Special Disclaimer: This article is an original work by Attorney Shao Shiwei. It reflects only the author’s personal views and does not constitute legal advice or a legal opinion on any specific matter. For article reprints, legal consultations, or business exchanges, please add: sswls66

 

In recent years, a notable trend has emerged in the numerous cases of infringing citizens’ personal information handled by Attorney Shao: the entities subject to investigation and prosecution are increasingly not the traditional “black- and gray-market teams” whose primary purpose is the illegal acquisition and trading of information, but rather companies that ostensibly operate in compliance and whose core businesses focus on customer acquisition services and data operations.

 

The initial reactions of many executives at the implicated enterprises were nearly identical:

“Everyone in the industry does this; why are we the ones facing trouble?”

 

It is also common for frontline employees to think along the following lines:

“I only handle technical or business development tasks; how did I get dragged into this?”

 

It is precisely these widespread misconceptions among practitioners that have made industries such as loan facilitation, precision marketing, big data services, real estate brokerage, insurance, healthcare, telecommunications, education and training, recruitment, e-commerce, and express logistics high-risk areas for offenses involving the infringement of citizens’ personal information.

 

For this reason, it is necessary for practitioners in these fields to examine their practices in light of the actual adjudication logic applied in judicial proceedings. Drawing on practical case precedents and a not-guilty case personally handled by Attorney Shao, this article outlines the key determinants distinguishing criminal conduct from non-criminal conduct in such cases, as well as relevant defense strategies, with the aim of providing industry participants with more actionable guidance for identifying risk boundaries and strengthening compliance measures.

 

I. Author: Attorney Shao Shiwei

 

 

 

1

 

These Business Scenarios Are Becoming High-Risk Areas for Offenses Involving the Infringement of Citizens’ Personal Information

 

Based on effective judgments in recent years and the industry distribution of cases handled by the author, the associated risks are concentrated in the aforementioned specific industries. These industries share a common characteristic: their growth is highly dependent on the efficiency of acquiring customer leads. If controls over source verification, authorization chains, or usage boundaries are lax, business expansion may lead to their activities being characterized as “relying on the flow of information as a significant profit model.”

 

The following two publicly available cases are representative.

 

1. The Case of Shujutang Employees Infringing upon Citizens’ Personal Information: “The First Listed Company in the Big Data Industry”

 

Shujutang (Beijing) Technology Co., Ltd. (hereinafter referred to as “Shujutang”), known as “the first big data trading platform in China” and “the first listed company in the big data industry,” is a pioneer in the big data sector. In 2016, its market capitalization once reached RMB 2.1 billion. This case was a major special case involving the infringement of personal information, supervised by the Ministry of Public Security and the Supreme People’s Procuratorate.

 

After collecting, processing, and trading information, the company assigned different tags based on users’ interests and preferences, and then conducted precision marketing to clients according to their needs. According to the indictment filed by the procuratorial organ, “Shujutang delivered more than 600,000 data records containing citizens’ personal information to Jinshi Company. Jinshi Company sent a total of more than 1.68 million records of citizens’ personal information to its clients.” The court of final instance held that all defendants involved constituted the crime of “infringing upon citizens’ personal information” and were sentenced to imprisonment terms ranging from ten months to four years and six months [Case No. (2018) Lu 13 Xing Zhong 549].

 

Notably, six employees of the company who participated in the information processing and circulation stages were all held accountable.

 

2. The “First Case of Criminal Liability for Web Crawlers” – Mojie Technology

 

Hangzhou Mojie Data Technology Co., Ltd. was established in 2016, primarily engaging in financial big data SaaS services. Its main business model involved embedding front-end plugins into online lending platforms. When users applied for loans, they were guided to input their account passwords for websites such as telecommunications operators, social security, and Taobao. After obtaining authorization, the company used crawler programs to log in on behalf of users and collect personal data, which was then provided to online lending platforms for creditworthiness assessment, with a fee of RMB 0.1 to 0.3 per transaction.

 

Although the agreement signed between Mojie Technology and users promised “not to save account passwords and to collect data only under one-time authorization,” the company actually employed technical means to long-term store users’ private information on rented Alibaba Cloud servers. By the time the case came to light, forensic inspection of the servers revealed that more than 21.24 million personal account passwords were illegally stored in plaintext, some of which were used secondary without authorization. The company’s legal representative and technical personnel were sentenced to three years of imprisonment, suspended for four years [Case No. (2020) Zhe 0106 Xing Chu 437].

 

3. Insights from Multiple Precedents: How Do Companies Typically Step into Criminal Risk?

 

Based on adjudicated cases and the cases handled by the author, it is evident that the transition of relevant enterprises from normal operations to encountering criminal risks gradually occurs during the course of business development.

 

Initially, most companies merely introduced external data to improve customer acquisition efficiency;

Subsequently, the business became dependent on batch data;

Later, multiple departments including technology, operations, and sales successively participated in data processing;

At a certain stage, the overall business model is assessed as deriving significant profits primarily from the circulation of information.

 

By the time many enterprises genuinely recognize the issue, the case has often already entered criminal proceedings.

However, whether an individual case meets the threshold for criminal liability must be determined based on the specific nature of the information involved and the evidentiary circumstances, rather than drawing simplistic conclusions solely on the basis of the outward appearance of the business operations or the scale of data.

 

It is precisely for this reason that, in judicial practice, ongoing disputes over the definition and classification of citizens’ personal information often lead to divergent judicial determinations in individual cases, such as findings of criminal versus non-criminal conduct, or distinctions between lesser and more serious offenses.

 

 

 

2

 

How to Determine Whether the Crime of Infringing Citizens’ Personal Information Is Committed? Two Key Defense Angles

 

Depending on the circumstances of each case, whether the crime of infringing citizens’ personal information is committed is by no means determined by mechanically counting and simply aggregating the number of information items bought or sold. To determine which information supports conviction and sentencing, it is necessary to assess whether each individual item qualifies as “citizens’ personal information” within the meaning of the Criminal Law. This point constitutes a key angle for defense in such cases and is elaborated below in two aspects:

 

1. How Should Information Types Be Classified? Different Classification Approaches May Directly Affect Whether Criminal Liability Is Incurred

 

Judicial interpretations provide that the crime of infringing upon citizens' personal information is constituted by the possession of 50 or more items of sensitive information, such as location tracking data; 500 or more items of moderately sensitive information, such as accommodation records; or 5,000 or more items of general information other than the aforementioned categories.

 

Interpretation of the Supreme People’s Court and the Supreme People’s Procuratorate on Several Issues Concerning the Application of Law in the Handling of Criminal Cases Involving Infringement of Citizens’ Personal Information

Article 5 Where any of the following circumstances exists in the illegal acquisition, sale, or provision of citizens’ personal information, it shall be deemed “serious circumstances” as prescribed in Article 253-1 of the Criminal Law:

  (3) Illegally acquiring, selling, or providing location trajectory information, communication content, credit reporting information, or property information;fifty itemsor more;

  (4) Illegally obtaining, selling, or providing citizens' personal information such as accommodation information, communication records, health and physiological information, transaction information, and other information that may affect personal and property safety500 itemsor more;

  (5) Illegally obtaining, selling, or providing citizens' personal information other than those specified in items (3) and (4)5,000 itemsor more;

 

However, in practice, there is significant controversy among different case-handling authorities regarding the precise matching and classification of the aforementioned three types of information on a case-by-case basis, which consequently leads to vastly different judgments in similar cases. 

 

For example, in a case involving the infringement of citizens' personal information handled by Attorney Shao, the perpetrator sold users' identity card information (fewer than 5,000 items). The case-handling authority believed that the identity card information included household registration addresses, which could be regarded as accommodation information. Therefore, the information involved should be classified as relatively sensitive information. Under this classification, according to legal provisions, exceeding 500 items constitutes a crime.

 

However, Attorney Shao argued that the case-handling authority had misinterpreted the judicial interpretation. "Accommodation information" should refer to information that can precisely locate a citizen's current residence, whereas household registration information is merely registered information and cannot be used to confirm a citizen's real-time location. Therefore, the address information on an identity card is not functionally comparable to accommodation information, as there are fundamental differences in their legal nature and risk levels. He thus advocated that the standard for general information, requiring more than 5,000 items, should apply, which was ultimately accepted by the case-handling authority.

 

2. Does information obtained from public channels necessarily not constitute the crime of infringing upon citizens' personal information?

 

If the information involved is publicly available information searchable on the internet, does the perpetrator's conduct constitute a crime? Regarding this point, different case-handling personnel also hold varying interpretations.

 

For example, in the case of Zhu’s infringement of citizens’ personal information handled by the Shanghai No. 1 Intermediate People’s Court [Case No. (2018) Hu 01 Xing Zhong 1184], the citizen’s personal information obtained by the perpetrator originated from files in a QQ group. The defendant used the downloaded publicly available information for order-farming on the “Ele.me” platform, arguing that the information was public and that he had not sold it, and therefore should not constitute the crime of infringing citizens’ personal information. However, the court held that this did not constitute the crime of infringing citizens’ personal information. The Shanghai No. 1 Intermediate People’s Court reasoned that citizens’ personal information is protected by law; citizen’s personal information appearing on the internet, whether passively disclosed or actively disclosed, is equally protected by law. Accordingly, the court found that Zhu had “provided citizens’ personal information,” thereby constituting a criminal offense.

 

However, in the case of Zhou’s infringement of citizens’ personal information handled by the Chongqing Intermediate People’s Court [Case No. (2017) Yu 05 Xing Zhong 1090], Zhou transmitted and received files containing more than 70,000 items of corporate legal person information via QQ online transfers. The appellate court held that publicly available corporate legal person information should not be counted within the scope of “information” for the crime of infringing citizens’ personal information.

 

It can thus be seen that although current laws and judicial interpretations have clearly stipulated the types of conduct and thresholds for initiating investigations for the crime of infringing citizens’ personal information, the relevant provisions remain somewhat framework-oriented. At the level of individual cases, there are often significant differences in how case-handling personnel understand the nature of the information, the methodology for counting quantities, and the characterization of the conduct, which directly affects the ultimate outcome regarding whether conduct constitutes a crime, and if so, the severity of the offense.

 

Therefore, in such cases, conducting a meticulous review focused on the classification of the personal information involved, the calculation of quantities, and whether the evidence is credible and sufficient often becomes a key defensive entry point that influences the case outcome.

 

The following case handled by Attorney Shao centered on the accurate determination of what constitutes citizens’ personal information in the criminal law sense, and ultimately resulted in the withdrawal of the case.

 

 

 

3

 

A loan-assistance company was investigated for involving 400,000 items of information; why was the case ultimately withdrawn?

 

A certain loan-assistance company was accused by public security authorities of attracting victims to provide personal information under the pretext of assisting them in obtaining loans, and was suspected of buying and selling more than 400,000 items of citizens’ personal information. All employees of the company were subjected to investigative proceedings.

 

When I became involved in the case, the overall situation was already quite unfavorable:

  • From the corporate perspective, there was indeed bulk procurement of user information from external channels;

  • From the interview records, technical staff explicitly stated to the public security authorities that “the company makes money by buying and selling data”;

  • From the objective evidence, the appraisal institution had calculated, based on backend statistics from the SaaS system, a volume of up to 400,000 items of information;

  • From the perspective of similar cases, a search of comparable cases in the region showed that the vast majority resulted in actual imprisonment.

 

Based on the existing evidence, there is virtually no dispute that the conduct in this case constitutes a criminal offense. The client has also exhibited a rather pessimistic outlook, believing that there is essentially no room for defense in this case.

 

However, after repeatedly reviewing the case file and studying the evidence, and after working with the client to meticulously map out the company’s actual business workflows, I gradually developed a defense strategy tailored to this case:

While this case appears to be a typical infringement of citizens’ personal information involving a “vast quantity of data,” the true focal point of contention likely lies not in the sheer volume itself, but in whether the existing evidence can establish, within the meaning of criminal law, that the data constitutes “citizens’ personal information” subject to legal evaluation.

In other words, if the foundational determinations regarding the nature of the information and its degree of identifiability are not solid, the mere aggregation of record counts does not automatically lead to a conclusion of criminal liability.

 

Based on this assessment, I began to shift the focus of the defense breakthrough in this case toward the technical aspects of data forms and processing methods.

 

Through in-depth discussions with the client, I learned that the company had consistently invested resources in data encryption and de-identification measures. However, as the company’s management lacked a technical background, they were unable to clearly explain the underlying implementation logic to the investigating authorities.

 

For this very reason, I decided to first thoroughly clarify the technical issues myself, and then engage in targeted communications with the investigating authorities based on that understanding.

It is imperative to clarify the technical issues because the key breakthrough in the defense of this case largely depends on whether the prosecutor can accurately understand the encryption and data desensitization measures adopted by the SaaS system during data transmission and processing. Only after the handling personnel fully comprehend this technical premise will there be a possibility for the prosecutor to accept the lawyer’s opinions, which further propose re-appraisal and deduplication of the data involved in the case, as well as a lawful calculation of the types and quantities of information that meet the criteria for criminal liability.

 

From the perspective of general technical architecture, SaaS systems typically implement protective measures at various stages, including data collection, transmission, storage, and usage. These protections primarily manifest in two types of operations:

 

First, data de-identification. This involves transforming sensitive fields—for example, masking a mobile phone number as “138****1234”—thereby reducing the ability to directly identify specific individuals while preserving the usability of the data structure.

Second, data encryption. This involves using algorithms to convert plaintext into ciphertext, whereby, in principle, only entities possessing the corresponding keys can restore the original information. This is primarily used to ensure the confidentiality of data during transmission and storage.

 

At the level of specific technical implementation, common practices also include field-level encryption upon data ingestion, hash storage, and mask writing, as well as dynamic masking, token mapping, and secondary encryption during data retrieval.

 

After systematically reviewing the aforementioned technical approaches, I engaged in multiple rounds of communication with the prosecutor regarding the relevant issues. Subsequently, based on the legal counsel’s opinions, the procuratorial organ recommended that the public security organ conduct further supplementary investigation into the data involved in the case.

 

Following the supplementary investigation, favorable developments indeed emerged. Because the SaaS system involved in the case employed encryption and de-identification measures in both its data ingestion and output processes, after re-deduplication and forensic appraisal, the number of records deemed to contain both names and mobile phone numbers was determined to be fewer than 5,000.

 

On this basis, I further submitted that the existing evidence was insufficient to prove that the data provided externally had stably reached, in terms of identifiability, the threshold for “citizens’ personal information” as defined under criminal law. Consequently, the evidentiary foundation for establishing the crime of infringing upon citizens’ personal information was inadequate.

 

Ultimately, the procuratorial organ accepted the legal counsel’s opinions and recommended that the public security organ withdraw the case, resulting in no criminal liability for any employees of the company.

 

However, based on an in-depth study of this case, I also observed that not all SaaS systems used by enterprises possess substantive protective capabilities. In practice, many systems merely implement “superficial de-identification” at the front-end display level, while storing data in plaintext in the back end; some systems lack mechanisms for automatic deletion or secondary de-identification, leaving partners with opportunities to access complete information. Under such circumstances, the related business activities may still face significant criminal risks. Therefore, practitioners are hereby specially reminded to exercise caution.

 

 

 

4

 

Conclusion

 

With the proliferation of online customer acquisition and data-driven operational models, an increasing number of enterprises encounter and process large volumes of personal information in their daily operations, which has become commonplace in many industries. Precisely because of this, if related business activities are improperly managed with respect to authorization, data sources, or usage boundaries, they are more likely to come under criminal scrutiny.

 

From a practical perspective, there remains a certain degree of flexibility in the specific determination of the crime of infringing upon citizens’ personal information. Differences among cases in terms of information types, technical processing methods, and evidentiary foundations often directly affect the final conclusions, and simple analogical judgments should not be made.

 

Therefore, on the one hand, enterprises must still ensure robust front-end compliance and systemic protective measures during their operations; on the other hand, once an investigation has commenced or criminal proceedings have been initiated, it is advisable to seek professional assessment tailored to the specific circumstances of the case at an early stage, so as to avoid passive responses at critical junctures.


 

 

Recommended Reading

What Lessons Can the Loan Facilitation Industry Draw from Two Cases of Virtual Currency Transactions Involving the Purchase and Sale of Personal Information Solved by Police?

In-Depth Analysis | Big Data Analysis and Typical Cases of the Crime of Infringing Upon Citizens’ Personal Information

Comprehensive Analysis | A Panoramic Overview of Loan Supermarket and Loan Facilitation Business Models: Development History, Regulatory Evolution, Fee Structures, and Analysis of Prevalent Criminal Risks

Article Summary | What Legal Risks May Loan Facilitation Companies and Loan Intermediaries Face When Engaging in “Debt Restructuring” and “Debt Optimization” Services?