Identify the actor, breached duty, consequence, and severity before quoting a fine. China does not use one universal cybersecurity maximum.
The amended Cybersecurity Law has applied since 1 January 2026. It now tiers several network-security penalties up to RMB 10 million, while the Data Security Law has separate ranges for data-security duties, core data, important-data exports, and responsible individuals.
Start with the breached provision, not the largest number on the page. A , , network product provider, data processor, app organizer, and app distribution platform can face different orders, fines, business restrictions, license consequences, personal liability, or cross-referenced enforcement. The facts determine which provision applies, and several laws may apply to the same incident.
1
Section 1
Network and CII security duties under the amended Cybersecurity Law
The consolidated Cybersecurity Law reflects the 2025 amendment effective 1 January 2026. A is the owner or manager of a network or a network service provider. Failure to perform the general classified-protection and incident-response duties in Articles 23 and 27 can lead to an , a warning, and an optional RMB 10,000-50,000 fine. Refusal to correct or resulting cybersecurity harm raises the organizational fine to RMB 50,000-500,000, with RMB 10,000-100,000 for directly responsible managers and other .
A has additional duties, including security organization and staffing, disaster-recovery backup, exercises, security agreements, and at-least-annual assessment. A breach of the listed CII duties can draw an , warning, and optional RMB 50,000-100,000 fine. Refusal to correct or resulting cybersecurity harm raises the operator fine to RMB 100,000-1 million, with RMB 10,000-100,000 for responsible personnel.
Serious consequence tier: if either group of duty failures causes consequences such as a large data leak or partial loss of CII function, the organization may be fined RMB 500,000-2 million and responsible personnel RMB 50,000-200,000.
Especially serious consequence tier: if the failure causes consequences such as loss of a CII's main functions, the organization may be fined RMB 2-10 million and responsible personnel RMB 200,000-1 million.
Do not assume that every security incident reaches a higher tier. The authority must connect the conduct and consequence to the applicable statutory conditions.
A provider that sets a malicious program, fails to act immediately on a product or service vulnerability, fails to notify users or report as required, or stops security maintenance without authority can receive an order and warning. Refusal to correct or resulting cybersecurity harm can bring an RMB 50,000-500,000 fine and an RMB 10,000-100,000 fine for the directly responsible manager. Malicious-program and vulnerability failures that cause the serious or especially serious consequences described in Article 61 move into its higher tiers.
A CII operator that uses a network product or service without the required security review, or after it failed review, may be ordered to correct within a time limit, stop using it, and eliminate the national-security effect. The operator is also subject to a fine of one to ten times the procurement amount, while directly responsible managers and other face RMB 10,000-100,000.
Selling or providing a listed network critical device or specialized cybersecurity product without the required certification or testing can lead to a stop order, warning, confiscation of illegal gains, and a fine. If gains are absent or below RMB 100,000, the fine is RMB 20,000-100,000; if gains are at least RMB 100,000, the fine is one to five times those gains.
A serious certification or testing violation may also lead to suspension of relevant business, closure for rectification, or revocation of a relevant business license or business registration.
Cybersecurity Review Measures Article 20 does not create a separate fine table. It directs violations to the Cybersecurity Law and Data Security Law, so the underlying actor and conduct still control.
A data processor that fails to establish required security management and technical measures, monitor and remedy risks, respond to an incident, or conduct and report a required important-data assessment may receive an , a warning, and an optional RMB 50,000-500,000 fine. Directly responsible managers and other may be fined RMB 10,000-100,000. Refusal to correct or serious consequences such as a large data leak raise the organization fine to RMB 500,000-2 million and the responsible-person fine to RMB 50,000-200,000; business suspension, closure for rectification, or license revocation may also follow.
A violation of the national core-data management system that harms national sovereignty, security, or development interests carries an RMB 2-10 million fine and may also bring business suspension, closure for rectification, or license revocation. Criminal responsibility applies when the conduct constitutes a crime. is the narrower, more serious category for data tied to national security, the lifeline of the national economy, important people's livelihoods, or major public interests; it is not a synonym for all .
Important-data export: violating the applicable outbound-important-data rule can bring an order, warning, and optional RMB 100,000-1 million fine, plus an optional RMB 10,000-100,000 fine for responsible personnel.
Serious important-data export violation: the organization may be fined RMB 1-10 million and responsible personnel RMB 100,000-1 million; suspension, closure for rectification, or license revocation may also apply.
Unauthorized provision to a foreign judicial or law-enforcement body: the ordinary tier is a warning and optional RMB 100,000-1 million organizational fine, with an optional RMB 10,000-100,000 responsible-person fine. Serious consequences raise those ranges to RMB 1-5 million and RMB 50,000-500,000, with possible business or license consequences.
Civil liability, public-security penalties, criminal responsibility, and sanctions under other laws remain possible where their separate conditions are met.
The MIIT app filing notice requires an app organizer providing internet information services in China to complete filing before service begins. An access provider, distribution platform, or smart-terminal manufacturer must not provide access, distribution, or pre-installation for an unfiled app. The notice says provincial communications administrations should handle unfiled or unlawful apps under the relevant laws and regulations; it does not state one universal app-filing fine.
The CAC app provisions prescribe operational measures, and other laws may also apply. An app provider may warn a user, restrict functions, or close an account for violations under law and the service agreement. A distribution platform may warn an app, suspend service, or remove it, while retaining records and reporting to the authority. Check the applicable statute or regulation separately to determine whether it also authorizes an administrative fine.
For unlawful personal-information processing, PIPL Article 66 provides a separate route. The ordinary sequence is an , warning, confiscation of illegal gains, and an order to suspend or terminate service for an unlawfully processing app; refusal to correct can add an organizational fine of up to RMB 1 million and an RMB 10,000-100,000 fine for responsible personnel. For a serious violation, the provincial-level or higher authority may impose up to RMB 50 million or 5% of the preceding year's turnover, plus business or licence measures, and RMB 100,000-1 million for responsible personnel. The serious tier is not the default outcome for every app or privacy defect.
Record separately: the filing breach, any content or data-security breach, the actor responsible, the governing provision, the authority involved, and each corrective or punitive measure.
Do not describe delisting, service suspension, business closure, license revocation, confiscation, a correction order, a warning, and an administrative fine as interchangeable outcomes.
For personal-information conduct, check the Personal Information Protection Law and other applicable provisions. The amended Cybersecurity Law now cross-refers personal-information infringements to those laws instead of supplying a complete standalone penalty range.
Build the penalty analysis from evidence: identify the regulated actor, the duty and article, the act or omission, the date and law version, whether correction was ordered, whether the actor refused or repeated the conduct, and what consequence occurred. Keep organizational exposure separate from fines for managers and other .
A statutory maximum is not a predicted outcome. The Cybersecurity Law expressly preserves the Administrative Penalty Law rules on lighter, mitigated, or no punishment. Case-specific enforcement also depends on the competent authority, evidence, harm, remedial action, and any overlapping law. This page supports issue spotting, not an individualized penalty opinion.
Preserve the scope decision, system and data inventory, incident chronology, regulator communications, correction evidence, and the version of each source used.
Check whether confiscation, suspension, closure, license action, credit-record publication, civil liability, public-security measures, or criminal referral is available in addition to a fine.
Use qualified language until the competent provision, actor, severity tier, and facts are established.
Article 66 establishes the ordinary and serious personal-information penalty tiers, app service suspension or termination, confiscation, responsible-person fines, and possible business or licence measures.