Skip to main content
Data Privacy & Cybersecurity

10 min read Last reviewed 2 Aug 2026

Data Breaches in China: What to Do When Your Personal Information Leaks

Wen Lei outlines practical steps and legal options after a personal information leak in China, including PIPL notification duties and remedies.

Statute Art. 253
Process Litigation
Data Breaches in China: What to Do When Your Personal Information Leaks

At two in the morning, a Beijing e-commerce founder called me in a state of alarm. Her phone number, national ID number, home address, and the final digits of her bank card had appeared in a social media chat group, alongside a screenshot of her customer database. Within hours, messages sent in her name were reaching her friends asking for urgent money transfers. Her first question — the one nearly every client asks me in the first hour of a data incident — was simple: "Can I report this to the police, and will they actually take the case?" The honest answer is more nuanced than most people expect. This article explains when a personal information leak becomes a police matter, what the law treats as personal information, what individuals should do in the first hours of a leak, and what obligations companies now face under China's data protection regime.

At two in the morning, a Beijing e-commerce founder called me in a state of alarm. Her phone number, national ID number, home address, and the final digits of her bank card had appeared in a social media chat group, alongside a screenshot of her customer database. Within hours, messages sent in her name were reaching her friends asking for urgent money transfers. Her first question — the one nearly every client asks me in the first hour of a data incident — was simple: "Can I report this to the police, and will they actually take the case?" The honest answer is more nuanced than most people expect. This article explains when a personal information leak becomes a police matter, what the law treats as personal information, what individuals should do in the first hours of a leak, and what obligations companies now face under China's data protection regime.

Can You Report a Data Leak to the Police?

Whether the public security authorities will accept and file a case on a personal information leak in China depends on two factors: whether the leak has caused adverse consequences, and whether you can present solid evidence. Where a leak has already produced concrete harm — an account hijacked, funds transferred out, fraud committed in your name, or your identity documents used to open loans — the police can and routinely do open a criminal case. Where information has merely been exposed with no demonstrable adverse consequence, filing a case is far less likely; the police will typically record the report but treat the matter as one for the platform and the regulators rather than for criminal investigation.

Background & legal framework

The legal foundation is the Criminal Law of the People's Republic of China, Article 253-1, which makes it a crime to sell or provide citizens' personal information to others, or to obtain it by theft, deception, or other illegal means. Under the judicial interpretation jointly issued by the Supreme People's Court and the Supreme People's Procuratorate in 2017, "serious circumstances" sufficient for prosecution include, for example, more than fifty items of tracking or location information, more than five hundred items of residence, communication, health, or transaction records, or more than five thousand items of other personal information. Even a comparatively modest leak can cross these thresholds — and when it does, the authorities have a statutory basis to investigate.

Evidence is the decisive variable. Screenshots of your data circulating online, chat logs, phishing messages, transfer records, and notarized copies of materials that are at risk of deletion all help demonstrate that a crime occurred and identify a suspect. As a practical matter, my advice to individuals is to document the harm first — the loss, the unauthorized transaction, the fraudulent use of your identity — because a case that cannot be evidenced is a case that will rarely be filed.

What Actually Counts as Personal Information

Many people underestimate how much of their digital footprint qualifies as personal information. The Personal Information Protection Law (PIPL), which took effect in November 2021, defines personal information broadly as any information related to an identified or identifiable natural person that is recorded electronically or by other means. In practice, the information exposed in a typical leak falls into six categories. First, basic information: name, gender, age, ID number, phone number, email address, and home address — and often more sensitive entries such as marital status, religion, occupation, employer, income, medical records, and childbirth details. Second, device information: location data, Wi-Fi network lists, MAC addresses, CPU and memory specifications, SD card data, and operating system versions, which are routinely harvested by malicious programs.

Third, account information: online banking credentials, third-party payment accounts, social media accounts, and important email accounts. Fourth, privacy information: contact lists, call records, text message logs, instant messaging chat history, and personal videos and photographs. Fifth, social relationship information: your circle of friends, family members, and workplace connections. Sixth, network behavior information: browsing times and locations, keystroke and input records, chat and dating activity, and website visitation patterns. Under PIPL Article 28, several of these — including medical records, financial accounts, precise location, and certain biometric data — are treated as sensitive personal information, which may only be processed under stricter conditions and with a separate, specific consent.

How the dispute was handled

The Threat Environment Behind the Headlines

The risk is not hypothetical. With the rapid spread of internet applications, malicious programs, phishing campaigns, and fraud schemes have sustained high growth, while hacker attacks and large-scale personal information leak incidents occur with increasing frequency. The result is a steady rise in both the exposure of personal data and the associated property losses suffered by ordinary internet users. Industry assessments cited in public reporting have estimated that known vulnerabilities alone could expose billions of records — figures on the order of 2.36 billion items of private data, spanning personal privacy information, account passwords, bank card details, and commercial secrets held by enterprises.

This environment is precisely why the law has moved from voluntary best practice to binding obligation. PIPL Article 51 requires personal information processors to adopt management and technical measures commensurate with risk, including encryption, access controls, and staff training, while Articles 55 and 56 mandate personal information protection impact assessments and records for high-risk processing activities. When a breach nevertheless occurs, the law does not leave companies to decide privately how to respond — it prescribes a response.

First Steps for Individuals Whose Information Has Been Leaked

Once your information is in the hands of others, it can be used not only to take over your accounts but to deceive the people closest to you. Fraudsters routinely use leaked identity details to make impersonation convincing: a message that arrives from "your friend" complete with her real name, her workplace, and a reference to a genuine conversation can defeat even cautious recipients. The single most important step, therefore, is to warn your family and friends immediately. Tell them your accounts may be compromised, that any urgent request for money or verification codes should be verified by a direct phone call, and that they should not click links in messages purporting to come from you.

Beyond the warning, the practical checklist I give clients is short but urgent. First, secure your accounts: change passwords on banking, payment, social media, and email accounts immediately, enable multi-factor authentication where available, and contact your bank to freeze or monitor cards associated with leaked numbers. Second, preserve evidence: take screenshots of where your data appears, keep phishing messages and call records, and save any transaction or loss records — these documents may later be the difference between a filed case and a dead end. Third, report the matter through the proper channels: notify the platform or website involved so it can take down the material, and where fraud or financial loss has already occurred, file a report with the police and obtain a written receipt of the report. Fourth, keep a log of everything you have done and the dates on which you did it; if you later pursue a civil claim or an administrative complaint, a contemporaneous record is far more persuasive than a reconstructed one.

Practical implications

What Companies Must Do: The Six-Step Incident Response

For companies holding customer data, the obligations are now explicit. Article 42 of the Cybersecurity Law requires network operators to adopt technical and other necessary measures to protect collected personal information, and provides that where personal information is leaked, damaged, or lost, the operator must immediately take remedial measures, promptly notify the affected individuals, and report to the competent authorities in accordance with the regulations. Article 57 of the PIPL goes further: on discovering that personal information has been leaked, tampered with, or lost, a processor must immediately take remedial measures and notify both the individuals concerned and the authority responsible for personal information protection — although notification to individuals may be dispensed with where the processor can take measures that effectively avoid harm. Where notification is required, it must describe the categories of information involved, the cause of the incident, the possible harm, the remedial measures taken, and the steps individuals can take to protect themselves.

In my incident response practice, I walk clients through six steps, and the first twenty-four to forty-eight hours decide the quality of the entire response. Detection: confirm that an incident has occurred, identify the affected systems and the types and volume of data involved, and distinguish a genuine breach from a false alarm. Containment: cut off the exfiltration channel, disable compromised accounts and credentials, and, where necessary, take affected services offline to stop the bleeding. Notification: discharge the PIPL Article 57 and Cybersecurity Law Article 42 obligations — notify affected individuals and relevant platforms in a timely manner, with content that is accurate but does not itself compound panic. Reporting: report to the competent regulators, including the cyberspace administration and public security authorities where the circumstances require, and keep records of every communication.

Evidence preservation: secure forensic copies of logs and systems before any cleanup begins, so that the chain of custody supports later regulatory review, civil claims, or criminal investigation. Remediation: close the vulnerability that allowed the breach, strengthen access controls and encryption, retrain staff, update impact assessments, and prepare the documentation regulators will ask for. Throughout, legal counsel and technical teams must work in parallel — the technicians contain the breach while the lawyers preserve the evidence, draft the notifications, and manage the regulatory and media interface. This is the discipline that separates a contained incident from a reputational catastrophe, and it is the core of the work I do with companies across Beijing's technology sector.

Legal Remedies: Civil, Administrative, and Criminal

Individuals harmed by a leak have three enforcement paths. Civilly, Article 1038 of the Civil Code prohibits information processors from disclosing, tampering with, or damaging the personal information they collect, and PIPL Article 69 provides that a processor who violates the law and thereby harms a person's rights and interests bears tort liability unless it can prove it was not at fault. Damages may cover the losses suffered or the benefits gained by the processor, and where the violation is intentional or grossly negligent and causes serious harm, the court may award punitive damages. Notably, PIPL Article 70 also allows procuratorates and consumer organizations to bring public interest litigation on behalf of affected groups — an avenue that has made large data incidents costly for their handlers.

Administratively, individuals may complain to the cyberspace administration, the industry and information technology authorities, or the market regulation authorities. Under PIPL Article 66, serious violations can draw fines of up to fifty million yuan or five percent of the violator's prior-year turnover, along with suspension of relevant business, revocation of permits, and disqualification of the responsible individuals — penalties designed to make data protection failures materially expensive. Criminally, where the leak involves the sale or illegal provision of personal information, or where it enables fraud or theft, the matter belongs with the public security authorities, and the Article 253-1 thresholds I described earlier provide the yardstick for case filing.

What parties should remember

Conclusion: Act in the First Hours

Data leaks are no longer a question of whether they will happen, but when. For individuals, the first hours determine the damage: warn your circle, secure your accounts, preserve your evidence, and report where harm has occurred — because the police will file a case when there is real harm and solid evidence, but rarely for a silent exposure. For companies, the law now demands a documented response, and the sequence is fixed: detect, contain, notify, report, preserve evidence, and remediate. In an incident, the first hours decide the outcome. Speed preserves evidence, protects reputation, and keeps you — whether you are an individual or an enterprise — in control of the story.

Sources & trust

How to use this article

This insight is general information for orientation on China-related legal topics. It is not legal advice and does not create an attorney–client relationship. Prefer primary statutes, courts, and official guidance when making decisions.

Editorial Policy · AI Content Policy · Lawyer Verification Policy · Listing standards · Disclaimer · Request a consultation

Share LinkedIn X Email
Wen Lei

About the author

Wen Lei

Beijing Jingshi Law Firm. Verified listing on China Legal Portal. Insights are educational and do not create an attorney–client relationship.

Discussion

Join the conversation

Share a professional question or experience. This is not legal advice — no attorney–client relationship is formed by posting here.

Next step

Need counsel on this topic?

Connect with verified data privacy & cybersecurity lawyers across China, or ask a free initial question.

Educational information only — not legal advice. Laws change; consult qualified counsel for your situation. No attorney–client relationship is formed by using this site. See our Disclaimer, Editorial Policy, and AI Content Policy.