China: The Surveillance State in Practice
Podcast requires regeneration.

The most misleading way to understand surveillance in China is to imagine a single machine.
There is no one screen on which the government watches every citizen. There is no universal number that rises when a person behaves obediently and falls when they cross the street incorrectly. The familiar Western image of a national “social credit score” is a distortion: a dramatic simplification of a much larger and more consequential reality.
China has not built one surveillance system.
It has built the conditions under which many systems can cooperate.
Identity records, cameras, telecommunications, travel systems, financial regulation, internet platforms, local police databases and administrative blacklists do not have to become one perfect database to change the relationship between citizen and state. They need only become reliable enough to identify the same person, interoperable enough to exchange information and useful enough to shape what institutions do next.
This is the implementation phase of surveillance.
The first installment of this investigation examined how artificial intelligence converts accumulated data into knowledge. The second examined the long political struggle that created private life and the speed with which convenience helped dissolve it. China presents the next question: what happens when collection, identity, analysis and administrative power are not merely available, but organized as ordinary instruments of governance?
The answer is not science fiction. It is bureaucracy at scale.
The Myth of the Single Score
China’s social-credit system is often described abroad as if every citizen carries a single numerical rating that determines whether they may board a train, rent an apartment or send a child to school. That story is memorable. It is also inaccurate.
The real system is less theatrical and more institutional. It consists of regulatory records, court-enforcement lists, sector-specific evaluations, company credit information, administrative sanctions and incentives distributed across different levels of government. A business may be evaluated for tax compliance, food safety or environmental conduct. A person who refuses to comply with a court judgment may face restrictions connected to that judgment. Local experiments have sometimes used points, but they are not evidence of one unified national score assigned to every citizen.
Correcting the myth does not make the system harmless. It reveals what actually matters.
Power does not require a magic number. It requires records that follow an identity and consequences that can travel between institutions.
China’s 2025 national guidance on the social-credit system describes a legal and administrative infrastructure intended to cover different kinds of entities and economic activity. The same guidance also warns against excessive collection, improper use and the overgeneralization of punitive measures. Those protections matter. Their existence also tells us what the system makes possible: information gathered for one administrative purpose can acquire influence elsewhere unless boundaries are actively enforced.
The danger is not that an algorithm secretly reduces a life to 742 points.
The danger is that a person can become legible across institutions.
The Identity Layer
Every scalable surveillance system confronts the same problem: how does it know that records produced in different places belong to the same person?
A camera captures a face. A railway system records a ticket. A platform stores an account. A hotel verifies a guest. A court records a judgment. A telecommunications company knows a subscriber. None of these records becomes truly powerful until identity can connect them.
China’s national network identity authentication public service, governed by rules that took effect in July 2025, is an attempt to create such a layer. The service can issue an online identity number and credential linked to a person’s legal identity, allowing participating services to verify the user without repeatedly collecting the underlying identity document. The official rationale is partly protective: reduce the excessive retention of national identification information by private platforms and disclose only what a transaction requires.
That is a real privacy argument. A reusable credential can be safer than giving every application a copy of a government identification card.
It is also centralization.
The rules describe participation by individuals as voluntary and limit service providers from forcing use where other lawful verification methods are available. They impose duties of minimum collection, security and purpose limitation. Yet the infrastructure still establishes a state-supported method by which activity across services can be tied to verified identity. Where law requires the provision of identity information or logs to authorities, the system can provide it.
The same mechanism can therefore reduce one kind of commercial exposure while increasing the coherence of the identity environment as a whole.
Privacy is not determined only by how much information each service sees. It is determined by who can connect the services.
In June 2026, China’s internet regulator published draft rules for distributed digital identity interoperability. They remain proposals, not enacted law. But the direction is revealing: identity credentials designed to function across finance, transportation, customs, taxation and other domains. The administrative dream is not necessarily a giant database containing every transaction. A common identity layer can make separate databases behave as though they belong to the same system.
Interoperability is often presented as efficiency.
From the perspective of power, it is also reach.
The Camera Is Becoming an Institution
China’s camera networks are famous enough to have become visual shorthand for the surveillance state. Images of dense urban camera installations appear in nearly every foreign account. The hardware matters, but the camera itself is no longer the important unit.
The important unit is the governed system around it.
State Council regulations that took effect in April 2025 define public-security video systems as systems that collect, transmit, display and store video related to public safety. The regulations establish rules for placement, warning signs, cybersecurity, data security and the protection of personal information. They prohibit cameras in hotel rooms, dormitories, bathrooms, changing rooms and other intimate spaces. They restrict unlawful access and dissemination. Separate facial-recognition rules, effective in June 2025, require a specific purpose and sufficient necessity, minimum impact on individual rights, notice, separate consent in consent-based uses, short retention and privacy-impact assessment.
The rules also say facial recognition should not be the only verification method where another method can achieve the same purpose. Public-place systems must be necessary for public security. Operators storing facial information from 100,000 people must file with provincial-level or higher internet regulators.
These are not trivial protections. A serious account of China should not erase them.
But regulation does not mean retreat. It means normalization.
China is not abandoning facial recognition or public-security video. It is writing the rules by which these systems become durable parts of the state. National technical standards continue to define public-security video analysis and camera requirements. The companies and public-security research institutions involved in those standards are not debating whether machine vision will exist. They are deciding how it will operate.
This is what the implementation phase looks like. A technology moves from demonstration to procurement, from procurement to standards, from standards to routine administration. Its most consequential moment may not be the day it is first deployed. It may be the day it becomes unremarkable.
Xinjiang and the Difference Between Capacity and Use
No examination of surveillance in China can avoid Xinjiang.
United Nations human-rights experts and the Office of the High Commissioner for Human Rights have documented allegations of large-scale arbitrary detention, intrusive monitoring, biometric collection and technology-assisted policing directed at Uyghurs and other predominantly Muslim communities. Chinese authorities dispute many of these findings and describe their policies in terms of counterterrorism, deradicalization, public safety and development.
The disagreement is politically profound. The institutional lesson is more basic.
A surveillance architecture cannot be evaluated only by its ordinary consumer uses or by the safeguards written into national rules. It must also be evaluated by what happens when the state declares a population, movement or region to be a security problem.
Systems that appear administrative in ordinary life can become coercive under exceptional authority. Identity verification can become movement control. Camera networks can become persistent tracking. Police databases can become tools of association mapping. Checkpoints can become opportunities for extraction. A risk flag can become the beginning of investigation rather than the result of one.
The distinction between data and punishment is politically comforting but technically weak. Data does not punish anyone by itself. Institutions do. Yet institutions act through information, and the quality of the information environment determines how widely suspicion can spread.
Xinjiang shows why “the system has safeguards” and “the system can be used coercively” can both be true.
Capacity survives the policy of the moment.
The Phone, the Platform and the State
Surveillance in China is not produced solely by police cameras. As elsewhere, everyday life creates the archive.
Mobile payments, super-apps, location services, transportation systems, online accounts and platform moderation generate records because they are necessary to modern commerce and communication. China’s Personal Information Protection Law and related data-security rules impose consent, purpose, minimization and security obligations on many forms of processing. Chinese regulators have repeatedly acted against applications for excessive collection and other violations.
Again, the simplistic story fails. China is not a country without privacy law.
It is a country in which privacy protections operate inside a political system that gives the party-state broad authority in the name of national security, public order and social governance. Commercial privacy and political privacy are not the same thing. A citizen may have a legitimate complaint when a company collects unnecessary contacts while possessing far less ability to resist a lawful demand made under state authority.
This distinction exists in democracies too. Companies are restrained in some contexts while governments retain expansive powers in others. The difference is not that one society has law and another has only surveillance. The difference lies in who can challenge a demand, which court can hear the challenge, what evidence becomes public, how independent the adjudicator is and whether political opposition itself remains protected.
Privacy is not merely a rule governing data.
It is a structure governing power.
Prediction Changes Policing
Traditional policing begins with an event. A crime is reported, evidence is collected, suspects are identified and an investigation follows.
Data-driven policing can reverse the sequence.
It can begin with a person, place, relationship or pattern that a system has classified as worthy of attention. The prediction does not need to be called an arrest decision to alter a life. It can determine who is questioned, whose device is inspected, which neighborhood receives patrols, which traveler is delayed or which account receives additional scrutiny.
Every predictive system faces a recursive problem. It learns from records created by previous enforcement. If police concentrate attention in one place, they will record more incidents there. Those records may justify additional attention. The system can transform the history of institutional observation into evidence about the population being observed.
AI makes this loop faster, but it does not make it objective.
In China, the integration of public-security video, identity systems and administrative data creates the possibility of moving from retrospective search toward continuous classification. Not every available capability is used everywhere, and publicly accessible evidence rarely permits outsiders to map the entire system with precision. It would be irresponsible to claim otherwise.
The central fact does not require omniscience. The state is building standardized, identity-aware and increasingly machine-readable systems at national scale. Once those capacities exist, political restraint must do more work than technological limitation once did.
China Is Not the Future
Western discussion often treats China as a warning from somewhere else.
That is too convenient.
China’s political system permits forms of central coordination, censorship and state authority that distinguish it from liberal democracies. Those differences are real and should not be blurred for rhetorical effect. But the underlying components of the surveillance architecture are not uniquely Chinese. Facial recognition, commercial location data, identity verification, automated license-plate readers, platform records, predictive analytics and government contracts exist throughout the democratic world.
The procurement pathways differ. The legal doctrines differ. The rhetoric differs. The infrastructure is becoming familiar.
China is important not because every country will copy its institutions exactly. It is important because it demonstrates what occurs when the components are treated as a coherent governing capacity rather than isolated tools. It shows that surveillance does not have to arrive through one dramatic law. It can arrive through standards, contracts, identity systems, safety programs, fraud prevention, platform obligations and administrative convenience.
The democratic world prefers to describe each system separately.
The data broker is commercial.
The camera is local.
The border database concerns immigration.
The facial-recognition search concerns crime.
The identity credential prevents fraud.
The intelligence purchase uses information already for sale.
Each statement may be true. Together they describe an architecture.
The question is therefore not when China’s system will come here.
The question is which parts have already arrived, who operates them, and whether dividing power among companies, police departments, intelligence agencies and contractors makes the citizen more protected—or merely makes the system harder to see.
That is the subject of the next investigation.
Sources
- Cyberspace Administration of China and Ministry of Public Security, “Measures for the Security Management of the Application of Facial Recognition Technology,” March 21, 2025: https://www.cac.gov.cn/2025-03/21/c_1744174262342111.htm
- State Council of the People’s Republic of China, regulations on public-security video systems, February 10, 2025: https://english.www.gov.cn/policies/latestreleases/202502/10/content_WS67a9d629c6d0868f4e8ef898.html
- Cyberspace Administration of China, national network identity authentication public-service rules, May 23, 2025: https://www.cac.gov.cn/2025-05/23/c_1749711107837215.htm
- Cyberspace Administration of China, draft distributed digital identity interoperability rules, June 18, 2026: https://www.cac.gov.cn/2026-06/18/c_1783525605384124.htm
- State Council guidance on improving the social-credit system, March 2025: https://english.www.gov.cn/policies/latestreleases/202503/31/content_WS67ea9a7fc6d0868f4e8ef898.html
- Office of the United Nations High Commissioner for Human Rights, *Assessment of human rights concerns in the Xinjiang Uyghur Autonomous Region, People’s Republic of China*, August 31, 2022: https://www.ohchr.org/sites/default/files/documents/countries/2022-08-31/22-08-31-final-assesment.pdf
This is Part III of The End of Privacy, a three-part NOMOTO MEDIA Investigation into artificial intelligence, surveillance, data collection, identity, and institutional power.