In an era of stringent regulation, Web3 projects must not merely pursue technological "coolness" but must also prioritize operational stability.

Introduction

On October 28, 2025, the 18th Session of the Standing Committee of the 14th National People's Congress voted to adopt the Decision on Amending the Cybersecurity Law of the People's Republic of China. The amended law will officially come into effect onJanuary 1, 2026came into formal effect.

This amendment represents not merelyhigher penaltiesbut rathera fundamental shift in regulatory philosophy.

 

Regulatory Landscape Observation: Key Developments in the Web3 Sector

The current logic of cybersecurity regulation is undergoing critical changes.For Web3 projects, the following areas are particularly noteworthy:

1. Significantly Strengthened Penalties:Under the new regulations, if an enterprise fails to fulfill its cybersecurity obligations and causes particularly serious consequences, the maximum fine has been substantially increased from the previous approximatelyRMB 500,000 to RMB 10 million.Furthermore, the new regulationshave abolished the prior flexible approach of “issuing a warning first for a first-time violation,”and regulatory authorities are now empowered to directly impose fines.

2. Artificial Intelligence Explicitly Brought Within the Regulatory Scope:For the first time in foundational legislation, the new regulationsestablish the principle of placing equal emphasis on “encouraging development” and “ensuring security” with respect to AI.This means thatthe responsibilities and obligations relating to algorithm security, model security, and computing power platformshave been formally incorporated into the regulatory framework.

3. Extension of Accountability to Individuals:The maximum fine for directly responsible personnel has beenincreased to RMB 1 million.This adjustment sends a clear signal: while imposing penalties on entities, law enforcement authorities will concurrently pursue individual liability, thereby identifying specific persons who may be subject to subsequent criminal accountability.

In legal practice, administrative penalties often serve as the evidentiary foundation for criminal charges. When administrative fines reach the tens of millions of renminbi, it typically indicates that the consequences have reached the threshold of “serious circumstances” or “particularly serious circumstances” under the Criminal Law of the People’s Republic of China.

 

Caution is warranted: how administrative violations may escalate into criminal offenses

Due to theirdecentralizedandcross-bordercharacteristics, Web3 projects are frequentlysubject to piercing review in judicial practice.Once “technical vulnerabilities” are compounded by “compliance deficiencies,” project operators must be alert to the following two criminal risks:

1. The crime of refusing to fulfill obligations for information network security management (Article 286-1 of the Criminal Law)

The core of this offense lies in the project operator’s capacity to comply with regulatory requirements while engaging in passive nonfeasance.

In Web3 scenarios, project operators often assert“technological neutrality”or“the inability to modify code.”However, judicial authorities conduct a substantive, look-through review:so long as the project operator effectively controls the front-end interface, operational permissions, governance voting rights, or core nodes, it will be deemed in law to possess managerial capacity.

If regulatory authorities have issued clear rectification orders concerning money laundering or illegal information on the platform, and the project operator delays or refuses to rectify on the ground of technical reasons, such conduct may constitute this offense. Substantial administrative fines imposed under new regulations may also directly serve as evidence in criminal conviction.

2. The crime of infringing citizens’ personal information (Article 253-1 of the Criminal Law)

In the context of Web3 projectsKYC verification, real-name node managementandcross-border data transferIn the course of these activities, the processing of personal information is facing stringent penetrative scrutiny.

Under the Personal Information Protection Law (PIPL) and related judicial interpretations aligned with the new regulations, the collection of sensitive personal information (such as facial recognition data and real-name information) must obtain "separate consent." Common Web3 practices of default opt-in or blanket authorization may be deemed "illegal acquisition" in criminal assessments.

The Beijing No. 4 Intermediate People's Court has clarified in typical cases that:"Complexity of technical architecture" and "human and technical costs" do not constitute statutory defenses for failing to fulfill personal information protection obligations.Particularly in relation to the cross-border transmission of KYC data, failure to perform the statutory security assessment procedures or file standard contracts may readily be deemed "illegally providing citizens' personal information to others."

For Web3 entrepreneurs,lagging compliance awareness is not only the starting point of financial risks but also a trigger for crossing criminal red lines.

 

Practical Discussion: How to Define Liability and Mitigate Personal Risks

The new regulations have significantly raised the upper limit of fines imposed on individuals, with the core purposePiercing the corporate veil to hold directly accountable the individuals who actually make the decisions.

For heads or actual controllers of Web3 projects, mitigating criminal risk cannot rely solely on technical isolation; the key lies in demonstrating that you have fulfilled your compliance obligations in management.

1. How to distinguish between “corporate crime” and “individual liability”?

The key determination is whether the unlawful conduct resulted from collective corporate decision-making, and whether the person in charge, within the scope of their duties, made diligent efforts to comply with rules and prevent risks.

In criminal determinations, whether you possess “management capacity” is not assessed solely by whether you control the code. Judicial authorities will comprehensively examine: where project revenues flow, how many users your project affects, and who substantively directs the development of the project ecosystem. Even if the technical architecture is decentralized, if the principal exerts decisive influence over business operations, the corresponding legal liabilities cannot be evaded.

2. How to effectively isolate personal risk?

The key is to demonstrate that the unlawful conduct was not intended by the company’s systems, but rather violated the company’s existing compliance framework. If an enterprise can achieve the following, the relevant persons in charge will find it easier to prove that they“lacked criminal intent”:

  • Conduct regular compliance audits (refer to the first batch of certified audit firms in this field).
  • Upon receiving regulatory rectification notices, retain complete records of implementation, written responses, and evidence of technical improvements.

In this way, effective risk isolation can be established at both the institutional level and the level of individual subjective intent.

 

Compliance Guidance: How Web3 Projects Should Respond to Heightened Cybersecurity Regulatory Pressure

Below, we explain these four compliance guidelines in plain language to help readers easily understand the underlying logic.

1. Do not rely solely on internal assessments; engage qualified external experts for independent reviews

Do not simply accept your technical team’s assertion that “everything is fine.” Instead, regularly engage state-accredited professional cybersecurity firms to conduct comprehensive audits of your smart contracts and data protection measures.

This professional audit report serves as your most important“safeguard.”In the event of future incidents, it can demonstrate to regulators and courts that you have made diligent efforts to implement security measures and did not act with neglect.

2. Eliminate the practice of “one-time blanket consent”

When an app requests sensitive personal information such as identity card details or facial recognition data, it must not provide only a single “agree with one click” button.You must clearly list each category of data to be collected and the specific purposes for its use, requiring users to provide item-by-item consent.

This approach both respects user rights and effectively closes the most common and easily prosecutable loophole of “illegal collection of personal information.” All consent records must be securely stored and remain immutable.

3. Respond promptly to regulatory requirements; do not ignore them

Designate a specific person within the companyA designated person responsible for liaising with regulators.Upon receipt of a rectification notice, you must not delay or resist. If technical constraints prevent immediate compliance, promptly submit a report explaining the difficulties and proposing an interim solution that can be implemented immediately.

Thisproactive communication stanceis critical. In determining whether there has been a “refusal to perform” under the law, the key factor is your subjective intent. A proactive response can effectively help avoid the most severe criminal liability.

4. Keep the data “vault” in China and file reports for cross-border transfers

As long as your project hasusers in China,their core personal information must be stored on servers located in China. If business needs genuinely require transferring data abroad, you must complete security assessments or filing procedures with the cyberspace administration authorities in advance.

Clear rules on data storage and flowscan ensure that your business architecture remains compliant, avoiding suspension of the entire business due to cross-border data transfer issues.

 

Conclusion

In an era of stringent regulation, Web3 projects must not merely pursue technological "coolness" but, more importantly, operational stability. Demonstrate your efforts through professional audits, safeguard users and your own interests through standardized processes, earn regulatory understanding through proactive communication, and uphold legal boundaries with a clear corporate structure. This is the path to long-term survival.

For the Web3 industry, the implementation of new regulations in 2026 heralds a profound transformation in the regulatory paradigm. The era of relying on "technical isolation" to circumvent legal obligations is coming to an end.

Compliance is no longer a marginal cost for enterprises, but the foundation for survival in a high-pressure regulatory environment. Practitioners must recognize that technical rationality cannot supersede legal order. Only by proactively establishing a compliance framework and building a penetrative legal defense system can sustainable evolution of technological innovation be ensured within the rule of law.