A journalist found his own passport number

Hofer, a journalist, went looking through a police surveillance dashboard and found himself in it. The entry held a photograph taken by Chinese immigration officials at the border, a passport number and the mobile number used while in the country. It was not a leak in the ordinary sense, and nobody had to break anything to see it. The dashboard was reachable and unsecured.

The system had been built for the Public Security Bureau of Zhangjiakou, a city in Hebei province not far from Beijing. It is an unremarkable place to find a comprehensive foreigner-tracking platform, and that is precisely what makes it worth an hour of an operator's attention. Nothing about Zhangjiakou suggests it was chosen as a showcase.

What the dashboard actually held

The platform carried nearly 12,000 entries in total, covering fugitives, people from Hong Kong and Taiwan, more than 700 foreign residents of the city and more than 300 foreign journalists. Each person was categorised by nationality and carried a structured profile: date of birth, sex, marital status, address, occupation, and in some cases religion.

Attached to those profiles were sightings. Individuals appeared in camera captures at traffic intersections, in markets, in shopping centres and, in at least one instance, at a mosque. The distinction worth holding onto is between a list and a dossier. A list records that somebody is present. What this system produced was a continuously updated pattern of life, assembled from identity documents and public cameras and joined into a single view of a named person.

The vendor is the finding, not the city

One city running an unusually thorough system would be a curiosity. The reporting traced links between the platform and Origin Dynamic, a Beijing company that supplies robotics, surveillance services and equipment to police forces. The same company filed a patent application in 2023 covering a comparable system, described as an information interface for non-Chinese citizens.

Read those two facts together and the shape of the thing changes. A patent application is what a supplier files when it intends to sell something repeatedly and wants the design protected while it does so. This is a productised capability with a named vendor and intellectual property behind it, which means the sensible planning assumption is not that Zhangjiakou is unusual. It is that Zhangjiakou is an installation, and installations have siblings.

Two risks, and most policies name only one

Every competent travel and posting policy already assumes state collection. Firms brief staff on clean devices, on what to carry, on what to say, and they price the assumption that a foreign authority may hold a record. That risk is old, understood and largely managed. It is not what is new here.

The new risk is the access control, or rather its absence. An aggregated dossier on your employee, sitting in a system that anyone able to find it could read, is exposed to a much wider set of parties than the authority that built it: ordinary criminals, commercial data brokers, and anyone running a competitive intelligence operation against your firm. A profile combining passport number, home address, employer, movements and religion is exactly the raw material for targeted fraud, coercion or an impersonation attempt against your finance function. The state was the intended reader. The security failure means it was not the only possible one.

Three changes worth making this quarter

Brief the people affected, and brief them accurately. Staff posted to or travelling in China should be told that a structured profile is being assembled, that it will include immigration photography and movement data, and that on the evidence of this case it may not be securely held. That last clause is the part that changes behaviour, because it converts an abstract political risk into an ordinary data-exposure risk that people already know how to think about.

Then reduce what you add to the pile. Hold the minimum personal data on assignees in your local entity that local law requires, and stop volunteering more. Finally, make the record honest: if employee personal data can foreseeably enter a foreign state system, that belongs in your processing register and in your transfer risk assessment, not in an unwritten assumption. European employers carry obligations to their staff about what happens to their personal data, and a documented assessment is worth more than an informal understanding when somebody eventually asks.