Hero background
NEWSLETTERS|Calendar icon30 Jul 2026 9 mins read

Data Newsletter | July 30, 2026

Lusheng Editor
Lusheng Editor

Takeaways

  • The Measures for Security Assessment of Network Data Risks will take effect on August 20. Important data processors will be required to conduct a risk assessment annually and submit the report to the competent authority within 20 days. Regulatory authorities at or above the provincial level may inspect and verify the assessment reports.
  • The Guidelines for Data Classification and Grading in Financial Information Services and the Guidelines for Data Classification and Grading in Energy Industry (2026 Edition) have been issued in succession. Relevant enterprises should promptly classify and grade their data in accordance with the guidelines and compile and submit catalogs of important data. If identified as important data processors, enterprises should fulfill the enhanced compliance obligations applicable, including conducting annual security risk assessments.
  • Following Shanghai’s disclosure of two cross-border hotel booking data transfer enforcement cases in January this year, Trip.com was fined RMB 10 million for failing to comply with cross-border data transfer security assessment requirements and unlawfully transferring personal information overseas. This is the first cross-border data transfer case in which the amount of the fine has been publicly disclosed. Hotel management companies and other international travel companies should pay attention to data transfer compliance requirements before transferring data abroad to mitigate regulatory risks.

Regulatory Highlights

Cyberspace Administration of China and Two Other Authorities Release the Measures for Security Assessment of Network Data Risks

The network data security risk assessment refers to activities aimed at identifying, analyzing and evaluating risks related to network data and data processing activities. Under the Data Security Law and the Regulations on the Administration of Network Data Security, data processors are required to conduct periodic risk assessment. On June 18, CAC, The Ministry of Industry and Information Technology (MIIT) and Ministry of Public Security (MPS) jointly issued the Measures for Security Assessment of Network Data Risks, which clarify requirements regarding assessment frequency, implementation methods, third-party assessment institutions and regulatory inspections. The Measures will take effect on August 20, 2026. Key provisions include:

  • Assessment frequency differentiated by data type. Important data processors must conduct a risk assessment annually. Where there is a material change in the security status of important data that may adversely affect data security, a special risk assessment must be carried out promptly. Network data processors handling only general data are encouraged to conduct a risk assessment at least once every three years.
  • Data processors can conduct assessments themselves or by qualified entrusted third parties. Third-party institutions are prohibited from subcontracting assessment work to other organizations. Where an assessment institution identifies a significant data security risk, it must promptly notify the relevant data processor.
  • Important data processors must prepare and submit risk assessment reports. Relevant authorities at or above the provincial level may inspect and verify such reports.
  • Relevant authorities at or above the provincial level may require network data processors to engage a certified assessment institution to conduct a risk assessment. Where an important data processing activity may endanger national security or the public interest, regulators should order corrective actions. If the processor refuses to rectify the issue or fails to meet remediation requirements, authorities may order it to cease processing important data. Data processors that fail to conduct risk assessments as required may be subject to enforcement actions in accordance with the law.

Guidelines on Data Classification and Grading for Financial Information Services and Energy Industry Released; Enterprises Shall Conduct Data Classification and Grading and Submit Reports in Accordance with the Guidelines

On June 13, six authorities including CAC and the People’s Bank of China released the Guidelines on Data Classification and Grading for Financial Information Services. The appendix provides examples of classified and graded financial service data along with submission templates for important data. Important data falls into two main categories: (1) The first category includes commodity data, industrial data (agriculture, forestry, fishery, manufacturing, food, beverage and other sectors), and research report data. If its coverage, time span, and precision exceed publicly released information and reflect conditions at or above the provincial level, it is deemed important data. (2) User data reaching specified volume thresholds qualifies as important data: basic personal information of over 10 million individuals, transaction data of over 1 million individuals, biometric identification data of over 100,000 individuals; basic information of over 1 million institutional users, transaction data of over 100,000 institutional users, and institutional user transaction data whose leakage or tampering would directly endanger national security.
On June 30, the National Energy Administration released the Guidelines on Data Classification and Grading for the Energy Industry (2026 Version).  It divides non-confidential energy industry data into twelve primary categories by energy type, including coal, petroleum and natural gas. Articles 8 to 11 of the Guidelines set out criteria for identifying important data and core data. High-precision geographic coordinates data and real-time instruction data of specific energy facilities, as well as raw power consumption data from super-class critical power users, Class I and Class II defense and military critical users, and mass users with more than 10 million entries.

The Shanghai Cyberspace Administration Imposes RMB 10 Million Administrative Penalty on Trip.com

In June, the Shanghai Cyberspace Administration handled a batch of law enforcement cases targeting local enterprises for failing to fulfill primary network and data security responsibilities, lacking security protection mechanisms, having insufficient compliance capabilities for backend data processing, and carrying out lax compliance audits on cross-border data transfers. Among them, Trip.com was fined RMB 10 million (about USD 1.47 million) and ordered to rectify within a specified period for failing to complete mandatory security assessments for cross-border data flows and illegally transferring personal information overseas.

In January, the Shanghai Cyberspace Administration also highlighted two typical cross-border data violation cases involving hotel operators. One concerned a hotel management firm that, despite being determined by the CAC that its online reservation data lacked necessity of cross-border transfer, continued to illegally send domestic users’ personal information abroad and was fined alongside a rectification order. The other targeted a property management enterprise running an APP for hotel booking and check-in services. It transferred user data, such as accommodation logs and financial accounts (sensitive), overseas without completing any prior compliant procedures and received a warning. Domestic and overseas enterprises engaged in property management, hotel and travel booking services shall strengthen data security management and fulfill all compliance obligations prior to cross-border data transfer.

AI Regulation

CAC announced that an additional 120 generative AI services completed the national filing from May to June 2026. As of June 30, a total of 988 generative AI services had finished filing procedures, and 598 generative AI applications or functions that completed registration.

On June 12, the Report Center of CAC launched a dedicated reporting channel for AI application misconduct. It accepts reports concerning 14 types of issues, including failure to complete generative AI model filing and registration requirements, inadequate security mechanisms, content review and filtering capabilities on AI platforms.

MIIT, the National Data Administration and the National Financial Regulatory Administration issued separate documents to promote the development of the “AI + information and communications” sector, advance the construction of high-quality industrial datasets, and guide the secure development of AI in the banking and insurance sectors.

Data Supervision

On June 17, the Guangdong High People’s Court clarified the validity of dispute resolution clauses unilaterally modified by online platforms in typical judicial review cases of arbitration. The court ruled that if a platform fails to inform users of such revisions through sufficiently prominent notification methods including pop-up windows for separate confirmation, mandatory reading prompts or public consultations, the revisions shall not be binding for platform users.

On June 18, CAC and two other authorities jointly issued the First Batch of Product Catalogs Subject to Cybersecurity Labels and related implementation rules. Connected cameras purchased or used by individual consumers or organizations are subject to cybersecurity labeling management, and manufacturers may voluntarily apply for cybersecurity labels.

On June 11, SAMR, together with CAC and the National Railway Administration (NRA), held regulatory talks with seven third-party train ticket platforms including Trip.com regarding their irregular business practices such as illegal collection and use of users’ personal information. Back in April, CAC and NRA had already held another round of regulatory talks, warning them not to use automated programs to conduct large-scale, high-frequency ticket purchasing or otherwise interfere with the security verification processes and stable operation of the China Railway 12306 ticketing system.

Since June, routine supervision of mobile apps has continued steadily. On June 3, the National Cybersecurity and Information Security Notification Center disclosed 71 apps that illegally collected and utilized personal information. On June 4, the Shanghai Communications Administration notified 56 apps (SDKs) infringing users’ rights. On June 11, CAC reported personal information collection and usage violations existing in 30 apps. On June 22, the MPS’s Computer Information System Security Product Quality Supervision and Inspection Center disclosed 40 apps for illegal collection and use of personal information. On June 25, the Shanghai Cyberspace Administration reported personal information collection and usage flaws found in 8 locally managed apps and mini-programs.

The Cybersecurity Bureau of the MPS released warning cases, urging enterprises to prevent risks including data leakage and data resale by employees as well as phishing attacks carried out by the SilverFox Trojan, to prevent the illegal theft of corporate data.

Data System Development

On June 26, Shanghai’s first filing after the expansion of application scope of data export negative list was implemented in Jingan District. ITX Asia Pacific Enterprise Management Co., Ltd., the core operating entity of ZARA’s parent company in the Asia-Pacific market, is now able to transfer the member data overseas through a standard contract filing, instead of undergoing the security assessment, as would otherwise have been required.

On June 8, the National Data Administration released the Digital China Development Report (2025); On June 12, CAC released the China Personal Information Protection Report (2025).

Overseas

On June 11, South Korea’s Personal Information Protection Commission imposed a fine of KRW 624.7 billion (approximately USD 430 billion) on an e-commerce platform Coupang. The penalty stemmed primarily from a data breach reported in November 2025, which affected 33.22 million records of users and 4.33 million records of the third-party personal information. The fine represents the largest penalty ever imposed by a privacy regulator in South Korea’s history.

On June 15, the United Kingdom announced plans to follow Australia’s online child protection model, introduced in December 2025, by banning under-16s from major social media platforms and imposing strict controls on livestreaming and social features in online games for minors. Detailed rules have yet to be released. The first implementing measures are expected by year-end and will take effect in spring 2027.

One June 30, The European Council approved amendments to the EU Artificial Intelligence Act, prohibiting the generation of non-consensual intimate images or videos of individuals and child sexual abuse materials. AI systems which generate nude images of real people or edit clothes out in existing photos to reveal intimate parts are set to be banned as of December this year. At the same time, the amendments postpone the application of certain provisions governing high-risk AI systems, deferring the compliance requirements for independent high-risk AI systems until December 2027 and high-risk AI systems embedded in other products until August 2028.


SIGN UP TO OUR NEWSLETTER

Stay in the loop with
our latest listings

Subscribe Now