Py学习  »  Git

Digital Economy and Data Protection Newsletter(25.23)

TMT法律论坛 • 9 月前 • 423 次点击  

Click above|Follow us


Recently, in terms of legislation, the cyberspace administration has issued the "Measures for Network Data Security Risk Assessment (Draft for Comments)"; the public security department has issued the "Measures for Network Space Security Supervision and Inspection by Public Security Organs (Draft for Comments)". In terms of law enforcement, the Ministry of Industry and Information Technology has announced 24 apps and SDKs that infringe on user rights and interests; the Shanghai High People's Court has released cases of punitive damages for intellectual property rights; the National Network and Information Security Information Notification Center has reported 69 mobile applications that illegally collect and use personal information; and cyberspace administrations in multiple regions have launched industry-specific rectification campaigns and app notifications. Internationally, the European Commission has initiated compliance investigations into platforms such as Google and Meta; the U.S. White House has released the National Framework for Artificial Intelligence; the FTC has launched an investigation into TP-LINK; and the UK ICO has published an interim impact assessment report on the Children's Code Strategy, etc..


HOTSPOT

HOTSPOT



CAC solicits public comments on the Measures for Risk Assessment of Cybersecurity and Data Security (Draft for Comment)


On December 6, 2025, in order to regulate network data security risk assessment activities, ensure network data security, and promote the lawful, reasonable, and effective utilization of network data, the Cyberspace Administration of China drafted the "Measures for Network Data Security Risk Assessment (Draft for Comments)" (hereinafter referred to as the "Measures"), soliciting public feedback until January 5, 2026. Regarding the competent authorities, the Measures clarify that relevant regulatory departments shall regularly organize risk assessments for their respective industries and fields in accordance with the principle of "whoever manages the business, manages the business data, and manages data security." For data processors, the Measures provide explicit regulations on scenarios requiring network data security risk assessments, assessment procedures, and reporting requirements. Network data security risk assessments are mandatory for significant data processors, and relevant entities should pay special attention to these requirements.


For more information, please click here.

Source: CAC 







The Ministry of Public Security is soliciting public feedback on the "Measures for Cybersecurity Supervision and Inspection by Public Security Organs (Draft for Comments)."


On November 29, 2025, the Ministry of Public Security initiated a public consultation on the "Measures for Cybersecurity Supervision and Inspection by Public Security Organs (Draft for Comments)" (hereinafter referred to as the "Measures"), which will remain open for feedback until December 28. This revision of the "Regulations on Cybersecurity Supervision and Inspection by Public Security Organs (2018)" is based on laws such as the Cybersecurity Law, the Data Security Law, the Personal Information Protection Law, and the Network Data Security Management Regulations, and it clarifies the procedural standards for cybersecurity supervision and inspection.

Among its provisions, the Measures stipulate that operators of critical information infrastructure and network operators with a cybersecurity protection level of 3 or above must undergo an on-site inspection annually. Entities that have been in operation for less than one year, experienced security incidents or illegal/criminal activities within the past two years, or received administrative penalties will be designated as key inspection targets. Inspections will combine online monitoring with offline verification (on-site inspections). For risks or hazards identified during online monitoring, offline verification will be conducted.

Based on inspection findings, public security organs may take measures such as urging rectification, issuing reminder letters, or summoning responsible persons for interviews. Entities found in serious violation of regulations will face penalties in accordance with the law. It is recommended that businesses closely monitor regulatory developments and prepare response plans for inspections.


For more information, please click here.

Source: Ministry of Public Security    






Shanghai People's High Court Releases Typical Cases and Adjudication Highlights Involving Intellectual Property Punitive Damages


On December 12, 2025, the Shanghai High People's Court held a press conference and released ten typical cases involving punitive damages for intellectual property rights. These cases cover high-incidence areas such as malicious trademark registration, infringement in online game adaptations, and counterfeit practices within offline franchise systems, involving various rights including trademarks and copyrights. The released cases clarify key rules for determining malicious infringement and calculating the base amount for compensation. For example:

1)Preemptive registration of another party's well-known trademark and its use in competing for major projects, with substantial transaction amounts involved, may warrant calculating the base amount based on the transaction value and a reasonable profit margin, followed by the application of a high multiplier for punitive damages.

2)If an infringer continues or introduces new infringing content after reaching a settlement with the rights holder, it constitutes repeated infringement with clear malicious intent, and punitive damages should be applied according to the law.

3)Where the infringing acts are separable, punitive damages may be applied to the identifiable portion of illicit gains, while statutory damages may be applied to the unidentifiable portion.

If the infringer refuses to provide financial accounts or other evidence, the court may infer the illicit gains based on revenue such as franchise fees and use this as the basis for calculating punitive damages.


Source: Shanghai People’s High Court 






NEWSLETTER

NEWSLETTER


(Click on the source or copy the corresponding link to view the details)




LEGISLATION

  1. CAC solicits public comments on the Measures for Risk Assessment of Cybersecurity and Data Security (Draft for Comment)

    Source: CAC


  2. SAMR issues the standard Basic Requirements for the Service Management of Food Delivery Platforms

    Source: SAMR


  3. NDRC and other relevant departments jointly issue the Opinions on Strengthening the Construction of Data Element - related Disciplines and Specialties and the Contingent of Digital Talents

    Source: NDRC

    https://www.ndrc.gov.cn/xxgk/zcfb/tz/202512/t20251202_1402109.html


  4. Hubei Provincial Data Bureau solicits public comments on the Interim Measures for the Circulation and Transaction of Data in Hubei Province (Draft for Public Comment)

    Source: Wuhan Municipal Data Bureau

    https://home.wuhan.gov.cn/yjzj/202512/t20251205_2691243.shtml?sessionid=#:~


  5. MIIT issues the Measures for the Administration of Public Service Platforms for Industrial Technology Bases

    Source: MIIT

    https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2025/art_8d58788c9ccc448fb8428812a1734b86.html


  6. TC260 releases a notice on the approval of 48 foreign - language version projects of national cybersecurity standards

    Source: TC260

    https://www.tc260.org.cn/portal/article/2/9fd730091ad94d39a42a33720dfe2c0f



INDUSTRY TRENDS

  1. CAC guides website platforms to further rectify the irregularities in online live streaming rewards

    Source: CAC


  2. National Cyber Security and Information Notification Center notifies 69 mobile applications that illegally collect and use personal information

    Source: Cybersecurity Bureau of MPS


  3. Shanghai releases 5 typical cases of failure to fulfill personal information protection obligations

    Source: Shanghai CAC


  4. Shanghai CAC issues a circular on typical cases of the special rectification campaign to regulate the order of online real estate information dissemination

    Source: Shanghai CAC


  5. Zhejiang Communications Administration guides enterprises in the province to provide convenient package change services to protect users' right to choose

    Source: Zhejiang Communications Administration


  6. Hunan issues a notice on the submission of 2025 automotive data

    Source: Hunan CAC


  7. Zhuzhou City, Hunan Province holds collective interviews with principals of 15 mobile applications in the people's livelihood field

    Source: Hunan CAC


  8. Cyber police crack a case of illegal intrusion into computer information systems through "AI face - swapping" technology

    Source: Cybersecurity Bureau of MPS


  9. Doubao releases a statement on adjusting its ability to operate mobile phones via AI

    Source: Doubao Mobile Assistant


  10. Beijing holds a seminar on the standardization of data infrastructure agents

    Source: TC609

    https://www.tc609.org.cn/tc609/sjxw/202512/459300f829574b38838667d3483ee314.shtml


  11. Beijing holds a seminar on the Research Report on the Standardization of Embodied Intelligence Data

    Source: TC 609

    https://www.tc609.org.cn/tc609/sjxw/202512/83c113c2e71b4e3ca5917155e3b9c218.shtml


  12. National Computer Virus Emergency Response Center detects 69 mobile applications that illegally collect and use personal information

    Source: National Cyber Security Notification Center


  13. MIIT releases the results of security testing on key network equipment (Batch 23)

    Source: MIIT

    https://www.miit.gov.cn/xwfb/gxdt/sjdt/art/2025/art_9d94133e4537487f881e236c1a0fea10.html


  14. MIIT notifies 24 APPs and SDKs that infringe on users' rights and interests

    Source: MIIT


  15. Huangpu District People's Court of Shanghai renders a judgment on a copyright case involving AI prompts

    Source: IP Treasure


  16. CAC releases the second batch of typical cases of the special rectification campaign against irregularities in the automotive industry's online sector

    Source: CAC

    https://www.cac.gov.cn/2025-12/11/c_1767128004806559.htm


  17. Beijing CAC issues an announcement on the filed information of generative AI services in Beijing (December 11, 2025)

    Source: Beijing CAC


  18. Shanghai Higher People's Court releases typical cases and key judicial rules concerning punitive damages for intellectual property infringements

    Source: Shanghai High People's Court


  19. Guangzhou Intermediate People's Court Releases Details of a Case Involving the Crime of Violating Personal Information Protection by Selling Users’ Internet Preference Data

    Source: Guangzhou Intermediate People's Court



OVERSEAS

  1. EU:

    1. The Implementing Regulation of the Network Resilience Act is released

      Source: EUR - LEX

      https://eur-lex.europa.eu/eli/reg_impl/2025/2392/oj/eng


    2. EDPB issues Recommendation 2025/2 on the Legal Basis for Requiring User Account Registration on E - commerce Websites

      Source: EDPB

      https://www.edpb.europa.eu/our-work-tools/documents/public-consultations/2025/recommendations-22025-legal-basis-requiring_en


    3. CJEU rules that online marketplace operators are liable for the processing of personal data contained in advertisements posted on their platforms

      Source: Court of Justice of the EU

      https://curia.europa.eu/jcms/upload/docs/application/pdf/2025-12/cp250150en.pdf


    4. European Commission launches an antitrust investigation into Meta's restriction of third - party AI service providers' access to WhatsApp

      Source: European Commission

      https://digital-strategy.ec.europa.eu/en/news/commission-opens-antitrust-investigation-metas-new-policy-regarding-ai-providers-access-whatsapp


    5. European Commission receives notifications from Apple under the Digital Markets Act

      Source: European Commission

      https://digital-markets-act.ec.europa.eu/commission-receives-notifications-apple-under-digital-markets-act-2025-11-27_en


    6. European Commission solicits comments on the draft implementing act for establishing AI regulatory sandboxes under the AI Act

      Source: European Commission

      https://digital-strategy.ec.europa.eu/en/consultations/commission-seeks-feedback-draft-implementing-act-establish-ai-regulatory-sandboxes-under-ai-act#:~:text=The%20Commission%20will%20adopt%20an%20implementing%20act%20to,for%205%20weeks.%20You%20can%20submit%20your%20comments


    7. European Commission launches an investigation into Google's alleged anti - competitive practice of misusing online content to train AI

      Source: European Commission

      https://ec.europa.eu/commission/presscorner/detail/en/ip_25_2964


    8. Meta commits to offering EU users the right to choose personalized ads under the DMA

      Source: DMA Official Website

      https://digital-markets-act.ec.europa.eu/meta-commits-give-eu-users-choice-personalised-ads-under-dma-2025-12-08_en#:~:text=The%20European%20Commission%20acknowledges%20Meta%27s%20undertaking%20to%20offer,to%20comply%20with%20the%20Digital%20Markets%20Act%20%28DMA%29


    9. European Parliament releases an initiative report on the European Commission's preparation of the Cloud and AI Development Act

      Source: European Parliament

      https://www.europarl.europa.eu/RegData/etudes/BRIE/2025/779251/EPRS_BRI(2025)779251_EN.pdf


    10. General Court of the EU upholds the European Commission's 2023 unfavorable antitrust decision against Intel while reducing the fine

      Source: Court of Justice of the EU

      https://curia.europa.eu/jcms/upload/docs/application/pdf/2025-12/cp250153en.pdf


    11. NOYB criticizes the EU - US data cross - border transfer framework

      Source: NOYB

      https://noyb.eu/en/eu-us-data-transfers-time-prepare-more-trouble-come


    12. EU Commission fines X €120 million under the Digital Services Act

      Source: EU Commission

      https://ec.europa.eu/commission/presscorner/detail/en/ip_25_2934


    13. EU Commission accepts TikTok's commitments on advertising transparency under the Digital Services Act

      Source: EU Commission

      https://ec.europa.eu/commission/presscorner/detail/en/ip_25_2940


  2. US:

    1. USPTO updates guidelines on AI - assisted inventions, specifying that only natural persons can be designated as inventors

      Source: USPTO

      https://www.uspto.gov/subscription-center/2025/revised-inventorship-guidance-ai-assisted-inventions


    2. 36 Attorneys General send a letter to Congress opposing the moratorium on state regulation of AI

      Source: New York AG

      https://ag.ny.gov/press-release/2025/attorney-general-james-leads-bipartisan-coalition-urging-congress-reject#:~:text=NEW%20YORK%20%E2%80%93%20New%20York%20Attorney%20General%20Letitia,or%20enforcing%20laws%20to%20regulate%20artificial%20intelligence%20(AI)


    3. Indiana Attorney General releases the Indiana Consumer Data Privacy Bill of Rights

      Source: Indiana AG

      https://www.in.gov/attorneygeneral/files/Indiana-Consumer-Data-Protection-Consumer-Bill-of-Rights_Web.pdf


    4. Florida Attorney General subpoenas TP - Link over cybersecurity risks

      Source: Florida Department of Justice

      https://www.myfloridalegal.com/newsrelease/attorney-general-james-uthmeier-issues-subpoena-tp-link-over-cybersecurity-risks#:~:text=TALLAHASSEE,%20Fla.%E2%80%94Attorney%20General%20James%20Uthmeier%20today%20announced%20that,supply-chain%20infrastructure,%20and%20handling%20of%20U.S.%20consumer%20data


    5. Hikvision sues the Federal Communications Commission (FCC)

      Source: Reuters

      https://money.usnews.com/investing/news/articles/2025-12-03/hikvision-challenges-us-decision-to-expand-crackdown-on-chinese-telecom-gear


    6. NSA and international cybersecurity agencies jointly issue principles on the secure integration of AI into operational technology

      Source: NSA

      https://media.defense.gov/2025/Dec/03/2003834257/-1/-1/0/JOINT_GUIDANCE_PRINCIPLES_FOR_THE_SECURE_INTEGRATION_OF_AI_IN_OT.PDF#:~:text=This%20guidance%E2%80%94co-authored%20by%20the%20Cybersecurity%20and%20Infrastructure%20Security,practical%20information%20for%20integrating%20AI%20into%20OT%20environments


    7. Arizona Attorney General sues Temu on suspicion of data theft

      Source: Arizona Department of Justice

      https://www.azag.gov/press-release/attorney-general-mayes-sues-online-shopping-platform-temu-stealing-arizonans-data-and#:~:text=PHOENIX%20%E2%80%93%20Attorney%20General%20Kris%20Mayes%20today%20announced,and%20counterfeiting%20some%20of%20Arizona%E2%80%99s%20most%20iconic%20brands


    8. US President issues an executive order on the "National Policy Framework for Securing Artificial Intelligence"

      Source: The White House

      https://www.whitehouse.gov/presidential-actions/2025/12/eliminating-state-law-obstruction-of-national-artificial-intelligence-policy/


    9. Disney invests 1 billion US dollars in OpenAI and allows users to create videos using Disney's copyrighted characters on Sora

      Source: Disney

      https://thewaltdisneycompany.com/disney-openai-sora-agreement/


    10. FTC Examines Whether TP-Link Misled US Consumers About Its China Split

      Source: U.S. NEWS

      https://money.usnews.com/investing/news/articles/2025-12-04/ftc-examines-whether-tp-link-misled-us-consumers-about-its-china-split-source-says


  3. UK:

    1. ICO announces that it will closely monitor the protection of children's privacy in mobile games

      Source: ICO

      https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2025/12/children-s-online-privacy-in-mobile-games-under-spotlight/


    2. Ofcom fines AVS Group Limited 1.05 million pounds for failing to implement rigorous age verification checks and respond to information requests

      Source: Ofcom

      https://www.ofcom.org.uk/online-safety/protecting-children/ofcom-fines-porn-company-1million-for-not-having-robust-age-checks?__cf_chl_rt_tk=iJIY1OP0olut_hr7EePb6No6F_c07YT2FvGNh_LsnuQ-1765444464-1.0.1.1-qrwVZ6fdVnJobt6KzTVBcOgQ1MkJYs8bOVTJpBUu6FY


    3. ICO publishes Children’s Code Strategy: Interim Impact Assessment Report

      Source: ICO

      https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/childrens-information/childrens-code-guidance-and-resources/protecting-childrens-privacy-online-our-childrens-code-strategy/children-s-code-strategy-progress-update-december-2025/


  4. Ireland: Coimisiún na Meán launches DSA investigations into TikTok and LinkedIn

    Source: Coimisiún na Meán

    https://www.cnam.ie/coimisiun-na-mean-commences-investigations-into-tiktok-and-linkedin/


  5. Netherlands: AP launches a cookies awareness campaign

    Source: Autoriteit Persoonsgegevens

    https://www.autoriteitpersoonsgegevens.nl/actueel/ap-lanceert-campagne-om-organisaties-te-helpen-met-een-goed-cookiebeleid


  6. Sweden: IMY clarifies the right to be forgotten and search engine results

    Source: Swedish Authority for Privacy Protection

    https://www.imy.se/nyheter/ratten-att-bli-bortglomd-och-soktraffar-till-nyhetsartiklar/


  7. Portugal: The transposition law of NIS2 is published in the Official Gazette

    Source: Diário da República

    https://diariodarepublica.pt/dr/detalhe/lei/59-2025-941547424


  8. Czech Republic: The government approves the Draft Digital Economy Act

    Source: Czech Government

    https://mpo.gov.cz/cz/rozcestnik/pro-media/tiskove-zpravy/bezpecnejsi-on-line-prostredi--vlada-schvalila-navrh-zakona-o-digitalni-ekonomice--290645/


  9. South Korea:

    1. PIPC releases the Notice on the Transmission of Personal Information in the Power Industry (Draft)

      Source: PIPC

      https://www.pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS061&mCode=C010010000&nttId=1163 8#LINK


    2. South Korean e-commerce giant Coupang experiences large-scale data breach

      Source: YONHAP NEWS

      https://en.yna.co.kr/view/AEN20251129002000320


  10. Taiwan Region: The Taiwan authorities impose a one - year ban on Xiaohongshu, citing "failure to pass information security inspections" and involvement in "fraud cases"

    Source: The Beijing News


  11. Paraguay: The President approves the Data Protection Act

    Source: Paraguayan Government

    https://baselegal.com.py/docs/c0a4f95a-cc40-11f0-8c5a-525400343722


  12. Kyrgyzstan: SAPDP releases guidelines on common mistakes in the registration of personal data organizations

    Source: SAPDP

    https://dpa.gov.kg/ky/post/206


  13. Vietnam: Vietnam enacts its first Artificial Intelligence Act

    Source: VIETNAM.VN

    https://www.vietnam.vn/en/quoc-hoi-thong-qua-luat-tri-tue-nhan-tao-hoan-thien-hanh-lang-phap-ly-cho-ky-nguyen-so


  14. Russia: Russia bans Roblox platform over allegations of promoting LGBT content and terrorism to children

    Source: Cybernews

    https://cybernews.com/tech/roblox-ban-russia/


  15. Australia: Australia’s Online Safety Amendment (Social Media Minimum Age) Bill 2024 takes effect

    Source: Australia Parliament

    https://www.aph.gov.au/Parliamentary_Business/Bills_Legislation/Bills_Search_Results/Result?bId=r7284



Note

本文由Gen AI翻译,仅供参考。

Translated by Gen AI service. For reference only.


本期编辑:吴佳蔚 陈煜烺 林婉琪 陈曦宇 张丽

Python社区是高质量的Python/Django开发社区
本文地址:http://www.python88.com/topic/190498