Author Archives: ZSL2024

The Evolution of Credit Assessment from “Judging Character” to “Examining Records” and Its Implications for China’s Credit Economy

When a person falls behind on a loan payment, it will naturally affect their next loan application. But matters become more complicated when loan delinquencies, contractual breaches, administrative penalties, judicial enforcement actions, and platform rule violations are all placed within a single framework of “credit.” Although these records may all appear to be related to “credit,” they are fundamentally different in nature. Loan delinquency is primarily a matter of financial risk; contractual breach is primarily a matter of civil liability; an administrative penalty is primarily a matter of violating administrative law; judicial enforcement primarily concerns compliance with legally binding instruments; and platform violations primarily concern the governance of platform rules. All of these may constitute negative records, but the fact that they are negative does not mean they should all be interpreted as evidence that “this person is untrustworthy,” still less as proof that “this person has bad character.”

This is precisely the issue that China must guard against as its credit economy develops: once the concept of credit becomes overly expansive, specific records of conduct from different fields can easily be blended into a vague label attached to a person’s character.

The history of credit reporting in the United States provides a useful point of reference. Early American credit reporting also relied on character, reputation, lifestyle, and local opinion. Put simply, creditworthiness was judged by assessing a person’s “character.” Later, however, as the market expanded, credit-reporting data accumulated, legal regulation improved, and scoring technologies developed, mainstream financial credit reporting gradually shifted toward standardized records such as account status, debt burden, delinquencies, and repayment history.

In other words, the modernization of credit assessment does not mean incorporating more character judgments into credit. It means limiting credit assessment to records of conduct that are more specific, more verifiable, and more closely related to risk.

I. Early Credit Reporting: “Character Judgments” in a Market of Strangers

In a society of acquaintances, determining whether someone can be trusted with a loan often requires no complex data. You know where the person lives, what they normally do, what kind of reputation they have, and whether they have ever failed to repay a debt. Among acquaintances, credit depends on reputation and personal relationships.

In the nineteenth century, however, the American market expanded rapidly, and transactions were no longer confined to local circles of acquaintances. Merchants might conduct business with people far away, while creditors increasingly dealt with strangers. A new question therefore arose: if I do not know you, how can I tell whether you will repay your debt?

Today, we can examine accounts, transaction records, debt levels, and histories of delinquency. In early America, however, such standardized data systems had not yet been established. Credit-reporting agencies therefore began collecting information about borrowers on behalf of creditors, including their property, business conditions, local reputation, personal character, lifestyle, and even neighborhood gossip.[1]

In other words, early credit reporting transformed the reputation-based judgments of an acquaintance society into written reports that could be sold to distant creditors.

II. Why Did Early Credit Assessment Become a Matter of “Judging Character”?

Early credit reporting became moralized not because credit reporting inherently required an assessment of morality, but because reliable data were unavailable at the time.

There were no unified account records, no long-term repayment histories, and no information systems capable of sharing data across regions. Creditors could therefore ask only rougher questions: Is this person diligent? Do they exercise restraint? Do they have undesirable habits? Do they have a good local reputation? Do they conduct business honestly?

Today, these questions may appear to be assessments of character, but at the time they were believed to be related to repayment risk. People assumed that someone who lacked restraint, stability, or diligence would also be more likely to fail to repay a debt on time.

Early credit reports were therefore unlike modern credit reports, which consist primarily of accounts and figures. They were more like brief biographies of a person’s character. Rather than merely recording whether someone had ever been delinquent, they sought to determine whether that person was fundamentally worthy of trust.

This was the moralization of early credit: credit was not merely about debt, but about the person as a whole.

The problem lay precisely here. Local rumors could be inaccurate, personal impressions could be biased, and so-called “reputation” could be shaped by social prejudices involving class, gender, race, religion, and other factors. Once such evaluations were entered into credit reports, they could be packaged as “credit facts” and affect a person’s opportunities in the marketplace.[2]

III. Modern Financial Credit Reporting: From “Evaluating the Person” to “Recording Conduct”

As consumer credit became increasingly widespread in the United States and financial markets continued to expand, local reputation and hearsay could no longer support credit decisions on a nationwide scale.

Banks, retailers, and financial companies needed information that was faster, more standardized, and easier to compare. The credit-reporting system therefore gradually evolved from small local agencies into nationwide databases, and the focus of credit assessment began to change.[3]

The question used to be: Does this person have good character?

The question later became: Has this person made repayments on time?

Previously, the relevant factors were reputation, lifestyle, and local opinion.

Later, the focus shifted to account status, debt burden, delinquencies, repayment history, and records of credit inquiries.

This was the “de-moralization” of mainstream financial credit reporting. It should be noted, however, that de-moralization does not mean that credit is entirely neutral, nor does it mean that credit systems no longer evaluate people. It simply means that mainstream financial credit reporting no longer directly assesses whether someone is a “good person.” Instead, it records whether the person has fulfilled their obligations within financial relationships.

Modern credit reporting has not ceased to evaluate people; it has simply adopted a different method of evaluation. Rather than using the language of character, it evaluates people through records of conduct and probabilities of risk.

IV. How Did Law and Technology Change Credit Assessment?

The transformation of American credit reporting resulted not only from market development, but also from legal regulation and technological progress.

On the one hand, the law began to restrict the use of certain identity-related factors in credit decisions. In the past, for example, women applying for credit could face restrictions because of their marital status or family role. Later, the Equal Credit Opportunity Act and related rules restricted credit discrimination based on factors such as sex and marital status. This helped redirect credit assessment toward information genuinely related to the risk of nonperformance, such as income, debt, and repayment history.[4]

On the other hand, credit-scoring technologies emerged. Credit scoring compresses complex account records into a single score or risk category, enabling financial institutions to assess risk more quickly, consistently, and at lower cost.[5]

This further accelerated the shift from narratives about character to calculations of risk.

Technology, however, is not inherently fair. In the past, a credit report might have stated that “this person is of poor character.” Today, a system may simply assign the person a low score. The language and format have changed, but the function of screening remains.

V. Credit Did Not Disappear; It Was “Diverted into Different Channels”

One of the most common misunderstandings about the modernization of American credit reporting is the belief that it has completely eliminated moral judgment. In fact, it has not.

Mainstream financial credit reporting has increasingly centered on records of contractual performance. Yet in areas such as housing, employment, insurance, and background checks, consumer reports may still contain extensive information used to determine a person’s eligibility.[6]

When renting a home, for example, a landlord may review a tenant-screening report. The report may contain credit history, rent-payment records, eviction records, and civil or criminal records. The problem is that an eviction record does not necessarily mean that a tenant deliberately breached an agreement. It may have resulted from a dispute, settlement, dismissal of the case, or even an incomplete record. Once it enters a screening system, however, it may be reduced to the conclusion that “this person presents a risk.”

The same applies to employment. Employers may examine criminal records, educational backgrounds, professional licenses, and employment histories. Certain criminal records may genuinely be relevant to the risks associated with particular positions. But if an employer fails to distinguish between the nature of the offense, how long ago it occurred, and its relevance to the position, and instead excludes anyone with any record, a single event from the past can become a long-term label.

American credit reporting therefore did not move from moralization to complete de-moralization. Instead, an institutional division occurred. On one side is mainstream financial credit reporting, which primarily assesses lending risk. On the other side are specialized consumer reports, which continue to perform eligibility-screening functions in housing, employment, insurance, and other contexts.

Evaluation has not disappeared. It has merely changed its location, form, and language.

VI. Implications for China: The Development of the Credit Economy Must Have Boundaries

As the market economy, online transactions, and the platform economy develop, the scope of transactions continues to expand, and many transactions no longer take place among acquaintances. Businesses, platforms, financial institutions, consumers, and government departments all require more verifiable information to reduce transaction costs, identify the risk of nonperformance, and improve regulatory efficiency. The 2025 Opinions on Improving the Social Credit System, issued by the General Office of the Communist Party of China Central Committee and the General Office of the State Council, also explicitly states that the social credit system is a foundational institution of the market economy. It calls for the establishment of a social credit system that covers all types of entities, operates under unified institutional rules, and is jointly developed, shared, and utilized, while supporting the unified national market and high-quality development.[7]

The construction of a credit system therefore has a legitimate rationale. Financial credit reporting can help banks assess borrowers’ risks; corporate credit information can help counterparties understand the condition of a business; and the disclosure of administrative penalties and judicial enforcement information can improve regulatory transparency and encourage compliance with legal obligations.

The problem, however, is that the construction of a credit system must not turn “credit” into an excessively broad concept.

Records of different kinds may be used, but they must not be used as though they were equivalent. Financial delinquencies, contractual breaches, administrative penalties, judicial enforcement actions, and platform violations correspond to different risks, responsibilities, and governance contexts. They cannot all be simplistically interpreted as evidence that “this person is untrustworthy.”

This is precisely the lesson offered by the history of American credit reporting: the direction of modern credit assessment is not to incorporate more judgments about character, but to confine credit to records of conduct that are specific, relevant, and verifiable.

The development of China’s credit economy should therefore observe at least three boundaries.

First, the boundary of purpose. Credit information should serve specific contexts and should not be used arbitrarily across different contexts. Financial credit reporting should be used to assess lending risk; information about administrative penalties should be used for administrative supervision; judicial enforcement information should be used to promote compliance with legally binding instruments; and records of platform violations should be used to maintain order on the platform.

Second, the boundary of information. Information included in credit assessments should be related to the specific risk concerned. Lifestyle, identity characteristics, and general moral conduct should not be incorporated into credit judgments.

Third, the boundary of procedure. Whenever credit information may affect lending, housing, employment, business operations, or public services, individuals and entities should be guaranteed the rights to access the information, raise objections, request corrections, and seek remedies.

In a word, the central task in developing a credit economy is not to incorporate every negative record into the concept of credit, but to distinguish between records of specific conduct and judgments about a person’s overall character.

Conclusion: Credit Is Not Better When It Is Broader, but When It Is Clearer

The history of American credit reporting shows that credit institutions originally contained a strong element of character assessment. Later, mainstream financial credit reporting gradually shifted from “judging character” to “examining records of performance,” and from character judgments to risk assessment.

This does not mean, however, that credit assessment has become entirely neutral, nor does it mean that moral judgments have completely disappeared. Modern credit increasingly affects people’s opportunities through records, scores, models, and reports.

What truly matters, therefore, is not making credit omnipresent, but ensuring that it is used where it properly belongs.

Credit can help markets reduce risk, but it must not become an all-purpose tool for judging people.

Credit can record specific acts of performance or nonperformance, but it must not be casually elevated into a judgment about character.

Credit can serve specific contexts, but it must not expand without limit across different contexts.

In a word, the central aim of a credit system is not to make the concept of credit ever broader, but to make its boundaries ever clearer.

References

[1] Josh Lauer, Creditworthy: A History of Consumer Surveillance and Financial Identity in America, 2017.

[2] Jonathan Weinberg, “Know Everything That Can Be Known about Everybody: The Birth of the Credit Report,” 2018.

[3] Mark Furletti, “An Overview and History of Credit Reporting,” 2002.

[4] Consumer Financial Protection Bureau, “Equal Credit Opportunity Act.”

[5] Federal Reserve, “Report to the Congress on Credit Scoring,” 2007.

[6] CFPB, “Tenant Background Checks Market Report,” 2022.

[7] General Office of the Communist Party of China Central Committee and General Office of the State Council, Opinions on Improving the Social Credit System, 2025.

Note: The author is Shanli Zhang. He is a doctoral student at the Law School of Shandong University. This article is a popularized version of the working paper titled From “Character” to “Risk”: Limited De-moralization, Eligibility Screening, and Boundary Governance in the History of American Credit Reporting. WeChat: 18811157736. Comments and corrections are welcome.

After You Click “Agree,” Who Should Be Responsible for Your Data—How MyData and Corporate Responsibility Can Build a Privacy Governance Framework for the AI Era

Editor’s Note: This article is an extension of “Latest Perspective | Don’t Cram Privacy Risks into a Single “Agree” Button—Companies Should Bear Their Share of Responsibility” The previous article discussed the limitations of the “notice-and-consent” mechanism in the AI era, arguing that privacy protection should not depend primarily on individuals reading terms and assessing risks; instead, greater responsibility should be placed on the companies that control data and algorithms. Building on that discussion, this article introduces the MyData concept and explores how corporate accountability can be combined with individual autonomy over personal data. On the one hand, companies must not treat user consent as a basis for avoiding liability. On the other hand, mechanisms such as personal data stores, data portability, and intelligent agents should give individuals genuine and continuous control over their data. The article’s central argument is that privacy governance in the AI era should not require a choice between “individual responsibility” and “corporate responsibility.” Instead, it should establish a collaborative framework based on “individual control, corporate accountability, and technological assistance.”

Daniel J. Solove is a professor at the George Washington University Law School in the United States whose research focuses primarily on privacy, information technology, and legal governance. In his Wall Street Journal article “How Can We Protect Our Privacy in the Age of AI?”, Solove discusses the new risks to personal privacy arising from the development of artificial intelligence. The internet, smartphones, and digital platforms continuously collect personal data, while AI can combine and analyze those data to infer sensitive information that individuals have never directly disclosed. Consumers may share only records of ordinary purchases, such as soap or beverages, yet algorithms may use those records to infer their health conditions and political leanings.[1]

Solove argues that the current privacy regime places too much responsibility on consumers. Faced with vast numbers of privacy policies, authorization pop-ups, and data-processing rules, ordinary people have neither enough time to read them individually nor the ability to determine how their data will be combined and used. AI further increases the complexity of data-based inferences. Even when consumers know what information they have provided, they cannot accurately predict what companies may derive from it.

At first glance, this view appears to be somewhat at odds with the individual autonomy over personal data emphasized by MyData. Solove is cautious about placing responsibility for data control on consumers, whereas MyData advocates using technological and institutional arrangements to return control over personal data to individuals. The MyData Declaration identifies individual empowerment, control over data, and more balanced relationships between people and organizations as important objectives.[2]

Closer analysis reveals that Solove’s emphasis on corporate responsibility and the MyData philosophy are highly complementary. MyData addresses individuals’ lack of data-management tools and meaningful control, while Solove’s approach to corporate accountability addresses the problem of companies using technological complexity to shift responsibility onto individuals. Combining the two can respond to concerns that consumers are incapable of bearing the burden of privacy protection alone, while also providing a more comprehensive data-governance framework for the next-generation data economy, particularly during the MyData 2.0 stage.

I. The Core Connection: Different Paths Toward the Shared Goal of Ending the Failure of “Informed Consent”

Solove’s position and the MyData philosophy share a common target of criticism: the existing “notice-and-consent” model. Under this model, companies use privacy policies and user agreements to explain their data-processing practices to consumers. Once users click “Agree,” companies obtain permission to collect and use their data.

This system assumes that consumers can understand the terms, assess the risks, and anticipate the consequences of data use. In reality, consumers encounter large numbers of authorization pages every day. Privacy policies are usually lengthy, while data-processing activities involve multiple platforms, systems, and partner organizations. Individuals find it difficult to read every policy carefully or continuously track who retains their data, how those data are used, and how long they are stored.

Solove has described this problem as “privacy self-management and the consent dilemma.” He points out that relying on individual consent to manage privacy has clear limitations and that privacy law should not depend excessively on consumers’ personal choices.[3] The development of AI further magnifies those limitations. When users consent to a company’s collection of an ordinary piece of data, they have little way of knowing whether the company will combine it with other information or whether an algorithm will use it to infer sensitive information concerning health, religion, or political views.

In Solove’s view, companies satisfy formal notification requirements through lengthy privacy statements, while the actual burden of protecting privacy falls on consumers. When problems arise, companies may also justify their conduct by arguing that “the user already consented.” A user’s click of the consent button can show only that the user accepted the conditions presented at that time. It can hardly prove that the user understood every possible future use of the data or every inference that an algorithm might draw.

MyData criticizes the same model from the perspective of data-control structures. The current data ecosystem is centered on companies. Once users grant authorization, their personal data generally enter corporate servers, where companies retain, analyze, and use them over extended periods. Users have little ability to monitor the continuing flow of their data and lack practical means to modify permissions, stop data use, or transfer their data at any time.

MyData seeks to shift data governance from a company-centric model to a human-centric one, enabling individuals to access, manage, and use data concerning themselves and to understand how those data flow.[4] Users should be able to decide who may use their data and for what purposes, and to modify or withdraw those decisions in response to changing circumstances. In this way, personal data can be freed from the isolated silos of different corporate systems.

Solove focuses on companies’ use of “consent” to shift responsibility, while MyData focuses on individuals’ loss of meaningful control after they have “consented.” Together, these perspectives demonstrate that a one-time click of the consent button can no longer support privacy governance in the AI era. User authorization may constitute a condition for a company’s use of data, but it cannot serve as a basis for exempting the company from responsibility. A new governance model must strengthen both individuals’ continuing control and companies’ continuing responsibilities.

II. The Core Difference: A “Defensive Shield” and an “Empowerment Engine”

Solove and MyData place different emphases on possible solutions. Solove gives greater weight to risk prevention and corporate accountability. He argues that assigning responsibility for data control to consumers is deeply problematic because ordinary people have very limited attention, time, and professional expertise and cannot manage the complex risks created by AI-generated inferences.

Even when the law gives consumers more choices and consent buttons, users still struggle to identify discrimination, errors, and excessive analysis embedded in algorithmic design. Solove advocates using data minimization, technological review, algorithmic accountability, and legal liability to build a “defensive shield” for consumers. When companies’ use of data or AI algorithms creates an unreasonable risk of harm, they should bear the corresponding responsibility.

In his article, Solove draws on the historical experience of the food, pharmaceutical, and automobile industries. Food and automobiles once presented serious safety problems. Only after the law established systems for inspection, testing, and liability did companies acquire stronger incentives to improve product safety.[1] Under the same logic, digital technologies and AI should undergo privacy and safety reviews before being placed into use, and companies should be held accountable when their algorithms cause harm.

MyData places greater emphasis on individual empowerment, with the central objective of returning control over data to individuals. Through data portability rights and personal data stores, individuals can aggregate, manage, and use their own data and choose the parties to which those data will be provided according to specific needs. They can also restrict the scope of data use, stop data flows when necessary, or transfer their data to other services.

The MyData white paper describes this as a human-centric model for the use of personal data and emphasizes the construction of an interoperable data ecosystem in which individuals participate in exercising control.[4] Under this model, individuals are transformed from passive sources of data into active participants in data relationships. MyData is therefore more akin to an “empowerment engine,” focused on improving individuals’ ability to manage and use their data.

The two approaches also differ in the emphasis they place on the value of data. Solove focuses primarily on the risks associated with data, with the aim of reducing excessive corporate data collection and preventing algorithms from harming individuals.

MyData also recognizes the value of data as an asset and a factor of production, seeking to enable data to flow under conditions that are secure, transparent, and subject to individual control. Individuals can use their multidimensional data to obtain fairer credit assessments and more personalized services that better reflect their actual circumstances.

III. Building a Unified Framework: Deep Integration of Sovereignty and Accountability

Combining MyData with Solove’s approach to corporate responsibility can produce an integrated model consisting of “underlying autonomy, overarching accountability, and intelligent agents.” Within this framework, individuals possess meaningful control over their data, companies cannot use user consent to avoid responsibility, and technological tools help reduce the difficulty individuals face in managing their data.

The first component is the infrastructure layer, which establishes personal data sovereignty based on personal data stores. Users’ core behavioral data can be stored in personal data stores (PDSs) or corresponding decentralized nodes, reducing the unrestricted accumulation of data by centralized companies. At the same time, users possess direct, operational control over “cutting off data flows” and “porting and transferring data,” thereby implementing the “right to deletion” and the genuine control supported by Solove.

The second component is the regulatory baseline layer, which removes the liability-exempting effect of “consent.” “User consent” is no longer a justification for exempting companies from responsibility. Even when users authorize a company to use their data through MyData, the company must still bear strict legal responsibility if its AI algorithm produces discrimination—for example, by misusing nonfinancial data in credit-technology assessments—or makes out-of-scope inferences about sensitive information. This addresses Solove’s concern that “ordinary people cannot anticipate AI risks.”

The third component is the implementation and agency layer, consisting of AI-powered personal data fiduciaries. Solove argues that giving users control is unworkable because the technology is too complex. The key to resolving this contradiction is to use AI to counter AI. Under the unified framework, users do not need to read the terms personally. A “personal AI agent” embedded in the PDS system serves as a digital-era “lawyer” or “fiduciary.” Based on the user’s broad preferences, it automatically negotiates terms with companies’ AI systems and applies data-minimization filters.

The fourth component is the application layer, involving native data-driven credit technology and value assessment. Historically, the U.S. credit system of the 1970s and 1980s was “technology-driven,” having been built on early information-technology architectures. Today’s global innovations, particularly those in China, are instead natively “data-driven.” Under this unified framework, the development of modern credit technology, or CreditTech, will become healthier. Through MyData, users can aggregate their multidimensional data and use them to demonstrate their creditworthiness to B2B service providers or financial institutions. When institutions process those data, however, they must be subject to requirements such as the “pre-market algorithm review” advocated by Solove. This approach not only prevents unlawful inferences about sensitive information but also fully satisfies the demanding requirements of international financial standards, eliminating overly generalized and unprofessional labels.

Conclusion

Daniel J. Solove identifies an exceptionally important problem: we should not expect exposed and defenseless consumers to protect themselves. By combining his model of “strong accountability” with MyData’s model of “strong autonomy,” we can arrive at an ideal solution. MyData provides the tools and vault—the PDS—for managing data, while Solove’s accountability regime surrounds that vault with an impenetrable, high-voltage legal barrier. Under this unified framework, data can remain securely under individual control while also being used with confidence to support economic innovation in the AI era.

References

[1] Solove, Daniel J. “How Can We Protect Our Privacy in the Age of AI?” Chinese edition of The Wall Street Journal,

https://cn.wsj.com/articles/ai-privacy-laws-data-b272b29f?mod=cn_feature_1_pos_4.

[2] MyData Global. “MyData Declaration.” https://mydata.org/participate/declaration/.

[3] Daniel J. Solove, “Privacy Self-Management and the Consent Dilemma,” 126 Harv. L. Rev. 1880 (2013).

[4] Poikola, Antti, et al. MyData: An Introduction to Human-Centric Use of Personal Data. Third Updated English Edition, MyData Global, 2020.

Note: The author, Shanli Zhang, is a doctoral student at Shandong University Law School and a research assistant to Dr. Xinhai Liu. His research focuses on personal data and personal privacy protection. WeChat: 18811157736. Comments and corrections are welcome.

Two Tracks and Three Pathways A Comprehensive Guide to Three Concurrently Introduced “Credit Repair” Policies That Most People Confuse

As the economy and society continue to develop and the credit system is gradually improved, credit repair has appeared with increasing frequency in policy discussions and public discourse. Public attention has risen significantly, particularly following the recent introduction by the People’s Bank of China of policy arrangements concerning “one-time credit repair.”[1][2] At the same time, however, there have been widespread misunderstandings that conflate “financial credit repair” with “public credit repair.” To address this confusion, this article uses a “two-track, three-pathway” framework to systematically explain the differences between financial credit repair and public credit repair in terms of their governing authorities, applicable parties, and repair mechanisms, thereby helping the public avoid conceptual confusion when interpreting and using these policies.

I. Background

China began gradually establishing its social credit system in the early 2000s and has continued to improve it alongside economic and social development. On this basis, credit repair has progressively developed into a “two-track, three-pathway” framework: financial credit repair led by the People’s Bank of China, together with the National Development and Reform Commission pathway and the market regulation pathway within public credit repair. This framework is shown in Figure 1:

Figure 1 Categories of Credit Repair in China

As shown in Table 1, financial credit repair is primarily led by the People’s Bank of China and constitutes an important component of China’s financial infrastructure, consistent with internationally accepted principles of credit-reporting governance. It focuses on correcting financial-behavior data concerning individuals and enterprises, such as records of overdue loans and credit-card payments. It generally affects access to financial services and restores financial credit through information correction or updating, adjustments to display rules, or removal upon expiration in accordance with laws and regulations. Public credit repair, by contrast, is led by authorities including the National Development and Reform Commission and the State Administration for Market Regulation. It focuses on social governance and compliance constraints and generally restores an entity’s social credit by ending the public disclosure of relevant information and lifting restrictions after the entity has corrected its misconduct and fulfilled its obligations. Both systems emphasize providing an “opportunity to correct mistakes,” but they differ in their scope of application and the boundaries of their respective mechanisms.

Table 1 The “Dual-Track System”: The Same Term with Different Meanings

II. The Background, Development, and Authoritative Policy Positions of the Three Major Credit Repair Systems

China’s credit repair system is administered by multiple government departments and primarily comprises the financial credit system, the public credit system led by the National Development and Reform Commission, and the market regulation system led by the State Administration for Market Regulation. Although all three systems involve credit repair, they differ in their backgrounds, development paths, and authoritative policy positions.

(I) Financial Credit Repair by the People’s Bank of China: From “Absolute Recordkeeping” to “Policy-Based Relief”

1. Background and Origins, 1999–2013

China’s financial credit-reporting system began relatively early. A credit-reporting administration was established as early as 1999, primarily to address information asymmetry in financial markets and assist financial institutions in assessing borrowers’ credit risks. During this period, the credit-reporting system was centered on “faithful recordkeeping,” requiring financial institutions to record the credit histories of individuals and enterprises fully and accurately in order to prevent financial risks. The concept of credit repair had not yet been clearly defined, and the system focused solely on the objective recording and management of credit information.

2. Development Path, 2013–2024

The promulgation of the Regulation on the Administration of the Credit Reporting Industry in 2013 marked a new stage in the development of China’s financial credit system. The Regulation provides that adverse personal information must be retained for five years from the date on which the relevant adverse conduct or event ends and must be deleted in accordance with the law after the five-year period expires.[3] This is not equivalent to the “arbitrary deletion of records”; rather, it is a rules-based removal process following the expiration of a statutory retention period. Within this framework, “active repair” in the traditional sense is reflected primarily in mechanisms such as information correction, dispute resolution, and adjustments to display rules.

3. Authoritative Policy Position, 2025

On October 27, 2025, Pan Gongsheng, Governor of the People’s Bank of China, announced that the central bank would implement a “one-time personal credit relief policy” in early 2026.[4] The policy is primarily directed at borrowers who defaulted on small consumer loans because of the pandemic or other force majeure events but have since fulfilled their repayment obligations. The relevant default information of eligible borrowers will be subject to policy-based adjustment in the credit-reporting system in accordance with applicable rules. On December 22, 2025, the People’s Bank of China issued the Notice on Arrangements for Implementing the One-Time Credit Repair Policy, further clarifying the applicable conditions and operational arrangements. It should be emphasized that the policy provides for eligible overdue information to be “excluded from display in accordance with applicable rules,” rather than permitting “paid deletion” or “whitewashing.” It is also a policy-based relief arrangement that eligible individuals may enjoy automatically without submitting an application.

(II) Public Credit Repair by the National Development and Reform Commission: From “Across-the-Board Sanctions” to “Tiered and Classified Restructuring”

1. Background and Origins, 2014–2018

With the issuance of the Planning Outline for the Development of the Social Credit System (2014–2020) in 2014, China began constructing a credit system covering the whole of society.[5] During this period, the Chinese government focused on promoting social integrity and establishing a cross-departmental joint disciplinary mechanism against untrustworthy conduct that covered the whole of society. By publicly disclosing information about untrustworthy conduct, restricting certain rights and interests of untrustworthy entities, and implementing disciplinary measures, the government sought disciplinary measures, the government sought to compel such entities to comply with laws and regulations and fulfill their social responsibilities.

Public credit repair was not clearly defined at the outset. Instead, the emphasis was placed on sanctioning and recording untrustworthy conduct. Once such conduct was confirmed, it would be recorded and publicly disclosed on the Credit China website. Repair mechanisms during this stage were relatively preliminary and relied mainly on untrustworthy entities applying for removal from a “blacklist” after proactively correcting their misconduct.

2. Development Path, 2019–2024

After 2019, as the social credit system was further improved, the National Development and Reform Commission began gradually adjusting the measures used to sanction untrustworthy conduct and introduced more flexible credit repair models. In particular, a repair model under which an application could be made once the misconduct had been corrected began to be implemented. This model allowed untrustworthy entities, after proactively correcting their conduct and fulfilling their statutory obligations, to apply to the relevant authorities to end the public disclosure of the relevant information and lift associated restrictions.

3. Authoritative Policy Position, 2025

On November 20, 2025, the National Development and Reform Commission issued the Measures for the Administration of Credit Repair, which will formally take effect on April 1, 2026.[6] The Measures provide more systematic and detailed rules for public credit repair, clearly specifying the repair standards and time limits applicable to different records of untrustworthy conduct. They also introduce, for the first time, a “tiered and classified” management model for information concerning untrustworthy conduct, under which different repair periods are established according to the seriousness of the misconduct. The introduction of this policy not only improves the precision of public credit repair administration but also provides untrustworthy entities with fairer opportunities.

(III) Credit Repair by the State Administration for Market Regulation: An Important Component of the Public Credit System

1. Background and Origins, 2014–2021

The credit repair policies of the State Administration for Market Regulation constitute an important part of the public credit system and are specifically directed at market entities. In the early stages, market regulators supervised enterprises through instruments such as the List of Enterprises with Abnormal Operations and the List of Seriously Untrustworthy and Unlawful Entities. The aim was to increase overall public awareness of creditworthiness and compliance with the law through transparent information disclosure and disciplinary mechanisms.

2. Development Path, 2021–2024

In 2021, the State Administration for Market Regulation issued the Measures for the Administration of Credit Repair in Market Regulation, marking the institutionalization and standardization of credit repair mechanisms in the field of market regulation.[7] The Measures provided enterprises with clear pathways for credit repair, including applications for removal from the List of Enterprises with Abnormal Operations and the termination of untrustworthiness-related management measures. At the same time, the State Administration for Market Regulation accelerated the development of a “national unified platform” and promoted the “one-stop credit repair service” reform, simplifying repair procedures and improving the efficiency with which enterprises could restore their credit.

3. Authoritative Policy Position, 2025

On December 25, 2025, the State Administration for Market Regulation will implement the latest revised version of the Measures for the Administration of Credit Repair in Market Regulation. The revision further expands the scope of credit repair and establishes temporary credit repair arrangements for “enterprises undergoing reorganization or settlement.” During the implementation of a reorganization plan or settlement agreement, an enterprise may apply for temporary credit repair by submitting the relevant ruling or other legal documents issued by a people’s court. The relevant information concerning untrustworthy conduct may then be temporarily concealed, and management measures that could affect the implementation of the reorganization or settlement may be lifted.[8] This measure helps reduce the prolonged effects of credit sanctions, supports enterprises in resuming operations and participating in market competition, and is consistent with the policy objective of improving the business environment.

III. A Comprehensive Comparison: The Logic and Core Differences Among the Three Major Credit Repair Pathways

As shown in Table 2, although China’s two categories of credit repair—financial credit repair and public credit repair—both serve the objective of restoring the credit of entities that have engaged in untrustworthy conduct, they differ in their underlying logic, scope of application, repair pathways, and implementation mechanisms. Financial credit repair is concentrated primarily in the financial sector and mainly concerns the correction of financial data. Public credit repair led by the National Development and Reform Commission focuses on social compliance and primarily addresses the correction of untrustworthy conduct. Credit repair under market regulation, led by the State Administration for Market Regulation, focuses on the compliance of enterprise conduct, particularly the restoration of enterprises’ operating qualifications and market credit in the commercial sphere.

Table 2 A Comprehensive Comparison of the Two Categories of Credit Repair

(I) Financial Credit Repair

Financial credit repair led by the People’s Bank of China follows the principle that “recording itself constitutes a sanction.” Financial institutions record customers’ defaults in credit reports, while the core of repair lies in restoring the credit eligibility and borrowing capacity of the relevant individuals or entities through information correction or updating, adjustments to display rules, or removal upon expiration in accordance with laws and regulations, rather than arbitrarily “deleting history.”

Financial credit repair is driven primarily by two factors. The first is policy-based relief under particular circumstances, such as relief arrangements introduced in response to the pandemic or other force majeure events, under which information relating to eligible defaulters may be subject to adjustments in its display in accordance with applicable rules. The second is automatic removal following the expiration of the statutory retention period, meaning that adverse financial records are removed from credit reports in accordance with the law after five years.

Financial credit repair applies to credit records submitted by financial institutions and commonly concerns defaults involving small consumer loans, outstanding credit-card balances, and similar obligations. The principal purpose of repair measures is to restore the financial credit of individuals and enterprises in accordance with laws and regulations, enabling them to regain access to loans, credit cards, and other financial services.

(II) Public Credit Repair

1. Public Credit Repair Led by the National Development and Reform Commission

Public credit repair covers the field of social credit, including information concerning the social conduct of individuals and enterprises, administrative penalties, and related matters. Unlike financial credit repair, which focuses on credit-reporting data, public credit repair places greater emphasis on social compliance and lawful conduct and seeks to restore an entity’s social credit status after it has corrected its misconduct and fulfilled its obligations.

The governance logic of public credit repair is that “public disclosure itself constitutes a sanction.” Once the conduct of an untrustworthy entity is recorded and publicly disclosed, the entity becomes subject to social and regulatory constraints. After correcting its misconduct and fulfilling its statutory obligations, the entity may apply, in accordance with applicable rules, to end the public disclosure, lift the restrictions, and restore its eligibility to engage in the relevant activities.

2. Credit Repair under Market Regulation Led by the State Administration for Market Regulation

Credit repair under market regulation is an important component of the public credit repair system and focuses on credit repair at the enterprise level. Led by the State Administration for Market Regulation, this pathway principally operates through regulatory lists such as the List of Enterprises with Abnormal Operations and the List of Seriously Untrustworthy and Unlawful Entities. It uses credit repair mechanisms to help enterprises restore their market-access qualifications and credit status.

Credit repair under market regulation follows the principle that “listing itself constitutes a sanction.” Once an enterprise is included on a list of abnormal operations or serious untrustworthiness, it becomes subject to restrictions arising from the relevant regulatory measures. The core of the repair process is the enterprise’s removal from the relevant list in accordance with laws and regulations after it has fulfilled its statutory obligations or completed the required corrective measures, thereby restoring its qualification to conduct normal business activities in the market.

The drivers of credit repair under market regulation include the fulfillment of statutory obligations: after correcting unlawful conduct and completing the required rectification, an enterprise may apply for removal from the relevant list. In addition, mechanisms such as a “green channel” for bankruptcy reorganization may provide more convenient credit repair arrangements for particular types of enterprises, thereby reducing the prolonged effects of credit sanctions.

IV. Challenges and Public Misunderstandings Concerning Credit Repair

Although the advancement of credit repair policies has positive implications for strengthening social integrity and economic vitality, public misunderstandings remain a challenge in their practical implementation. Many people confuse financial credit repair with public credit repair and mistakenly believe that all types of records concerning untrustworthy conduct can be eliminated by applying for their “deletion” or “whitewashing.” In reality, the two differ in both their scope of application and the actions taken to achieve repair. Financial credit repair focuses on the correction of credit-reporting information and adjustments to display rules, whereas public credit repair focuses on ending public disclosure and lifting restrictions after misconduct has been corrected. Such misunderstandings may also foster a gray industry operating under the name of “credit-report repair,” in which unscrupulous organizations charge substantial fees while promising to “erase records.” Such promises are generally incapable of being lawfully fulfilled and may instead result in fraud and legal disputes, thereby disrupting the proper operation of the credit repair system.

In addition, financial credit repair and public credit repair are led by different government authorities, including the People’s Bank of China, the National Development and Reform Commission, and the State Administration for Market Regulation. Because the boundaries between the systems and their points of access are not sufficiently intuitive, members of the public may repeatedly seek advice or submit applications to different departments. Differences in the standards or explanations applied by those departments may even lead to procedural mismatches, increasing both time and administrative costs and reducing the efficiency of policy implementation.

The government therefore needs to further improve clarity in both information disclosure and policy implementation, ensuring that the public can properly understand and use these policies. Particular emphasis should be placed on explaining “what can be repaired, which authority should be contacted, and how the process works.” The applicable scope, application channels, required materials, and time limits for different types of repair should be clearly specified, while cross-departmental information sharing and procedural integration should be advanced. At the same time, continuing public education and risk warnings are needed to reduce misunderstanding and misuse.

Finally, if the definition and scope of credit repair are not clearly delineated, the financial credit system may be adversely affected, particularly through the weakening of the risk-warning function of “faithful recordkeeping.” One of the major objectives of financial credit reporting is to prevent financial risks and protect financial institutions from excessive risk exposure. If repair is excessive or abused, the credibility of the credit-reporting system will be undermined, potentially affecting the stability of financial markets. Maintaining the rigor and transparency of repair mechanisms and ensuring that they apply only to eligible individuals and entities in accordance with laws and regulations are therefore essential to the proper functioning of the credit system.

Overall, credit repair policies must maintain a careful balance in their implementation. They should provide sufficient repair opportunities to help entities that have engaged in untrustworthy conduct reintegrate into society, while also preventing abuse and improper practices and ensuring that repair procedures remain fair and transparent.

V. Conclusion

The “dual-track, three-pathway” credit repair system led by the People’s Bank of China, the National Development and Reform Commission, and the State Administration for Market Regulation applies to different parties and operates through different mechanisms. Financial credit repair focuses primarily on the presentation and updating of credit-reporting information. Public credit repair focuses on ending public disclosure and lifting restrictions after misconduct has been corrected. Credit repair under market regulation focuses on removal from regulatory lists and the restoration of market access. Together, these three repair pathways reflect an equal emphasis on sanctions and rehabilitation: while maintaining necessary constraints, they provide a route back for entities that have corrected their misconduct and fulfilled their obligations, thereby improving governance effectiveness and public trust.

Looking ahead, the further improvement of credit repair mechanisms requires clearer institutional distinctions among the different types of repair pathways in order to prevent confusion. Cross-departmental coordination should also be strengthened, information sharing and procedural integration should be promoted, and the efficiency of repair should be improved. Public education and risk warnings should be treated as long-term priorities to reduce misunderstanding and abuse. The objective of credit repair is to ensure that, after correcting their misconduct and fulfilling their obligations, entities that have engaged in untrustworthy conduct can restore their credit through legitimate channels and continue participating in social and economic activities, maintaining a balance between “compassion and order.”

References

[1] People’s Bank of China, “Notice of the People’s Bank of China on Arrangements for Implementing the One-Time Credit Repair Policy” [EB/OL], December 22, 2025, available at https://www.pbc.gov.cn/goutongjiaoliu/113456/113469/2025122116371667030/index.html (last accessed December 24, 2025).

[2] People’s Bank of China, “Questions and Answers with the Press Concerning the Notice of the People’s Bank of China on Arrangements for Implementing the One-Time Credit Repair Policy” [EB/OL], December 22, 2025, available at https://www.pbc.gov.cn/goutongjiaoliu/113456/113469/2025122116421625696/index.html (last accessed December 24, 2025).

[3] State Council, Regulation on the Administration of the Credit Reporting Industry, State Council Order No. 631, promulgated January 21, 2013, effective March 15, 2013, Article 16.

[4] Xinhua News Agency, “The People’s Bank of China Is Studying the Implementation of a One-Time Personal Credit Relief Policy” [EB/OL], October 27, 2025, available at http://www.news.cn/fortune/20251027/39190dbb704141a197ad9e8e7213b754/c.html (last accessed December 24, 2025).

[5] State Council, “Notice of the State Council on Issuing the Planning Outline for the Development of the Social Credit System (2014–2020),” State Council Document No. 21 [2014], June 14, 2014 [EB/OL], available at https://www.gov.cn/gongbao/content/2014/content_2711418.htm (last accessed December 24, 2025).

[6] National Development and Reform Commission, Measures for the Administration of Credit Repair [EB/OL] (PDF), available at https://www.ndrc.gov.cn/xxgk/zcfb/fzggwl/202511/P020251126424276238205.pdf. The document states, among other matters, that “these Measures shall take effect on April 1, 2026, and the Measures for the Administration of Credit Information Repair Following the Correction of Untrustworthy Conduct (Trial) shall be repealed” (last accessed December 24, 2025).

[7] State Administration for Market Regulation, “Notice of the State Administration for Market Regulation on Issuing the Measures for the Administration of Credit Repair in Market Regulation,” SAMR Credit Regulation Document No. 3 [2021], issued July 30, 2021, effective September 1, 2021 [EB/OL], available at https://www.gov.cn/zhengce/zhengceku/2021-08/04/content_5629304.htm (last accessed December 24, 2025).

[8] State Administration for Market Regulation, Measures for the Administration of Credit Repair in Market Regulation, State Administration for Market Regulation Order No. 107, promulgated November 21, 2025, effective December 25, 2025 [EB/OL], available at https://www.samr.gov.cn/zw/zfxxgk/fdzdgknr/fgs/art/2025/art_02b9d3e6f31a4cc38079901ab49994d5.html (last accessed December 24, 2025).

Note: The author is Shanli Zhang. He is a doctoral student at Shandong University. The original title of this article was “A Comprehensive Analysis of China’s Credit Repair System: The ‘Dual-Track’ Model of Financial Credit and Public Credit.” ItDual-Track’ Model of Financial Credit and Public Credit.” It is the full-text version of a roundtable presentation delivered at the “Eighth Credit Rule of Law · Shaoshan Luntang Forum,” held at Xiangtan University on December 21, 2025. WeChat: 18811157736. Comments and corrections are welcome.

Latest Perspective | Don’t Cram Privacy Risks into a Single “Agree” Button—Companies Should Bear Their Share of Responsibility

When was the last time you seriously read a privacy policy from beginning to end?

In the age of AI, the data we hand over every day may reveal far more than we realize. A shopping record, a browsing trace, or a one-time location permission may appear ordinary in isolation. However, once analyzed and combined by algorithms, such data may be used to infer a person’s health status, purchasing power, interests and preferences, and even more sensitive personal characteristics.

I. AI Can Understand Your Data—and It Is Magnifying an Old Problem

The Chinese edition of The Wall Street Journal recently published an article by Daniel J. Solove titled “How to Maintain Our Privacy in the AI Age,” which addresses precisely this issue: when AI can analyze enormous quantities of personal data, are our existing approaches to privacy protection still adequate? [1]

The author, Daniel J. Solove, is a professor at the George Washington University Law School who has long studied privacy law, data security, and technology governance. He developed the influential “taxonomy of privacy,” which divides privacy violations into different categories, including information collection, information processing, information dissemination, and invasion. [2]

Solove warns that the broader environment of this century has not been friendly to privacy. The internet has risen, smartphones track geographic locations, large numbers of companies continuously collect personal data, and surveillance networks continue to expand. AI is now capable of analyzing vast digital records and can infer a great deal of information about individuals. [1]

The problem is that many privacy laws and platform rules still rely on an old approach: companies provide notice, and users give consent. In theory, this gives users a choice. In reality, however, ordinary people find it difficult to understand what they are actually consenting to. How will their data be shared? What risks may arise from a privacy notice? Could those risks become more serious in the future as AI’s analytical capabilities grow? Most people have neither the time nor the professional expertise needed to assess each of these questions individually.

Using everyday consumer data as an example, Solove reminds us that seemingly ordinary shopping records, once analyzed by AI, may be used to infer more sensitive information, such as health conditions, religious beliefs, and political leanings. Solove therefore reaches a key conclusion: most laws today attempt to shift responsibility for protecting privacy onto consumers. But digital technologies are too complex for ordinary people to manage. We need a different strategy—one that holds companies accountable. [1]

II. Privacy Protection Cannot End with “I Have Read and Agree”

For more than two decades, online privacy protection has largely relied on the model of “notice and consent.” Companies draft privacy policies, users click “Agree,” and the processing of their data is then formally authorized.

The problem with this approach is that it places an extremely complex technological and legal issue on the shoulders of ordinary consumers. Users cannot fully understand what data a company collects. They also have difficulty knowing which third parties may use that data, let alone predicting what an AI system may infer from it. Although this arrangement appears to offer users a choice, many people simply click “Agree” so that they can continue using the service.

“I have read and agree” has often become little more than a formality. It appears to respect users’ choices, but it can easily become a tool through which companies shift responsibility. Solove’s proposed direction is clear: privacy protection must move away from consumer self-management and toward corporate accountability.

He notes that food and pharmaceutical manufacturers also operated under inadequate regulation in the past. Formaldehyde was once added to spoiled milk to make it taste sweeter, and it was only after many infants died that stronger regulation was introduced. The automobile industry went through a similar period. Before laws imposed mandatory safety requirements, automobiles were extremely dangerous means of transportation. [1] Food and automobile safety later improved not because consumers became better at protecting themselves, but because the law required companies to assume responsibility for safety. Cars became subject to safety testing, farms became subject to inspection, and accountability mechanisms were introduced for defective products. Innovations such as seat belts and airbags also emerged in response to safety requirements. [1]

Solove argues that privacy protection requires a similar approach. Companies that collect and use data should not be able to avoid liability merely by issuing a privacy policy. When a company’s use of data or AI algorithms creates an unreasonable risk of harm, it should be held accountable. [1]

More specifically, there are at least several possible directions.

(1) Data Minimization

Companies should collect and use data only for the purposes for which it was originally collected and should not arbitrarily expand the scope of its use. Strict implementation of the principle of data minimization is an important means of effectively protecting privacy. The European Union’s General Data Protection Regulation (GDPR) also establishes data minimization as a fundamental principle. [3] China’s Personal Information Protection Law likewise provides that the collection of personal information must be limited to the minimum scope necessary to achieve the purpose of processing. [4]

(2) The Right to Deletion

Solove notes that the right to deletion has long been part of European Union data protection law. Although it was once regarded as impractical in the United States, it has now been incorporated into consumer privacy laws in various U.S. states and no longer generates substantial controversy. [1] This demonstrates that some privacy protections once considered excessively strict are becoming more widely accepted institutional arrangements as the digital environment evolves.

(3) Restricting “Dark Patterns”

“Dark patterns” are deceptive or manipulative technological designs that induce users to share data they would not otherwise have provided. [1] Such designs prevent users from making genuine choices and further undermine the meaning of “consent.”

(4) Holding Irresponsible Technology Design and Harmful Algorithms Accountable

Solove proposes imposing liability for negligent or reckless technology design, holding harmful algorithms accountable, and requiring protective mechanisms to be built into technologies to prevent them from being used to violate privacy. [1]

The logic underlying these proposals is simple: those who control the data, algorithms, and technological systems should bear the corresponding responsibility. Ordinary consumers need rights, but companies need boundaries even more.

III. Implications for China: Turning the Principle of Corporate Responsibility into Action

China has already entered an era in which everyday life is highly digitalized. As of December 2025, China had 1.125 billion internet users, with an internet penetration rate of 80.1%. The number of generative AI users had reached 602 million, representing a penetration rate of 42.8%. [5] Users certainly need to improve their awareness of privacy. However, if privacy protection depends primarily on individuals reading agreements line by line and assessing each risk separately, it will be difficult to establish genuinely effective protection. For China, the priority is to clearly define the boundaries of corporate data collection, the boundaries of algorithmic use, and the boundaries of corporate responsibility when something goes wrong.

China’s existing laws already incorporate this approach. Article 6 of the Personal Information Protection Law requires that the collection of personal information be limited to the minimum scope necessary to achieve the purpose of processing and prohibits excessive collection. Article 9 provides that personal information processors must be responsible for their personal information processing activities and must adopt the measures necessary to protect the security of personal information. [4] The Data Security Law also requires data processors to establish sound, full-process data security management systems, adopt appropriate technical and other necessary measures to safeguard data security, and promptly take remedial, response, and reporting measures when risks are identified or security incidents occur. [6]

The next crucial step is to ensure that these principles are genuinely reflected in corporate conduct.

Companies must not collect as much data as possible simply because it has commercial value. They must not arbitrarily expand the purposes for which data is used merely because users have clicked “Agree.” They must not avoid explanation and accountability simply because algorithms are complex. Nor should they confine privacy protection to policy documents without implementing it in product design, data management, and algorithmic governance.

Privacy risks in the age of AI will become more difficult to detect. In the past, people were primarily concerned about information leaks. Today, they must also guard against information being inferred, combined, used to create profiles, and applied in ways that affect individual opportunities and choices. Many forms of harm may not take the form of an obvious, one-time data breach. Instead, they may occur gradually through long-term data analysis and algorithmic decision-making.

This is also the most important warning conveyed by Solove’s article: ordinary people cannot always be expected to shoulder the burden of privacy protection by themselves.

Individuals can become more vigilant, but they cannot live every day as though they were legal and technical experts. Those that truly need to assume greater responsibility are the companies that control the data, algorithms, and access points to digital platforms.

The central point in discussions of privacy protection in the age of AI is clear:

Data cannot be collected without limits, algorithms cannot be used without constraints, and responsibility cannot be shifted onto users through a privacy policy. Only by placing genuine responsibility on the companies that control data and technology can privacy protection in the age of AI move beyond a purely formal “Agree” button.

References

[1] Daniel J. Solove, “How to Maintain Our Privacy in the AI Age,” The Wall Street Journal (June 23, 2026).

[2] Daniel J. Solove, “A Taxonomy of Privacy,” University of Pennsylvania Law Review, Vol. 154, No. 3, p. 477, 2006.

[3] European Union General Data Protection Regulation (GDPR).

[4] Personal Information Protection Law of the People’s Republic of China.

[5] Policy and International Cooperation Institute of the China Internet Network Information Center, The 57th Statistical Report on China’s Internet Development, February 2026.

[6] Data Security Law of the People’s Republic of China.

Note: Shanli Zhang, the author of this article, is a doctoral student at Shandong University Law School and a research assistant to Dr. Xinhai Liu. His research focuses on personal data and privacy protection. WeChat: 18811157736. Comments, exchanges, and corrections are welcome.

Can the 8.48 Million “Deadbeat Debtors” (“Dishonest Persons Subject to Enforcement”) Restore Their Credit?

Against the backdrop of the continued development and deepening of China’s social credit system, public concern over issues relating to “credit” has reached an unprecedented level. As of December 30, 2025, a total of 8,485,046 dishonest persons subject to enforcement were publicly listed nationwide.[1] However, a common misconception is to conflate “deadbeat debtors” in the field of judicial enforcement—the legal term being “dishonest persons subject to enforcement”—with ordinary credit problems such as overdue bank payments, leading people to assume that all forms of credit impairment can be addressed through a unified credit restoration mechanism. This conceptual confusion may not only cause individuals or enterprises to “knock on the wrong door and apply the wrong remedy” when seeking relief, but also create fertile ground for gray-market businesses operating under the banner of “credit report repair.”

I. The Institutional Origin and Constitutive Elements of “Deadbeat Debtor” Status: A Sanctioning Status Arising from Judicial Enforcement

Before discussing how such status may be “restored,” it is first necessary to clarify the essential nature of a “deadbeat debtor.” It is neither a simple social label nor the result of a credit score. Rather, it is a sanctioning status arising from a specific judicial enforcement procedure and carrying a clear legal definition. Understanding its distinctive judicial origin is an indispensable foundation for examining all subsequent questions concerning restoration.

(I) Legal Definition and Origin of “Deadbeat Debtor” Status

The widely used expression “deadbeat debtor” is not a legal term. Its formal designation within the legal framework is “dishonest person subject to enforcement.” This system does not originate from the banking credit reporting system or from the broader social credit system. Instead, it derives directly from the Civil Procedure Law of the People’s Republic of China and the Several Provisions of the Supreme People’s Court on the Publication of Information Concerning the List of Dishonest Persons Subject to Enforcement. It constitutes a judicial sanction imposed during compulsory enforcement proceedings by a people’s court in response to specified forms of dishonest conduct.

The central purpose of establishing this system is clear: by using credit-based sanctions as a powerful deterrent and imposing pressure on various aspects of a dishonest person’s life, the system seeks to compel that person to voluntarily perform the obligations determined in an effective legal instrument. It thereby aims to address the long-standing problem of “difficulties in enforcement” that has troubled judicial practice and to firmly safeguard the authority of judicial decisions.

(II) Statutory Circumstances for Inclusion on the Dishonesty List

The legal procedure for determining that a person subject to enforcement is a “deadbeat debtor” and placing that person on the dishonesty list is highly cautious. Two indispensable preconditions must be satisfied simultaneously: first, there must be an effective legal instrument, such as a judgment or ruling; and second, the person subject to enforcement must have committed a specific form of dishonest conduct prescribed by law.

In other words, the mere existence of a debt does not directly result in a person being classified as a “deadbeat debtor.” The key question is whether, during the enforcement stage, the person has engaged in subjectively malicious and dishonest conduct. Article 1 of the Several Provisions of the Supreme People’s Court on the Publication of Information Concerning the List of Dishonest Persons Subject to Enforcement expressly identifies six principal categories of dishonest conduct:

1. Refusing to perform the obligations determined in an effective legal instrument despite having the ability to do so;

2. Obstructing or resisting enforcement by means such as fabricating evidence, violence, or threats;

3. Evading enforcement through sham litigation, sham arbitration, concealment or transfer of assets, or other means;

4. Violating the property reporting system;

5. Violating an order restricting consumption;

6. Refusing, without legitimate reason, to perform an enforcement settlement agreement.

(III) The Critical Distinction Between “Dishonesty” and “Inability to Perform”

To prevent the excessive application of sanctions, judicial policy has long and repeatedly emphasized the need to strictly distinguish “dishonest persons subject to enforcement” from “persons subject to enforcement who genuinely lack the ability to perform,” namely, those who are “incapable of performance.” The latter may have temporarily or permanently lost the ability to perform because of objective circumstances, such as corporate bankruptcy or an individual’s loss of working capacity. Such inability does not automatically constitute “dishonesty” in the legal sense.

This important distinction clearly demonstrates that the target of the dishonest-persons-under-enforcement system is subjectively malicious and objectively dishonest conduct involving “non-performance” or “evasion of performance.” Its institutional logic emphasizes responsibility for conduct rather than punishment for economic failure itself.

Precisely because “deadbeat debtor” status constitutes a judicial sanction, the legal consequences faced by such persons extend far beyond ordinary credit-record issues. A cross-departmental and cross-sectoral network of coordinated sanctions has therefore been established.

II. The Principal Consequences of “Deadbeat Debtor” Status: The Coordinated Sanctions Mechanism

The coordinated sanctions mechanism is the most deterrent component of the system governing dishonest persons subject to enforcement. Based on the principle that “dishonesty in one area results in restrictions everywhere,” the mechanism uses information sharing and coordinated supervision among people’s courts, government departments, financial institutions, industry associations, and other entities to transform an otherwise isolated judicial sanction into a society-wide network of restrictions. This substantially increases the cost of dishonest conduct, minimizes the room available for dishonest persons to operate, and compels them to perform their legal obligations.

(I) Operation of the Coordinated Sanctions Mechanism

The mechanism operates in a straightforward manner. People’s courts at all levels enter information concerning dishonest persons subject to enforcement into the unified database maintained by the Supreme People’s Court and notify “relevant government departments, financial regulatory authorities, financial institutions, public institutions performing administrative functions, industry associations, and other entities.” Upon receiving such information, these entities impose corresponding restrictive measures on the listed persons in accordance with the laws, regulations, and relevant rules governing their respective fields.

(II) Principal Sanctions

Once an individual or enterprise is included on the list of dishonest persons subject to enforcement, it will face a series of severe coordinated sanctions, including but not limited to the following:

  • Restrictions on financing and credit: When reviewing loan applications, processing credit card applications, and providing other services, financial institutions may impose strict restrictions or directly refuse to provide the relevant financial services, thereby effectively cutting off access to financing.
  • Restrictions on market access and qualification recognition: Dishonest persons subject to enforcement may be strictly restricted or directly excluded from key areas such as government procurement, bidding and tendering, administrative approvals, government support, and qualification recognition.
  • Restrictions on high-value consumption and consumption not necessary for daily life or work: This is the sanction most familiar to the public. Prohibited activities include traveling by airplane, occupying soft-sleeper berths on trains, or traveling in second-class or higher cabins on ships; engaging in high-value consumption at star-rated hotels, nightclubs, golf courses, and similar venues; and enrolling one’s children in high-fee private schools.
  • Restrictions on holding important positions: Dishonest persons subject to enforcement may be prohibited from serving as directors, supervisors, or senior executives of companies, as well as legal representatives of public institutions, senior executives of financial institutions, and holders of other important positions.

In the face of such severe coordinated sanctions, seeking credit restoration inevitably becomes the preferred course of action for dishonest persons or entities. However, the path to restoration is not unobstructed. It is first necessary to clearly define the boundaries between the judicial system and the various credit restoration systems.

III. Clarifying the Boundaries: Fundamental Differences Between Judicial Sanctions and the Three Categories of Credit Restoration Systems

The greatest public misunderstanding concerning credit restoration lies in the conflation of systems governed by different authorities, based on different regulatory rationales, and operating through different restoration mechanisms.

(I) Overview of China’s “Dual-Track, Three-Pathway” Credit Restoration System

As China’s credit restoration system has developed, it has gradually formed a clear “dual-track, three-pathway” structure. The “dual tracks” refer to financial credit restoration and public credit restoration. The public credit restoration track is further divided into two principal pathways: one coordinated by the National Development and Reform Commission and applicable across society as a whole, and the other led by the State Administration for Market Regulation and focused on business entities.

(II) Comparison of the Core Differences Among the Four Systems

To understand the restoration pathway available to a “deadbeat debtor,” it is first necessary to distinguish the judicial enforcement system from the three principal credit restoration systems. Table 1 provides an in-depth comparison across four core dimensions:

Table 1. Comparison of the Four Systems Related to Credit Restoration

The fundamental differences among these systems in terms of responsible authorities, regulatory rationale, forms of sanctions, and legal basis determine that the credit restoration of a “deadbeat debtor” cannot bypass judicial procedures. Instead, it must follow a specific sequence and pathway.

IV. The Path to Restoration: The Correct Sequence and Coordination Among Multiple Pathways

The credit restoration of a “deadbeat debtor” is a systematic undertaking rather than a single act. It requires the dishonest person or entity to first fulfill its obligations at the judicial level before proceeding in an orderly manner to address issues under the other three credit restoration systems.

(I) The Absolute Prerequisite: “Judicial Delisting” Through Completion of the Judicial Enforcement Procedure

For a “deadbeat debtor,” the sole and absolute starting point for every restoration pathway is to perform the relevant legal obligations and obtain “judicial delisting” from the enforcement court that made the original inclusion decision—that is, the deletion of the relevant information from the list of dishonest persons subject to enforcement. Any attempt at restoration that bypasses the court is institutionally ineffective.

Under Article 10 of the Several Provisions of the Supreme People’s Court on the Publication of Information Concerning the List of Dishonest Persons Subject to Enforcement, the principal statutory circumstances permitting “judicial delisting” include the following:

  • Full performance: The person subject to enforcement has performed the obligations determined in the effective legal instrument, or the people’s court has completed enforcement.
  • Performance of a settlement agreement: The parties have reached an enforcement settlement agreement, and the agreement has been fully performed.
  • Application by the enforcement applicant: The enforcement applicant submits a written request for the deletion of the dishonesty information, and the people’s court approves the request after review.
  • No assets available for enforcement: Following termination of the current enforcement procedure, the court has conducted at least two searches for the assets of the person subject to enforcement through the online enforcement inquiry and control system, no assets available for enforcement have been identified, and neither the enforcement applicant nor any other person has provided valid leads concerning assets.
  • Change in the enforcement procedure: The people’s court has lawfully ruled to suspend enforcement against the dishonest person subject to enforcement because of trial supervision proceedings or bankruptcy proceedings, or has lawfully ruled not to enforce or to terminate enforcement.

In addition, where a prescribed period of inclusion applies to the relevant dishonest conduct, the people’s court must delete the dishonesty information within three working days after the inclusion period expires.

Once the relevant conditions have been satisfied and the court has deleted the dishonesty information, the corresponding coordinated sanctions, such as restrictions on high-value consumption, will be lifted. This constitutes the legal foundation and “passport” for subsequent engagement with the other credit restoration systems.

(II) Relationship with Financial Credit Restoration: No Substitution, but Institutional Linkage Exists

The financial credit restoration mechanism cannot, as a matter of institutional design, directly affect or replace a person’s dishonest status at the judicial level. A “deadbeat debtor” cannot have the status of dishonest person subject to enforcement removed by applying to the People’s Bank of China or to any financial institution.

Nevertheless, a critical linkage exists between the two systems. People’s courts transmit information from the list of dishonest persons subject to enforcement to the central bank’s credit reporting system, and credit reporting agencies record such information in credit reports in accordance with the law.

An important detail following restoration must not be overlooked. Even after the court has completed “judicial delisting” and lifted the sanctions operating in real time, the relevant adverse records will, under the Regulations on the Administration of the Credit Reporting Industry, remain in an individual’s credit report for five years from the date on which the adverse conduct or event terminates. A clear distinction must therefore be drawn between the “lifting of real-time sanctions” and the “statutory retention of historical credit records.” These are two entirely different concepts.

(III) Relationship with Public Credit Restoration: A Subsequent Follow-On Mechanism

For a “deadbeat debtor,” the public credit restoration system coordinated by the National Development and Reform Commission functions as a subsequent follow-on mechanism rather than an independent starting pathway.

The correct sequence of restoration is as follows:

First, the people’s court must lawfully lift the dishonesty sanctions and complete the “judicial delisting.” Only thereafter may the dishonest person or entity apply, in accordance with the Measures for the Administration of Credit Restoration, to platforms such as the Credit China website for the cessation of publication of serious dishonesty information relating to the judicially determined dishonest conduct.

(IV) Relationship with Market Regulation Credit Restoration: A Parallel Mechanism for Business Entities

This restoration pathway principally applies to enterprises, individually owned businesses, and other business entities that have been classified as “deadbeat debtors.” Its relationship with judicial restoration may be characterized as parallel.

This means that even after an enterprise has completed “delisting” at the judicial level, if it has also been placed by the market regulation authority on the list of abnormal business operations or the list of seriously unlawful and dishonest entities for other reasons—such as failing to submit an annual report on time or being unreachable at its registered address—it must still independently apply to the market regulation authority that made the original inclusion decision for removal from the relevant list in accordance with the Measures for the Administration of Credit Restoration by Market Regulation Authorities. The two processes do not substitute for one another and must be addressed separately.

V. Conclusion and Summary of the Core Points

The essence of “deadbeat debtor” status, or the status of a dishonest person subject to enforcement, is that it constitutes a sanctioning status arising from judicial enforcement proceedings rather than a simple credit-scoring issue. Accordingly, its restoration must follow a specific pathway under which the performance of judicial obligations is the absolute prerequisite. Clarifying the boundary between judicial sanctions and social credit governance is of vital importance to safeguarding judicial authority, ensuring the sound operation of the credit restoration system, and guiding dishonest persons and entities toward the appropriate forms of relief.

For ease of understanding and practical application, the three principal conclusions and reminders of this article are summarized as follows:

1. “Deadbeat debtor” status is a judicial matter, and restoration begins with the court: The creation and termination of the status of a dishonest person subject to enforcement are ultimately determined by the people’s court. This reflects the basic principle of credit governance that “the authority that makes the determination is responsible for the restoration.” Any attempt to bypass the enforcement court and “clean up” the status of a dishonest person subject to enforcement through financial credit restoration or public credit restoration channels lacks a regulatory basis and is bound to fail. The only correct starting point for restoration is to perform the relevant legal obligations and obtain “judicial delisting” from the court.

2. Restoration is an institutional exit mechanism, not the deletion of historical records: Completion of credit restoration means that real-time sanctions, such as restrictions on high-value consumption, are lifted and the publication of the relevant dishonesty information is discontinued, allowing the person or entity to return to normal social and economic activities. It does not mean that every historical trace will be deleted. In particular, relevant adverse records in financial credit reports will remain for five years from the date on which the relevant conduct terminates, as required by law. Dishonest persons and entities should therefore establish appropriate expectations.

3. Credit restoration is legally provided free of charge; beware of “credit report repair” scams: All credit restoration procedures administered by official authorities, including courts, the National Development and Reform Commission, and the State Administration for Market Regulation, are free of charge. Any intermediary service claiming that it can use paid “internal operations” or “technical methods” to remove adverse records prematurely or in violation of applicable rules belongs to the gray market. Such services may not only cause financial losses but may also involve unlawful conduct. Applications should always be submitted lawfully through official channels to avoid fraud.

References

[1]China Enforcement Information Online (zxgk.court.gov.cn): https://zxgk.court.gov.cn/.

Note: The author is Shanli Zhang. He is a doctoral candidate at the School of Law, Shandong University. The original title of the article was “An Analysis of the Formation Mechanism of ‘Deadbeat Debtors’ and Their Normative Relationship with the Credit Restoration System.” WeChat: 18811157736. Comments and corrections are welcome.

The Implementation Guidelines for the Responsible Use and Innovative Development of AI Agents An Overview and International Comparison

I. Legal Nature of the Document: Not a Law, but a Strong Signal of Regulatory Intent

In formal terms, the document resembles a policy-oriented and guidance document rather than a law that directly creates legal liability. In other words, a violation of an individual principle contained in the document will not necessarily, by itself, result in an administrative penalty.

From the perspective of regulatory practice, however, documents of this kind generally serve three purposes:

First, they provide a policy basis for subsequent legislation, departmental rules, national standards, and industry standards. Second, they serve as a reference for regulatory authorities in determining whether an enterprise has fulfilled its obligations regarding safety and security management. Third, they provide a foundation for designing mechanisms such as pilot programs in key industries, filing requirements, testing, assessments, certification, and product recalls.

The document expressly refers to mechanisms including filing, testing, the recall of problematic products, third-party evaluations, mutual recognition of certifications, credit assessments, and mandatory standards. This indicates that it is not merely a broad policy initiative; rather, it is laying the groundwork for the future transformation of “soft law” into “hard law.”

II. Regulatory Focus: From “Model Compliance” to “Conduct Compliance”

Historically, AI compliance in China has primarily focused on several issues: whether training data was obtained and used lawfully, whether generated content was unlawful, whether algorithmic recommendations were transparent, whether deep-synthesis content was properly labeled, and whether personal information was processed lawfully. AI agents introduce a new set of questions: Will an agent make decisions on behalf of a person? Will it operate an account, send messages, place orders, make payments, control or schedule equipment, or access business systems on the user’s behalf? The central legal logic of this document is therefore that the subject of AI-agent regulation is not limited to “output content”; it also includes the agent’s “executive conduct.”

The document requires the clarification of decision-making authority. It calls for clear boundaries among decisions that may only be made by the user personally, decisions that require user authorization, and decisions that an AI agent may make autonomously. It also requires that users retain the right to be informed about autonomous decisions made by AI agents, as well as the right to make the final decision. Any action performed by an AI agent must remain within the scope of the user’s authorization. These requirements align with the rules on automated decision-making under the Personal Information Protection Law of the People’s Republic of China. Where a decision made through automated decision-making has a significant impact on an individual’s rights and interests, the individual has the right to request an explanation and the right to refuse a decision made solely through automated means.

III. The Real Compliance Challenge: An Agent’s “Permissions” Are More Dangerous Than Its “Answers”

When an ordinary chatbot gives an incorrect answer, the principal risk is misinformation. When an AI agent is connected to email, calendars, payment systems, office automation systems, customer relationship management systems, enterprise resource planning systems, medical systems, financial systems, or government service systems, the risk escalates into the possibility of real-world harm.

Enterprises therefore cannot limit compliance measures to content moderation. They must also conduct permission reviews, operational reviews, log audits, outcome reviews, and human verification.

IV. Relationship with Existing AI Regulations: Cumulative Rather Than Substitutive

This document does not exist in isolation. When an AI-agent product is deployed in China, it will generally be subject to multiple regulatory frameworks simultaneously.

Where an AI agent provides text, image, audio, video, or other content-generation services to the public within China, the Interim Measures for the Management of Generative Artificial Intelligence Services may apply. These Measures expressly apply to services that use generative AI technologies to provide generated content to the public within China. They emphasize the equal importance of development and security, law-based governance, inclusive and prudent regulation, and classified and tiered supervision.

Where an AI agent performs functions such as ranking, recommendation, personalized push notifications, scheduling decisions, or content distribution, the Provisions on the Administration of Algorithmic Recommendations in Internet Information Services may also apply. The regulatory objectives of these Provisions include regulating algorithmic recommendation activities, safeguarding national security and the public interest, protecting the lawful rights and interests of citizens and legal persons, and requiring algorithmic recommendation services to operate in accordance with the law.

Where an AI agent generates or synthesizes text, images, audio, video, virtual scenes, or other content, the requirements concerning the labeling of AI-generated and synthetic content must also be considered. The Measures for Labeling AI-Generated and Synthetic Content provide that such labeling includes both explicit and implicit labels. Service providers that conduct activities involving the labeling of generated or synthetic content under the prescribed circumstances are subject to these Measures.

Compliance for AI agents is therefore not a matter of determining whether a single document applies. It requires a combined assessment of multiple factors:

Is the service offered to the public? Does it generate content? Does it involve algorithmic recommendations? Does it involve deep synthesis? Does it process personal information? Does it use automated decision-making? Is it connected to a high-risk industry? Does it involve cross-border data transfers? Does it possess public-opinion attributes or the capacity for social mobilization?

V. Five Institutional Signals That Deserve Particular Attention

1. Classified and Tiered Governance Will Become the Main Regulatory Approach

The document proposes classified and tiered governance of AI agents according to their application scenarios and potential impact. For sensitive fields and key industries, cybersecurity and information authorities may work with the relevant sectoral regulators to determine the scenarios in which AI-agent applications may be permitted and may implement measures such as filing, testing, and the recall of problematic products. In low-risk areas, governance is more likely to rely on compliance self-assessments, information reporting, platform management, and industry self-regulation.

This means that future regulation of AI agents is unlikely to adopt a one-size-fits-all approach. Office assistants, entertainment and companionship agents, shopping assistants, medical-support agents, financial risk-control agents, judicial-support agents, and public-security agents will be subject to significantly different levels of regulatory scrutiny.

2. “Ultimate Human Control” Will Become a Mandatory Requirement

The document requires that users have the right to be informed about autonomous decisions made by AI agents and retain the right to make the final decision. In practical terms, this requires AI-agent systems to preserve mechanisms for human intervention. In sectors such as healthcare, finance, justice, government services, education, employment, insurance, and credit, it will be difficult for enterprises to avoid liability merely by claiming that “the system made the decision automatically.”

In practice, high-risk AI agents should, at a minimum, incorporate the following safeguards: explicit user authorization, secondary confirmation for significant actions, human review, revocable authorization, emergency or abnormal-operation termination mechanisms, operational logs, and complaint or appeal channels.

3. AI-Agent Conduct Must Be “Verifiable and Traceable”

The document proposes exploring the use of blockchain and other technologies to establish mechanisms under which the conduct of AI agents in important application scenarios can be verified and traced. This is highly significant for enterprises. Log retention is no longer merely a technical issue; it is also a matter of establishing a defense against liability and demonstrating regulatory compliance.

4. Supply-Chain Security Will Be Subject to Greater Scrutiny

The document emphasizes security management in areas including model integration, API calls, and the use of extension tools. This means that an enterprise cannot simply argue that it bears no responsibility because the underlying model was supplied by a third party. Where an enterprise combines third-party models, plug-ins, robotic process automation tools, knowledge bases, payment interfaces, and office systems into an AI-agent service, the enterprise, as the deployer or operator, must still assume the corresponding management responsibilities.

Contracts should clearly address the scope of data use, whether data may be used for training, responsibility for outputs, vulnerability-response obligations, log-retention requirements, audit rights, ownership of intellectual property, the relationship between personal information processors and entrusted processors, cross-border data arrangements, and incident-notification obligations.

5. Industry Applications Will Initially Be Opened and Subsequently Tightened

The document identifies potential applications in healthcare, financial services, judicial services, government services, public security, tendering and bidding, education, and other fields. This indicates that the policy does not prohibit AI agents from entering high-risk industries. Instead, it encourages “controlled pilot programs.” However, the more important or sensitive the industry, the more likely it is that subsequent mandatory standards, filing requirements, assessments, certifications, and regulatory inspections will be introduced.

VI. The Legal Pitfalls Enterprises Are Most Likely to Encounter

The first is excessive authorization. For example, a user may merely ask an AI agent to “check my emails,” while the system is granted, by default, full permission to read, forward, and delete emails, download attachments, access contacts, and send external messages. This creates significant personal information protection and data-security risks.

The second is automated decision-making without human review. Where matters involve lending, recruitment, insurance, educational assessment, medical advice, discriminatory pricing, or similar issues, decisions made entirely by AI agents may raise concerns regarding the fairness and transparency of automated decision-making, as well as the individual’s right to an explanation.

The third is the failure to label generated content. In the future, explicit and implicit labeling of AI-generated or synthetic text, images, audio, video, virtual scenes, and other content will become an important area of compliance.

The fourth is using AI agents to circumvent sector-specific licensing requirements. Examples include providing medical diagnoses without the necessary medical qualifications, giving investment advice without the required financial licenses, or guaranteeing the outcome of legal proceedings without the qualifications required to provide legal services. Such conduct may be regarded as operating beyond the permitted business scope, false advertising, or misleading consumers.

The fifth is the use of excessively broad disclaimers. A user agreement stating simply that “AI-generated results are for reference only and the platform assumes no responsibility” does not automatically exempt the platform from its statutory obligations regarding product design, data processing, security safeguards, content governance, and permission controls.

VII. Impact on Different Market Participants

For foundation-model providers, the primary areas of concern are model security, content governance, labeling and watermarking, interface security, filing and assessment requirements, and management of the developer ecosystem.

For AI-agent development platforms, the main priorities are plug-in review, tiered permission management, application-store governance, developer access requirements, the removal of malicious AI agents, and supply-chain audits.

For enterprises deploying AI agents in specific industries, the primary concerns are the legality of the business scenario, human review, industry qualifications, data compliance, log retention, and customer disclosure.

For terminal-device manufacturers, the key issues are local data processing, voice and image collection, the security of device controls, the protection of minors, private or secure spaces, and safeguards against accidental activation.

For government, judicial, medical, and financial institutions, AI agents are more appropriately used as supporting tools and should not directly replace the legally responsible person or institution in making final decisions.

The regulatory logic conveyed by the Implementation Opinions on the Regulated Application and Innovative Development of AI Agents may be summarized as follows: China’s approach to AI agents is not prohibition, but rather “encouraging application, implementing classified regulation, controlling permissions, recording conduct, ensuring traceability of risks, and applying stricter rules in key industries.”

For enterprises, whether an AI-agent product may be launched in compliance with the law depends not only on the strength of the underlying model, but also on six questions:

1. Does the user clearly understand what the AI agent can and cannot do?

2. Does the AI agent act only within the scope of the user’s authorization?

3. Is there a mechanism for final human confirmation where significant rights and interests are involved?

4. Are data, personal information, and sensitive information processed in accordance with the law?

5. Is AI-generated and synthetic content labeled as required by law?

6. Where an error, unauthorized action, infringement, or security incident occurs, can the chain of responsibility be traced?

VIII. International Comparison

From an international perspective, the major economies have adopted different regulatory approaches to AI and AI agents. A common trend, however, is that the focus of regulation is shifting beyond the question of whether the model itself is safe toward questions concerning how an AI system is deployed, whether it can make decisions on behalf of individuals, whether human oversight is maintained, and whether responsibility can be traced. This closely corresponds to the emphasis placed by the Implementation Opinions on the Regulated Application and Innovative Development of AI Agents on permission boundaries, behavioral controls, classified and tiered governance, and traceability mechanisms.

The European Union follows an approach centered on binding legislation. The EU Artificial Intelligence Act is based on risk classification and imposes stricter compliance obligations on high-risk AI systems, with particular emphasis on transparency, human oversight, risk management, and the protection of fundamental rights. In areas such as healthcare, finance, education, employment, and justice, it is not sufficient for an AI system to be merely “technically usable.” The provider or deployer must also demonstrate that its risks are controllable and that responsibility is clearly allocated.

The United States follows an approach that gives greater priority to innovation and standards-based frameworks. Unlike the European Union, the United States has not established a single, unified AI statute. Instead, it relies more heavily on risk-management frameworks issued by institutions such as the National Institute of Standards and Technology, together with sector-specific rules, government procurement requirements, corporate governance mechanisms, and ex post liability. The US model therefore places greater emphasis on whether an enterprise has established mechanisms for testing and evaluation, supply-chain management, data governance, security response, and internal accountability.

The United Kingdom follows a principles-based regulatory approach. It places greater emphasis on existing regulators interpreting and applying AI-governance principles within their respective industries, including safety and robustness, transparency and explainability, fairness, accountability, and access to redress. Rather than immediately adopting a single law governing all AI applications, the United Kingdom places greater importance on proportionate regulation tailored to different application scenarios.

Singapore, Japan, and the G7 Hiroshima AI Process reflect a greater reliance on soft-law governance and international coordination. These mechanisms generally promote the establishment of trustworthy AI systems through guidelines, testing tools, codes of conduct, and risk-management frameworks. Although they may not directly impose mandatory penalties, they influence the compliance standards applied to multinational enterprises, products entering overseas markets, and international cooperation.

The Implementation Opinions on the Regulated Application and Innovative Development of AI Agents reflect a combined regulatory approach. On the one hand, the document encourages the deployment of AI agents in important fields such as healthcare, finance, education, government services, justice, public security, and tendering and bidding. On the other hand, it emphasizes classified and tiered governance, controlled permissions, behavioral records, risk traceability, and stricter supervision in key industries. China is therefore not simply prohibiting the application of AI agents. Rather, it is promoting “controlled pilot programs” and “regulated development.”

The Implementation Opinions on the Regulated Application and Innovative Development of AI Agents may be understood within the broader global trend of AI governance. In the future, the key question in AI-agent compliance will not merely be whether the underlying model is powerful, but whether the enterprise can demonstrate that the AI agent operates in real-world business activities with proper authorization, clearly defined boundaries, effective oversight, adequate logs, mechanisms for accountability, and procedures for correcting errors.

Note: The author is Shanli Zhang. He is a doctoral candidate at the School of Law, Shandong University, and an editorial assistant at Data Economy Review. WeChat: 18811157736. Comments and corrections are welcome.

The 2rd China Korea International Seminar of MyData Successfully Held in Shanghai

Data is the core factor of the digital economy, and personal data is a key element within the entire data-factor market. It is not only a focal point of data governance across countries worldwide, but also a topic closely followed by major international media. MyData has become one of the mainstream industrial models in the global personal data economy in the post-GDPR era—characterized by stringent regulation of personal data—and has now attracted widespread attention globally, from Europe and the United States to emerging market economies.

I. Background of the Conference

On December 20, 2025, following the first conference held on May 1, 2024 in Seoul, the 2rd China Korea International Seminar of MyData was successfully convened in Zhangjiang, Shanghai.

(I) Conference Theme

“People-Centered Approach: Exploring Innovative Pathways for the Factorization and Monetization of Personal Data”

Conference Objectives: To share cutting-edge global developments in personal data governance, personal data circulation, and MyData practices; to showcase the latest domestic practices in the industrial application of data factorization and data monetization; to promote China–Korea cooperation in data rights, data transactions, and trusted applications; to discuss pain points, institutional innovations, and technological pathways in China’s data factor market; and to release research outcomes related to MyData Asia or data factorization, thereby advancing the implementation of cooperative projects.

Basic Information of the Conference:

Conference Title:

The 2rd China Korea International Seminar of MyData

Date & Time:

Saturday, December 20, 2025, 13:00–18:00

Venue:

AI Innovation Center, Shanghai Zhangjiang Fintech DataPort

(No. 56 Fanchang Road, Pudong New Area),

Building 4 (North Wing), 8th Floor, Shanghai

Conference Themes:

Personal Data: Global Development and Practices of MyData

Personal Data in Korea: Explorations and Lessons Learned from MyData

Potential Applications of MyData: Personal Data in China and Emerging Market Economies

Speakers Include:

Mr. Michael LeeAffiliation: MyData Global
Professor Tae Hoon LimAffiliation: Korea University
Professor Yikun XiaAffiliation: Nanjing University
Dr. Chuanwei ZouAffiliation: Jingsu Jinke Research Institute on Digital & Technology Finance
Dr. Xinhai LiuAffiliation: Beijing Credit Society
Professor Jidong ChenAffiliation: Low School of Tongji University
Dr. Zhiqi MaoAffiliation: Ant Group Co., Ltd
Mr. Pengli WangAffiliation: XinwuYitong
Dean Fu ShanAffiliation: Hainan Fiduciary-Data Institude
Mr. Guangyong AnAffiliation: Professional Committee of Credit Management, China Mergers & Acquisitions Association

Positioning of the Seminar:

A platform for experts and scholars in the digital economy from China and South Korea to exchange ideas and insights.

(II) Overview of Participation

The seminar was originally planned as a closed-door workshop with approximately 20 participants. However, due to strong interest from professionals in the field, the final attendance exceeded 50 participants. Top experts in the Korean MyData sector were present, and nearly all major domestic institutions related to personal data sent representatives. These included organizations ranging from the State Information Center to the National Data Administration; from financial information infrastructures such as payment and credit reporting systems to personal credit reporting companies; from telecommunications operators to maritime information institutions; from major technology companies such as Ant Group Co., Ltd to publicly listed data companies; from think-tank experts of the China Academy of Information and Communications Technology to grassroots leaders of local data bureaus, as well as multiple start-ups, open-source communities, and public-interest foundations. Numerous data institutions based in Shanghai also participated actively.

In addition, experts and scholars with diverse disciplinary backgrounds—including economics, information management, digital finance, law, digital technology, public administration, and artificial intelligence—attended the seminar. They came from institutions such as Antai College of Economics and Management of Shanghai Jiao Tong University, the Data Management Innovation Research Center of Nanjing University, the Low School of Tongji University, East China University of Political Science and Law, leading law firms, the China Mergers & Acquisitions Association, and the Beijing Credit Society.

fc1d7a725fc527139d49f9a31fe15512

II. Opening Remarks

(I) Remarks by the Host

Mr. Xiaoqiang Shen, General Manager of Shanghai Fintech DataPort Development Co., Ltd., delivered the welcome address and introduced the development of the Zhangjiang Fintech DataPort. Established in 2003, the Zhangjiang Fintech DataPort welcomed China UnionPay as its first resident project. Subsequently, a number of major financial institutions settled in the park, including Ping An Insurance, Bank of China, Bank of Communications, the Credit Reference Center of the People’s Bank of China, the Clearing Center, the Anti-Money Laundering Center, as well as many other financial institutions. Over the long term, the park has focused on key areas such as payment, clearing, credit reporting, regulation, security, and standards, and is committed to building a practice zone for financial digital transformation, a cluster for financial data enterprises, a demonstration zone for financial data applications, and a pilot zone for financial innovation and regulation.

Mr. Shen noted that, as an important component of the Zhangjiang Group, the Zhangjiang Fintech DataPort serves the overall development of Zhangjiang Science City. At present, Zhangjiang Science City covers a total area of approximately 220 square kilometers and brings together around 500,000 entrepreneurs and 24,000 technology enterprises. Looking ahead, the Fintech DataPort will continue to empower financial institutions and technology companies, and welcomes stakeholders from all sectors to jointly explore new pathways for unlocking data value in the data-driven era and to achieve coordinated development in Zhangjiang.

b09f545b1b845bc5855525c27dcd964e

(II) Conference Introduction by the Domestic Initiator of MyData

Dr. Xinhai Liu, Editor-in-Chief of Data Economy Review and initiator of the conference, introduced the background and origins of The 2rd China Korea International Seminar of MyData. He noted that he has long been engaged in technical work related to artificial intelligence, machine learning, and credit reporting, and through practice has deeply experienced the institutional and real-world challenges surrounding the proper use of personal data. In 2018, while participating in legislative research on the Personal Information Protection Law and related proposals to the National People’s Congress, he further came to recognize the significant differences among regulators, academia, industry, and the international community in their understanding of personal data. This prompted him to begin systematic policy and industry research in the field of personal data.

In 2019, during his research on South Korea’s personal credit reporting reform, Dr. Liu was first introduced to the concept of “MyData.” He has since continuously tracked its global development and became one of the earliest members of MyData Global in China. He emphasized that MyData, centered on the principle of “my data, my control,” represents an important model of data governance and data economy in the post-GDPR era. South Korea’s national-level promotion of MyData has achieved notable results, generating positive impacts for consumers, start-ups, and traditional institutions alike.

Dr. Liu believes that, as the world’s largest consumer data market, China possesses abundant application scenarios and a strong technological foundation, and that MyData is expected to become a new engine driving the high-quality development of China’s data economy. In recent years, his team has continuously promoted the dissemination of MyData-related concepts in China through research, publications, and international exchanges, and has launched MyData Journal, which has generated broad influence across academia, regulatory bodies, and industry. He noted in particular that his visits last year to MyData-related institutions in South Korea and his participation this year in the MyData Global Conference in Finland were highly rewarding, and he expressed his willingness to share these international frontier experiences with participants.

III. Keynote Speeches

The keynote session of the seminar was moderated by Mr. Pengli Wang, Co-founder of XinwuYitong, one of the event organizers known for its geek-oriented style. Mr. Guangyong An, a Korea-based expert in credit reporting and data and a researcher at the Research Institute of the China Mergers & Acquisitions Association, served as the professional interpreter for the two Korean experts participating in the seminar.

9f5e0d63d7062ce9a087cf3e4c617165

(I) Michael Lee, Board Member of MyData Global: Global Progress and Practices of MyData

Mr. Michael Lee, Board Member of MyData Global (the world’s largest non-profit organization dedicated to the personal data economy, established ten years ago and having exerted certain influence on EU policies), shared the latest global progress and practical experiences of MyData at the seminar, and systematically introduced the technological frontiers of MyData in the fields of blockchain and privacy-preserving computation. Mr. Lee has long been committed to research on blockchain-based MyData services and privacy protection technologies. He currently serves as a Board Member of MyData Global, Chief Executive Officer of SNPLab Inc., and Adjunct Professor of Artificial Intelligence Technology Management at the Graduate School of Technology Management of Kyung Hee University. He has worked for more than 27 years at multinational corporations such as Samsung Electronics and Motorola, and has extensive experience in security assessment, privacy policy, and data governance.

In his speech, he reviewed that MyData originated from a “people-centered data sovereignty movement,” with the core objective of enabling individuals to truly control their data, decide how their data is used, and obtain tangible value from data circulation. He pointed out that South Korea has taken the lead in institutionalizing and implementing MyData in sectors such as finance, public services, and healthcare. However, under a government-led and industry-segmented model, structural issues have gradually emerged, including insufficient innovation momentum and limited cross-industry collaboration. The future development of MyData, he argued, should return to the essence of personal sovereignty and avoid the formation of new platform monopolies.

Mr. Lee further shared a new pathway based on an “on-device data model,” under which personal data is stored directly on users’ devices and, combined with blockchain and privacy-preserving computation technologies, enables “data not to move while usage rights move.” This approach aims to truly assetize personal data and allow it to continuously create value. He expressed his expectation to deepen cooperation with China to jointly explore MyData development models with greater practical relevance and tailored to Asian markets, and to work together to advance a people-centered future of the data economy.

(II) Tae Hoon Lim, the Father of MyData in Korea: Exploration and Lessons of MyData in Korea

Professor Tae Hoon Lim, Research Professor at Korea University, systematically shared Korea’s exploration experiences and practical lessons in MyData at the seminar. Professor Lim has long been engaged in research related to MyData and is the author of MyData B.L.T.S., and is widely regarded in the industry as the “Father of MyData in Korea.” He currently serves as a Research Professor at the Institute for Convergence Research of Korea University, and is also involved in data policy research and industrial support work at the Korea Data Agency. For many years, he has provided consulting and services to governments and enterprises in the areas of data governance, data circulation, and industrial applications. His research fields cover MyData, data governance, data transactions, data value assessment, as well as the construction of data standards and quality systems.

Professor Lim pointed out that the rapid implementation of MyData in Korea has benefited from the BLTS ecosystem framework that he proposed and promoted, which advances data systems and industrial development in a coordinated manner across four dimensions: Business, Legal, Technology, and Society. This framework has provided a systematic methodology for the cross-industry promotion of MyData. At the practical level, Korea’s MyData has expanded from the financial sector to multiple scenarios including public services, healthcare, education, and transportation. Individuals are able to download, transfer, and use their own data through standardized APIs, enabling cross-institutional data circulation and service collaboration, such as the sharing of medical records across hospitals, the digitization of academic credentials, and one-stop aggregation of financial accounts.

He emphasized that the right to data portability and the individual’s right to independently decide on the use of personal data have been explicitly incorporated into Korea’s legal system, forming the core foundation for the operation of the MyData framework. However, Professor Lim also noted that Korea’s practice has revealed challenges in areas such as standards coordination, cross-industry collaboration, and public awareness. Looking ahead, he argued that the success of MyData depends not only on technological capabilities, but also on the formation of social consensus and the establishment of mandatory unified standards. He advised that, in advancing institutional innovation for personal data, China should focus on standard systems, legal authorization mechanisms, and shifts in multi-stakeholder perceptions, in order to truly achieve the goal of “returning data to individuals.”

6d15947f72b28a98b4363ef6973b6832

(III) Jidong Chen, Tongji University: Personal Data Spaces and Their Computational Constraints in the Construction of the Data Factor Market

Professor Jidong Chen from the Low School of Tongji University pointed out that the core of future governance will no longer focus solely on data itself, but rather on the concept that “circulation is computation,” requiring the replacement of silo-based system thinking with spatial collaboration. European cases such as Gaia-X and Catena-X demonstrate that data spaces have become an important foundation for promoting industrial collaboration and value-chain innovation. Meanwhile, legal frameworks such as the Data Act and the Data Governance Act are reshaping the landscape of data rights, encouraging enterprises to shift from being “data monopolists” to “data coordinators.” Technical rules and legal rules together constitute a new logic of cooperation and justice, providing important insights for the future circulation of data factors in China.

1873fa02262344e30c97ad915e869e96

(IV) Xinhai Liu, Beijing Credit Society: Applications of MyData in China and Emerging Market Economies

Dr. Xinhai Liu, Vice President of the Beijing Credit Society, shared key takeaways from the 2025 MyData Global Conference and expressed the view that MyData has broader prospects in China and emerging market economies. He proposed the establishment of MyData Asia to leverage global resource allocation and work together with emerging market countries to explore the future of the digital economy.

Dr. Liu pointed out that China possesses the world’s largest personal data infrastructure: platforms such as payments, credit reporting, medical insurance, big technology companies, and telecommunications operators each reach more than one billion users. However, the realization of data dividends faces an “impossible trinity” dilemma—protection pressure, innovation stagnation, and difficulties in data sharing. He emphasized that in the era of artificial intelligence, the real challenge is not data application itself, but rather “whether we trust whom we hand our data over to.” Therefore, it is necessary to build “digital fiduciaries” with ethical and institutional safeguards, enabling data to generate inclusive value while respecting privacy.

He noted that the MyData model offers a solution: through data portability, proactive personal AI assistants, and on-device computing technologies, data is no longer a moat for giants, but becomes common soil for innovation. He called for joint exploration of future digital economy innovation strategies in data governance for emerging market economies worldwide—“using China’s experience and exploration to provide solutions for the world.”

a4d9b0325f2e4b685d7a1185adcff592

IV. Thematic Presentations of the Seminar

(I) Pengli Wang, XinwuYitong: Personal Data Driving Consumption

Mr. Pengli Wang, Founder of XinwuYitong, stated that Chinese-style modernization requires the parallel advancement of spiritual civilization and material civilization. He emphasized that the future digital economy must be built upon trusted personal data spaces, enabling data to be genuinely transformed into a driver of economic growth. He proposed establishing an innovative pilot zone in Shanghai for “personal data–driven consumption” through compliant digital infrastructure based on Web 3.0, forming a consumption incentive model with data traceability and closed-loop fiscal management via mechanisms such as DID digital identities and blockchain-based cultural and tourism vouchers.

He noted that culture and tourism represent the optimal entry point linking consumption tax reform, fiscal structure adjustment, and the practical implementation of the digital economy, and that China has a full opportunity to lead a new global paradigm of the data economy through institutional innovation.

(II) Yikun Xia, Nanjing University: The Current State of Personal Data Governance Research at Home and Abroad

Professor Yikun Xia from the Data Management Innovation Research Center of Nanjing University systematically introduced global development trends in personal data governance. She pointed out that research on personal data has shifted from the traditional paradigm of “privacy protection” to that of “data governance,” with the governance logic evolving from an individual-informed-consent–centered approach toward collaborative governance involving multiple stakeholders and trusted third-party mechanisms. In this context, models such as MyData, data trusts, and data banks have become focal points of international exploration.

Professor Xia emphasized that China must seek an institutional balance between security and development. By innovating governance frameworks, China can address challenges such as insufficient clarification of data rights, conflicts in cross-border rules, and new types of privacy risks brought about by artificial intelligence, thereby building a future governance system that both protects individual rights and unlocks data value.

aa937902774e62a8548dfbcc3ba0fd96

(III) Chuanwei Zou, Jingsu Jinke Research Institute on Digital & Technology Finance: The Architecture of the Personal Data Factor Market

Dr. Chuanwei Zou, President of the Jingsu Jinke Research Institute on Digital & Technology Finance and a well-known scholar in financial technology research, systematically elaborated on the key elements for building a personal data factor market. He pointed out that commercial practices in the digital economy have fully demonstrated the significant monetization value of personal data, while also giving rise to structural problems such as privacy breaches, market imbalances, and information silos. Therefore, the effective circulation of personal data must be based on a clear data property rights regime and a robust security governance framework.

Dr. Zou emphasized that institutions matter more than technology. For data factors to participate in resource allocation, it is necessary to define the boundaries of rights related to the “holding–processing–operation” of personal data and to form fair prices through market mechanisms. He proposed that China should draw lessons from experiences such as open banking, Korea’s MyData, and India Stack. However, he stressed that ordinary individuals are not suited to directly enter the personal data factor market; instead, data aggregation, processing, and agency transactions should be carried out through data trusts, information banks, and professional brokers, with individuals benefiting through revenue return mechanisms.

He concluded that the real driving force behind market formation lies in safeguarding individual rights and incentivizing data controllers to change their behavior, rather than directly regulating and transforming platforms.

118f666bd070ca7758618fcc5603fbc2

(IV) Zhiqi Mao, Ant Group Co., Ltd.: Reflections on the Personal Credit Economy

Dr. Zhiqi Mao, Senior Research Expert at Ant Group Co., Ltd, delivered a keynote speech on “Reflections on the Personal Credit Economy,” proposing that the future construction of China’s credit system will enter a new stage centered on “personal credit assets.” She noted that the personal credit economy represents a new form of economy in which personal credit data serves as the core factor and individuals are the primary rights holders. Through the circulation of data factors and the development of credit systems, it provides credit support for individuals, financial institutions, and enterprises across financing, consumption, transactions, and public social services.

Dr. Mao emphasized that a socialist market economy is essentially a credit-based economy and a rule-of-law-based economy, and that the new credit economy should evolve along three major directions. First, the concretization of personal credit, enabling credit to be “visible and usable” in everyday life scenarios. Second, government participation and utilization in personal credit, providing foundational infrastructure through institutional safeguards and public credit platforms. Third, the industrialized operation of credit, forming market mechanisms in which product systems and operational systems develop in parallel.

f709a105a58bab992e5853871797c023

(V) Shanli Zhang, Shandong University: Consumer Reporting Companies in Vertical Consumption Scenarios—Implications for China’s Data Monetization Path

Mr. Shanli Zhang, Ph.D. candidate at the Law School of Shandong University, delivered a keynote speech entitled Consumer Reporting Companies in Vertical Consumption Scenarios: Implications for China’s Data Monetization. He pointed out that, in addition to traditional credit reporting agencies, an important pillar of the U.S. data economy lies in vertical consumer reporting companies that are deeply embedded in consumption and industrial value chains. These institutions primarily serve B2B clients and, across specific scenarios such as housing rentals, employment, medical billing, telecommunications billing, and vehicle valuation, provide risk identification and price formation capabilities through data processing, thereby achieving a truly commercial closed loop.

He emphasized that current discussions on data factorization in China focus more on institutions and regulation, but what ultimately determines the success of monetization is “who can transform data into decision-making capabilities and persuade enterprises to pay for risk reduction or price formation.” Therefore, as China advances the development of personal data markets, data trusts, and information banks, it should simultaneously deploy industry-specific consumer reporting institutions and, through trusted data agency mechanisms, ensure the return of benefits to individuals—so that data is not merely “seen,” but can truly be “realized.”

Dr. Fu Shan, President of the Hainan Fiduciary-Data Institude, shared new trends in legislation related to the digital economy and digital finance.

2bd326ba0e899bb51af2c021c5de44c5

During the open discussion session, Mr. Chunxue Xu, Director of the Public Service Department of State Information Center; Professor Yongguo Xu from the Antai College of Economics and Management of Shanghai Jiao Tong University; Ms. Xiaoyan Ke from the China Telecom Research Institute; Mr. Li Chen, Deputy Director of the Hechuan District Data Bureau of Chongqing Municipality; and Mr. Xin Wang, Vice President of Weiyan Technology, respectively took the floor to share their perspectives on personal data as well as their reflections on participating in the seminar.

76109975109178ee9b612893d1e4e0f3
a1e18b3457ff07af174d2681e99ed312

After the formal seminar concluded, sponsored by XinwuYitong, Chinese and international participants proceeded together to the Pujiang Dragon Boat Night Banquet, where they continued discussions on the data economy.

cb47b279da224646106a9102200af69b

V. Release of Seminar Outcomes

This seminar released three annual outcome reports and shared two new works by participating guests. Other outcomes, including additional presentations by seminar participants, will be gradually compiled and released to the public at a later stage.

(I) Release of the Chinese Translation of MyData B.L.T.S. (Chinese Title: A New Engine of the Digital Economy—Building the MyData Ecosystem)

This is a professional book on the MyData business model and ecosystem development. The author team includes Professor Tae Hoon Lim from Korea University and other scholars with profound research foundations in the field of MyData. The book provides an in-depth exploration of MyData as an emerging global data economy model, with a particular focus on its business logic, legal frameworks, technological pathways, and social impacts in the post-GDPR era. MyData aims to be people-centered, empowering individuals with self-determination over their own data while promoting innovation in the digital economy, and has been successfully implemented in Korea with remarkable results.

The book elaborates in detail on how to build a healthy data ecosystem through MyData, supporting the circulation of personal data and trust-based innovative services. Its content covers MyData from multiple perspectives, including legal, technological, service-related, and social impacts, providing valuable practical experience and theoretical foundations for practitioners in the fields of global data governance and the data economy.

Since its initial release in 2022, the book has attracted widespread attention in Korea and globally. To promote its dissemination in the Chinese market, the translation team is composed of well-known domestic data experts who, in combination with the characteristics of the Chinese market, strive to translate the concepts and applications of MyData into practical implementation, thereby advancing data factorization and the development of the personal data economy in China. The book is scheduled for publication in the first half of 2026.

5d17ba4a1457feca8bdcddf2e23f19f8

(II) MyData Annual Report (to Be Released Upon Authorization from MyData Global)

The core of this report centers on MyData, a people-centered personal data management model. Based on the MyData Global Conference held in September 2025 in Finland, the report explores how to balance data protection, data utilization, and economic value creation in the context of artificial intelligence and increasingly stringent global regulation. The conference brought together internationally renowned experts in the fields of data governance, law, and technology. The conference content mainly covered four interrelated areas:

(1) Governance, Law, and Policy;

(2) Technology, Interoperability, and Data Spaces;

(3) AI and Personal Agents;

(4) Sectoral Applications and Emerging Markets.

The MyData concept aims to build a fair, sustainable, and prosperous digital society. Its core lies in empowering individuals with control over their personal data, enabling them to acquire knowledge, make informed decisions, and interact effectively with other individuals and organizations. This concept proposes a set of principles and three major paradigm shifts, has been translated into more than a dozen languages, and has been endorsed by nearly 2,000 individuals and organizations.

261c4fe2912ae4599085a169a4be97ed

(III) Release of the Report Research on Innovative Models for the Development and Utilization of Global Personal Data

This report was jointly developed by the China Telecom Research Institute and Haiyang Jinzhi Data Technology (Beijing) Co., Ltd.. The report aims to explore innovative models for the development and utilization of personal data on a global scale, analyzing their concepts, current development status, characteristics, outcomes, and the challenges they face. It selects several representative models for in-depth study, including personal credit reporting, professional consumer reporting companies, data brokers, data trusts, and open banking, and also examines data practices in emerging market economies as well as data models of three major large technology platforms. In addition, the report places particular emphasis on introducing Korea’s MyData model, analyzing its characteristics and its reference value and implications for China. Through an examination of these models, the report seeks to provide useful insights on how to strike a balance between protecting personal privacy, promoting data-driven innovation, and achieving fair competition.

bec7d08e9e525f9c8ec85ce1d5d2886a

(IV) MyData and Data Sovereignty in the Age of AI

A work by Mr. Michael Lee, Board Member of MyData Global:

MyData and Data Sovereignty in the Age of AI

Overview:

The era of data sovereignty has arrived, and the world is transitioning toward a data-driven society. From the perspectives of big data and personal data, this book explores issues related to data ownership. Innovative services that integrate technologies such as blockchain, virtual reality/extended reality (VR/XR), and artificial intelligence (AI) are emerging one after another; however, what ultimately drives these innovative services is personal data.

Accordingly, the ownership, scope, and modes of use of data are also undergoing transformation. Data ownership is shifting from centralized to decentralized, from corporate ownership to individual ownership, and from big-data-based approaches to personal-data-based approaches.

From the perspectives of data sovereignty and the GDPR, the book elaborates on “MyData” and the changes it is expected to bring, and provides an in-depth discussion of the impact of artificial intelligence on “MyData.” The author proposes a people-centered and practically feasible implementation approach to “MyData,” and, in particular, puts forward a technical solution for the utilization of personal data based on data sovereignty.

In addition to policy discussions related to data sovereignty and personal data, the book also outlines research on data technology applications. It helps deepen the understanding of technological, policy, and market developments related to MyData.

eb80c93e4a077b1da30f2ea0b0b5c220

(V) A New Interpretation of Data

Authored by Mr. Li Chen, Deputy Director of the Data Bureau of Hechuan District, Chongqing Municipality.

A New Interpretation of Data advances the view that the state should build a universal network identity account for all users that is applicable across all industries, and that this account should be controlled to the greatest possible extent by the users themselves. Under overall national coordination, users would thereby regain data rights that allow them to engage in equal dialogue with platforms. Unlike the decentralization perspective of Web3 (the third generation of the Internet, a decentralized network built on blockchain technology), the book starts from the interrelated logic of “people, data, and time,” arguing for the establishment of a time-element–centered data network ecosystem that is “based on a national user management system, with users’ autonomous choice over the time traces of their data activities as the core.”

Using the foundational element of account existence—the “account”—as an entry point, the book analyzes, explains, and demonstrates, from the perspectives of current problems in data transformation, background logic, and response strategies, the necessity, urgency, and feasibility of building time-based accounts that take the time of individuals’ data activities as the sole reference element. When all data information associated with an individual is first linked to the user through a unique, time-based account, then all data generated by human behavior can be primarily controlled by the individual who has expended the time to perform those activities. In this way, people can truly feel secure in digitizing all activity behaviors and interacting—through digital twins—with others, with society, and with the past and the future.

Subsequently, a series of evolutions may gradually be realized, including the creation of a unique digital portal for individuals in cyberspace, the logical attribution of data property rights to users’ time traces, the controllable trading of data assets that become uniquely locked due to changes in time traces, and integrated sanctions against accounts involved in digital illegal activities. Under account rules that are controllable by users themselves, platforms’ practices of leveraging the overwhelming advantages of account agreements to obtain improper benefits will become unsustainable, prompting a shift toward better services and innovation.

38c418acfa57a2d7369b99b4c7e848b8

VI. Organizers of the Seminar

Organizers:

Beijing Credit Society

Data Economy Review & MyData China

Shanghai Fintech DataPort Development Co., Ltd.

XinwuYitong Digital Technology (Shanghai) Co., Ltd.

Co-organizers:

Haiyang Jinzhi Data Technology (Beijing) Co., Ltd.

Professional Committee of Credit Management, China Mergers & Acquisitions Association

39b311c914e4ff6c5e94378d9e717b4a

Special thanks are extended to the conference staff from the Fintech DataPort, XinwuYitong, and Haiyang Jinzhi for their support and contributions.

VII. Next Steps

The seminar also discussed preparations for MyData Asia. On the one hand, it aims to deepen domestic exchanges and discussions and promote collaboration among industry, academia, and research institutions; on the other hand, it seeks to bring together top global experts and industry organizations, absorb and draw upon international practical experience, and explore solutions for the monetization of personal data.

Personal data concerns the digital future of China’s 1.4 billion consumers and, from a global perspective, is closely linked to the digital dividends of 8 billion people worldwide. Data Economy Review will continue to build China’s MyData community by bringing together industry forces through professional exploration, running the MyData Journal effectively, and providing professional services such as timely dissemination of the latest global developments, sharing member information, integrating resources, and facilitating seminars and exchanges, in order to jointly explore innovative development pathways for China’s personal data economy.

0b6cc4949387702325821193f224fc6b

Order No. 4 [2021] of the People’s Bank of China (Measures for the Administration of Credit Reporting Services)

Order No. 4 [2021] of the People’s Bank of China

The Measuresfor the Administration of Credit Reporting Services, adopted on September 17, 2021 at the ninth executive meeting of the People’s Bank of China in 2021, is hereby issued   and shall come into force as of January 1, 2022.

Yi Gang, Governor of the People’s Bank of China

September 27, 2021

Measures for the Administration of Credit Reporting Services

Chapter I  General Provisions

Article 1 This Measures is formulated in accordance with the Law of the People Republic of China on the People Bank of China, the Personal Information Protection Law of the People Republic of China, the Regulation on the Administration of Credit Reporting Industry, and other applicable laws and regulations to regulate credit reporting services and  related activities, protect the legitimate rights and interests of information subjects, promote the healthy development of the credit reporting industry, and strengthen the social credit system.

Article 2 This Measures applies to the credit reporting services and related activities conducted within the mainland of the People’s Republic of China in relation to corporations and unincorporated organizations (hereinafter referred to as “enterprises”) and individuals.

Article 3 For the purpose of this Measures, credit reporting services refer to the collection, organization, preservation, and processing of the credit information of enterprises and individuals and the provision of such credit information to information users.

For the purpose of this Measures, credit information refers to the basic information, lending information, and other relevant information lawfully collected to identify and assess the credit status of enterprises and individuals to facilitate financial and other activities, as well as the analyses and evaluations made based on the forgoing information.

Article 4 Businesses that engage in credit reporting services for individuals shall lawfully obtain the consumer credit reporting agency license from the People’s Bank of China (“PBC”); businesses that engage in credit reporting services for enterprises shall lawfully complete the filing process for commercial credit reporting agencies; businesses that engage in credit rating services shall lawfully complete the filing process for credit rating agencies.

Article 5 Financial institutions shall not enter a business relationship with any market entity for its credit services if the market entity is not legally qualified to provide credit reporting services.

For the purpose of this Measures, financial institution refers to any institution that engages in financial business under the regulation and supervision of the financial regulatory authority under the State Council.

Local financial organizations regulated and supervised by local financial regulatory authorities are subject to the provisions of this Measures on financial institutions.

Article 6 Any businesses that engage in credit reporting services and related activities  shall protect the lawful rights and interests of the information subjects, ensure the safety and security of information, and prevent the leakage, loss, destruction, or misuse of credit information, and shall not undermine state secrets, invade personal privacy, or commit breach of confidential business information.

Credit reporting services and related activities shall be conducted on an independent, objective, and impartial basis and shall not violate relevant laws and regulations or offend public order or good morals.

Chapter II  Collection of Credit Information

Article 7 Consumer credit information shall be collected in a lawful and proper manner, in accordance with the principles of data minimization, and strictly on an “as needed” basis.

Article 8 A credit reporting agency shall not collect credit information:

(1) through deception, coercion, or inducement;

(2) by charging a fee from the information subjects;

(3) through illegitimate channels; or

(4) through any other method that harms the legitimate rights and interests of the information subjects.

Article 9 Where a credit reporting agency obtains credit information from an information provider, the credit reporting agency shall establish relevant rules to conduct the necessary checks on such matters as the source, quality, and safety and security of such information and the authorization from the information subjects.

Article 10 Credit reporting agencies and information providers, in conducting business and collaborations, shall comply with laws and regulations including the Personal Information Protection Law of the People Republic of China and specify, through an agreement or other means, the principles governing information collection and their respective rights, obligations, and responsibilities in relation to such matters as the obtainment of customer consent; the collection, processing, and correction of information; dispute resolution; and information safety and security.

Article 11 Any credit reporting agency that engages in consumer credit reporting services shall develop an information collection plan and report to the PBC such matters as the data items to be collected, source of information, methods of collection, and rules governing the protection of information subjects as well as any changes to the foregoing.

Article 12 Any credit reporting agency that collects consumer credit information shall obtain consent from the information subjects and expressly inform them of the purpose of collection, except for information that is made publicly available according to laws and  regulations.

Article 13 Where a credit reporting agency obtains personal consent through an information provider, the information provider shall fulfil the informing obligation to relevant information subjects.

Article 14 Each consumer credit reporting agency shall report to the PBC its partnering information providers that collect, organize, process, and analyze consumer credit information.

A consumer credit reporting agency shall standardize its collaboration agreements with information providers. An information provider shall accept the risk assessments conducted by consumer credit reporting agencies and the fact checks by the PBC with respect to its handling of consumer credit information.

Article 15 Enterprise credit information shall be collected for lawful purposes and not in a manner that constitutes a breach of confidential business information.

Chapter III Organization, Preservation, and Processing of Credit Information

Article 16 A credit reporting agency shall observe the principles of objectivity in    organizing, preserving, and processing credit information and shall not tamper with the original information.

Article 17 A credit reporting agency shall take Measures to improve the accuracy of information in its credit reporting system and ensure the quality of information.

Article 18 Where a credit reporting agency identifies any error in credit information during information organization, preservation, or processing, it shall promptly notify the relevant information provider to make corrections if the error is transmitted from the information provider, or promptly correct the error and optimize its internal processing procedures for credit information if the error originates from its internal processing.

Article 19 A credit reporting agency shall cross-check the information obtained from  different information providers and verify and resolve inconsistencies in a timely manner.

Article 20 Each credit reporting agency shall retain an individual’s negative entry for five years from the day when the negative behavior or event ceases to exist. 

Upon the expiration of this retention period, the negative entry shall be removed by the credit reporting agency from its external services and applications, or, if it is to be used as sample data, be anonymized.

Chapter IV Provision and Use of Credit Information

Article 21 In providing credit reporting products and services to external parties, a credit reporting agency shall observe the principle of fairness by not establishing any unreasonable commercial terms and conditions that restrict the use of information by different information users or by taking advantage of its position to provide discriminatory or exclusive products and services.

Article 22 Credit reporting agencies shall take appropriate Measures to check the identity, business qualifications, purpose of use of information, and other pertinent aspects of information users.

Credit reporting agencies shall assess the security and compliance management Measures of the networks and systems used by information users to access the credit reporting system, and shall monitor their queries. A credit reporting agency shall promptly verify any security risk or abnormal behavior and, upon discovering any illegal activity or misconduct, terminate its service.

Article 23 Each information user shall take the necessary Measures to ensure that it has obtained the consent of the relevant information subjects when querying consumer credit information and that it is using such information for the purposes agreed upon.

Article 24 An information user shall use the credit information provided by a credit reporting agency for lawful and legitimate purposes and shall not misuse it.

Article 25 Each individual information subject is entitled to his own credit report twice a year without charge. Credit reporting agencies may provide such credit report services over the internet, at places of business, or by other means.

Article 26 An information subject believing that there is any error or omission in its credit information may file a dispute with the relevant credit reporting agency or information provider. An information subject believing that its legitimate rights and interests are violated may file a complaint with the relevant branch of the PBC. Such disputes and complaints shall be handled in accordance the Regulation on the Administration of Credit Investigation Industry and other relevant provisions.

Article 27 No credit reporting agency may charge information subjects a fee for removing or not collecting negative entries.

Article 28 A credit reporting agency that provides credit reports and other credit information products and services shall present the requested credit information in an objective manner and provide explanations on the contents and specialized terms therein.

An information subject has the right to require a credit reporting agency to include a note of dispute or a consumer statement in its credit report.

Article 29 Any credit reporting agency that provides credit assessment products and services, such as credit profiling, scoring, or rating, shall establish the assessment criteria, which may not contain any element that is irrelevant to the credit status of the information subjects.

Before officially providing credit assessment products or services to external parties, a credit reporting agency shall perform the necessary internal tests and assessment and verification procedures to ensure its evaluation rules can be explained and the information is traceable.

Credit reporting agencies that provide credit rating products and services for economic entities or debt financing instruments shall conduct such businesses in accordance with the Interim Measures for the Administration of Credit Rating Industry (Order No. 5 [2019] of the People’s Bank of China, the National Development and Reform Commission, the Ministry of Finance, and the China Securities Regulatory Commission) and other relevant provisions.

Article 30 A credit reporting agency that offers anti-credit fraud products and services shall establish the criteria for determining fraudulent credit information.

Article 31 A credit reporting agency that offers credit information query, credit evaluation, and anti-credit fraud products and services shall submit the following to the PBC or one of its branches at or above the level of central sub-branch of the capital city of a province or autonomous region:

(1) the template and contents of its credit report;

(2) the assessment methodology, models, and major analytical dimensions and elements of its credit assessment  products and services; and

(3) for anti-fraud products and services, the sources of data and determination criteria for fraudulent credit information.

Article 32 No credit reporting agency may:

(1) make promises on the results of credit assessment;

(2) advertise products and services using implicit languages in regard to the credit assessment results;

(3) market its products or services in the name of government agencies or trade associations without their consent;

(4) provide credit reporting products or services to information subjects or information users through coercion, deception, or inducement;

(5) engage in false advertising for its credit reporting products or services; or

(6) offer any other credit reporting products or services that would undermine the objectivity and impartiality of credit reporting services.

Chapter V Safety and Security of Credit Information

Article 33 Credit reporting agencies shall implement the cybersecurity multi-level protection scheme; establish security protocols for relevant business activities, equipment, and facilities; and take effective safeguards to ensure the safety and security of the credit reporting system.

Article 34 Each consumer credit reporting company and each commercial credit reporting company that preserves or processes the credit information of 1,000,000 or more enterprises shall meet the following requirements:

(1) the core business information system has attained Level 3 in the cybersecurity multi-level protection scheme or above;

(2) the positions of head of information security and head of personal information protection have been established and are assumed by the officers designated in the corporate articles of association; and

(3) a specialized department is set up which is responsible for information security and protection of personal information and for periodically reviewing the enforcement of rules and regulations on credit reporting services, system safety and security, and protection of personal information.

Article 35 A credit reporting agency shall ensure the safety and security of the operational facilities and equipment, security control facilities and equipment, and internet application programs of its credit reporting system; properly manage the system’s day-to-day operation and maintenance; and ensure the safety and security of the physical system, communication networks, zone boundaries, computing environment, and administration center, to protect the credit reporting system from unauthorized access and sabotage.

Article 36 A credit reporting agency shall properly manage the personnel-related safety and security issues in relation to recruitment, termination, evaluation, safety and security education, training, and visitor management.

Article 37 A credit reporting agency shall strictly limit the authority and scope of its staff members who can query and access credit information through internal systems.

A credit reporting agency shall retain the activity log of its staff members ’ query and access of credit information, which should clearly record the time, method, contents, and purpose of such queries and access.

Article 38 A credit reporting agency shall have in place an emergency response framework such that, at the occurrence or likely occurrence of a leak of credit information or a similar event, it can take immediate and necessary actions to mitigate the damage and promptly report the situation to the PBC and one of its branches at or above the level of central sub-branch of the capital city of a province or autonomous region.

Article 39 With respect to the credit reporting services and related activities provided or conducted within the mainland of the People’s Republic of China by a credit reporting agency, the enterprise and consumer credit information so collected shall be stored within the mainland of the People’s Republic of China.

Article 40 A credit reporting agency shall comply with applicable laws and regulations when providing consumer credit information to overseas parties.

Any credit reporting agency that offers enterprise-credit-information query products and services to overseas information users shall conduct the necessary checks on the identity of  the information users and their purposes of use, so as to ensure that such information is used for cross-border trades, investment and financing, or other reasonable purposes and will not harm national security.

Article 41 Any credit reporting agency that collaborates with an overseas credit reporting agency shall file the collaboration agreement with the PBC after executing it and before commencing the collaboration program.

Chapter VI Supervision

Article 42 A credit reporting agency shall disclose the following information to the public and accept public supervision:

(1) the types of credit information collected;

(2) the basic format and contents of the credit report;

(3) the dispute handling process; and

(4) other items whose disclosure is deemed necessary by the PBC.

Article 43 A consumer credit reporting company shall conduct annual audits of the compliance of its consumer credit reporting services with the Personal Information Protection Law of the People Republic of China and the Regulation on the Administration of Credit Investigation Industry, and submit the compliance audit reports to the PBC in a timely manner.

Article 44 The PBC and its branches at or above the level of central sub-branch of the capital city of a province or autonomous region shall supervise and inspect the following   aspects of a credit reporting agency:

(1) its internal controls for credit reporting services, including the completeness, compliance, and viability of various rules and procedures;

(2) the state of compliance of its credit reporting services, covering the compliance of its collection of credit information, provision and use of credit information, handling of disputes and complaints, user management, and other relevant matters;

(3) the safety and security of its credit reporting system, covering IT rules, security management, and system development; and

(4) other aspects related to its credit reporting activities.

Article 45 The PBC and its branches at or above the level of central sub-branch of the capital city of a province or autonomous region shall inspect and penalize any information provider or information user that violates the provisions of the Regulation on the Administration of Credit Investigation Industry by harming the legitimate rights and interests of information subjects.

Chapter VII  Legal Liabilities

Article 46 Any businesses that violate Article 4 of this Measures by engaging in consumer credit reporting services without approval will be penalized by the PBC in accordance with Article 36 of the Regulation on the Administration of Credit Investigation Industry. Any businesses that engage in enterprise credit reporting services without approval will be penalized by the relevant PBC branches at or above the level of central sub-branch of the capital city of a province or autonomous region in accordance with Article 37 of the Regulation on the Administration of Credit Investigation Industry.

Where a financial institution violates Article 5 of this Measures by entering a business relationship with a market entity for credit reporting services even though the market entity is not legally qualified to provide such services, the PBC shall order the financial institution to make corrections and impose a fine of not more than RMB30,000 on the financial institution  and a fine of not more than RMB1,000 on the person-in-charge with direct responsibilities.

Article 47 A credit reporting agency that violates Article 8, Article 16, Article 20, Article 27, or Article 32 of this Measures will be penalized by the PBC or the relevant branches at or above the level of central sub-branch of the capital city of a province or autonomous region in accordance with Article 38 of the Regulation on the Administration of Credit Investigation Industry.

Article 48 A credit reporting agency that violates Article 14, Article 21, Article 31, Article 34, Article 39, or Article 42 of this Measures will be ordered to make corrections by the PBC or the relevant PBC branches at or above the level of central sub-branch of the capital city of a province or autonomous region, have its illegal gains confiscated, and be imposed a fine of not more than RMB30,000 on the credit reporting agency itself and a fine of not more than RMB1,000 on the person-in-charge with direct responsibilities. Where laws and administrative regulations provide otherwise, those provisions shall prevail.

Chapter VIII Ancillary Provisions

Article 49 This Measures applies mutatis mutandis to the submission and query of credit information at the Financial Credit Information Basic Database by institutions connected to the database and engaged in credit reporting services or lending activities.

Article 50 This Measures applies to institutions that substantively provide credit reporting services to external parties in the name of “credit information service,” “credit service,” “credit scoring,” “credit rating,” or “credit repair.”

Article 51 Institutions that substantively engage in credit reporting services but have not obtained license for consumer credit reporting services or completed filing for commercial credit reporting companies before the effectiveness of this Measures, shall achieve compliance within 18 months from the effectiveness of this Measures.

Article 52 The PBC reserves the right to interpret this Measures.

Article 53 This Measures takes effect on January 1, 2022.

Regulation on the Administration of Credit Investigation Industry

(Order of the State Council of the People’s Republic of China No. 631)

The Regulation on the Administration of Credit Investigation Industry, as adopted at the 228th executive meeting of the State Council on December 26, 2012, is hereby issued, and shall come into force on March 15, 2013.

Premier Wen Jiabao

January 21, 2013

Chapter I General Provisions

Article 1 This Regulation is made to regulate credit investigation activities, protect the legal rights and interests of the parties concerned, guide and promote the healthy development of credit investigation industry and enhance the building of the social credit system.

Article 2 This Regulation applies to credit investigation and the relevant activities carried out inside China. For the purpose of this Regulation, the term“credit investigation” refers to activities of collecting, arranging, saving and processing the credit information of enterprises, public institutions and other organizations (hereinafter referred to as “enterprises”) as well as individuals, and providing it to information users. The collection, arrangement, saving, processing and provision of information by the Basic Financial Credit Information Database formed by the state shall be governed by Chapter V of this Regulation. This Regulation is not applicable when state organs, or organizations authorized bylaws or regulations with the function of administering public affairs, collect, arrange, save, process and publish information of enterprises and individuals for the purpose of performing duties under laws, administrative regulations and the State Council provisions.

Article 3 Those engaged in credit investigation and the relevant activities shall abide bylaws and regulations and keep good faith, and may not endanger state secrets or infringe upon trade secrets or personal privacy.

Article 4 The People’s Bank of China (hereinafter referred to as “the supervisory and administrative department of credit investigation under the State Council”) and its local offices shall supervise and administer credit investigation industry by law. The local people’s governments at or above the county level and the relevant departments under the State Council shall enhance the building of social credit systems in the local regions and the relevant industries, develop the credit investigation market and promote the development of credit investigation industry.

Chapter II Credit Investigation Institutions

Article 5 For the purpose of this Regulation, the term “credit investigation institution” refers to legally formed institutions mainly engaged in credit investigation.

Article 6 To form a credit investigation institution engaged in individual credit investigation, it is required to satisfy the following conditions in addition to those set forth by the Company Law of the People’s Republic of China for the formation of companies, and obtain the approval of the supervisory and administrative department of credit investigation under the State Council:

1. Its principal shareholders have a good credit standing and have no record of gross violations of laws or regulations in the last three years;

2. Its registered capital is not less than 50 million yuan;

3. It is equipped with facilities, devices, systems and measures which satisfy the requirements of the supervisory and administrative department of credit investigation under the State Council to ensure information security;

4. Persons to be its directors, supervisors and senior managers satisfy the eligibility requirements as set forth by Article 8 of this Regulation; and

5. Other prudential conditions as set forth by the supervisory and administrative department of credit investigation under the State Council.

Article 7 To apply for forming a credit investigation institution engaged in individual credit investigation, the applicant shall submit an application form and materials proving its satisfaction of conditions specified in Article 6 of this Regulation to the supervisory and administrative department of credit investigation under the State Council. The supervisory and administrative department of credit investigation under the State Council shall examine the application by law, and make a decision of approval or disapproval within 60 days after accepting the application. In the case of approval, it shall issue an individual credit investigation   business operation permit; in the case of disapproval, it shall give reasons in writing. A credit investigation institution formed to operate individual credit investigation business upon approval shall handle registration formalities at the company registration organ on the basis of the individual credit investigation business operation permit. No entity or individual may engage in individual credit investigation without the approval of the supervisory and administrative department of credit investigation under the State Council.

Article 8 The directors, supervisors and senior managers of a credit investigation institution engaged in individual credit investigation shall be familiar with laws and regulations governing credit investigation, have experience and management ability required for performing duties in credit investigation industry, have no record of gross violations of laws or regulations in the last three years, and have the qualification ratified by the supervisory and administrative department of credit investigation under the State Council.

Article 9 For the formation of branch offices, merger or split, change of registered capital, or change of shareholders whose investment accounts for 5% or more of the total capital or shareholders holding shares accounting for 5% or more of the total shares, a credit investigation institution engaged in individual credit investigation shall obtain the approval of the supervisory and administrative department of credit investigation under the State Council. For the change of name, a credit investigation institution engaged in individual credit investigation shall file it with the supervisory and administrative department of credit investigation under the State Council.

Article 10 To form a credit investigation institution engaged in enterprise credit investigation, it is required to satisfy conditions set forth by the Company Law of the People’s Republic of China, and, on the basis of the following materials, handle filing formalities at the local office of the supervisory and administrative department of credit investigation under the State Council within 30 days after its registration is approved by the company registration organ:

1. its business license;

2. an explanation on its equity structure or organizational setup;

3. basic information about its scope of business, business rules and business systems; and

4. information security and risk prevention measures. For any change in matters to be filed, it is required to handle modification formalities at the original filing organ within 30 days as of the day of change.

Article 11 Credit investigation institutions shall report their credit investigation business operations of the last year according to the requirements of the supervisory and administrative department of credit investigation under the State Council. The supervisory and administrative department of credit investigation under the State Council shall announce the lists of credit investigation institutions engaged in individual credit investigation and those engaged in enterprise credit investigation to the general public, and update such lists betimes.

Article 12 When a credit investigation institution is dissolved or lawfully declared bankrupt, it is required to report to the supervisory and administrative department of credit investigation under the State Council, and dispose of its information database in the following way:

1. transferring the database to another credit investigation institution if it has reached an agreement thereon with the said credit investigation institution and obtained the approval of the supervisory and administrative department of credit investigation under the State Council;

2. transferring the database to a credit investigation institution designated by the supervisory and administrative department of credit investigation under the State Council when it fails to transfer the database in the way described in the preceding paragraph; or

3. destroying the database under the supervision of the supervisory and administrative department of credit investigation under the State Council when it fails to  transfer the database in the way described in either of the preceding paragraphs. When a credit investigation institution engaged in individual credit investigation is dissolved or lawfully declared bankrupt, it shall make an announcement at a medium designated by the supervisory and administrative department of credit investigation under the State Council, and surrender its individual credit investigation business operation permit to the supervisory and administrative department of credit investigation under the State Council for cancellation.

Chapter III Credit Investigation Rules

Article 13 To collect personal information, it is required to obtain the consent of the subject of the information. Otherwise, it may not be collected, unless for information which should be disclosed under laws or administrative regulations. Information about the performance of duties by directors, supervisors or senior managers of enterprises is not categorized as individual information.

Article 14 Credit investigation institutions are prohibited to collect information about the religious belief, gene, fingerprints, bloodtype, disease or medical history of individuals, as well as other individual information the collection of which is prohibited bylaws or administrative regulations. Credit investigation institutions may not collect information about the income, deposit, negotiable securities, commercial insurance, real property or taxes of individuals, unless they have expressly informed the individuals concerned of the possible adverse consequences that may be brought along with the provision of such information and have obtained their written consent.

Article 15 Before providing bad information about an individual to a credit investigation institution, the provider shall inform the said individual, unless for bad information that should be disclosed under laws or administrative regulations.

Article 16 Credit investigation institutions shall keep the bad information of individuals for five years from the daywhen the bad behavior or event stops. Upon   the expiration of five years, such information shall be deleted. During the period of retention of bad information, the subject of the bad information may make an explanation on the bad information, and the credit investigation institutionshall put it on record.

Article 17 Information subjects may inquire of credit investigation institutions about their information. Individual subjects have the right to have access to their own credit reports twice every year without paying fees.

Article 18 To inquire of credit investigation institutions about personal information, it is required to obtain the written consent of the information subject and reach an agreement with the subject on the use of such information, except for information which can be inquired about without consent as prescribed bylaws. Credit   investigation institutions may not provide personal information in violation of the preceding paragraph.

Article 19 A credit investigation institution, information provider or information user shall, when using a format contract to obtain the consent of the individual information subject, give prompts conspicuous enough to catch the attention of the individual and make explicit explanations as required by the individual.

Article 20 Information users shall use the personal information according to the stipulations in the agreement with the individual information subjects, and may not use it for other purposes or provide it to third parties without the consent of individual information subjects.

Article 21 Credit investigation institutions may collect enterprise information from sources such as information provided by information subjects, counterparties of enterprises and industry associations, information lawfully disclosed by the relevant governmental departments and judgments or decisions announced by people’s courts. Credit investigation institutions may not collect enterprise information the collection of which is prohibited bylaws or administrative regulations.

Article 22 Credit investigation institutions shall, according to the provisions of the supervisory and administrative department of credit investigation under the State Council, establish, improve and strictly implement information security rules, and take effective technical measures to guarantee information security. Credit investigation institutions engaged in individual credit investigation shall explicitly specify their staff members’ privileges and procedures to inquire about personal information, and register the inquiries made by their staff members about personal information by truthfully recording the name of staff members making inquiries, the time of inquiry, and the content and use of information. Staff members may not inquire about information in violation of the prescribed privileges or procedures or divulge information which they have access to in work.

Article 23 Credit investigation institutions shall take reasonable measures to ensure the accuracy of information provided by them. Information provided by credit investigation institutions may be used by information users as reference.

Article 24 For information collected inside China, credit investigation institutions shall arrange, save and process it inside China. To provide information to overseas organizations or individuals, credit investigation institutions shall abide bylaws, administrative regulations and the relevant provisions of the supervisory and administrative department of credit investigation under the State Council.

Chapter IV Demurs and Complaints

Article 25 An information subject holding that there is any error or omission in the information collected, saved or provided by a credit investigation institution has the right to raise a demur to the credit investigation institution or information provider, requesting for a correction. After receiving such a demur, the credit  investigation institution or information provider shall label the information concerned as demurred at according to the provisions of the supervisory and administrative department of credit investigation under the State Council, check and handle it within 20 days as of the day when the demur is received, and give a written reply to the demurrer. If it is found out upon check that there is an error or omission, the information provider or credit investigation institution shall correct it; if it has been confirmed that there is no error or omission, the label shall be removed; if it is unable to decide whether there is an error or omission upon check, the checking process and the demur shall be put on record.

Article 26 Information subjects holding that any credit investigation institutions, information providers or information users have infringed upon their legal rights    and interests may lodge complaints to the local offices of the supervisory and administrative department of credit investigation under the State Council. The local offices of the supervisory and administrative department of credit investigation under the State Council shall check and handle in a timely manner, and give written replies to complainants within 30 days as of the date of acceptance. Information subjects holding that any credit investigation institutions, information providers or information users have infringed upon their legal rights and interests may directly bring charges to people’s courts.

Chapter V Basic Financial Credit Information Database

Article 27 The state shall establish a Basic Financial Credit Information Database to provide information services for preventing financial risks and enhancing the development of the financial sector. The Basic Financial Credit Information Database shall be built, run and maintained by a specialized non-for-profit institution subject to the supervision and administration of the supervisory and administrative department of credit investigation under the State Council.

Article 28 The Basic Financial Credit Information Database receives credit information provided by institutions engaged in credit business according to the relevant provisions. The Basic Financial Credit Information Database provides inquiry services for information subjects and information users that have obtained the written consents of information subjects. State organs may inquire about information at the Basic Financial Credit Information Database by law.

Article 29 Institutions engaged in credit business shall provide credit information to the Basic Financial Credit Information Database according to the relevant provisions. Before providing credit information to the Basic Financial Credit Information Database or other subjects, institutions engaged in credit business shall obtain the written consent of information subjects and be governed by this Regulation as information providers.

Article 30 The specific measures for financial institutions not engaged in credit business to provide credit information to or inquire about credit information from the Basic Financial Credit Information Database and for the database to accept credit information provided by such financial institutions shall be made by the     supervisory and administrative department of credit investigation under the State Council together with the relevant financial supervisory and administrative department under the State Council.

Article 31 The institution operating the Basic Financial Credit Information Database may collect inquiry service charges on the cost compensation principle. The charging rates shall be determined by the price administrative department under the State Council.

Article 32 Articles 14, 16, 17, 18, 22, 23, 24, 25 and 26 of this Regulation apply to the institution operating the Basic Financial Credit Information Database.

Chapter VI Supervision and Administration

Article 33 The supervisory and administrative department of credit investigation under the State Council and the local offices thereof shall, according to laws,    administrative regulations and the State Council provisions, perform supervisory and administrative duties on the credit investigation industry and the institution operating the Basic Financial Credit Information Database, and may take the following supervision and inspection measures:

1. entering credit investigation institutions and the institution operating the Basic Financial Credit Information Database to make on-site inspections, and checking whether institutions providing information to or acquiring information from the Basic Financial Credit Information Database have observed this Regulation;

2. interviewing the parties concerned or entities and individuals relating to the event under investigation and asking them to make explanations on matters relating to the event under investigation;

3. consulting and copying documents or materials relating to the event under investigation, and sealing up materials likely to be transferred, destroyed, concealed or altered; and

4. checking the relevant information systems. The number of on-site inspectors or investigators shall not be less than two, and they shall produce their lawful credentials and the inspection or investigation notice. Entities and individuals under inspection or investigation shall be cooperative and truthfully provide the  relevant documents or materials, and may not withhold information or refuse or obstruct the inspection or investigation.

Article 34 Where a major information divulgence occurs to a credit investigation institution engaged in individual credit investigation, the Basic Financial Credit     Information Database or an institution providing information to or acquiring information from the Basic Financial Credit Information Database, the supervisory and administrative department of credit investigation under the State Council may temporarily take over the relevant information system or take other necessary measures to prevent the increase of damage.

Article 35 The staff members of the supervisory and administrative department of credit investigation under the State Council and the local offices thereof shall keep confidential state secrets and information subjects’information which they have access to in the course of performing duties.

Chapter VII Legal Liability

Article 36 Where any entity or individual forms a credit investigation institution engaged in individual credit investigation or engages in individual credit investigation without the approval of the supervisory and administrative department of credit investigation under the State Council, the supervisory and administrative department of credit investigation under the State Council shall close it down and impose a fine of not more than 500,000 yuan but not less than 50,000 yuan. If any crime is constituted, the liable party shall assume criminal liability.

Article 37 Where any credit investigation institution engaged in individual credit investigation violates Article 9 of this Regulation, the supervisory and administrative department of credit investigation under the State Council shall order it to correct within a certain time limit, impose a fine of not more than 200,000 yuan but not less than 20,000 yuan upon the institution and, for the directly responsible person in charge and other directly liable persons, give a warning and impose a fine of not more than 10,000 yuan. Where any credit investigation institution engaged in enterprise credit investigation fails to handle filing formalities under Article 10 of this Regulation, the local office of the supervisory and administrative department of credit investigation under the State Council shall order it to correct within a certain time limit and, if it fails to correct within the prescribed time, punish it according to the preceding paragraph.

Article 38 Where any credit investigation institution or the institution operating the Basic Financial Credit Information Database, in violation of this Regulation, has any of the following conduct, the supervisory and administrative department of credit investigation under the State Council or the local office thereof shall order it to correct within a certain time limit, impose a fine of not more than 500,000 yuan but not less than 50,000 yuan upon the institution and a fine of not more than 100,000 yuan but not less than 10,000 yuan upon the directly responsible person in charge and other directly liable persons, and confiscate the illegal gains if any. If any losses are caused to information subjects, the liable party shall assume civil liability; if any crime is constituted, the liable party shall assume criminal liability:

1. stealing information or otherwise illegally acquiring information;

2. collecting individual information whose collection is prohibited or without the consent of information subjects;

3. illegally providing or selling information;

4. divulging information due to negligence;

5. failing to delete bad information of individuals upon the expiration of the prescribed retention period;

6. failing to check and handle information at which demurs have been raised as required;

7. refusing or impeding the inspection or investigation activities of the supervisory and administrative department of credit investigation under the State Council or the local office thereof, or failing to truthfully provide the relevant documents or materials; or

8. any other conduct that violates the credit investigation rules or infringes upon the legal rights and interests of information subjects. Where any credit investigation institution engaged in individual credit investigation has any of the above-mentioned conduct, and if the circumstances or consequences are serious, the supervisory and administrative department of credit investigation under the State Council shall revoke its individual credit investigation business operation permit.

Article 39 Where any credit investigation institution, in violation of this Regulation, fails to report its credit investigation business operations of the last year as required, the supervisory and administrative department of credit investigation under the State Council or the local office thereof shall order it to correct within a certain time limit; if the institution fails to correct within the prescribed time, it shall impose a fine of not more than 100,000 yuan but not less than 20,000 yuan upon the institution and, for the directly responsible person in charge and other directly liable persons, give a warning and impose a fine of not more than 10,000 yuan.

Article 40 Where any institution providing information to or acquiring information from the Basic Financial Credit Information Database, in violation of this Regulation, has any of the following conduct, the supervisory and administrative department of credit investigation under the State Council or the local office thereof shall order it to correct within a certain time limit, impose a fine of not more than 500,000 yuan but not less than 50,000 yuan upon the institution and a fine of not more than 100,000 yuan but not less than 10,000 yuan upon the directly responsible person in charge and other directly liable persons, and confiscate the illegal gains if any. If any losses are caused to information subjects, the liable party shall assume civil liability; if any crime is constituted, the liable party shall  assume criminal liability:

1. illegally providing or selling information;

2. divulging information due to negligence;

3. inquiring about personal information or the credit information of enterprises without consent;

4. failing to handle demurs as required or correct information with errors or omissions; or

5. refusing or impeding the inspection or investigation activities of the supervisory and administrative department of credit investigation under the State Council or the local office thereof, or failing to truthfully provide the relevant documents or materials;

Article 41 Where any information provider, in violation of this Regulation, provides any credit investigation institution or the Basic Financial Credit Information Database with any individual’s bad information which is not information that should be disclosed according to law without notifying the individual beforehand, and if the circumstances or consequences are serious, the supervisory and administrative department of credit investigation under the State Council or the local office thereof shall impose a fine of not more than 200,000 yuan but not less than 20,000 yuan if the provider is an entity or a fine of not more than 50,000 yuan but not less than 10,000 yuan if the provider is an individual.

Article 42 Where any information user, in violation of this Regulation, uses personal information for purposes not agreed upon with the information subject or provides individual information to any third party without the consent of the information subject, and if the circumstances or consequences are serious, the supervisory and administrative department of credit investigation under the State Council or the local office thereof shall impose a fine of not more than 200,000 yuan but not less than 20,000 yuan if the user is an entity or a fine of not more than 50,000 yuan but not less than 10,000 yuan if the user is an individual; and confiscate the illegal gains if any. If any losses are caused to information subjects, the user shall assume civil liability; if any crime is constituted, the user shall assume criminal liability.

Article 43 Where any staff member of the supervisory and administrative department of credit investigation under the State Council or its local offices abuses powers, neglects duties, engages in malpractice for personal gains, fails to perform supervisory and administrative duties, or divulges state secrets or information of information subjects, sanctions shall be imposed by law. If any losses are caused to information subjects, he/she shall assume civil liability; if any crime is constituted, he/she shall assume criminal liability.

Chapter VIII Supplementary Provisions

Article 44 The meaning of terms mentioned in this Regulation is as follows:

1. Information providers refer to entities and individuals providing information to credit investigation institutions and entities providing information to the Basic Financial Credit Information Database.

2. Information users refer to entities and individuals acquiring information from credit investigation institutions and the Basic Financial Credit Information Database.

3. Bad information refers to information which exerts adverse impact on the credit standing of information subjects, such as: information about information subjects’failure to perform contracts in loaning, credit purchasing, guarantee, lease, insurance and credit card use activities; information about administrative punishments on information subjects; information about the judgments or rulings of people’s courts deciding that information subjects shall perform obligations or be subject to enforcement measures; and other bad information as specified by the supervisory and administrative department of credit investigation under the State Council.

Article 45 The conditions for the formation of foreign-funded credit investigation institutions shall be made by the supervisory and administrative department of credit investigation under the State Council together with other relevant departments under the State Council, and be subject to the approval of the State Council. Overseas credit investigation institutions shall obtain the approval of the supervisory and administrative department of credit investigation under the State Council before engaging in credit investigation inside China.

Article 46 Institutions which have already been engaged in individual credit investigation before the implementation of this Regulation shall apply for individual credit investigation business operation permits according to this Regulation within six months as of the date of implementation of this Regulation. Institutions which have already been engaged in enterprise credit investigation before the implementation of this Regulation shall handle filing formalities according to this Regulation within three months as of the date of implementation of this Regulation.

Article 47 This Regulation shall come into force on March 15, 2013.

Regulatory Legislation | “Regulations on Promoting and Standardizing Cross-Border Data Flows”

State Internet Information Office Order

No. 16

The “Regulations on Promoting and Standardizing Cross-Border Data Flows” have been reviewed and approved at the 26th office meeting of the State Internet Information Office on November 28, 2023. They are hereby announced and shall be implemented from the date of announcement.

Director of the State Internet Information Office

Zhuang Rongwen

March 22, 2024

Provisions on Promoting and Standardizing Cross-Border Data Flows

Article 1: In order to safeguard data security, protect the rights and interests of personal information, and promote the lawful and orderly free flow of data, these provisions are formulated in accordance with the laws and regulations of the People’s Republic of China, including the Cybersecurity Law of the People’s Republic of China, the Data Security Law of the People’s Republic of China, and the Personal Information Protection Law of the People’s Republic of China, concerning the implementation of the data export system, such as data export security assessments, standard contracts for the export of personal information, and personal information protection certification.

Article 2: Data processors shall identify and declare important data in accordance with relevant regulations. If data has not been identified or publicly announced as important data by relevant departments or regions, data processors are not required to undergo a data export security assessment for data that is not declared as important data.

Article 3: Data collected and generated in activities such as international trade, cross-border transportation, academic cooperation, cross-border production and manufacturing, and marketing, provided to overseas without involving personal information or important data, shall be exempted from the requirement to undergo a data export security assessment, enter into standard contracts for the export of personal information, or obtain personal information protection certification.

Article 4: When personal information collected and generated by data processors overseas is transferred to China for processing and subsequently provided to overseas without introducing personal information or important data during the processing, they shall be exempted from the requirement to undergo a data export security assessment, enter into standard contracts for the export of personal information, or obtain personal information protection certification.

Article 5: Data processors providing personal information overseas shall be exempted from the requirement to undergo a data export security assessment, enter into standard contracts for the export of personal information, or obtain personal information protection certification if they meet one of the following conditions:

(1) It is necessary to provide personal information overseas for the conclusion or performance of contracts in which individuals are parties, such as cross-border shopping, cross-border mailing, cross-border remittance, cross-border payment, cross-border account opening, airline and hotel reservations, visa application, examination services, etc.;

(2) It is necessary to provide employee personal information overseas for the implementation of cross-border human resources management in accordance with legally formulated labor regulations and collective contracts signed in accordance with the law;

(3) It is necessary to provide personal information overseas to protect the life, health, and property safety of natural persons in emergency situations;

(4) Data processors other than operators of critical information infrastructure have provided less than 100,000 pieces of personal information (excluding sensitive personal information) overseas cumulatively since January 1 of the current year.

The personal information provided overseas as referred to in the preceding paragraph does not include important data.

Article 6: Free Trade Pilot Zones may independently formulate a negative list of data that needs to be included in the scope of data export security assessments, standard contracts for the export of personal information, and personal information protection certification management within the framework of the national data classification and grading protection system. After approval by the provincial-level cybersecurity and informatization committee, it shall be filed with the competent authority of the State Cyberspace Administration and the competent authority of the National Data Management Department.

Data processors providing data overseas within the Free Trade Pilot Zones that is not included in the negative list may be exempted from the requirement to undergo a data export security assessment, enter into standard contracts for the export of personal information, or obtain personal information protection certification.

Article 7: Data processors providing data overseas shall apply for a data export security assessment through the provincial-level cyberspace administration department to the competent authority of the State Cyberspace Administration if they meet one of the following conditions:

(1) Operators of critical information infrastructure provide personal information or important data overseas;

(2) Data processors other than operators of critical information infrastructure provide important data overseas or have provided personal information (excluding sensitive personal information) to overseas exceeding one million people, or sensitive personal information exceeding ten thousand people cumulatively since January 1 of the current year.

The provisions of Articles 3, 4, 5, and 6 of these regulations shall apply to the above situations.

Article 8: Data processors other than operators of critical information infrastructure that have provided personal information (excluding sensitive personal information) to overseas exceeding one hundred thousand people but less than one million people, or sensitive personal information to less than ten thousand people cumulatively since January 1 of the current year, shall conclude standard contracts for the export of personal information with the overseas recipient or obtain personal information protection certification in accordance with the law.

The provisions of Articles 3, 4, 5, and 6 of these regulations shall apply to the above situations.

Article 9: The validity period of the results of the data export security assessment shall be three years from the date of issuance of the assessment results. When the validity period expires and it is necessary to continue data export activities without the occurrence of circumstances requiring a reapplication for a data export security assessment, data processors may apply to extend the validity period of the assessment results to the competent authority of the State Cyberspace Administration through the provincial-level cyberspace administration department 60 working days before the expiration of the validity period. With the approval of the competent authority of the State Cyberspace Administration, the validity period of the assessment results may be extended for three years.

Article 10: Data processors providing personal information overseas shall fulfill obligations such as notification, obtaining individual consent, and conducting personal information protection impact assessments in accordance with laws and regulations.

Article 11: Data processors providing data overseas shall comply with laws and regulations, fulfill obligations of data security protection, adopt technical measures and other necessary measures to ensure data export security. In the event of or potential for a data security incident, remedial measures shall be taken, and timely reports shall be made to the provincial-level and above cyberspace administration departments and other relevant competent authorities.

Article 12: Local cyberspace administration departments shall strengthen guidance and supervision over data processors’ data export activities, improve the data export security assessment system, and optimize the assessment process. They shall strengthen end-to-end and all-domain supervision before, during, and after data export activities. In case of significant risks in data export activities or occurrence of data security incidents, data processors shall be required to rectify and eliminate hidden dangers. Those who refuse to correct or cause serious consequences shall be held accountable according to law.

Article 13: If there is any inconsistency between these regulations and the “Measures for the Security Assessment of Data Export” (Order No. 11 of the State Cyberspace Administration, announced on July 7, 2022), and the “Methods for Standard Contracts for the Export of Personal Information” (Order No. 13 of the State Cyberspace Administration, announced on February 22, 2023), and other relevant regulations promulgated on July 7, 2022, and February 22, 2023, these regulations shall prevail.

Article 14: These regulations shall come into force on the date of promulgation.