From passports to relationship graphs: Chinese surveillance of foreigners enters the phase of information fusion

Key Takeaways

The Zhangjiakou dashboard was described by the researcher as a demonstration environment, not connected at that time to real-time data streams. Incomplete fields, placeholder images and a risk indicator uniformly set at 63 per cent indicate that the modules were not fully implemented. However, the same environment contained genuine personal data, files on foreign journalists and access logs apparently relating to police stations. The correct statement is therefore not that ‘China monitors every foreigner in real time’, but that a platform designed to incorporate such capabilities used genuine government material and remained exposed on the web.
The area under surveillance no longer corresponds to the camera’s field of view. Passports, visas, trains, seats, hotels, hospitals, fuel purchases, biometric ski passes and co-presence with other individuals all become nodes within a single profile. The operational value does not lie in accumulating more data, but in reconstructing patterns of life, producing relational graphs and providing advance warning of the arrival or interaction of individuals classified as persons of interest.
This issue goes beyond individual privacy. For correspondents, students, academics, managers and diplomatic staff, the interplay between mobility, role, organisation and relationships can restrict freedom of movement, expose sources, facilitate counter-intelligence activities and influence economic or scientific relations. In terms of strategic cyber threat intelligence, the risk lies not merely in being observed, but above all in the possibility that fragmentary information may be transformed into a decision-making profile of the individual and their network.

The surveillance of foreign nationals in China is no longer limited to facial recognition, recording their stay or tracking their movements. The strategic focus lies in the integration of functions that transform everyday life into an operational profile: documents, visas, transport, accommodation, access to healthcare, payments, CCTV, places frequented, professional networks and social relationships. The case of the Dynamic Control Platform for Overseas Personnel does not in itself prove that every module is in full operational use nationwide; however, it does illustrate the architecture towards which Chinese smart policing is converging: not a single CCTV camera, but a layer of intelligence capable of correlating identities, trajectories, events and connections to guide alerts, monitoring and decision-making.

From surveillance of the individual to surveillance of relationships

The most common mistake in interpreting Chinese surveillance is to continue thinking in terms of a single camera, a single database or a single individual under surveillance. Whilst this level remains important, it is no longer sufficient. The strategic transformation concerns the shift from observing the individual to the computational construction of their context. If the face serves to identify and the trajectory serves to reconstruct, the relationship serves to interpret. When these three levels are merged, the system no longer merely records where a person is, but ends up producing an operational representation of what they are doing, who they meet and which events might warrant attention.

This distinction is also crucial from a computer forensics perspective. An integrated surveillance infrastructure can be broken down into at least seven functions: data acquisition; identity normalisation; biometric matching; spatio-temporal correlation; construction of the relational graph; risk classification; generation of alerts or reports. The presence of a menu item does not prove that every function is active, reliable or fed in real time. Confusing the interface, the designed capability, the data actually acquired and operational use produces a spectacular but flawed interpretation. Separating the levels, on the other hand, allows each piece of evidence to be given its correct probative weight.

In the case of Zhangjiakou, the qualitative leap lies not in the absolute quantity of records, but in their interrelatability – as if to say that a passport archive becomes administration; a stream of CCTV footage, surveillance; a list of journeys, mobility; and a register of healthcare visits, service. When such datasets are linked to a single identity, ordered chronologically and correlated with other individuals, they become patterns of life. It is this transformation—that is, from administrative data to an interpreted context—that generates value for the police, internal security and counter-intelligence.

The strategic threshold therefore does not coincide with the number of CCTV cameras installed or with the ability to locate someone at a single point in time. It coincides with the point at which the digital representation of the individual becomes sufficiently continuous to guide preventive decisions: who to monitor, which journey to flag, which meeting to investigate further, which source to approach, and which organisation to link to a network. Power no longer lies solely in seeing. It lies in transforming what is seen into operational priorities. It is here that surveillance becomes strategic infrastructure.

The Zhangjiakou case: what the dashboard reveals and what it does not

The Dynamic Control Platform for Overseas Personnel is said to have been developed for the Public Security Bureau in Zhangjiakou, in Hebei province, a city also known for having co-hosted the 2022 Winter Olympics. According to documentation gathered by NetAskari and reported in the international press, the system listed over 700 foreign residents and nearly 12,000 records in total. The categories included permanent residents, international students, citizens of Hong Kong and Taiwan, wanted individuals, people classified as key personnel and more than 300 foreign journalists, some of whom were not recorded as having visited Zhangjiakou.

The most significant finding is the presence of information that is difficult to attribute to a mere academic exercise: photographs purportedly from immigration procedures, passport numbers, telephone numbers, dates of birth, addresses, occupations and records relating to correspondents accredited in Beijing. The researcher also described login records apparently associated with police stations in Zhangjiakou and other cities. A subsequent investigation by the New York Times reported links between the platform and Origin Dynamic, a Beijing-based company active in supplying robotics, services and surveillance equipment to police forces through public procurement contracts. These elements increase the plausibility of an institutional link, but do not eliminate the limitations. NetAskari described the environment as a test system that was not connected, at the time of observation, to a real-time ecosystem. Several screenshots showed incomplete fields, placeholder images, poorly formatted output and identical values for all profiles. The underlying service appeared unstable and the platform was taken offline by May. There is no independent access to the server, no certified copies of the database, no complete contracts, no connector configurations and no statements from the competent authority.

The most rigorous conclusion is therefore qualified, and the existence of a publicly exposed interface, populated at least in part with authentic personal data, is confirmed. It is highly plausible that the project was designed for public security purposes and that individuals with access to government data contributed to its development. However, the actual level of use, the continuity of data flows over time, the reliability of the analytical modules and the nationwide deployment of equivalent platforms remain unproven. The distinction between these propositions marks the boundary between useful intelligence and over-interpretation.

Pattern-of-life and data fusion: when the ordinary becomes the subject ofintelligence

The information visible on the dashboard covered a wide range of everyday life: flights, train journeys with carriage and seat numbers, hotel stays, hospital visits, fuel purchases, places frequented, length of stay, and data recorded by CCTV cameras or facial recognition gates. The system also appeared capable of incorporating photographs from biometric passes at a ski resort. Taken in isolation, each piece of data may serve an administrative or commercial purpose. The transformation occurs when the same identity is recognised across different environments and each event is placed within a coherent timeline.

From a technical perspective, such an architecture requires at least entity resolution, the normalisation of names and documents, deduplication, geospatial correlation, the management of time windows, the association of events with individuals, as well as a logic to distinguish between chance presence, recurrence and anomalies. Facial recognition can act as a bridge between the physical world and the administrative database; the knowledge graph can link individuals, organisations, locations, modes of transport and events; anomaly detection can prioritise sequences deemed unusual. But each step introduces potential errors: homonyms, obsolete data, low-quality images, unsynchronised clocks, false matches, duplicates and relationships inferred from mere co-occurrences.

The intelligence value of the pattern-of-life therefore does not stem from a single sensor, but from the persistence of the correlation. A single visit to hospital tells us almost nothing; a series of visits, cross-referenced with movements, encounters, work and nationality, can become an indicator.

A train journey is ordinary; its proximity to a sensitive area or a monitored individual may trigger an alert. It is here that the infrastructure changes in nature: it does not merely record what has happened, but sets the context within which an operator will interpret what will happen next. In the transition from data to pattern, the capacity for anticipation is formed, but so too is the risk that weak correlations may be mistaken for intentions.

Journalists, students and foreign nationals: mobility as a sphere of counter-intelligence

The presence of an extensive database of foreign journalists is one of the most sensitive elements. According to the researcher, certain profiles could be flagged as trackable and linked to tracking or early-warning functions. The fact that many of the names were based in Beijing rather than Zhangjiakou suggests a purpose that goes beyond mere registration: to enable a local office to recognise the entry of an individual already classified elsewhere. In operational terms, the platform does not need to constantly monitor every journalist; it simply needs to alert the authorities when a person of interest enters a jurisdiction or appears near a sensitive location.

For investigative journalism, the most significant consequence concerns sources. A graph built on shared locations, universities, workplaces, nationalities and meetings can reveal individuals who were not initially targets. Monitoring relationships is often more effective than monitoring the reporter: it makes it possible to identify who speaks to them, who accompanies them, which driver they use, which facilities they visit and which people change their behaviour following contact. The chilling effect stems not only from the possibility of being stopped, but from the awareness that every interaction may pose a risk to local interlocutors.

The same principles apply to students, researchers, managers, technicians, consultants and diplomatic staff. Chinese legislation requires the registration of foreigners’ accommodation and structurally integrates hotels, universities and local authorities into the information cycle. Added to this are personalised transport services, digital payments, access controls and biometric systems. None of these elements, on its own, proves hostile activity. Taken together, however, they reduce the amount of genuinely anonymous movement and make it easier to link professional roles, affiliations and networks of contacts.

What is at stake for businesses and institutions is not merely the confidentiality of an individual trip, but rather the protection of the purpose that trip serves: negotiation, due diligence, research, consular assistance, journalistic reporting, audits, crisis management or technological development. If the system can reconstruct who meets whom, when and in what sequence, even a seemingly ordinary diary can reveal priorities, dependencies, key contacts and organisational vulnerabilities. Mobility thus becomes a field of counter-intelligence.

AI, facial recognition and risk scoring. Classification becomes operational power

The AI component must be handled with precision. It is plausible in biometric matching, similarity searches, entity resolution, event correlation, trajectory classification and graph construction. The interface displayed counts of facial detections, early warning and relationship mapping functions, and a risk indicator. However, the model used, the training data, the similarity thresholds, the false acceptance and false rejection rates, the metrics by demographic group, the deduplication logic, and the criteria by which an event was converted into an alert are not available.

 

The uniform value of 63 per cent observed across profiles suggests that at least that module was simulated or incomplete. To speak of ‘fully operational predictive AI’ would therefore go beyond the available evidence.

The strategic problem arises even before full automation. A system can generate operational power simply by sorting people into lists, making certain identities more visible and associating labels with nationality, profession, religion, location or relationships. If the biometric matching is incorrect, the error can propagate to the profile; if the profile is out of date, it can contaminate the alert; if co-occurrence is interpreted as a link, the graph can transform a coincidence into suspicion. China’s PIPL sets out principles of necessity, data minimisation, data quality, security and transparency inautomated decision-making, whilst assigning specific rules to state bodies for the exercise of their statutory functions. The case does not allow for the identification of a specific legal breach, but it highlights the tension between administrative rationality, national security and the verifiability of classification.

Procurement and the surveillance supply chain: the private supplier as a node of coercive sovereignty

Integrated surveillance is not produced by a single administrative body. It requires cameras, biometric readers, databases, identity management systems, analytical software, networks, cloud or data centres, maintenance, updates and integration with external sources. It is therefore also an industrial supply chain. Ministries and public security agencies define objectives and access rights; technology firms design interfaces, middleware, analytics modules and reporting tools; subcontractors manage components, hosting and support. Public authority is exercised through a technical-commercial ecosystem. A report in the New York Times highlighted links between the platform and Origin Dynamic, a Beijing-based company which, according to tender documents examined by the newspaper, supplies robotics, equipment and surveillance services to the police. This link reinforces the hypothesis that the project forms part of a genuine procurement process, but does not definitively clarify whether the company was the lead developer, an integrator, a component supplier or merely an associated party. To assign roles and responsibilities, contracts, tender specifications, code versions, delivery logs and acceptance test documentation would be required. Outsourcing creates a paradox: whilst it increases speed and capacity for innovation, it also expands the attack surface and fragments accountability. Each supplier adds accounts, credentials, APIs, test environments, copies of databases and staff with privileges. China’s own regulations on data security and the management of network data require state bodies to supervise entities responsible for building, managing or maintaining public systems and to protect government data. A publicly available dashboard shows that the problem is not merely how much the state can know, but how effectively it can safeguard what it knows.

On a geopolitical level, the supply chain matters because it makes surveillance replicable, purchasable and exportable. A model comprising standard modules – from facial recognition to smart policing, from knowledge graphs to early warning systems and reporting – can be adapted to cities, borders, major events or infrastructure. However, one cannot automatically infer from any single case either uniform nationwide deployment or the export of the same product. The well-founded conclusion is more limited: there exists a market and a technical language capable of transforming surveillance from an administrative practice into an industrialised platform.

Cybersecurity of surveillance: the paradox of the exposed system

The OSINT discovery stemmed from a basic yet strategically serious vulnerability: a sensitive interface was accessible via the public internet, with credentials that appeared to be pre-filled. The researcher was able to navigate functions, view personal data and download material before the service was taken down.

During the months of observation, the system exhibited instability and issues relating to the underlying Redis service. Even if one were to assume it was intended for demonstration purposes, the presence of authentic data makes this exposure a high-impact security incident. The concentration of biometric, health, travel, contact, residence and relationship data creates a target of exceptional value. A hostile actor gaining access to a similar platform could identify journalists, diplomats, researchers, wanted individuals, sources or police officers. They could also reconstruct investigative priorities, categories of interest and surveillance coverage. The breach does not merely affect the privacy of registered individuals: it can compromise operations, intelligence-gathering techniques and staff security.

Integrity is certainly as important as confidentiality. If an attacker were able to modify a profile, associate an incorrect photograph, alter a trajectory or insert a fabricated relationship, the system could generate false suspicions with operational consequences. In decision-making surveillance systems, data poisoning does not necessarily mean attacking a complex model; it can mean contaminating the database that feeds the operator. The more an authority relies on automated correlation, the greater the coercive value of manipulated data.

Resilience therefore requires environment segmentation, rigorous identity and access management, strong authentication, encryption, immutable logging, monitoring of privileged access, control of test copies, an inventory of connectors, vulnerability management and vendor oversight. Above all, however, it requires a governance rule: real data should not be transferred to demo or development environments without necessity, minimisation and traceability. The system described here shows that a platform built to reduce uncertainty for the state can, if poorly protected, increase uncertainty and risk for all parties involved.

Digital forensics and levels of evidence: from the interface to actual use

A comprehensive digital forensic assessment must distinguish between five levels. The first is the existence of the interface. The second is the authenticity of the data present. The third is the functioning of the modules and connectors. The fourth is actual use by identifiable operators. The fifth is organisational attribution: who commissioned, developed, administered and used the system. In the Zhangjiakou case, the first level is documented; the second is supported by strong indicators; however, the third and fourth remain only partially observable; the fifth is plausible but has not been definitively reconstructed.

To make further progress, we would need forensic snapshots of the server and the database, hashes of the copies, authentication logs, account history, network configurations, table schemas, the provenance of the records, API mapping, software versions, repositories or deployment packages, certificates, maintenance logs and contracts. For the AI modules, we would need the model, version, thresholds, validation datasets, inference logs and human review procedures. Without these artefacts, it is impossible to determine whether a screenshot reflects a real function, a mock-up, a pre-compiled output or a combination of the three. OSINT nevertheless retains decisive value. Domains, certificates, company registers, tender documents, patents, client-side code, metadata, shared assets, naming conventions and infrastructure can link otherwise separate pieces of information. However, the collection must be clearly reproducible: date and time, URL, method of acquisition, hash, contextualised screenshots, content preservation and annotation of limitations. The absence of a chain of custody does not negate the informational value, but it does reduce the ability to use the material as robust technical evidence. The correct framework is therefore that of confidence levels. ‘Documented’ for what is directly observable;

‘corroborated’ for what is independently verified; ‘plausible’ for inferences supported by the architecture; ‘unproven’ for national or ongoing operations. This framework does not weaken the analysis. It makes it usable by decision-makers, businesses, professional firms and institutions that need to distinguish real risk from narrative and transform the available evidence into a proportionate decision.

Italy, Europe and the Indo-Pacific: protecting people, data and relationships

This issue does not concern only those living permanently in China. It affects every Italian or European organisation that sends journalists, researchers, students, managers, technicians, consultants or institutional delegations. The European Council Recommendation on research security has already identified the unwanted transfer of knowledge, foreign interference and breaches of integrity as risks associated with international cooperation. This perspective must be extended to mobility; in other words, the security of research and business also depends on what data, relationships and priorities become visible during the journey.

The answer is not an indiscriminate closure off to China, nor the illusion of making every activity invisible. It is informed de-risking: minimising the data carried, separating what is necessary from what is sensitive, applying least privilege to accounts, setting up dedicated devices and profiles, protecting contact lists and the identities of sources, reducing the concentration of information, defining escalation channels and conducting a review upon return. For high-risk missions, travel security, cyber security, source protection and business continuity must form part of the same plan.

In terms of national interest, the issue is decision-making sovereignty. A country or a company loses ground not only when a secret is stolen, but when an external party can reconstruct its network, predict its moves, identify the most exposed nodes and apply targeted pressure. Europe must therefore keep trade, research and diplomacy open without confusing openness with a lack of protection. In the Indo-Pacific, the battle for information also hinges on the ability to understand others without revealing everything about oneself. This is where contextual knowledge becomes a strategic lever.

The real strategic threshold

For this reason, as of 3 August 2026, the real question is not whether the Chinese authorities collect data on foreigners. Entry, residence and mobility procedures have long made a significant amount of information available. The more serious question is another, and it is this: ‘When does the fusion of such data become sufficiently continuous, relational and automated to transform a person’s ordinary presence into a permanent operational profile?’. The strategic threshold does not coincide with the first facial recognition nor with the mere availability of a database, but with the ability to merge identities, trajectories, roles and relationships into a single information framework from which alerts, operational priorities and decisions are derived. Zhangjiakou brings this dynamic into sharp focus because it combines a medium-sized city, international tourism, Olympic infrastructure, foreigner registration, transport, accommodation facilities and biometric systems. It does not prove that every Chinese city has the same platform or that every function was active. However, it demonstrates how a local environment can become a laboratory for data fusion, and how data collected for different purposes can be recombined into a unified view of the individual. Thus, a passport is no longer merely a document, travel is no longer merely movement, and even an encounter is no longer merely a relationship. All become events that can be analysed.

The most rigorous conclusion is not that every foreigner in China is tracked in real time, nor that artificial intelligence makes surveillance infallible. The conclusion is more subtle: contemporary competition is transforming the ability to correlate people, places, times and relationships into an infrastructure of power. The advantage lies not merely in collecting more data, but in making it decision-grade before the adversary, the company, the journalist or the diplomat does. For Italy and Europe, the response cannot be limited to formal privacy considerations, but must combine strategic cyber threat intelligence, AI risk, the protection of individuals and a digital evidence strategy, so as to know what is documented, what is inferred, which relationships are exposed, and which decisions remain truly autonomous.

Primary, regulatory, institutional and strategic analysis sources

NetAskari. Tracking China’s Mass Surveillance Capabilities via Abandoned Online Dashboards. Original OSINT research published on 27 April 2026 and updated on 10 May 2026.

NetAskari. Sharp Eyes: Mass Surveillance of Foreigners in China – Part 1. Original OSINT research on the Dynamic Control Platform for Overseas Personnel, published on 19 May 2026.

NetAskari. Sharp Eyes: Mass Surveillance of Foreigners in China – Part 2. Technical and contextual analysis of the surveillance platform, published on 25 May 2026.

Kuo, Lily; Wu, Pei-Lin. “How China Keeps Tabs on Foreigners.” The New York Times, 2 August 2026.

Standing Committee of the National People’s Congress of the People’s Republic of China. Exit and Entry Administration Law of the People’s Republic of China. Adopted on 30 June 2012, entered into force on 1 July 2013.

National Immigration Administration of the People’s Republic of China. Announcement on the Pilot Implementation of Online Accommodation Registration for Foreigners Residing or Staying in Domiciles Other Than Hotels. Announcement No. 1 of 2026.

Standing Committee of the National People’s Congress of the People’s Republic of China. Personal Information Protection Law of the People’s Republic of China (PIPL). Adopted on 20 August 2021, entered into force on 1 November 2021.

Standing Committee of the National People’s Congress of the People’s Republic of China. Data Security Law of the People’s Republic of China. Adopted on 10 June 2021, entered into force on 1 September 2021.

State Council of the People’s Republic of China. Regulations on Network Data Security Management. State Council Decree No. 790, promulgated on 24 September 2024 and entered into force on 1 January 2025.

Foreign Correspondents’ Club of China. Media Freedoms Report 2025: The New Abnormal. Beijing, 2026.

Council of the European Union. Council Recommendation on Enhancing Research Security. Official Journal of the European Union, C/2024/3510, 30 May 2024.

European Commission, Directorate-General for Research and Innovation. Tackling R&I Foreign Interference. Commission Staff Working Document SWD(2022) 12 final, Brussels, 2022.

European Data Protection Board. Guidelines 05/2022 on the Use of Facial Recognition Technology in the Area of Law Enforcement. Version 2.0, 26 April 2023.

Wang, Maya. China’s Algorithms of Repression: Reverse Engineering a Xinjiang Police Mass Surveillance App. Human Rights Watch, New York, 2019.

Feldstein, Steven. The Global Expansion of AI Surveillance. Carnegie Endowment for International Peace, Washington, DC, 2019.

Cave, Danielle; Ryan, Fergus; Xu, Vicky Xiuzhong. Mapping More of China’s Tech Giants: AI and Surveillance. Australian Strategic Policy Institute, International Cyber Policy Centre, Canberra, 2019.

National Counterintelligence and Security Centre. Secure Innovation: Scenarios and Mitigations. Office of the Director of National Intelligence, Washington, DC, 2024.

National Counterintelligence and Security Centre. Safeguarding the Data of U.S. Financial Institutions: Navigating Threats from China. Office of the Director of National Intelligence, Washington, DC, 2026.

Bi Xiaohui, Hao Xuning, Liu Xiang, Wang Chenglong, Mo Mingjuan and Wang Baojie; Hisense TransTech Co., Ltd. Method and Device for Constructing an Integrated Profile of Key Personnel Based on a Knowledge Graph (Chinese patent application CN201911033306.6; publication CN111427968A), 2020.

Note: The opinion expressed in the articles are those of the respective authors and may not reflect the views of the Machiavelli Foundation.

SHARE:

Author of the article

Related content