New Regulations from the Chinese Communist Party Target Individuals, Raising Concerns Over Mobile Phone Data Privacy.

The image shows an Apple iPhone. (Getty Images)

[People News] On August 7, the Ministry of Public Security of the Chinese Communist Party announced the "Measures for the Supervision and Inspection of Cybersecurity by Public Security Organs," which are set to take effect on October 1. Compared to the 2018 regulations, the new Measures broaden the targets and scope of public security network supervision and inspection, now including data processors and personal information handlers. It explicitly states that "the subjects of inspection are individuals," who will be supervised and inspected by local public security authorities at their usual places of residence.

According to a report by Radio Free Asia, police will have the authority to conduct online information patrols, capability tests for information review, and vulnerability scans. Public security at the municipal level and above will also be able to perform remote testing, including vulnerability detection and penetration testing. During on-site inspections, police can review and copy information related to the matters under supervision and inspection.

Shen Liangqing, a former prosecutor from Anhui, commented in an interview with Radio Free Asia: "These practices are not only a routine method for the CCP to control public opinion through information censorship, but also a strategy to govern the country using authoritarian police state measures amid internal troubles, external pressures, economic downturns, and financial difficulties that threaten social stability. The ultimate goal is to maintain the Communist Party's national security. Over the years, the power of police agencies has been steadily increasing, and with the current tense situation, this power is likely to expand even further."

The scope of regulation now extends to individuals.

The previous regulations implemented in 2018 primarily focused on internet service providers and connected user units. The new Measures further include data processors and personal information handlers within the supervisory scope, directly incorporating "individuals" into the jurisdictional provisions for supervision and inspection.

This indicates that whether it's contacting overseas friends and family via mobile phones, circumventing firewalls to access foreign information, or freelancers managing client data in their daily activities, the online activities of ordinary individuals may increasingly come under the scrutiny of public security authorities.

Following the announcement of the new regulations, discussions erupted among netizens on overseas social media platforms. One user on the X platform encapsulated the personal impact of the new rules as 'one's own mouth, one's own wallet,' stating: 'Do not break the law with your mouth, and do not break the law with your wallet.' Another user linked the new regulations to the inspection of personal mobile phones and online activities, voicing concerns about public security's oversight encroaching further into personal lives.

Li Tianlin (pseudonym), a former lawyer in Shanghai, told Radio Free Asia: 'The new regulations not only bring data processors and personal information handlers under regulatory oversight but also explicitly state that 'the subjects of inspection are individuals,' to be enforced by the public security at their place of residence. Additionally, public security at the city level and above is authorized to conduct vulnerability assessments and penetration testing, with algorithm recommendations, content orientation, and internet ideological security also included in the scope of supervision and inspection. This goes beyond merely checking the safety of internet equipment; it further intrudes into personal data, platform content, and the dissemination of information.'

Li Tianlin remarked that ordinary internet users, freelancers, and even individuals deemed to be receiving 'sensitive information' could be subject to inspection. Previously, the extraction of data from mobile phones and electronic devices was primarily associated with criminal investigations, searches, and seizures; however, the new regulations now incorporate techniques such as vulnerability detection and penetration testing into routine network security oversight. In practice, if personal data is stored on mobile phones, computers, or other digital devices, questions will arise regarding how public security authorities will conduct 'review and copying', as well as how to define the boundary between private devices and law enforcement authority.

Public Security Inspections Expand to Content and Algorithms

The new regulations also encompass user registration information, internet logs, algorithm security, and information content within the inspection framework, with techniques like vulnerability detection and penetration testing officially included in the public security supervision and inspection system.

In inspections that involve multiple departments, 'content-oriented management' and 'cyber ideological security' have also been added to the oversight scope. The inspection will also assess whether the subjects under scrutiny provide the necessary technical support to public security for maintaining national security, counter-terrorism, and criminal investigations.

Mr. Zhou, a legal expert from Henan, shared in an interview with Radio Free Asia that the aim of the new regulations is to further limit citizens' freedom of speech, with key targets for inspection likely to include internet platforms, technology companies, data processors, and personal information handlers. Mr. Zhou noted that such measures are not a sudden development but rather part of the ongoing internet control by the Communist Party, stating, 'the entire space for speech is becoming increasingly constricted, the space is getting smaller and smaller, this is a significant trend.'

The new regulations have established an early intervention mechanism. When security risks in cyberspace are detected, even if they do not yet "constitute illegal crimes," the Public Security Bureau can send warning letters to the relevant parties. In cases of significant risk, they may also summon the responsible individuals for discussions. When data security and personal information protection are involved, those being summoned can include relevant organizations and individuals as well.

Mr. Zhang, a lawyer from Shandong, expressed his concerns during an interview with Radio Free Asia about the legal basis for the Ministry of Public Security to expand its inspection powers through departmental "measures."

He remarked, "This is illegal; the Ministry of Public Security does not have this authority. If it is merely a set of 'measures,' it must be implemented at the legal level. This situation violates the constitution and contradicts the laws they have enacted themselves; they are not considering what is legal or illegal."

Special inspections may be conducted during major security periods.

The new 'measures' also specify that during 'national major security protection tasks,' the Public Security Bureau can conduct special supervision and inspections of network operators, data processors, and personal information processors related to these security tasks.

The Communist Party has introduced restrictive regulations such as the 'Cybersecurity Law,' 'Data Security Law,' and 'Personal Information Protection Law,' which require online platforms to take on responsibilities for real-name registration, log retention, data protection, and cooperation with regulatory authorities. Recently, the Ministry of Public Security has changed the original 'Internet Security Supervision and Inspection' to 'Cyberspace Security Supervision and Inspection,' thereby expanding the scope of public security intervention in internet governance from technical security to include data and information content. △