Policy & RegulationAnalysis

China Clarifies Compliance Limits on Public Data and Leak Prevention

The Cyberspace Administration of China issued guidance clarifying rules on publicly disclosed personal information and common technical causes of data breaches.

Share
Close-up of a person examining a credit card authorization form inside an office setting.
Photo by RDNE Stock project on Pexels

The Brief

The Cyberspace Administration of China (CAC) has published regular regulatory guidance detailing strict boundaries for handling publicly available personal data and identifying frequent technical vulnerabilities behind data leaks. The guidance emphasizes that personal information in the public domain cannot be processed beyond reasonable scope, used for unrelated commercial marketing, or weaponized for online harassment. It also urges organizations to eliminate basic technical flaws such as plaintext data storage, weak passwords, and unauthenticated web interfaces to comply with China's Personal Information Protection Law.

Why it matters

The clarification gives enterprises operating in China specific technical and compliance benchmarks to evaluate their data handling practices. By spelling out prohibited uses of public data and frequent security lapses, regulators are providing clear criteria for ongoing compliance audits and supervisory inspections.

China context

Since enforcing the Personal Information Protection Law (PIPL) and companion compliance audit rules, Chinese cyberspace authorities have routinely issued practical guidance to help firms align operational practices with regulatory requirements. The move reflects an evolving enforcement focus on both technical cybersecurity hygiene and consumer privacy rights.

Editor's View

EDITOR'S VIEW — Analysis and inference, not factual reporting. The guidance highlights a dual regulatory priority: closing widespread operational security loopholes and clamping down on the misuse of publicly available data. For businesses, the explicit ban on harvesting publicly accessible phone numbers and email addresses for commercial outreach narrows common lead-generation tactics, while the focus on exposed credentials and unauthenticated APIs signals that basic security lapses will face little regulatory leniency during compliance audits.

What to watch

  • Whether enterprises conduct technical self-inspections to address unauthenticated interfaces and plaintext data storage
  • Regulatory enforcement actions targeting the unauthorized harvesting and commercial use of publicly disclosed personal information
  • Adoption of updated standard operating procedures ahead of mandatory compliance audits

Key Takeaways

  • 1The CAC issued practical guidance detailing restrictions on using legally public personal information.
  • 2Sending unsolicited commercial messages to publicly listed contact details is explicitly classified as non-compliant.
  • 3The regulator highlighted four major technical causes of data leaks, including plaintext storage, weak passwords, and unauthenticated APIs.
  • 4Handlers must implement classification, encryption, access controls, and emergency plans under Article 51 of the PIPL.
The Cyberspace Administration of China (CAC) has issued a regulatory question-and-answer notice clarifying compliance standards for handling publicly disclosed personal information and identifying common technical vulnerabilities that lead to data breaches. Under China's Personal Information Protection Law (PIPL), personal information handlers may process personal data that individuals have disclosed themselves or that has otherwise been lawfully made public, provided the processing remains within a reasonable scope and the individual has not explicitly refused. If the processing significantly affects the rights and interests of the individual, handlers must obtain explicit consent. The CAC reiterated specific violations outlined in the accompanying compliance audit guidelines for the PIPL. These prohibited activities include sending commercial messages to publicly listed email addresses or phone numbers when such outreach is unrelated to the original purpose of disclosure; leveraging public personal information to engage in cyber violence or spread rumors and false information; processing data after an individual's explicit refusal; processing high-impact data without consent; and collecting, retaining, or using publicly disclosed data in a scope, duration, or manner exceeding reasonable limits. The regulatory notice also outlined four primary technical causes of personal data breaches observed across information systems. First, organizations frequently store and transmit personal information in plaintext without applying proper encryption or de-identification. Second, back-end systems and databases holding personal information often fail to enforce effective security controls, such as relying on weak passwords or omitting multi-step login authentication. Third, internet-facing data application programming interfaces (APIs) often lack adequate identity verification mechanisms. Fourth, web pages sometimes inadvertently expose login credentials and passwords for linked internal databases and systems. The CAC reminded organizations that Article 51 of the PIPL requires data handlers to implement comprehensive internal management systems, data classification, encryption, access controls, periodic personnel training, and incident contingency plans to prevent unauthorized access, leakage, tampering, or loss of personal data.

Sources

  1. 个人信息保护政策法规问答(2026年8月) Cyberspace Administration of China · 8/12/2026