{"id":4151,"date":"2026-06-22T16:00:15","date_gmt":"2026-06-22T14:00:15","guid":{"rendered":"https:\/\/lome.legal\/digital-regulations-in-china-in-2026-changes-in-cybersecurity-data-protection-and-ai\/"},"modified":"2026-08-08T15:03:05","modified_gmt":"2026-08-08T13:03:05","slug":"digital-regulations-in-china-in-2026-changes-in-cybersecurity-data-protection-and-ai","status":"publish","type":"post","link":"https:\/\/lome.legal\/en\/digital-regulations-in-china-in-2026-changes-in-cybersecurity-data-protection-and-ai\/","title":{"rendered":"Digital Regulations in China in 2026: Changes in Cybersecurity, Data Protection, and AI"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>In 2026, China is undergoing a true regulatory revolution in the digital sphere. From the amendment to the Cybersecurity Law (CSL) to the development of the Personal Information Protection Law (PIPL), and on to the first comprehensive AI ethics review system. The Chinese legal landscape is becoming increasingly complex and challenging for companies operating in this market. In this article, we analyze the most important changes, their practical implications, and the differences between the Chinese and European approaches to digital regulation.   <\/strong><\/p>\n\n<h2 class=\"wp-block-heading\">1. Cybersecurity in China: The 2026 Amendment to the Cybersecurity Law<\/h2>\n\n<h3 class=\"wp-block-heading\">1.1. The biggest change since 2017<\/h3>\n\n<p class=\"wp-block-paragraph\">On January 1, 2026, the first amendment to China\u2019s Cybersecurity Law (\u7f51\u7edc\u5b89\u5168\u6cd5) took effect. This is the first major update to the law since it took effect in June 2017. The amendment, approved in October 2025 by the Standing Committee of the National People\u2019s Congress, introduces<strong> three key changes <\/strong>that directly affect all entities operating in China or with Chinese partners.  <\/p>\n\n<h3 class=\"wp-block-heading\">1.2. Extended extraterritorial jurisdiction (Article 77 of the CSL)<\/h3>\n\n<p class=\"wp-block-paragraph\">Prior to the amendment, the CSL was limited to attacks on China\u2019s critical infrastructure (CII). Following the changes, the scope of the regulations was expanded to include<strong> all \u201cactivities by foreign entities that threaten the security of China\u2019s cyber networks.\u201d<\/strong> This means that even companies based outside China may be subject to sanctions\u2014including asset freezes\u2014if their activities are deemed a threat to Chinese cybersecurity. This change is particularly significant for international operators, including shipowners, whose onboard communications may fall under Chinese jurisdiction.   <\/p>\n\n<h3 class=\"wp-block-heading\">1.3. Tiered Penalty System<\/h3>\n\n<p class=\"wp-block-paragraph\">The amendment to China\u2019s Cybersecurity Law puts an end to legal ambiguities by introducing a precise schedule of penalties. The new system directly links the severity of sanctions to the actual consequences of an incident. Importantly for businesses, financial liability increases sharply, and the consequences affect not only corporate budgets but also the personal finances of executives.  <\/p>\n\n<p class=\"wp-block-paragraph\">Under the new legal framework, financial risk is categorised into three levels.<\/p>\n\n<h4 class=\"wp-block-heading\"><strong>A fundamental breach, i.e. a breach without the need to prove damage<\/strong><\/h4>\n\n<p class=\"wp-block-paragraph\">A basic breach of the regulations is punishable by a fine of between 50,000 and 500,000 RMB (Renminbi, which is equivalent to between approximately 6,000 EUR and over 64,000 EUR, and between approximately 27,000 PLN and over 270,000 PLN). Most importantly from the perspective of the regulatory authorities, this penalty may be imposed without the need to prove that the incident caused any actual losses. <\/p>\n\n<h4 class=\"wp-block-heading\"><strong>Aggravating circumstances<\/strong><\/h4>\n\n<p class=\"wp-block-paragraph\">The stakes rise significantly when incidents of a more serious nature occur. The new regulations define these situations precisely, citing, amongst other things, \u2018mass data breaches\u2019 or \u2018partial disruption of critical infrastructure\u2019. In such cases, a company faces a fine of between 500,000 and 2,000,000 RMB (which, when converted to euros, ranges from approximately 64,000 EUR to nearly 260,000 EUR, and when converted to Polish zlotys: from over 270,000 PLN to approximately 1.1 million PLN). However, that is not all \u2013 the amendment personalises liability by imposing a personal fine of between 50,000 and 200,000 RMB on the decision-maker.    <\/p>\n\n<h4 class=\"wp-block-heading\"><strong>Worst-case scenario<\/strong><\/h4>\n\n<p class=\"wp-block-paragraph\">At the top of this pyramid of sanctions are cases classified as having \u2018particularly serious consequences\u2019. Here, the financial penalties range from 2,000,000 to as much as <strong>10,000,000 RMB<\/strong> (i.e. from over 250,000 EUR to approx. 1.29 million EUR, or from approx. 1.1 million PLN to over 5.48 million PLN). At the same time, pressure on senior management is rising dramatically \u2013 a person responsible for gross negligence faces a personal fine of up to 1,000,000 RMB.  <\/p>\n\n<h3 class=\"wp-block-heading\">1.4. Reductions in penalties<\/h3>\n\n<p class=\"wp-block-paragraph\">The amendment is not purely punitive. It also introduces mechanisms for the mitigation or remission of penalties, in accordance with the Administrative Penalties Act. The Cyberspace Administration of China (CAC) may reduce a penalty where the offender voluntarily eliminates or mitigates the harmful effects of the infringement, acted under duress or inducement, voluntarily discloses an infringement unknown to the regulators, and cooperates with law enforcement authorities. In the case of a first-time breach with minor consequences that has been rectified without delay, the penalty may even be waived entirely.    <\/p>\n\n<h3 class=\"wp-block-heading\">1.5. New obligations for critical infrastructure operators (CIIs)<\/h3>\n\n<p class=\"wp-block-paragraph\">The amendment to the regulations places critical infrastructure operators, in particular, on high alert. These are the entities responsible for strategic sectors such as<strong> energy, transport, water management, finance and public services.<\/strong> For these pillars of the state\u2019s functioning, Beijing has drawn up a package of obligations that raise the bar for day-to-day operational activities.  <\/p>\n\n<p class=\"wp-block-paragraph\">First and foremost, any purchase of online products or services by these entities must now be preceded by a more rigorous security assessment. At the same time, the state is tightening the system for monitoring users themselves by introducing a strict requirement for <em>real-name authentication<\/em> for the most important online services, which in practice eliminates anonymity. <\/p>\n\n<p class=\"wp-block-paragraph\">However, the greatest emphasis has been placed on data transparency. Operators have been subject to significantly broader obligations than before to immediately report any security incidents to the regulatory authorities. Furthermore, the amendment enshrines the principle of data localisation:<strong> all information generated within China must physically remain in the country<\/strong>. Cross-border transfers are only permitted in exceptional circumstances \u2013 following a complex administrative procedure, culminating in official approval by the regulator.   <\/p>\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6a846a57aac34&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6a846a57aac34\" class=\"wp-block-image size-full wp-lightbox-container\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1272\" height=\"848\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on--pointerdown=\"actions.preloadImage\" data-wp-on--pointerenter=\"actions.preloadImageWithDelay\" data-wp-on--pointerleave=\"actions.cancelPreload\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/lome.legal\/wp-content\/uploads\/2026\/06\/3_1.png\" alt=\"Digital regulations in China 2026\" class=\"wp-image-3875\" srcset=\"https:\/\/lome.legal\/wp-content\/uploads\/2026\/06\/3_1.png 1272w, https:\/\/lome.legal\/wp-content\/uploads\/2026\/06\/3_1-300x200.png 300w, https:\/\/lome.legal\/wp-content\/uploads\/2026\/06\/3_1-1024x683.png 1024w, https:\/\/lome.legal\/wp-content\/uploads\/2026\/06\/3_1-768x512.png 768w\" sizes=\"(max-width: 1272px) 100vw, 1272px\" \/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\tdata-wp-bind--aria-label=\"state.thisImage.triggerButtonAriaLabel\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.thisImage.buttonRight\"\n\t\t\tdata-wp-style--top=\"state.thisImage.buttonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><\/figure>\n\n<h2 class=\"wp-block-heading\">2. Protection of personal data in China: the evolution of the PIPL<\/h2>\n\n<h3 class=\"wp-block-heading\">2.1. PIPL as the \u2018Chinese GDPR\u2019<\/h3>\n\n<p class=\"wp-block-paragraph\"><strong>The Personal Information Protection Law <\/strong>(PIPL, \u4e2a\u4eba\u4fe1\u606f\u4fdd\u62a4\u6cd5) came into force on 1 November 2021. It is the first comprehensive piece of legislation at national level governing the protection of personal data in China. Although it is often compared to the European GDPR, the PIPL has important differences that every company needs to be aware of.  <\/p>\n\n<h3 class=\"wp-block-heading\">2.2. The main similarities and differences between the PIPL and the GDPR<\/h3>\n\n<p class=\"wp-block-paragraph\">The Chinese Personal Information Protection Law (PIPL) resembles the European GDPR in many respects, which makes it easier for entities operating in the international market to understand its principles. Both sets of regulations are based on a similar definition of personal data, understood as <strong>information relating to an identified or identifiable natural person<\/strong>. As in Europe, the standard requirement in China is to obtain consent for processing, and citizens are granted a similar set of rights: the right to access, rectify, erase and transfer their data.  <\/p>\n\n<p class=\"wp-block-paragraph\">The supervisory mechanisms and sanctions are also similar. Organisations processing the data of more than one million people are required to appoint the equivalent of a Data Protection Officer (PIPO), and serious breaches are subject to heavy financial penalties \u2013 up to 50 million RMB or 5 per cent of annual turnover. <\/p>\n\n<p class=\"wp-block-paragraph\">Despite such striking similarities, there are several fundamental differences that set the Chinese system apart.<\/p>\n\n<h4 class=\"wp-block-heading\"><strong>Absence of a \u2018legitimate interest\u2019<\/strong><\/h4>\n\n<p class=\"wp-block-paragraph\"> Unlike the GDPR, where this is one of the most important and most frequently used legal bases for data processing, the PIPL does not provide for such an arrangement. In the Chinese legal system, the user\u2019s informed consent remains the primary \u2013 and often the only \u2013 legal basis for data processing operations. <\/p>\n\n<h4 class=\"wp-block-heading\"><strong>The national security dimension<\/strong><\/h4>\n\n<p class=\"wp-block-paragraph\">Chinese legislation explicitly links data protection to the interests of the state. The PIPL contains mechanisms allowing for the creation of a so-called<strong> blacklist of foreign entities<\/strong>. Companies included on this list may, for security reasons, be completely barred from accessing the personal data of Chinese citizens.  <\/p>\n\n<h4 class=\"wp-block-heading\"><strong>Data protection for deceased persons<\/strong><\/h4>\n\n<p class=\"wp-block-paragraph\">This is a significant departure from European standards, where data protection rights expire upon a person\u2019s death. In China, close relatives may exercise rights over a deceased person\u2019s data in pursuit of their own legitimate and lawful interests. <\/p>\n\n<h4 class=\"wp-block-heading\"><strong>Higher age limit for children<\/strong><\/h4>\n\n<p class=\"wp-block-paragraph\">PIPL takes a more restrictive approach to the protection of the youngest children. Parental consent to the processing of their children\u2019s data is required for all children under the age of 14 (by comparison, under the GDPR, the general age limit is 16, with the option for individual countries to lower this to 13). <\/p>\n\n<h4 class=\"wp-block-heading\"><strong>Specific restrictions for the public sector<\/strong><\/h4>\n\n<p class=\"wp-block-paragraph\">National public authorities are subject to a strict localisation rule. All personal data they collect must be stored exclusively within Chinese territory. <\/p>\n\n<h3 class=\"wp-block-heading\">2.3. The new GB\/T 45574-2025 standard \u2013 sensitive data<\/h3>\n\n<p class=\"wp-block-paragraph\">From 1 November 2025, the national standard GB\/T 45574-2025 will come into force in China, introducing significant changes to the <strong>way sensitive data is identified.<\/strong> Instead of the previous, rigid catalogue of information, the new regulations require companies to analyse the context of data processing on a case-by-case basis and assess the impact of these activities on the privacy and security of a specific individual. <\/p>\n\n<p class=\"wp-block-paragraph\">Under the new guidelines, the category of sensitive data primarily includes:<\/p>\n\n<ul class=\"wp-block-list\">\n<li>biometric data, including facial recognition systems,<\/li>\n\n\n\n<li>information on financial accounts,<\/li>\n\n\n\n<li>precise location data,<\/li>\n\n\n\n<li>information about one\u2019s state of health,<\/li>\n\n\n\n<li>personal data of minors under the age of 14.<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\">Processing this type of information entails additional formal obligations. Organisations must obtain separate, explicit consent from the user and also provide them with detailed information about the purpose of the processing and its impact on their rights. <\/p>\n\n<p class=\"wp-block-paragraph\">In addition, before carrying out any processing of sensitive data, organisations are required to conduct a data protection impact assessment (PIPIA \u2013 <em>Personal Information Protection Impact Assessment<\/em>). The documentation compiled in this way must be retained for at least three years in the event of an inspection. <\/p>\n\n<h3 class=\"wp-block-heading\">2.4. Cross-border data transfers and the new framework for incident reporting<\/h3>\n\n<p class=\"wp-block-paragraph\">The Chinese system governing the transfer of personal data abroad is based on three distinct legal frameworks. These have been tailored to the scale of a company\u2019s operations and the type of information processed. <\/p>\n\n<ul class=\"wp-block-list\">\n<li><strong><em>Security Assessment. <\/em><\/strong>This procedure applies to organisations operating on a large scale. It is mandatory in situations where a company processes the data of more than one million individuals or where the data being transferred is classified by the state as \u2018sensitive data\u2019. <\/li>\n\n\n\n<li><strong><em>Standard Contract.<\/em> <\/strong>This solution is designed for smaller organisations. It enables data transfers based on a standard contract template that has been approved by the CAC regulator. <\/li>\n\n\n\n<li><strong><em>Certification.<\/em><\/strong> This option has been in place since the start of 2026 and is designed to facilitate the operations of international corporate groups. It enables companies to obtain a formal certificate from an authorised body, which simplifies the procedures for the flow of information within corporate structures. <\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\">In parallel with the streamlining of transfer rules, the regulations governing the response to crisis situations (<em>Measures for the Administration of the Reporting of Cybersecurity Incidents<\/em>) have been tightened. These regulations require companies to notify regulatory authorities of security breaches within a strictly defined, short timeframe. <\/p>\n\n<p class=\"wp-block-paragraph\">For most organisations, the<strong> basic deadline for reporting an incident is 4 hours<\/strong>. For critical infrastructure operators (CIIs), the requirements are stricter \u2013 in their scenario, this timeframe is one hour. The regulations also explicitly define the severity of individual incidents: a data breach involving more than one million personal data records is automatically classified as a \u2018<em>relatively major<\/em>\u2019 incident. <\/p>\n\n<h3 class=\"wp-block-heading\">2.5. The 2026 Enforcement Campaign<\/h3>\n\n<p class=\"wp-block-paragraph\">In April 2026, Chinese regulatory bodies \u2013 led by the CAC, the Ministry of Industry and Information Technology (MIIT) and the Ministry of Public Security (MPS) \u2013 launched a coordinated campaign aimed at enforcing personal data protection regulations. These measures quickly led to specific decisions at local level and significant legal rulings. <\/p>\n\n<p class=\"wp-block-paragraph\">This round of inspections is divided into three main areas.<\/p>\n\n<ul class=\"wp-block-list\">\n<li><strong>Removing incompatible applications.<\/strong> In the country\u2019s major economic centres, such as Beijing, Shanghai, Zhejiang, Jiangsu, Chongqing and Sichuan, local authorities have begun actively removing mobile apps from the market that have breached users\u2019 privacy rights.<\/li>\n\n\n\n<li><strong>Simplifications for smaller businesses.<\/strong> Alongside these restrictive measures, the regulator is working to ensure a balance in administrative obligations. The CAC has published draft new regulations that simplify procedures for small data controllers, making it easier for smaller companies to comply with legal requirements efficiently. <\/li>\n\n\n\n<li><strong>The courts\u2019 unequivocal position.<\/strong> A ruling by the Beijing Internet Court has become a key indicator for the market. The court ruled that the transfer of personal data to third parties without obtaining the user\u2019s separate, explicit consent constitutes a direct breach of the PIPL. <\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\">This ruling finally confirms that <strong>the practice of sharing information within business partnerships or advertising networks without the consumer\u2019s knowledge will not be tolerated in China<\/strong>.<\/p>\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6a846a57ac47c&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6a846a57ac47c\" class=\"wp-block-image size-full wp-lightbox-container\"><img decoding=\"async\" width=\"1272\" height=\"848\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on--pointerdown=\"actions.preloadImage\" data-wp-on--pointerenter=\"actions.preloadImageWithDelay\" data-wp-on--pointerleave=\"actions.cancelPreload\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/lome.legal\/wp-content\/uploads\/2026\/06\/7_1.png\" alt=\"Regulations in China 2026 PIPL\" class=\"wp-image-3887\" srcset=\"https:\/\/lome.legal\/wp-content\/uploads\/2026\/06\/7_1.png 1272w, https:\/\/lome.legal\/wp-content\/uploads\/2026\/06\/7_1-300x200.png 300w, https:\/\/lome.legal\/wp-content\/uploads\/2026\/06\/7_1-1024x683.png 1024w, https:\/\/lome.legal\/wp-content\/uploads\/2026\/06\/7_1-768x512.png 768w\" sizes=\"(max-width: 1272px) 100vw, 1272px\" \/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\tdata-wp-bind--aria-label=\"state.thisImage.triggerButtonAriaLabel\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.thisImage.buttonRight\"\n\t\t\tdata-wp-style--top=\"state.thisImage.buttonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><\/figure>\n\n<h2 class=\"wp-block-heading\">3. Artificial intelligence in China<\/h2>\n\n<h3 class=\"wp-block-heading\">3.1. The absence of a single piece of legislation \u2013 the five pillars of regulation<\/h3>\n\n<p class=\"wp-block-paragraph\">Whilst the European Union has opted to create a single, comprehensive piece of legislation (the AI Act), China has adopted a different strategy. Beijing is taking a <strong>vertical approach<\/strong>, which involves regulating specific applications and algorithms through a range of specialised legislative and administrative measures. This entire system is based on <strong>five fundamental pillars<\/strong>.  <\/p>\n\n<h4 class=\"wp-block-heading\">Pillar 1: Government policies and strategies<\/h4>\n\n<p class=\"wp-block-paragraph\">The direction of development is set out in official government plans, which define the country\u2019s strategic objectives. The first policy document of this nature was the \u2018Plan for the Development of Next-Generation Artificial Intelligence\u2019 from 2017. This document is supplemented by official guidelines from the Council of State, aimed at strengthening ethical oversight in the fields of science and new technologies, such as the \u2018Opinions on Strengthening Ethical Governance in Science and Technology\u2019.   <\/p>\n\n<h4 class=\"wp-block-heading\">Pillar 2: General legal provisions<\/h4>\n\n<p class=\"wp-block-paragraph\">Regulations specific to artificial intelligence do not operate in a vacuum \u2013 they are underpinned by three key pieces of legislation. The Personal Data Protection Act (PIPL) protects personal data used to train and operate algorithms, the Data Security Act (DSL) ensures the protection of the data sets themselves, and the Cybersecurity Act (CSL) safeguards the network infrastructure on which AI systems rely. <\/p>\n\n<h4 class=\"wp-block-heading\">Pillar 3: Administrative and sector-specific regulations<\/h4>\n\n<p class=\"wp-block-paragraph\">This is where you\u2019ll find tools targeting specific technologies and their developers. One example is the \u2018Interim Guidelines for the Management of Generative AI Services\u2019 (AIGC Measures), which regulate content generated by language models or image generators. Separate, detailed regulations apply to recommendation systems and so-called <em>deep synthesis technologies<\/em> \u2013 including, amongst other things, tools for creating deepfake content.    <\/p>\n\n<h4 class=\"wp-block-heading\">Pillar 4: Local and regional regulations<\/h4>\n\n<p class=\"wp-block-paragraph\">Chinese cities enjoy a high degree of autonomy in shaping local market regulations. Major technology hubs, such as Shanghai and Shenzhen, are implementing their own regulations. The aim is, on the one hand, to promote innovation and, on the other, to enable local authorities to exercise detailed control over higher-risk AI products.  <\/p>\n\n<h4 class=\"wp-block-heading\">Pillar 5: National and technical standards<\/h4>\n\n<p class=\"wp-block-paragraph\">The final component of the system is a set of precise engineering guidelines. The China Electronics Standardisation Institute is systematically developing a series of standards for artificial intelligence systems. According to the agreed timetable, work on over 50 new national and industry standards is due to be finalised by the end of 2026, which will set out uniform technical requirements for the entire market.  <\/p>\n\n<h3 class=\"wp-block-heading\">3.2. The rules of the game for generative AI \u2013 the principles underlying the \u2018AIGC Measures\u2019<\/h3>\n\n<p class=\"wp-block-paragraph\">The document entitled \u201cInterim Rules on the Management of Generative Artificial Intelligence Services\u201d, drawn up by the CAC in collaboration with six other government agencies, came into force on 15 August 2023. To this day, it remains the most important piece of legislation governing the operation of content-generating systems within China. These regulations precisely define the obligations of technology providers and set clear boundaries for the commercial use of algorithms.  <\/p>\n\n<p class=\"wp-block-paragraph\">The key requirements for developers of AIGC (Generative AI) services include:<\/p>\n\n<ul class=\"wp-block-list\">\n<li><strong>the legality of training data <\/strong>\u2013 system providers must ensure and demonstrate that the sources of information used to train the models are entirely lawful;<\/li>\n\n\n\n<li>protection of privacy during the training phase \u2013 if personal data is contained in the training datasets, its use requires prior consent from the data subjects;<\/li>\n\n\n\n<li><strong>respect for users\u2019 rights <\/strong>\u2013 artificial intelligence systems must be designed in such a way as to enable, from the outset, the exercise of the rights set out in the PIPL Act \u2013 including the right to access, rectify or erase data;<\/li>\n\n\n\n<li><strong>built-in safeguards<\/strong> \u2013 providers are required to implement technical measures that effectively prevent data leaks and protect users\u2019 privacy.<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\">The list of prohibited activities has been formulated just as clearly. Chinese law in this area unequivocally prohibits: <\/p>\n\n<ul class=\"wp-block-list\">\n<li><strong>generation of harmful content <\/strong>\u2013 algorithms must not create material that infringes the rights of third parties or poses a threat to national security;<\/li>\n\n\n\n<li><strong>monopolistic practices<\/strong> \u2013 it is prohibited to use AI technology to engage in unfair competition or to establish a monopoly position in the market;<\/li>\n\n\n\n<li><strong>algorithmic discrimination <\/strong>\u2013 the regulations prohibit unjustified differences in the treatment of customers in commercial transactions. In practice, this eliminates, amongst other things, the phenomenon of price discrimination, i.e. the automatic increase in the prices of services or products by AI for selected user profiles.  <\/li>\n<\/ul>\n\n<h3 class=\"wp-block-heading\">3.3. Automated decision-making (Article 24 of the PIPL)<\/h3>\n\n<p class=\"wp-block-paragraph\">Automated decision-making Article 24 of the PIPL Act is the primary regulatory framework for artificial intelligence in China. This provision focuses on automated decision-making processes and imposes requirements on system controllers designed to protect users from the arbitrary behaviour of algorithms. (Article 24 of the PIPL) <\/p>\n\n<p class=\"wp-block-paragraph\">Under this regulation, any process based on automated data analysis must meet specific criteria.<\/p>\n\n<ul class=\"wp-block-list\">\n<li><strong>Transparency.<\/strong> The algorithm itself and the way in which it makes decisions cannot remain a company secret \u2013 full transparency regarding the system\u2019s operation is required.<\/li>\n\n\n\n<li><strong>Objectivity.<\/strong> The results generated by IT systems must be fair and impartial, in order to prevent technology from perpetuating biases.<\/li>\n\n\n\n<li><strong>The right to an explanation.<\/strong> A user who has been subject to an automated decision has the right to request a detailed explanation of the reasons on which the system was based.<\/li>\n\n\n\n<li><strong>Refusal to automate.<\/strong> Consumers are entitled to object to a decision if it has been made entirely by automated means, without any human intervention.<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\">Another key element of this article is the<strong> explicit ban on unjustified differentiation in transaction terms<\/strong>. This provision directly targets the practice known as <em>\u2018big data price discrimination<\/em>\u2019, which is widely used by e-commerce platforms. In practice, this means that online shops and service providers cannot, without an objective reason, offer the same product at different prices to different users, based solely on an algorithmic assessment of their profile or purchase history.  <\/p>\n\n<h3 class=\"wp-block-heading\">3.4. AI in the public sector<\/h3>\n\n<p class=\"wp-block-paragraph\">The active implementation of artificial intelligence in China\u2019s public sector has been the subject of considerable interest and debate on the international stage for years. Beijing does not view algorithms merely as the preserve of the private sector, but as a tool for improving the governance of the state and society at many levels. <\/p>\n\n<p class=\"wp-block-paragraph\">The practical application of these technologies today extends to areas that are subject to strict restrictions in other parts of the world. In urban areas, <strong>advanced facial recognition systems<\/strong> are commonplace, their operation regulated by the provisions of the PIPL and CSL Acts. New technologies also support the local justice system, where <strong>algorithms assist judges in analysing court documents<\/strong> and searching for relevant precedents. In education, meanwhile, AI systems are used to <strong>automatically mark pupils\u2019 work<\/strong> and monitor their behaviour during lessons. A separate branch is <strong>the citizen assessment system<\/strong>, or <em>social credit system<\/em>. Within the Chinese legal system, this remains a fully legitimate administrative instrument.     <\/p>\n\n<p class=\"wp-block-paragraph\">The most significant difference compared with European standards concerns the approach to the presence of technology in everyday life. Whilst the EU\u2019s AI Act, in most cases, considers the use of biometric identification systems in public spaces to be prohibited, in China such solutions are entirely legal and form an integral part of the state\u2019s infrastructure. <\/p>\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6a846a57adc4b&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6a846a57adc4b\" class=\"wp-block-image size-full wp-lightbox-container\"><img decoding=\"async\" width=\"1272\" height=\"848\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on--pointerdown=\"actions.preloadImage\" data-wp-on--pointerenter=\"actions.preloadImageWithDelay\" data-wp-on--pointerleave=\"actions.cancelPreload\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/lome.legal\/wp-content\/uploads\/2026\/06\/6_1.png\" alt=\"artificial intelligence in China\" class=\"wp-image-3884\" srcset=\"https:\/\/lome.legal\/wp-content\/uploads\/2026\/06\/6_1.png 1272w, https:\/\/lome.legal\/wp-content\/uploads\/2026\/06\/6_1-300x200.png 300w, https:\/\/lome.legal\/wp-content\/uploads\/2026\/06\/6_1-1024x683.png 1024w, https:\/\/lome.legal\/wp-content\/uploads\/2026\/06\/6_1-768x512.png 768w\" sizes=\"(max-width: 1272px) 100vw, 1272px\" \/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\tdata-wp-bind--aria-label=\"state.thisImage.triggerButtonAriaLabel\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.thisImage.buttonRight\"\n\t\t\tdata-wp-style--top=\"state.thisImage.buttonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><\/figure>\n\n<h2 class=\"wp-block-heading\">4. Ethical AI in China: from voluntary guidelines to mandatory regulations<\/h2>\n\n<h3 class=\"wp-block-heading\">4.1. A new phase of oversight: The AI ethics assessment system<\/h3>\n\n<p class=\"wp-block-paragraph\">On 3 April 2026, the Ministry of Science and Technology (MOST) and the Ministry of Industry and Information Technology (MIIT), acting in consultation with eight other government departments, published new regulatory guidelines: \u2018Interim Measures for the Administration of AI Technology Ethics Review and Services\u2019 (<em>Measures for the Administration of AI Technology Ethics Review and Services (Trial)<\/em>).<\/p>\n\n<p class=\"wp-block-paragraph\">This document introduces <strong>China\u2019s first dedicated ethical assessment system for artificial intelligence-based solutions<\/strong>. Rather than making general declarations, the state administration is thus establishing a formal regulatory framework. The aim is to ensure that new technologies are developed and implemented in a manner consistent with accepted social and legal standards before they are put into widespread use.  <\/p>\n\n<h3 class=\"wp-block-heading\">4.2. The broad scope of the new regulations \u2013 who and what is subject to ethical assessment?<\/h3>\n\n<p class=\"wp-block-paragraph\">The newly introduced regulations are wide-ranging and cover all activities relating to artificial intelligence carried out within China, provided that they may give rise to ethical challenges. Supervision will primarily apply to projects that have an impact on: <\/p>\n\n<ul class=\"wp-block-list\">\n<li>human dignity and public order,<\/li>\n\n\n\n<li>the lives and health of citizens,<\/li>\n\n\n\n<li>the natural environment and sustainable development.<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\">The regulations are not limited solely to the worlds of technology and business. A wide range of entities is now required to carry out ethical assessments. Both businesses and universities, research institutes and healthcare organisations that develop or use artificial intelligence systems in their operations must comply with the new legal procedures.  <\/p>\n\n<h3 class=\"wp-block-heading\">4.3. A three-tier structure \u2013 a framework for the ethical assessment of artificial intelligence<\/h3>\n\n<p class=\"wp-block-paragraph\">China\u2019s new ethical oversight system is based on a transparent, three-tiered supervisory structure. Responsibility for verifying projects is shared between the organisations themselves, specialised external bodies and the state administration. This division allows procedures to be flexibly tailored to the scale and specific nature of a given technological solution.  <\/p>\n\n<p class=\"wp-block-paragraph\">The verification process is carried out at the following levels:<\/p>\n\n<ul class=\"wp-block-list\">\n<li><strong>Level 1: Internal ethics committees.<\/strong> Every organisation operating in the field of artificial intelligence is required to establish its own internal ethics committee. Such a committee must comprise at least five experts representing various specialisms: AI technology, its practical applications, as well as ethics and law. The committee is responsible for the initial assessment of projects and the ongoing monitoring of work within the organisation.  <\/li>\n\n\n\n<li><strong>Level 2: External service centres.<\/strong> The legislator has provided a solution for organisations that do not have the necessary expertise or staff to carry out such analyses themselves. They may entrust the assessment to authorised external bodies. These centres operate as certified partners, carrying out reviews on behalf of clients and helping companies to comply with legal requirements.  <\/li>\n\n\n\n<li><strong>Level 3: Government expert review.<\/strong> The highest level of scrutiny is reserved for high-risk technologies. These are systems that can directly shape public opinion, influence users\u2019 psychological behaviour, or rely on advanced, fully automated decision-making. In such cases, the assessment is carried out by a special panel of experts organised by government bodies. Officials have 30 days from the date of formal acceptance of the application to issue an official decision.   <\/li>\n<\/ul>\n\n<h3 class=\"wp-block-heading\">4.4. Assessment criteria \u2013 what do Chinese AI auditors look at?<\/h3>\n\n<p class=\"wp-block-paragraph\">The ethical review procedure is not merely a formality \u2013 it is a detailed assessment of the technology based on seven fundamental principles. The proposed artificial intelligence system must: <\/p>\n\n<ol class=\"wp-block-list\">\n<li>to promote human well-being (the principle of human well-being),<\/li>\n\n\n\n<li>to respect life and human rights, <\/li>\n\n\n\n<li>to ensure fairness and impartiality (to<em> prevent bias and discrimination<\/em>),<\/li>\n\n\n\n<li>ensure sound risk management,<\/li>\n\n\n\n<li>to ensure openness and transparency,<\/li>\n\n\n\n<li>ensure the protection of privacy and security,<\/li>\n\n\n\n<li>to be controllable and reliable \u2013 (the principle of controllability and reliability).<\/li>\n<\/ol>\n\n<p class=\"wp-block-paragraph\">In practice, the developers\u2019 declarations are compared with the software architecture. During the audit, the experts analyse the following elements in detail: <\/p>\n\n<ul class=\"wp-block-list\">\n<li>criteria for selecting training data \u2013 the sources of information, their representativeness, the legality of their collection, and the potential for reproducing errors and social biases are verified;<\/li>\n\n\n\n<li>system architecture \u2013 the rationality of the algorithm itself, the structure of the model and the overall technical design are assessed in relation to the objectives for which it is intended;<\/li>\n\n\n\n<li>protection against discrimination \u2013 checks are carried out on the safeguards put in place to prevent bias and the exploitation of algorithmic advantages in the market;<\/li>\n\n\n\n<li>human oversight \u2013 the system\u2019s architecture must ensure that it is genuinely possible for a human to intervene and take control of the application\u2019s operation should the need arise;<\/li>\n\n\n\n<li>operational transparency \u2013 developers must demonstrate complete clarity regarding the project\u2019s objectives, the logic behind the decisions made by the algorithm, and the potential risks associated with its operation.<\/li>\n<\/ul>\n\n<h3 class=\"wp-block-heading\">4.5. Under constant scrutiny \u2013 the principles of ongoing ethical oversight<\/h3>\n\n<p class=\"wp-block-paragraph\">Under constant scrutiny \u2013 the principles of ongoing ethical oversight: Receiving a positive ethical assessment does not mean that the regulatory authorities will cease to take an interest. The Chinese system introduces a mechanism for ongoing oversight, which means that approved projects are subject to systematic reviews throughout their entire operational period. <\/p>\n\n<p class=\"wp-block-paragraph\">The frequency of subsequent audits depends directly on the level of sophistication and the specific nature of the technology in question. In standard projects, a follow-up audit takes place on a regular basis, every 12 months. Projects on the expert list, due to their higher level of risk, are subject to more frequent verification, which is carried out every 6 months. However, if significant changes occur in the system\u2019s operation that affect its ethical aspects, the full assessment procedure must be repeated.   <\/p>\n\n<p class=\"wp-block-paragraph\">Separate rules apply to emergency situations directly related to the protection of public health or safety. In such crisis situations, a fast-track procedure is activated, which requires a review to be carried out within 72 hours. <\/p>\n\n<h3 class=\"wp-block-heading\">4.6. The cost of error \u2013 how is China enforcing the new regulations?<\/h3>\n\n<p class=\"wp-block-paragraph\">Breaches of the rules governing the ethical assessment of artificial intelligence carry consequences. Although the guidelines themselves do not establish a new, separate schedule of penalties, the Chinese legislature has integrated the regulatory framework into existing, overarching legislation. <\/p>\n\n<p class=\"wp-block-paragraph\">This means that entities which fail to comply with the audit requirement or implement systems that do not comply with the standards are liable under the four key pieces of legislation governing the local technology and science market.<\/p>\n\n<ul class=\"wp-block-list\">\n<li><strong>The Cybersecurity Act (CSL).<\/strong> Used in situations where the irregularities relate to the security of the network infrastructure itself on which the AI solution in question operates.<\/li>\n\n\n\n<li><strong>The Data Security Act (DSL).<\/strong> It applies if the breaches are directly linked to the management of data sets or inadequate protection of such data.<\/li>\n\n\n\n<li><strong>The Personal Data Protection Act (PIPL).<\/strong> It applies when an AI system infringes users\u2019 privacy, perpetuates biases or processes their information without the required consent.<\/li>\n\n\n\n<li><strong>The Science and Technology Progress Act. <\/strong>It sets out general standards for the conduct of research and development work and defines the rules governing institutional liability for breaches of scientific ethics.<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\">Thanks to this approach, supervisory authorities can apply a proven and comprehensive range of sanctions. Depending on the nature of the offence, companies and institutions face administrative penalties \u2013 ranging from orders to suspend work on a project and block services, to substantial financial fines provided for in the key digital legislation. <\/p>\n\n<h3 class=\"wp-block-heading\">4.7. Two philosophies: the Chinese model of AI ethics compared with Western approaches<\/h3>\n\n<p class=\"wp-block-paragraph\">All the major economic powers \u2013 from the United States and the European Union to Asia \u2013 are unanimously implementing strict legal frameworks for the artificial intelligence market. The difference lies in the philosophy and the objectives set by legislators. Europe is drafting its legislation with a view to protecting individual rights and citizens\u2019 privacy. China, on the other hand, is subordinating technology to state objectives: maintaining social stability and the controlled stimulation of the economy.   <\/p>\n\n<p class=\"wp-block-paragraph\">The table below sets out the key differences in approaches to algorithm management:<\/p>\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><td><strong>Aspect<\/strong><\/td><td><strong>Europe (AI Act)<\/strong><\/td><td><strong>China (Multi-act system)<\/strong><\/td><\/tr><\/thead><tbody><tr><td><strong>Top priority<\/strong><\/td><td>Individual rights, human autonomy, consumer protection<\/td><td>Social stability, national security, economic development<\/td><\/tr><tr><td><strong>Model of the approach<\/strong><\/td><td>Horizontal \u2013 a single comprehensive piece of legislation for the entire market<\/td><td>Vertical \u2013 numerous scattered acts relating to specific technologies<\/td><\/tr><tr><td><strong>Biometrics in public spaces<\/strong><\/td><td>Limited to exceptional circumstances expressly provided for in the legislation<\/td><td>Legal, universal and regulated by the state<\/td><\/tr><tr><td><strong>Form of ethical oversight<\/strong><\/td><td>Conformity assessment prior to placing on the market<\/td><td>Internal committees within organisations and government expert panels<\/td><\/tr><tr><td><strong>Maximum penalties<\/strong><\/td><td>Up to EUR 35 million (approx. PLN 149 million) or up to 7 per cent of global annual turnover<\/td><td>Up to 50 million RMB (approx. 6.4 million EUR \/ 27.4 million PLN) or up to 5 per cent of annual turnover<\/td><\/tr><tr><td><strong>The basis of data operations<\/strong><\/td><td>A wide range of legal bases (e.g. legitimate interest)<\/td><td>First and foremost, the user\u2019s explicit consent<\/td><\/tr><\/tbody><\/table><\/figure>\n\n<p class=\"wp-block-paragraph\">The key conclusion drawn from the analysis of Chinese regulations concerns the point at which the state decides to intervene. The system there treats AI ethics as a prerequisite (a \u2018gating requirement\u2019), rather than as a voluntary declaration made after the technology has already been implemented. <\/p>\n\n<p class=\"wp-block-paragraph\">Successfully passing an ethical review is a mandatory step required to obtain regulatory approval for the commercialisation of a product. In practice, this requires developers to establish a detailed audit trail. It also enables government bodies to ensure that genuine accountability is upheld at every stage of an algorithm\u2019s lifecycle.  <\/p>\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6a846a57af7a6&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6a846a57af7a6\" class=\"wp-block-image size-full wp-lightbox-container\"><img loading=\"lazy\" decoding=\"async\" width=\"1272\" height=\"848\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on--pointerdown=\"actions.preloadImage\" data-wp-on--pointerenter=\"actions.preloadImageWithDelay\" data-wp-on--pointerleave=\"actions.cancelPreload\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/lome.legal\/wp-content\/uploads\/2026\/06\/9_2.png\" alt=\"Ethical artificial intelligence in China\" class=\"wp-image-3893\" srcset=\"https:\/\/lome.legal\/wp-content\/uploads\/2026\/06\/9_2.png 1272w, https:\/\/lome.legal\/wp-content\/uploads\/2026\/06\/9_2-300x200.png 300w, https:\/\/lome.legal\/wp-content\/uploads\/2026\/06\/9_2-1024x683.png 1024w, https:\/\/lome.legal\/wp-content\/uploads\/2026\/06\/9_2-768x512.png 768w\" sizes=\"(max-width: 1272px) 100vw, 1272px\" \/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\tdata-wp-bind--aria-label=\"state.thisImage.triggerButtonAriaLabel\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.thisImage.buttonRight\"\n\t\t\tdata-wp-style--top=\"state.thisImage.buttonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><\/figure>\n\n<h2 class=\"wp-block-heading\">5. Practical recommendations for businesses<\/h2>\n\n<p class=\"wp-block-paragraph\">Current changes to Chinese digital law require companies to review their existing procedures. Businesses operating in the Chinese market or collaborating with local entities are faced with the need to implement new standards for information and technology management. Effectively safeguarding an organisation\u2019s interests requires a focus on three key areas.  <\/p>\n\n<h3 class=\"wp-block-heading\">5.1. Verification of procedures, i.e. a compliance audit<\/h3>\n\n<p class=\"wp-block-paragraph\">The starting point for any organisation should be a detailed review of its legal and technical structures. These measures enable the identification of any potential security gaps and should include: <\/p>\n\n<ul class=\"wp-block-list\">\n<li>an analysis of compliance with the amendment to the Cybersecurity Act (CSL), with particular regard to provisions of an extraterritorial nature,<\/li>\n\n\n\n<li>aligning operations with the requirements of the PIPL Act, including the new guidelines set out in the national standard GB\/T 45574-2025,<\/li>\n\n\n\n<li>a review of data transfer channels, i.e. verification of the legality and correctness of the transfer of information outside China,<\/li>\n\n\n\n<li>an audit of artificial intelligence systems in light of the provisions of the AIGC regulations and the requirements of Article 24 of the PIPL Act,<\/li>\n\n\n\n<li>preparing organisational structures for the planned state ethical review.<\/li>\n<\/ul>\n\n<h3 class=\"wp-block-heading\">5.2. Documentation under scrutiny by the regulator<\/h3>\n\n<p class=\"wp-block-paragraph\">Chinese regulatory authorities are placing increasing emphasis on formal documentation, which serves as evidence of compliance with the law for auditors. Companies must ensure that certain records are kept and archived accurately. Among the most important of these are data protection impact assessments (PIPIA), which must be retained for a period of at least three years.  <\/p>\n\n<p class=\"wp-block-paragraph\">It is also necessary to formally register the Data Protection Officer (PIPO) in the CAC\u2019s online system. The evidence base should be supplemented by full reports on the AI ethics reviews carried out and detailed minutes of internal compliance audits. <\/p>\n\n<h3 class=\"wp-block-heading\">5.3. A proactive approach<\/h3>\n\n<p class=\"wp-block-paragraph\">Implementing the appropriate procedures ahead of an official inspection brings tangible operational benefits to organisations. This approach represents a direct investment in the organisation\u2019s legal and technical security. It helps to build trust in relationships with local consumers and business partners.  <\/p>\n\n<p class=\"wp-block-paragraph\">Above all, however, streamlining processes at an early stage effectively protects the company\u2019s budget from fines running into the millions. It also ensures secure operational continuity in the demanding Chinese market. <\/p>\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6a846a57b05c0&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6a846a57b05c0\" class=\"wp-block-image size-full wp-lightbox-container\"><img loading=\"lazy\" decoding=\"async\" width=\"1272\" height=\"848\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on--pointerdown=\"actions.preloadImage\" data-wp-on--pointerenter=\"actions.preloadImageWithDelay\" data-wp-on--pointerleave=\"actions.cancelPreload\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/lome.legal\/wp-content\/uploads\/2026\/06\/4_2.png\" alt=\"Regulations in China 2026\" class=\"wp-image-3878\" srcset=\"https:\/\/lome.legal\/wp-content\/uploads\/2026\/06\/4_2.png 1272w, https:\/\/lome.legal\/wp-content\/uploads\/2026\/06\/4_2-300x200.png 300w, https:\/\/lome.legal\/wp-content\/uploads\/2026\/06\/4_2-1024x683.png 1024w, https:\/\/lome.legal\/wp-content\/uploads\/2026\/06\/4_2-768x512.png 768w\" sizes=\"(max-width: 1272px) 100vw, 1272px\" \/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\tdata-wp-bind--aria-label=\"state.thisImage.triggerButtonAriaLabel\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.thisImage.buttonRight\"\n\t\t\tdata-wp-style--top=\"state.thisImage.buttonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><\/figure>\n\n<h2 class=\"wp-block-heading\">Summary: China\u2019s new era of digital compliance<\/h2>\n\n<p class=\"wp-block-paragraph\">The year 2026 brings significant changes to Chinese digital law. The amendment to the CSL, the development of the PIPL, the implementation of AIGC principles and the introduction of an ethical assessment system for artificial intelligence create a complex regulatory landscape. Companies that are able to adapt their processes efficiently and in advance to these requirements will gain a competitive advantage in one of the world\u2019s most important markets.  <\/p>\n\n<p class=\"wp-block-paragraph\">It is worth bearing in mind that Chinese legislation constitutes a completely autonomous legal system with its own distinct characteristics, entirely different from the European GDPR. The protection of national security, state control and economic development are treated on a par with individual rights. Conducting business effectively in China therefore requires both knowledge of the specific articles and a full understanding of the philosophy underpinning the local legislation.  <\/p>\n\n<h3 class=\"wp-block-heading\">Professional support: LO:ME\u2019s Chinese Desk<\/h3>\n\n<p class=\"wp-block-paragraph\">The support offered by LO:ME Law Firm is a response to growing regulatory challenges. Through its dedicated <strong><a href=\"https:\/\/lome.legal\/en\/chinese-desk-2\/\" type=\"specjalizacje\" id=\"814\">Chinese Desk practice<\/a><\/strong>, the firm provides legal services to entities operating at the intersection of the European and Chinese markets. <\/p>\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6a846a57b108e&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6a846a57b108e\" class=\"wp-block-image size-full wp-lightbox-container\"><img loading=\"lazy\" decoding=\"async\" width=\"1272\" height=\"848\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on--pointerdown=\"actions.preloadImage\" data-wp-on--pointerenter=\"actions.preloadImageWithDelay\" data-wp-on--pointerleave=\"actions.cancelPreload\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/lome.legal\/wp-content\/uploads\/2025\/10\/LOME-Blog-1272-x-848-px-2.png\" alt=\"Marta Dargas-Draganik, attorney-at-law\" class=\"wp-image-3101\" srcset=\"https:\/\/lome.legal\/wp-content\/uploads\/2025\/10\/LOME-Blog-1272-x-848-px-2.png 1272w, https:\/\/lome.legal\/wp-content\/uploads\/2025\/10\/LOME-Blog-1272-x-848-px-2-300x200.png 300w, https:\/\/lome.legal\/wp-content\/uploads\/2025\/10\/LOME-Blog-1272-x-848-px-2-1024x683.png 1024w, https:\/\/lome.legal\/wp-content\/uploads\/2025\/10\/LOME-Blog-1272-x-848-px-2-768x512.png 768w\" sizes=\"(max-width: 1272px) 100vw, 1272px\" \/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\tdata-wp-bind--aria-label=\"state.thisImage.triggerButtonAriaLabel\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.thisImage.buttonRight\"\n\t\t\tdata-wp-style--top=\"state.thisImage.buttonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><\/figure>\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/lome.legal\/en\/team\/dargas-draganik\/\" type=\"zespol\" id=\"2191\">Find out more about Marta Dargas-Draganik<\/a><\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\">LO:ME\u2019s experts combine expertise in the fields of technology law, cybersecurity and artificial intelligence with a thorough understanding of the economic realities and cultural nuances of China. In light of these developments, the firm offers services fully tailored to the new obligations facing businesses: <\/p>\n\n<ul class=\"wp-block-list\">\n<li><strong>Audits of the compliance<\/strong> of IT systems with Chinese legislation (including the PIPL and the amended CSL),<\/li>\n\n\n\n<li><strong>Verification and mapping of procedures<\/strong> for the secure transfer of data outside China,<\/li>\n\n\n\n<li><strong>Preparing and finalising regulatory documentation,<\/strong> including data protection impact assessments (PIPIA),<\/li>\n\n\n\n<li><strong>Consultancy on the implementation of AI systems<\/strong>, preparing the organisation to successfully pass both government and internal ethical audits.<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\">Thanks to this support, managers can be confident that administrative matters remain under constant control. This allows the company to focus on the secure growth of its business. <\/p>\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"320\" height=\"100\" src=\"https:\/\/lome.legal\/wp-content\/uploads\/2025\/11\/Button-kontakt.png\" alt=\"Contact\" class=\"wp-image-3237\" srcset=\"https:\/\/lome.legal\/wp-content\/uploads\/2025\/11\/Button-kontakt.png 320w, https:\/\/lome.legal\/wp-content\/uploads\/2025\/11\/Button-kontakt-300x94.png 300w\" sizes=\"(max-width: 320px) 100vw, 320px\" \/><\/figure>\n\n<figure class=\"wp-block-image aligncenter size-full\"><a href=\"https:\/\/tel.887217166\"><img loading=\"lazy\" decoding=\"async\" width=\"400\" height=\"125\" src=\"https:\/\/lome.legal\/wp-content\/uploads\/2025\/12\/Buttony-LOME.png\" alt=\"Phone number for the LO:ME law firm\" class=\"wp-image-3358\" srcset=\"https:\/\/lome.legal\/wp-content\/uploads\/2025\/12\/Buttony-LOME.png 400w, https:\/\/lome.legal\/wp-content\/uploads\/2025\/12\/Buttony-LOME-300x94.png 300w\" sizes=\"(max-width: 400px) 100vw, 400px\" \/><\/a><\/figure>\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"2560\" height=\"1707\" src=\"https:\/\/lome.legal\/wp-content\/uploads\/2025\/09\/20250918-_X1A4494_blur-scaled.jpg\" alt=\"LO:ME law firm\" class=\"wp-image-2762\" srcset=\"https:\/\/lome.legal\/wp-content\/uploads\/2025\/09\/20250918-_X1A4494_blur-scaled.jpg 2560w, https:\/\/lome.legal\/wp-content\/uploads\/2025\/09\/20250918-_X1A4494_blur-300x200.jpg 300w, https:\/\/lome.legal\/wp-content\/uploads\/2025\/09\/20250918-_X1A4494_blur-1024x683.jpg 1024w, https:\/\/lome.legal\/wp-content\/uploads\/2025\/09\/20250918-_X1A4494_blur-768x512.jpg 768w, https:\/\/lome.legal\/wp-content\/uploads\/2025\/09\/20250918-_X1A4494_blur-1536x1024.jpg 1536w, https:\/\/lome.legal\/wp-content\/uploads\/2025\/09\/20250918-_X1A4494_blur-2048x1365.jpg 2048w\" sizes=\"(max-width: 2560px) 100vw, 2560px\" \/><\/figure>\n\n<p class=\"wp-block-paragraph\"><em>This article is based on the current Chinese legislation in force in June 2026. The information is provided for guidance only and does not constitute legal advice. <\/em><\/p>\n\n<h4 class=\"wp-block-heading\"><strong>Sources and bibliography:<\/strong><\/h4>\n\n<p class=\"has-small-font-size wp-block-paragraph\">1. Cybersecurity Law of the People\u2019s Republic of China (amended 2026) \u2013 Standing Committee of the National People\u2019s Congress, October 2025<\/p>\n\n<p class=\"has-small-font-size wp-block-paragraph\">2. Personal Information Protection Law of the People\u2019s Republic of China \u2013 ONZPL, 20 August 2021<\/p>\n\n<p class=\"has-small-font-size wp-block-paragraph\">3. GB\/T 45574-2025 \u2013 National Standard of the People\u2019s Republic of China on the Identification of Sensitive Personal Information<\/p>\n\n<p class=\"has-small-font-size wp-block-paragraph\">4. Interim Measures for the Management of Generative Artificial Intelligence Services (AIGC Measures) \u2013 CAC and 6 agencies, 15 August 2023<\/p>\n\n<p class=\"has-small-font-size wp-block-paragraph\">5. Measures for the Administration of Artificial Intelligence Technology Ethics Review and Services (Pilot) \u2013 MOST, MIIT and 8 departments, 3 April 2026<\/p>\n\n<p class=\"has-small-font-size wp-block-paragraph\">6. Measures for the Certification of the Outbound Transfer of Personal Information \u2013 CAC, 1 January 2026<\/p>\n\n<p class=\"has-small-font-size wp-block-paragraph\">7. Measures for the Administration of Cybersecurity Incident Reporting \u2013 CAC, 1 November 2025<\/p>\n\n<p class=\"has-small-font-size wp-block-paragraph\">8. Network Data Security Management Regulation \u2013 Council of the State, 1 January 2025<\/p>\n\n<p class=\"has-small-font-size wp-block-paragraph\">9. Regulations on Facilitating and Regulating Cross-border Data Transfers \u2013 State Council, 22 March 2024<\/p>\n\n<p class=\"has-small-font-size wp-block-paragraph\">10. Views on Strengthening Ethical Governance in Science and Technology \u2013 The Council to the State<\/p>\n\n<p class=\"has-small-font-size wp-block-paragraph\">11. Measures for the Administration of Personal Information Protection Compliance Audits \u2013 CAC, 1 May 2025<\/p>\n\n<p class=\"has-small-font-size wp-block-paragraph\">12. Data Security Law of the People\u2019s Republic of China \u2013 ONZPL, 1 September 2021<\/p>\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In 2026, China is undergoing a true regulatory revolution in the digital sphere. From the amendment to the Cybersecurity Law (CSL) to the development of the Personal Information Protection Law (PIPL), and on to the first comprehensive AI ethics review system. The Chinese legal landscape is becoming increasingly complex and challenging for companies operating in [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":3892,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58,215],"tags":[],"class_list":["post-4151","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-law-technology-en","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/lome.legal\/en\/wp-json\/wp\/v2\/posts\/4151","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lome.legal\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lome.legal\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lome.legal\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/lome.legal\/en\/wp-json\/wp\/v2\/comments?post=4151"}],"version-history":[{"count":1,"href":"https:\/\/lome.legal\/en\/wp-json\/wp\/v2\/posts\/4151\/revisions"}],"predecessor-version":[{"id":4152,"href":"https:\/\/lome.legal\/en\/wp-json\/wp\/v2\/posts\/4151\/revisions\/4152"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lome.legal\/en\/wp-json\/wp\/v2\/media\/3892"}],"wp:attachment":[{"href":"https:\/\/lome.legal\/en\/wp-json\/wp\/v2\/media?parent=4151"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lome.legal\/en\/wp-json\/wp\/v2\/categories?post=4151"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lome.legal\/en\/wp-json\/wp\/v2\/tags?post=4151"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}