A Genuine Gap, Named After a Real Victim
On July 29, 2026, the Cyberspace Administration of China (CAC) published a draft Law of the People's Republic of China on Prevention of Cyberbullying for public comment, open until August 28. At 60 articles, it would be China's first dedicated statute on online harassment, layered atop the narrower 2023 Provisions on the Governance of Cyberviolence Information, which took effect in August 2024 but left enforcement scattered across defamation, privacy and cybersecurity law.
The timing is not abstract. In April 2026, a 31-year-old man was given 10 days' administrative detention and fined after police in Guangdong found he had run a WeChat group called "Splash Conquerors Alliance" dedicated to insulting Olympic diving champion Quan Hongchan's weight and appearance — including a group rule exempting every athlete from mockery except her. Quan, then 19, had described in an interview becoming afraid to weigh herself and considering retirement. Her case fits a well-documented pattern: peer-reviewed analysis of Chinese social-media harassment cases finds women are disproportionately targeted, with attacks concentrated on appearance, relationships and family life — categories that rarely rise to the threshold of criminal defamation but inflict sustained psychological harm.
The Steelman: A Real Enforcement Gap
The strongest case for this law is straightforward. China's existing legal toolkit — criminal defamation, the 2023 cyberviolence provisions, platform self-regulation — has consistently failed to act before harm compounds, because each remedy requires the victim to identify a specific bad actor and file a complaint after the pile-on has already spread. The draft law, per China Daily's summary of the text, instead obligates platforms to build "mechanisms for user registration, account management, privacy protection, content review, monitoring and early warning, incident handling, and complaint reporting" — shifting the burden of early detection onto the platforms whose recommendation systems often accelerate pile-ons in the first place. It also bars payment processors, hosting providers and data brokers from knowingly servicing harassment campaigns, closing a real gap: coordinated harassment groups have historically relied on rented accounts and pooled personal data to evade individual-level bans. Penalties reported by Caixin — fines up to 10 million yuan, business suspension, license revocation — are proportionate to the scale of platforms that have, until now, treated harassment moderation as a cost center rather than a compliance obligation. None of this is manufactured urgency; the Quan Hongchan case is a genuine, well-documented harm that existing law handled only after the fact.
Where the Draft Overreaches
The defect is not the anti-harassment framework — it's what has been bundled into it. The draft requires platforms to verify users' real identities before allowing posts or instant messaging. This is not a narrow anti-doxxing measure; it extends a de-anonymization trajectory that predates this bill by years and has nothing to do with harassment enforcement specifically. As MIT Technology Review documented, China required IP-location display in 2022, mandated real names for accounts with 500,000+ followers in October 2023, and has steadily disabled anonymous-reply features — all justified, at the time, as anti-bullying measures. Researcher Xinyu Pan's work, cited in that reporting, found anonymity is precisely what lets vulnerable users speak at all: women disclosing domestic violence, LGBTQ+ users, and — notably, given this law's stated purpose — harassment victims seeking to report abuse without exposing themselves to retaliation. A Chengdu lawyer told the South China Morning Post that broader speech restrictions dressed as anti-cyberbullying measures make ordinary users "more cautious when giving their true opinions" — the opposite of what a law meant to protect speech from intimidation should produce.
The Test That Matters
A cyberbullying law that actually protects women should be judged on enforcement precision, not article count. The 2023 provisions already gave the CAC most of the technical levers — monitoring, warning systems, account-level blocking tools — this draft claims credit for. What's new and consequential is identity verification at the point of posting, which functions identically whether the target is a harasser or a critic of the Ministry of Public Security. Proportionate regulation would decouple the two: real-name requirements scoped to organized harassment campaigns (the payment-processor and data-broker provisions already model this approach) rather than blanket pre-posting verification for ordinary speech. As comments close August 28, that is the provision worth watching — not whether China regulates online harassment, which it should, but whether the final text keeps the anonymity carve-outs that let harassment victims report abuse in the first place.