Mechanism
From Fragmented Records to Police Leads
Traces how police platforms ingest, standardize, and link records into leads or check tasks, while separating capacity, deployment, operation, and consequences.
Contents
Police Data Fusion Chain
This observable chain combines public design documents with IJOP technical evidence; it does not show that every locality deployed and operated every stage.
Five Evidentiary Levels
Evidence at an earlier level cannot prove later operation or consequences.
| Evidence Level | Can Establish | Cannot Establish |
|---|---|---|
| Stated Goals | Construction and operational requirements | Actual procurement or deployment |
| Procured Capacity | Functions listed in procurement | That functions entered operation |
| Local Deployment | Projects publicly described as deployed | Use of a function in a specific case |
| Technical Operation | Observable interfaces and operation | All back-end algorithms and permissions |
| Case Consequences | Recorded tasks, checks, or actions | The same consequences in other regions |
Core Question
Police big-data fusion in China is neither a single giant database nor simply a new search tool for officers. It is a process for bringing together records that were previously separated across household registration, case, vehicle, address, organization, and other police systems. The same environment may also receive information shared by other government departments, data from organizations outside government, internet material, and multimedia records. Public technical documents describe a basic sequence: ingest the data, clean and standardize it, link records that refer to the same entities, apply rules or models, and deliver the results to operational users [1].
The outputs can include search results, relationship leads, alerts, or tasks for local officers to check. Evidence that a platform was designed, purchased, or publicly described as deployed can establish capacity at those levels. It does not by itself show that a function was used in a particular case or that its output was accurate. Materials from Jiangsu, Shandong, Hunan, and Liaoning also point to different combinations of provincial platforms, municipal projects, specialized police systems, and front-line applications, rather than one demonstrably identical nationwide system [2] [3] [4] [5].
How Data Enters a Common System
The first stage is access. Chinese public-security agencies already operate internal platforms and systems used by different police service branches. External inputs may include data shared by other government departments, records held by social organizations or businesses, and internet, video, or other multimedia material. Names, identification numbers, addresses, formats, and update dates can differ across sources. A fusion platform therefore needs to standardize fields, formats, and categories before the records become usable in a common analytical layer. A government technical paper separates internal police data, information obtained through departmental sharing, data from social organizations, and internet and multimedia data, and places standardization before application [1].
The second stage is entity linkage. Cross-database fusion means determining whether records from separate systems refer to the same person, address, organization, object, or case. Stable identifiers such as a national identification number can serve as a link. Addresses, contact details, organizations, and case relationships can extend that link into a wider network. An investigation of early police-cloud procurement documents from Shandong, Jiangsu, and Tianjin found plans to connect police, government, and corporate data through identifiers including identification numbers, with relationship discovery and anomaly detection among the intended uses [9].
The third stage is an operational output. Official technical and local-government materials list labels, profiles of people or other subjects, multidimensional relationship analysis, search and information delivery, monitoring alerts, and integrated command functions. An officer may see a returned profile, a relationship map, a lead requiring verification, or a task pushed by a command system rather than the underlying data warehouse. These descriptions establish the direction of planned or reported functions. On their own, they do not reveal how every alert rule was set or whether each result was justified [1] [3].
How It Works
Public technical plans and procurement records translate construction and operational requirements into modules for data collection, standardization, interfaces, search, and alerts [1] [6]. Provincial or municipal cloud platforms can provide computing, storage, and a shared data layer. Systems for individual police service branches retain their specialized records, data-governance services perform aggregation and standardization, and application layers deliver results to command centers or front-line personnel [2] [3]. A recent Ministry of Public Security procurement also covered connections across government networks, data integration, and information sharing, but the scope of a central procurement cannot substitute for checking what each locality actually deployed [6].
Front-line use turns stored information into police action. Officers may search for a person, add newly collected information, receive an alert or investigative lead, and return the result of a field check to an operational system. Shandong's public account places information from multiple police branches, links to social information, front-line use, and user feedback within the same construction narrative. This indicates that local officers may be both recipients of system outputs and sources of additional data [3].
The people whose information is aggregated, linked, and labeled bear the immediate risk of errors. An incorrect field can travel into more operational settings after linkage, while a broad risk rule can turn ordinary activity into a lead requiring a check. Public descriptions of local projects say much more about system components and intended capacity than about false-positive rates, correction procedures, or how a person could learn that their information had been accessed. Specific consequences should be attributed only when evidence reaches the stage of a task, check, or enforcement action.
Key Facts: Local Systems Are Not One Template
Jiangsu's public account emphasizes a province-and-city integrated police cloud and comprehensive data aggregation. Shandong's account gives greater attention to links among information from different police branches and social sources, as well as the extension of data applications to local officers and the feedback generated through use. Both describe fusion, but one public narrative centers on provincial and municipal infrastructure while the other highlights operational coordination and front-line application. A shared label such as "police cloud" does not establish identical fields, rules, or access permissions [2] [3].
A Hunan Provincial Public Security Department response describes both a provincial cloud platform and related investment by cities and prefectures [4]. In Anshan, a city in Liaoning province, the procurement award placed resource leasing in Package 001, combined data integration and aggregation, big-data applications, and construction of the new integrated policing platform in Package 002, and assigned project supervision to Package 003 [5]. Under that package structure, infrastructure can be procured separately from the combined data-integration and application-construction service. These differences are evidence of how local systems can be assembled, not a basis for constructing a fixed product list for every city.
The investigation of procurement documents from Shandong, Jiangsu, and Tianjin examined projects from 2015 through 2017 and focused on cross-government and corporate data links, relationship analysis, and anomaly alerts [9]. Jiangsu publicly described an integrated smart-policing structure in 2018, Shandong described local information applications in 2019, Hunan reported on its provincial platform and local investment in 2023, and Anshan announced the result of a big-data and new integrated-policing-platform procurement in 2025 [2] [3] [4] [5]. This timeline establishes continued local development. The dates alone do not show that every locality followed the same upgrade sequence.
What IJOP Reveals
The Integrated Joint Operations Platform in Xinjiang is commonly known by the acronym IJOP. It matters here not because it can stand for every Chinese police platform, but because outside researchers obtained technical material closer to operational use than is available for many local projects. Reverse engineering of its mobile application identified interfaces for person searches, individual files, information collection, and the transfer of tasks or leads. Taken together, those interfaces make visible a loop in which information enters a system, rules flag a person, and a task reaches personnel responsible for checking that person [10].
The reverse engineering has a clear limit. Researchers lacked a username and password and therefore did not log into the IJOP app; they also did not connect to IJOP servers to obtain data that would populate it [10]. Client-side code therefore cannot reconstruct all back-end databases, algorithms, or permission settings. It supports the existence of certain search, collection, and task functions between the platform and mobile users, but cannot establish how every label was calculated or the accuracy of every alert [10].
In its 2022 assessment, the Office of the United Nations High Commissioner for Human Rights considered publicly available IJOP material within the broader environment of surveillance in Xinjiang. It found that the available information indicated aggregation of extensive personal data and a system capable of flagging individuals as potential candidates for detention. The assessment also addressed risks of discrimination and arbitrary detention. Its findings concern Xinjiang's specific governance context and do not replace operational evidence for platforms in other provinces [11].
An Associated Press investigation published in 2025 used leaked emails, internal documents, procurement records, and interviews to report on labels, risk scores, alerts, a path to detention, and software errors. That investigation linked technology suppliers, system outputs, and effects on individuals more specifically. Its figures about scale and consequences retain the evidentiary scope of its own materials and should be presented separately from the United Nations assessment and the application reverse engineering, rather than treated as independent versions of the same original record [12] [11] [10].
Legal Boundaries and Compliance
China's Personal Information Protection Law requires state bodies to process personal information within their statutory authority and procedures and not beyond the scope necessary to perform their duties [7]. The Data Security Law requires public-security bodies seeking access to data to follow relevant national rules and strict approval procedures [8]. These provisions supply questions for legal review: whether an authority had power to obtain the information, whether the scope was necessary, and whether approval procedures were followed. The statutory text does not establish that every interface on an operating platform complies, nor does it document how local systems apply the approval requirements in practice.
The 2025 regulation on public-security video-image information systems provides more specific administrative rules for the construction, collection, transmission, storage, and use of video systems. It also assigns guidance and supervisory responsibilities to public-security organs and sets requirements for local coordination and personal-information protection [13]. Video is only one category of input to a fusion platform. The regulation can inform review of how that category enters and is used by a system, but it does not automatically resolve every legal question involving household registration, communications, or interdepartmental government data.
Disputes and Evidence Limits
The Chinese government has publicly rejected the legitimacy and credibility of the United Nations assessment on Xinjiang, saying that it relied on false information and was politically motivated [14]. That response belongs alongside the assessment, but the dispute operates at several levels. The Chinese government challenges sources, methods, and legal evaluation. The United Nations assessment, the technical reverse engineering, and the later investigation respectively provide analysis of public material, observations from client software, and reporting based partly on leaked records. Readers should compare those forms of evidence item by item, rather than treating either side's general assessment as a direct answer to every technical finding made by the other [11] [10] [12].
The evidence supports a relatively firm description of a fusion architecture: internal and external data access, standardization, entity linkage, and delivery of outputs to police operations. Several localities have also publicly described different combinations of cloud infrastructure, data governance, and front-line applications. IJOP material makes the later stages of task delivery and person checks more visible. It is reasonable to infer that data quality, linkage rules, and feedback processes affect who is selected for a check. Public evidence remains insufficient to conclude that every locality uses the same algorithm, every purchased function is operational, or every alert produces the same type of action.
Our Position
Any evaluation of police big-data fusion should keep five evidentiary levels separate: the goals stated in policy or technical documents, the capabilities listed in procurement, deployment described by local authorities, operation visible in technical materials, and consequences recorded in individual cases. Evidence at an earlier level cannot prove a later one. Local examples show that fusion platforms are assembled from infrastructure, data-governance services, specialized police systems, and front-line applications. IJOP shows that in a specific region, data aggregation, rule-based flagging, and checks on people can form an operational loop. Together they explain the mechanism, but they do not erase geographic or methodological limits [2] [3] [10].
The central questions are not whether a platform appears sufficiently intelligent. They are whether each act of data access, linkage, labeling, and task delivery has clear authority; whether errors can be detected and corrected; and whether individuals bear costs they have no meaningful way to challenge. The public record is detailed enough to make those questions concrete. It is not detailed enough to support one conclusion about every region, system, and case.
Sources
- [1] State Information Center, "Building a Police Data Analysis Platform in the Era of Big Data."
- [2] Cyberspace Administration of China, "Jiangsu Police Take the Lead in Building a New Smart-Policing System."
- [3] Cyberspace Administration of China, "Shandong Localities Expand Police Informatization to Put Data to Work."
- [4] Hunan Provincial Public Security Department, response to Proposal No. 1312 of the First Session of the 14th Provincial People's Congress.
- [5] China Government Procurement Network, award announcement for the police big-data intelligence and new integrated policing platform project.
- [6] China Government Procurement Network, public tender announcement for Ministry of Public Security Project KXX2205.
- [7] National People's Congress, Personal Information Protection Law of the People's Republic of China.
- [8] National People's Congress, Data Security Law of the People's Republic of China.
- [9] Human Rights Watch, "China: Police 'Big Data' Systems Violate Privacy, Target Dissent."
- [10] Human Rights Watch, "China's Algorithms of Repression: Reverse Engineering a Xinjiang Police Mass Surveillance App."
- [11] Office of the United Nations High Commissioner for Human Rights, "Assessment of Human Rights Concerns in the Xinjiang Uyghur Autonomous Region, People's Republic of China."
- [12] Associated Press, "How Silicon Valley Enabled China's Digital Police State."
- [13] State Council, Regulation on the Administration of Public-Security Video-Image Information Systems.
- [14] Ministry of Foreign Affairs of the People's Republic of China, regular press conference of September 21, 2022.
What the available sources establish
A 2023 public reply from the Hunan Provincial Public Security Department stated that procurement for five first-phase provincial public-security big-data infrastructure projects had been completed with investment exceeding RMB 300 million, while projects by 14 prefecture-level public security authorities exceeded RMB 650 million.
Technical analysis of an application linked to Xinjiang's Integrated Joint Operations Platform found that it aggregated multiple forms of personal data and generated leads for police follow-up.
A 2025 Associated Press investigation reported, based on leaked materials, that hundreds of thousands of people had been tagged as ‘untrustworthy,’ that IJOP flagged 24,412 people as ‘suspicious’ in one week in 2017, and that engineers fixed a software bug to release hundreds of people categorized as high risk.
Sources
Building a Public Security Data Analysis Platform in the Big Data Eratechnical-researchUnchecked
Jiangsu Police Build a New Smart Policing Systemprimary-recordUnchecked
Shandong Localities Deepen Public Security Informatizationprimary-recordUnchecked
Reply to Recommendation No. 1312 of the First Session of the 14th Hunan Provincial People's Congressprimary-recordUnchecked
Award Notice for the Public Security Big Data and New Integrated Policing Platform Projectprimary-recordUnchecked
Ministry of Public Security KXX2205 Project Public Tender Noticeprimary-recordUnchecked
Personal Information Protection Law of the PRCprimary-recordUnchecked
Data Security Law of the PRCprimary-recordUnchecked
China: Police ‘Big Data’ Systems Violate Privacy, Target Dissenthuman-rights-reportUnchecked
China's Algorithms of Repression: Reverse Engineering a Xinjiang Police Apptechnical-researchLive
OHCHR Assessment of Human Rights Concerns in Xinjiangofficial-findingUnchecked
How Silicon Valley Enabled China's Digital Police Stateinvestigative-reportingUnchecked
Regulation on Public Security Video Image Information Systemsprimary-recordLive
Foreign Ministry Spokesperson Wang Wenbin's Regular Press Conference on September 21, 2022primary-recordUnchecked