Data Protection and Privacy 2025

CHINA Law and Practice Contributed by: Jihong Chen, Zhong Lun Law Firm

There is no centralised regulatory body. Among all these regulators, the most important ones include: • the Cyberspace Administration of China (CAC); • the Ministry of Public Security (MPS); and • the Ministry of Industry and Information Tech - nology (MIIT). Specifically, according to Article 8 of the CSL and Article 60 of the PIPL, the CAC is in charge of overall planning with regard to data protec - tion and privacy, and co-ordinates the compe - tent authorities. The MIIT, the MPS, the State Administration for Market Regulation (SAMR) and other industry regulators are in charge of law enforcement in the respective industries. Moreover, it is noteworthy that the National Data Bureau, inaugurated in October 2023, is respon - sible for overseeing the integration, sharing and development of data resources, co-ordinating the construction of data infrastructure systems, and the planning and construction of digital China, the digital economy and digital society. How Regulators Operate in Practice When initiating administrative proceedings and enforcing the Three Fundamental Laws and oth - er relevant laws and regulations, the competent authoritiesmust abide by the Law on Administra- tive Penalty ( 行政处罚法 ). The competent authori - ties should conduct investigations to ascertain the facts of the alleged violating acts before imposing punishment on anyone (Article 54). The penalised parties should be given opportunities to state their case and defend themselves (Arti - cle 7). The penalised party is entitled to a hearing in cases where the administrative punishment involves the suspension of business, rescission

of a business permit or licence, or a large penalty (Article 63). According to Article 7 of the Law on Adminis - trative Penalty, a party that refuses to accept administrative penalties imposed upon it may first apply to the relevant administrative organ for a reconsideration. If the party is still dissatisfied with the reconsideration decision, it is entitled to initiate an action before the people’s courts. Unless otherwise stipulated by applicable laws requiring the exhaustion of administrative recon - sideration before seeking judicial review, it may also initiate an action before the people’s courts directly. 1.3 Enforcement Proceedings and Fines Administrative Proceedings Administrative proceedings initiated by regula - tors can be triggered in different ways, including: • reporting – where users may report to the regulators mentioned in 1.2 Regulators and consumer protection organisations, and investigations are launched accordingly; • regular and irregular inspections – where special projects that last several months are launched to target specific industries or pain points in cyberspace; and • inquiries into data leakage events, network loopholes or other cybersecurity/data inci - dents. In addition to the procedures of administrative proceedings described in 1.2 Regulators , public security departments must abide by the special rules provided for them under the Regulations for Internet Security Supervision and Inspection by Public Security Organs ( 公安机关互联网安全监督 检查规定 ). For example, there must be at least two police officers in the event of an on-site inspec - tion, and such law enforcement officers must

74

CHAMBERS.COM

Powered by