The Chinese Ministry of Public Security has recently issued a new regulation expanding the scope of supervision and inspection in the online space. The regulation extends public security supervision from internet security to network, data, and information security. The subjects of inspection now include data processors, individuals handling personal information, and it allows public security to access, copy, and inspect relevant information. Legal experts are concerned that the new regulation broadens the power of public security to inspect personal electronic devices.
According to Chinese state media CCTV, on August 7th, the new version of “Regulations on Supervision and Inspection of Public Security Agencies in Cyberspace Security” includes network operators, data processors, individuals handling personal information as targets. Inspection methods include online patrols, offline checks, routine inspections, and special inspections. Article 4 of the new regulation allows public security to conduct online patrols of the network security of the subjects being inspected through methods such as network information patrols, information auditing, vulnerability scanning, and more.
Mr. Wei, a legal scholar in Guangxi, emphasized that the core of the new regulation is shifting the police oversight from early-stage “network equipment defense” to direct examination of “information and data content.” He pointed out that the definition of “data and personal information processors” in the higher-level laws completely covers ordinary individuals, meaning that as long as abnormalities are found in routine online patrols, or suspicions arise during major events or security checks, the police can demand unlocking phones and computers for inspection of chat records and digital data.
Moreover, the new regulation states that for “individuals subject to inspection,” supervision and inspection will be carried out by the local public security bureau where they reside, specifically including “individuals” in the territorial jurisdiction clause of public security scrutiny in cyberspace.
In response to this, Mr. Zhang, a human rights lawyer from Hubei, expressed concerns to reporters that this administrative order grants the public security the power to “check and copy,” ostensibly for the purpose of safeguarding national data security but essentially establishing a mechanism for “legally expropriating citizens’ digital assets.”
In the digital age, a person’s mobile phone data is an extension of their soul; when public power can freely copy this data without court authorization, ordinary citizens will completely lose the last line of defense of dignity and privacy before the state machinery.
The new regulation further expands the area of on-site inspections by public security. When conducting supervision and inspection, public security can enter business premises, computer rooms, workplaces, inquire about responsible persons, security managers, and “check, copy and supervise information related to inspection matters,” and inspect the operation of security protection measures. City-level and above public security bureaus can also conduct remote detections of network facilities and information systems through methods like vulnerability scanning and penetration testing.
While the 2018 old regulation already had the authority to “check and copy relevant information,” the new regulation includes data processors, individuals handling personal information, and individuals into the supervision system, and includes data security and information security in the inspection scope, broadening the subjects and types of information involved in public security inspections. Though the new regulation does not explicitly state “checking phones” or “checking computers,” when individuals are subject to inspection, and related data is stored in terminals like phones and computers, the power to “check and copy relevant information” directly involves personal electronic devices and their data.
The new regulation also involves information determined to be prohibited from being published or disseminated according to laws and administrative regulations, and specifies that during “national major security defense tasks,” public security can carry out special supervision and inspection of relevant network operators, data processors, and individuals handling personal information to check network security, data security, information security, and other related issues such as “content-oriented management” and “ideological security.”
Mr. Wu, a legal scholar from Mainland China, believes that compared to the old regulations, the new regulation thoroughly connects these four areas, which had different emphases in the law. With the “technical cloak” of network and data security, it encompasses the “administrative means” of reviewing information content, ultimately achieving the “political purpose” of safeguarding ideological security. He said, “This means that in the future within China, ‘politically incorrect’ actions will have nowhere to hide technically, and ‘digital privacy’ will no longer exist in law. From now on, public security will reshaped the entire network space and mobile phones of the mainland people into a continuous surveillance digital panorama prison without walls.”
