• About Us
  • People
    • Matthew Murphy
    • Ellen Wang
    • Yu Du
    • Xia Yu
    • Sarah Xuan
  • Practice Areas
    • Intellectual Property
    • Technology
    • Corporate
    • International Trade
    • International Arbitration
  • Insights
  • Accolades
  • Locations
  • Contact Us
  • 中文

China Releases Typical Cases on Punishment of Crimes Infringing Personal Information and Related Offences

Published 18 May 2026 Xia Yu
On 8 May 2026, the Supreme People’s Court of the People’s Republic of China released five typical cases concerning crimes infringing citizens’ personal information and related offences. The cases collectively cover multiple high-risk scenarios, including medical data, travel information, educational and student-status information, “doxxing” cyber violence (referring to malicious conduct whereby offenders illegally obtain and publicly disclose sensitive personal information of others in order to incite online harassment and abuse), and precision fraud schemes. These cases not only reflect the continued strengthening by Chinese judicial authorities of criminal enforcement against offences involving infringement of citizens’ personal information, but also further demonstrate that China’s judicial practice in personal information protection is gradually evolving from traditional “privacy infringement governance” toward an integrated governance model encompassing “data security, cyberspace order, and public interest protection.”
The adjudicative reasoning underlying the five typical cases is principally grounded upon the normative framework established by the Criminal Law of the People’s Republic of China, the Personal Information Protection Law of the People’s Republic of China, the Cybersecurity Law of the People’s Republic of China, and the Interpretation of the Supreme People’s Court and the Supreme People’s Procuratorate on Several Issues Concerning the Application of Law in Handling Criminal Cases of Infringing Citizens’ Personal Information. Collectively, these authorities demonstrate that China has gradually established a personal information protection framework integrating “administrative compliance, criminal accountability, and public-interest remedies.”
Typical Case 1: Bomou Software Co., Ltd. and He Moumou et al. — Risks of Excessive Data Processing in the Context of Medical Outsourcing Services: The principal guiding significance of this case lies in the Chinese judiciary’s express inclusion, within the scope of criminal regulation concerning infringement of citizens’ personal information, of conduct whereby outsourced service providers exploit service convenience to privately retain and accumulate data. Even where an actor lawfully gains access to patient information through a legitimate cooperative relationship, once the data processing activities exceed the necessary scope authorized by contractual arrangements, privacy policies, or service purposes — for example, privately extracting and establishing databases for the purpose of “data stockpiling” — such conduct may constitute the illegal acquisition of citizens’ personal information, without requiring proof that the data was actually sold or leaked.
Between 2015 and 2020, the defendant entity, Bomou Software Co., Ltd. (“Bomou Company”), was responsible for developing and maintaining an online registration system for a hospital. Defendant He Moumou served as the legal representative of Bomou Company. During the provision of services, He Moumou secretly collected personal information relating to hospital registration users through unlawful access to backend systems, and instructed company employees Xiong Mou and Luo Moumou to import the acquired data into a self-established company database. In early 2021, Xiong Mou further arranged for personnel to install an interface into software developed for the hospital, automatically importing users’ personal information into the company’s database. Following the investigation, personal information relating to registered users was extracted from the company’s servers, self-built database, and devices located at He Moumou’s residence, amounting to 2,878,070 records after deduplication.
The Xishan District People’s Court of Wuxi City held that Bomou Company had illegally obtained citizens’ personal information during the course of providing services, under circumstances deemed “particularly serious”, thereby constituting the crime of infringing citizens’ personal information and warranting criminal punishment according to law. The court further held that He Moumou and others, as persons directly in charge and other directly responsible personnel of Bomou Company, had likewise committed the same offence. Taking into account the facts, circumstances, and consequences of the case, the court imposed upon Bomou Company a criminal fine of RMB 300,000 (approximately US$ 44,100), and sentenced He Moumou and the other defendants to fixed-term imprisonment ranging from five years and six months to one year and six months, together with fines ranging from RMB 100,000 to RMB 10,000 (approximately US$ 14,700 to USD 1,470).
Typical Case 2: Chen Moumou et al. — Judicial Governance of “Industry Insiders” and Abuse of Internal Access Privileges The principal guiding significance of this case lies in the formal establishment by the Chinese judiciary of a dual accountability model combining “criminal liability + public-interest litigation liability” in respect of “industry insiders” who illegally access and sell citizens’ personal information by exploiting their positions. The defendants, acting as railway passenger service personnel, used internal ticketing systems to query and sell citizens’ high-speed rail travel information, including travel times, train numbers, seat information, departure locations, and destinations. Illegal gains amounted to approximately RMB 190,000 (approximately US$ 27,930). The court not only treated the abuse of professional position as an aggravating sentencing factor, but also ordered, through ancillary civil public-interest litigation, the deletion of data, public apologies, and compensation for damage to the public interest.
Beginning in January 2019, defendant Chen Moumou exploited his position as a railway station passenger service employee to query information regarding other persons’ high-speed rail travel through the railway ticketing system, including whether individuals had travelled by high-speed rail, travel times, train numbers, departure and arrival stations, seat details, and identification numbers. Such information was sold at prices ranging from RMB 10 to RMB 60 (approximately US$ 1.47 to US$ 8.82) per record. During periods when Chen Moumou was not on duty, he arranged for colleagues, including defendant Zeng Mou, to conduct queries on his behalf for fees ranging from RMB 5 to RMB 10 (approximately USD 0.74 to USD 1.47) per query. Certain illegally obtained personal information was subsequently sold to defendants including Lin Moumou for use in paid inquiries into the travel itineraries of performing artists and other individuals. By September 2021, Chen Moumou had obtained illegal proceeds totaling approximately RMB 190,000 (approximately US$ 27,930).
The Nanhai District People’s Court of Foshan City held that Chen Moumou and the other defendants had illegally obtained and sold citizens’ personal information by taking advantage of their professional positions, under particularly serious circumstances, thereby constituting the crime of infringing citizens’ personal information and warranting heavier punishment according to law. After considering the facts, circumstances, and consequences of the case, the court sentenced the defendants to fixed-term imprisonment ranging from three years and eight months to nine months, with certain suspended sentences of one year and six months, together with fines ranging from RMB 200,000 to RMB 14,000 (approximately US$ 29,400 to US$ 2,058). In respect of the ancillary civil public-interest litigation initiated by the procuratorial authorities, the court further ordered the defendants to pay public-interest damages ranging from RMB 200,000 to more than RMB 10,000 (approximately US$ 29,400 to USD 1,470), delete all illegally obtained personal information, and issue public apologies through national-level media outlets.
Typical Case 3: Huang Moumou et al. — Governance of Black and Grey Market Industrial Chains Involving Circumvention of Real-Name Authentication and Educational Data The principal guiding significance of this case lies in the Chinese judiciary’s express recognition that the use of technical means to circumvent official real-name authentication mechanisms, thereby obtaining educational and student-status information in bulk for profit-making purposes, constitutes the crime of infringing citizens’ personal information. The judiciary further demonstrated a “full-chain crackdown” approach toward associated black and grey market industrial chains. Defendants including Huang Moumou circumvented the real-name authentication system of China Higher Education Student Information and Career Center (“CHSI”) by fabricating identity card images and dynamic verification videos, subsequently downloading educational information in bulk for resale and profit. This conduct formed a complete criminal chain involving “forged identity documents — account registration — false verification — downloading and resale”. The judgment demonstrates that, even where the underlying information originates from public or official channels, if the acquisition method is deceptive and bypasses legally mandated security measures, such conduct constitutes unlawful infringement of citizens’ personal information, irrespective of whether the information was subsequently used in downstream offences such as fraud. The case also combined criminal penalties with ancillary civil public-interest litigation, ordering the defendants not only to serve prison terms and pay fines, but also to delete unlawfully held information, deregister infringing accounts, issue public apologies, and compensate for public-interest losses, thereby reflecting a governance approach aimed at “cutting off financial incentives and eliminating recidivism capacity” within black and grey market industries.
Since August 2021, defendant Huang Moumou accepted clients’ requests, through defendant Liu Moumou, to query educational information using names and citizen identification numbers. Defendant Li Moumou located corresponding identification photographs to create forged identity card images, while Huang Moumou and defendant Gao Mou rented mobile telephone numbers to receive SMS verification codes for registration of CHSI accounts. Huang Moumou then used the forged identity card images and technical means to pass CHSI registration verification procedures, downloaded the Electronic Registration Filing Forms for Ministry of Education Academic Certificates, and sold them for profit. At the time of the case, illegal proceeds obtained by Huang Moumou and others ranged from approximately RMB 300,000 to RMB 6,000 (approximately US$ 44,100 to US$ 882).
The Xicheng District People’s Court of Beijing held that Huang Moumou and the other defendants had violated relevant state regulations by illegally obtaining and selling citizens’ personal information under particularly serious circumstances, thereby constituting the crime of infringing citizens’ personal information. Taking into account the facts, circumstances, and consequences of the case, the court sentenced the defendants to fixed-term imprisonment ranging from three years and eight months to eight months, together with fines ranging from RMB 310,000 to RMB 10,000 (approximately US$ 45,570 to US$ 1,470). In the ancillary civil public-interest litigation brought by the procuratorial authorities, the court further ordered the defendants to issue public apologies through national-level media, delete unlawfully possessed personal information, deregister communication software used for infringement, and pay public-interest damages ranging from RMB 300,000 to RMB 6,000 (approximately USD 44,100 to USD 882).
Typical Case 4: Lin Moumou and Wang Moumou — Criminalisation Trends Concerning “Doxxing” Cyber Violence and “Social Engineering Databases” The principal guiding significance of this case lies in the Chinese judiciary’s establishment of a stringent enforcement model targeting the integrated conduct of “acquisition + public disclosure + incitement” in relation to emerging cybercrimes involving “doxxing” online violence. Defendants Lin Moumou and Wang Moumou illegally obtained more than 600 million items of citizens’ personal information data and established a “social engineering database” website containing more than 170 million data records for paid public searches. They further illegally utilized information networks to establish online groups disseminating unlawful and criminal content involving privacy infringements, insults, and abusive attacks against others. The court imposed concurrent punishment upon Lin Moumou for both the crime of infringing citizens’ personal information and the crime of illegally utilizing information networks, resulting in a combined sentence of seven years’ imprisonment. The judgment clearly conveys that the large-scale acquisition of citizens’ personal information already constitutes an independent serious offence, while the subsequent use of such information for public dissemination, incitement, and abusive online attacks separately constitutes the crime of illegally utilizing information networks. The cumulative punishment for both offences substantially increase the criminal costs associated with “doxxing” conduct.
Between 2023 and 2025, defendants Lin Moumou and Wang Moumou illegally acquired citizens’ personal information data through encrypted communication tools and other internet channels, subsequently selling such data for profit through methods including receipt of cryptocurrency payments. Investigations revealed that Lin Moumou had illegally acquired more than 600 million records of personal information data, while Wang Moumou had acquired more than 300 million records. During 2025, Lin Moumou and Wang Moumou, together with Wang Mou (handled separately), established a “social engineering database” website using illegally acquired personal information data. Investigations further established that the website database contained more than 170 million records of citizens’ personal information, and that the defendants had unlawfully provided personal information through the website on more than 1,300 occasions, while the website itself received more than 100,000 visits. Also during 2025, Lin Moumou, together with Wang Mou and others (handled separately), established online groups through encrypted communication tools and served as group administrators, disseminating unlawful and criminal content involving privacy infringements, insults, and abusive attacks against others. The group had more than 2,000 members.
The Haidian District People’s Court of Beijing held that Lin Moumou and Wang Moumou, together with others, had violated relevant state regulations by illegally acquiring and selling citizens’ personal information under particularly serious circumstances, thereby constituting the crime of infringing citizens’ personal information. The court further held that Lin Moumou, together with others, had established online groups for the commission of unlawful and criminal activities and disseminated unlawful and criminal information, thereby constituting the crime of illegally utilizing information networks. As Lin Moumou committed multiple offences, concurrent punishment was imposed according to law. Taking into account the facts, circumstances, and consequences of the case, the court sentenced Lin Moumou to six years and six months’ imprisonment and a fine of RMB 60,000 (approximately US$ 8,820) for the crime of infringing citizens’ personal information, and to one year’s imprisonment and a fine of RMB 10,000 (approximately US$ 1,470) for the crime of illegally utilizing information networks, with a combined sentence of seven years’ imprisonment and a total fine of RMB 70,000 (approximately US$ 10,290). Wang Moumou was sentenced to five years and six months’ imprisonment and a fine of RMB 50,000 (approximately US$ 7,350) for the crime of infringing citizens’ personal information.
Typical Case 5: Liang Moumou and Wang Moumou — Full-Chain Governance Model for “Personal Information Crime + Precision Fraud”: The principal guiding significance of this case lies in the Chinese judiciary’s establishment of a rigid adjudicative approach involving concurrent punishment and cumulative severe penalties for full-chain crimes combining “illegal acquisition of personal information + precision fraud”. Defendants Liang Moumou and Wang Moumou first infiltrated legitimate HPV vaccine reservation websites by implanting Trojan programs and illegally obtained more than 290,000 HPV vaccine reservation records. They subsequently created phishing websites, disseminated fraudulent text messages in bulk, impersonated doctors and customer service personnel, and carried out precision fraud schemes, thereby defrauding 51 victims of more than RMB 580,000 (approximately US$ 85,260). The court separately convicted and sentenced the defendants for both the crime of infringing citizens’ personal information and the crime of fraud, before imposing combined sentences. Liang Moumou received a sentence of twelve years’ imprisonment, while Wang Moumou received eleven years and nine months’ imprisonment — penalties substantially exceeding the maximum punishment available for either single offence alone. The judgment demonstrates that where the illegal acquisition of personal information forms a connected chain with downstream fraud offences as both means and purpose, judicial authorities will not absorb one offence into the other or impose punishment based solely upon the more serious offence but will instead insist upon concurrent punishment proportionate to each crime, thereby seeking to sever completely the conversion chain between illicit data industries and telecommunications fraud.
Between February and July 2022, defendants Liang Moumou and Wang Moumou jointly financed the purchase of Trojan programs through internet black and grey market industry platforms and implanted them into legitimate HPV (Human Papillomavirus) vaccine reservation and inoculation websites. Through such means, they illegally obtained administrator account credentials and passwords and subsequently accessed more than 290,000 HPV vaccine reservation order records stored on the websites. The two defendants later rented virtual hosting servers, uploaded unlawfully acquired website source code into domain service spaces, and created imitation phishing websites. Together with multiple accomplices operating under a division-of-labor arrangement, they disseminated fraudulent “successful vaccine reservation” text messages in bulk through SMS platforms, inducing reservation applicants to click phishing links contained within the messages. By impersonating doctors and customer service personnel and using false pretexts such as “price adjustments”, “priority reservations”, and “re-ordering discounts”, the defendants defrauded 51 victims of more than RMB 580,000 (approximately US$ 85,260).
The Hanjiang District People’s Court of Yangzhou City held that Liang Moumou and Wang Moumou had violated state regulations by infiltrating computer information systems through the implantation of Trojan programs and illegally obtaining citizens’ personal information under particularly serious circumstances, thereby constituting the crime of infringing citizens’ personal information. The court further held that the defendants had organized others to commit telecommunications network fraud through the use of mass text messaging, phishing websites, and other internet-based technical means, fabricating false HPV vaccine reservation scenarios to defraud unspecified victims of particularly huge sums, thereby constituting the crime of fraud. Concurrent punishment was therefore imposed according to law. Taking into account the facts, circumstances, and consequences of the case, the court sentenced Liang Moumou to eleven years’ imprisonment and a fine of RMB 100,000 (approximately US$ 14,700) for fraud, and to three years and six months’ imprisonment and a fine of RMB 50,000 (approximately US$ 7,350) for infringing citizens’ personal information, with a combined sentence of twelve years’ imprisonment and a total fine of RMB 150,000 (approximately US$ 22,050). Wang Moumou was sentenced to ten years and nine months’ imprisonment and a fine of RMB 100,000 (approximately US$ 14,700) for fraud, and to three years’ imprisonment and a fine of RMB 40,000 (approximately US$ 5,880) for infringing citizens’ personal information, with a combined sentence of eleven years and nine months’ imprisonment and a total fine of RMB 140,000 (approximately US$ 20,580).
Conclusion
The five typical cases collectively outline, in a systematic manner, the comprehensive logic and stringent position adopted by the Chinese judiciary in combating crimes involving infringement of citizens’ personal information. The cases emphasize full-chain governance, heightened supervision of key industries, strengthened platform governance responsibilities, and increased costs of non-compliance through mechanisms including concurrent punishment for multiple offences, public-interest litigation, and integrated remedies.
© 2026 - All rights reserved.

We use cookies to enable essential functionality on our website, and analyze website traffic. By clicking Accept you consent to our use of cookies. Cookies and Privacy Policy.

Your Cookie Settings

We use cookies to enable essential functionality on our website and analyze website traffic. For more information, read our Cookies and Privacy Policy below..

Cookie Categories
Essential

These cookies are strictly necessary to provide you with services available through our websites.

Analytics

These cookies collect information that is used in aggregate and in an anonymized form to help us understand how our website is being used and how effectively our site is performing.