Public Security Organs Rules on the Collection of Electronic Data Evidence (Draft for Comment)

The Ministry of Public Security has released a comprehensive set of draft regulations titled the "Public Security Organs Rules on the Collection of Electronic Data Evidence," aimed at standardizing the methods by which law enforcement agencies gather, store, and analyze digital evidence. These rules, intended to replace the previous 2018 iteration, reflect the growing complexity of criminal and administrative cases in an era dominated by cloud computing, encrypted communications, and decentralized data storage. By establishing rigorous technical and procedural standards, the draft seeks to ensure the "legality, authenticity, integrity, and relevance" of electronic data used in judicial proceedings.

Modernizing Digital Jurisprudence: The Scope of the New Rules

The draft regulations provide a detailed framework for public security organs handling both criminal and administrative cases. According to Article 2, the scope of the rules covers the entire lifecycle of electronic data evidence, including scene investigation, seizure, sealing of original storage media, data freezing, extraction, and professional appraisal. This holistic approach is designed to minimize the risk of data tampering and to protect the legal rights of citizens and organizations.

The definition of "electronic data" under Article 57 has been significantly expanded to keep pace with technological advancements. It now explicitly includes information from web pages, social media platforms (such as WeChat Moments and microblogs), login logs, system logs, source code, and even content generated by artificial intelligence. This broad categorization ensures that law enforcement has a clear legal basis for pursuing evidence across the modern digital landscape.

Procedural Rigor and Integrity Checks

A central theme of the 2026 draft is the preservation of data integrity. Article 3 mandates that all collection activities must adhere to established technical standards to ensure that the data remains unchanged from the moment of discovery. One of the primary mechanisms for this is the "integrity check value," commonly known in technical circles as a cryptographic hash (such as MD5 or SHA-256).

The rules stipulate that whenever electronic data is extracted or frozen, law enforcement must calculate these integrity values. If the data is later transferred or analyzed, the integrity values must be re-verified. Any discrepancy between the original and subsequent values must be documented, as it could potentially invalidate the evidence in court. This focus on "mathematical certainty" is intended to bridge the gap between traditional forensic methods and the volatile nature of digital information.

Chronology of Electronic Data Regulation in China

The evolution of digital evidence rules in China reflects the rapid digitalization of the national economy and social life:

  • 2016: The Supreme People’s Court, the Supreme People’s Procuratorate, and the Ministry of Public Security jointly issued initial provisions on electronic data in criminal cases.
  • 2018: The Ministry of Public Security released the "Rules for Public Security Organs on the Collection of Electronic Data Evidence" (Document No. 41), which provided the first dedicated internal guidelines for police.
  • 2020–2024: Incremental updates were made to address specific technologies, including blockchain-based evidence and remote cloud storage.
  • July 2026: The current "Draft for Comment" is released, consolidating previous updates and introducing stricter requirements for synchronized audio and video recording during evidence collection.
  • Late 2026: Expected official implementation following the public consultation period.

The Seizure and Sealing of Physical Media

While much of modern evidence is stored in the cloud, physical devices remain a critical starting point for many investigations. Articles 14 through 19 detail the procedures for seizing original storage media, such as smartphones, hard drives, and servers.

Under Article 15, seizures generally require approval from the head of a county-level public security organ. However, in "urgent circumstances"—where data might be remotely wiped or physically destroyed—officers are permitted to seize media immediately, provided they report the action and complete the necessary paperwork within 24 hours. To prevent remote tampering, Article 18 requires that seized devices with wireless communication capabilities, such as mobile phones, be placed in signal-shielding bags or have their network connections physically severed.

Extraction and Remote Investigation

Recognizing that it is not always feasible to seize physical hardware—particularly in cases involving critical infrastructure or large-scale data centers—the rules allow for "on-scene extraction" and "online extraction."

Article 25 permits on-scene extraction if seizing the hardware would cause significant public disruption, such as shutting down a major information system. In such instances, officers must use "write-protection" devices (Article 42) to ensure that the act of accessing the data does not inadvertently modify it.

Furthermore, Article 30 addresses the challenge of cross-border data. It authorizes the online collection of publicly available information and data stored on remote systems within mainland China. For data stored on overseas servers, law enforcement may extract data through accounts and passwords provided by suspects or through international cooperation mechanisms.

Protecting Privacy and Confidentiality

In response to increasing public concern regarding data privacy, the draft includes specific protections for sensitive information. Article 7 requires public security organs and their hired experts to maintain the confidentiality of state secrets, commercial secrets, and personal privacy encountered during investigations.

Moreover, Article 8 establishes a hierarchy for obtaining passwords and access keys. Police should first attempt to obtain these from the data holder. If the holder refuses, and the case is of significant importance, the police may, with high-level approval, employ technical measures to bypass security—but only after documenting the refusal and ensuring that the process is recorded.

Supporting Data: The Rising Tide of Digital Evidence

The necessity for these updated rules is underscored by recent judicial statistics. According to data from various provincial courts, electronic data is now a factor in over 85% of criminal cases, ranging from telecommunications fraud to traditional crimes like theft and assault where GPS logs or chat records provide critical timelines.

Category of Evidence Estimated Growth (2020–2025) Percentage of Total Cases (2025)
Chat Records (WeChat/QQ) +120% 72%
Financial Transaction Logs +95% 64%
Cloud Storage Data +210% 38%
IoT Device Logs +450% 12%

This data suggests that the "digital footprint" has replaced the fingerprint as the most common form of forensic evidence, necessitating the more sophisticated legal framework provided by the new draft rules.

Official Responses and Expert Analysis

Initial reactions from the legal and technological sectors have been largely focused on the balance between investigative efficiency and procedural justice. An official from the Ministry of Public Security’s Cybersecurity Bureau stated, "The goal of this draft is to provide our officers with a clear, standardized handbook that stands up to the scrutiny of the courts. In the digital age, a procedural error can lead to the loss of a key piece of evidence; we want to eliminate those errors."

Legal scholars have noted that the requirement for synchronized audio and video recording during evidence collection (Article 13) is a significant step forward. "By recording the extraction process in real-time, the police are providing a ‘visual chain of custody,’" said a professor of criminal law at a leading Beijing university. "This protects the suspect from fabricated evidence and protects the police from unfounded accusations of misconduct."

However, some tech industry analysts have raised questions regarding Article 39, which discusses the collection of personal communications like emails and SMS. They emphasize that the "minimum necessity" principle mentioned in Article 20 must be strictly enforced to prevent overreach into the private lives of non-suspects.

Broader Impact and Implications

The implementation of these rules will have far-reaching implications for several stakeholders:

  1. Law Enforcement: Police departments will require significant investment in training and equipment, particularly in write-protection hardware and signal-shielding technology, to comply with the new standards.
  2. The Judiciary: Judges and prosecutors will have a more standardized "checklist" to evaluate the admissibility of digital evidence, likely leading to more consistent rulings across different jurisdictions.
  3. Technology Companies: Internet service providers and data centers will see a more formalized process for "Case-handling Cooperation Letters" (Article 38), which may streamline their legal departments’ responses to police requests.
  4. Legal Defense: Defense attorneys will have more specific grounds on which to challenge evidence if the strict "integrity check" and "synchronized recording" requirements are not met.

As the draft moves through the public comment phase, it represents a pivotal moment in China’s efforts to codify the intersection of technology and the law. By formalizing the "digital chain of custody," the Ministry of Public Security aims to ensure that the transition to a data-driven judicial system is both effective and transparent.

Related Posts

Guiding Opinions on the Application of the Leniency System for Pleas and Punishments 2026

China’s highest judicial and law enforcement authorities have issued a comprehensive update to the nation’s criminal justice framework, signaling a significant shift toward procedural efficiency and the standardization of sentencing.…

Procuratorial Public Interest Litigation Law of the People’s Republic of China Second Review Draft

The National People’s Congress of the People’s Republic of China has released the second review draft of the Law on Procuratorial Public Interest Litigation, marking a significant milestone in the…

You Missed

Alibaba Considers Revenue Sharing Model for Large Commercial Users of Its Open-Weight Qwen AI Models

Alibaba Considers Revenue Sharing Model for Large Commercial Users of Its Open-Weight Qwen AI Models

Would-be Suicide Bomber Sets Off Explosion in NYC Subway Passage

Would-be Suicide Bomber Sets Off Explosion in NYC Subway Passage

Strengthening Taiwans Pharmaceutical Resilience and Global Competitiveness Through Strategic Policy Reform and International Collaboration

  • By Asro
  • August 10, 2026
  • 1 views
Strengthening Taiwans Pharmaceutical Resilience and Global Competitiveness Through Strategic Policy Reform and International Collaboration

The Final Investigation Report into the Tai Po Blaze Concludes a Cigarette Butt Ignited Combustible Materials, Causing a Catastrophic Fire

The Final Investigation Report into the Tai Po Blaze Concludes a Cigarette Butt Ignited Combustible Materials, Causing a Catastrophic Fire

China Expresses "Serious Concern" Over Latest US Trade Restrictions, Signaling Renewed Tensions Ahead of Crucial Summit.

  • By Muslim
  • August 10, 2026
  • 2 views
China Expresses "Serious Concern" Over Latest US Trade Restrictions, Signaling Renewed Tensions Ahead of Crucial Summit.

Social Media Platforms Restrict Dangerous Stunt Content After Tragic Deaths, Sparking Global Debate on Online Safety and Content Moderation

Social Media Platforms Restrict Dangerous Stunt Content After Tragic Deaths, Sparking Global Debate on Online Safety and Content Moderation