The Lawxy Times

Author Image
Abhishek Mundra

Chongqing Tech Firm Warned Over Unlawful Personal Data Processing

On August 11, 2026, the Chongqing Municipal Internet Regulator issued a warning to a technology company in Jiulongpo District, China, for unlawfully denying products or services to users who refused to consent to the processing of their personal information. This ruling highlights the limits of companies' ability to deny services based on personal data consent. The company must rectify its violations and improve its personal-information protection compliance, review its app's operation to ensure compliance with applicable rules.

Full News Breakdown

The dispute was triggered by an inspection by the local internet regulator, which found that the company's app unlawfully denied products or services to users who refused to consent to the processing of their personal information. The core disagreement was whether the company's actions constituted a violation of personal data protection regulations. The company was ordered to rectify its violations, improve its personal-information protection compliance, strengthen technical safeguards, address potential risks, and enhance employee training on internet-related laws and regulations. The company stated it will carry out the required rectification, strengthen its internal management and cybersecurity mechanisms, and review its app's operation to ensure compliance with applicable rules.

How Does This Affect You?

The regulator specifically resolved that companies cannot unlawfully deny products or services to users who refuse to consent to the processing of their personal information. This creates a compliance obligation for companies operating in China's tech industry. Users have more control over their personal data, and companies must take into account the new personal data protection regulations in China. The ruling affects the way companies handle personal data in China, making it certain that users' rights will be protected.

For Lawyers & Advocates

  • Lawyers may find it useful to review client contracts to ensure compliance with the new personal data protection regulations in China, focusing on consent mechanisms and service denial clauses.

  • Lawyers may consider advising clients on necessary changes to their internal management and cybersecurity mechanisms to ensure compliance with the regulator's orders.

  • Lawyers may want to draft new policies and procedures for handling personal data in China, considering the implications of this ruling on companies' ability to deny services.

  • Lawyers may find it useful to update their knowledge on the latest developments in personal data protection in China, including the regulator's interpretation of "unlawful denial of services."

  • Lawyers may want to consider the impact of this ruling on pending or ongoing client matters, particularly those involving personal data processing and consent.

For Law Students

The decision provides an opportunity to examine the importance of proportionality in data protection law, particularly in the context of companies' ability to deny services based on personal data consent. The core legal doctrine to focus on is the balance between data protection and the free movement of personal data. The decision is particularly relevant for the study of Data Protection Law, EU Law, Human Rights Law, Contract Law. The comparable cases of Google Spain SL v. Agencia Española de Protección de Datos (2014) CJEU and Schrems v. Data Protection Commissioner (2015) CJEU provide insight into the EU's approach to data protection and the balance between data protection and the free movement of personal data.

For Businesses

  • Businesses may want to consider ensuring their apps comply with the new personal data protection regulations, focusing on consent mechanisms and service denial clauses.

  • Businesses may find it useful to update their internal documentation and filing processes to reflect the new regulations, including policies on personal data processing and consent.

  • Businesses may want to decide whether to implement new technical safeguards to address potential risks, considering the regulator's orders and the implications of this ruling.

  • Businesses may find it useful to train their employees on the new internet-related laws and regulations, ensuring they understand the implications of this ruling on companies' ability to deny services.

Key Takeaways

  • The legal principle established is that companies cannot unlawfully deny products or services to users who refuse to consent to the processing of their personal information.

  • The practice consequence is that lawyers may find it useful to review client contracts and ensure they comply with the new personal data protection regulations in China.

  • The enforcement consequence is that regulators can issue warnings and orders to companies that fail to comply with the new regulations.

  • What to watch next is the upcoming regulatory action on personal data protection in China, including potential amendments to existing regulations.

  • Companies operating in China's tech industry may want to review their internal documentation and filing processes to reflect the new regulations before the end of 2026, to mitigate potential implications.

Source: Tech company in China's Chongqing warned over personal-data violations

LAWXY

Legal Intelligence Layer Businesses Rely On

Copyright© 2026 Lawxy AI. All Rights Reserved.

Secure by design. Built for enterprise.

More About Security

Lawxy AI is designed with encrypted infrastructure, access controls, audit visibility, and enterprise-grade security standards.

SOC 2 Type I, II

GDPR

ISO 27001

VAPT Tested

LAWXY

Legal Intelligence Layer Businesses Rely On

Copyright© 2026 Lawxy AI. All Rights Reserved.

Secure by design. Built for enterprise.

More About Security

Lawxy AI is designed with encrypted infrastructure, access controls, audit visibility, and enterprise-grade security standards.

SOC 2 Type I, II

GDPR

ISO 27001

VAPT Tested

LAWXY

Legal Intelligence Layer Businesses Rely On

Copyright© 2026 Lawxy AI. All Rights Reserved.

Secure by design. Built for enterprise.

More About Security

Lawxy AI is designed with encrypted infrastructure, access controls, audit visibility, and enterprise-grade security standards.

SOC 2 Type I, II

GDPR

ISO 27001

VAPT Tested