• About Us
  • People
    • Matthew Murphy
    • Ellen Wang
    • Yu Du
    • Xia Yu
    • Sarah Xuan
  • Practice Areas
    • Intellectual Property
    • Technology
    • Corporate
    • International Trade
    • International Arbitration
  • Insights
  • Accolades
  • Locations
  • Contact Us
  • 中文

China Releases Draft Rules on Electronic Data Forensics for Comment

Published 29 May 2026 Xia Yu
On 22 May 2026, China’s Ministry of Public Security (“MPS”) released the Public Security Organs’ Electronic Data Forensics Rules (Draft for Comment) (“ Draft Rules”) to solicit public comment through 21 June 2026. As a fundamental overhaul of China’s legal framework for electronic data forensics, the Draft Rules build upon the 2019 iteration of the Public Security Organs’ Rules for Electronic Data Forensics in Criminal Cases (“Rules 2019”) to expand their scope of application from solely criminal investigations to encompass both criminal cases and administrative cases, and systematically upgrade due process protections. As digital transformation deepens, electronic data will play an increasingly critical role in law enforcement. The Draft Rules provide law enforcement authorities with clearer procedural guidance and more stringent compliance boundaries, while also offering data subjects stronger legal safeguards for their rights and interests.
Summary of the Draft Rules
The Draft Rules consist of 6 chapters and 61 articles, supplemented by seven standard forms. Chapter I (General Provisions) sets out the legal basis, scope of application, general principles and methods of forensics. Chapter II elaborates the requirements for electronic data inspection, the seizure and sealing of original storage media, as well as the circumstances, documentation and time limits for freezing electronic data. Chapter III (Extraction and Production of Electronic Data) specifies the requirements and protective measures for on‑site extraction and online extraction, and the procedures and approval requirements for production of electronic data. Chapter IV (Electronic Data Examination and Experiment) defines the circumstances under which examination is permitted, the requirements for examination, and the approval procedures and specific requirements for forensic experiments. Chapter V (Outsourced Inspection and Identification) addresses the circumstances in which outsourced inspection and identification are permitted and the requirements for expert reports. Chapter VI (Supplementary Provisions) clarifies key definitions, the evidentiary requirements for electronic data obtained through technical investigation measures, and the effective date of the Draft Rules.
The overall structure of the Draft Rules is more complete than that of the Rules 2019. While preserving the basic “extraction – examination – identification” workflow, the Draft Rules have reorganized the content concerning inspection, freezing, production and sampling forensics along the logical lines of criminal investigation and administrative fact‑finding, demonstrating a clear trend toward systematization and refinement. The revisions encompass: expansion of the scope of application; standardization of concepts relating to electronic data forensics; refinement of approval procedures; the addition of special forensic procedures for obtaining account credentials and private communication content; and the standardization of forensic documentation.
Due Process in the Digital Age
The Draft Rules establish dedicated approval and procedural requirements for two categories of special forensic actions – obtaining account credentials and accessing private communication content – reflecting the MPS’s institutional efforts to strike a balance between combating crime and protecting citizens’ rights in the course of electronic data forensics.
Article 8 provides that when law enforcement authorities need to enter account credentials for a smart terminal relevant to a case, the holder of the electronic data shall first provide the credentials. If the holder refuses to do so, authorities may, subject to approval by the responsible official at the county level or above, issue a special decision document, inform the holder or have a witness present, and then take appropriate measures to obtain the credentials. In exigent circumstances where delay would risk the destruction of the electronic data, authorities may take measures first but must complete the approval procedures within 24 hours. Article 34 provides that extraction of private communications such as text messages may, if the holder does not cooperate, be carried out only after obtaining approval from the responsible official at the county level or above and issuing a special decision document. Article 34 further provides that production of private communications such as email, where the holder does not cooperate and the law enforcement authorities need to obtain such communications from an internet service provider, requires approval from the responsible official at the city level or above, the issuance of a special decision document, and service of that document together with a notice of production on the internet service provider, with notice to the holder or in the presence of a witness.
Taken as a whole, the Draft Rules represent a shift in public security organs’ approach to electronic data forensics, moving from a “technical operations manual” toward a “digital code of procedure”. Forensics is no longer merely a matter of how technical personnel extract data; it is now a legal process involving approval authority, notification of data subjects’ rights, witness procedures, and documentation. Other provisions of the Draft Rules, including the distinction between on‑site extraction records and online extraction records, the mandatory use of integrity verification values (hash values), and the seven‑day deadline for handling storage media held for safekeeping, all reflect the trend toward proceduralizing. This transformation is of great significance for ensuring the admissibility of electronic data and protecting the legal rights of data subjects.
Chain of Custody Management Approaching International Forensic Standards
1. Systematic Integrity Verification and Write‑Protection Measures
The Draft Rules systematically mandate the use of integrity verification values. For example, during extraction of electronic data (Article 27), the integrity verification value of the electronic data must be calculated; during transfer of electronic data for examination (Article 41), the integrity verification value must be checked for consistency; and when electronic data is produced (Article 37), the producing party must attach the integrity verification value and an explanation of the methods used to protect data integrity. By systematically employing integrity verification values (hash values), the Draft Rules ensure that electronic data remains verifiable throughout its entire lifecycle – from extraction, transportation and storage to examination.
At the operational level, the Draft Rules specify several technical measures to protect the integrity of electronic data: during examination of electronic data (Article 42), access must be through a write‑blocker or by creating a forensic image; if a write‑blocker cannot be used and a forensic image cannot be created, the reasons must be documented, and the process must be recorded on video. When sealing a mobile phone or other original storage medium with wireless communication capabilities (Article 18), measures such as signal shielding or blocking must be taken to prevent remote deletion or tampering.
2. Standardisation of Sampling Forensics
Article 45 of the Draft Rules provides for sampling forensics in cases where electronic data is numerous and of the same nature, characteristics or function, and it is impractical to examine each item individually. With the approval of the responsible official at the county level or above, sampling may be conducted at a certain ratio or quantity. Sampling must follow objective and scientific principles, in accordance with relevant national or industry standards; where no such standards exist, it must use generally accepted statistical methods such as random sampling to ensure the representativeness of the sample, with an explanation of the scientific basis for the sampling. A record of the examination must be prepared, and the entire process must be recorded on video.
3. Alignment with International Forensic Standards
In terms of the precision and standardization of chain of custody management, the Draft Rules have achieved a high degree of consistency with internationally accepted forensic standards.
The principal international standard for electronic data forensics is ISO/IEC 27037, jointly issued by the International Organisation for Standardisation (ISO) and the International Electrotechnical Commission (IEC). ISO/IEC 27037 focuses on the early stages of the digital evidence lifecycle and sets out requirements for the identification, collection, acquisition and preservation of electronic data. The core purpose of the standard is to minimize the risk of evidence tampering by requiring strict chain‑of‑custody documentation and the use of cryptographic hashing (such as SHA‑256) to ensure the integrity, authenticity and reliability of digital evidence, thereby safeguarding its admissibility in court and in cross‑border mutual legal assistance.
The Draft Rules align with ISO/IEC 27037 in the following respects:
1) Identification: Article 10 requires that electronic data inspection analyses the scope of electronic data that needs to be extracted and demonstrate the content and status of the data.
2) Collection: Articles 25 to 27 set out detailed requirements for protective measures and operational procedures during on‑site extraction of electronic data.
3) Acquisition: Article 29 requires that extraction records specify the source of the electronic data, the method of extraction, and the integrity verification value.
4) Preservation: Articles 14 to 19 systematically regulate the seizure, sealing and holding for safekeeping of original storage media.
Comparison with Electronic Data Forensics Rules in the EU and the US
1. Divergent Approaches to Cross‑Border Evidence Production
The European Union has established a harmonized direct evidence‑production mechanism within the EU through its Regulation (EU) 2023/1543 on European Production and Preservation Orders for Electronic Evidence in Criminal Proceedings, which will take full effect on 18 August 2026. Under the Regulation, a law enforcement authority in one Member State may issue a European Production Order directly to a service provider in another Member State, requiring the production of electronic evidence relevant to a criminal investigation. This “direct‑to‑service‑provider” mechanism bypasses traditional mutual legal assistance channels and significantly reduces the time required for cross‑border evidence production.
The United States, through the Clarifying Lawful Overseas Use of Data Act, has adopted a data‑controller model, under which US law enforcement authorities may compel a domestic service provider to produce data stored on servers outside the United States.
In contrast, China’s current approach relies primarily on the cooperation of data subjects and traditional mutual legal assistance channels. The Draft Rules address mainly domestic evidentiary procedures, with limited provisions on cross‑border evidence production. Article 38 deals with inter‑regional evidence production, providing that the law enforcement authority in the place where the case is being investigated may, through a cooperation mechanism, delegate the evidence production to the local authority, who will transmit the electronic data through the police information system. Article 30 provides that electronic data located on a remote computer information system outside China may be extracted online through account credentials voluntarily provided by the suspect or alleged offender. These provisions depend mainly on the cooperation of the data subject or domestic cooperation mechanisms, and do not involve compulsory measures directed at foreign service providers.
2. Divergent Regulatory Approaches to Forensic Procedures
The legal framework for electronic data forensics in the United States is rooted in the Fourth Amendment to the US Constitution, which provides that a search and seizure of electronic data constitutes a “search” for constitutional purposes, generally requiring probable cause and a warrant. The most influential US cases are Riley v. California (2014), in which the US Supreme Court held that searching the contents of a mobile phone generally requires a warrant, and that obtaining long‑term cell‑site location information also requires a warrant.
In contrast to the US approach of developing rules on a case‑by‑case basis through judicial decisions, the Draft Rules adopt a legislative approach through codified rules, replacing the US model’s judicial warrant with a pre‑action approval procedure. In terms of rights protection, the US model emphasizes judicial checks on law enforcement, whereas the Draft Rules primarily rely on internal hierarchical approvals within law enforcement authorities and a multilayered documentation system to safeguard procedural legitimacy. This difference reflects the divergent philosophies of power allocation in criminal procedure design between China and the United States.
3. Implications for Practice
For multinational enterprises, understanding these differences is of considerable importance. First, in Chinese electronic data forensics, internal approval documentation (decision documents, records, inventories, etc.) is key evidence of the lawfulness of the forensic process. If a defense lawyer can identify procedural defects in the approval process, it may constitute a viable challenge to the admissibility of the evidence. Second, the mandatory use of integrity verification values (hash values) under the Draft Rules means that where law enforcement authorities fail to calculate or record the integrity verification value during the forensic process, or where the verification value is found to be inconsistent upon transfer, the integrity of the evidence may be questioned. Third, in cross‑border data flows, Chinese enterprises facing evidence production requests from multiple jurisdictions must take into account the different levels of procedural protection across jurisdictions and design their compliance strategies accordingly.
Conclusion
The release of the Draft Rules marks a milestone in China’s evolution from a “criminal‑only” evidence rule toward a “general code of procedure” for electronic data forensics. From an international comparative perspective, the Draft Rules align with global trends in both the innovation of due process protections and the systematic upgrading of technical standards, while preserving a regulatory pathway that is adapted to China’s legal traditions and law enforcement system.



© 2026 - All rights reserved.

We use cookies to enable essential functionality on our website, and analyze website traffic. By clicking Accept you consent to our use of cookies. Cookies and Privacy Policy.

Your Cookie Settings

We use cookies to enable essential functionality on our website and analyze website traffic. For more information, read our Cookies and Privacy Policy below..

Cookie Categories
Essential

These cookies are strictly necessary to provide you with services available through our websites.

Analytics

These cookies collect information that is used in aggregate and in an anonymized form to help us understand how our website is being used and how effectively our site is performing.