China releases draft law on anti-cyberviolence for public comment
Key contacts
On 29 July 2026, the Cyberspace Administration of China (CAC) released the draft Anti-Cyberviolence Law of the People’s Republic of China (PRC) for public comment, which builds on the Provisions on the Governance of Cyberviolence Information, a departmental regulation in effect since 1 August 2024. If enacted, the Draft would establish a dedicated national statutory framework for anti-cyberviolence governance in line with the 2026 Legislative Work Plan of the Standing Committee of the National People’s Congress. The deadline for submitting comments is 28 August 2026.
The draft Anti-Cyberviolence Law is made up of seven chapters and 60 articles and establishes a comprehensive framework covering platform governance, government oversight, social co-governance, judicial protection and legal liability.
Application scope
The draft Anti-Cyberviolence Law defines cyberviolence broadly as concentrated or sustained online conduct against individuals or organisations that infringes lawful rights and interests, and includes the following conduct:
- the concentrated dissemination of insulting or abusive content, rumours or defamatory statements, content inciting hatred or hostility, threats or discriminatory content;
- the unlawful concentrated disclosure of personal information;
- persistent online intimidation or harassment; and
- other acts of cyberviolence that infringe upon legitimate rights and interests.
It applies to cyberviolence activities within the PRC and carries liability for overseas organisations or individuals targeting persons or organisations within the PRC.
Highlights
Businesses should be alert to the following provisions in the Draft:
- Monitoring and identification obligations: Network service providers must establish comprehensive systems covering user registration, account management, personal information protection, content review, monitoring and early warning, identification and disposal, and complaint and reporting mechanisms. From a technical perspective, providers must build cyberviolence feature databases, case sample libraries, and early warning models.
- Risk warning and mitigation obligations: Once a cyberviolence risk is detected, providers must promptly act to mitigate such risks, including refraining from pushing the relevant information, verifying the real identity information of abnormal accounts, attaching visible risk labels, and notifying the competent authorities when metrics increase significantly. Providers must also comply with applicable requirements for AI-generated or synthetic content and enhance traceability.
- Content handling and user protection obligations: Once cyberviolence content is detected, providers must immediately stop its transmission and take appropriate measures including deletion, blocking, disabling links, restricting account functionality and monetisation privileges, and closing accounts. Providers must preserve relevant data and notify authorities, establish user protection functions (e.g. block unknown or specified users and disable reposts or comments), and inform users of all cyberviolence risks and the available protective measures.
- Dedicated protection of vulnerable groups: Enhanced measures and protections must be provided for vulnerable groups exposed to cyberviolence risks, including minors, the elderly, and persons with disabilities. In particular, live-streaming, audio/video and social networking service providers must provide services to minors through a dedicated minor-protection mode and offer guardians accessible functions to receive cyberviolence risk alerts and insights on how minors may use the relevant online services.
- Enhanced obligations for large platforms: Platforms with large user bases or significant influence over users must establish rapid-response mechanisms, conduct periodic cyberviolence risk assessments, and publish annual cyberviolence governance reports subject to public oversight.
- Multi-tiered liabilities: The draft Anti-Cyberviolence Law establishes a graduated liability regime covering administrative, civil and criminal liabilities. Depending on the nature and severity of the violation, network service providers may face warnings, confiscation of illegal gains, fines, suspension of relevant business operations, closure of websites or applications, and revocation of relevant permits or business licences. Personnel with direct responsibility for violations are potentially subject to individual fines. For the most serious violations, fines may reach RMB 10 million for service providers and RMB 1 million for directly responsible personnel. Organisations and individuals involved in organising, inciting or assisting cyberviolence may be subject to heavier administrative penalties and may also bear civil or criminal liability.
Summary
The draft Anti-Cyberviolence Law strengthens China’s regulatory framework for preventing and addressing cyberviolence. If enacted in its current form, it would impose more comprehensive governance obligations on network service providers and other stakeholders. The draft Anti-Cyberviolence Law may also be relevant to multinational businesses beyond Chinese online platforms. International enterprises operating network services or other online communication services in China should assess whether such services may fall within the scope of the proposed requirements. Overseas companies should also be aware of the draft law’s extraterritorial reach for cyberviolence activities targeting persons or organisations within the PRC.
The original publication can be found here (Chinese only).
For more information on China’s Cyberviolence Law and cybersecurity regulations, contact your CMS client partner or the CMS experts who wrote this article.