In 2026, China is undergoing a true regulatory revolution in the digital sphere. From the amendment to the Cybersecurity Law (CSL) to the development of the Personal Information Protection Law (PIPL), and on to the first comprehensive AI ethics review system. The Chinese legal landscape is becoming increasingly complex and challenging for companies operating in this market. In this article, we analyze the most important changes, their practical implications, and the differences between the Chinese and European approaches to digital regulation.
1. Cybersecurity in China: The 2026 Amendment to the Cybersecurity Law
1.1. The biggest change since 2017
On January 1, 2026, the first amendment to China’s Cybersecurity Law (网络安全法) took effect. This is the first major update to the law since it took effect in June 2017. The amendment, approved in October 2025 by the Standing Committee of the National People’s Congress, introduces three key changes that directly affect all entities operating in China or with Chinese partners.
1.2. Extended extraterritorial jurisdiction (Article 77 of the CSL)
Prior to the amendment, the CSL was limited to attacks on China’s critical infrastructure (CII). Following the changes, the scope of the regulations was expanded to include all “activities by foreign entities that threaten the security of China’s cyber networks.” This means that even companies based outside China may be subject to sanctions—including asset freezes—if their activities are deemed a threat to Chinese cybersecurity. This change is particularly significant for international operators, including shipowners, whose onboard communications may fall under Chinese jurisdiction.
1.3. Tiered Penalty System
The amendment to China’s Cybersecurity Law puts an end to legal ambiguities by introducing a precise schedule of penalties. The new system directly links the severity of sanctions to the actual consequences of an incident. Importantly for businesses, financial liability increases sharply, and the consequences affect not only corporate budgets but also the personal finances of executives.
Under the new legal framework, financial risk is categorised into three levels.
A fundamental breach, i.e. a breach without the need to prove damage
A basic breach of the regulations is punishable by a fine of between 50,000 and 500,000 RMB (Renminbi, which is equivalent to between approximately 6,000 EUR and over 64,000 EUR, and between approximately 27,000 PLN and over 270,000 PLN). Most importantly from the perspective of the regulatory authorities, this penalty may be imposed without the need to prove that the incident caused any actual losses.
Aggravating circumstances
The stakes rise significantly when incidents of a more serious nature occur. The new regulations define these situations precisely, citing, amongst other things, ‘mass data breaches’ or ‘partial disruption of critical infrastructure’. In such cases, a company faces a fine of between 500,000 and 2,000,000 RMB (which, when converted to euros, ranges from approximately 64,000 EUR to nearly 260,000 EUR, and when converted to Polish zlotys: from over 270,000 PLN to approximately 1.1 million PLN). However, that is not all – the amendment personalises liability by imposing a personal fine of between 50,000 and 200,000 RMB on the decision-maker.
Worst-case scenario
At the top of this pyramid of sanctions are cases classified as having ‘particularly serious consequences’. Here, the financial penalties range from 2,000,000 to as much as 10,000,000 RMB (i.e. from over 250,000 EUR to approx. 1.29 million EUR, or from approx. 1.1 million PLN to over 5.48 million PLN). At the same time, pressure on senior management is rising dramatically – a person responsible for gross negligence faces a personal fine of up to 1,000,000 RMB.
1.4. Reductions in penalties
The amendment is not purely punitive. It also introduces mechanisms for the mitigation or remission of penalties, in accordance with the Administrative Penalties Act. The Cyberspace Administration of China (CAC) may reduce a penalty where the offender voluntarily eliminates or mitigates the harmful effects of the infringement, acted under duress or inducement, voluntarily discloses an infringement unknown to the regulators, and cooperates with law enforcement authorities. In the case of a first-time breach with minor consequences that has been rectified without delay, the penalty may even be waived entirely.
1.5. New obligations for critical infrastructure operators (CIIs)
The amendment to the regulations places critical infrastructure operators, in particular, on high alert. These are the entities responsible for strategic sectors such as energy, transport, water management, finance and public services. For these pillars of the state’s functioning, Beijing has drawn up a package of obligations that raise the bar for day-to-day operational activities.
First and foremost, any purchase of online products or services by these entities must now be preceded by a more rigorous security assessment. At the same time, the state is tightening the system for monitoring users themselves by introducing a strict requirement for real-name authentication for the most important online services, which in practice eliminates anonymity.
However, the greatest emphasis has been placed on data transparency. Operators have been subject to significantly broader obligations than before to immediately report any security incidents to the regulatory authorities. Furthermore, the amendment enshrines the principle of data localisation: all information generated within China must physically remain in the country. Cross-border transfers are only permitted in exceptional circumstances – following a complex administrative procedure, culminating in official approval by the regulator.

2. Protection of personal data in China: the evolution of the PIPL
2.1. PIPL as the ‘Chinese GDPR’
The Personal Information Protection Law (PIPL, 个人信息保护法) came into force on 1 November 2021. It is the first comprehensive piece of legislation at national level governing the protection of personal data in China. Although it is often compared to the European GDPR, the PIPL has important differences that every company needs to be aware of.
2.2. The main similarities and differences between the PIPL and the GDPR
The Chinese Personal Information Protection Law (PIPL) resembles the European GDPR in many respects, which makes it easier for entities operating in the international market to understand its principles. Both sets of regulations are based on a similar definition of personal data, understood as information relating to an identified or identifiable natural person. As in Europe, the standard requirement in China is to obtain consent for processing, and citizens are granted a similar set of rights: the right to access, rectify, erase and transfer their data.
The supervisory mechanisms and sanctions are also similar. Organisations processing the data of more than one million people are required to appoint the equivalent of a Data Protection Officer (PIPO), and serious breaches are subject to heavy financial penalties – up to 50 million RMB or 5 per cent of annual turnover.
Despite such striking similarities, there are several fundamental differences that set the Chinese system apart.
Absence of a ‘legitimate interest’
Unlike the GDPR, where this is one of the most important and most frequently used legal bases for data processing, the PIPL does not provide for such an arrangement. In the Chinese legal system, the user’s informed consent remains the primary – and often the only – legal basis for data processing operations.
The national security dimension
Chinese legislation explicitly links data protection to the interests of the state. The PIPL contains mechanisms allowing for the creation of a so-called blacklist of foreign entities. Companies included on this list may, for security reasons, be completely barred from accessing the personal data of Chinese citizens.
Data protection for deceased persons
This is a significant departure from European standards, where data protection rights expire upon a person’s death. In China, close relatives may exercise rights over a deceased person’s data in pursuit of their own legitimate and lawful interests.
Higher age limit for children
PIPL takes a more restrictive approach to the protection of the youngest children. Parental consent to the processing of their children’s data is required for all children under the age of 14 (by comparison, under the GDPR, the general age limit is 16, with the option for individual countries to lower this to 13).
Specific restrictions for the public sector
National public authorities are subject to a strict localisation rule. All personal data they collect must be stored exclusively within Chinese territory.
2.3. The new GB/T 45574-2025 standard – sensitive data
From 1 November 2025, the national standard GB/T 45574-2025 will come into force in China, introducing significant changes to the way sensitive data is identified. Instead of the previous, rigid catalogue of information, the new regulations require companies to analyse the context of data processing on a case-by-case basis and assess the impact of these activities on the privacy and security of a specific individual.
Under the new guidelines, the category of sensitive data primarily includes:
- biometric data, including facial recognition systems,
- information on financial accounts,
- precise location data,
- information about one’s state of health,
- personal data of minors under the age of 14.
Processing this type of information entails additional formal obligations. Organisations must obtain separate, explicit consent from the user and also provide them with detailed information about the purpose of the processing and its impact on their rights.
In addition, before carrying out any processing of sensitive data, organisations are required to conduct a data protection impact assessment (PIPIA – Personal Information Protection Impact Assessment). The documentation compiled in this way must be retained for at least three years in the event of an inspection.
2.4. Cross-border data transfers and the new framework for incident reporting
The Chinese system governing the transfer of personal data abroad is based on three distinct legal frameworks. These have been tailored to the scale of a company’s operations and the type of information processed.
- Security Assessment. This procedure applies to organisations operating on a large scale. It is mandatory in situations where a company processes the data of more than one million individuals or where the data being transferred is classified by the state as ‘sensitive data’.
- Standard Contract. This solution is designed for smaller organisations. It enables data transfers based on a standard contract template that has been approved by the CAC regulator.
- Certification. This option has been in place since the start of 2026 and is designed to facilitate the operations of international corporate groups. It enables companies to obtain a formal certificate from an authorised body, which simplifies the procedures for the flow of information within corporate structures.
In parallel with the streamlining of transfer rules, the regulations governing the response to crisis situations (Measures for the Administration of the Reporting of Cybersecurity Incidents) have been tightened. These regulations require companies to notify regulatory authorities of security breaches within a strictly defined, short timeframe.
For most organisations, the basic deadline for reporting an incident is 4 hours. For critical infrastructure operators (CIIs), the requirements are stricter – in their scenario, this timeframe is one hour. The regulations also explicitly define the severity of individual incidents: a data breach involving more than one million personal data records is automatically classified as a ‘relatively major’ incident.
2.5. The 2026 Enforcement Campaign
In April 2026, Chinese regulatory bodies – led by the CAC, the Ministry of Industry and Information Technology (MIIT) and the Ministry of Public Security (MPS) – launched a coordinated campaign aimed at enforcing personal data protection regulations. These measures quickly led to specific decisions at local level and significant legal rulings.
This round of inspections is divided into three main areas.
- Removing incompatible applications. In the country’s major economic centres, such as Beijing, Shanghai, Zhejiang, Jiangsu, Chongqing and Sichuan, local authorities have begun actively removing mobile apps from the market that have breached users’ privacy rights.
- Simplifications for smaller businesses. Alongside these restrictive measures, the regulator is working to ensure a balance in administrative obligations. The CAC has published draft new regulations that simplify procedures for small data controllers, making it easier for smaller companies to comply with legal requirements efficiently.
- The courts’ unequivocal position. A ruling by the Beijing Internet Court has become a key indicator for the market. The court ruled that the transfer of personal data to third parties without obtaining the user’s separate, explicit consent constitutes a direct breach of the PIPL.
This ruling finally confirms that the practice of sharing information within business partnerships or advertising networks without the consumer’s knowledge will not be tolerated in China.

3. Artificial intelligence in China
3.1. The absence of a single piece of legislation – the five pillars of regulation
Whilst the European Union has opted to create a single, comprehensive piece of legislation (the AI Act), China has adopted a different strategy. Beijing is taking a vertical approach, which involves regulating specific applications and algorithms through a range of specialised legislative and administrative measures. This entire system is based on five fundamental pillars.
Pillar 1: Government policies and strategies
The direction of development is set out in official government plans, which define the country’s strategic objectives. The first policy document of this nature was the ‘Plan for the Development of Next-Generation Artificial Intelligence’ from 2017. This document is supplemented by official guidelines from the Council of State, aimed at strengthening ethical oversight in the fields of science and new technologies, such as the ‘Opinions on Strengthening Ethical Governance in Science and Technology’.
Pillar 2: General legal provisions
Regulations specific to artificial intelligence do not operate in a vacuum – they are underpinned by three key pieces of legislation. The Personal Data Protection Act (PIPL) protects personal data used to train and operate algorithms, the Data Security Act (DSL) ensures the protection of the data sets themselves, and the Cybersecurity Act (CSL) safeguards the network infrastructure on which AI systems rely.
Pillar 3: Administrative and sector-specific regulations
This is where you’ll find tools targeting specific technologies and their developers. One example is the ‘Interim Guidelines for the Management of Generative AI Services’ (AIGC Measures), which regulate content generated by language models or image generators. Separate, detailed regulations apply to recommendation systems and so-called deep synthesis technologies – including, amongst other things, tools for creating deepfake content.
Pillar 4: Local and regional regulations
Chinese cities enjoy a high degree of autonomy in shaping local market regulations. Major technology hubs, such as Shanghai and Shenzhen, are implementing their own regulations. The aim is, on the one hand, to promote innovation and, on the other, to enable local authorities to exercise detailed control over higher-risk AI products.
Pillar 5: National and technical standards
The final component of the system is a set of precise engineering guidelines. The China Electronics Standardisation Institute is systematically developing a series of standards for artificial intelligence systems. According to the agreed timetable, work on over 50 new national and industry standards is due to be finalised by the end of 2026, which will set out uniform technical requirements for the entire market.
3.2. The rules of the game for generative AI – the principles underlying the ‘AIGC Measures’
The document entitled “Interim Rules on the Management of Generative Artificial Intelligence Services”, drawn up by the CAC in collaboration with six other government agencies, came into force on 15 August 2023. To this day, it remains the most important piece of legislation governing the operation of content-generating systems within China. These regulations precisely define the obligations of technology providers and set clear boundaries for the commercial use of algorithms.
The key requirements for developers of AIGC (Generative AI) services include:
- the legality of training data – system providers must ensure and demonstrate that the sources of information used to train the models are entirely lawful;
- protection of privacy during the training phase – if personal data is contained in the training datasets, its use requires prior consent from the data subjects;
- respect for users’ rights – artificial intelligence systems must be designed in such a way as to enable, from the outset, the exercise of the rights set out in the PIPL Act – including the right to access, rectify or erase data;
- built-in safeguards – providers are required to implement technical measures that effectively prevent data leaks and protect users’ privacy.
The list of prohibited activities has been formulated just as clearly. Chinese law in this area unequivocally prohibits:
- generation of harmful content – algorithms must not create material that infringes the rights of third parties or poses a threat to national security;
- monopolistic practices – it is prohibited to use AI technology to engage in unfair competition or to establish a monopoly position in the market;
- algorithmic discrimination – the regulations prohibit unjustified differences in the treatment of customers in commercial transactions. In practice, this eliminates, amongst other things, the phenomenon of price discrimination, i.e. the automatic increase in the prices of services or products by AI for selected user profiles.
3.3. Automated decision-making (Article 24 of the PIPL)
Automated decision-making Article 24 of the PIPL Act is the primary regulatory framework for artificial intelligence in China. This provision focuses on automated decision-making processes and imposes requirements on system controllers designed to protect users from the arbitrary behaviour of algorithms. (Article 24 of the PIPL)
Under this regulation, any process based on automated data analysis must meet specific criteria.
- Transparency. The algorithm itself and the way in which it makes decisions cannot remain a company secret – full transparency regarding the system’s operation is required.
- Objectivity. The results generated by IT systems must be fair and impartial, in order to prevent technology from perpetuating biases.
- The right to an explanation. A user who has been subject to an automated decision has the right to request a detailed explanation of the reasons on which the system was based.
- Refusal to automate. Consumers are entitled to object to a decision if it has been made entirely by automated means, without any human intervention.
Another key element of this article is the explicit ban on unjustified differentiation in transaction terms. This provision directly targets the practice known as ‘big data price discrimination’, which is widely used by e-commerce platforms. In practice, this means that online shops and service providers cannot, without an objective reason, offer the same product at different prices to different users, based solely on an algorithmic assessment of their profile or purchase history.
3.4. AI in the public sector
The active implementation of artificial intelligence in China’s public sector has been the subject of considerable interest and debate on the international stage for years. Beijing does not view algorithms merely as the preserve of the private sector, but as a tool for improving the governance of the state and society at many levels.
The practical application of these technologies today extends to areas that are subject to strict restrictions in other parts of the world. In urban areas, advanced facial recognition systems are commonplace, their operation regulated by the provisions of the PIPL and CSL Acts. New technologies also support the local justice system, where algorithms assist judges in analysing court documents and searching for relevant precedents. In education, meanwhile, AI systems are used to automatically mark pupils’ work and monitor their behaviour during lessons. A separate branch is the citizen assessment system, or social credit system. Within the Chinese legal system, this remains a fully legitimate administrative instrument.
The most significant difference compared with European standards concerns the approach to the presence of technology in everyday life. Whilst the EU’s AI Act, in most cases, considers the use of biometric identification systems in public spaces to be prohibited, in China such solutions are entirely legal and form an integral part of the state’s infrastructure.

4. Ethical AI in China: from voluntary guidelines to mandatory regulations
4.1. A new phase of oversight: The AI ethics assessment system
On 3 April 2026, the Ministry of Science and Technology (MOST) and the Ministry of Industry and Information Technology (MIIT), acting in consultation with eight other government departments, published new regulatory guidelines: ‘Interim Measures for the Administration of AI Technology Ethics Review and Services’ (Measures for the Administration of AI Technology Ethics Review and Services (Trial)).
This document introduces China’s first dedicated ethical assessment system for artificial intelligence-based solutions. Rather than making general declarations, the state administration is thus establishing a formal regulatory framework. The aim is to ensure that new technologies are developed and implemented in a manner consistent with accepted social and legal standards before they are put into widespread use.
4.2. The broad scope of the new regulations – who and what is subject to ethical assessment?
The newly introduced regulations are wide-ranging and cover all activities relating to artificial intelligence carried out within China, provided that they may give rise to ethical challenges. Supervision will primarily apply to projects that have an impact on:
- human dignity and public order,
- the lives and health of citizens,
- the natural environment and sustainable development.
The regulations are not limited solely to the worlds of technology and business. A wide range of entities is now required to carry out ethical assessments. Both businesses and universities, research institutes and healthcare organisations that develop or use artificial intelligence systems in their operations must comply with the new legal procedures.
4.3. A three-tier structure – a framework for the ethical assessment of artificial intelligence
China’s new ethical oversight system is based on a transparent, three-tiered supervisory structure. Responsibility for verifying projects is shared between the organisations themselves, specialised external bodies and the state administration. This division allows procedures to be flexibly tailored to the scale and specific nature of a given technological solution.
The verification process is carried out at the following levels:
- Level 1: Internal ethics committees. Every organisation operating in the field of artificial intelligence is required to establish its own internal ethics committee. Such a committee must comprise at least five experts representing various specialisms: AI technology, its practical applications, as well as ethics and law. The committee is responsible for the initial assessment of projects and the ongoing monitoring of work within the organisation.
- Level 2: External service centres. The legislator has provided a solution for organisations that do not have the necessary expertise or staff to carry out such analyses themselves. They may entrust the assessment to authorised external bodies. These centres operate as certified partners, carrying out reviews on behalf of clients and helping companies to comply with legal requirements.
- Level 3: Government expert review. The highest level of scrutiny is reserved for high-risk technologies. These are systems that can directly shape public opinion, influence users’ psychological behaviour, or rely on advanced, fully automated decision-making. In such cases, the assessment is carried out by a special panel of experts organised by government bodies. Officials have 30 days from the date of formal acceptance of the application to issue an official decision.
4.4. Assessment criteria – what do Chinese AI auditors look at?
The ethical review procedure is not merely a formality – it is a detailed assessment of the technology based on seven fundamental principles. The proposed artificial intelligence system must:
- to promote human well-being (the principle of human well-being),
- to respect life and human rights,
- to ensure fairness and impartiality (to prevent bias and discrimination),
- ensure sound risk management,
- to ensure openness and transparency,
- ensure the protection of privacy and security,
- to be controllable and reliable – (the principle of controllability and reliability).
In practice, the developers’ declarations are compared with the software architecture. During the audit, the experts analyse the following elements in detail:
- criteria for selecting training data – the sources of information, their representativeness, the legality of their collection, and the potential for reproducing errors and social biases are verified;
- system architecture – the rationality of the algorithm itself, the structure of the model and the overall technical design are assessed in relation to the objectives for which it is intended;
- protection against discrimination – checks are carried out on the safeguards put in place to prevent bias and the exploitation of algorithmic advantages in the market;
- human oversight – the system’s architecture must ensure that it is genuinely possible for a human to intervene and take control of the application’s operation should the need arise;
- operational transparency – developers must demonstrate complete clarity regarding the project’s objectives, the logic behind the decisions made by the algorithm, and the potential risks associated with its operation.
4.5. Under constant scrutiny – the principles of ongoing ethical oversight
Under constant scrutiny – the principles of ongoing ethical oversight: Receiving a positive ethical assessment does not mean that the regulatory authorities will cease to take an interest. The Chinese system introduces a mechanism for ongoing oversight, which means that approved projects are subject to systematic reviews throughout their entire operational period.
The frequency of subsequent audits depends directly on the level of sophistication and the specific nature of the technology in question. In standard projects, a follow-up audit takes place on a regular basis, every 12 months. Projects on the expert list, due to their higher level of risk, are subject to more frequent verification, which is carried out every 6 months. However, if significant changes occur in the system’s operation that affect its ethical aspects, the full assessment procedure must be repeated.
Separate rules apply to emergency situations directly related to the protection of public health or safety. In such crisis situations, a fast-track procedure is activated, which requires a review to be carried out within 72 hours.
4.6. The cost of error – how is China enforcing the new regulations?
Breaches of the rules governing the ethical assessment of artificial intelligence carry consequences. Although the guidelines themselves do not establish a new, separate schedule of penalties, the Chinese legislature has integrated the regulatory framework into existing, overarching legislation.
This means that entities which fail to comply with the audit requirement or implement systems that do not comply with the standards are liable under the four key pieces of legislation governing the local technology and science market.
- The Cybersecurity Act (CSL). Used in situations where the irregularities relate to the security of the network infrastructure itself on which the AI solution in question operates.
- The Data Security Act (DSL). It applies if the breaches are directly linked to the management of data sets or inadequate protection of such data.
- The Personal Data Protection Act (PIPL). It applies when an AI system infringes users’ privacy, perpetuates biases or processes their information without the required consent.
- The Science and Technology Progress Act. It sets out general standards for the conduct of research and development work and defines the rules governing institutional liability for breaches of scientific ethics.
Thanks to this approach, supervisory authorities can apply a proven and comprehensive range of sanctions. Depending on the nature of the offence, companies and institutions face administrative penalties – ranging from orders to suspend work on a project and block services, to substantial financial fines provided for in the key digital legislation.
4.7. Two philosophies: the Chinese model of AI ethics compared with Western approaches
All the major economic powers – from the United States and the European Union to Asia – are unanimously implementing strict legal frameworks for the artificial intelligence market. The difference lies in the philosophy and the objectives set by legislators. Europe is drafting its legislation with a view to protecting individual rights and citizens’ privacy. China, on the other hand, is subordinating technology to state objectives: maintaining social stability and the controlled stimulation of the economy.
The table below sets out the key differences in approaches to algorithm management:
| Aspect | Europe (AI Act) | China (Multi-act system) |
| Top priority | Individual rights, human autonomy, consumer protection | Social stability, national security, economic development |
| Model of the approach | Horizontal – a single comprehensive piece of legislation for the entire market | Vertical – numerous scattered acts relating to specific technologies |
| Biometrics in public spaces | Limited to exceptional circumstances expressly provided for in the legislation | Legal, universal and regulated by the state |
| Form of ethical oversight | Conformity assessment prior to placing on the market | Internal committees within organisations and government expert panels |
| Maximum penalties | Up to EUR 35 million (approx. PLN 149 million) or up to 7 per cent of global annual turnover | Up to 50 million RMB (approx. 6.4 million EUR / 27.4 million PLN) or up to 5 per cent of annual turnover |
| The basis of data operations | A wide range of legal bases (e.g. legitimate interest) | First and foremost, the user’s explicit consent |
The key conclusion drawn from the analysis of Chinese regulations concerns the point at which the state decides to intervene. The system there treats AI ethics as a prerequisite (a ‘gating requirement’), rather than as a voluntary declaration made after the technology has already been implemented.
Successfully passing an ethical review is a mandatory step required to obtain regulatory approval for the commercialisation of a product. In practice, this requires developers to establish a detailed audit trail. It also enables government bodies to ensure that genuine accountability is upheld at every stage of an algorithm’s lifecycle.

5. Practical recommendations for businesses
Current changes to Chinese digital law require companies to review their existing procedures. Businesses operating in the Chinese market or collaborating with local entities are faced with the need to implement new standards for information and technology management. Effectively safeguarding an organisation’s interests requires a focus on three key areas.
5.1. Verification of procedures, i.e. a compliance audit
The starting point for any organisation should be a detailed review of its legal and technical structures. These measures enable the identification of any potential security gaps and should include:
- an analysis of compliance with the amendment to the Cybersecurity Act (CSL), with particular regard to provisions of an extraterritorial nature,
- aligning operations with the requirements of the PIPL Act, including the new guidelines set out in the national standard GB/T 45574-2025,
- a review of data transfer channels, i.e. verification of the legality and correctness of the transfer of information outside China,
- an audit of artificial intelligence systems in light of the provisions of the AIGC regulations and the requirements of Article 24 of the PIPL Act,
- preparing organisational structures for the planned state ethical review.
5.2. Documentation under scrutiny by the regulator
Chinese regulatory authorities are placing increasing emphasis on formal documentation, which serves as evidence of compliance with the law for auditors. Companies must ensure that certain records are kept and archived accurately. Among the most important of these are data protection impact assessments (PIPIA), which must be retained for a period of at least three years.
It is also necessary to formally register the Data Protection Officer (PIPO) in the CAC’s online system. The evidence base should be supplemented by full reports on the AI ethics reviews carried out and detailed minutes of internal compliance audits.
5.3. A proactive approach
Implementing the appropriate procedures ahead of an official inspection brings tangible operational benefits to organisations. This approach represents a direct investment in the organisation’s legal and technical security. It helps to build trust in relationships with local consumers and business partners.
Above all, however, streamlining processes at an early stage effectively protects the company’s budget from fines running into the millions. It also ensures secure operational continuity in the demanding Chinese market.

Summary: China’s new era of digital compliance
The year 2026 brings significant changes to Chinese digital law. The amendment to the CSL, the development of the PIPL, the implementation of AIGC principles and the introduction of an ethical assessment system for artificial intelligence create a complex regulatory landscape. Companies that are able to adapt their processes efficiently and in advance to these requirements will gain a competitive advantage in one of the world’s most important markets.
It is worth bearing in mind that Chinese legislation constitutes a completely autonomous legal system with its own distinct characteristics, entirely different from the European GDPR. The protection of national security, state control and economic development are treated on a par with individual rights. Conducting business effectively in China therefore requires both knowledge of the specific articles and a full understanding of the philosophy underpinning the local legislation.
Professional support: LO:ME’s Chinese Desk
The support offered by LO:ME Law Firm is a response to growing regulatory challenges. Through its dedicated Chinese Desk practice, the firm provides legal services to entities operating at the intersection of the European and Chinese markets.

LO:ME’s experts combine expertise in the fields of technology law, cybersecurity and artificial intelligence with a thorough understanding of the economic realities and cultural nuances of China. In light of these developments, the firm offers services fully tailored to the new obligations facing businesses:
- Audits of the compliance of IT systems with Chinese legislation (including the PIPL and the amended CSL),
- Verification and mapping of procedures for the secure transfer of data outside China,
- Preparing and finalising regulatory documentation, including data protection impact assessments (PIPIA),
- Consultancy on the implementation of AI systems, preparing the organisation to successfully pass both government and internal ethical audits.
Thanks to this support, managers can be confident that administrative matters remain under constant control. This allows the company to focus on the secure growth of its business.



This article is based on the current Chinese legislation in force in June 2026. The information is provided for guidance only and does not constitute legal advice.
Sources and bibliography:
1. Cybersecurity Law of the People’s Republic of China (amended 2026) – Standing Committee of the National People’s Congress, October 2025
2. Personal Information Protection Law of the People’s Republic of China – ONZPL, 20 August 2021
3. GB/T 45574-2025 – National Standard of the People’s Republic of China on the Identification of Sensitive Personal Information
4. Interim Measures for the Management of Generative Artificial Intelligence Services (AIGC Measures) – CAC and 6 agencies, 15 August 2023
5. Measures for the Administration of Artificial Intelligence Technology Ethics Review and Services (Pilot) – MOST, MIIT and 8 departments, 3 April 2026
6. Measures for the Certification of the Outbound Transfer of Personal Information – CAC, 1 January 2026
7. Measures for the Administration of Cybersecurity Incident Reporting – CAC, 1 November 2025
8. Network Data Security Management Regulation – Council of the State, 1 January 2025
9. Regulations on Facilitating and Regulating Cross-border Data Transfers – State Council, 22 March 2024
10. Views on Strengthening Ethical Governance in Science and Technology – The Council to the State
11. Measures for the Administration of Personal Information Protection Compliance Audits – CAC, 1 May 2025
12. Data Security Law of the People’s Republic of China – ONZPL, 1 September 2021