Research across the library

Search laws, regulations, standards and guides

Suggested searches

Current priorities

2026-07-03Revised Internet Information Service Measures draft2026-06-18Network data risk assessment: draft versus final

What changed

Material differences at a glance

The amendment adds national-policy and artificial-intelligence provisions, links personal-information handling to the PIPL and Civil Code, restructures liability provisions, increases consequence-based penalties, and broadens the extraterritorial provision.

  • New provisions address national cybersecurity policy and artificial-intelligence development and security.
  • Personal-information handling is expressly linked to the PIPL, Civil Code, and other laws and administrative regulations.
  • Liability provisions are reorganized with higher penalties for serious consequences and new mitigation language.

Source comparison

9 reviewed change records
Article / SectionPrevious TextUpdated TextTypePractical ImpactNotes
New Article 3No equivalent standalone provision.Adds an express national cybersecurity policy provision.+ AddedPlaces the law within the current national cybersecurity policy framework.Added by item 1 of the amendment decision.Effective: 2026-01-01Current source
Former Article 18 / new Article 20Former Article 18 included a second paragraph that was removed.Adds support for AI research, infrastructure, ethics, risk monitoring, security supervision, and AI-enabled cybersecurity management.~ ModifiedExpressly brings AI development and safety into the Cybersecurity Law framework.Items 2 and 3 of the amendment decision.Effective: 2026-01-01Current source
Former Article 40 / new Article 42The article addressed protection of user information collected by network operators.Adds an express requirement to comply with the Cybersecurity Law, Civil Code, PIPL, and other laws and administrative regulations when processing personal information.i ClarifiedClarifies coordination with the later personal-information legal framework.Item 4 of the amendment decision.Effective: 2026-01-01Current source
New Article 61Former Article 59 contained the earlier penalty structure for specified security-protection failures.Introduces differentiated penalties and higher bands where failures cause serious or particularly serious cybersecurity consequences.~ ModifiedRaises consequence-based exposure for network operators and critical information infrastructure operators, including responsible personnel.Item 5 of the amendment decision; consult the official text for exact penalty ranges.Effective: 2026-01-01Current source
New Article 63No equivalent standalone liability article for selling or providing specified uncertified or non-compliant products.Adds liability for selling or providing network critical equipment and specialized cybersecurity products that do not meet certification or testing requirements.+ AddedCreates a dedicated enforcement basis for this product-control requirement.Item 7 of the amendment decision.Effective: 2026-01-01Current source
New Articles 64–69Former liability articles used the earlier numbering and penalty structure.Reorders and revises liability for prohibited activities, review obligations, CII procurement, and prohibited-information handling.~ ModifiedRequires compliance mappings and citations to use the amended numbering and penalty provisions.Items 8–11 of the amendment decision.Effective: 2026-01-01Current source
New Article 71Personal-information and cross-border liabilities were distributed across former Articles 64, 66, and 70.Consolidates coordination with other laws and administrative regulations for prohibited content, personal-information rights, and CII cross-border storage or transfer conduct.↔ ProceduralDirects readers to the relevant specialized legal regime for handling and penalties.Item 12 of the amendment decision.Effective: 2026-01-01Current source
New Article 73No equivalent express cross-reference in the law.Adds an express cross-reference to lighter, mitigated, or no punishment under the Administrative Penalty Law.+ AddedMakes general administrative-penalty mitigation principles explicit within the law.Item 13 of the amendment decision.Effective: 2026-01-01Current source
Former Article 75 / new Article 77The earlier extraterritorial provision addressed attacks, intrusion, interference, destruction, or other activities causing serious consequences.Uses broader language covering activities by overseas institutions, organizations, or individuals that endanger PRC cybersecurity and retains possible sanctions for serious consequences.~ ModifiedBroadens the wording of the extraterritorial conduct provision.Item 14 of the amendment decision.Effective: 2026-01-01Current source

Official sources

This website is for informational and educational purposes only. It does not constitute legal advice. The Chinese text shall prevail. Users should consult qualified legal counsel for specific matters.