BEIJING, Aug. 11 (Xinhua) -- Chinese police on Tuesday disclosed 10 cases involving the infringement of citizens' personal information, as the country intensifies efforts to combat data-related crimes and protect individual rights in the digital era.
The cases, released by the cybersecurity bureau of the Ministry of Public Security (MPS), revealed organized criminal networks that exploited inducements, cyber intrusions, and insider collusion to harvest and trade personal data for profit.
The issue carries particular significance in China, home to more than 1.4 billion people and one of the world's largest and most interconnected digital ecosystems. Few countries face the challenge of protecting personal information on a comparable scale, while the rapid adoption of facial recognition and artificial intelligence has added urgency to the task.
In one case, a gang used cash rewards to lure people into registering e-commerce accounts and business licenses under their real names, and then sold the credentials on to facilitate money laundering.
In another case, suspects bought large volumes of real-name-verified accounts on online platforms such as WeChat and Douyin, and then resold them to overseas syndicates for telecom and online fraud crimes.
All suspects in the 10 cases have been handled in accordance with the law, the MPS said.
But the cases also raise a broader question: Once personal information enters the digital marketplace, can individuals ever fully regain control of it?
A student surnamed Li first realized he had lost control of his personal information after registering on an educational platform.
"I signed up simply to download some exam review materials, but the sales calls started coming immediately," Li said. He still does not know who obtained his information or whether it can ever be fully deleted.
Li's experience reflects concerns, not only about excessive collection and data leaks, but also about whether individuals can effectively regain control of their personal information.
China has sought to address such concerns through legislation, targeted enforcement and stronger corporate accountability.
The Personal Information Protection Law allows individuals to request the deletion of their information under specified circumstances and requires personal information processors to follow principles, including necessity, transparency and consent.
In April, China's cyberspace, industry and information technology, and public security authorities launched a series of joint operations targeting violations involving mobile applications, online advertising, education, transportation, health care and finance.
The campaign targets excessive collection, forced consent and unnecessary reliance on facial recognition. It also addresses failures to provide users with effective ways to correct or delete their information, reject its processing and cancel their accounts.
The measures reflect a broader shift from responding to leaks after they occur toward protecting personal information throughout its life cycle, from collection and storage to use, transmission and deletion.
The latest crackdowns reflect China's sustained drive against data-related crimes. From 2020 to 2024, through specified campaigns, Chinese police agencies cracked more than 40,000 cases involving the infringement of citizens' personal information.
In 2025, the ministry combined tough law enforcement with tighter regulation to build a more comprehensive cyberspace governance system aimed at protecting network, data and information security.
Experts believe that China should build a full-chain, multi-layered, systematic protection framework with whole-of-society participation to safeguard personal information.
Hu Changlong, a law professor at Shandong University, called for sustained upgrades to cybercrime investigation capabilities and deeper long-term collaboration among police, internet firms and cybersecurity researchers to jointly address platform vulnerabilities and emerging threats. ■



