This English version may have been machine-generated from the Chinese original and may not convey the original meaning accurately.

According to the materials, the Measures for the Supervision and Inspection of Cyberspace Security by Public Security Organs, issued by China’s Ministry of Public Security, will take effect on October 1. Compared with the 2018 regulations, the new rules expand the subjects and scope of supervision and inspection, bringing data processors, personal information processors, and even individuals within their ambit, while allowing the police to consult and copy information related to inspection matters. Vulnerability detection, penetration testing, user registration information, Internet logs, algorithm security, and information content have also been brought under regulatory scrutiny. As for how the police may access personal devices such as mobile phones and computers, and how “relevant information” will be defined, the materials indicate that major questions remain.
The issue is not merely whether mobile phone data may be accessed, but who has the authority to decide to access it, under what procedures, and who will supervise what happens afterward. If administrative organs can expand inspection powers through departmental regulations, issue warning letters and summon individuals for discussions when conduct “does not yet constitute a violation of law or a crime,” and incorporate “content orientation” and “cyberspace ideological security” into routine supervision, then cybersecurity may shift from protecting citizens and society to becoming a tool for controlling speech and gathering personal information. Ordinary people may consequently worry about being monitored simply for contacting relatives and friends overseas via their phones, browsing foreign news and information, or handling client data; this chilling effect is itself an erosion of freedom of expression and personal dignity.
Legal professionals cited in the materials question whether the Ministry of Public Security has the authority to expand the relevant inspection powers solely through the Measures. This question goes straight to the root of the system: under a one-party dictatorship, the police are both executors of power and lack independent judicial review, effective parliamentary oversight, and questioning by a free press. The boundaries of so-called “national security” can continue to expand, while individual rights lack practical and enforceable safeguards. Even if the law provides for personal information protection, rights are unlikely to withstand power if law-enforcement agencies can interpret the rules themselves and decide whom to inspect.
Genuine cybersecurity should not be built on universal self-censorship and the boundless intervention of the police. It should instead rest on clear statutory authorization, a strict warrant system, the principles of necessity and proportionality, review by independent courts, data minimization, and effective compensation mechanisms. More fundamentally, only constitutional democracy, the separation of powers, judicial independence, and freedom of the press and speech can ensure that security powers remain subject to sustained checks and balances, preventing “supervision” from degenerating into surveillance.
Citizens are not data objects to be managed, and mobile phones are not archives that power may open at will. Defending digital privacy ultimately means defending everyone’s right to think freely, communicate freely, and live with dignity.
News background: The original report on which this commentary is based can be found at Radio Free Asia Mandarin。