![]() |
Pix credit here (Family members, relatives and friends of criminal secret agents, you must supervise and urge criminals to register and turn over a new leaf!"; 1950) |
On 6 August 2026, Wang Xiaohong, Minister of Public Security, had promulgated the Measures for the Supervision and Inspection of Cyberspace Security by
Public Security Organs [《公安机关网络空间安全监督检查办法》](Ministry of Public Security Order No. 176), to take effect on October 1, 2026 at which time the 2018 "Provisions on the
Supervision and Inspection of Internet Security by Public Security
Organs" (Ministry of Public Security Order No. 151) would be repealed. The new measure consists of 23 articles, covering aspects such as the subjects, methods, content, and mechanisms of supervision and inspection, the application of inspection results, and legal liabilities. [这是《公安机关网络空间安全监督检查办法》(公安部令第176号)的官方原文页面。该办法于2026年8月6日由公安部部长王小洪签署公布,自页面包含完整正文(共23条),内容涵盖监督检查对象、方式、内容、机制、结果运用及法律责任等。].
Ministry of Public Security Order No. 176 will prove controversial and their scope and application at home and abroad have yet to be revealed. With the aid of Grok, this post includes (1) a summary of the new measures; (2) an analysis of the provisions of Ministry of Public Security Order No. 176 in the context of Chinese law; (3) an initial consideration of possible breadth of application to individuals and enterprises; and (4) an initial consideration of a comparison of Ministry of Public Security Order No. 176 with what may come close to being equivalent measures in the United States, the European Union, and Brazil.
1. Summary Measures for the Supervision and Inspection of Cyberspace Security by Public Security Organs (Ministry of Public Security Order No. 176)
Promulgated on 6 August 2026 by Minister Wang Xiaohong after approval at the 2nd Ministry of Public Security ministerial meeting on 1 July 2026. The Measures take effect on 1 October 2026 and simultaneously repeal the 2018 Provisions on the Supervision and Inspection of Internet Security by Public Security Organs (MPS Order No. 151).
Purpose and Scope (Articles 1–2) The Measures aim to safeguard national security and public interests, protect the legitimate rights of citizens, legal persons and other organizations, standardize public security organs’ cyberspace security inspections, and prevent/combat cyber-related illegal activities and crimes. They are enacted pursuant to the People’s Police Law, Cybersecurity Law, Data Security Law, Personal Information Protection Law, Critical Information Infrastructure Security Protection Regulations, Network Data Security Management Regulations, and Internet Information Services Management Measures.
They apply to public security organs’ inspections of network operators, data processors, personal information handlers and others regarding their fulfilment of statutory cybersecurity, data security and information security obligations. “Cyberspace security” is expressly defined as encompassing cybersecurity + data security + information security.
Guiding Principles and Coordination (Article 3) Inspections must be conducted under the leadership of the Central Cyberspace Affairs Commission and related bodies, following the principles of lawful and scientific management that both ensures security and promotes development. Public security organs must strictly observe statutory authority and procedures, improve enforcement methods, and establish coordination mechanisms with competent industry regulators. For routine on-site inspections where an industry regulator exists, the industry regulator shall normally take the lead. A graded and classified inspection system must be established, subject to supervision by inspected entities and the public.
Inspection Methods (Article 4)
- Online patrols: network information monitoring, information-review capability testing, vulnerability scanning and similar non-disruptive methods within the jurisdiction. Advance notice (3 working days) is required for information-review capability tests.
- Remote testing (municipal-level and above public security organs): vulnerability probing and penetration testing of network facilities and information systems other than critical information infrastructure, again with 3 working days’ prior notice, no disruption of normal operations, and notification to the same-level cyberspace administration and industry regulators. Special rules apply to basic telecommunications networks under the Critical Information Infrastructure regulations. Risks discovered online or remotely must be verified; on-site inspection may be used when necessary.
Jurisdiction (Article 5) On-site inspections are conducted by the county-level or higher public security organ of the place where the inspected entity’s operational institution is located (actual main place of operations, management office, network facilities, or industrial/commercial registration). For individuals, the place of habitual residence applies. Jurisdictional disputes are resolved by the common superior organ. Higher-level organs supervise lower-level ones and may elevate or organize inspections.
Inspected Entities (Article 6) Public security organs may inspect: (1) Internet service providers (access, data centres, CDN, domain-name, information services, etc.); (2) public Internet access service providers; (3) network operators and their builders/maintainers; (4) critical information infrastructure operators and their builders/maintainers; (5) network product and service providers; (6) data processors; (7) personal information handlers; (8) other entities subject to inspection by law.
Entities that have previously suffered security incidents or have been administratively punished for non-compliance and failed to rectify are priorities.
Inspection Content (Articles 7–8) Routine inspections focus on 11 categories of statutory obligations, including: network unit filing and user/log retention; security management systems; multi-level protection scheme (MLPS) obligations; critical information infrastructure protection; technical measures against viruses/attacks; vulnerability remediation; content filtering for prohibited information; algorithm security responsibilities; data security and personal information protection obligations; and technical support/assistance to public security organs for national security, counter-terrorism and criminal investigation.
During major national security protection tasks (or for key counter-terrorism targets), special inspections examine contingency plans, risk assessments, emergency drills, additional protective measures and incident reporting.
Frequency, Coordination and Burden Reduction (Articles 9–10) Routine on-site inspections are coordinated under national cybersecurity and data-security mechanisms to avoid duplication. Level-3 (and above) MLPS networks and critical information infrastructure operators receive one routine on-site inspection per year; results of inspections already conducted by other competent authorities in the same year are reused. Special or case-related inspections proceed as needed under statutory procedures.
Multi-industry/department routine inspections ordered by the Ministry of Public Security require Central Cyberspace Affairs Commission approval (with additional coordination for data security or content/ideology issues). Basic telecommunications network inspections are conducted at municipal level or above. Inspections of telecommunications, energy, transport, water conservancy, finance, defence science & industry and similar sectors require 5 working days’ prior notice to the cyberspace administration and industry regulators, who may request joint inspections. Results are promptly shared with those departments.
On-site Powers and Procedures (Articles 11–15) At least two people’s police officers must participate and present police credentials plus a written inspection notice issued by a county-level or higher public security organ. Powers include: entering premises/machine rooms; questioning responsible persons or security managers; inspecting and copying relevant materials; examining technical protective measures; and conducting vulnerability probing/penetration testing.
Public security organs may engage qualified cybersecurity service institutions or specialists for technical support (subject to higher-level filing). Such personnel operate under police command, must sign confidentiality undertakings covering trade secrets, personal privacy and personal information, and undergo background checks for penetration-testing work. For critical information infrastructure, the industry regulator must be informed.
Inspections must be objective and impartial; no fees may be charged and no designated products/services may be required. Written records must be prepared and signed by the officers and the inspected entity’s representative (or noted if signature is refused). Remote-testing records are signed by the officers; technical-support personnel also sign when involved. Materials are archived.
Outcomes and Follow-up (Articles 16–19) Risks and hazards are noted and the entity is guided to eliminate them. Non-compliance triggers legal liability under the Cybersecurity Law, Data Security Law, Personal Information Protection Law and related regulations.
Where risks do not yet constitute illegal/criminal conduct, public security organs may:
- issue a “Public Security Reminder Letter” (公安提示函) to the entity (county level and above);
- issue a reminder letter to the industry regulator (municipal level and above);
- issue a non-entity-specific public notice (provincial level and above).
Major risks affecting Level-3+ networks, critical information infrastructure or important data are promptly reported to industry regulators and the cyberspace administration. Severe regional or sectoral risks threatening national security, public security or the public interest are reported to the people’s government and higher public security organs, with possible public notices.
Provincial-level or higher public security organs may interview the legal representative or principal responsible person of a network operator that presents significant risk or has suffered an incident. County-level or higher organs may interview relevant organisations or individuals concerning data- or personal-information-related risks/incidents. Interviewees must rectify.
Confidentiality and Liability (Articles 20–22) Public security personnel and engaged technical-support providers must protect state secrets, work secrets, trade secrets, personal privacy and personal information obtained during inspections; such information may be used only for cyberspace security purposes. After inspection, technical-support providers must return or destroy materials as directed.
Abuse of power, dereliction of duty or favouritism by public security personnel leads to disciplinary or criminal liability. Technical-support providers who engage in illegal intrusion, disruption, data theft or unauthorised disclosure of secrets/privacy face administrative or criminal penalties.
Entry into Force (Article 23) Effective 1 October 2026; the 2018 Internet Security Inspection Provisions are repealed.
2. Analysis of Provisions in the Context of Chinese Law
These Measures represent a significant evolution of China’s cybersecurity regulatory architecture and the role of the public security organs (公安机关) within it.
From “Internet Security” to “Cyberspace Security” The 2018 Provisions (Order No. 151) focused narrowly on “internet security.” The 2026 Measures deliberately broaden the concept to “cyberspace security,” explicitly encompassing cybersecurity, data security and information security. This mirrors the post-2016 legislative expansion: Cybersecurity Law (2017), Data Security Law (2021), Personal Information Protection Law (2021), Critical Information Infrastructure Security Protection Regulations (2021) and Network Data Security Management Regulations (2024/2025). The public security organs’ inspection mandate is thereby aligned with the full suite of modern Chinese digital-security legislation rather than remaining limited to the older “internet” framing.
Integration into the Multi-Layer Governance System Article 3 places inspections under the leadership of the Central Cyberspace Affairs Commission (and related mechanisms). This reflects China’s dual-track governance model in which the Cyberspace Administration of China (CAC / 网信办) holds overall coordination and content/ideology responsibilities, while public security organs retain strong enforcement, technical-inspection and criminal-investigation powers. The Measures carefully allocate roles: industry regulators take the lead on routine on-site checks where they exist; public security organs coordinate rather than unilaterally dominate; and multi-sector inspections require Central Cyberspace Affairs Commission approval. This reduces inter-agency friction and responds to long-standing industry complaints about overlapping inspections.
Expansion of Inspected Subjects and Content The list of inspectable entities (Article 6) is broader than the 2018 version and now expressly includes data processors and personal information handlers—directly implementing the Data Security Law and Personal Information Protection Law. Inspection content (Article 7) adds algorithm security responsibilities, data-security and personal-information protection obligations, and the duty to provide technical assistance for national-security, counter-terrorism and criminal investigations (echoing Cybersecurity Law Art. 28 and related provisions). Special inspections during major security tasks and for counter-terrorism targets further embed the Measures in China’s national-security and counter-terrorism legal framework.
Procedural Safeguards and Burden Reduction Compared with the 2018 rules, the 2026 Measures contain more detailed procedural protections: advance notice for remote testing and capability tests; requirement of two officers and written notice; prohibition on fees and designated products; reuse of other regulators’ inspection results; and explicit coordination to avoid duplication. These provisions respond to both the Administrative Licensing Law / Administrative Penalty Law principles of proportionality and fairness and to practical business concerns about regulatory burden. The graded/classified approach and annual-inspection ceiling for high-level systems further operationalise risk-based supervision.
Enforcement Toolbox and Soft-Law Instruments The introduction of the “Public Security Reminder Letter” (公安提示函) and non-entity-specific public notices (Article 17) creates a graduated response short of formal administrative penalties—consistent with the broader trend in Chinese administrative law toward “soft” compliance tools before hard sanctions. Interview/约谈 powers (Article 19) continue the well-established practice under cybersecurity and data-security laws. Major-risk reporting obligations (Article 18) feed into the national risk-early-warning and incident-reporting systems required by the Cybersecurity Law and Data Security Law.
Confidentiality, Technical Support and Accountability Articles 20–22 strengthen confidentiality obligations (aligning with Personal Information Protection Law and state-secret rules) and impose background checks and full-process management on third-party technical supporters. This addresses practical risks of data leakage during penetration testing while preserving public security organs’ ability to leverage external expertise. Liability provisions for both public security personnel and technical providers reinforce the accountability mechanisms already present in the People’s Police Law and Criminal Law.
Overall Significance The Measures complete the transition of public security organs’ role from primarily “internet police” under the 2018 framework to a comprehensive cyberspace-security supervisor operating within the modern tripartite (network–data–information) regulatory system. They balance expanded substantive powers with procedural constraints and inter-agency coordination, reflecting both the heightened national-security emphasis of recent years and the policy goal of reducing unnecessary burdens on digital-economy participants. Implementation from October 2026 will test how effectively the coordination mechanisms and burden-reduction rules function in practice across China’s multi-level public security apparatus and sectoral regulators.
3. Breadth of Application
1. Individuals in China (Chinese citizens and foreigners) Article 5 of the Measures expressly contemplates natural persons as inspection subjects and assigns jurisdiction to the public security organ of the individual’s habitual residence. Article 6’s functional categories (network operators, data processors, personal information handlers, etc.) are not limited by nationality.
Caveat / interpretive note: The Measures do not contain an explicit statement that ordinary private, non-commercial use of networks by individuals falls within scope. In practice, inspection of pure personal users appears unlikely unless the individual performs one of the listed functional roles at scale. Whether low-level or incidental processing triggers inspection remains an enforcement-practice question rather than a clear textual rule.
2. Domestic and foreign economic and nonprofit entities The language of Articles 2 and 6 is functional rather than organisational-form-specific. Entities performing the listed roles—whether Chinese companies, foreign-invested enterprises, representative offices, or nonprofits—are covered if they operate within the territorial jurisdiction rules of Article 5.
Caveat: The Measures themselves do not contain a detailed list of covered legal forms. Coverage of nonprofits and foreign-invested entities follows from the functional definitions plus the place-of-operations test; it is a reasoned reading rather than an express enumeration.
3. Extraterritorial effects The Measures are drafted as territorial enforcement tools. Jurisdiction is tied to the location of the operational institution or the individual’s habitual residence inside China (Article 5). There is no freestanding grant of authority for public security organs to conduct physical inspections outside Chinese territory.
Interpretive assessment (flagged as such): Meaningful extraterritorial effects can arise indirectly through the underlying statutes the Measures implement—particularly PIPL Article 3 and Data Security Law Article 2—when foreign entities target Chinese users, process data of persons in China, or maintain a local operational footprint. How aggressively public security organs will use local affiliates, data centres, or staff as the practical entry point for inspection is an enforcement question on which the Measures themselves are silent. Purely overseas activities with no China nexus remain outside the text of these particular inspection powers.
4. Comparative Analysis (E.U.; U.S. and Brazil)
China’s Measures (MPS Order No. 176, effective 1 October 2026) give public security organs broad, proactive powers to conduct online patrols, remote vulnerability/penetration testing, and on-site inspections of network operators, data processors, personal information handlers, critical information infrastructure (CII) operators, and related entities. The focus is on cybersecurity + data security + information security obligations, with graded inspection frequency, inter-agency coordination requirements, soft tools (reminder letters, interviews), and strong confidentiality rules.
The comparison treats the Chinese Measures as one model among several. Statements about relative “breadth,” “proactivity,” or “strength” are interpretive judgments, not objective rankings.
The closest E.U. analogues are the NIS2 Directive (Directive (EU) 2022/2555) for cybersecurity of essential and important entities, and the GDPR (Regulation (EU) 2016/679) for personal data protection. National competent authorities (often cybersecurity agencies or data-protection authorities) exercise the powers. In contrast, in the U.S., there is no single comprehensive equivalent. The US system is highly fragmented across voluntary frameworks, sector-specific regulation, and law-enforcement investigative powers. Lastly, in Brazil, the main instruments are the LGPD (Lei Geral de Proteção de Dados, Law 13.709/2018) enforced by the ANPD (Autoridade Nacional de Proteção de Dados), plus a more fragmented cybersecurity landscape (National Cybersecurity Policy, sector-specific rules from Central Bank, ANATEL, etc.). Brazil lacks a single police-led cyberspace inspection regime comparable to China’s.
European Union (NIS2 + GDPR)
NIS2 gives national competent authorities powers of on-site inspection, security audits, and security scans; essential entities face more proactive (ex ante) supervision than important entities. GDPR Article 58 grants data-protection authorities access to premises and processing equipment.
Similarities: Both systems authorise on-site inspections and technical reviews of cybersecurity / data-security obligations.
Differences (interpretive): The Chinese model places primary authority with public security organs and expressly contemplates remote vulnerability/penetration testing with prior notice. EU supervision is generally exercised by specialised civilian or independent regulatory authorities rather than police. Whether the Chinese coordination rules (industry-regulator lead on routine checks, result-reuse) will prove more effective at reducing burden than EU mutual-assistance mechanisms is an empirical question that cannot yet be answered from the text alone.
United States
No single federal statute creates a routine, police-led administrative inspection regime comparable in structure to the Chinese Measures. CISA possesses limited administrative subpoena authority for identifying owners of certain vulnerable systems; continuous monitoring programmes such as CyberSentry are consent-based; most on-site or remote access by law enforcement requires a warrant.
Interpretive note: The absence of a direct equivalent does not mean U.S. authorities lack tools—sectoral regulators and criminal investigative powers exist—but the institutional design (fragmented, partnership-oriented, warrant-constrained) differs markedly from the centralised administrative model in the Measures. Claims that one system is “stronger” or “weaker” overall depend on the metric chosen (routine reach versus constitutional limits, for example) and are therefore judgments rather than textual facts.
Brazil
The ANPD possesses investigatory powers under the LGPD, including the ability to request information, conduct audits, and access premises and systems. Cybersecurity obligations remain more sectoral and less centralised than in China.
Caveat: Brazil has been moving toward more active oversight, but the ANPD model remains that of an independent data-protection authority rather than a public-security organ with integrated cybersecurity, data-security, and information-security inspection powers. Direct parallels should therefore be drawn cautiously.
Overall Framing Caveats
- The Measures are new (promulgated August 2026, effective October 2026). Actual enforcement practice, resource allocation, and inter-agency coordination behaviour will only become clear over time.
- Many operational details (exact thresholds for “priority” inspection, frequency of remote testing, willingness to issue reminder letters versus formal penalties) are left to implementation and are not fixed by the text.
- Comparative statements about “breadth,” “proactivity,” or institutional philosophy are analytical observations, not definitive legal conclusions. Different legal systems prioritise different values (centralised administrative efficiency versus institutional independence and warrant requirements); ranking them requires explicit normative criteria that the Measures themselves do not supply.
- Each set of measures will be interpreted and applied in ways that align to national ideologies, the way in which each understands key terms, and the overall fundamental political lines of each state, especially when transposed into cultures of national security; all of this strongly suggests but does not "prove that these measures will signal as well as permit a much more comprehensive approach to the protection of naitonal security and a significantly broader ambit of state "permission" to observe, categorize, determine, and punish infraction.
- The breadth of ambiguity will prove substantial space, within the confines of national practice, culture, expectations, and political and constitutional constraints, to exercise discreiton in the application of the measures, and in the process, where these discretionary actions become routinized or expected, to effectively make or create de facto regulation, in the process adding depth but also substance to the measures .
- Where these measures intersect, or where efforts are made to project the measures outward into another jurisdiction, one can expect substantial and sharp countermeasures, These will not be confined to the legal-administrative sphere but will have substantial political and strategic effects.
Below is a more comprehensive effort to compare 《公安机关网络空间安全监督检查办法》with what I might suggest are the closest frameworks in the US, EU, and Brazil. The full text of Ministry of Public Security Order No. 176 in the original Chinese and in English also follow below.
Comparison of China’s 2026 Measures for the Supervision and Inspection of Cyberspace Security by Public Security Organs with Equivalents in the United States, European Union, and Brazil
China’s Measures (MPS Order No. 176, effective 1 October 2026) give public security organs broad, proactive powers to conduct online patrols, remote vulnerability/penetration testing, and on-site inspections of network operators, data processors, personal information handlers, critical information infrastructure (CII) operators, and related entities. The focus is on cybersecurity + data security + information security obligations, with graded inspection frequency, inter-agency coordination requirements, soft tools (reminder letters, interviews), and strong confidentiality rules. Below is a structured comparison with the closest frameworks in the US, EU, and Brazil.
1. European Union
The closest analogues are the NIS2 Directive (Directive (EU) 2022/2555) for cybersecurity of essential and important entities, and the GDPR (Regulation (EU) 2016/679) for personal data protection. National competent authorities (often cybersecurity agencies or data-protection authorities) exercise the powers.
| Aspect | China (2026 Measures) | EU (NIS2 + GDPR) |
|---|---|---|
| Scope | Broad: network operators, data processors, PI handlers, CII, product/service providers, etc. Includes individuals in some cases. Explicitly covers cybersecurity, data security, and information/content security. | NIS2: Essential and important entities in critical sectors (energy, transport, banking, health, digital infrastructure, public administration, etc.). GDPR: All controllers/processors of personal data. Narrower cybersecurity focus under NIS2; data protection under GDPR. |
| Inspection powers | Online patrols, remote vulnerability/penetration testing (with notice), on-site entry, questioning, copying materials, technical testing. At least two officers + written notice required for on-site. Can engage third-party technical support under police command. | NIS2: On-site inspections (including random/unannounced for essential entities), off-site supervision, security audits (regular, targeted, ad hoc), security scans, information requests, access to data/documents. GDPR Art. 58: Access to premises and processing equipment, data protection audits, information orders. Unannounced inspections possible. |
| Proactivity & frequency | Routine annual on-site for Level-3+ MLPS and CII; reuse of other regulators’ results; risk-based priority for prior incidents/non-compliance. Online/remote methods continuous. | NIS2: Proactive (ex ante) ongoing supervision for essential entities; largely ex post for important entities. Risk-based prioritisation allowed. GDPR: Complaint-driven or own-initiative investigations. |
| Coordination & burden reduction | Strong emphasis: industry regulators normally lead routine on-site checks; multi-sector checks need Central Cyberspace Affairs Commission approval; 5-day notice + joint option for key sectors; results shared. | NIS2 requires cooperation with GDPR supervisory authorities on personal-data incidents. Cross-border cooperation and mutual assistance among Member States. Less explicit “avoid duplication” language than China’s Measures. |
| Soft tools & outcomes | Public Security Reminder Letters, public notices, interviews (约谈) of legal representatives, guidance to remediate before formal penalties. | Warnings, reprimands, orders to cease/comply/inform, appointment of monitoring officers, temporary suspension of certifications/authorisations. Administrative fines (up to €10m / 2% worldwide turnover under NIS2; up to €20m / 4% under GDPR). |
| Extraterritorial reach | Primarily territorial enforcement, but underlying laws (PIPL, DSL) reach foreign entities targeting China or harming Chinese interests; local presence/affiliates can be inspected. | NIS2 applies to entities providing services in the EU (even without establishment, via representative). GDPR has strong extraterritorial application (Art. 3) for targeting EU data subjects. |
| Key differences | Police-led, national-security oriented, integrates content/algorithm security, allows remote penetration testing with notice. Stronger inter-agency coordination mandates to reduce burden. | Civilian/regulatory-agency led (not primarily police). Stronger formal independence of supervisors, higher maximum fines, more emphasis on independent audits. Unannounced inspections more readily available for essential entities. |
Overall, the EU frameworks are the closest functional equivalents in terms of structured supervisory and inspection powers over cybersecurity and data security, but they are more fragmented (cyber vs data protection) and less police-centric.
2. United States
There is no single comprehensive equivalent. The US system is highly fragmented across voluntary frameworks, sector-specific regulation, and law-enforcement investigative powers.
| Aspect | China (2026 Measures) | United States |
|---|---|---|
| Scope | Broad functional coverage of network/data/PI operators and CII. | Critical infrastructure (16 sectors) under CISA coordination; sector regulators (e.g., FCC, SEC, DOE, TSA); CIRCIA mandatory incident reporting for certain CI entities. No general “data processor” or “personal information handler” inspection regime at federal level. |
| Inspection powers | Routine/proactive online, remote technical testing, and on-site with relatively low formal barriers (police credentials + notice). | CISA: Limited administrative subpoena power mainly to identify owners of vulnerable internet-connected CI systems for notification purposes. CyberSentry continuous monitoring is consent-based. Sector regulators have varying audit/inspection authority. FBI/DOJ: Criminal investigative powers (warrants under Rule 41 for searches, including remote access in some botnet cases). No general proactive remote penetration-testing authority against private entities without consent or warrant. |
| Proactivity | Explicit routine annual inspections for higher-risk systems + continuous online methods. | Mostly voluntary partnerships, risk assessments, and information sharing. Mandatory elements are narrower (incident reporting under CIRCIA; sector-specific rules). Emergency orders possible in limited cases (e.g., grid security). |
| Coordination | Detailed rules requiring coordination with industry regulators and cyberspace authorities to avoid duplication. | Complex multi-agency model (CISA as National Coordinator, Sector Risk Management Agencies, FBI for threat response). Public-private partnerships emphasised; less formal “reuse of results” mandate. |
| Outcomes | Graduated soft tools (reminder letters, interviews) before penalties under underlying laws. | Civil enforcement by sector agencies/FTC; criminal prosecution by DOJ. No direct equivalent of the “Public Security Reminder Letter.” |
| Key differences | Centralised police-led administrative inspection regime with technical testing powers. | Strong constitutional limits (Fourth Amendment warrants for most on-site/remote searches), preference for voluntary cooperation, and sectoral fragmentation. Far less routine proactive inspection authority outside regulated sectors or criminal investigations. |
The US approach prioritises partnership, information sharing, and targeted law-enforcement action over routine administrative inspections by police.
3. Brazil
The main instruments are the LGPD (Lei Geral de Proteção de Dados, Law 13.709/2018) enforced by the ANPD (Autoridade Nacional de Proteção de Dados), plus a more fragmented cybersecurity landscape (National Cybersecurity Policy, sector-specific rules from Central Bank, ANATEL, etc.). Brazil lacks a single police-led cyberspace inspection regime comparable to China’s.
| Aspect | China (2026 Measures) | Brazil (LGPD/ANPD + cybersecurity rules) |
|---|---|---|
| Scope | Broad cybersecurity + data + information security across many entity types. | LGPD: Personal data controllers and processors (public and private). Cybersecurity obligations exist mainly via sector regulators or general security principles in LGPD; no comprehensive equivalent of China’s multi-level protection + CII inspection regime. |
| Inspection powers | Online, remote technical testing, on-site entry/questioning/copying by public security organs. | ANPD: Monitoring, guidance, preventive and repressive activities; can request information, conduct audits, and perform on-site inspections/access to premises, equipment, systems and data. Controllers must cooperate and allow access. Sector regulators have their own audit powers. |
| Proactivity | Routine scheduled inspections for higher-risk systems + continuous online methods. | ANPD uses a mix of monitoring, sample inspections, complaint/incident-driven actions, and priority programmes. Moving toward more active oversight, but historically more guidance-oriented. |
| Coordination | Explicit multi-agency coordination and burden-reduction rules. | ANPD coordinates with sector regulators; cooperation agreements possible. Less detailed statutory anti-duplication rules than China’s Measures. |
| Outcomes | Reminder letters, interviews, guidance, then liability under CSL/DSL/PIPL etc. | Warnings, fines (up to 2% of Brazilian group revenue, capped at BRL 50 million per violation), public disclosure, suspension of database operations, temporary prohibition on processing. |
| Key differences | Police (public security) as primary inspector with strong technical testing powers and national-security framing. | Independent data-protection authority (ANPD) as primary enforcer for personal data; cybersecurity more sectoral and less centralised. ANPD has on-site powers but operates in a more regulatory/administrative (less police) model. |
Comparative Analysis
The comparison treats the Chinese Measures as one model among several. Statements about relative “breadth,” “proactivity,” or “strength” are interpretive judgments, not objective rankings.
European Union (NIS2 + GDPR) NIS2 gives national competent authorities powers of on-site inspection, security audits, and security scans; essential entities face more proactive (ex ante) supervision than important entities. GDPR Article 58 grants data-protection authorities access to premises and processing equipment.
Similarities: Both systems authorise on-site inspections and technical reviews of cybersecurity / data-security obligations.
Differences (interpretive): The Chinese model places primary authority with public security organs and expressly contemplates remote vulnerability/penetration testing with prior notice. EU supervision is generally exercised by specialised civilian or independent regulatory authorities rather than police. Whether the Chinese coordination rules (industry-regulator lead on routine checks, result-reuse) will prove more effective at reducing burden than EU mutual-assistance mechanisms is an empirical question that cannot yet be answered from the text alone.
United States No single federal statute creates a routine, police-led administrative inspection regime comparable in structure to the Chinese Measures. CISA possesses limited administrative subpoena authority for identifying owners of certain vulnerable systems; continuous monitoring programmes such as CyberSentry are consent-based; most on-site or remote access by law enforcement requires a warrant.
Interpretive note: The absence of a direct equivalent does not mean U.S. authorities lack tools—sectoral regulators and criminal investigative powers exist—but the institutional design (fragmented, partnership-oriented, warrant-constrained) differs markedly from the centralised administrative model in the Measures. Claims that one system is “stronger” or “weaker” overall depend on the metric chosen (routine reach versus constitutional limits, for example) and are therefore judgments rather than textual facts.
Brazil The ANPD possesses investigatory powers under the LGPD, including the ability to request information, conduct audits, and access premises and systems. Cybersecurity obligations remain more sectoral and less centralised than in China.
Caveat: Brazil has been moving toward more active oversight, but the ANPD model remains that of an independent data-protection authority rather than a public-security organ with integrated cybersecurity, data-security, and information-security inspection powers. Direct parallels should therefore be drawn cautiously.
Overall Framing Caveats
- The Measures are new (promulgated August 2026, effective October 2026). Actual enforcement practice, resource allocation, and inter-agency coordination behaviour will only become clear over time.
- Many operational details (exact thresholds for “priority” inspection, frequency of remote testing, willingness to issue reminder letters versus formal penalties) are left to implementation and are not fixed by the text.
- Comparative statements about “breadth,” “proactivity,” or institutional philosophy are analytical observations, not definitive legal conclusions. Different legal systems prioritise different values (centralised administrative efficiency versus institutional independence and warrant requirements); ranking them requires explicit normative criteria that the Measures themselves do not supply.
Summary of Comparative Positioning
- Closest overall: EU (NIS2 + GDPR) — structured supervisory powers, on-site and technical inspection tools, risk-based approach, and extraterritorial elements.
- Most different: United States — fragmented, partnership-heavy, warrant-constrained, and less routine administrative inspection authority.
- Intermediate: Brazil — solid data-protection inspection powers via ANPD, but weaker and more fragmented pure cybersecurity inspection regime compared with China’s integrated, police-led model.
China’s Measures stand out for placing primary inspection authority with public security organs, explicitly combining cybersecurity/data/information security, authorising remote penetration-style testing (with notice), and embedding detailed inter-agency coordination rules aimed at reducing regulatory burden. The EU comes closest in the breadth of supervisory tools, while the US and Brazil remain more specialised or fragmented.
中华人民共和国公安 部 令
第176号
《公安机关网络空间安全监督检查办法》已经2026年7月1日第2次公安部部务会议审议通过,现予以公布,自2026年10月1日起施行。
部 长 王小洪
2026年8月6日
公安机关网络空间安全监督检查办法
第一条 为了维护国家安全和社会公共利益,保障公民、法人和其他组织合法权益,规范公安机关对网络空间安全的监督检查工作,防范、治理网络违法犯罪,根据《中华人民共和国人民警察法》《中华人民共和国网络安全法》《中华人民共和国数据安全法》《中华人民共和国个人信息保护法》《关键信息基础设施安全保护条例》《网络数据安全管理条例》《互联网信息服务管理办法》等有关法律、行政法规规定,制定本办法。
第二条 本办法适用于公安机关依法对网络运营者、数据处理者、个人信息处理者等履行法律法规规定的网络安全、数据安全、信息安全义务情况开展的监督检查。
本办法所称网络空间安全,包括网络安全、数据安全、信息安全。
第三条 公安机关开展网络空间安全监督检查,应当在中央网络安全和信息化委员会等领导下开展,遵循依法科学管理、保障和促进发展的方针,严格遵守法定权限和程序,改进执法方式方法,会同有关主管部门建立健全网络空间安全监督检查协作配合机制。对日常性的现场检查,有行业主管部门的,原则上以行业主管部门开展现场检查为主。
公安机关应当按照分级分类管理等原则,建立并落实网络空间安全监督检查制度,自觉接受被检查对象和人民群众的监督。
第四条 公安机关通过网络信息巡查、信息审核能力测试、漏洞扫描等不影响被检查对象正常业务运行和网络空间安全的方式,对本辖区范围内被检查对象的网络空间安全情况进行线上巡查,以发现风险隐患。开展信息审核能力测试的,应当提前三个工作日告知被检查对象巡查时间、巡查范围等事项。
设区的市级以上公安机关可以通过漏洞探测、渗透性测试等方式,对本辖区范围内关键信息基础设施以外的网络设施、信息系统进行远程检测,但应当提前三个工作日告知被检查对象检查时间、检查范围等事项,不得干扰、破坏被检查对象网络设施、信息系统的正常运行,并通报同级网信部门、行业主管部门。对基础电信网络开展漏洞探测、渗透性测试等活动的,应当依照《关键信息基础设施安全保护条例》等有关规定进行。
对线上巡查、远程检测发现的风险隐患,应当进行核查;必要时,通过现场检查等方式进行线下核查。
第五条 开展网络空间安全现场检查,由被检查对象运营机构所在地县级以上公安机关实施。被检查对象为个人的,由其经常居住地公安机关实施。
前款所称运营机构所在地,是指运营者的实际主要运营地,或者管理机构所在地、网络设施所在地、工商注册登记地等。公安机关对监督检查的管辖权存在争议的,由共同的上级公安机关指定实施监督检查的公安机关。
上级公安机关应当对下级公安机关开展监督检查的情况进行指导和监督。必要时,可以提级或者组织有关公安机关开展监督检查。
第六条 公安机关根据维护网络空间安全需要,对下列对象依法开展监督检查:
(一)提供互联网接入、数据中心、内容分发、域名服务、信息服务等的互联网服务提供者;
(二)公共上网服务提供者;
(三)网络运营者及其建设者、维护者;
(四)关键信息基础设施运营者及其建设者、维护者;
(五)网络产品、服务的提供者;
(六)数据处理者;
(七)个人信息处理者;
(八)其他依法可以监督检查的对象。
对曾发生网络安全、数据安全等事件,或者因未履行法定网络安全、数据安全、信息安全义务被行政处罚且未按照要求整改的,应当重点开展监督检查。
第七条 公安机关应当对被检查对象履行法定网络安全、数据安全、信息安全义务等情况进行监督检查,重点检查以下内容:
(一)是否依法办理联网单位备案手续,并报送接入单位和用户基本信息及变更情况;
(二)是否依法制定并落实网络安全、数据安全、信息安全管理制度和操作规程;
(三)是否依法记录并留存用户注册信息和上网日志信息;
(四)是否依法履行网络安全等级保护定级备案、等级测评、建设整改、自查等安全保护义务;
(五)是否依法履行关键信息基础设施安全保护义务;
(六)是否依法采取防范计算机病毒和网络攻击、网络侵入等技术措施;
(七)是否依法针对网络安全漏洞、隐患采取相应的整改措施,消除风险隐患;
(八)是否依法在公共信息服务中对法律、行政法规禁止发布或者传输的信息采取防范措施;
(九)是否依法落实算法安全主体责任,建立健全算法推荐管理制度和技术措施;
(十)是否依法履行数据安全、个人信息保护义务;
(十一)是否依法为公安机关维护国家安全、防范调查恐怖活动、侦查犯罪等提供技术支持和协助。
第八条 在国家重大安全保卫任务期间,对与国家重大安全保卫任务相关的网络运营者、数据处理者、个人信息处理者,公安机关重点对下列内容开展专项监督检查:
(一)是否制定重大安全保卫任务所要求的工作方案,明确安全责任分工并确定安全管理人员;
(二)是否依法组织开展网络安全、数据安全、信息安全风险评估,并采取相应风险管控措施,堵塞安全漏洞隐患;
(三)是否制定网络安全、数据安全、信息安全应急处置预案并开展应急演练,应急处置相关设施是否完备有效;
(四)是否依法采取重大安全保卫任务所需要的其他网络安全、数据安全、信息安全防范措施;
(五)是否依法报告网络安全、数据安全、信息安全事件及处置情况。
对防范恐怖袭击的重点目标的网络空间安全监督检查,按照前款规定执行。
第九条 公安机关开展网络空间安全日常性的现场检查,在国家网络安全、数据安全等机制统筹协调下进行,加强监督检查的协同配合、信息沟通,合理确定现场检查的频次、范围、方式,避免重复检查、交叉检查,最大程度减少被检查对象的负担。
对网络安全等级保护第三级(含)以上的网络运营者、关键信息基础设施运营者,每年开展一次日常性的现场检查;本年度其他主管部门已经开展的现场检查,公安机关复用相关检查结果,不再重复开展现场检查。
公安机关为调查处置网络空间安全案事件开展监督检查,或者为执行重大安全保卫任务等开展专项监督检查,应当及时依照法定职责、程序进行。
第十条 公安部部署开展涉及多行业、多部门的日常性的现场检查,应当报中央网络安全和信息化委员会审批。其中,涉及数据安全的,应当在国家数据安全工作协调机制统筹指导下,按照有关要求开展;涉及内容导向管理、网络意识形态安全等工作的,应当在意识形态主管部门统筹指导下,按照有关要求开展。
对基础电信网络开展日常性的现场检查,由设区的市级以上公安机关组织实施。对电信、能源、交通、水利、金融、国防科技工业等行业网络空间安全开展日常性的现场检查,应当提前五个工作日告知网信部门、行业主管部门;网信部门、行业主管部门提出联合检查的,公安机关会同网信部门、行业主管部门联合开展检查。
公安机关应当将现场检查相关情况及时通报同级网信部门、行业主管部门。
第十一条 公安机关开展网络空间安全现场检查,人民警察不得少于二人,并应当出示人民警察证和县级以上公安机关出具的监督检查通知书。
第十二条 公安机关开展网络空间安全现场检查,可以采取下列措施:
(一)进入营业场所、机房、工作场所;
(二)问询被检查对象的负责人或者网络安全、数据安全、信息安全管理人员,要求对监督检查事项说明情况;
(三)查阅、复制与监督检查事项相关的信息;
(四)查看安全保护技术措施运行情况;
(五)开展漏洞探测、渗透性测试等技术检测。
第十三条 公安机关开展网络空间安全监督检查,可以委托具有相应技术能力的网络安全服务机构或者专门人员提供技术支持,并向上一级公安机关备案。网络安全服务机构或者专门人员应当在人民警察指挥下开展监督检查,并通过与被检查对象签订承诺书等方式,承诺对检查过程中知悉的商业秘密、个人隐私、个人信息等予以保密。
公安机关对关键信息基础设施开展监督检查,确因工作需要委托网络安全服务机构或者专门人员提供技术支持的,应当告知行业主管部门。
公安机关应当对参与漏洞探测、渗透性测试的网络安全服务机构及其工作人员开展背景审查,并进行全流程的安全管理。
第十四条 公安机关开展网络空间安全监督检查应当客观公正,不得向被检查对象收取费用,不得要求被检查对象购买、使用指定的产品和服务。
第十五条 公安机关开展网络空间安全现场检查,应当制作监督检查记录,并由开展监督检查的人民警察和被检查对象的负责人或者网络安全管理人员签名。被检查对象的负责人或者网络安全管理人员对监督检查记录有异议的,应当允许其作出说明;拒绝签名的,人民警察应当在监督检查记录中注明。
公安机关开展漏洞探测、渗透性测试等远程检测,应当制作监督检查记录,并由开展监督检查的人民警察在监督检查记录上签名。
委托网络安全服务机构、专门人员提供技术支持的,技术支持人员应当一并在监督检查记录上签名。
监督检查过程中形成的文件材料,应当按照规定立卷存档。
第十六条 公安机关在监督检查中发现被检查对象存在网络空间安全风险隐患的,应当督促指导其采取措施消除风险隐患,并在监督检查记录上注明。
被检查对象存在不依法履行网络安全、数据安全、信息安全义务等情况的,公安机关依据职责按照《中华人民共和国网络安全法》《中华人民共和国数据安全法》《中华人民共和国个人信息保护法》《关键信息基础设施安全保护条例》《网络数据安全管理条例》《互联网信息服务管理办法》《计算机信息网络国际联网安全保护管理办法》等法律法规,追究其法律责任。
第十七条 公安机关在监督检查中,发现被检查对象存在网络空间安全风险隐患,尚不构成违法犯罪的,可以按照下列程序予以提示或者通告:
(一)由县级以上公安机关向被检查对象发放公安提示函,督促其采取安全防范措施;
(二)由设区的市级以上公安机关向同级行业主管部门发放公安提示函,督促其加强本行业网络安全、数据安全、信息安全监督管理;
(三)由省级以上公安机关向社会发布不指向具体被检查对象的公安通告,提示网络空间安全风险隐患,督促社会公众采取防范措施。
第十八条 公安机关在网络空间安全监督检查中,发现网络安全等级保护第三级(含)以上网络、关键信息基础设施、重要数据存在重大安全风险隐患的,应当及时通报行业主管部门、网信部门。
发现重要行业或者本地区存在严重威胁国家安全、公共安全和社会公共利益的重大网络空间安全风险隐患的,应当报告人民政府和上级公安机关,并按照规定发布公安提示或者通告。
第十九条 省级以上公安机关在履行网络安全、信息安全监督管理职责中,发现存在较大安全风险或者发生安全事件的,可以对该网络运营者的法定代表人或者主要负责人进行约谈。
县级以上公安机关在履行数据安全监督管理职责中,发现数据处理、个人信息处理活动存在较大安全风险或者发生数据安全、个人信息安全事件的,可以对有关组织、个人进行约谈。
被约谈对象应当按照法律、行政法规要求采取措施进行整改,消除网络空间安全风险隐患。
第二十条 公安机关及其工作人员和受委托提供技术支持的网络安全服务机构、专门人员,应当保守监督检查中知悉的国家秘密、工作秘密、商业秘密以及个人隐私、个人信息,不得泄露、出售或者非法向他人提供。
在监督检查中获取的信息、资料,只能用于维护网络空间安全的需要,不得用于其他用途,不得非法提供给其他组织、个人。监督检查完毕后,参与监督检查的网络安全服务机构及其工作人员应当将获取的信息、资料交由公安机关保管,或者按照公安机关要求进行删除、销毁。
第二十一条 公安机关及其工作人员在网络空间安全监督检查中玩忽职守、滥用职权、徇私舞弊的,对直接负责的主管人员和其他直接责任人员依法给予处分;构成犯罪的,依法追究刑事责任。
第二十二条 受公安机关委托提供技术支持的网络安全服务机构、专门人员,从事非法侵入被检查对象网络、干扰网络正常功能、窃取网络数据等危害网络空间安全的活动,窃取或者以其他非法方式获取、出售、提供在工作中获悉的国家秘密、工作秘密、商业秘密以及个人隐私、个人信息的,依法予以处罚;构成犯罪的,依法追究刑事责任。
第二十三条 本办法自2026年10月1日起施行,2018年9月15日发布的《公安机关互联网安全监督检查规定》(公安部令第151号)同时废止。
- 相关文档
- 公安部发布《公安机关网络空间安全监督检查办法》
-
Order of the Ministry of Public Security of the People’s Republic of China No. 176
The Measures for the Supervision and Inspection of Cyberspace Security by Public Security Organs were deliberated and adopted at the 2nd Ministerial Meeting of the Ministry of Public Security on 1 July 2026. They are hereby promulgated and shall come into force on 1 October 2026.
Minister Wang Xiaohong 6 August 2026
Measures for the Supervision and Inspection of Cyberspace Security by Public Security Organs
Article 1 These Measures are formulated for the purposes of safeguarding national security and the public interest, protecting the legitimate rights and interests of citizens, legal persons and other organisations, standardising the work of public security organs in the supervision and inspection of cyberspace security, and preventing and addressing cyber-related illegal and criminal activities, in accordance with the People’s Police Law of the People’s Republic of China, the Cybersecurity Law of the People’s Republic of China, the Data Security Law of the People’s Republic of China, the Personal Information Protection Law of the People’s Republic of China, the Regulations on the Security Protection of Critical Information Infrastructure, the Regulations on the Management of Network Data Security, the Measures for the Administration of Internet Information Services, and other relevant laws and administrative regulations.
Article 2 These Measures apply to the supervision and inspection conducted by public security organs in accordance with the law of the performance by network operators, data processors, personal information handlers and others of their cybersecurity, data security and information security obligations as prescribed by laws and regulations.
For the purposes of these Measures, “cyberspace security” includes cybersecurity, data security and information security.
Article 3 Public security organs shall carry out cyberspace security supervision and inspection under the leadership of the Central Cyberspace Affairs Commission and other relevant bodies, adhere to the principles of lawful and scientific management that both safeguards and promotes development, strictly observe statutory powers and procedures, improve methods of law enforcement, and, in conjunction with the competent departments concerned, establish and improve mechanisms for coordination and cooperation in cyberspace security supervision and inspection. For routine on-site inspections, where an industry competent department exists, such inspections shall in principle be led by the industry competent department.
Public security organs shall, in accordance with the principles of graded and classified management and other relevant principles, establish and implement a system of cyberspace security supervision and inspection, and shall consciously accept supervision by the inspected parties and the public.
Article 4 Public security organs may, through network information patrols, information-review capability testing, vulnerability scanning and other methods that do not affect the normal business operations or cyberspace security of the inspected party, conduct online patrols of the cyberspace security situation of inspected parties within their administrative areas in order to discover risks and hidden dangers. Where information-review capability testing is conducted, the inspected party shall be notified three working days in advance of the time, scope and other relevant matters of the patrol.
Public security organs at or above the level of a city divided into districts may, by means of vulnerability probing, penetration testing and other methods, conduct remote testing of network facilities and information systems within their administrative areas other than critical information infrastructure; provided that the inspected party shall be notified three working days in advance of the time, scope and other relevant matters of the testing, that the normal operation of the inspected party’s network facilities and information systems shall not be interfered with or disrupted, and that the cyberspace administration department and industry competent department at the same level shall be notified. Activities such as vulnerability probing and penetration testing conducted on basic telecommunications networks shall be carried out in accordance with the Regulations on the Security Protection of Critical Information Infrastructure and other relevant provisions.
Risks and hidden dangers discovered through online patrols or remote testing shall be verified; where necessary, offline verification may be conducted by means of on-site inspection or other methods.
Article 5 On-site inspections of cyberspace security shall be conducted by the public security organ at or above the county level of the place where the operational institution of the inspected party is located. Where the inspected party is an individual, the inspection shall be conducted by the public security organ of the place of his or her habitual residence.
For the purposes of the preceding paragraph, the “place where the operational institution is located” means the actual principal place of operations of the operator, or the place where the management institution is located, the place where the network facilities are located, the place of industrial and commercial registration, or other relevant places. Where a dispute arises over jurisdiction for supervision and inspection among public security organs, the common superior public security organ shall designate the public security organ to conduct the supervision and inspection.
Superior public security organs shall provide guidance and supervision over the supervision and inspection work of subordinate public security organs. Where necessary, they may elevate the level of inspection or organise relevant public security organs to conduct the supervision and inspection.
Article 6 Public security organs shall, according to the needs of maintaining cyberspace security, conduct supervision and inspection in accordance with the law of the following parties:
(1) internet service providers that provide internet access, data centres, content delivery, domain-name services, information services and the like; (2) providers of public internet access services; (3) network operators and their constructors and maintainers; (4) operators of critical information infrastructure and their constructors and maintainers; (5) providers of network products and services; (6) data processors; (7) personal information handlers; (8) other parties that may be subject to supervision and inspection in accordance with the law.
Priority supervision and inspection shall be conducted in respect of parties that have previously experienced cybersecurity, data security or other incidents, or that have been subjected to administrative penalties for failure to perform statutory cybersecurity, data security or information security obligations and have failed to make rectification as required.
Article 7 Public security organs shall supervise and inspect the performance by inspected parties of their statutory cybersecurity, data security and information security obligations, focusing on the following matters:
(1) whether networking unit filing formalities have been completed in accordance with the law, and whether basic information on access units and users and any changes thereto have been reported; (2) whether cybersecurity, data security and information security management systems and operating procedures have been formulated and implemented in accordance with the law; (3) whether user registration information and online log information have been recorded and retained in accordance with the law; (4) whether the security protection obligations of graded protection of cybersecurity, including grading and filing, graded assessment, construction and rectification, and self-inspection, have been performed in accordance with the law; (5) whether the security protection obligations in respect of critical information infrastructure have been performed in accordance with the law; (6) whether technical measures have been adopted in accordance with the law to guard against computer viruses, network attacks, network intrusions and the like; (7) whether corresponding rectification measures have been taken in accordance with the law in respect of cybersecurity vulnerabilities and hidden dangers so as to eliminate risks and hidden dangers; (8) whether preventive measures have been adopted in accordance with the law in public information services against information the publication or transmission of which is prohibited by laws or administrative regulations; (9) whether the primary responsibility for algorithm security has been implemented in accordance with the law, and whether management systems and technical measures for algorithm recommendation have been established and improved; (10) whether data security and personal information protection obligations have been performed in accordance with the law; (11) whether technical support and assistance have been provided in accordance with the law to public security organs in safeguarding national security, preventing and investigating terrorist activities, and investigating crimes.
Article 8 During periods of major national security protection tasks, public security organs shall conduct special supervision and inspection of network operators, data processors and personal information handlers related to such major national security protection tasks, focusing on the following matters:
(1) whether work plans required for the major security protection tasks have been formulated, security responsibility divisions clarified, and security management personnel designated; (2) whether cybersecurity, data security and information security risk assessments have been organised and conducted in accordance with the law, and corresponding risk-control measures adopted to close security vulnerabilities and hidden dangers; (3) whether emergency response plans for cybersecurity, data security and information security have been formulated and emergency drills conducted, and whether the relevant emergency response facilities are complete and effective; (4) whether other cybersecurity, data security and information security protective measures required for the major security protection tasks have been adopted in accordance with the law; (5) whether cybersecurity, data security and information security incidents and the handling thereof have been reported in accordance with the law.
Supervision and inspection of the cyberspace security of key targets for the prevention of terrorist attacks shall be conducted in accordance with the provisions of the preceding paragraph.
Article 9 Routine on-site inspections of cyberspace security by public security organs shall be conducted under the overall coordination of national cybersecurity, data security and other mechanisms; coordination and information sharing in supervision and inspection shall be strengthened; the frequency, scope and methods of on-site inspections shall be reasonably determined so as to avoid duplicate and overlapping inspections and to minimise to the greatest extent the burden on inspected parties.
For network operators and operators of critical information infrastructure whose cybersecurity graded protection is at Level 3 or above, one routine on-site inspection shall be conducted each year; where other competent departments have already conducted on-site inspections in the same year, public security organs shall reuse the relevant inspection results and shall not conduct duplicate on-site inspections.
Where public security organs conduct supervision and inspection for the purpose of investigating and handling cyberspace security cases or incidents, or conduct special supervision and inspection for the performance of major security protection tasks or other purposes, such inspections shall be carried out promptly in accordance with statutory duties and procedures.
Article 10 Where the Ministry of Public Security deploys routine on-site inspections involving multiple industries and departments, approval shall be obtained from the Central Cyberspace Affairs Commission. Where data security is involved, the inspections shall be conducted under the overall guidance of the national data security work coordination mechanism and in accordance with relevant requirements; where content orientation management, network ideological security or other such work is involved, the inspections shall be conducted under the overall guidance of the competent ideological department and in accordance with relevant requirements.
Routine on-site inspections of basic telecommunications networks shall be organised and conducted by public security organs at or above the level of a city divided into districts. For routine on-site inspections of cyberspace security in the telecommunications, energy, transport, water conservancy, finance, national defence science and technology industry and other sectors, the cyberspace administration department and industry competent department shall be notified five working days in advance; where the cyberspace administration department or industry competent department proposes a joint inspection, the public security organ shall conduct the inspection jointly with the cyberspace administration department and industry competent department.
Public security organs shall promptly notify the cyberspace administration department and industry competent department at the same level of the relevant circumstances of on-site inspections.
Article 11 When conducting on-site inspections of cyberspace security, public security organs shall ensure that no fewer than two people’s police officers participate, and that the people’s police officers present their people’s police credentials and a written notice of supervision and inspection issued by a public security organ at or above the county level.
Article 12 When conducting on-site inspections of cyberspace security, public security organs may adopt the following measures:
(1) enter business premises, machine rooms and workplaces; (2) question the responsible persons of the inspected party or the management personnel responsible for cybersecurity, data security or information security, and require them to provide explanations concerning the matters under supervision and inspection; (3) consult and copy information related to the matters under supervision and inspection; (4) examine the operation of security protection technical measures; (5) conduct technical testing such as vulnerability probing and penetration testing.
Article 13 When conducting cyberspace security supervision and inspection, public security organs may entrust cybersecurity service institutions or specialised personnel possessing the corresponding technical capabilities to provide technical support, and shall file the matter with the public security organ at the next higher level. The cybersecurity service institutions or specialised personnel shall carry out the supervision and inspection under the command of the people’s police, and shall, by means of signing letters of commitment with the inspected party or other methods, undertake to maintain the confidentiality of trade secrets, personal privacy, personal information and other information learned in the course of the inspection.
Where public security organs conduct supervision and inspection of critical information infrastructure and, due to genuine work needs, entrust cybersecurity service institutions or specialised personnel to provide technical support, they shall notify the industry competent department.
Public security organs shall conduct background reviews of cybersecurity service institutions and their staff participating in vulnerability probing and penetration testing, and shall implement full-process security management.
Article 14 Public security organs shall conduct cyberspace security supervision and inspection in an objective and impartial manner, shall not collect fees from inspected parties, and shall not require inspected parties to purchase or use designated products or services.
Article 15 When conducting on-site inspections of cyberspace security, public security organs shall prepare records of the supervision and inspection, which shall be signed by the people’s police officers conducting the inspection and by the responsible person of the inspected party or the cybersecurity management personnel. Where the responsible person of the inspected party or the cybersecurity management personnel raises objections to the inspection record, they shall be permitted to provide explanations; where they refuse to sign, the people’s police officers shall note the circumstances in the inspection record.
When conducting remote testing such as vulnerability probing or penetration testing, public security organs shall prepare records of the supervision and inspection, which shall be signed by the people’s police officers conducting the inspection.
Where cybersecurity service institutions or specialised personnel are entrusted to provide technical support, the technical support personnel shall also sign the inspection record.
Documents and materials formed in the course of supervision and inspection shall be filed and archived in accordance with relevant provisions.
Article 16 Where public security organs discover in the course of supervision and inspection that an inspected party has cyberspace security risks or hidden dangers, they shall urge and guide the party to take measures to eliminate such risks and hidden dangers, and shall note the circumstances in the inspection record.
Where an inspected party fails to perform its cybersecurity, data security or information security obligations in accordance with the law or is otherwise in violation, the public security organ shall, in accordance with its duties and pursuant to the Cybersecurity Law of the People’s Republic of China, the Data Security Law of the People’s Republic of China, the Personal Information Protection Law of the People’s Republic of China, the Regulations on the Security Protection of Critical Information Infrastructure, the Regulations on the Management of Network Data Security, the Measures for the Administration of Internet Information Services, the Measures for the Security Protection of Computer Information Networks Connected to the Internet and other laws and regulations, pursue the legal liability of the party.
Article 17 Where public security organs discover in the course of supervision and inspection that an inspected party has cyberspace security risks or hidden dangers that do not yet constitute illegal or criminal conduct, they may issue prompts or notices in accordance with the following procedures:
(1) public security organs at or above the county level may issue a Public Security Reminder Letter to the inspected party, urging it to adopt security protective measures; (2) public security organs at or above the level of a city divided into districts may issue a Public Security Reminder Letter to the industry competent department at the same level, urging it to strengthen supervision and management of cybersecurity, data security and information security in the industry; (3) public security organs at or above the provincial level may issue a Public Security Notice to the public that does not identify any specific inspected party, prompting awareness of cyberspace security risks and hidden dangers and urging the public to adopt protective measures.
Article 18 Where public security organs discover in the course of cyberspace security supervision and inspection that networks at Level 3 or above of cybersecurity graded protection, critical information infrastructure or important data have major security risks or hidden dangers, they shall promptly notify the industry competent department and the cyberspace administration department.
Where major cyberspace security risks or hidden dangers that seriously threaten national security, public security or the public interest are discovered in important industries or in the local area, the matter shall be reported to the people’s government and the superior public security organ, and Public Security Reminders or Notices shall be issued in accordance with relevant provisions.
Article 19 Public security organs at or above the provincial level, in performing their duties of supervision and management of cybersecurity and information security, may, upon discovering relatively significant security risks or the occurrence of security incidents, conduct an interview with the legal representative or principal responsible person of the network operator concerned.
Public security organs at or above the county level, in performing their duties of supervision and management of data security, may, upon discovering relatively significant security risks in data processing or personal information processing activities or the occurrence of data security or personal information security incidents, conduct an interview with the relevant organisation or individual.
The party subject to the interview shall, in accordance with the requirements of laws and administrative regulations, take measures to make rectification and eliminate cyberspace security risks and hidden dangers.
Article 20 Public security organs and their staff, as well as cybersecurity service institutions and specialised personnel entrusted to provide technical support, shall keep confidential state secrets, work secrets, trade secrets, personal privacy and personal information learned in the course of supervision and inspection, and shall not disclose, sell or illegally provide such information to others.
Information and materials obtained in the course of supervision and inspection may be used only for the needs of maintaining cyberspace security, and shall not be used for other purposes or illegally provided to other organisations or individuals. After the supervision and inspection is completed, the cybersecurity service institutions and their staff that participated in the inspection shall hand over the information and materials obtained to the public security organ for safekeeping, or delete or destroy them in accordance with the requirements of the public security organ.
Article 21 Where public security organs or their staff neglect their duties, abuse their powers or engage in favouritism or irregularities in the course of cyberspace security supervision and inspection, the persons directly in charge and other persons directly responsible shall be given sanctions in accordance with the law; where a crime is constituted, criminal liability shall be pursued in accordance with the law.
Article 22 Where cybersecurity service institutions or specialised personnel entrusted by public security organs to provide technical support engage in activities that endanger cyberspace security, such as illegally intruding into the networks of inspected parties, interfering with the normal functions of networks or stealing network data, or steal or by other illegal means obtain, sell or provide state secrets, work secrets, trade secrets, personal privacy or personal information learned in the course of their work, they shall be punished in accordance with the law; where a crime is constituted, criminal liability shall be pursued in accordance with the law.
Article 23 These Measures shall come into force on 1 October 2026. The Provisions on the Supervision and Inspection of Internet Security by Public Security Organs (Order No. 151 of the Ministry of Public Security) promulgated on 15 September 2018 shall be repealed simultaneously.

No comments:
Post a Comment