Cybersecurity Law of the People’s Republic of China (2025 Amendment)

Version and sources (verifiable)

ItemContent
Original lawadopted 7 November 2016, effective 1 June 2017
AmendmentDecision on Amending the Cybersecurity Law of the People’s Republic of China adopted 28 October 2025
Versionthis page contains the consolidated amended text, effective 1 January 2026
Structure7 chapters, 81 articles
Key amendmentsnew Article 3 (CPC leadership; holistic approach to national security); new Article 20 (artificial intelligence); new Article 63 (penalties for uncertified critical network equipment); penalty caps raised to RMB 10 million in the most serious cases; article numbering re-ordered throughout — always cite the version
Chinese originalCAC — amended text; amendment decision
English versionNo official English translation of the 2025 amendment has been published. This English text is a translation by our editorial team cross-checked article by article against the official Chinese text; it is not an official translation and is for reference only.
VerificationRetrieved 2026-09-22; 81 articles, no gaps; chapter and section structure verified against the official text

Chapter I General provisions

Article 1 This Law is enacted for the purposes of safeguarding cybersecurity, maintaining cyberspace sovereignty and national security and public interests, protecting the lawful rights and interests of citizens, legal persons and other organisations, and promoting the sound development of the information economy and society.

Article 2 This Law applies to the construction, operation, maintenance and use of networks within the territory of the People’s Republic of China, and to the supervision and administration of cybersecurity.

Article 3 Cybersecurity work upholds the leadership of the Communist Party of China, implements the holistic approach to national security, coordinates development and security, and advances the building of a strong cyber power.

Article 4 The State attaches equal importance to cybersecurity and the development of informatisation, follows the principles of active use, scientific development, administration in accordance with law and ensuring security, promotes the construction of cyber infrastructure and interconnection, encourages innovation in and application of cyber technology, supports the training of cybersecurity professionals, and establishes and improves a cybersecurity assurance system so as to enhance cybersecurity protection capacity.

Article 5 The State formulates and continuously improves the national cybersecurity strategy, defines the basic requirements and main objectives for safeguarding cybersecurity, and sets out cybersecurity policies, tasks and measures for key areas.

Article 6 The State takes measures to monitor, defend against and handle cybersecurity risks and threats originating within and outside the territory of the People’s Republic of China, protects critical information infrastructure against attacks, intrusions, interference and destruction, and punishes cybercrime and unlawful activities in accordance with law so as to maintain security and order in cyberspace.

Article 7 The State advocates honesty, credibility, healthy and civilised online conduct, promotes the dissemination of the core socialist values, and takes measures to raise the cybersecurity awareness and standards of society as a whole, so as to create a favourable environment in which all of society participates in promoting cybersecurity.

Article 8 The State actively carries out international exchanges and cooperation in cyberspace governance, research and development of cyber technology and formulation of standards, and combating cybercrime and unlawful activities, promotes the building of a peaceful, secure, open and cooperative cyberspace, and works to establish a multilateral, democratic and transparent system of cyberspace governance.

Article 9 The national cyberspace administration department is responsible for coordinating cybersecurity work and the related supervision and administration. The telecommunications department of the State Council, the public security department and other relevant authorities are responsible, within the scope of their respective duties, for cybersecurity protection and supervision and administration in accordance with this Law and the provisions of relevant laws and administrative regulations.
The cybersecurity protection and supervision and administration duties of the relevant departments of local people’s governments at or above the county level shall be determined in accordance with the relevant provisions of the State.

Article 10 In conducting business and service activities, network operators shall comply with laws and administrative regulations, respect public order and good morals, observe business ethics, act in good faith, perform their cybersecurity protection obligations, accept supervision by the government and society, and bear social responsibility.

Article 11 In constructing or operating networks or providing services through networks, technical measures and other necessary measures shall be taken in accordance with laws, administrative regulations and the mandatory requirements of national standards to safeguard cybersecurity and stable operation, effectively respond to cybersecurity incidents, prevent and combat cybercrime and unlawful activities, and maintain the integrity, confidentiality and availability of network data.

Article 12 Network-related industry organisations shall, in accordance with their articles of association, strengthen industry self-regulation, formulate norms of cybersecurity conduct, guide their members in strengthening cybersecurity protection, raise the level of cybersecurity protection and promote the sound development of the industry.

Article 13 The State protects the right of citizens, legal persons and other organisations to use networks in accordance with law, promotes the spread of network access, improves network service standards, provides society with secure and convenient network services, and safeguards the lawful, orderly and free flow of network information.
Any individual or organisation using a network shall comply with the Constitution and laws, observe public order, respect public morality, and must not endanger cybersecurity or use networks to engage in activities that endanger national security, honour and interests; incite subversion of State power or overthrow of the socialist system; incite secession or undermine national unity; propagate terrorism or extremism; propagate ethnic hatred or ethnic discrimination; disseminate violent or obscene and pornographic information; fabricate or disseminate false information disrupting economic and social order; or infringe the reputation, privacy, intellectual property rights or other lawful rights and interests of others.

Article 14 The State supports the research, development and provision of network products and services conducive to the healthy growth of minors, punishes in accordance with law the use of networks for activities harmful to the physical and mental health of minors, and provides minors with a secure and healthy network environment.

Article 15 Any individual or organisation has the right to report conduct endangering cybersecurity to the cyberspace administration, telecommunications and public security departments. Departments receiving such reports shall handle them promptly in accordance with law; where a report falls outside their duties, they shall promptly transfer it to the competent department.
The relevant departments shall keep confidential the information of the reporting person and protect the reporting person’s lawful rights and interests.

Chapter II Support for and promotion of cybersecurity

Article 16 The State establishes and improves the cybersecurity standards system. The administrative department for standardisation of the State Council and other relevant departments of the State Council shall, in accordance with their respective duties, organise the formulation and timely revision of national and industry standards relating to cybersecurity administration and the security of network products, services and operation.
The State supports enterprises, research institutions, institutions of higher education and network-related industry organisations in participating in the formulation of national and industry cybersecurity standards.

Article 17 The State Council and the people’s governments of provinces, autonomous regions and municipalities directly under the Central Government shall, through overall planning, increase investment, support key cybersecurity technology industries and projects, support the research, development and application of cybersecurity technology, promote secure and trustworthy network products and services, protect intellectual property rights in network technology, and support enterprises, research institutions and institutions of higher education in participating in national cybersecurity technology innovation projects.

Article 18 The State promotes the building of a socialised cybersecurity service system and encourages relevant enterprises and institutions to carry out security services such as cybersecurity certification, testing and risk assessment.

Article 19 The State encourages the development of technologies for the protection and exploitation of network data security, promotes the opening of public data resources, and drives technological innovation and economic and social development.

Article 20 The State supports basic theoretical research on artificial intelligence and the research and development of key technologies such as algorithms, advances the construction of infrastructure including training data resources and computing power, improves ethical norms for artificial intelligence, strengthens risk monitoring, assessment and security regulation, and promotes the application and healthy development of artificial intelligence.
The State supports innovation in cybersecurity management methods and the use of new technologies such as artificial intelligence to raise the level of cybersecurity protection.

Article 21 People’s governments at all levels and their relevant departments shall organise and carry out regular cybersecurity publicity and education, and guide and urge relevant entities to perform cybersecurity publicity and education work well.
The mass media shall carry out targeted cybersecurity publicity and education for the public.

Article 22 The State supports enterprises and institutions of higher education, vocational schools and other education and training institutions in carrying out cybersecurity-related education and training, cultivates cybersecurity professionals in various ways, and promotes the exchange of cybersecurity professionals.

Chapter III Network operation security

Section 1 General provisions

Article 23 The State applies a system of classified protection for cybersecurity. Network operators shall, in accordance with the requirements of the classified protection system for cybersecurity, perform the following security protection obligations to protect networks against interference, destruction or unauthorised access and to prevent network data from being leaked, stolen or tampered with:
(1) formulate internal security management systems and operating procedures, designate a person responsible for cybersecurity, and implement cybersecurity protection responsibilities;
(2) adopt technical measures to prevent computer viruses, cyber attacks, network intrusions and other conduct endangering cybersecurity;
(3) adopt technical measures to monitor and record network operation status and cybersecurity incidents, and retain the relevant network logs for not less than six months as required;
(4) adopt measures such as data classification, backup of important data and encryption;
(5) other obligations provided for by laws and administrative regulations.

Article 24 Network products and services shall comply with the mandatory requirements of relevant national standards. Providers of network products and services must not install malicious programs; where they discover risks such as security defects or vulnerabilities in their network products or services, they shall immediately take remedial measures, promptly inform users and report to the competent departments as required.
Providers of network products and services shall continuously provide security maintenance for their products and services; within the period prescribed or agreed by the parties, they must not terminate the provision of security maintenance.
Where network products or services have the function of collecting user information, their providers shall expressly inform users and obtain their consent; where personal information of users is involved, the provisions of this Law and relevant laws and administrative regulations on the protection of personal information shall also be complied with.

Article 25 Critical network equipment and specialised cybersecurity products shall be sold or provided only after passing security certification by a qualified institution or meeting the requirements of security testing in accordance with the mandatory requirements of relevant national standards. The national cyberspace administration department, together with the relevant departments of the State Council, formulates and publishes the catalogue of critical network equipment and specialised cybersecurity products, and promotes mutual recognition of security certification and security testing results so as to avoid duplicated certification and testing.

Article 26 Where a network operator handles network access or domain name registration services for a user, handles network access formalities such as fixed-line and mobile telephony, or provides a user with services such as information publication or instant messaging, it shall require the user to provide true identity information when concluding an agreement with the user or confirming the provision of services. Where a user does not provide true identity information, the network operator must not provide the relevant services to that user.
The State implements a trusted identity strategy for networks, supports the research, development and provision of secure and convenient electronic identity authentication technologies, and promotes mutual recognition among different electronic identity authentication systems.

Article 27 Network operators shall formulate emergency response plans for cybersecurity incidents and promptly handle security risks such as system vulnerabilities, computer viruses, cyber attacks and network intrusions; when an incident endangering cybersecurity occurs, they shall immediately activate the emergency response plan, take corresponding remedial measures and report to the competent departments as required.

Article 28 Conducting activities such as cybersecurity certification, testing and risk assessment, and releasing to the public cybersecurity information such as system vulnerabilities, computer viruses, cyber attacks and network intrusions, shall comply with the relevant provisions of the State.

Article 29 No individual or organisation may engage in activities endangering cybersecurity such as unlawfully intruding into another’s network, interfering with the normal functions of another’s network, or stealing network data; nor provide programs or tools specifically used for such activities as intruding into networks, interfering with the normal functions of networks and protective measures, or stealing network data; where a person knows that another is engaged in activities endangering cybersecurity, the person must not provide technical support, advertising promotion, payment and settlement or other assistance to that other person.

Article 30 Network operators shall provide technical support and assistance to public security organs and State security organs in their activities to safeguard national security and investigate crimes in accordance with law.

Article 31 The State supports cooperation among network operators in the collection, analysis, notification and emergency handling of cybersecurity information so as to enhance network operators’ security assurance capability.
Relevant industry organisations shall establish and improve cybersecurity protection norms and cooperation mechanisms for their industries, strengthen analysis and assessment of cybersecurity risks, periodically issue risk warnings to their members, and support and assist their members in responding to cybersecurity risks.

Article 32 Information obtained by the cyberspace administration departments and relevant departments in the performance of cybersecurity protection duties may only be used for the needs of maintaining cybersecurity and must not be used for other purposes.

Section 2 Security of the operation of critical information infrastructure

Article 33 On the basis of the classified protection system for cybersecurity, the State applies key protection to critical information infrastructure in important industries and fields such as public communications and information services, energy, transport, water conservancy, finance, public services and e-government, and other critical information infrastructure which, once destroyed, losing its function or suffering data leakage, may seriously endanger national security, the national economy and people’s livelihood, or the public interest. The specific scope of critical information infrastructure and the measures for its security protection shall be formulated by the State Council.
The State encourages network operators other than those of critical information infrastructure to participate voluntarily in the critical information infrastructure protection system.

Article 34 In accordance with the division of duties prescribed by the State Council, the departments responsible for the security protection of critical information infrastructure shall respectively prepare and organise the implementation of security plans for critical information infrastructure in their respective industries and fields, and guide and supervise the security protection of the operation of critical information infrastructure.

Article 35 The construction of critical information infrastructure shall ensure that it has the performance to support stable and continuous business operation, and shall ensure that security technical measures are planned, built and put into use simultaneously.

Article 36 In addition to the provisions of Article 23 of this Law, operators of critical information infrastructure shall also perform the following security protection obligations:
(1) establish a dedicated security management body and a security management officer, and conduct security background checks on that officer and personnel in key positions;
(2) periodically conduct cybersecurity education, technical training and skills assessment for employees;
(3) carry out disaster recovery backup for important systems and databases;
(4) formulate emergency response plans for cybersecurity incidents and conduct regular drills;
(5) other obligations provided for by laws and administrative regulations.

Article 37 Where the procurement of network products and services by an operator of critical information infrastructure may affect national security, it shall undergo a national security review organised by the national cyberspace administration department together with the relevant departments of the State Council.

Article 38 Operators of critical information infrastructure shall, as required, conclude security and confidentiality agreements with providers when procuring network products and services, clarifying security and confidentiality obligations and responsibilities.

Article 39 Personal information and important data collected and generated by operators of critical information infrastructure in the course of their operations within the territory of the People’s Republic of China shall be stored within the territory. Where it is truly necessary to provide them abroad for business needs, a security assessment shall be conducted in accordance with the measures formulated by the national cyberspace administration department together with the relevant departments of the State Council; where laws and administrative regulations provide otherwise, those provisions shall prevail.

Article 40 Operators of critical information infrastructure shall, by themselves or by engaging a cybersecurity service institution, conduct at least one testing and assessment each year of the security of their networks and of possible risks, and submit the testing and assessment results and improvement measures to the department responsible for the security protection of critical information infrastructure.

Article 41 The national cyberspace administration department shall coordinate the relevant departments in taking the following measures for the security protection of critical information infrastructure:
(1) conduct spot checks and testing of the security risks of critical information infrastructure, propose improvement measures, and, where necessary, engage cybersecurity service institutions to test and assess security risks existing in the networks;
(2) periodically organise operators of critical information infrastructure to conduct cybersecurity emergency drills to improve their capacity to respond to cybersecurity incidents and their coordination capabilities;
(3) promote the sharing of cybersecurity information among relevant departments, operators of critical information infrastructure, relevant research institutions and cybersecurity service institutions;
(4) provide technical support and assistance for the emergency handling of cybersecurity incidents and the restoration of network functions.

Chapter IV Network information security

Article 42 Network operators shall keep strictly confidential the user information they collect and shall establish and improve user information protection systems.
In processing personal information, network operators shall comply with the provisions of this Law, the Civil Code of the People’s Republic of China, the Personal Information Protection Law of the People’s Republic of China and other laws and administrative regulations.

Article 43 Network operators shall, in collecting and using personal information, follow the principles of lawfulness, legitimacy and necessity, publicly disclose their rules for collection and use, expressly state the purpose, method and scope of collecting and using the information, and obtain the consent of the person whose information is collected.
Network operators must not collect personal information unrelated to the services they provide, must not collect or use personal information in violation of laws and administrative regulations or contrary to the agreement between the parties, and shall handle the personal information they retain in accordance with laws and administrative regulations and their agreement with users.

Article 44 Network operators must not divulge, tamper with or destroy the personal information they collect; they must not provide personal information to others without the consent of the person whose information is collected, except where the information cannot identify a specific person and cannot be restored after processing.
Network operators shall adopt technical measures and other necessary measures to ensure the security of the personal information they collect and to prevent leakage, destruction or loss of information. Where personal information is or may be leaked, destroyed or lost, they shall immediately take remedial measures, promptly inform users as required and report to the competent departments.

Article 45 Where an individual discovers that a network operator collects or uses his or her personal information in violation of laws and administrative regulations or of the agreement between the parties, the individual has the right to require the network operator to delete the personal information; where the personal information collected or stored by the network operator is erroneous, the individual has the right to require the network operator to correct it. Network operators shall take measures to delete or correct it.

Article 46 No individual or organisation may steal or obtain personal information by other unlawful means, or unlawfully sell or unlawfully provide personal information to others.

Article 47 Departments with cybersecurity supervision and administration duties in accordance with law and their staff must keep strictly confidential the personal information, privacy and trade secrets learned in the performance of their duties, and must not divulge, sell or unlawfully provide them to others.

Article 48 Every individual and organisation shall be responsible for its conduct in using networks, and must not set up websites or communication groups for committing fraud, teaching criminal methods, or producing or selling prohibited or controlled items or other illegal or criminal activities, and must not use networks to publish information involving the commission of fraud, the production or sale of prohibited or controlled items, or other illegal or criminal activities.

Article 49 Network operators shall strengthen the administration of information published by their users, and where they discover information whose publication or transmission is prohibited by laws and administrative regulations, they shall immediately stop transmitting that information, take measures such as elimination, prevent the spread of the information, preserve the relevant records and report to the competent departments.

Article 50 Electronic information sent and application software provided by any individual or organisation must not contain malicious programs or information whose publication or transmission is prohibited by laws and administrative regulations.
Providers of electronic information sending services and providers of application software download services shall perform their security management obligations, and where they know that their users have committed the acts specified in the preceding paragraph, they shall stop providing services, take measures such as elimination, preserve the relevant records and report to the competent departments.

Article 51 Network operators shall establish complaint and reporting systems for network information security, publish information on how to make complaints and reports, and promptly accept and handle complaints and reports concerning network information security.
Network operators shall cooperate with the supervision and inspection carried out by cyberspace administration departments and relevant departments in accordance with law.

Article 52 Where the national cyberspace administration department and relevant departments, in performing their network information security supervision and administration duties in accordance with law, discover information whose publication or transmission is prohibited by laws and administrative regulations, they shall require network operators to stop transmitting it, take measures such as elimination and preserve relevant records; for such information originating outside the territory of the People’s Republic of China, they shall notify the relevant institutions to take technical measures and other necessary measures to block its dissemination.

Chapter V Monitoring, early warning and emergency handling

Article 53 The State establishes systems for cybersecurity monitoring, early warning and information notification. The national cyberspace administration department shall coordinate the relevant departments in strengthening the collection, analysis and notification of cybersecurity information and shall uniformly release cybersecurity monitoring and early warning information as required.

Article 54 Departments responsible for the security protection of critical information infrastructure shall establish and improve cybersecurity monitoring, early warning and information notification systems for their respective industries and fields, and submit cybersecurity monitoring and early warning information as required.

Article 55 The national cyberspace administration department shall coordinate the relevant departments in establishing and improving cybersecurity risk assessment and emergency response mechanisms, formulating emergency response plans for cybersecurity incidents, and organising regular drills.
Departments responsible for the security protection of critical information infrastructure shall formulate emergency response plans for cybersecurity incidents in their respective industries and fields and organise regular drills.
Emergency response plans for cybersecurity incidents shall classify cybersecurity incidents according to factors such as the degree of harm and scope of impact after occurrence and shall provide for corresponding emergency handling measures.

Article 56 Where the risk of a cybersecurity incident increases, the relevant departments of people’s governments at or above the provincial level shall, in accordance with the prescribed powers and procedures, and in light of the characteristics of the cybersecurity risk and the harm it may cause, take the following measures:
(1) require the relevant departments, institutions and personnel to promptly collect and report information and strengthen monitoring of cybersecurity risks;
(2) organise relevant departments, institutions and professionals to analyse and assess cybersecurity risk information and predict the likelihood, scope of impact and degree of harm of an incident;
(3) release cybersecurity risk warnings to the public and publish measures to avoid and mitigate harm.

Article 57 Where a cybersecurity incident occurs, the emergency response plan for cybersecurity incidents shall be immediately activated, the incident shall be investigated and assessed, network operators shall be required to take technical measures and other necessary measures to eliminate hidden security dangers and prevent the expansion of harm, and warning information relevant to the public shall be released to the public in a timely manner.

Article 58 Where the relevant departments of people’s governments at or above the provincial level, in performing their cybersecurity supervision and administration duties, discover that a relatively serious security risk exists in a network or that a security incident has occurred, they may, in accordance with the prescribed powers and procedures, conduct a regulatory interview with the legal representative or principal person in charge of the network operator. The network operator shall take measures as required, carry out rectification and eliminate the hidden danger.

Article 59 Where a cybersecurity incident gives rise to an emergency or a work safety accident, it shall be handled in accordance with the provisions of the Emergency Response Law of the People’s Republic of China, the Work Safety Law of the People’s Republic of China and other relevant laws and administrative regulations.

Article 60 Where necessary for safeguarding national security and public order or handling a major sudden social security incident, temporary measures such as restricting network communications in specified areas may be taken upon decision or approval by the State Council.

Article 61 Where a network operator fails to perform the cybersecurity protection obligations provided for in Articles 23 and 27 of this Law, the competent departments shall order it to correct, give it a warning and may impose a fine of not less than RMB 10,000 and not more than RMB 50,000; where it refuses to correct or causes consequences such as endangering cybersecurity, a fine of not less than RMB 50,000 and not more than RMB 500,000 shall be imposed, and a fine of not less than RMB 10,000 and not more than RMB 100,000 shall be imposed on the directly responsible persons in charge and other directly responsible persons.
Where an operator of critical information infrastructure fails to perform the cybersecurity protection obligations provided for in Articles 35, 36, 38 and 40 of this Law, the competent departments shall order it to correct, give it a warning and may impose a fine of not less than RMB 50,000 and not more than RMB 100,000; where it refuses to correct or causes consequences such as endangering cybersecurity, a fine of not less than RMB 100,000 and not more than RMB 1,000,000 shall be imposed, and a fine of not less than RMB 10,000 and not more than RMB 100,000 shall be imposed on the directly responsible persons in charge and other directly responsible persons.
Where the acts in the preceding two paragraphs cause serious consequences endangering cybersecurity, such as the leakage of a large volume of data or the loss of partial functions of critical information infrastructure, the competent departments shall impose a fine of not less than RMB 500,000 and not more than RMB 2,000,000, and a fine of not less than RMB 50,000 and not more than RMB 200,000 on the directly responsible persons in charge and other directly responsible persons; where the acts cause especially serious consequences endangering cybersecurity, such as the loss of the main functions of critical information infrastructure, a fine of not less than RMB 2,000,000 and not more than RMB 10,000,000 shall be imposed, and a fine of not less than RMB 200,000 and not more than RMB 1,000,000 shall be imposed on the directly responsible persons in charge and other directly responsible persons.

Article 62 Where the provisions of the first and second paragraphs of Article 24 and the first paragraph of Article 50 of this Law are violated and any of the following acts is committed, the competent departments shall order correction and give a warning; where the offender refuses to correct or causes consequences such as endangering cybersecurity, a fine of not less than RMB 50,000 and not more than RMB 500,000 shall be imposed, and a fine of not less than RMB 10,000 and not more than RMB 100,000 shall be imposed on the directly responsible person in charge:
(1) installing malicious programs;
(2) failing to immediately take remedial measures for risks such as security defects or vulnerabilities in its products or services, or failing to promptly inform users and report to the competent departments as required;
(3) terminating without authorisation the provision of security maintenance for its products or services.
Where the acts in items (1) and (2) of the preceding paragraph cause the consequences specified in the third paragraph of Article 61 of this Law, the penalty shall be imposed in accordance with that paragraph.

Article 63 Where the provisions of Article 25 of this Law are violated by selling or providing critical network equipment or specialised cybersecurity products that have not passed security certification or security testing, or that fail to pass security certification or do not meet the requirements of security testing, the competent departments shall order the cessation of the sale or provision, give a warning and confiscate the unlawful gains; where there are no unlawful gains or the unlawful gains are less than RMB 100,000, a concurrent fine of not less than RMB 20,000 and not more than RMB 100,000 shall be imposed; where the unlawful gains are RMB 100,000 or more, a concurrent fine of not less than one time and not more than five times the unlawful gains shall be imposed; where the circumstances are serious, the competent departments may concurrently order the suspension of the relevant business, suspension of business for rectification, revocation of the relevant business licence or revocation of the business licence. Where laws and administrative regulations provide otherwise, those provisions shall prevail.

Article 64 Where a network operator violates the first paragraph of Article 26 of this Law by failing to require a user to provide true identity information, or by providing the relevant services to a user who does not provide true identity information, the competent departments shall order correction; where the operator refuses to correct or the circumstances are serious, a fine of not less than RMB 50,000 and not more than RMB 500,000 shall be imposed, and the competent departments may concurrently order the suspension of the relevant business, suspension of business for rectification, closure of the website or application, revocation of the relevant business licence or revocation of the business licence, and shall impose a fine of not less than RMB 10,000 and not more than RMB 100,000 on the directly responsible persons in charge and other directly responsible persons.

Article 65 Where the provisions of Article 28 of this Law are violated by conducting activities such as cybersecurity certification, testing or risk assessment, or by releasing to the public cybersecurity information such as system vulnerabilities, computer viruses, cyber attacks or network intrusions, the competent departments shall order correction, give a warning and may impose a fine of not less than RMB 10,000 and not more than RMB 100,000; where the offender refuses to correct or the circumstances are serious, a fine of not less than RMB 100,000 and not more than RMB 1,000,000 shall be imposed, and the competent departments may concurrently order the suspension of the relevant business, suspension of business for rectification, closure of the website or application, revocation of the relevant business licence or revocation of the business licence, and shall impose a fine of not less than RMB 10,000 and not more than RMB 100,000 on the directly responsible persons in charge and other directly responsible persons.
Where the acts in the preceding paragraph cause the consequences specified in the third paragraph of Article 61 of this Law, the penalty shall be imposed in accordance with that paragraph.

Article 66 Where the provisions of Article 29 of this Law are violated by engaging in activities endangering cybersecurity, or providing programs or tools specifically used for such activities, or providing technical support, advertising promotion, payment and settlement or other assistance to another person’s activities endangering cybersecurity, and the act does not yet constitute a crime, the public security organ shall confiscate the unlawful gains and impose detention of not more than five days, and may concurrently impose a fine of not less than RMB 50,000 and not more than RMB 500,000; where the circumstances are relatively serious, detention of not less than five days and not more than fifteen days shall be imposed, and a fine of not less than RMB 100,000 and not more than RMB 1,000,000 may concurrently be imposed.
Where a unit commits the act in the preceding paragraph, the public security organ shall confiscate its unlawful gains, impose a fine of not less than RMB 100,000 and not more than RMB 1,000,000, and punish the directly responsible persons in charge and other directly responsible persons in accordance with the provisions of the preceding paragraph.
A person who violates Article 29 of this Law and receives a public security administration penalty must not engage in cybersecurity management or key positions in network operations for five years; a person who receives a criminal penalty must not engage in cybersecurity management or key positions in network operations for life.

Article 67 Where an operator of critical information infrastructure violates Article 37 of this Law by using network products or services that have not undergone security review or have failed security review, the competent departments shall order correction within a time limit, order the cessation of use and the elimination of the impact on national security, impose a fine of not less than one time and not more than ten times the procurement amount, and impose a fine of not less than RMB 10,000 and not more than RMB 100,000 on the directly responsible persons in charge and other directly responsible persons.

Article 68 Where the provisions of Article 48 of this Law are violated by setting up websites or communication groups for committing illegal or criminal activities, or by using networks to publish information involving the commission of illegal or criminal activities, and the act does not yet constitute a crime, the public security organ shall impose detention of not more than five days, and may concurrently impose a fine of not less than RMB 10,000 and not more than RMB 100,000; where the circumstances are relatively serious, detention of not less than five days and not more than fifteen days shall be imposed, and a fine of not less than RMB 50,000 and not more than RMB 500,000 may concurrently be imposed. The websites or communication groups used for committing the illegal or criminal activities shall be closed.
Where a unit commits the act in the preceding paragraph, the public security organ shall impose a fine of not less than RMB 100,000 and not more than RMB 500,000 and shall punish the directly responsible persons in charge and other directly responsible persons in accordance with the provisions of the preceding paragraph.

Article 69 Where a network operator violates Article 49 of this Law by failing to stop transmitting information whose publication or transmission is prohibited by laws and administrative regulations, failing to take measures such as elimination, failing to preserve the relevant records or failing to report to the competent departments, or violates Article 52 of this Law by failing to stop transmitting such information, take measures such as elimination and preserve the relevant records at the request of the relevant departments, the competent departments shall order correction, give a warning and circulate a notice of criticism, and may impose a fine of not less than RMB 50,000 and not more than RMB 500,000; where the offender refuses to correct or the circumstances are serious, a fine of not less than RMB 500,000 and not more than RMB 2,000,000 shall be imposed, and the competent departments may concurrently order the suspension of the relevant business, suspension of business for rectification, closure of the website or application, revocation of the relevant business licence or revocation of the business licence, and shall impose a fine of not less than RMB 50,000 and not more than RMB 200,000 on the directly responsible persons in charge and other directly responsible persons.
Where the acts in the preceding paragraph cause an especially serious impact or especially serious consequences, the competent departments shall impose a fine of not less than RMB 2,000,000 and not more than RMB 10,000,000, order the suspension of the relevant business, suspension of business for rectification, closure of the website or application, revocation of the relevant business licence or revocation of the business licence, and impose a fine of not less than RMB 200,000 and not more than RMB 1,000,000 on the directly responsible persons in charge and other directly responsible persons.
Where a provider of electronic information sending services or a provider of application software download services fails to perform the security management obligations provided for in the second paragraph of Article 50 of this Law, it shall be punished in accordance with the preceding two paragraphs.

Article 70 Where a network operator violates the provisions of this Law and commits any of the following acts, the competent departments shall order correction; where the operator refuses to correct or the circumstances are serious, a fine of not less than RMB 50,000 and not more than RMB 500,000 shall be imposed, and a fine of not less than RMB 10,000 and not more than RMB 100,000 shall be imposed on the directly responsible persons in charge and other directly responsible persons:
(1) refusing or obstructing supervision and inspection carried out by the relevant departments in accordance with law;
(2) refusing to provide technical support and assistance to public security organs and State security organs.

Article 71 Any of the following acts shall be handled and punished in accordance with the provisions of relevant laws and administrative regulations:
(1) publishing or transmitting information whose publication or transmission is prohibited by the second paragraph of Article 13 of this Law or by other laws and administrative regulations;
(2) infringing upon the rights and interests of personal information in violation of the third paragraph of Article 24 and Articles 43 to 45 of this Law;
(3) in violation of Article 39 of this Law, storing personal information and important data outside the territory or providing personal information and important data abroad by an operator of critical information infrastructure.
A person who violates Article 46 of this Law by stealing or otherwise unlawfully obtaining, unlawfully selling or unlawfully providing personal information to others, where the act does not yet constitute a crime, shall be punished by the public security organ in accordance with the provisions of relevant laws and administrative regulations.

Article 72 Where an unlawful act is provided for in this Law, it shall be recorded in credit files and made public in accordance with the provisions of relevant laws and administrative regulations.

Article 73 Where this Law is violated but circumstances provided for in the Administrative Penalty Law of the People’s Republic of China for a mitigated, reduced or no penalty exist, a mitigated or reduced penalty shall be imposed or no penalty shall be imposed in accordance with those provisions.

Article 74 Where an operator of a government network of a State organ fails to perform the cybersecurity protection obligations provided for in this Law, its superior authority or the relevant authority shall order it to correct; the directly responsible persons in charge and other directly responsible persons shall be given sanctions in accordance with law.

Article 75 Where the cyberspace administration departments and relevant departments violate Article 32 of this Law by using information obtained in the performance of cybersecurity protection duties for other purposes, the directly responsible persons in charge and other directly responsible persons shall be given sanctions in accordance with law.
Where staff of the cyberspace administration departments and relevant departments derelict their duties, abuse their powers or engage in malpractices for personal gain, and the act does not yet constitute a crime, they shall be given sanctions in accordance with law.

Article 76 Where a violation of this Law causes damage to another person, civil liability shall be borne in accordance with law.
Where a violation of this Law constitutes an act violating public security administration, a public security administration penalty shall be imposed in accordance with law; where a crime is constituted, criminal liability shall be pursued in accordance with law.

Article 77 Where an institution, organisation or individual outside the territory engages in activities endangering the cybersecurity of the People’s Republic of China, legal liability shall be pursued in accordance with law; where serious consequences are caused, the public security department of the State Council and the relevant departments may decide to take measures such as freezing property or other necessary sanctions against that institution, organisation or individual.

Chapter VII Supplementary provisions

Article 78 For the purposes of this Law, the following terms have the meanings set out below:
(1) “network” means a system composed of computers or other information terminals and related equipment that collects, stores, transmits, exchanges and processes information in accordance with certain rules and procedures;
(2) “cybersecurity” means, through the adoption of necessary measures, preventing attacks, intrusions, interference, destruction and unlawful use of, and accidents affecting, networks, keeping networks in a stable and reliable state of operation, and the capacity to safeguard the integrity, confidentiality and availability of network data;
(3) “network operator” means the owner or administrator of a network and the provider of network services;
(4) “network data” means various electronic data collected, stored, transmitted, processed and generated through networks;
(5) “personal information” means various information recorded electronically or otherwise that can, alone or in combination with other information, identify a natural person’s personal identity, including but not limited to a natural person’s name, date of birth, identity document number, personal biometric information, address and telephone number.

Article 79 In addition to complying with this Law, the security protection of the operation of networks that store or process information involving State secrets shall also comply with the provisions of laws and administrative regulations on the protection of secrets.

Article 80 The security protection of military networks shall be separately prescribed by the Central Military Commission.

Article 81 This Law shall come into force on 1 June 2017.