![]() |
Pix credit here (Family members, relatives and friends of criminal secret agents, you must supervise and urge criminals to register and turn over a new leaf!"; 1950) |
On 6 August 2026, Wang Xiaohong, Minister of Public Security, had promulgated the Measures for the Supervision and Inspection of Cyberspace Security by
Public Security Organs [《公安机关网络空间安全监督检查办法》](Ministry of Public Security Order No. 176), to take effect on October 1, 2026 at which time the 2018 "Provisions on the
Supervision and Inspection of Internet Security by Public Security
Organs" (Ministry of Public Security Order No. 151) would be repealed. The new measure consists of 23 articles, covering aspects such as the subjects, methods, content, and mechanisms of supervision and inspection, the application of inspection results, and legal liabilities. [这是《公安机关网络空间安全监督检查办法》(公安部令第176号)的官方原文页面。该办法于2026年8月6日由公安部部长王小洪签署公布,自页面包含完整正文(共23条),内容涵盖监督检查对象、方式、内容、机制、结果运用及法律责任等。].
Ministry of Public Security Order No. 176 will prove controversial and their scope and application at home and abroad have yet to be revealed. With the aid of Grok, this post includes (1) a summary of the new measures; (2) an analysis of the provisions of Ministry of Public Security Order No. 176 in the context of Chinese law; (3) an initial consideration of possible breadth of application to individuals and enterprises; and (4) an initial consideration of a comparison of Ministry of Public Security Order No. 176 with what may come close to being equivalent measures in the United States, the European Union, and Brazil.
1. Summary Measures for the Supervision and Inspection of Cyberspace Security by Public Security Organs (Ministry of Public Security Order No. 176)
Promulgated on 6 August 2026 by Minister Wang Xiaohong after approval at the 2nd Ministry of Public Security ministerial meeting on 1 July 2026. The Measures take effect on 1 October 2026 and simultaneously repeal the 2018 Provisions on the Supervision and Inspection of Internet Security by Public Security Organs (MPS Order No. 151).
Purpose and Scope (Articles 1–2) The Measures aim to safeguard national security and public interests, protect the legitimate rights of citizens, legal persons and other organizations, standardize public security organs’ cyberspace security inspections, and prevent/combat cyber-related illegal activities and crimes. They are enacted pursuant to the People’s Police Law, Cybersecurity Law, Data Security Law, Personal Information Protection Law, Critical Information Infrastructure Security Protection Regulations, Network Data Security Management Regulations, and Internet Information Services Management Measures.
They apply to public security organs’ inspections of network operators, data processors, personal information handlers and others regarding their fulfilment of statutory cybersecurity, data security and information security obligations. “Cyberspace security” is expressly defined as encompassing cybersecurity + data security + information security.
Guiding Principles and Coordination (Article 3) Inspections must be conducted under the leadership of the Central Cyberspace Affairs Commission and related bodies, following the principles of lawful and scientific management that both ensures security and promotes development. Public security organs must strictly observe statutory authority and procedures, improve enforcement methods, and establish coordination mechanisms with competent industry regulators. For routine on-site inspections where an industry regulator exists, the industry regulator shall normally take the lead. A graded and classified inspection system must be established, subject to supervision by inspected entities and the public.
Inspection Methods (Article 4)
- Online patrols: network information monitoring, information-review capability testing, vulnerability scanning and similar non-disruptive methods within the jurisdiction. Advance notice (3 working days) is required for information-review capability tests.
- Remote testing (municipal-level and above public security organs): vulnerability probing and penetration testing of network facilities and information systems other than critical information infrastructure, again with 3 working days’ prior notice, no disruption of normal operations, and notification to the same-level cyberspace administration and industry regulators. Special rules apply to basic telecommunications networks under the Critical Information Infrastructure regulations. Risks discovered online or remotely must be verified; on-site inspection may be used when necessary.
Jurisdiction (Article 5) On-site inspections are conducted by the county-level or higher public security organ of the place where the inspected entity’s operational institution is located (actual main place of operations, management office, network facilities, or industrial/commercial registration). For individuals, the place of habitual residence applies. Jurisdictional disputes are resolved by the common superior organ. Higher-level organs supervise lower-level ones and may elevate or organize inspections.
Inspected Entities (Article 6) Public security organs may inspect: (1) Internet service providers (access, data centres, CDN, domain-name, information services, etc.); (2) public Internet access service providers; (3) network operators and their builders/maintainers; (4) critical information infrastructure operators and their builders/maintainers; (5) network product and service providers; (6) data processors; (7) personal information handlers; (8) other entities subject to inspection by law.
Entities that have previously suffered security incidents or have been administratively punished for non-compliance and failed to rectify are priorities.
Inspection Content (Articles 7–8) Routine inspections focus on 11 categories of statutory obligations, including: network unit filing and user/log retention; security management systems; multi-level protection scheme (MLPS) obligations; critical information infrastructure protection; technical measures against viruses/attacks; vulnerability remediation; content filtering for prohibited information; algorithm security responsibilities; data security and personal information protection obligations; and technical support/assistance to public security organs for national security, counter-terrorism and criminal investigation.
During major national security protection tasks (or for key counter-terrorism targets), special inspections examine contingency plans, risk assessments, emergency drills, additional protective measures and incident reporting.
Frequency, Coordination and Burden Reduction (Articles 9–10) Routine on-site inspections are coordinated under national cybersecurity and data-security mechanisms to avoid duplication. Level-3 (and above) MLPS networks and critical information infrastructure operators receive one routine on-site inspection per year; results of inspections already conducted by other competent authorities in the same year are reused. Special or case-related inspections proceed as needed under statutory procedures.
Multi-industry/department routine inspections ordered by the Ministry of Public Security require Central Cyberspace Affairs Commission approval (with additional coordination for data security or content/ideology issues). Basic telecommunications network inspections are conducted at municipal level or above. Inspections of telecommunications, energy, transport, water conservancy, finance, defence science & industry and similar sectors require 5 working days’ prior notice to the cyberspace administration and industry regulators, who may request joint inspections. Results are promptly shared with those departments.
On-site Powers and Procedures (Articles 11–15) At least two people’s police officers must participate and present police credentials plus a written inspection notice issued by a county-level or higher public security organ. Powers include: entering premises/machine rooms; questioning responsible persons or security managers; inspecting and copying relevant materials; examining technical protective measures; and conducting vulnerability probing/penetration testing.
Public security organs may engage qualified cybersecurity service institutions or specialists for technical support (subject to higher-level filing). Such personnel operate under police command, must sign confidentiality undertakings covering trade secrets, personal privacy and personal information, and undergo background checks for penetration-testing work. For critical information infrastructure, the industry regulator must be informed.
Inspections must be objective and impartial; no fees may be charged and no designated products/services may be required. Written records must be prepared and signed by the officers and the inspected entity’s representative (or noted if signature is refused). Remote-testing records are signed by the officers; technical-support personnel also sign when involved. Materials are archived.
Outcomes and Follow-up (Articles 16–19) Risks and hazards are noted and the entity is guided to eliminate them. Non-compliance triggers legal liability under the Cybersecurity Law, Data Security Law, Personal Information Protection Law and related regulations.
Where risks do not yet constitute illegal/criminal conduct, public security organs may:
- issue a “Public Security Reminder Letter” (公安提示函) to the entity (county level and above);
- issue a reminder letter to the industry regulator (municipal level and above);
- issue a non-entity-specific public notice (provincial level and above).
Major risks affecting Level-3+ networks, critical information infrastructure or important data are promptly reported to industry regulators and the cyberspace administration. Severe regional or sectoral risks threatening national security, public security or the public interest are reported to the people’s government and higher public security organs, with possible public notices.
Provincial-level or higher public security organs may interview the legal representative or principal responsible person of a network operator that presents significant risk or has suffered an incident. County-level or higher organs may interview relevant organisations or individuals concerning data- or personal-information-related risks/incidents. Interviewees must rectify.
Confidentiality and Liability (Articles 20–22) Public security personnel and engaged technical-support providers must protect state secrets, work secrets, trade secrets, personal privacy and personal information obtained during inspections; such information may be used only for cyberspace security purposes. After inspection, technical-support providers must return or destroy materials as directed.
Abuse of power, dereliction of duty or favouritism by public security personnel leads to disciplinary or criminal liability. Technical-support providers who engage in illegal intrusion, disruption, data theft or unauthorised disclosure of secrets/privacy face administrative or criminal penalties.
Entry into Force (Article 23) Effective 1 October 2026; the 2018 Internet Security Inspection Provisions are repealed.
2. Analysis of Provisions in the Context of Chinese Law
These Measures represent a significant evolution of China’s cybersecurity regulatory architecture and the role of the public security organs (公安机关) within it.
From “Internet Security” to “Cyberspace Security” The 2018 Provisions (Order No. 151) focused narrowly on “internet security.” The 2026 Measures deliberately broaden the concept to “cyberspace security,” explicitly encompassing cybersecurity, data security and information security. This mirrors the post-2016 legislative expansion: Cybersecurity Law (2017), Data Security Law (2021), Personal Information Protection Law (2021), Critical Information Infrastructure Security Protection Regulations (2021) and Network Data Security Management Regulations (2024/2025). The public security organs’ inspection mandate is thereby aligned with the full suite of modern Chinese digital-security legislation rather than remaining limited to the older “internet” framing.
Integration into the Multi-Layer Governance System Article 3 places inspections under the leadership of the Central Cyberspace Affairs Commission (and related mechanisms). This reflects China’s dual-track governance model in which the Cyberspace Administration of China (CAC / 网信办) holds overall coordination and content/ideology responsibilities, while public security organs retain strong enforcement, technical-inspection and criminal-investigation powers. The Measures carefully allocate roles: industry regulators take the lead on routine on-site checks where they exist; public security organs coordinate rather than unilaterally dominate; and multi-sector inspections require Central Cyberspace Affairs Commission approval. This reduces inter-agency friction and responds to long-standing industry complaints about overlapping inspections.
Expansion of Inspected Subjects and Content The list of inspectable entities (Article 6) is broader than the 2018 version and now expressly includes data processors and personal information handlers—directly implementing the Data Security Law and Personal Information Protection Law. Inspection content (Article 7) adds algorithm security responsibilities, data-security and personal-information protection obligations, and the duty to provide technical assistance for national-security, counter-terrorism and criminal investigations (echoing Cybersecurity Law Art. 28 and related provisions). Special inspections during major security tasks and for counter-terrorism targets further embed the Measures in China’s national-security and counter-terrorism legal framework.
Procedural Safeguards and Burden Reduction Compared with the 2018 rules, the 2026 Measures contain more detailed procedural protections: advance notice for remote testing and capability tests; requirement of two officers and written notice; prohibition on fees and designated products; reuse of other regulators’ inspection results; and explicit coordination to avoid duplication. These provisions respond to both the Administrative Licensing Law / Administrative Penalty Law principles of proportionality and fairness and to practical business concerns about regulatory burden. The graded/classified approach and annual-inspection ceiling for high-level systems further operationalise risk-based supervision.
Enforcement Toolbox and Soft-Law Instruments The introduction of the “Public Security Reminder Letter” (公安提示函) and non-entity-specific public notices (Article 17) creates a graduated response short of formal administrative penalties—consistent with the broader trend in Chinese administrative law toward “soft” compliance tools before hard sanctions. Interview/约谈 powers (Article 19) continue the well-established practice under cybersecurity and data-security laws. Major-risk reporting obligations (Article 18) feed into the national risk-early-warning and incident-reporting systems required by the Cybersecurity Law and Data Security Law.
Confidentiality, Technical Support and Accountability Articles 20–22 strengthen confidentiality obligations (aligning with Personal Information Protection Law and state-secret rules) and impose background checks and full-process management on third-party technical supporters. This addresses practical risks of data leakage during penetration testing while preserving public security organs’ ability to leverage external expertise. Liability provisions for both public security personnel and technical providers reinforce the accountability mechanisms already present in the People’s Police Law and Criminal Law.
Overall Significance The Measures complete the transition of public security organs’ role from primarily “internet police” under the 2018 framework to a comprehensive cyberspace-security supervisor operating within the modern tripartite (network–data–information) regulatory system. They balance expanded substantive powers with procedural constraints and inter-agency coordination, reflecting both the heightened national-security emphasis of recent years and the policy goal of reducing unnecessary burdens on digital-economy participants. Implementation from October 2026 will test how effectively the coordination mechanisms and burden-reduction rules function in practice across China’s multi-level public security apparatus and sectoral regulators.
3. Breadth of Application
1. Individuals in China (Chinese citizens and foreigners) Article 5 of the Measures expressly contemplates natural persons as inspection subjects and assigns jurisdiction to the public security organ of the individual’s habitual residence. Article 6’s functional categories (network operators, data processors, personal information handlers, etc.) are not limited by nationality.
Caveat / interpretive note: The Measures do not contain an explicit statement that ordinary private, non-commercial use of networks by individuals falls within scope. In practice, inspection of pure personal users appears unlikely unless the individual performs one of the listed functional roles at scale. Whether low-level or incidental processing triggers inspection remains an enforcement-practice question rather than a clear textual rule.
2. Domestic and foreign economic and nonprofit entities The language of Articles 2 and 6 is functional rather than organisational-form-specific. Entities performing the listed roles—whether Chinese companies, foreign-invested enterprises, representative offices, or nonprofits—are covered if they operate within the territorial jurisdiction rules of Article 5.
Caveat: The Measures themselves do not contain a detailed list of covered legal forms. Coverage of nonprofits and foreign-invested entities follows from the functional definitions plus the place-of-operations test; it is a reasoned reading rather than an express enumeration.
3. Extraterritorial effects The Measures are drafted as territorial enforcement tools. Jurisdiction is tied to the location of the operational institution or the individual’s habitual residence inside China (Article 5). There is no freestanding grant of authority for public security organs to conduct physical inspections outside Chinese territory.
Interpretive assessment (flagged as such): Meaningful extraterritorial effects can arise indirectly through the underlying statutes the Measures implement—particularly PIPL Article 3 and Data Security Law Article 2—when foreign entities target Chinese users, process data of persons in China, or maintain a local operational footprint. How aggressively public security organs will use local affiliates, data centres, or staff as the practical entry point for inspection is an enforcement question on which the Measures themselves are silent. Purely overseas activities with no China nexus remain outside the text of these particular inspection powers.
4. Comparative Analysis (E.U.; U.S. and Brazil)
China’s Measures (MPS Order No. 176, effective 1 October 2026) give public security organs broad, proactive powers to conduct online patrols, remote vulnerability/penetration testing, and on-site inspections of network operators, data processors, personal information handlers, critical information infrastructure (CII) operators, and related entities. The focus is on cybersecurity + data security + information security obligations, with graded inspection frequency, inter-agency coordination requirements, soft tools (reminder letters, interviews), and strong confidentiality rules.
The comparison treats the Chinese Measures as one model among several. Statements about relative “breadth,” “proactivity,” or “strength” are interpretive judgments, not objective rankings.
The closest E.U. analogues are the NIS2 Directive (Directive (EU) 2022/2555) for cybersecurity of essential and important entities, and the GDPR (Regulation (EU) 2016/679) for personal data protection. National competent authorities (often cybersecurity agencies or data-protection authorities) exercise the powers. In contrast, in the U.S., there is no single comprehensive equivalent. The US system is highly fragmented across voluntary frameworks, sector-specific regulation, and law-enforcement investigative powers. Lastly, in Brazil, the main instruments are the LGPD (Lei Geral de Proteção de Dados, Law 13.709/2018) enforced by the ANPD (Autoridade Nacional de Proteção de Dados), plus a more fragmented cybersecurity landscape (National Cybersecurity Policy, sector-specific rules from Central Bank, ANATEL, etc.). Brazil lacks a single police-led cyberspace inspection regime comparable to China’s.
European Union (NIS2 + GDPR)
NIS2 gives national competent authorities powers of on-site inspection, security audits, and security scans; essential entities face more proactive (ex ante) supervision than important entities. GDPR Article 58 grants data-protection authorities access to premises and processing equipment.
Similarities: Both systems authorise on-site inspections and technical reviews of cybersecurity / data-security obligations.
Differences (interpretive): The Chinese model places primary authority with public security organs and expressly contemplates remote vulnerability/penetration testing with prior notice. EU supervision is generally exercised by specialised civilian or independent regulatory authorities rather than police. Whether the Chinese coordination rules (industry-regulator lead on routine checks, result-reuse) will prove more effective at reducing burden than EU mutual-assistance mechanisms is an empirical question that cannot yet be answered from the text alone.
United States
No single federal statute creates a routine, police-led administrative inspection regime comparable in structure to the Chinese Measures. CISA possesses limited administrative subpoena authority for identifying owners of certain vulnerable systems; continuous monitoring programmes such as CyberSentry are consent-based; most on-site or remote access by law enforcement requires a warrant.
Interpretive note: The absence of a direct equivalent does not mean U.S. authorities lack tools—sectoral regulators and criminal investigative powers exist—but the institutional design (fragmented, partnership-oriented, warrant-constrained) differs markedly from the centralised administrative model in the Measures. Claims that one system is “stronger” or “weaker” overall depend on the metric chosen (routine reach versus constitutional limits, for example) and are therefore judgments rather than textual facts.
Brazil
The ANPD possesses investigatory powers under the LGPD, including the ability to request information, conduct audits, and access premises and systems. Cybersecurity obligations remain more sectoral and less centralised than in China.
Caveat: Brazil has been moving toward more active oversight, but the ANPD model remains that of an independent data-protection authority rather than a public-security organ with integrated cybersecurity, data-security, and information-security inspection powers. Direct parallels should therefore be drawn cautiously.
Overall Framing Caveats
- The Measures are new (promulgated August 2026, effective October 2026). Actual enforcement practice, resource allocation, and inter-agency coordination behaviour will only become clear over time.
- Many operational details (exact thresholds for “priority” inspection, frequency of remote testing, willingness to issue reminder letters versus formal penalties) are left to implementation and are not fixed by the text.
- Comparative statements about “breadth,” “proactivity,” or institutional philosophy are analytical observations, not definitive legal conclusions. Different legal systems prioritise different values (centralised administrative efficiency versus institutional independence and warrant requirements); ranking them requires explicit normative criteria that the Measures themselves do not supply.
- Each set of measures will be interpreted and applied in ways that align to national ideologies, the way in which each understands key terms, and the overall fundamental political lines of each state, especially when transposed into cultures of national security; all of this strongly suggests but does not "prove that these measures will signal as well as permit a much more comprehensive approach to the protection of naitonal security and a significantly broader ambit of state "permission" to observe, categorize, determine, and punish infraction.
- The breadth of ambiguity will prove substantial space, within the confines of national practice, culture, expectations, and political and constitutional constraints, to exercise discreiton in the application of the measures, and in the process, where these discretionary actions become routinized or expected, to effectively make or create de facto regulation, in the process adding depth but also substance to the measures .
- Where these measures intersect, or where efforts are made to project the measures outward into another jurisdiction, one can expect substantial and sharp countermeasures, These will not be confined to the legal-administrative sphere but will have substantial political and strategic effects.
Below is a more comprehensive effort to compare 《公安机关网络空间安全监督检查办法》with what I might suggest are the closest frameworks in the US, EU, and Brazil. The full text of Ministry of Public Security Order No. 176 in the original Chinese and in English also follow below.









