• About Us
  • People
    • Matthew Murphy
    • Ellen Wang
    • Yu Du
    • Xia Yu
    • Sarah Xuan
  • Practice Areas
    • Intellectual Property
    • Technology
    • Corporate
    • International Trade
    • International Arbitration
  • Insights
  • Accolades
  • Locations
  • Contact Us
  • 中文

China: Key Institutional Provisions and Observations on the Provisions on Personal Information Protection by Large Personal Information Processors (Draft for Comment)

Published 19 August 2026 Sarah Xuan
On August 7, 2026, the Cyberspace Administration of China (CAC) issued the Provisions on Personal Information Protection by Large Personal Information Processors (Draft for Comments) (the “Draft Provisions”) for public comment, with comments due by September 7, 2026 . The Draft Provisions comprise six chapters and fifty articles and are accompanied by the Guidelines for Formulating the Working Rules of the Personal Information Protection Supervisory Committee. According to the explanation released by the CAC, the Draft Provisions are intended to regulate the personal information processing activities of large personal information processors and are formulated pursuant to laws and administrative regulations including the Personal Information Protection Law of the People’s Republic of China (the “PIPL”) and the Regulations on Network Data Security Management.
From the perspective of their position within the legal framework, the Draft Provisions may be regarded as further implementing rules for the PIPL and the Regulations on Network Data Security Management in the context of large personal information processors. In addition, the Draft Provisions are systematically connected with the Provisions on Simplified Measures for Personal Information Protection by Small Personal Information Processors (the “Provisions for Small Processors”), which were promulgated one month earlier. The successive introduction of these two sets of rules indicates that China’s personal information protection regime is developing a clearer framework of tiered and classified regulation. For entities with a relatively small scale of processing and comparatively simple business operations, the regulatory rules emphasize proportionality to their scale and capabilities and reduce unnecessary compliance burdens through simplified procedures. For entities capable of processing personal information on a large scale and potentially producing systemic effects, the requirements concerning governance, auditing, transparency, and supervision are further enhanced. Accordingly, the uniform baseline obligations established by the PIPL are increasingly being calibrated to the scale of processing, complexity of business operations, and potential risks, thereby forming a more proportionate regulatory structure.
I. Identification of Large Personal Information Processors
For the identification of a “large personal information processor,” the Draft Provisions do not establish an absolute threshold based solely on the number of users or the quantity of personal information processed. Instead, they establish a comprehensive identification mechanism combining quantitative scale, business importance, and social impact.
Under Article 2, the identification of a large personal information processor should comprehensively take into account three conditions: first, the processing of personal information of more than 10 million natural persons; second, the provision of important network services involving personal information processing, or the operation of multiple lines of business involving personal information processing; and third, the personal information processing activities having a significant impact on national security, economic operations, social stability, public health and safety, or other such matters. A processor that processes the personal information of more than 10 million persons and, following a self-assessment, considers that it also satisfies the latter two conditions must apply for identification to the national cyberspace administration through the provincial-level cyberspace administration where it is located. The national cyberspace administration will ultimately, together with the competent telecommunications authority, public security authorities, and other departments performing personal information protection duties, study and determine the list of large personal information processors and announce it to the public. This approach stands in marked contrast to the identification method under the Provisions for Small Processors. The latter use “fewer than 100,000 persons” as the basic quantitative standard, with an emphasis on identifiability and institutional convenience, whereas the Draft Provisions add the factors of important services and social impact to the threshold of 10 million persons, reflecting a regulatory approach aimed at the precise identification of high-risk entities.
If the Draft Provisions are ultimately implemented under the current framework, China’s personal information protection regulation will in effect form three relatively clear tiers: small processors will be subject to simplified rules; ordinary processors will continue to be subject to the general regime under the PIPL, the Regulations on Network Data Security Management, and other applicable rules; and large personal information processors will be subject to further enhanced governance requirements in addition to the general obligations.
II. Basic Rules for Personal Information Processing by Large Personal Information Processors
With respect to specific processing rules, the Draft Provisions significantly raise the transparency requirements applicable to large personal information processors. Article 10 provides that large personal information processors must use clear and readily understandable language to truthfully, accurately, and completely list, item by item, matters relating to personal information processing. In particular, the purposes, methods, and categories of personal information collected and used for each function or service, the names and frequency of permissions invoked, and the necessity of processing sensitive personal information and its impact on personal rights and interests must all be disclosed through a structured list. For embedded software development kits (SDKs), the processor must also disclose the name, package name, version, principal functions, operator, categories of personal information collected and used, and the means of accessing the complete personal information processing rules. Where personal information is provided to another personal information processor, the recipient, contact details, processing purposes and methods, and categories of information must also be disclosed.
The significance of this requirement lies in its movement of personal information processing rules from principle-based and generalized privacy policies toward verifiable data-processing inventories. Traditional privacy policies often describe data-processing activities in lengthy natural-language texts, making it difficult for users to determine directly what permissions a particular function actually requires, what data it collects, and how frequently permissions are invoked. By requiring structured disclosure on a function-by-function basis, the Draft Provisions facilitate a corresponding relationship among “function—data—permission—purpose—third party,” and also enable regulatory authorities and compliance audit institutions to verify more effectively whether personal information processing activities comply with the principle of minimum necessity.
III. Requirements for Local Data Storage and Data Center Governance
Articles 13 through 16 of the Draft Provisions set out relatively systematic requirements for the data storage arrangements of large personal information processors. These provisions are also among the more noteworthy aspects of the present institutional design.
Article 13 expressly requires large personal information processors to store within China the personal information collected and generated in the course of operations within the territory of the People’s Republic of China. Article 14 further requires that the relevant data centers be established within China, that the legal representative or actual controller of the data center management entity be a Chinese national, and that applicable national policy and standards requirements be satisfied. Where a third-party data center management entity is entrusted with processing personal information, the large personal information processor must also enter into a written contract with that entity specifying the processing purpose, duration, method, storage location, scale, categories, security measures, and the rights and obligations of both parties.
Of particular note, the object of regulation here extends beyond whether personal information “may be transferred abroad” to the data centers that host the data and the entities that manage those centers. Existing rules on cross-border data transfers primarily focus on outbound-transfer mechanisms such as security assessments, standard contracts, and personal information protection certification. By contrast, the Draft Provisions establish stronger baseline requirements for local data storage by large personal information processors and further prescribe qualification conditions and security responsibilities for data centers. At the same time, the Draft Provisions do not entirely close off the cross-border flow of personal information. Article 20 continues to permit large personal information processors to provide personal information to recipients outside China where required for business purposes, provided that they lawfully complete the procedures for outbound data transfer security assessments, standard contracts, or personal information protection certification in accordance with relevant national provisions and assess the management and technical measures adopted by the overseas recipient. If the overseas recipient is found to be unable to perform the relevant personal information protection obligations, the provision of personal information to that recipient must be suspended.
IV. Regulation of Automated Decision-Making
The Draft Provisions also address automated decision-making in a manner that is highly responsive to practical concerns. Article 17 provides that where a large personal information processor uses automated decision-making to push information or conduct commercial marketing to individuals, it must provide an option to disable personalized recommendations that is easy to understand, access, and operate. Once a user disables personalized recommendations, the processor must cease using the relevant personal information for personalized recommendation purposes. It must also provide users with functions enabling them to delete user tags generated on the basis of their personal characteristics, among other functions.
Compared with the principles established by the PIPL concerning transparency and fairness in automated decision-making and the right to refuse information pushes based on personal characteristics, this provision moves regulation further into the underlying mechanisms of automated decision-making systems. This development is significant. The risks arising from algorithmic recommendations do not ordinarily arise only from the final recommendation results; upstream data aggregation, feature extraction, and user profiling may themselves continuously affect the information environment experienced by individuals on a platform. By allowing users to delete tags generated on the basis of their personal characteristics, the Draft Provisions extend individual rights further upstream in the algorithmic decision-making chain.
Relatedly, Article 18 addresses risks arising from data aggregation and integration. If, after aggregation or integration, personal information meets the criteria for sensitive personal information under Article 28 of the PIPL, it must be identified and protected as sensitive personal information even if the underlying data, taken separately, may not each constitute sensitive personal information. This provision reflects a shift in data-protection risk assessment from static identification by data type toward an assessment based on processing results and inferential capability. In a big-data analytics environment, the combination of multiple items of ordinary data may readily reveal health, financial, location, identity, or other highly sensitive information. Reassessing the sensitivity of integrated data more closely reflects the actual risk structure of modern data analytics technologies.
V. Personal Information Protection Officer Must Be a Member of Management
The Draft Provisions significantly strengthen the internal governance structure of large personal information processors. Article 25 requires a large personal information processor to designate a member of management to serve as the personal information protection officer and to publicly disclose that person’s contact information. Article 26 further provides that the personal information protection officer is responsible not only for traditional compliance matters such as establishing systems, conducting risk assessments, compliance audits and impact assessments, and providing education and training, but must also participate in decisions relating to personal information processing and promptly provide opinions on decisions presenting security risks. Of particular note, where a large personal information processor, without legitimate grounds, fails to address the compliance opinion of the personal information protection officer, or where the outcome of its handling violates laws, regulations, or relevant national provisions, the personal information protection officer may report directly to the provincial-level cyberspace administration where the processor is located. This institutional arrangement significantly elevates the organizational status of the personal information protection officer. The role extends beyond that of a conventional privacy liaison or internal compliance implementation officer and more closely resembles a senior compliance officer with a degree of independent supervisory authority.
At the same time, Article 27 requires each business department to assign personnel with personal information protection compliance audit capabilities to be responsible for personal information protection work within that department and to operate under the guidance of the personal information protection officer. This creates a vertical organizational structure extending from the management-level officer to compliance personnel within individual business departments.
VI. An Independent Personal Information Protection Supervisory Committee as a Core Institutional Innovation
While the personal information protection officer mechanism strengthens professional supervision within the enterprise, the personal information protection supervisory committee further introduces an external and independent supervisory mechanism. Under Article 37, a large personal information processor must establish a personal information protection supervisory committee within six months after being identified as such. The committee must have an odd number of members and no fewer than seven members in total; external members must account for at least two-thirds of the membership; the chair of the committee must be an external member; and the chair must possess the capabilities required of a senior personal information protection compliance auditor.
The Draft Provisions also impose stringent requirements regarding the professional competence and independence of external members. For example, external members must have at least three years of relevant work experience and may not concurrently be engaged by more than three large personal information processors. Persons who have worked for the enterprise within the preceding year, shareholders holding specified ownership percentages and their close relatives, and certain persons employed by major shareholder entities and their close relatives are all subject to restrictions on appointment. External members must also conduct an annual self-assessment of their independence, while the enterprise’s board of directors or other decision-making body must evaluate their independence and disclose the relevant information in the social responsibility report on personal information protection.
In addition, under the Draft Provisions, the supervisory committee’s scope of supervision covers core areas including the enterprise’s personal information protection system, platform rules, protection of sensitive personal information and minors’ personal information, impact assessments, compliance audits, risk assessments, personal information security incidents, outbound data transfers, automated decision-making, requests concerning individual rights, and the performance of duties by the personal information protection officer. The accompanying Guidelines for Formulating the Working Rules of the Personal Information Protection Supervisory Committee further provide that the supervisory committee must hold a regular meeting at least once every six months and that, where evidence exists of unlawful personal information processing, an extraordinary meeting may be convened upon the proposal of at least one-third of the members. Resolutions adopted by the committee must be submitted to the enterprise’s board of directors or other decision-making body for handling. Where compliance opinions are not addressed without legitimate grounds, or where the result of the handling violates laws or regulations, the supervisory committee may report the matter to the provincial-level cyberspace administration where the enterprise is located.
This mechanism is one of the institutional innovations in the Draft Provisions with the strongest corporate-governance character. It embeds, alongside the enterprise’s traditional governance structure, a personal information protection body composed primarily of external professionals and equipped with independent supervisory functions and a channel for reporting to regulators. This creates an interconnected governance structure comprising the “management-level officer—business-department compliance personnel—independent supervisory committee.” For large enterprises whose personal information processing has significant public impact, personal information protection is thereby elevated from a matter of legal compliance alone to an issue of corporate governance.
VII. Impact Assessments, Compliance Audits, and Risk Assessments Form an Ongoing Supervisory Mechanism
The Draft Provisions further increase the rigor of personal information protection impact assessments and compliance audits. Article 31 provides that before launching products, services, or functions involving automated decision-making, the processing of sensitive personal information, or other activities that may have a significant impact on personal rights and interests, a large personal information processor must conduct a personal information protection impact assessment in advance and, within fifteen working days after completing the assessment, submit the assessment report for record-filing with the national cyberspace administration through the provincial-level cyberspace administration where it is located. The assessment must cover not only whether the processing purpose and method are lawful, legitimate, and necessary, as well as the relevant risks and protective measures, but must also specifically examine whether the frequency of permission calls and data precision are limited to the minimum frequency and minimum scope, and the measures adopted by automated decision-making mechanisms to avoid precise targeting of specific individuals and the effectiveness of those measures. At the same time, Article 33 requires large personal information processors to conduct a personal information protection compliance audit at least once every two years and to conduct an annual risk assessment of personal information processing activities. Article 32 further requires an annual special compliance audit concerning minors’ personal information.
This means that, for high-risk processing activities of large personal information processors, personal information protection impact assessments will no longer remain entirely as internal corporate records but will begin to carry a regulatory record-filing function. Regulatory authorities will thus be able to obtain information about personal information risks in major products and processing mechanisms of large enterprises at an earlier stage.
By comparison, the Provisions for Small Processors permit small personal information processors to conduct a personal information protection compliance audit at least once every five years using a simplified self-inspection form and to conduct personal information protection impact assessments using a simplified impact-assessment form. Small processors that have obtained personal information protection certification may even be exempt from conducting personal information protection compliance audits during the validity period of the certification. The differences between the two regimes clearly reflect the principle of proportionate regulation: for small entities, the regulatory objective is to prevent procedural obligations from exceeding their actual risks and governance capabilities; for large entities, ongoing supervision is created through more frequent risk assessments, periodic audits, and record-filing of important matters.
VIII. Platform Governance Obligations and the Simplified Mechanism for Small Processors Form an Institutional Linkage
Another particularly noteworthy institutional connection between the Draft Provisions and the Provisions for Small Processors is the intermediary governance role of online platforms within the tiered personal information protection framework.
Article 8 of the Provisions for Small Processors provides that where a small personal information processor conducts personal information processing activities solely through an online platform, does not provide personal information to processors outside the platform, and the online platform has already formulated personal information processing rules for the relevant activities and clarified the rights and obligations of both parties, the small processor may, if it declares that it will comply with those rules and its processing activities do not exceed their scope, refrain from separately formulating personal information processing rules and from repeatedly performing the corresponding notification obligations. If compliance audits and personal information protection impact assessments already conducted by the platform cover the relevant processing activities of the small processor, the small processor may also be exempt from duplicating such work. Correspondingly, Article 29 of the Draft Provisions requires a large personal information processor that provides online platform services to specify the rules, permissions, and protection obligations applicable to personal information processing by providers of products or services on the platform, urge such providers to establish internal personal information protection management systems and process personal information in accordance with law, and, upon discovering serious unlawful personal information processing by a provider of products or services on the platform, immediately take measures such as suspending the provision of services and report the matter to the relevant regulatory authorities.
Viewed together, these two regimes reveal a regulatory arrangement of considerable systemic significance: platform governance capabilities are being incorporated into the allocation of regulatory resources for personal information protection. Subject to prescribed conditions, small operators may rely on platform rules, impact assessments, and compliance audits to reduce duplicative compliance costs, while large platforms correspondingly assume governance responsibilities for rule-setting, permission configuration, compliance supervision, and the handling of serious unlawful conduct. Accordingly, the partial procedural relief afforded to small processors does not mean that the corresponding personal information processing risks leave the regulatory framework; rather, under certain conditions, compliance capabilities are centrally allocated through platform governance. This arrangement can reduce duplicative compliance costs for a large number of small operators while requiring platforms with technological capabilities, organizational capabilities, and economies of scale to assume responsibilities commensurate with their governance capabilities. It is also one of the areas in which the two sets of provisions display the strongest institutional synergy.
IX. Further Refinement of Mechanisms for the Exercise of Individual Rights
The Draft Provisions also substantially refine the mechanisms for exercising personal information rights. Taking the right to transfer personal information as an example, Article 19 provides that, for requests satisfying the relevant conditions under the Regulations on Network Data Security Management, a large personal information processor should, in principle, complete the transfer of personal information in a commonly used or machine-readable format within thirty working days after completing identity and request verification. Where an extension is genuinely necessary due to the number of requests, operational complexity, or similar reasons, the period may be extended by an additional thirty working days within a reasonable and necessary scope. The Draft Provisions also support the provision of transfer channels through application programming interfaces or other standardized technical means. With respect to the right to deletion, where an individual requests deletion of personal information and the enterprise has legitimate grounds for being unable to delete it, the enterprise must respond within fifteen working days. For complaints and reports concerning personal information, any processing period committed to by the large personal information processor may not exceed fifteen working days; where no period has been committed to, the same fifteen-working-day limit applies.
These provisions further translate the principle-based rights under the PIPL into operational obligations with specific time limits and technical requirements. Whether personal information rights can be effectively realized depends to a significant extent on whether enterprises have established corresponding systems for data retrieval, identity verification, export, deletion, and complaint handling. Through time-bound and standardized requirements, the Draft Provisions further embed rights protection into enterprises’ information systems and business processes.
X. Protection of Minors’ Personal Information Becomes a Distinct Dimension of Governance
The protection of minors’ personal information is also further strengthened under the Draft Provisions. Large personal information processors must designate dedicated personnel responsible for protecting minors’ personal information and may identify minors through means such as the national public service for online identity authentication. Special personal information processing rules must be formulated for minors under the age of fourteen, while targeted personal information protection measures must be adopted for minors who have reached the age of fourteen but are under the age of eighteen. At the same time, in accordance with the Regulations on the Protection of Minors in Cyberspace, an annual compliance audit concerning the protection of minors’ personal information must be conducted.
Notably, while continuing the special protection mechanism for the personal information of children under the age of fourteen, the Draft Provisions expressly bring minors aged fourteen to under eighteen within a dedicated protection framework. This creates a more refined age-based differentiation in the protection of minors’ personal information and requires large personal information processors to take into account the cognitive abilities and risks to rights and interests associated with different age groups in product design, permission controls, and data-processing mechanisms.
XI. Shift from “Large Online Platforms” to “Large Personal Information Processors”
Another important change in the Draft Provisions concerns the subject of regulation itself. The CAC has expressly stated that the present document was formed by integrating and improving the earlier Provisions on the Establishment of Personal Information Protection Supervisory Committees by Large Online Platforms (Draft for Comments) and the Provisions on Personal Information Protection by Large Online Platforms (Draft for Comments). The title of the final draft for comments was changed from “large online platforms” to “large personal information processors.”
As digitalization continues to deepen, entities capable of processing personal information on a large scale and producing systemic effects are not necessarily all internet platforms in the traditional sense. Entities in finance, healthcare, transportation, telecommunications, and other highly digitalized industries may likewise possess vast personal information databases and sophisticated data-processing capabilities. By making “large personal information processors” the subject of regulation, the regime can focus more directly on the actual scale of data processing, complexity of business operations, and public impact, avoiding excessive dependence of the regulatory scope on an enterprise’s business model or whether it possesses platform characteristics. This institutional adjustment reflects the gradual shift of China’s personal information protection regulation from regulation of particular business models toward functional regulation based on data-processing risks.
XII. Rules for Large and Small Processors Jointly Reflect Proportionate Regulation in the Field of Personal Information Protection
When the Draft Provisions are considered together with the Provisions for Small Processors, their institutional value becomes clearer. The Provisions for Small Processors allow small entities to use simplified personal information processing rules and impact-assessment tools, conduct compliance audits at least once every five years, and, in specified circumstances, rely on industrial parks, property management entities, or online platforms to centrally perform certain obligations. They also expressly provide that, where unlawful conduct is minor, is promptly corrected, and causes no harmful consequences, no penalty shall be imposed in accordance with law, and that lighter or mitigated penalties shall be imposed in accordance with law in certain circumstances. The Draft Provisions, by contrast, require large entities to establish comprehensive internal management systems, appoint a management-level personal information protection officer and professional personnel within business departments, conduct compliance audits at least once every two years and annual risk assessments, conduct and file impact assessments before launching certain high-risk products, establish an independent supervisory committee composed primarily of external members, and disclose governance information to the public through annual social responsibility reports. Taken together, the two regimes indicate that the intensity of compliance requirements under China’s personal information protection regulation is being aligned with the scale of personal information processing, the complexity of processing activities, and the potential risks to rights and interests and to the public.This tiered system does not lower the substantive protection standards established by the PIPL. Lawfulness, legitimacy, necessity, good faith, minimum necessity, security safeguards, and respect for individual rights remain baseline requirements common to all processors. What changes principally are the organizational structures, procedural intensity, audit frequency, and supervisory methods required to achieve those objectives. Personal information protection is thus beginning to develop from a uniform-obligation model into a regulatory system of “common substantive baselines + differentiated governance mechanisms.”
Conclusion
Through mechanisms including the identification of large processors, a management-level personal information protection officer, a responsibility system within business departments, a personal information protection supervisory committee, periodic audits, risk assessments, record-filing of impact assessments, and social responsibility reports, the Provisions on Personal Information Protection by Large Personal Information Processors (Draft for Comments) embed personal information protection into the business decision-making and corporate governance structures of large enterprises.
Of particular note, the Draft Provisions and the Provisions on Simplified Measures for Personal Information Protection by Small Personal Information Processors promulgated in July 2026 form a relatively complete institutional correspondence in terms of regulatory direction. The rules for small processors reduce institutional costs for small and medium-sized enterprises and micro-enterprises through simplified procedures and shared compliance capabilities, while the rules for large processors raise governance and supervision requirements in light of the systemic risks that may arise from large-scale data processing. Together, they advance China’s personal information protection regulation from relatively uniform application of rules toward a tiered and classified system calibrated to scale, capability, and risk.
The Draft Provisions are, of course, still at the stage of public consultation and may be adjusted before their formal promulgation. From the perspective of the overall regulatory direction, however, their issuance already sends a clear signal: China’s personal information protection regime is entering a more refined stage of implementation. Regulatory attention is shifting from “whether an enterprise has established personal information protection rules” toward “whether the enterprise has established a data-governance mechanism commensurate with its scale and risks, capable of continuous operation, and subject to external supervision.” This will also become one of the most significant institutional developments for large enterprises in building their future personal information compliance systems.


© 2026 - All rights reserved.

We use cookies to enable essential functionality on our website, and analyze website traffic. By clicking Accept you consent to our use of cookies. Cookies and Privacy Policy.

Your Cookie Settings

We use cookies to enable essential functionality on our website and analyze website traffic. For more information, read our Cookies and Privacy Policy below..

Cookie Categories
Essential

These cookies are strictly necessary to provide you with services available through our websites.

Analytics

These cookies collect information that is used in aggregate and in an anonymized form to help us understand how our website is being used and how effectively our site is performing.