How the CAC became Chinese tech’s biggest nightmare

The Cyberspace Administration of China’s core functions have expanded from content control to data security and privacy, and it now affects the entire digital economy.

The Chinese flag on a flagpole, flying in the wind.

CAC's rising power and expanding territory are evident in the spike in the number of releases, policies and regulations it issues.

Photo: Jordan McAlister via Getty Images

The Cyberspace Administration of China (CAC) rose to fame as China’s central internet censor and it still is. But in the past few years, the agency has expanded its regulatory scope, gradually morphing into a super regulator that affects virtually every internet company in China.

The CAC has been making headlines all over the world for the past two years as its power has grown exponentially and it has become the leading Chinese regulator in data security and privacy — playing an instrumental role in China’s ongoing tech crackdown.

It was CAC that ordered a cybersecurity review on DiDi's data infrastructure just days after the ride-hailing giant’s U.S. IPO. The cyber watchdog later required companies that hold data for more than 1 million users to undergo a security review before listing their shares overseas. The agency also represents China’s interest in international data governance.

“Its core functions expanded from content to now include data security and privacy,” Jamie Horsley, a senior fellow at Yale Law School’s Paul Tsai China Center, told Protocol. “They permeate everything in a modern economy. It really gives them an arm in or a finger in every regulatory pie basically.”

What is CAC?

CAC is a young agency. Established in 2013, CAC’s initial mandate was to regulate online content, authorized by the State Council, China’s cabinet. As China’s cyberspace watchdog, its launch coincided with Xi Jinping’s focus on cyberspace, and it was tasked with drafting and implementing the country’s 2017 Cybersecurity Law.

Today, beyond being the primary regulator of online content, the CAC is also in charge of drafting some of the most important legal frameworks regarding data in China, such as the Data Security Law and the Personal Information Protection Law, which went into effect last year. CAC asserting its jurisdiction over the DiDi IPO launched it into an area that used to be just the purview of the Chinese securities regulator, the Ministry of Commerce and, to some extent, the State Council, according to Horsley.

A graph displaying years on the X axis and "mentions of personal information" on the Y axis. Mentions were highest in 2019 and 2021, but extremely low prior to 2019. Mentions of "personal information" in CAC's work skyrocketed in late 2019, and again last year.Image: Protocol

After CAC launched an investigation into DiDi’s data infrastructure, it established a cybersecurity review regime for future overseas listings. It’s clear that CAC is “expanding their regulatory scope extraterritorially, not only within China; now they're doing cybersecurity screening to companies seeking IPOs in the U.S. and in Hong Kong,” said Xiaomeng Lu, a director in Eurasia Group's geo-technology practice.

The expansion of CAC’s mandate in part reflects the evolution of the notion of cybersecurity. “The Cybersecurity Law has the data component to it, but it's very much hardware-focused,” Lu said. “But over time, data has been playing a much bigger role in cyberspace from a cybersecurity perspective … [data] is one of the many characters in the movie that became the breakout character and it needs its own show.”

Behind CAC’s rising power

But CAC is not just any ordinary regulator. Besides acting like an administrative agency that writes rules and enforces them, CAC has a more important identity: It is an opaque Party entity, directly under the Central Committee of the Chinese Communist Party, which acts as the board of directors for the Party.

During China’s massive 2018 government reorganization, Horsley found that CAC was removed from State Council oversight and put directly under the Central Committee. Since then, the agency with dual state-party identity morphed away from just ensuring a clean, healthy, non-threatening internet to more broadly protecting privacy and data security.

“The question is, ‘Where's the CAC getting its orders from? Where is it getting its power from?’” Horsley said. “And the only answer you can think of is, ‘Look, it's right under Xi Jinping and the Central Committee, basically. It can do whatever it decides, and [Xi and the Central Committee] decide what should be its focus.”

CAC's rising power and expanding territory are evident in the spike in the number of releases, policies and regulations it issues. Before 2019, the powerful internet regulator rarely issued more than 20 official releases a month. But CAC started weighing in more regularly just before COVID-19, and for the past several months it has averaged more than 40 notices each month.

A graph displaying years on the X axis and CAC releases on the Y axis. Releases show a seasonal spike every year but each successive spike trends higher than the one before it. CAC got busy in 2021.Image: Protocol

Not all of these notices are substantive; many detail Xi Jinping’s speeches, meetings and calls with foreign diplomats. As an agency that blurs the line between the state and party institutions, CAC’s propaganda function perhaps isn’t all that surprising. Protocol reviewed almost 1,600 official releases from CAC, from its founding in 2013 through late 2021, and found that while the total number of notices published each month held steady, monthly mentions of Xi began increasing shortly after Xi Jinping Thought was enshrined in the constitution in 2018. Mentions really skyrocketed from early 2019, shortly after the Two Sessions and just before the 30th anniversary of Tiananmen Square.

A graph displaying years on the X axis and mentions of Xi Jinping on the Y access, compared against the number of total CAC releases each month. Mentions of Xi skyrocketed since 2019. Xi Jinping has personally become a cornerstone of CAC's releases.Image: Protocol

Concerns about CAC’s dual identity

As a rule-maker, CAC acts like a regular administrative agency, drafting regulations that encompass online content, algorithms and cybersecurity issues and seeking public comments before finalizing the rules.

“On the rule-making side, they seem to be fairly rational and transparent,” Horsley said. “It's good governance practice because it's the way you get a better rule when you help ensure compliance.”

CAC also operates under this state organ identity when it represents China in meetings with global partners to collaborate on international privacy and data governance.

But CAC’s Party identity raises questions and concerns. As a Party entity, it’s not a transparent agency because it’s not subject to administrative law and other rules that would ordinarily regulate agency behavior. Its heavy Party interest particularly concerns experts when CAC, one of the main Chinese data regulators, goes overseas to discuss issues like data transfer and localization with other countries. “So yeah, they use the state name when they go overseas,” Horsley said. “The problem now is CAC is very clearly not, as an organizational matter, part of the State Council. It's a Party animal.”

Correction: This story was updated on March 11, 2022 to correct a misspelling of Horsley's name and to clarify a definition of the CAC as a Party entity.


Gavin Newsom shows crypto some California love

“A more flexible approach is needed,” Gov. Newsom said in rejecting a bill that would require crypto companies to get a state license.

Strong bipartisan support wasn’t enough to convince Newsom that requiring crypto companies to register with the state’s Department of Financial Protection and Innovation is the smart path for California.

Photo: Jerod Harris/Getty Images for Vox Media

The Digital Financial Assets Law seemed like a legislative slam dunk in California for critics of the crypto industry.

But strong bipartisan support — it passed 71-0 in the state assembly and 31-6 in the Senate — wasn’t enough to convince Gov. Gavin Newsom that requiring crypto companies to register with the state’s Department of Financial Protection and Innovation is the smart path for California.

Keep Reading Show less
Benjamin Pimentel

Benjamin Pimentel ( @benpimentel) covers crypto and fintech from San Francisco. He has reported on many of the biggest tech stories over the past 20 years for the San Francisco Chronicle, Dow Jones MarketWatch and Business Insider, from the dot-com crash, the rise of cloud computing, social networking and AI to the impact of the Great Recession and the COVID crisis on Silicon Valley and beyond. He can be reached at or via Google Voice at (925) 307-9342.

Sponsored Content

Great products are built on strong patents

Experts say robust intellectual property protection is essential to ensure the long-term R&D required to innovate and maintain America's technology leadership.

Every great tech product that you rely on each day, from the smartphone in your pocket to your music streaming service and navigational system in the car, shares one important thing: part of its innovative design is protected by intellectual property (IP) laws.

From 5G to artificial intelligence, IP protection offers a powerful incentive for researchers to create ground-breaking products, and governmental leaders say its protection is an essential part of maintaining US technology leadership. To quote Secretary of Commerce Gina Raimondo: "intellectual property protection is vital for American innovation and entrepreneurship.”

Keep Reading Show less
James Daly
James Daly has a deep knowledge of creating brand voice identity, including understanding various audiences and targeting messaging accordingly. He enjoys commissioning, editing, writing, and business development, particularly in launching new ventures and building passionate audiences. Daly has led teams large and small to multiple awards and quantifiable success through a strategy built on teamwork, passion, fact-checking, intelligence, analytics, and audience growth while meeting budget goals and production deadlines in fast-paced environments. Daly is the Editorial Director of 2030 Media and a contributor at Wired.

Slack’s rallying cry at Dreamforce: No more meetings

It’s not all cartoon bears and therapy pigs — work conferences are a good place to talk about the future of work.

“We want people to be able to work in whatever way works for them with flexible schedules, in meetings and out of meetings,” Slack chief product officer Tamar Yehoshua told Protocol at Dreamforce 2022.

Photo: Marlena Sloss/Bloomberg via Getty Images

Dreamforce is primarily Salesforce’s show. But Slack wasn’t to be left out, especially as the primary connector between Salesforce and the mainstream working world.

The average knowledge worker spends more time using a communication tool like Slack than a CRM like Salesforce, positioning it as the best Salesforce product to concern itself with the future of work. In between meeting a therapy pig and meditating by the Dreamforce waterfall, Protocol sat down with several Slack execs and conference-goers to chat about the shifting future.

Keep Reading Show less
Lizzy Lawrence

Lizzy Lawrence ( @LizzyLaw_) is a reporter at Protocol, covering tools and productivity in the workplace. She's a recent graduate of the University of Michigan, where she studied sociology and international studies. She served as editor in chief of The Michigan Daily, her school's independent newspaper. She's based in D.C., and can be reached at

LA is a growing tech hub. But not everyone may fit.

LA has a housing crisis similar to Silicon Valley’s. And single-family-zoning laws are mostly to blame.

As the number of tech companies in the region grows, so does the number of tech workers, whose high salaries put them at an advantage in both LA's renting and buying markets.

Photo: Nat Rubio-Licht/Protocol

LA’s tech scene is on the rise. The number of unicorn companies in Los Angeles is growing, and the city has become the third-largest startup ecosystem nationally behind the Bay Area and New York with more than 4,000 VC-backed startups in industries ranging from aerospace to creators. As the number of tech companies in the region grows, so does the number of tech workers. The city is quickly becoming more and more like Silicon Valley — a new startup and a dozen tech workers on every corner and companies like Google, Netflix, and Twitter setting up offices there.

But with growth comes growing pains. Los Angeles, especially the burgeoning Silicon Beach area — which includes Santa Monica, Venice, and Marina del Rey — shares something in common with its namesake Silicon Valley: a severe lack of housing.

Keep Reading Show less
Nat Rubio-Licht

Nat Rubio-Licht is a Los Angeles-based news writer at Protocol. They graduated from Syracuse University with a degree in newspaper and online journalism in May 2020. Prior to joining the team, they worked at the Los Angeles Business Journal as a technology and aerospace reporter.


SFPD can now surveil a private camera network funded by Ripple chair

The San Francisco Board of Supervisors approved a policy that the ACLU and EFF argue will further criminalize marginalized groups.

SFPD will be able to temporarily tap into private surveillance networks in certain circumstances.

Photo: Justin Sullivan/Getty Images

Ripple chairman and co-founder Chris Larsen has been funding a network of security cameras throughout San Francisco for a decade. Now, the city has given its police department the green light to monitor the feeds from those cameras — and any other private surveillance devices in the city — in real time, whether or not a crime has been committed.

This week, San Francisco’s Board of Supervisors approved a controversial plan to allow SFPD to temporarily tap into private surveillance networks during life-threatening emergencies, large events, and in the course of criminal investigations, including investigations of misdemeanors. The decision came despite fervent opposition from groups, including the ACLU of Northern California and the Electronic Frontier Foundation, which say the police department’s new authority will be misused against protesters and marginalized groups in a city that has been a bastion for both.

Keep Reading Show less
Issie Lapowsky

Issie Lapowsky ( @issielapowsky) is Protocol's chief correspondent, covering the intersection of technology, politics, and national affairs. She also oversees Protocol's fellowship program. Previously, she was a senior writer at Wired, where she covered the 2016 election and the Facebook beat in its aftermath. Prior to that, Issie worked as a staff writer for Inc. magazine, writing about small business and entrepreneurship. She has also worked as an on-air contributor for CBS News and taught a graduate-level course at New York University's Center for Publishing on how tech giants have affected publishing.

Latest Stories