CybersecurityChina

China Cybersecurity Law penalties and fines

Identify the actor, breached duty, consequence, and severity before quoting a fine. China does not use one universal cybersecurity maximum.

The amended Cybersecurity Law has applied since 1 January 2026. It now tiers several network-security penalties up to RMB 10 million, while the Data Security Law has separate ranges for data-security duties, core data, important-data exports, and responsible individuals.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 25, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 25, 2026
Overview

Start with the breached provision, not the largest number on the page. A , , network product provider, data processor, app organizer, and app distribution platform can face different orders, fines, business restrictions, license consequences, personal liability, or cross-referenced enforcement. The facts determine which provision applies, and several laws may apply to the same incident.

Section 1

Network and CII security duties under the amended Cybersecurity Law

The consolidated Cybersecurity Law reflects the 2025 amendment effective 1 January 2026. A is the owner or manager of a network or a network service provider. Failure to perform the general classified-protection and incident-response duties in Articles 23 and 27 can lead to an , a warning, and an optional RMB 10,000-50,000 fine. Refusal to correct or resulting cybersecurity harm raises the organizational fine to RMB 50,000-500,000, with RMB 10,000-100,000 for directly responsible managers and other .

A has additional duties, including security organization and staffing, disaster-recovery backup, exercises, security agreements, and at-least-annual assessment. A breach of the listed CII duties can draw an , warning, and optional RMB 50,000-100,000 fine. Refusal to correct or resulting cybersecurity harm raises the operator fine to RMB 100,000-1 million, with RMB 10,000-100,000 for responsible personnel.

  • Serious consequence tier: if either group of duty failures causes consequences such as a large data leak or partial loss of CII function, the organization may be fined RMB 500,000-2 million and responsible personnel RMB 50,000-200,000.
  • Especially serious consequence tier: if the failure causes consequences such as loss of a CII's main functions, the organization may be fined RMB 2-10 million and responsible personnel RMB 200,000-1 million.
  • Do not assume that every security incident reaches a higher tier. The authority must connect the conduct and consequence to the applicable statutory conditions.
Section 2

Product, service, and procurement violations

A provider that sets a malicious program, fails to act immediately on a product or service vulnerability, fails to notify users or report as required, or stops security maintenance without authority can receive an order and warning. Refusal to correct or resulting cybersecurity harm can bring an RMB 50,000-500,000 fine and an RMB 10,000-100,000 fine for the directly responsible manager. Malicious-program and vulnerability failures that cause the serious or especially serious consequences described in Article 61 move into its higher tiers.

A CII operator that uses a network product or service without the required security review, or after it failed review, may be ordered to correct within a time limit, stop using it, and eliminate the national-security effect. The operator is also subject to a fine of one to ten times the procurement amount, while directly responsible managers and other face RMB 10,000-100,000.

  • Selling or providing a listed network critical device or specialized cybersecurity product without the required certification or testing can lead to a stop order, warning, confiscation of illegal gains, and a fine. If gains are absent or below RMB 100,000, the fine is RMB 20,000-100,000; if gains are at least RMB 100,000, the fine is one to five times those gains.
  • A serious certification or testing violation may also lead to suspension of relevant business, closure for rectification, or revocation of a relevant business license or business registration.
  • Cybersecurity Review Measures Article 20 does not create a separate fine table. It directs violations to the Cybersecurity Law and Data Security Law, so the underlying actor and conduct still control.
Section 3

Data Security Law fines

A data processor that fails to establish required security management and technical measures, monitor and remedy risks, respond to an incident, or conduct and report a required important-data assessment may receive an , a warning, and an optional RMB 50,000-500,000 fine. Directly responsible managers and other may be fined RMB 10,000-100,000. Refusal to correct or serious consequences such as a large data leak raise the organization fine to RMB 500,000-2 million and the responsible-person fine to RMB 50,000-200,000; business suspension, closure for rectification, or license revocation may also follow.

A violation of the national core-data management system that harms national sovereignty, security, or development interests carries an RMB 2-10 million fine and may also bring business suspension, closure for rectification, or license revocation. Criminal responsibility applies when the conduct constitutes a crime. is the narrower, more serious category for data tied to national security, the lifeline of the national economy, important people's livelihoods, or major public interests; it is not a synonym for all .

  • Important-data export: violating the applicable outbound-important-data rule can bring an order, warning, and optional RMB 100,000-1 million fine, plus an optional RMB 10,000-100,000 fine for responsible personnel.
  • Serious important-data export violation: the organization may be fined RMB 1-10 million and responsible personnel RMB 100,000-1 million; suspension, closure for rectification, or license revocation may also apply.
  • Unauthorized provision to a foreign judicial or law-enforcement body: the ordinary tier is a warning and optional RMB 100,000-1 million organizational fine, with an optional RMB 10,000-100,000 responsible-person fine. Serious consequences raise those ranges to RMB 1-5 million and RMB 50,000-500,000, with possible business or license consequences.
  • Civil liability, public-security penalties, criminal responsibility, and sanctions under other laws remain possible where their separate conditions are met.
Section 4

App filing and platform enforcement

The MIIT app filing notice requires an app organizer providing internet information services in China to complete filing before service begins. An access provider, distribution platform, or smart-terminal manufacturer must not provide access, distribution, or pre-installation for an unfiled app. The notice says provincial communications administrations should handle unfiled or unlawful apps under the relevant laws and regulations; it does not state one universal app-filing fine.

The CAC app provisions prescribe operational measures, and other laws may also apply. An app provider may warn a user, restrict functions, or close an account for violations under law and the service agreement. A distribution platform may warn an app, suspend service, or remove it, while retaining records and reporting to the authority. Check the applicable statute or regulation separately to determine whether it also authorizes an administrative fine.

For unlawful personal-information processing, PIPL Article 66 provides a separate route. The ordinary sequence is an , warning, confiscation of illegal gains, and an order to suspend or terminate service for an unlawfully processing app; refusal to correct can add an organizational fine of up to RMB 1 million and an RMB 10,000-100,000 fine for responsible personnel. For a serious violation, the provincial-level or higher authority may impose up to RMB 50 million or 5% of the preceding year's turnover, plus business or licence measures, and RMB 100,000-1 million for responsible personnel. The serious tier is not the default outcome for every app or privacy defect.

  • Record separately: the filing breach, any content or data-security breach, the actor responsible, the governing provision, the authority involved, and each corrective or punitive measure.
  • Do not describe delisting, service suspension, business closure, license revocation, confiscation, a correction order, a warning, and an administrative fine as interchangeable outcomes.
  • For personal-information conduct, check the Personal Information Protection Law and other applicable provisions. The amended Cybersecurity Law now cross-refers personal-information infringements to those laws instead of supplying a complete standalone penalty range.
Section 5

How to assess a potential violation

Build the penalty analysis from evidence: identify the regulated actor, the duty and article, the act or omission, the date and law version, whether correction was ordered, whether the actor refused or repeated the conduct, and what consequence occurred. Keep organizational exposure separate from fines for managers and other .

A statutory maximum is not a predicted outcome. The Cybersecurity Law expressly preserves the Administrative Penalty Law rules on lighter, mitigated, or no punishment. Case-specific enforcement also depends on the competent authority, evidence, harm, remedial action, and any overlapping law. This page supports issue spotting, not an individualized penalty opinion.

  • Preserve the scope decision, system and data inventory, incident chronology, regulator communications, correction evidence, and the version of each source used.
  • Check whether confiscation, suspension, closure, license action, credit-record publication, civil liability, public-security measures, or criminal referral is available in addition to a fine.
  • Use qualified language until the competent provision, actor, severity tier, and facts are established.
Primary sources

References and citations

cac.gov.cn
Referenced sections
  • Article 20 sends violations of the Measures to the Cybersecurity Law and Data Security Law rather than stating a standalone fine range.
miit.gov.cn
Referenced sections
  • Establishes pre-service filing, actor verification duties, restrictions on serving unfiled apps, and enforcement under relevant laws and regulations.
cac.gov.cn
Referenced sections
  • Articles 61-77 distinguish correction, warning, confiscation, fines, business and license measures, credit-record publication, mitigation under the Administrative Penalty Law, civil liability, public-security penalties, criminal responsibility, and sanctions.
cac.gov.cn
Referenced sections
  • Articles 45-52 distinguish data-security violations, severity conditions, organizational and individual fines, business restrictions, civil liability, and criminal responsibility.
cac.gov.cn
Referenced sections
  • Article 66 establishes the ordinary and serious personal-information penalty tiers, app service suspension or termination, confiscation, responsible-person fines, and possible business or licence measures.
Related guides

Explore more topics

China App Filing vs Personal Information Rules
Decide whether a China mobile app needs MIIT filing, personal-information controls, or both, with current triggers, duties, dates, and evidence.
China cybersecurity and data security requirements
China cybersecurity requirements by actor: network operators, data processors, CII operators, platforms, app providers, and distribution platforms.
China cybersecurity compliance checklist
A China cybersecurity checklist for scoping network duties, data security, CII procurement review, app rules, MIIT filing, and supporting standards.
China cybersecurity deadlines and compliance calendar
Separate China cybersecurity commencement dates from recurring duties, filing lead times, review periods, and event-driven response deadlines.
China Cybersecurity Law FAQ
Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.
China Cybersecurity Law vs EU Cyber Resilience Act
Compare China's network-operator rules with the EU CRA's product duties, including scope, actors, evidence, reporting dates, and launch decisions.
China Cybersecurity Law vs EU NIS2 Directive
Compare China's network-operator duties with NIS2 entity duties, including scope, management accountability, incident reporting, evidence, and enforcement.
China Cybersecurity Review vs Data Export Assessment
Separate China's cybersecurity-review triggers from CAC data-export assessment triggers, thresholds, filings, evidence, timing, and reapplication rules.
China cybersecurity review workflow
Determine whether CII procurement, platform data processing, or a qualifying foreign listing triggers China's Cybersecurity Review Measures.
China mobile app filing and app governance
Identify the China app sponsor, complete MIIT filing before service, and separate provider, platform, privacy, content, and security duties.
China Smart-Home Security vs Telecom and Radio Approval
Separate GB/T 41387-2022 smart-home security evidence from China telecom network-access and radio approval decisions for connected products.
CII and network operator role triage
How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
Does an app need MIIT filing and CAC app governance review?
An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.
GB/T 22239-2019 classified protection baseline
How to scope and document a GB/T 22239-2019 classified protection baseline without treating the recommended standard as a standalone law.
GB/T 41387-2022 smart home security standard
How connected-device teams can scope and document GB/T 41387-2022 without treating it as an automatic certification or product-approval duty.
How do smart home security standards fit with China cybersecurity law?
GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.
How does important data change China cybersecurity obligations?
Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.
Is every company a network operator under China Cybersecurity Law?
No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.
MLPS classified protection evidence map
Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence.
What is MLPS classified protection evidence?
MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.
When does China cybersecurity review apply?
China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.