Skip to main content
China Legal Guides · National framework

Personal-Information Crimes: Criminal Procedure in China

A practical guide to criminal exposure for unlawful collection, sale or provision of personal information in China, including data types, thresholds, evidence and coordination with PIPL compliance.

63lawyer profiles listed
Updated10 Sep 2026
AudienceForeign businesses & individuals
Author China Legal Portal Editorial · Last reviewed · 5 min read · Editorial policy · AI content policy · Disclaimer · Not legal advice — confirm current rules with counsel and authorities

At a glance

Practice: typical process stages

Four high-level stages — details and local variations are in the guide below.

  1. FrameMap facts to PRC rules
  2. PlanOptions, risks & timeline
  3. ExecuteFilings, contracts, forums
  4. ReviewCompliance & next steps
City hubs

Local guides & lawyers

Drill into city × practice hubs where available, or open the city legal market guide.

Legal planning desk with source documents, authority records and evidence file
Working file · authority, workflow and evidence

A personal-information allegation in China may begin as a platform complaint, employee tip, cybercrime investigation, fraud-linked inquiry or internal compliance review. The first task is to identify the data type, the alleged conduct, the volume and context, and whether a corporate PIPL or data-compliance investigation is also live. Administrative privacy exposure and criminal liability are related but not identical tracks.

Suspects, companies and counsel should preserve source systems, access logs, purchase or sale records, chat and transfer evidence, sample datasets, consent or public-source claims, and every notice of search, freeze, summons or detention. This guide provides national procedural orientation and does not assess guilt, likely sentence or regulatory outcome in a particular case.

Subject to editorial and legal review. Obtain case-specific advice where anyone is detained, datasets are seized, or a criminal or regulatory deadline is running.

Separate criminal, regulatory and internal tracks

The same facts can generate a Criminal Law case for infringing citizens’ personal information, a Personal Information Protection Law or other regulatory inquiry, a civil claim, and an internal employment or vendor investigation. Identify which authority has opened a file, what conduct is alleged, and whether the company is treating the matter as an employee offence, a vendor breach, a system vulnerability or a business-acquisition of leads. Corporate remediation and criminal defence need coordinated document control so that logs are preserved rather than overwritten.

What counts as citizens’ personal information

Under Criminal Law Article 253-1 and the 2017 SPC/SPP interpretation, citizens’ personal information means information recorded electronically or otherwise that can alone or with other information identify a specific natural person or reflect that person’s activities. Examples include name, identity-document number, contact details, address, account credentials, property status and whereabouts. Later guiding cases confirm that facial-recognition information and resident-identity-card packages can fall within protected categories. Not every data field in a commercial database is automatically criminal personal information; identifiability and use context still matter.

Classify the alleged conduct

Typical charged patterns include selling or providing personal information in violation of state rules; illegally obtaining it by theft or other methods; and unit offences where a company organizes the conduct. “Providing” can include supply to a specific person or publication through a network or other channel. “Violation of state provisions” is assessed against laws, administrative regulations and departmental rules on personal-information protection, which now include the Personal Information Protection Law framework as well as earlier sector rules. Changing the purpose or scope of already-public information and then exploiting it can still support an illegal-acquisition theory under current case guidance.

Sensitivity, volume and “serious circumstances”

The 2017 interpretation grades thresholds by information type. Highly sensitive categories such as whereabouts, communication content, credit and property information have lower quantity triggers; other information that may affect personal or property safety has an intermediate trigger; ordinary personal information has a higher trigger. Illegal gains, prior penalties, knowing supply for use in other crime, and residual “other serious circumstances” can also matter. Batch counts should be tested for authenticity, duplication and whether the records are truly identifiable personal information rather than raw noise.

Business acquisition of leads and “legitimate operations”

Buying or receiving ordinary personal information for claimed legitimate business use is not automatically non-criminal. The interpretation sets separate thresholds and conditions for that pattern, including profit levels and prior administrative or criminal history, and it excludes the more sensitive information categories from that safer pathway. Marketing teams, data brokers, recruiters and outsourced lead vendors should preserve the legal basis claimed for collection, the contract chain, and evidence of how the data were actually used.

Overlap with fraud, accounts and cyber assistance

Personal-information cases often sit upstream of telecom or online fraud, account trading, payment abuse or assistance to information-network crime. Separate opinions treat illegal acquisition or provision of certain internet account credentials and biometric information as potentially within the personal-information offence when statutory conditions are met. Where the same actor also participates in fraud or related offences, charging may follow the heavier or concurrent pathway. Preserve the downstream use evidence rather than assuming the case ends at the data sale.

Evidence, devices and corporate response

Useful materials include database exports, admin logs, API keys, chat negotiations, payment records, sample packets, consent screens, privacy policies and vendor contracts. Forensic imaging should capture originals before remediation wiping. If a company discovers the issue first, document the discovery date, containment steps, who accessed which systems, and what was reported to whom. Employees and vendors should not delete chats, reformat phones or “clean” lead sheets once a criminal risk is live.

Working-file checklist

  • Data-type inventory and whether sensitive categories are involved.
  • Chronology of collection, purchase, sale, transfer and discovery.
  • Volume counts with deduplication and authenticity notes.
  • Source systems, access logs, devices and cloud accounts.
  • Contracts, consent claims, public-source claims and privacy notices.
  • Payment, chat and delivery records for any sale or brokerage.
  • All custody, search, freeze and rights notices.
  • Parallel PIPL, platform, employment or vendor investigation files.

Official sources

Law checked: September 10, 2026. Official Chinese texts control. Confirm the data type, alleged conduct, quantity evidence, custody status and any parallel regulatory investigation before acting.

Legal source archive with indexed legislation and official records
Source register · primary authorities and verification
Sources & trust

How to use this guide

Editorial, AI and verification policies

This page is general information for orientation. It is not legal advice and does not create an attorney–client relationship.

Review the Editorial Policy, AI Content Policy, and Lawyer Verification Policy.

Consultation preparation

What to prepare before contacting counsel

Send a focused first package so counsel can check conflicts, understand scope, and identify urgent deadlines.

  • A concise timeline and the result you want to achieve.
  • Names of all parties and affiliates for a conflict check.
  • Key contracts, notices, correspondence, filings, or decisions.
  • Known deadlines, preferred language, location, and budget constraints.
Directory

Practice lawyer profiles

China-based listings shown first. Review profiles for practice, then submit an initial enquiry.

Status shown per profileFree initial intakeChina-first directory sort

Browse practice directory →

Cross-border legal details arranged for a prepared counsel enquiry
Next route · prepared enquiry

Move from orientation to a properly prepared legal brief.

Bring the parties, objective, relevant documents, chronology, known deadlines and the decision you need counsel to make.

Prepare your legal enquiry →

Need counsel on practice?

Review listed lawyer profiles and submit an initial enquiry. No obligation.