribed authority and procedures, conduct a regulatory interview with the legal representative or principal person in charge of the operator of that network. The network operator shall take measures as required, carry out rectification, and eliminate the hazards.
Article 59. Where, as a result of a cybersecurity incident, an emergency or a work-safety accident occurs, it shall be handled in accordance with the provisions of relevant laws and administrative regulations such as the “Emergency Response Law of the People’s Republic of China” and the “Work Safety Law of the People’s Republic of China.”
Article 60. Where it is necessary, for the purpose of safeguarding national security and public order and of handling a major social-security emergency, temporary measures such as restrictions on network communications may be taken in specific regions, upon a decision or approval of the State Council.
Chapter VI — Legal Liability
Article 61. Where a network operator fails to perform the cybersecurity protection obligations provided for in Articles 23 and 27 of this Law, the relevant competent department shall order corrections and give a warning, and may impose a fine of not less than 10,000 yuan and not more than 50,000 yuan; where it refuses to make corrections or where consequences such as endangering cybersecurity result, a fine of not less than 50,000 yuan and not more than 500,000 yuan shall be imposed, and a fine of not less than 10,000 yuan and not more than 100,000 yuan shall be imposed on the directly responsible person in charge and other directly responsible persons.
Where an operator of critical information infrastructure fails to perform the cybersecurity protection obligations provided for in Articles 35, 36, 38, and 40 of this Law, the relevant competent department shall order corrections and give a warning, and may impose a fine of not less than 50,000 yuan and not more than 100,000 yuan; where it refuses to make corrections or where consequences such as endangering cybersecurity result, a fine of not less than 100,000 yuan and not more than 1,000,000 yuan shall be imposed, and a fine of not less than 10,000 yuan and not more than 100,000 yuan shall be imposed on the directly responsible person in charge and other directly responsible persons.
Where conduct described in the preceding two paragraphs causes consequences seriously endangering cybersecurity, such as the leakage of large amounts of data or the loss of partial functionality of critical information infrastructure, the relevant competent department shall impose a fine of not less than 500,000 yuan and not more than 2,000,000 yuan, and a fine of not less than 50,000 yuan and not more than 200,000 yuan on the directly responsible person in charge and other directly responsible persons; where it causes consequences particularly seriously endangering cybersecurity, such as the loss of the main functionality of critical information infrastructure, a fine of not less than 2,000,000 yuan and not more than 10,000,000 yuan shall be imposed, and a fine of not less than 200,000 yuan and not more than 1,000,000 yuan on the directly responsible person in charge and other directly responsible persons.
Article 62. Where, in violation of the provisions of the first and second paragraphs of Article 24 and the first paragraph of Article 50 of this Law, any of the following conduct occurs, the relevant competent department shall order corrections and give a warning; where corrections are refused or where consequences such as endangering cybersecurity result, a fine of not less than 50,000 yuan and not more than 500,000 yuan shall be imposed, and a fine of not less than 10,000 yuan and not more than 100,000 yuan on the directly responsible person in charge:
(1) installing malicious programs;
(2) failing to immediately take remedial measures for risks such as security defects or vulnerabilities existing in its products or services, or failing to promptly inform users and report to the relevant competent department in accordance with regulations;
(3) terminating, without authorization, the provision of security maintenance for its products or services.
Where conduct described in items (1) and (2) of the preceding paragraph causes the consequences provided for in the third paragraph of Article 61 of this Law, punishment shall be imposed in accordance with the provisions of that paragraph.
Article 63. Where, in violation of the provisions of Article 25 of this Law, critical network equipment or specialized cybersecurity products that have not undergone security certification or security testing, or that have failed security certification or do not meet the requirements of security testing, are sold or provided, the relevant competent department shall order the sale or provision to stop, give a warning, and confiscate the unlawful gains; where there are no unlawful gains or the unlawful gains are less than 100,000 yuan, a fine of not less than 20,000 yuan and not more than 100,000 yuan shall also be imposed; where the unlawful gains are 100,000 yuan or more, a fine of not less than one time and not more than five times the unlawful gains shall also be imposed; where the circumstances are serious, it may also be ordered to suspend the relevant business, suspend operations for rectification, or have the relevant business permit or business license revoked. Where laws or administrative regulations provide otherwise, those provisions shall apply.
Article 64. Where a network operator, in violation of the provisions of the first paragraph of Article 26 of this Law, fails to require users to provide genuine identity information, or provides relevant services to users who do not provide genuine identity information, the relevant competent department shall order corrections; where corrections are refused or the circumstances are serious, a fine of not less than 50,000 yuan and not more than 500,000 yuan shall be imposed, and it may also be ordered to suspend the relevant business, suspend operations for rectification, close the website or application, or have the relevant business permit or business license revoked, and a fine of not less than 10,000 yuan and not more than 100,000 yuan shall be imposed on the directly responsible person in charge and other directly responsible persons.
Article 65. Where, in violation of the provisions of Article 28 of this Law, activities such as cybersecurity certification, testing, or risk assessment are carried out, or cybersecurity information such as that on system vulnerabilities, computer viruses, network attacks, or network intrusions is released to the public, the relevant competent department shall order corrections and give a warning, and may impose a fine of not less than 10,000 yuan and not more than 100,000 yuan; where corrections are refused or the circumstances are serious, a fine of not less than 100,000 yuan and not more than 1,000,000 yuan shall be imposed, and it may also be ordered to suspend the relevant business, suspend operations for rectification, close the website or application, or have the relevant business permit or business license revoked, and a fine of not less than 10,000 yuan and not more than 100,000 yuan shall be imposed on the directly responsible person in charge and other directly responsible persons.
Where conduct described in the preceding paragraph causes the consequences provided for in the third paragraph of Article 61 of this Law, punishment shall be imposed in accordance with the provisions of that paragraph.
Article 66. Where, in violation of the provisions of Article 29 of this Law, a person engages in activities endangering cybersecurity, provides programs or tools specifically used for engaging in activities endangering cybersecurity, or provides others engaging in activities endangering cybersecurity with assistance such as technical support, advertising and promotion, or payment settlement, and a crime is not yet constituted, the public security organ shall confiscate the unlawful gains and impose detention of not more than five days, and may also impose a fine of not less than 50,000 yuan and not more than 500,000 yuan; where the circumstances are relatively serious, detention of not less than five days and not more than fifteen days shall be imposed, and a fine of not less than 100,000 yuan and not more than 1,000,000 yuan may also be imposed.
Where a unit engages in conduct described in the preceding paragraph, the public security organ shall confiscate the unlawful gains, impose a fine of not less than 100,000 yuan and not more than 1,000,000 yuan, and punish the directly responsible person in charge and other directly responsible persons in accordance with the provisions of the preceding paragraph.
A person who, in violation of the provisions of Article 29 of this Law, is subjected to a public-security administrative penalty may not, for five years, engage in work in key positions of cybersecurity management or network operations; a person subjected to a criminal penalty may not, for life, engage in work in key positions of cybersecurity management or network operations.
Article 67. Where an operator of critical information infrastructure, in violation of the provisions of Article 37 of this Law, uses network products or services that have not undergone a security review or that have failed a security review, the relevant competent department shall order corrections within a time limit, order the use to stop, and order the elimination of the effect on national security, impose a fine of not less than one time and not more than ten times the procurement amount, and impose a fine of not less than 10,000 yuan and not more than 100,000 yuan on the directly responsible person in charge and other directly responsible persons.
Article 68. Where, in violation of the provisions of Article 48 of this Law, a person establishes a website or communication group used for carrying out unlawful or criminal activities, or uses a network to publish information involving the carrying out of unlawful or criminal activities, and a crime is not yet constituted, the public security organ shall impose detention of not more than five days, and may also impose a fine of not less than 10,000 yuan and not more than 100,000 yuan; where the circumstances are relatively serious, detention of not less than five days and not more than fifteen days shall be imposed, and a fine of not less than 50,000 yuan and not more than 500,000 yuan may also be imposed. The website or communication group used for carrying out unlawful or criminal activities shall be closed.
Where a unit engages in conduct described in the preceding paragraph, the public security organ shall impose a fine of not less than 100,000 yuan and not more than 500,000 yuan, and punish the directly responsible person in charge and other directly responsible persons in accordance with the provisions of the preceding paragraph.
Article 69. Where a network operator, in violation of the provisions of Article 49 of this Law, fails to stop the transmission of information the publication or transmission of which is prohibited by laws or administrative regulations, to take disposal measures such as elimination, to preserve the relevant records, or to report to the relevant competent department, or, in violation of the provisions of Article 52 of this Law, fails, as required by the relevant department, to stop the transmission of, take disposal measures such as elimination for, or preserve the relevant records of, information the publication or transmission of which is prohibited by laws or administrative regulations, the relevant competent department shall order corrections, give a warning, and issue a public notice, and may impose a fine of not less than 50,000 yuan and not more than 500,000 yuan; where corrections are refused or the circumstances are serious, a fine of not less than 500,000 yuan and not more than 2,000,000 yuan shall be imposed, and it may also be ordered to suspend the relevant business, suspend operations for rectification, close the website or application, or have the relevant business permit or business license revoked, and a fine of not less than 50,000 yuan and not more than 200,000 yuan shall be imposed on the directly responsible person in charge and other directly responsible persons.
Where conduct described in the preceding paragraph causes a particularly serious impact or particularly serious consequences, the relevant competent department shall impose a fine of not less than 2,000,000 yuan and not more than 10,000,000 yuan, order the suspension of the relevant business, the suspension of operations for rectification, the closure of the website or application, or the revocation of the relevant business permit or business license, and impose a fine of not less than 200,000 yuan and not more than 1,000,000 yuan on the directly responsible person in charge and other directly responsible persons.
Where a provider of electronic-information-sending services or a provider of application-software-download services fails to perform the security management obligations provided for in the second paragraph of Article 50 of this Law, punishment shall be imposed in accordance with the provisions of the preceding two paragraphs.
Article 70. Where a network operator, in violation of the provisions of this Law, engages in any of the following conduct, the relevant competent department shall order corrections; where corrections are refused or the circumstances are serious, a fine of not less than 50,000 yuan and not more than 500,000 yuan shall be imposed, and a fine of not less than 10,000 yuan and not more than 100,000 yuan shall be imposed on the directly responsible person in charge and other directly responsible persons:
(1) refusing or obstructing the supervision and inspection carried out by the relevant department in accordance with law;
(2) refusing to provide technical support and assistance to public security organs or state security organs.
Article 71. Any of the following conduct shall be dealt with and punished in accordance with the provisions of relevant laws and administrative regulations:
(1) publishing or transmitting information the publication or transmission of which is prohibited by the second paragraph of Article 13 of this Law and by other laws and administrative regulations;
(2) infringing upon the rights and interests in personal information in violation of the provisions of the third paragraph of Article 24 and Articles 43 through 45 of this Law;
(3) where an operator of critical information infrastructure, in violation of the provisions of Article 39 of this Law, stores personal information and important data outside the territory, or provides personal information and important data to parties outside the territory.
Where, in violation of the provisions of Article 46 of this Law, a person steals or obtains by other unlawful means, or unlawfully sells or unlawfully provides to others, personal information, and a crime is not yet constituted, the public security organ shall impose punishment in accordance with the provisions of relevant laws and administrative regulations.
Article 72. Where there is unlawful conduct provided for in this Law, it shall be recorded in credit files and publicized in accordance with the provisions of relevant laws and administrative regulations.
Article 73. Where there is a violation of the provisions of this Law but there exist circumstances for a lighter, mitigated, or waived penalty as provided in the “Administrative Penalty Law of the People’s Republic of China,” a lighter, mitigated, or waived penalty shall be imposed in accordance with the provisions of that Law.
Article 74. Where the operator of a government-affairs network of a state organ fails to perform the cybersecurity protection obligations provided for in this Law, its superior organ or the relevant organ shall order corrections; the directly responsible person in charge and other directly responsible persons shall be given sanctions in accordance with law.
Article 75. Where the cyberspace administration department or a relevant department, in violation of the provisions of Article 32 of this Law, uses information obtained in the performance of its cybersecurity protection duties for other purposes, the directly responsible person in charge and other directly responsible persons shall be given sanctions in accordance with law.
Where staff of the cyberspace administration department or a relevant department neglect their duties, abuse their powers, or engage in malpractice for personal gain, and a crime is not yet constituted, they shall be given sanctions in accordance with law.
Article 76. Where a violation of the provisions of this Law causes harm to another person, civil liability shall be borne in accordance with law.
Where a violation of the provisions of this Law constitutes conduct violating public security administration, a public-security administrative penalty shall be imposed in accordance with law; where a crime is constituted, criminal liability shall be pursued in accordance with law.
Article 77. Where an institution, organization, or individual outside the territory engages in activities that endanger the cybersecurity of the People’s Republic of China, legal liability shall be pursued in accordance with law; where serious consequences result, the public security department of the State Council and the relevant departments may also decide to adopt measures against that institution, organization, or individual, such as freezing property or other necessary sanctions.
Chapter VII — Supplementary Provisions
Article 78. The meanings of the following terms in this Law are as follows:
(1) “Network” means a system, composed of computers or other information terminals and related equipment, that collects, stores, transmits, exchanges, and processes information in accordance with certain rules and procedures.
(2) “Cybersecurity” means the capability, achieved by taking necessary measures, to guard against attacks on, intrusions into, interference with, sabotage of, and unlawful use of networks, as well as accidents, so as to keep networks in a state of stable and reliable operation, and to safeguard the integrity, confidentiality, and availability of network data.
(3) “Network operator” means the owner or administrator of a network and a network service provider.
(4) “Network data” means all kinds of electronic data collected, stored, transmitted, processed, and generated through networks.
(5) “Personal information” means all kinds of information, recorded electronically or by other means, that can identify, on its own or in combination with other information, the personal identity of a natural person, including but not limited to the natural person’s name, date of birth, identity-document number, personal biometric information, address, and telephone number.
Article 79. The protection of the operational security of networks that store or process information involving state secrets shall, in addition to complying with this Law, also comply with the provisions of secrecy laws and administrative regulations.
Article 80. The security protection of military networks shall be separately provided for by the Central Military Commission.
Article 81. This Law shall take effect as of June 1, 2017.
Closing
The original document was published in Chinese by the National People’s Congress of the People’s Republic of China; we translated it into English, which is what you read above. This translation is provided for quick comprehension only and should be used at your own discretion and risk — always confirm the current requirements with qualified legal counsel.
If you need further help from our team, contact us today, and our experts will help you keep your presence in China compliant from the ground up.