On August 7, the Ministry of Public Security released the Measures for Public Security Organs' Cybersecurity Supervision and Inspection, set to take effect on October 1, 2026. Given the increasingly severe and complex cybersecurity landscape, public security authorities are fulfilling their legal duties to further standardize and strengthen oversight of cyberspace security.
In recent years, China has enacted laws such as the Data Security Law of the People's Republic of China and the Personal Information Protection Law of the People's Republic of China. This created a need to revise the 2018 Regulations on Public Security Organs' Internet Security Supervision and Inspection to update the targets and scope of inspections, aligning with the requirements for maintaining cyberspace security in the new era.
The Measures for Public Security Organs' Cybersecurity Supervision and Inspection contains 23 articles primarily covering six key areas. First, it clarifies the supervision targets, including network operators, data processors, and personal information processors. Second, it defines supervision methods, covering online patrols, offline checks, routine inspections, and special inspections. Third, it specifies the supervision content, such as whether entities are fulfilling their statutory cyberspace security obligations and key inspection points during major event security periods. Fourth, it establishes a supervision mechanism, requiring coordination under national cybersecurity and data security frameworks, enhanced inter-agency collaboration, and joint inspections to reduce the burden on enterprises. Fifth, it outlines the application of inspection results, empowering public security organs to take measures such as ordering rectification, issuing police advisory letters, and imposing penalties. Sixth, it details legal responsibilities, including liabilities for public security organs and their personnel involving dereliction of duty, abuse of power, and disclosure of state secrets.
The Measures for Public Security Organs' Cybersecurity Supervision and Inspection includes provisions to improve joint inspection mechanisms and reduce the burden on enterprises. Public security organs are required to establish and improve mechanisms for coordinated supervision and inspection with relevant departments, enhancing cross-agency collaboration and information sharing. They must reasonably determine the frequency, scope, and methods of on-site inspections to avoid duplicate or overlapping checks. When conducting on-site inspections of a specific industry, public security organs should notify the cyberspace administration and the relevant industry authorities in advance, preferably conducting joint inspections to minimize the burden on enterprises. Additionally, the measures encourage the use of online patrols as a primary inspection method to minimize the impact on business operations.
The Measures for Public Security Organs' Cybersecurity Supervision and Inspection also sets further requirements for the standardized law enforcement of public security bodies. It specifies detailed requirements for the personnel and documentation involved in supervision and inspection activities, as well as security management protocols for entrusting technical support agencies to assist with inspections. For remote testing methods such as vulnerability detection and penetration testing, implementation must be organized by public security organs at or above the prefecture and city level. Furthermore, the measures impose confidentiality obligations on public security organs and their personnel regarding state secrets, work secrets, trade secrets, personal privacy, and personal information obtained during their duties. By further standardizing supervision and inspection procedures, these rules aim to enhance the level of standardized law enforcement by public security organs.
Comments