Hero background
NEWSLETTERS|Calendar icon25 Jun 2026 10 mins read

Data Newsletter | June 25, 2026

This content has been AI-translated from the original and is provided for reference only.

Lusheng Editor
Lusheng Editor

Takeaways

  • China’s pharmaceutical trial data protection regime has been formally implemented, granting 3-6 years of exclusivity to undisclosed original trial data for innovative drugs, modified new drugs, and certain first generics. New indications are calculated separately. Compared with patent protection, data protection requires prior application but does not require active enforcement. Notably, China’s system is not absolute - applications with consent may still obtain approval during the protection period, leaving room for commercialization of drug trial data.

  • National cross-border data transfer negative lists continue to be updated. Beijing’s new measures expand the scope to the entire municipality and add four new sectors, including medical devices. Guangdong’s negative list targets enterprises in the intelligent equipment manufacturing and personal credit reporting sectors within the Guangdong FTZ and the Hetao Shenzhen Park.

  • The Supreme People’s Court released a typical case involving an outsourced healthcare IT company stealing patient privacy data, highlighting the need for processors of sensitive personal information to strengthen security management in system outsourcing and entrusted data processing.

  •  In May, regulators focused on AI labeling requirements and app compliance.

Regulatory Highlights

Beijing and Guangdong Cyberspace Authorities, Together with Multiple Departments, Issue Data Export Negative Lists and Implementing Rules

On May 8, the Beijing Cyberspace Administration, along with two other authorities, issued the 2025 version of the data export negative list and its implementing measures. The scope of application has been expanded from the former pilot free trade zone to the entire municipality of Beijing. The covered sectors have been broadened from the original five - automotive, pharmaceuticals, retail, civil aviation, and artificial intelligence - to include four additional sectors: medical devices, autonomous driving (intelligent connected vehicles), trade logistics, and the banking industry. In addition, a mechanism has been established to incorporate negative lists from other provinces: where enterprises have practical needs, negative lists issued by other provinces or municipalities may, upon assessment and filing, be dynamically incorporated into the local system.

On May 15, the Guangdong Cyberspace Administration, together with two other authorities, issued for the first time a negative list, implementing measures, and declaration guidelines applicable to enterprises registered in the Guangdong Pilot Free Trade Zone and the Hetao Cooperation Zone - Shenzhen. The covered sectors include intelligent equipment manufacturing and personal credit reporting services. The rules also allow reference to negative lists issued by other pilot free trade zones. Enterprises are required to conduct their own assessment to determine whether the data to be exported falls within the negative list.

The National Medical Products Administration (NMPA) Issues the Implementation Measures for the Protection of Drug Trial Data

Drug trial data protection operates parallel to patent protection. It grants a period of administrative data exclusivity over undisclosed original trial data submitted by applicants of innovative drugs or certain first generics, restricting other applicants from using such data to file marketing authorization applications. China first introduced the drug trial data protection regime in the 2002 Regulations for the Implementation of the Drug Administration Law, limiting protection to “new chemical entities” without detailed supporting provisions. After multiple revisions spanning over more than two decades, the new amendment this year first ever expands the scope of protection to “other eligible medicinal products”. One the same day the amendment took effective, NMPA released the Implementation Measures and the Working Procedures for the Protection of Drug Trial Data, formally implementing the drug trial data protection regime.

Specific protection rules are set out below:

  •  Within the drug trial data protection period, NMPA shall reject any marketing authorization application that relies on the undisclosed, self-generated trial data of chemical and biological products of other applicants without consent.
  •  Differentiated protection periods apply by drug type, calculated from the date of marketing approval in China: six years for innovative drugs and overseas-marketed original drugs not yet marketed in China; four years for improved new drugs, improved vaccines, and biological products; and three years for the first generics of overseas-marketed original drugs not yet marketed in China. No data protection is granted to generics biosimilars, and similar products of China-marketed original drugs. Protection for new indications is calculated separately.
  • Data protection must be proactively requested. Applicants shall file the application concurrently with their drug marketing authorization application. The Center for Drug Evaluation (CDE) of NMPA will confirm protection scope and duration during review and publish the protection information in a dedicated section on its official website.
  • A pre-expiry transition mechanism is introduced. Other applicants are permitted to submit marketing authorization applications or supplemental applications relying on the protected data during the one-year period before the expiry of the relevant drug data protection term. After completing the technical review, the CDE will suspend the review timeline, and approval may be granted after the data protection term expires.

The Supreme People’s Court (SPC) Releases Typical Cases on Punishing Crimes Involving Infringement of Citizens’ Personal Information and Related Offenses

On May 8, 2026, SPC issued five typical cases punishing crimes involving infringement of personal information and related offenses, covering medical data, travel information, academic credentials, and vaccine data, detailed as follows:

  1. Case of B Software Co., Ltd., He et al. for infringement of citizens’ personal information: An outsourced developer of hospital registration system stole over 2.87 million users’ personal data and was convicted of infringing citizens’ personal information. The company was fined RMB 300,000 (about USD 44,280), while the person in charge faced sentence up to 5 years and 6 months, together with a fine of RMB 100,000 (about USD 14,664).
  2. Case of Chen et al. for infringement of citizens’ personal information: A railway clerk accessed and sold citizens’ travel and ID information via the railway ticketing system, especially for paid inquiries into celebrities’ travel information.
  3. Case of Huang et al. for infringement of citizens’ personal information: Multiple defendants forged ID images to register on Center for Student Services and Development (the official platform for verifying higher education credentials in China), illegally obtaining and reselling citizens’ student record and higher education qualification information.
  4.  Case of Lin and Wang for infringement of citizens’ personal information and illegal use of information network: The defendants illegally obtained and sold over 900 million pieces of personal data via encrypted communication tools and other channels, sharing private information through self-built databases and online groups, constituting the crimes of infringing personal information and illegally using information networks.
  5. Case of Liang and Wang for fraud and infringement of citizens’ personal information: The defendants obtained more than 290,000 HPV vaccine appointment records by implanting Trojans and set up websites for telecom fraud, defrauding victims of over RMB 580,000 (about USD 85,582). Both defendants were convicted of infringing personal information and fraud.

AI Regulation

Following the launch of Cyberspace Administration of China's (CAC) Clear and Bright – Rectifying the Abuse of AI Applications special campaign on April 30, Chongqing, Zhejiang, and Shanghai have successively taken actions. Major platforms including Rednote, MiniMax, Pinduoduo, and Bilibili have issued corresponding governance announcements.

CAC continues to regulate AI-generated content labeling. On May 3, CAC publicized typical cases involving current-affairs self-media accounts. Major violations include failure to indicate information sources for domestic and international current events, public policies and social events, as well as missing AI-generated or fictional content tags. A total of 98,000 non-compliant accounts were handled. On May 12, CAC advanced the work on short-video content labeling, requiring platforms to standardize content labels for short videos, e.g. setting six mandatory labels such as "contains AI-generated content". Platforms are also required to make content labeling a compulsory step before release and to strengthen reviews on labeling for newly uploaded short videos.

Since the Negative List for Algorithms for Life Service Platforms (Trial) was issued in January 2026, cyberspace authorities nationwide have urged key platforms in food delivery, ride-hailing, freight, e-commerce, online travelling, and ticketing to conduct self-inspections. Platforms including Meituan, Taobao Tmall, Didi, Baidu, and TikTok have rolled out 63 optimization measures, pledged to comply with 139 algorithm compliance rules, and set deadlines for 125 pending rectification items. Optimization involves algorithms for order assignment, time estimation, safety assurance, merchant commission and pricing. Meanwhile, platforms have improved appeal handling mechanisms and algorithm transparency.

APP Supervision

According to the China Internet Integrity Development Report (2026) released on May 20, in 2025, China’s cyberspace authorities conducted regulatory interviews with 5,811 websites and platforms in accordance with the law, issued 1,646 warnings, imposed fines on 521 websites and platforms, ordered suspension of functions or information updates for 668 times, removed 2,133 mobile apps and 192 mini-programs, and, together with telecommunications regulators, cancelled filings and shut down 9,637 websites and apps.

Since May, routine supervision of mobile apps has continued steadily. On May 6, the Beijing Communications Administration reported five apps with compliance issues and four apps ordered to be removed from all app stores. On May 14, the Ministry of Public Security’s Computer Information System Security Product Quality Supervision and Inspection Center reported 41 apps for illegally collecting and using personal information. On May 21, the Ministry of Industry and Information Technology (MIIT) notified issues involving 31 apps (SDKs). On May 25, the Shanghai Cyberspace Administration reported personal data collection issues found in 13 locally operated apps and mini-programs in consumer retail and other sectors in 2026. On May 29, the Guangdong Cyberspace Administration identified personal data collection and usage issues in 28 locally operated apps and mini-programs related to the.

Data System Development

On May 27, The State Council Information Office held a press conference in the thematic series on the launch of the 15th Five-Year Plan. During the 15th Five-Year Plan period, people’s courts in China will formulate judicial documents on AI and data property rights protection and improve adjudication rules on data ownership, data transactions, and AI-generated outputs.

On May 9, MIIT initiated a pilot program on AI science ethics review and services. The pilot program requires provinces with designated National AI Innovation and Application Pilot Zones to nominate one to two key cities to take the lead in carrying out AI science ethics review and services. These cities will work with around five innovation entities each in the areas of foundational AI infrastructure and vertical applications to establish basic working mechanisms, launch review service centers and find out standardized procedures.

A series of regulatory and guidance documents have been rolled out: On May 8, CAC, the National Development and Reform Commission (NDRC), and MIIT jointly issued the Implementation Guidelines on Regulating the Application and Promoting Innovative Development of Intelligent Agents. On May 19, the National Information Security Standardization Technical Committee released a reference technical document, the Guidelines for Ethical and Safety Practices in AI Applications 1.0. On May 28, the State Administration for Market Regulation and NDRC jointly published the Guidelines on Building an AI Measurement System and Capacity. In addition, Shanghai has consecutively issued opinions on upgrading the service sector and further developing itself into a global asset management center, emphasizing the full implementation of the citywide cross-border data transfers through negative lists and the exploration of negative lists in additional sectors.

On May 22, the General Office of the National Data Administration and other departments released typical examples on data circulation security governance in the transportation and meteorological services areas for 2026. These cases cover a range of application scenarios, including a cloud-based early warning system for expressway traffic safety, secure data circulation for ship energy efficiency and carbon accounting, and container pickup and drop-off operations at ports.

Worldwide News

On May 28, Temu, the cross-border e-commerce platform owned by Pinduoduo, was fined EUR 200 million by the European Commission for selling a large number of non-compliant products. According to the Commission, Temu failed to adequately fulfill its obligations under the Digital Services Act (DSA), including conducting regular risk assessments and implementing appropriate controls as required for large online platforms. The risk reports it submitted relied heavily on industry-standard or even outdated data and did not sufficiently take into account the impact of its recommendation algorithms. As a result, the risks associated with the spread of non-compliant products on the platform were significantly underestimated. Temu is required to submit a corrective action plan by August 28. If the plan is not approved by the Commission, the company may face additional penalties.

On May 21, the European Commission released its annual report on the implementation of the Digital Markets Act (DMA).  As of the end of 2025, seven companies had been designated as “gatekeepers” under the DMA, including Alphabet, Amazon, Apple, Booking, ByteDance, Meta, and Microsoft. In terms of enforcement, the Commission has promoted compliance through binding compliance decisions, fines, and regulatory dialogue. For example, it found that Meta’s “Consent or Pay” model for processing users’ personal data on Facebook and Instagram failed to provide users with a sufficiently equivalent alternative, thereby violating DMA requirements. Meanwhile, the Commission has continued to push companies like Apple and Google to open up their mobile ecosystems, allowing app developers to direct users to alternative download options or external payment channels outside the platforms.


SIGN UP TO OUR NEWSLETTER

Stay in the loop with
our latest listings

Subscribe Now