China: Nationwide PIPL Special Enforcement Campaign Now Producing Published Precedents — First Fine on Unassessed PI Export (September 2026)

Updated

China: Nationwide PIPL Special Enforcement Campaign Now Producing Published Precedents — First Fine on Unassessed PI Export (September 2026)

The joint CAC + MIIT + MPS personal information protection special enforcement campaign announced April 2, 2026 has moved from launch to published enforcement precedents, and two of the new cases sit directly on cross-border data transfer and AI tooling.

CAC's ten "typical cases" (September 15, 2026). The CAC published ten enforcement typical cases (执法典型案例) across cybersecurity, data security and personal information protection. Six are familiar perimeter failures (weak passwords, unpatched vulnerabilities, unauthorized access, an app forcing unnecessary permissions). Per Data Compliance China's read of the notice, four are new and change how compliance teams test:

"a Chongqing property company fined for running facial recognition on 5,000+ customers for marketing without separate consent, apparently the first public penalty to turn directly on PIPL Article 26; a Shanghai company fined for exporting personal information through a Windows desktop client with no data-export security assessment; a Sichuan company's WeChat mini-program ordered offline for failing to add explicit and implicit labels to AI-generated content; and a Jiangsu company warned for running two websites as an 'API relay station' (API中转站) over third-party LLM APIs without a security assessment1." — Data Compliance China

The Shanghai case is the first published fine this cycle squarely on exporting personal information without a data-export security assessment — and the vehicle was an ordinary Windows desktop client, meaning any endpoint tool that moves PI out of China counts. The Jiangsu case extends the same logic to LLM API relays.

CVERC's 82-app batch (September 23, 2026). The National Computer Virus Emergency Response Center named 82 mobile apps whose personal information collection failed testing conducted July 29–September 4 under the same joint campaign. Three things set this batch apart:

"of the 75 apps CVERC named in August, 28 still failed on retest and have been taken down by the distribution platforms" — Data Compliance China, on the published retest loop

The taxonomy has also moved past the 2019 Identification Method into PIPL's statutory text — five categories track PIPL Articles 23, 24, 30, 31 and 51 nearly word for word (separate consent for sharing with another handler, opt-out from automated-decision push, notice for sensitive personal information, dedicated rules for children under 14, security measures). The perimeter now reaches WeChat/Baidu/Alipay mini-programs, ad SDKs, TV apps, and hospital channels (eight named, four findings of sharing PI without separate consent).

What it means for compliance teams: the campaign is producing named, citable penalties with a working retest-and-takedown loop. Treat export security assessments for any client, tool or relay that moves personal information out of China as active enforcement territory, and expect app-store takedowns (not just fines) as the standard remedy. The AI-routing dimension is developing separately in China Treats AI Query Routing as a Cross-Border Data Transfer Problem: CAC Probes DeepSeek and Moonshot (September 2026).


  1. An instance of Routing prompts to a foreign AI model is now a cross-border data transfer. — Published enforcement now treats relaying queries through offshore LLM APIs as an unassessed cross-border data transfer, exactly the rule the theme asserts. ↩︎

Part of

This finding is an example of a pattern recurring across your work:

Backlinks

Revision history

  • Update: September 2026 typical cases (incl. first fine on unassessed PI export) and CVERC 82-app batch show the April campaign producing published precedents.
    · by the agent
  • Updated without a stated reason.
    · by migration
  • Updated without a stated reason.
    · by migration
  • Updated without a stated reason.
    · by migration
  • Updated without a stated reason.
    · by migration
  • Updated without a stated reason.
    · by migration
  • Updated without a stated reason.
    · by migration
  • Updated without a stated reason.
    · by migration
  • Updated without a stated reason.
    · by migration
  • Updated without a stated reason.
    · by migration
  • Updated without a stated reason.
    · by migration
  • Updated without a stated reason.
    · by migration
  • Updated without a stated reason.
    · by migration
  • Updated without a stated reason.
    · by migration
  • Updated without a stated reason.
    · by migration
  • Updated without a stated reason.
    · by migration
  • Updated without a stated reason.
    · by migration
  • Updated without a stated reason.
    · by migration