A personal-information allegation in China may begin as a platform complaint, employee tip, cybercrime investigation, fraud-linked inquiry or internal compliance review. The first task is to identify the data type, the alleged conduct, the volume and context, and whether a corporate PIPL or data-compliance investigation is also live. Administrative privacy exposure and criminal liability are related but not identical tracks.
Suspects, companies and counsel should preserve source systems, access logs, purchase or sale records, chat and transfer evidence, sample datasets, consent or public-source claims, and every notice of search, freeze, summons or detention. This guide provides national procedural orientation and does not assess guilt, likely sentence or regulatory outcome in a particular case.
Subject to editorial and legal review. Obtain case-specific advice where anyone is detained, datasets are seized, or a criminal or regulatory deadline is running.
Separate criminal, regulatory and internal tracks
The same facts can generate a Criminal Law case for infringing citizens’ personal information, a Personal Information Protection Law or other regulatory inquiry, a civil claim, and an internal employment or vendor investigation. Identify which authority has opened a file, what conduct is alleged, and whether the company is treating the matter as an employee offence, a vendor breach, a system vulnerability or a business-acquisition of leads. Corporate remediation and criminal defence need coordinated document control so that logs are preserved rather than overwritten.
What counts as citizens’ personal information
Under Criminal Law Article 253-1 and the 2017 SPC/SPP interpretation, citizens’ personal information means information recorded electronically or otherwise that can alone or with other information identify a specific natural person or reflect that person’s activities. Examples include name, identity-document number, contact details, address, account credentials, property status and whereabouts. Later guiding cases confirm that facial-recognition information and resident-identity-card packages can fall within protected categories. Not every data field in a commercial database is automatically criminal personal information; identifiability and use context still matter.
Classify the alleged conduct
Typical charged patterns include selling or providing personal information in violation of state rules; illegally obtaining it by theft or other methods; and unit offences where a company organizes the conduct. “Providing” can include supply to a specific person or publication through a network or other channel. “Violation of state provisions” is assessed against laws, administrative regulations and departmental rules on personal-information protection, which now include the Personal Information Protection Law framework as well as earlier sector rules. Changing the purpose or scope of already-public information and then exploiting it can still support an illegal-acquisition theory under current case guidance.
Sensitivity, volume and “serious circumstances”
The 2017 interpretation grades thresholds by information type. Highly sensitive categories such as whereabouts, communication content, credit and property information have lower quantity triggers; other information that may affect personal or property safety has an intermediate trigger; ordinary personal information has a higher trigger. Illegal gains, prior penalties, knowing supply for use in other crime, and residual “other serious circumstances” can also matter. Batch counts should be tested for authenticity, duplication and whether the records are truly identifiable personal information rather than raw noise.
Business acquisition of leads and “legitimate operations”
Buying or receiving ordinary personal information for claimed legitimate business use is not automatically non-criminal. The interpretation sets separate thresholds and conditions for that pattern, including profit levels and prior administrative or criminal history, and it excludes the more sensitive information categories from that safer pathway. Marketing teams, data brokers, recruiters and outsourced lead vendors should preserve the legal basis claimed for collection, the contract chain, and evidence of how the data were actually used.
Overlap with fraud, accounts and cyber assistance
Personal-information cases often sit upstream of telecom or online fraud, account trading, payment abuse or assistance to information-network crime. Separate opinions treat illegal acquisition or provision of certain internet account credentials and biometric information as potentially within the personal-information offence when statutory conditions are met. Where the same actor also participates in fraud or related offences, charging may follow the heavier or concurrent pathway. Preserve the downstream use evidence rather than assuming the case ends at the data sale.
Evidence, devices and corporate response
Useful materials include database exports, admin logs, API keys, chat negotiations, payment records, sample packets, consent screens, privacy policies and vendor contracts. Forensic imaging should capture originals before remediation wiping. If a company discovers the issue first, document the discovery date, containment steps, who accessed which systems, and what was reported to whom. Employees and vendors should not delete chats, reformat phones or “clean” lead sheets once a criminal risk is live.
Working-file checklist
- Data-type inventory and whether sensitive categories are involved.
- Chronology of collection, purchase, sale, transfer and discovery.
- Volume counts with deduplication and authenticity notes.
- Source systems, access logs, devices and cloud accounts.
- Contracts, consent claims, public-source claims and privacy notices.
- Payment, chat and delivery records for any sale or brokerage.
- All custody, search, freeze and rights notices.
- Parallel PIPL, platform, employment or vendor investigation files.
Official sources
- National People's Congress: Criminal Law
- National People's Congress: Criminal Procedure Law
- National People's Congress: Personal Information Protection Law
- SPC/SPP: interpretation on criminal cases involving citizens' personal information
- Supreme People's Court: 35th batch of guiding cases on personal-information offences
- SPC/SPP/MPS: Opinion II on telecom and online fraud and related crimes
Law checked: September 10, 2026. Official Chinese texts control. Confirm the data type, alleged conduct, quantity evidence, custody status and any parallel regulatory investigation before acting.


