HomeAnswersChina AI Compliance and Filing

Algorithmic recommendation and filing

What must you keep for a cyberspace administration inspection?

Based on: the Provisions on the Administration of Algorithmic Recommendation in Internet Information Services (互联网信息服务算法推荐管理规定)
Conclusion: The competent authority carries out security assessment and supervisory inspection in accordance with the law, and raises rectification points with a deadline for any problem found. An enterprise shall keep network logs as required by law, cooperate with the inspection and provide the necessary technical, data and other support and assistance. The organisations and personnel involved in the inspection shall keep confidential, in accordance with the law, the personal privacy, personal information and trade secrets they learn of.

What you may need to do

  1. Keep network logs as required by law and make sure they can be queried and exported
  2. Name a contact person for inspection cooperation and prepare a document list
  3. Complete rectification on schedule after receiving rectification points, and report back in writing
  4. Assemble the algorithm mechanism, model and data explanations into a deliverable pack

Clause basis

Provisions on the Administration of Algorithmic Recommendation in Internet Information Services (互联网信息服务算法推荐管理规定) Article 28
The cyberspace administration, together with the telecommunications, public security, market regulation and other relevant departments, carries out security assessment and supervisory inspection of algorithmic recommendation services in accordance with the law, and promptly raises rectification points with a deadline for any problem found.
Provisions on the Administration of Algorithmic Recommendation in Internet Information Services (互联网信息服务算法推荐管理规定) Article 28
Providers of algorithmic recommendation services shall keep network logs as required by law, cooperate with the cyberspace administration and the telecommunications, public security, market regulation and other relevant departments in carrying out security assessment and supervisory inspection, and provide the necessary technical, data and other support and assistance.
Provisions on the Administration of Algorithmic Recommendation in Internet Information Services (互联网信息服务算法推荐管理规定) Article 30
Where any organisation or individual discovers conduct that violates these Provisions, it may complain to or report it to the cyberspace administration and the relevant departments. A department that receives such a complaint or report shall handle it promptly in accordance with the law.

One-line answer

At the inspection stage an enterprise cannot respond passively: it must keep network logs as required by law, cooperate with the competent authority in security assessment and supervisory inspection, and provide the necessary technical, data and other support and assistance; problems raised during the inspection must be rectified within the deadline.

The basis

Article 28, paragraph 1 describes what the regulator does: the cyberspace administration, together with the telecommunications, public security, market regulation and other relevant departments, carries out security assessment and supervisory inspection of algorithmic recommendation services in accordance with the law, and promptly raises rectification points with a deadline for any problem found.

Paragraph 2 of the same article is the enterprise-side duty to cooperate: providers of algorithmic recommendation services shall keep network logs as required by law, cooperate with the cyberspace administration and the telecommunications, public security, market regulation and other relevant departments in carrying out security assessment and supervisory inspection, and provide the necessary technical, data and other support and assistance. The key words here are “keep” and “cooperate”: the first is an ongoing data management requirement, the second is a behavioural requirement that applies once an inspection happens.

Article 29 is the confidentiality boundary enterprises care about: the relevant organisations and personnel involved in the security assessment and supervisory inspection of algorithmic recommendation services shall keep confidential, in accordance with the law, the personal privacy, personal information and trade secrets they learn of in the course of performing their duties, and shall not disclose them or provide them illegally to others. This article is both reassurance for the enterprise and the basis for talking to the inspectors — you can rely on it to have the inspectors' confidentiality duty made explicit.

Article 30 is the external supervision channel: where any organisation or individual discovers conduct that violates these Provisions, it may complain to or report it to the cyberspace administration and the relevant departments, and a department that receives such a complaint or report shall handle it promptly in accordance with the law. An enterprise's user appeals entry point and this article together form the complaint and reporting loop.

What you need to do

Common pitfalls

Logs kept only on a local machine and impossible to export amount to no retention at all. When the regulator asks you to explain the mechanism of the algorithm, you have product documentation but no algorithm description. The rectification response only says “rectified”, with no verifiable evidence attached. Concern about trade secrets is stretched into refusing to provide the necessary technical and data support, when the article expressly requires that assistance be provided.

Common follow-up questions

The specific retention period for network logs is not prescribed in the source document; follow the Cybersecurity Law (网络安全法) and other laws and administrative regulations, and the practice of the local cyberspace administration office.

Common follow-up questions

Can we refuse to provide algorithm details during an inspection?
Article 28, paragraph 2 requires the necessary technical, data and other support and assistance. For the parts that involve trade secrets, you can rely on Article 29 to require the inspectors to perform their confidentiality duty.
Is there a deadline for rectification?
Article 28, paragraph 1 says rectification “within a deadline”; the specific deadline is set by the department that raised the rectification points.

This entry belongs to the “China AI Compliance and Filing” cluster (42 entries in total): View all · Answers home

Who we are: a knowledge base and AI customer service team serving small and micro businesses, delivering implementations that take AI customer service through the national standard and the filing process.

Content on this site is compiled from publicly released regulatory texts for enterprises' own self-check reference; the specific filing requirements of the local cyberspace administration authorities prevail, and this is not legal advice.

This page is generated from the China AI compliance and filing MCP corpus — agents can call the same data directly.