The Ministry of Public Security of the People’s Republic of China has released a comprehensive new draft of regulations titled the Rules for Public Security Organs’ Electronic Data Evidence Collection. This legislative update, intended to modernize the procedural framework for digital forensics, is set to replace the existing 2018 guidelines. The draft provides a rigorous set of standards for how law enforcement agencies at all levels must identify, collect, preserve, and analyze digital evidence in both criminal and administrative cases. As China continues its transition toward a "Digital China," where social and economic activities are increasingly mediated by information technology, these rules represent a pivotal shift in the legal landscape, balancing the efficiency of criminal investigations with the protection of civil liberties and data privacy.
Strengthening the Legal Framework for Digital Evidence
The newly drafted rules are grounded in a suite of high-level national laws, including the Criminal Procedure Law, the Administrative Punishment Law, and the Public Security Administration Punishment Law. By aligning with these statutes, the Ministry of Public Security (MPS) aims to standardize the quality of electronic data evidence, which has become a cornerstone of modern litigation. Article 1 of the draft explicitly states that the primary objectives are to regulate the evidence-gathering activities of public security organs, ensure the quality of electronic data, protect the lawful rights and interests of citizens and organizations, and improve the efficiency of law enforcement.
Under the new regulations, "electronic data" is broadly defined to include any digital information that can prove the facts of a case. This encompasses information from web pages, social media platforms (such as WeChat moments and microblogs), user registration details, system logs, source code, and personal communications like SMS and encrypted instant messages. Notably, the draft includes modern formats such as short videos and live-streamed content, reflecting the rapid evolution of China’s internet ecosystem.
Procedural Rigor and the Role of Personnel
A significant portion of the draft is dedicated to ensuring that digital evidence is collected in a manner that maintains its integrity and admissibility in court. Article 5 mandates that all electronic data collection must be conducted by at least two police officers. In situations requiring high technical expertise, professional technical personnel may be appointed or invited to assist, but they must operate under the direct supervision of the lead officers.
The rules place a heavy emphasis on the "integrity check value" (often referred to as a digital fingerprint or hash value). Article 3 requires public security organs to collect evidence comprehensively and objectively, ensuring its legality, authenticity, and relevance. To prevent tampering, the regulations require the use of write-protection equipment during forensics and the creation of identical backups for analysis, leaving the original storage media untouched whenever possible.
Chronology of Digital Evidence Regulation in China
The release of this draft is the latest step in a decades-long evolution of Chinese digital evidence law:
- 2005: The National People’s Congress Standing Committee issued a decision on the management of forensic identification, beginning the formalization of digital forensics.
- 2012: The Criminal Procedure Law was amended to officially include "electronic data" as a distinct category of evidence.
- 2016: The Supreme People’s Court, the Supreme People’s Procuratorate, and the MPS issued joint rules on the collection and preservation of electronic data in criminal cases.
- 2018: The Ministry of Public Security issued the "Rules for Public Security Organs’ Electronic Data Evidence Collection," which served as the primary operational manual for six years.
- 2024–2025: The current draft was developed to address gaps in the 2018 rules, particularly concerning cloud computing, encrypted communications, and AI-generated content.
- 2026: The new rules are slated for full implementation, officially superseding the 2018 version.
Detailed Provisions for Seizure and Freezing
The draft outlines specific protocols for the seizure of original storage media, such as smartphones, hard drives, and servers. Article 14 dictates that if police find digital data that can prove guilt or innocence, they must seize the original media and create a detailed record of its state. If the owner or a witness is present, they must sign the seizure record. In cases where a witness cannot be found, the entire process must be recorded on video to ensure transparency (Article 13).
In instances where data is too large to be moved or resides on a remote server, the rules allow for "freezing" the data. According to Article 20, freezing is a "minimum necessity" measure. It involves locking a network account or calculating the integrity check value of a dataset to ensure it cannot be modified while the investigation proceeds. The period for freezing data in criminal cases is generally capped at six months, though extensions can be granted under special circumstances.
On-Scene Extraction and Remote Inspections
One of the most complex areas addressed in the draft is the on-scene extraction of data (Article 25). Law enforcement is permitted to extract data directly at the scene if it is inconvenient to seize the physical hardware or if the case is urgent and data might be destroyed. To protect the target system, officers are forbidden from installing new applications unless absolutely necessary and approved by a department head.
Furthermore, Article 30 introduces protocols for "online extraction." This allows police to collect data that is publicly available or stored on remote systems within Chinese territory. For systems located overseas, police may extract data if the suspect provides the necessary credentials (usernames and passwords), provided the process is meticulously documented and verified.
Supporting Data and the Rise of Cybercrime
The necessity for these updated rules is underscored by the rising volume of digital evidence in Chinese courts. According to data from the Supreme People’s Procuratorate, cyber-related crimes in China have seen an average annual increase of over 20% since 2019. In 2023 alone, Chinese authorities handled more than 600,000 cases involving telecommunications fraud, nearly all of which relied heavily on electronic data evidence.
Moreover, the complexity of evidence has increased. While 2018-era cases mostly involved simple SMS logs, modern cases frequently involve blockchain transactions, cloud-based collaborative documents, and "Deepfake" media. The draft’s inclusion of Article 50, which mentions the identification of "information generated by artificial intelligence," is a direct response to this trend.
Official Responses and Stakeholder Perspectives
While the MPS has not released a formal statement on the internal deliberations, the draft itself reflects a response to past judicial challenges where digital evidence was excluded due to procedural errors. Legal experts in China have noted that the emphasis on "video recording the entire process" for major cases (Article 13) is a significant step toward preventing law enforcement overreach.
Privacy advocates and legal scholars are expected to pay close attention to Article 8, which discusses the acquisition of passwords. The draft stipulates that if a suspect refuses to provide a password, police may use technical measures to bypass the lock, provided they have approval from a county-level public security official or higher. This "emergency" provision allows for retroactive approval within 24 hours if there is a risk of data loss, a point that is likely to be a focal point of public comments.
Analysis of Implications and Impact
The implementation of these rules in 2026 will have far-reaching implications for several sectors:
1. Law Enforcement: Police departments will require significant investment in forensic hardware and training. The requirement for two officers and potential video recording for all major cases increases the administrative burden but significantly lowers the risk of evidence being thrown out in court.
2. Technology Companies: Internet Service Providers (ISPs) and data centers will face clearer but more frequent requests for data. Article 37 clarifies the "Case-handling Cooperation Letter" system, streamlining how police request data from private entities while requiring the police to provide formal legal documents.
3. The Legal Profession: Defense attorneys will have a more robust "procedural yardstick" to challenge the prosecution’s evidence. If a hash value is inconsistent or a video record is missing, the defense has a clear path to argue for the exclusion of that evidence.
4. Civil Liberties: The draft attempts to address privacy by requiring the "timely return or destruction" of materials unrelated to the case (Article 7). However, the broad definition of "emergency" measures remains a point of debate regarding the potential for abuse.
Conclusion and Future Outlook
The Rules for Public Security Organs’ Electronic Data Evidence Collection (Draft for Comments) represent a comprehensive effort to codify the digital frontlines of Chinese law enforcement. By replacing the 2018 rules, the MPS is acknowledging that the tools of the past are no longer sufficient for the technologies of the future. As the draft moves through the public comment phase, it will likely undergo further refinement to address the delicate balance between state security and individual data protection. Once finalized and implemented in 2026, these rules will serve as the definitive guide for digital justice in the world’s largest internet market, setting a standard that will likely influence digital forensics protocols across the region.








