China, which has been racing to implement one of the world’s toughest data privacy regimes, frequently excoriates companies for mishandling data. But the authorities rarely point fingers at the country’s other top collector of personal information: the government itself.
Security researchers say the leaked database, apparently used by the police in Shanghai, had been left online and unsecured for months. It was exposed after an anonymous user posted in an online forum offering to sell the vast trove of data for 10 Bitcoin, or about $200,000. The New York Times confirmed parts of a sample of the database released by the anonymous user, who posted under the name ChinaDan.
In addition to basic information like names, addresses and ID numbers, the sample also featured details that appeared to be drawn from external databases, like instructions for couriers on where to drop off deliveries, raising questions about how much information private companies share with the authorities. And, of particular concern for many, it also contained intensely personal information, such as police reports that included the names of people accused of rape and domestic violence, as well as private information about political dissidents.
Article source: https://www.nytimes.com/2022/07/14/business/china-data-privacy.html