China’s Simplified Measures for Personal Information Protection by Small-scale Personal Information Processors
Published 13 August 2026
Sarah Xuan
On July 22, 2026, the Cyberspace Administration of China and the Ministry of Public Security jointly promulgated, by Order No. 25, the Provisions on Simplified Measures for Personal Information Protection by Small-scale Personal Information Processors (the “Provisions”), which will take effect on September 1, 2026. The Provisions establish, for business entities that process personal information on a relatively small scale, a mechanism for fulfilling personal information protection obligations that is commensurate with their business scale, processing capabilities, and level of risk.
Since the Personal Information Protection Law of the People’s Republic of China (the “Personal Information Protection Law”) came into force, China has developed a personal information protection framework founded on the Personal Information Protection Law, supplemented by administrative regulations such as the Regulations on Network Data Security Management, and further refined by sector-specific departmental rules concerning matters such as cross-border transfers of personal information, compliance audits, and facial recognition. However, personal information processors differ substantially in scale, processing capabilities, and risk levels. If all entities were required to implement personal information processing rules, impact assessments, audits, and internal management requirements through similar institutional structures and at comparable compliance costs, the compliance investment required of small-scale business entities could become disproportionate to the actual risks involved. The Provisions constitute a specific implementation of Article 62 of the Personal Information Protection Law, which provides that “the national cyberspace administration shall coordinate with relevant departments to formulate specialized personal information protection rules and standards for small-scale personal information processors, sensitive personal information, and new technologies and applications such as facial recognition and artificial intelligence.”
The following provides an interpretation and commentary on the principal provisions of the Provisions.
I. Defining Small-scale Personal Information Processors by the Criterion of “Processing Personal Information of Fewer Than 100,000 Individuals”
Article 2 of the Provisions first makes clear that the Provisions apply to small-scale personal information processors within the territory of the People’s Republic of China, and defines a “small-scale personal information processor” as “a personal information processor that processes personal information of fewer than 100,000 individuals.” Rather than relying on an enterprise’s registered capital, operating revenue, number of employees, or enterprise size under the Standards for Classification of Small and Medium-sized Enterprises, the provision directly uses the scale of personal information processing as the core criterion. Accordingly, a “small-scale personal information processor” is not necessarily synonymous with a “micro or small enterprise” in the traditional sense. An internet company with few employees and relatively low operating revenue may fall outside the scope of the Provisions if it processes personal information of more than 100,000 individuals; conversely, an offline enterprise of a certain business scale may fall within the scope of the Provisions if the personal information it actually processes consistently relates to fewer than 100,000 individuals. The official interpretation further clarifies that the “100,000 individuals” threshold is calculated based on the current cumulative number of natural persons whose personal information has been processed, excluding personal information that has already been deleted.
This design effectively establishes a tiered mechanism for regulated entities based on the scale of data processing. China has previously used quantitative thresholds such as one million and ten million individuals in instruments including the Regulations on Network Data Security Management and the Measures for the Administration of Personal Information Protection Compliance Audits to impose more stringent organizational and audit obligations. The Provisions now establish a dedicated rule at the lower threshold of “fewer than 100,000 individuals,” making the scale of personal information processing an increasingly important quantitative parameter for determining regulatory obligations.
II. Simplifying Personal Information Processing Rules and Notification Mechanisms
Article 17 of the Personal Information Protection Law establishes a prior notification obligation for personal information processors, with the aim of safeguarding individuals’ right to be informed about information processing activities and ensuring transparency in processing. In view of the relatively simple business models and limited processing scale of small-scale personal information processors, Article 4 of the Provisions simplifies the required content and methods of publication of personal information processing rules. It requires disclosure primarily of core matters such as the processor’s identity, channels for accepting requests concerning individual rights, and the purposes, methods, categories, and retention periods of processing. It also permits disclosure through notices at business premises, service agreements, pop-up notices in client applications, website notices, or other methods depending on whether the business is conducted online or offline.
This arrangement does not alter the notification obligation established by the Personal Information Protection Law; rather, it makes a proportionate adjustment to the manner in which that obligation is fulfilled. The principal institutional objective is to ensure that individuals can effectively obtain information closely related to their rights and interests, while reducing formalistic compliance costs for small-scale entities whose processing activities are relatively simple and whose risks do not warrant such burdens. It reflects the Provisions’ differentiated regulatory approach while maintaining the standard of protection for individual rights and interests.
Article 5 of the Provisions further allows service and management entities for industrial parks, industrial bases, commercial properties, and similar premises to formulate and publish unified personal information processing rules for small-scale personal information processors engaged in the same offline business within their management scope. By consolidating certain repetitive compliance work, this arrangement helps reduce the institutional development costs of similar small-scale business entities and improves the standardization of rulemaking.
It should be noted that the unified formulation of personal information processing rules concerns only the manner in which compliance obligations are fulfilled and does not alter the allocation of responsibility for personal information processing. The relevant business operators remain legally responsible for their actual processing activities. If their processing purposes, methods, or categories of personal information exceed the scope covered by the unified rules, they must still fulfill the corresponding legal obligations with respect to the excess. Accordingly, the effectiveness of this mechanism depends on whether the unified rules remain consistent with the actual personal information processing activities of each business entity.
III. Simplifying Notification and the Processing Mechanism for Information Proactively Provided by Individuals While Maintaining High Standards of Protection for Sensitive Personal Information
Article 6 of the Provisions further simplifies the method of notification in specified circumstances. For non-sensitive personal information necessary for the provision of products or services, where such information is neither provided to other personal information processors nor disclosed publicly, and the relevant processing has been expressly stated in the personal information processing rules, a small-scale personal information processor may fulfill its notification obligation by publishing those rules, provided that the rules are prominently brought to individuals’ attention and are readily accessible for review and retention. By replacing repetitive individualized notifications with a unified public notice where the prescribed conditions are met, this arrangement protects individuals’ right to be informed while reducing the procedural compliance costs associated with low-risk processing activities.
On this basis, Article 7 of the Provisions further provides that, where an individual, with full knowledge, voluntarily and proactively provides, or cooperates in providing, personal information necessary to obtain products or services, a small-scale personal information processor may process such information in accordance with its published personal information processing rules. This provision creates a more direct institutional connection between the common transactional act of an individual proactively providing information and the personal information processing rules, and further reflects the Provisions’ approach of adjusting the manner in which obligations are fulfilled according to the level of risk associated with the processing activity.
However, the foregoing simplifications do not apply to sensitive personal information. The Provisions make clear that where sensitive personal information is processed for a specific purpose, the processor must still inform the individual of the necessity of processing the sensitive personal information and the impact on the individual’s rights and interests, and must obtain the individual’s separate consent in accordance with law. Notably, compared with the earlier draft for public comment, the final text deletes provisions that would have permitted a comparatively simplified processing mechanism where individuals proactively cooperated in providing sensitive personal information such as facial information or biological samples, thereby maintaining the higher standard of protection established by the Personal Information Protection Law for sensitive personal information.
Accordingly, Articles 6 and 7 establish a relatively clear risk-based hierarchy. For ordinary personal information processing activities with clear purposes, limited scope, and relatively low risk, notification and processing procedures may be appropriately simplified. Where sensitive personal information is involved, core safeguards such as notification of necessity and separate consent continue to apply. This also demonstrates that the regulatory burden reduction provided by the Provisions for small-scale personal information processors is focused primarily on procedures and methods of performance and does not reduce the substantive protection requirements applicable to high-risk personal information processing activities.
IV. Establishing a “Compliance Sharing” Mechanism in Platform-based Scenarios
Article 8 of the Provisions is one of the more innovative provisions in the overall framework. It establishes a relatively clear compliance-sharing mechanism for small-scale personal information processors that conduct business through online platforms. Where a small-scale personal information processor conducts personal information processing activities solely through an online platform, does not provide information to other personal information processors outside the platform, and the platform has formulated rules for the relevant processing activities and clearly defined the rights and obligations of both parties, the small-scale personal information processor may, after declaring that it will comply with the platform rules and provided that its processing activities are limited to what is necessary for providing products or services, refrain from separately formulating personal information processing rules and from independently fulfilling the corresponding notification obligations.
With respect to compliance audits and personal information protection impact assessments, the Provisions further allow audit and assessment results already produced by the platform to cover small-scale business operators on the platform. So long as the relevant audits and assessments have in fact covered the personal information processing activities conducted by the small-scale personal information processor through the platform, the processor may be exempted from repeating the same work. By reducing highly duplicative compliance procedures between platforms and business operators, this mechanism improves the efficiency with which personal information protection obligations are fulfilled within platform ecosystems.
This institutional arrangement strengthens the organizational and supporting role of online platforms in personal information protection governance. Subject to the prescribed conditions, personal information processing rules, compliance audits, and impact assessments formulated or conducted by a platform may serve as a common basis for small-scale business operators on the platform to fulfill the relevant obligations, thereby enabling a degree of shared compliance resources. Such sharing, however, is subject to strict limitations as to business scope and is premised on the operator’s actual processing activities remaining within the scope covered by the platform rules and the relevant audits and assessments. If the actual processing purposes, methods, or categories of personal information of a small-scale personal information processor exceed the scope covered by the platform rules, the processor must independently fulfill, in accordance with law, the obligations to formulate personal information processing rules, provide notification, conduct compliance audits, and carry out personal information protection impact assessments with respect to the excess. Where platform rules are adjusted, the platform must also promptly notify the relevant business operators. Accordingly, Article 8 provides relief from duplicative compliance under specified conditions, without altering the fundamental principle that business operators remain responsible for their own personal information processing activities.
V. Rules on Information Transfers in Corporate Mergers, Dissolutions, and Bankruptcy Scenarios
The Personal Information Protection Law provides that where a personal information processor needs to transfer personal information due to a merger, division, dissolution, declaration of bankruptcy, or other reason, it must inform the individuals concerned of the name and contact information of the recipient, and the recipient must continue to fulfill the obligations of a personal information processor. On this basis, Article 9 of the Provisions makes an adaptive simplification to the notification methods available to small-scale personal information processors, allowing the notification obligation to be fulfilled through notices at business premises, text message reminders, pop-up notices in client applications, notices on platform pages, mini-program notices, or other means. It also requires the relevant matters to be disclosed at least 30 working days in advance and to remain publicly available for no less than 30 working days.
This article primarily adjusts the manner in which the notification obligation is implemented, with the aim of adapting the protection of individuals’ right to be informed in personal information transfer scenarios to the actual business models and technical conditions of small-scale business entities. By specifying simplified notification channels that may be used and a minimum publication period, the Provisions reduce procedural burdens while preserving sufficient time for individuals to become fully informed and make corresponding arrangements.
From the perspective of corporate mergers, business transfers, dissolutions, or market exits, Article 9 also means that the disposition of personal information should be incorporated into the advance planning for the relevant transaction or exit process. In particular, the requirement that disclosure be made 30 working days in advance and remain available for at least 30 working days means that personal information transfers should not be treated as an incidental matter after a company has ceased operations, but rather as a compliance step that must be completed in parallel with organizational changes and data handover.
VI. Further Simplifying Cross-border Data Transfer Obligations for Small-scale Personal Information Processors
The Personal Information Protection Law establishes the basic framework governing cross-border transfers of personal information, including compliance pathways such as security assessments for cross-border data transfers, personal information protection certification, and standard contracts for cross-border transfers of personal information. The Provisions on Facilitating and Regulating Cross-border Data Flows subsequently further optimized the relevant regime by establishing quantitative thresholds and exemptions for specified scenarios. On this basis, Article 10 of the Provisions introduces more facilitative arrangements for cross-border data transfers by small-scale personal information processors.
Under this article, exemptions from filing for a security assessment for cross-border data transfers, entering into a standard contract for cross-border transfers of personal information, or obtaining personal information protection certification are available in circumstances including where the transfer is necessary for the performance of a contract to which an individual is a party, such as for cross-border shopping, cross-border delivery, cross-border payment, airline ticket and hotel reservations, or visa applications; where it is necessary for implementing cross-border human resources management, urgently protecting the life, health, and property security of natural persons, or performing statutory duties or legal obligations; and where a processor that is not an operator of critical information infrastructure has, cumulatively since January 1 of the current year, provided personal information of fewer than 100,000 individuals overseas and such information does not include sensitive personal information.
The foregoing exemptions primarily concern procedural compliance mechanisms for cross-border transfers of personal information and do not affect the substantive obligations that personal information processors must bear in accordance with law. The Provisions make clear that when a small-scale personal information processor provides personal information overseas, it must still fulfill obligations such as providing notification and obtaining the individual’s separate consent in accordance with law; the relevant exemptions also do not apply where important data is involved. Therefore, “fewer than 100,000 individuals” means only that specified cross-border transfer procedures may be reduced where the applicable conditions are satisfied, and does not constitute a general exemption from regulatory requirements governing cross-border transfers of personal information. In addition, for small-scale personal information processors that are required to file for a security assessment for cross-border data transfers, the Provisions allow the provincial-level cyberspace administration at the processor’s location to formulate a recommended assessment conclusion and submit it to the national cyberspace administration for approval, while encouraging relevant departments and cross-border data service centers to provide consultation services. While continuing the policy of facilitating cross-border data flows, this arrangement also reflects a regulatory orientation toward reducing the cross-border data compliance costs of small-scale business entities through procedural optimization and public compliance services.
VII. Procedural Simplification of Safeguards for Individual Rights Without Reduction of Substantive Rights
The Personal Information Protection Law grants individuals a range of rights, including the rights to access, copy, correct, supplement, and delete personal information and to withdraw consent. The Regulations on Network Data Security Management further require network data processors to provide convenient means for individuals to exercise their rights and prohibit the imposition of unreasonable conditions.
Article 11 of the Provisions allows small-scale personal information processors to establish corresponding mechanisms for accepting and handling requests by publicly identifying the department or personnel responsible for receiving applications concerning individual rights, together with their contact information.
What this article simplifies is, in substance, the form of internal organization. Large enterprises may typically establish dedicated data protection teams, complaint platforms, or automated rights-request systems, whereas small merchants may perform the same function by designating specific personnel and publishing their contact information.
Accordingly, the Provisions’ emphasis on measures being “commensurate with scale and capabilities” should not be understood to mean that individuals enjoy fewer rights when dealing with small-scale business operators. Individuals’ substantive rights of access, correction, deletion, and the like derive from the Personal Information Protection Law; what the Provisions primarily adjust is the organizational manner in which processors safeguard those rights.
VIII. Simplifying Compliance Audits and Establishing a Mutual Recognition Mechanism for Certification
Article 54 of the Personal Information Protection Law requires personal information processors to conduct personal information protection compliance audits on a regular basis. The Measures for the Administration of Personal Information Protection Compliance Audits further refine the audit regime and expressly require processors handling personal information of more than ten million individuals to conduct a compliance audit at least once every two years. Article 13 of the Provisions adopts a differentiated arrangement for small-scale personal information processors that process personal information of fewer than 100,000 individuals, allowing them to conduct a simplified audit in accordance with the annexed Self-inspection Checklist for Personal Information Protection Compliance Audits by Small-scale Personal Information Processors. It also specifies a general audit cycle of at least once every five years and requires the self-inspection checklist to be retained for no less than five years.
By using a standardized self-inspection checklist and a longer audit cycle, this arrangement reduces the professional and procedural costs of compliance audits for small-scale personal information processors while providing a clearer standard for fulfilling their obligation to conduct “regular audits.” Its principal institutional objective is to align audit methods and frequency with the scale of personal information processing, the complexity of the business, and the level of risk, while using standardized tools to encourage processors to continuously review core compliance matters such as the collection and retention of personal information, access control, and security safeguards.
On this basis, Article 17 of the Provisions further makes clear that a small-scale personal information processor that has obtained personal information protection certification may be exempted from conducting personal information protection compliance audits during the certification’s validity period. Read together with Article 8, which provides that a small-scale personal information processor may be exempted from duplicating compliance audits and personal information protection impact assessments where the platform has already conducted such work and it covers the relevant processing activities, the Provisions can be seen as establishing a degree of mutual recognition of outcomes and relief from duplicative obligations across different compliance mechanisms.
These arrangements reflect the Provisions’ policy orientation toward reducing duplicative compliance and improving the efficiency with which compliance resources are used. However, simplifying audit methods and extending audit cycles does not mean that processors may disregard ongoing compliance during the intervening period. Where there are material changes to the business model, processing purposes, categories of personal information, or technical conditions, or where a personal information security incident or other circumstance arises that may significantly alter the risk profile, processors must still promptly assess the relevant processing activities and adopt corresponding compliance measures, rather than treating the five-year audit cycle as the sole criterion for determining whether their compliance obligations have been fulfilled.
IX. Administrative Penalty Rules Reflect Inclusive and Prudent Regulation but Do Not Exempt Small-scale Entities from Liability
Articles 18 and 19 of the Provisions specifically address circumstances in which no administrative penalty is to be imposed, or a lighter or mitigated penalty is to be imposed, for violations by small-scale personal information processors. Where a violation is minor, is promptly corrected, and causes no harmful consequences, no penalty shall be imposed. Where there is sufficient evidence to establish the absence of subjective fault, no penalty shall likewise be imposed. For a first violation that causes only minor harmful consequences and is promptly corrected, no penalty may be imposed. Where a party proactively eliminates or mitigates the harmful consequences, voluntarily discloses a violation not yet known to the regulatory authorities, promptly takes remedial measures and proactively notifies the relevant authorities following a security incident, or renders meritorious assistance in an investigation, a lighter or mitigated penalty shall be imposed in accordance with law.
These provisions closely align with the regimes under Articles 32 and 33 of the Administrative Penalty Law concerning lighter or mitigated penalties and circumstances in which no penalty is imposed. Their principal institutional significance lies in improving the predictability of enforcement. In the past, although enterprises could invoke the Administrative Penalty Law to argue for “no penalty for a first violation,” “no penalty for a minor violation,” or “no penalty absent fault,” the specific standards for applying these principles in personal information protection enforcement were not necessarily clear. By expressly incorporating these general administrative law principles into the regulatory framework for small-scale personal information processors, the Provisions help promote more consistent enforcement standards.
At the same time, even where no administrative penalty is ultimately imposed in accordance with law, regulatory authorities may still take measures such as conducting regulatory interviews or issuing reminder letters. Accordingly, “no penalty” means that no administrative penalty is imposed; it does not mean that the regulatory authority has determined the conduct to be fully compliant with personal information protection requirements. More importantly, Article 21 of the Provisions expressly retains mechanisms for supervision, inspection, and strict handling. Where an entity unlawfully processes personal information or repeatedly experiences personal information security incidents, cyberspace administrations, public security authorities, and other departments responsible for personal information protection may still take action in accordance with law and, pursuant to relevant provisions, record the matter in credit files and make it public. This creates, in effect, a distinctly graduated enforcement mechanism: for isolated, minor violations that are promptly corrected, greater emphasis is placed on education and rectification; for entities that repeatedly violate the rules or create higher risks, strict regulation is re-applied. This is consistent with risk-based regulation and the principle of proportionality in administrative penalties.
Conclusion
The promulgation of the Provisions on Simplified Measures for Personal Information Protection by Small-scale Personal Information Processors further improves China’s classified and tiered governance mechanism in the field of personal information protection. Building on the unified institutional framework established by the Personal Information Protection Law, the Provisions use the processing of personal information of fewer than 100,000 individuals as the applicability threshold and make differentiated arrangements concerning processing rules, notification obligations, platform governance, cross-border data transfers, compliance audits, impact assessments, internal management, and other matters, thereby creating a more reasonable correspondence between compliance obligations and the scale of processing, business complexity, and level of risk.
For small-scale personal information processors whose processing activities are relatively simple and low-risk, the Provisions appropriately reduce procedural and duplicative compliance costs; for high-risk matters such as sensitive personal information, important data, and personal information security incidents, they continue to maintain higher protection requirements. At the same time, through mechanisms such as platform rules, unified processing rules, mutual recognition of certification, and public compliance services, the Provisions further expand the available pathways through which small-scale personal information processors may fulfill their compliance obligations. The approaches reflected in the Provisions—including differentiated allocation of obligations, mutual recognition of compliance outcomes, and reduction of duplicative compliance—will help advance China’s personal information protection regime from the application of uniform rules toward more refined and risk-based governance.
Since the Personal Information Protection Law of the People’s Republic of China (the “Personal Information Protection Law”) came into force, China has developed a personal information protection framework founded on the Personal Information Protection Law, supplemented by administrative regulations such as the Regulations on Network Data Security Management, and further refined by sector-specific departmental rules concerning matters such as cross-border transfers of personal information, compliance audits, and facial recognition. However, personal information processors differ substantially in scale, processing capabilities, and risk levels. If all entities were required to implement personal information processing rules, impact assessments, audits, and internal management requirements through similar institutional structures and at comparable compliance costs, the compliance investment required of small-scale business entities could become disproportionate to the actual risks involved. The Provisions constitute a specific implementation of Article 62 of the Personal Information Protection Law, which provides that “the national cyberspace administration shall coordinate with relevant departments to formulate specialized personal information protection rules and standards for small-scale personal information processors, sensitive personal information, and new technologies and applications such as facial recognition and artificial intelligence.”
The following provides an interpretation and commentary on the principal provisions of the Provisions.
I. Defining Small-scale Personal Information Processors by the Criterion of “Processing Personal Information of Fewer Than 100,000 Individuals”
Article 2 of the Provisions first makes clear that the Provisions apply to small-scale personal information processors within the territory of the People’s Republic of China, and defines a “small-scale personal information processor” as “a personal information processor that processes personal information of fewer than 100,000 individuals.” Rather than relying on an enterprise’s registered capital, operating revenue, number of employees, or enterprise size under the Standards for Classification of Small and Medium-sized Enterprises, the provision directly uses the scale of personal information processing as the core criterion. Accordingly, a “small-scale personal information processor” is not necessarily synonymous with a “micro or small enterprise” in the traditional sense. An internet company with few employees and relatively low operating revenue may fall outside the scope of the Provisions if it processes personal information of more than 100,000 individuals; conversely, an offline enterprise of a certain business scale may fall within the scope of the Provisions if the personal information it actually processes consistently relates to fewer than 100,000 individuals. The official interpretation further clarifies that the “100,000 individuals” threshold is calculated based on the current cumulative number of natural persons whose personal information has been processed, excluding personal information that has already been deleted.
This design effectively establishes a tiered mechanism for regulated entities based on the scale of data processing. China has previously used quantitative thresholds such as one million and ten million individuals in instruments including the Regulations on Network Data Security Management and the Measures for the Administration of Personal Information Protection Compliance Audits to impose more stringent organizational and audit obligations. The Provisions now establish a dedicated rule at the lower threshold of “fewer than 100,000 individuals,” making the scale of personal information processing an increasingly important quantitative parameter for determining regulatory obligations.
II. Simplifying Personal Information Processing Rules and Notification Mechanisms
Article 17 of the Personal Information Protection Law establishes a prior notification obligation for personal information processors, with the aim of safeguarding individuals’ right to be informed about information processing activities and ensuring transparency in processing. In view of the relatively simple business models and limited processing scale of small-scale personal information processors, Article 4 of the Provisions simplifies the required content and methods of publication of personal information processing rules. It requires disclosure primarily of core matters such as the processor’s identity, channels for accepting requests concerning individual rights, and the purposes, methods, categories, and retention periods of processing. It also permits disclosure through notices at business premises, service agreements, pop-up notices in client applications, website notices, or other methods depending on whether the business is conducted online or offline.
This arrangement does not alter the notification obligation established by the Personal Information Protection Law; rather, it makes a proportionate adjustment to the manner in which that obligation is fulfilled. The principal institutional objective is to ensure that individuals can effectively obtain information closely related to their rights and interests, while reducing formalistic compliance costs for small-scale entities whose processing activities are relatively simple and whose risks do not warrant such burdens. It reflects the Provisions’ differentiated regulatory approach while maintaining the standard of protection for individual rights and interests.
Article 5 of the Provisions further allows service and management entities for industrial parks, industrial bases, commercial properties, and similar premises to formulate and publish unified personal information processing rules for small-scale personal information processors engaged in the same offline business within their management scope. By consolidating certain repetitive compliance work, this arrangement helps reduce the institutional development costs of similar small-scale business entities and improves the standardization of rulemaking.
It should be noted that the unified formulation of personal information processing rules concerns only the manner in which compliance obligations are fulfilled and does not alter the allocation of responsibility for personal information processing. The relevant business operators remain legally responsible for their actual processing activities. If their processing purposes, methods, or categories of personal information exceed the scope covered by the unified rules, they must still fulfill the corresponding legal obligations with respect to the excess. Accordingly, the effectiveness of this mechanism depends on whether the unified rules remain consistent with the actual personal information processing activities of each business entity.
III. Simplifying Notification and the Processing Mechanism for Information Proactively Provided by Individuals While Maintaining High Standards of Protection for Sensitive Personal Information
Article 6 of the Provisions further simplifies the method of notification in specified circumstances. For non-sensitive personal information necessary for the provision of products or services, where such information is neither provided to other personal information processors nor disclosed publicly, and the relevant processing has been expressly stated in the personal information processing rules, a small-scale personal information processor may fulfill its notification obligation by publishing those rules, provided that the rules are prominently brought to individuals’ attention and are readily accessible for review and retention. By replacing repetitive individualized notifications with a unified public notice where the prescribed conditions are met, this arrangement protects individuals’ right to be informed while reducing the procedural compliance costs associated with low-risk processing activities.
On this basis, Article 7 of the Provisions further provides that, where an individual, with full knowledge, voluntarily and proactively provides, or cooperates in providing, personal information necessary to obtain products or services, a small-scale personal information processor may process such information in accordance with its published personal information processing rules. This provision creates a more direct institutional connection between the common transactional act of an individual proactively providing information and the personal information processing rules, and further reflects the Provisions’ approach of adjusting the manner in which obligations are fulfilled according to the level of risk associated with the processing activity.
However, the foregoing simplifications do not apply to sensitive personal information. The Provisions make clear that where sensitive personal information is processed for a specific purpose, the processor must still inform the individual of the necessity of processing the sensitive personal information and the impact on the individual’s rights and interests, and must obtain the individual’s separate consent in accordance with law. Notably, compared with the earlier draft for public comment, the final text deletes provisions that would have permitted a comparatively simplified processing mechanism where individuals proactively cooperated in providing sensitive personal information such as facial information or biological samples, thereby maintaining the higher standard of protection established by the Personal Information Protection Law for sensitive personal information.
Accordingly, Articles 6 and 7 establish a relatively clear risk-based hierarchy. For ordinary personal information processing activities with clear purposes, limited scope, and relatively low risk, notification and processing procedures may be appropriately simplified. Where sensitive personal information is involved, core safeguards such as notification of necessity and separate consent continue to apply. This also demonstrates that the regulatory burden reduction provided by the Provisions for small-scale personal information processors is focused primarily on procedures and methods of performance and does not reduce the substantive protection requirements applicable to high-risk personal information processing activities.
IV. Establishing a “Compliance Sharing” Mechanism in Platform-based Scenarios
Article 8 of the Provisions is one of the more innovative provisions in the overall framework. It establishes a relatively clear compliance-sharing mechanism for small-scale personal information processors that conduct business through online platforms. Where a small-scale personal information processor conducts personal information processing activities solely through an online platform, does not provide information to other personal information processors outside the platform, and the platform has formulated rules for the relevant processing activities and clearly defined the rights and obligations of both parties, the small-scale personal information processor may, after declaring that it will comply with the platform rules and provided that its processing activities are limited to what is necessary for providing products or services, refrain from separately formulating personal information processing rules and from independently fulfilling the corresponding notification obligations.
With respect to compliance audits and personal information protection impact assessments, the Provisions further allow audit and assessment results already produced by the platform to cover small-scale business operators on the platform. So long as the relevant audits and assessments have in fact covered the personal information processing activities conducted by the small-scale personal information processor through the platform, the processor may be exempted from repeating the same work. By reducing highly duplicative compliance procedures between platforms and business operators, this mechanism improves the efficiency with which personal information protection obligations are fulfilled within platform ecosystems.
This institutional arrangement strengthens the organizational and supporting role of online platforms in personal information protection governance. Subject to the prescribed conditions, personal information processing rules, compliance audits, and impact assessments formulated or conducted by a platform may serve as a common basis for small-scale business operators on the platform to fulfill the relevant obligations, thereby enabling a degree of shared compliance resources. Such sharing, however, is subject to strict limitations as to business scope and is premised on the operator’s actual processing activities remaining within the scope covered by the platform rules and the relevant audits and assessments. If the actual processing purposes, methods, or categories of personal information of a small-scale personal information processor exceed the scope covered by the platform rules, the processor must independently fulfill, in accordance with law, the obligations to formulate personal information processing rules, provide notification, conduct compliance audits, and carry out personal information protection impact assessments with respect to the excess. Where platform rules are adjusted, the platform must also promptly notify the relevant business operators. Accordingly, Article 8 provides relief from duplicative compliance under specified conditions, without altering the fundamental principle that business operators remain responsible for their own personal information processing activities.
V. Rules on Information Transfers in Corporate Mergers, Dissolutions, and Bankruptcy Scenarios
The Personal Information Protection Law provides that where a personal information processor needs to transfer personal information due to a merger, division, dissolution, declaration of bankruptcy, or other reason, it must inform the individuals concerned of the name and contact information of the recipient, and the recipient must continue to fulfill the obligations of a personal information processor. On this basis, Article 9 of the Provisions makes an adaptive simplification to the notification methods available to small-scale personal information processors, allowing the notification obligation to be fulfilled through notices at business premises, text message reminders, pop-up notices in client applications, notices on platform pages, mini-program notices, or other means. It also requires the relevant matters to be disclosed at least 30 working days in advance and to remain publicly available for no less than 30 working days.
This article primarily adjusts the manner in which the notification obligation is implemented, with the aim of adapting the protection of individuals’ right to be informed in personal information transfer scenarios to the actual business models and technical conditions of small-scale business entities. By specifying simplified notification channels that may be used and a minimum publication period, the Provisions reduce procedural burdens while preserving sufficient time for individuals to become fully informed and make corresponding arrangements.
From the perspective of corporate mergers, business transfers, dissolutions, or market exits, Article 9 also means that the disposition of personal information should be incorporated into the advance planning for the relevant transaction or exit process. In particular, the requirement that disclosure be made 30 working days in advance and remain available for at least 30 working days means that personal information transfers should not be treated as an incidental matter after a company has ceased operations, but rather as a compliance step that must be completed in parallel with organizational changes and data handover.
VI. Further Simplifying Cross-border Data Transfer Obligations for Small-scale Personal Information Processors
The Personal Information Protection Law establishes the basic framework governing cross-border transfers of personal information, including compliance pathways such as security assessments for cross-border data transfers, personal information protection certification, and standard contracts for cross-border transfers of personal information. The Provisions on Facilitating and Regulating Cross-border Data Flows subsequently further optimized the relevant regime by establishing quantitative thresholds and exemptions for specified scenarios. On this basis, Article 10 of the Provisions introduces more facilitative arrangements for cross-border data transfers by small-scale personal information processors.
Under this article, exemptions from filing for a security assessment for cross-border data transfers, entering into a standard contract for cross-border transfers of personal information, or obtaining personal information protection certification are available in circumstances including where the transfer is necessary for the performance of a contract to which an individual is a party, such as for cross-border shopping, cross-border delivery, cross-border payment, airline ticket and hotel reservations, or visa applications; where it is necessary for implementing cross-border human resources management, urgently protecting the life, health, and property security of natural persons, or performing statutory duties or legal obligations; and where a processor that is not an operator of critical information infrastructure has, cumulatively since January 1 of the current year, provided personal information of fewer than 100,000 individuals overseas and such information does not include sensitive personal information.
The foregoing exemptions primarily concern procedural compliance mechanisms for cross-border transfers of personal information and do not affect the substantive obligations that personal information processors must bear in accordance with law. The Provisions make clear that when a small-scale personal information processor provides personal information overseas, it must still fulfill obligations such as providing notification and obtaining the individual’s separate consent in accordance with law; the relevant exemptions also do not apply where important data is involved. Therefore, “fewer than 100,000 individuals” means only that specified cross-border transfer procedures may be reduced where the applicable conditions are satisfied, and does not constitute a general exemption from regulatory requirements governing cross-border transfers of personal information. In addition, for small-scale personal information processors that are required to file for a security assessment for cross-border data transfers, the Provisions allow the provincial-level cyberspace administration at the processor’s location to formulate a recommended assessment conclusion and submit it to the national cyberspace administration for approval, while encouraging relevant departments and cross-border data service centers to provide consultation services. While continuing the policy of facilitating cross-border data flows, this arrangement also reflects a regulatory orientation toward reducing the cross-border data compliance costs of small-scale business entities through procedural optimization and public compliance services.
VII. Procedural Simplification of Safeguards for Individual Rights Without Reduction of Substantive Rights
The Personal Information Protection Law grants individuals a range of rights, including the rights to access, copy, correct, supplement, and delete personal information and to withdraw consent. The Regulations on Network Data Security Management further require network data processors to provide convenient means for individuals to exercise their rights and prohibit the imposition of unreasonable conditions.
Article 11 of the Provisions allows small-scale personal information processors to establish corresponding mechanisms for accepting and handling requests by publicly identifying the department or personnel responsible for receiving applications concerning individual rights, together with their contact information.
What this article simplifies is, in substance, the form of internal organization. Large enterprises may typically establish dedicated data protection teams, complaint platforms, or automated rights-request systems, whereas small merchants may perform the same function by designating specific personnel and publishing their contact information.
Accordingly, the Provisions’ emphasis on measures being “commensurate with scale and capabilities” should not be understood to mean that individuals enjoy fewer rights when dealing with small-scale business operators. Individuals’ substantive rights of access, correction, deletion, and the like derive from the Personal Information Protection Law; what the Provisions primarily adjust is the organizational manner in which processors safeguard those rights.
VIII. Simplifying Compliance Audits and Establishing a Mutual Recognition Mechanism for Certification
Article 54 of the Personal Information Protection Law requires personal information processors to conduct personal information protection compliance audits on a regular basis. The Measures for the Administration of Personal Information Protection Compliance Audits further refine the audit regime and expressly require processors handling personal information of more than ten million individuals to conduct a compliance audit at least once every two years. Article 13 of the Provisions adopts a differentiated arrangement for small-scale personal information processors that process personal information of fewer than 100,000 individuals, allowing them to conduct a simplified audit in accordance with the annexed Self-inspection Checklist for Personal Information Protection Compliance Audits by Small-scale Personal Information Processors. It also specifies a general audit cycle of at least once every five years and requires the self-inspection checklist to be retained for no less than five years.
By using a standardized self-inspection checklist and a longer audit cycle, this arrangement reduces the professional and procedural costs of compliance audits for small-scale personal information processors while providing a clearer standard for fulfilling their obligation to conduct “regular audits.” Its principal institutional objective is to align audit methods and frequency with the scale of personal information processing, the complexity of the business, and the level of risk, while using standardized tools to encourage processors to continuously review core compliance matters such as the collection and retention of personal information, access control, and security safeguards.
On this basis, Article 17 of the Provisions further makes clear that a small-scale personal information processor that has obtained personal information protection certification may be exempted from conducting personal information protection compliance audits during the certification’s validity period. Read together with Article 8, which provides that a small-scale personal information processor may be exempted from duplicating compliance audits and personal information protection impact assessments where the platform has already conducted such work and it covers the relevant processing activities, the Provisions can be seen as establishing a degree of mutual recognition of outcomes and relief from duplicative obligations across different compliance mechanisms.
These arrangements reflect the Provisions’ policy orientation toward reducing duplicative compliance and improving the efficiency with which compliance resources are used. However, simplifying audit methods and extending audit cycles does not mean that processors may disregard ongoing compliance during the intervening period. Where there are material changes to the business model, processing purposes, categories of personal information, or technical conditions, or where a personal information security incident or other circumstance arises that may significantly alter the risk profile, processors must still promptly assess the relevant processing activities and adopt corresponding compliance measures, rather than treating the five-year audit cycle as the sole criterion for determining whether their compliance obligations have been fulfilled.
IX. Administrative Penalty Rules Reflect Inclusive and Prudent Regulation but Do Not Exempt Small-scale Entities from Liability
Articles 18 and 19 of the Provisions specifically address circumstances in which no administrative penalty is to be imposed, or a lighter or mitigated penalty is to be imposed, for violations by small-scale personal information processors. Where a violation is minor, is promptly corrected, and causes no harmful consequences, no penalty shall be imposed. Where there is sufficient evidence to establish the absence of subjective fault, no penalty shall likewise be imposed. For a first violation that causes only minor harmful consequences and is promptly corrected, no penalty may be imposed. Where a party proactively eliminates or mitigates the harmful consequences, voluntarily discloses a violation not yet known to the regulatory authorities, promptly takes remedial measures and proactively notifies the relevant authorities following a security incident, or renders meritorious assistance in an investigation, a lighter or mitigated penalty shall be imposed in accordance with law.
These provisions closely align with the regimes under Articles 32 and 33 of the Administrative Penalty Law concerning lighter or mitigated penalties and circumstances in which no penalty is imposed. Their principal institutional significance lies in improving the predictability of enforcement. In the past, although enterprises could invoke the Administrative Penalty Law to argue for “no penalty for a first violation,” “no penalty for a minor violation,” or “no penalty absent fault,” the specific standards for applying these principles in personal information protection enforcement were not necessarily clear. By expressly incorporating these general administrative law principles into the regulatory framework for small-scale personal information processors, the Provisions help promote more consistent enforcement standards.
At the same time, even where no administrative penalty is ultimately imposed in accordance with law, regulatory authorities may still take measures such as conducting regulatory interviews or issuing reminder letters. Accordingly, “no penalty” means that no administrative penalty is imposed; it does not mean that the regulatory authority has determined the conduct to be fully compliant with personal information protection requirements. More importantly, Article 21 of the Provisions expressly retains mechanisms for supervision, inspection, and strict handling. Where an entity unlawfully processes personal information or repeatedly experiences personal information security incidents, cyberspace administrations, public security authorities, and other departments responsible for personal information protection may still take action in accordance with law and, pursuant to relevant provisions, record the matter in credit files and make it public. This creates, in effect, a distinctly graduated enforcement mechanism: for isolated, minor violations that are promptly corrected, greater emphasis is placed on education and rectification; for entities that repeatedly violate the rules or create higher risks, strict regulation is re-applied. This is consistent with risk-based regulation and the principle of proportionality in administrative penalties.
Conclusion
The promulgation of the Provisions on Simplified Measures for Personal Information Protection by Small-scale Personal Information Processors further improves China’s classified and tiered governance mechanism in the field of personal information protection. Building on the unified institutional framework established by the Personal Information Protection Law, the Provisions use the processing of personal information of fewer than 100,000 individuals as the applicability threshold and make differentiated arrangements concerning processing rules, notification obligations, platform governance, cross-border data transfers, compliance audits, impact assessments, internal management, and other matters, thereby creating a more reasonable correspondence between compliance obligations and the scale of processing, business complexity, and level of risk.
For small-scale personal information processors whose processing activities are relatively simple and low-risk, the Provisions appropriately reduce procedural and duplicative compliance costs; for high-risk matters such as sensitive personal information, important data, and personal information security incidents, they continue to maintain higher protection requirements. At the same time, through mechanisms such as platform rules, unified processing rules, mutual recognition of certification, and public compliance services, the Provisions further expand the available pathways through which small-scale personal information processors may fulfill their compliance obligations. The approaches reflected in the Provisions—including differentiated allocation of obligations, mutual recognition of compliance outcomes, and reduction of duplicative compliance—will help advance China’s personal information protection regime from the application of uniform rules toward more refined and risk-based governance.