How the CAC became Chinese tech’s biggest nightmare

The Cyberspace Administration of China’s core functions have expanded from content control to data security and privacy, and it now affects the entire digital economy.

The Chinese flag on a flagpole, flying in the wind.

CAC's rising power and expanding territory are evident in the spike in the number of releases, policies and regulations it issues.

Photo: Jordan McAlister via Getty Images

The Cyberspace Administration of China (CAC) rose to fame as China’s central internet censor and it still is. But in the past few years, the agency has expanded its regulatory scope, gradually morphing into a super regulator that affects virtually every internet company in China.

The CAC has been making headlines all over the world for the past two years as its power has grown exponentially and it has become the leading Chinese regulator in data security and privacy — playing an instrumental role in China’s ongoing tech crackdown.

It was CAC that ordered a cybersecurity review on DiDi's data infrastructure just days after the ride-hailing giant’s U.S. IPO. The cyber watchdog later required companies that hold data for more than 1 million users to undergo a security review before listing their shares overseas. The agency also represents China’s interest in international data governance.

“Its core functions expanded from content to now include data security and privacy,” Jamie Horsley, a senior fellow at Yale Law School’s Paul Tsai China Center, told Protocol. “They permeate everything in a modern economy. It really gives them an arm in or a finger in every regulatory pie basically.”

What is CAC?

CAC is a young agency. Established in 2013, CAC’s initial mandate was to regulate online content, authorized by the State Council, China’s cabinet. As China’s cyberspace watchdog, its launch coincided with Xi Jinping’s focus on cyberspace, and it was tasked with drafting and implementing the country’s 2017 Cybersecurity Law.

Today, beyond being the primary regulator of online content, the CAC is also in charge of drafting some of the most important legal frameworks regarding data in China, such as the Data Security Law and the Personal Information Protection Law, which went into effect last year. CAC asserting its jurisdiction over the DiDi IPO launched it into an area that used to be just the purview of the Chinese securities regulator, the Ministry of Commerce and, to some extent, the State Council, according to Horsley.

A graph displaying years on the X axis and "mentions of personal information" on the Y axis. Mentions were highest in 2019 and 2021, but extremely low prior to 2019.Mentions of "personal information" in CAC's work skyrocketed in late 2019, and again last year.Image: Protocol

After CAC launched an investigation into DiDi’s data infrastructure, it established a cybersecurity review regime for future overseas listings. It’s clear that CAC is “expanding their regulatory scope extraterritorially, not only within China; now they're doing cybersecurity screening to companies seeking IPOs in the U.S. and in Hong Kong,” said Xiaomeng Lu, a director in Eurasia Group's geo-technology practice.

The expansion of CAC’s mandate in part reflects the evolution of the notion of cybersecurity. “The Cybersecurity Law has the data component to it, but it's very much hardware-focused,” Lu said. “But over time, data has been playing a much bigger role in cyberspace from a cybersecurity perspective … [data] is one of the many characters in the movie that became the breakout character and it needs its own show.”

Behind CAC’s rising power

But CAC is not just any ordinary regulator. Besides acting like an administrative agency that writes rules and enforces them, CAC has a more important identity: It is an opaque Party entity, directly under the Central Committee of the Chinese Communist Party, which acts as the board of directors for the Party.

During China’s massive 2018 government reorganization, Horsley found that CAC was removed from State Council oversight and put directly under the Central Committee. Since then, the agency with dual state-party identity morphed away from just ensuring a clean, healthy, non-threatening internet to more broadly protecting privacy and data security.

“The question is, ‘Where's the CAC getting its orders from? Where is it getting its power from?’” Horsley said. “And the only answer you can think of is, ‘Look, it's right under Xi Jinping and the Central Committee, basically. It can do whatever it decides, and [Xi and the Central Committee] decide what should be its focus.”

CAC's rising power and expanding territory are evident in the spike in the number of releases, policies and regulations it issues. Before 2019, the powerful internet regulator rarely issued more than 20 official releases a month. But CAC started weighing in more regularly just before COVID-19, and for the past several months it has averaged more than 40 notices each month.

A graph displaying years on the X axis and CAC releases on the Y axis. Releases show a seasonal spike every year but each successive spike trends higher than the one before it.CAC got busy in 2021.Image: Protocol

Not all of these notices are substantive; many detail Xi Jinping’s speeches, meetings and calls with foreign diplomats. As an agency that blurs the line between the state and party institutions, CAC’s propaganda function perhaps isn’t all that surprising. Protocol reviewed almost 1,600 official releases from CAC, from its founding in 2013 through late 2021, and found that while the total number of notices published each month held steady, monthly mentions of Xi began increasing shortly after Xi Jinping Thought was enshrined in the constitution in 2018. Mentions really skyrocketed from early 2019, shortly after the Two Sessions and just before the 30th anniversary of Tiananmen Square.

A graph displaying years on the X axis and mentions of Xi Jinping on the Y access, compared against the number of total CAC releases each month. Mentions of Xi skyrocketed since 2019.Xi Jinping has personally become a cornerstone of CAC's releases.Image: Protocol

Concerns about CAC’s dual identity

As a rule-maker, CAC acts like a regular administrative agency, drafting regulations that encompass online content, algorithms and cybersecurity issues and seeking public comments before finalizing the rules.

“On the rule-making side, they seem to be fairly rational and transparent,” Horsley said. “It's good governance practice because it's the way you get a better rule when you help ensure compliance.”

CAC also operates under this state organ identity when it represents China in meetings with global partners to collaborate on international privacy and data governance.

But CAC’s Party identity raises questions and concerns. As a Party entity, it’s not a transparent agency because it’s not subject to administrative law and other rules that would ordinarily regulate agency behavior. Its heavy Party interest particularly concerns experts when CAC, one of the main Chinese data regulators, goes overseas to discuss issues like data transfer and localization with other countries. “So yeah, they use the state name when they go overseas,” Horsley said. “The problem now is CAC is very clearly not, as an organizational matter, part of the State Council. It's a Party animal.”

Correction: This story was updated on March 11, 2022 to correct a misspelling of Horsley's name and to clarify a definition of the CAC as a Party entity.


Judge Zia Faruqui is trying to teach you crypto, one ‘SNL’ reference at a time

His decisions on major cryptocurrency cases have quoted "The Big Lebowski," "SNL," and "Dr. Strangelove." That’s because he wants you — yes, you — to read them.

The ways Zia Faruqui (right) has weighed on cases that have come before him can give lawyers clues as to what legal frameworks will pass muster.

Photo: Carolyn Van Houten/The Washington Post via Getty Images

“Cryptocurrency and related software analytics tools are ‘The wave of the future, Dude. One hundred percent electronic.’”

That’s not a quote from "The Big Lebowski" — at least, not directly. It’s a quote from a Washington, D.C., district court memorandum opinion on the role cryptocurrency analytics tools can play in government investigations. The author is Magistrate Judge Zia Faruqui.

Keep ReadingShow less
Veronica Irwin

Veronica Irwin (@vronirwin) is a San Francisco-based reporter at Protocol covering fintech. Previously she was at the San Francisco Examiner, covering tech from a hyper-local angle. Before that, her byline was featured in SF Weekly, The Nation, Techworker, Ms. Magazine and The Frisc.

The financial technology transformation is driving competition, creating consumer choice, and shaping the future of finance. Hear from seven fintech leaders who are reshaping the future of finance, and join the inaugural Financial Technology Association Fintech Summit to learn more.

Keep ReadingShow less
The Financial Technology Association (FTA) represents industry leaders shaping the future of finance. We champion the power of technology-centered financial services and advocate for the modernization of financial regulation to support inclusion and responsible innovation.

AWS CEO: The cloud isn’t just about technology

As AWS preps for its annual re:Invent conference, Adam Selipsky talks product strategy, support for hybrid environments, and the value of the cloud in uncertain economic times.

Photo: Noah Berger/Getty Images for Amazon Web Services

AWS is gearing up for re:Invent, its annual cloud computing conference where announcements this year are expected to focus on its end-to-end data strategy and delivering new industry-specific services.

It will be the second re:Invent with CEO Adam Selipsky as leader of the industry’s largest cloud provider after his return last year to AWS from data visualization company Tableau Software.

Keep ReadingShow less
Donna Goodison

Donna Goodison (@dgoodison) is Protocol's senior reporter focusing on enterprise infrastructure technology, from the 'Big 3' cloud computing providers to data centers. She previously covered the public cloud at CRN after 15 years as a business reporter for the Boston Herald. Based in Massachusetts, she also has worked as a Boston Globe freelancer, business reporter at the Boston Business Journal and real estate reporter at Banker & Tradesman after toiling at weekly newspapers.

Image: Protocol

We launched Protocol in February 2020 to cover the evolving power center of tech. It is with deep sadness that just under three years later, we are winding down the publication.

As of today, we will not publish any more stories. All of our newsletters, apart from our flagship, Source Code, will no longer be sent. Source Code will be published and sent for the next few weeks, but it will also close down in December.

Keep ReadingShow less
Bennett Richardson

Bennett Richardson ( @bennettrich) is the president of Protocol. Prior to joining Protocol in 2019, Bennett was executive director of global strategic partnerships at POLITICO, where he led strategic growth efforts including POLITICO's European expansion in Brussels and POLITICO's creative agency POLITICO Focus during his six years with the company. Prior to POLITICO, Bennett was co-founder and CMO of Hinge, the mobile dating company recently acquired by Match Group. Bennett began his career in digital and social brand marketing working with major brands across tech, energy, and health care at leading marketing and communications agencies including Edelman and GMMB. Bennett is originally from Portland, Maine, and received his bachelor's degree from Colgate University.


Why large enterprises struggle to find suitable platforms for MLops

As companies expand their use of AI beyond running just a few machine learning models, and as larger enterprises go from deploying hundreds of models to thousands and even millions of models, ML practitioners say that they have yet to find what they need from prepackaged MLops systems.

As companies expand their use of AI beyond running just a few machine learning models, ML practitioners say that they have yet to find what they need from prepackaged MLops systems.

Photo: artpartner-images via Getty Images

On any given day, Lily AI runs hundreds of machine learning models using computer vision and natural language processing that are customized for its retail and ecommerce clients to make website product recommendations, forecast demand, and plan merchandising. But this spring when the company was in the market for a machine learning operations platform to manage its expanding model roster, it wasn’t easy to find a suitable off-the-shelf system that could handle such a large number of models in deployment while also meeting other criteria.

Some MLops platforms are not well-suited for maintaining even more than 10 machine learning models when it comes to keeping track of data, navigating their user interfaces, or reporting capabilities, Matthew Nokleby, machine learning manager for Lily AI’s product intelligence team, told Protocol earlier this year. “The duct tape starts to show,” he said.

Keep ReadingShow less
Kate Kaye

Kate Kaye is an award-winning multimedia reporter digging deep and telling print, digital and audio stories. She covers AI and data for Protocol. Her reporting on AI and tech ethics issues has been published in OneZero, Fast Company, MIT Technology Review, CityLab, Ad Age and Digiday and heard on NPR. Kate is the creator of and is the author of "Campaign '08: A Turning Point for Digital Media," a book about how the 2008 presidential campaigns used digital media and data.

Latest Stories