Follow us on

Current location:

Home > ChinaCompliance
China Eases Personal Information Protection Duties for Small-Scale Handlers – JUL, 2026

2026.08.28 11:45

Author:admin

Tags: by ED04 #Data Security #Cybersecurity

Share to--:

On 24 July 2026, the Cyberspace Administration of China (CAC) and the Ministry of Public Security (MPS) jointly issued the Provisions on Simplified Measures for Personal Information Protection by Small Personal Information Processors (hereinafter referred to as the Provision), which takes effect on 1 September 2026.

The Provisions implement Article 62 of the Personal Information Protection Law (PIPL), which authorizes the CAC to formulate dedicated rules for small-scale personal information (PI) handlers. Both the Provisions and the CAC's accompanying Q&A make clear that the measure is part of a broader policy push to support micro, small and medium-sized enterprises by lowering compliance costs while holding the bottom line on PI security. In scope, the Provisions apply to PI handlers located in China that process the PI of fewer than 100,000 individuals, counted by the cumulative number of natural persons whose PI is currently held, excluding deleted records.

For qualifying handlers, the reliefs are substantial. Content requirements for PI processing rules are streamlined, and such rules may be published through postings at business premises, pop-ups or website announcements. Where processing is necessary for providing a product or service, involves no sensitive PI and no external sharing, notice may be given solely through the published rules, and an individual's voluntary provision of PI counts as consent.

Merchants running identical offline businesses within industrial parks or commercial properties may rely on unified rules prepared by the management unit, while platform-dependent sellers (e.g., e-commerce or social media marketplace) meeting strict conditions are exempted from drafting their own rules and repeating audits or Personal Information Protection Impact Assessment (PIPIA) already covered by the platform. Cross-border transfers under specified conditions no longer require security assessment, standard contract or certification.

Compliance audits may follow a self-check template at least once every five years, and handlers that have obtained personal information protection certification from an accredited body are exempted from audits during the certification's validity period. PIPIA, internal policies, and incident notification may likewise be completed through simplified templates and methods. The Provisions further introduce no-penalty and mitigated-penalty scenarios for minor or first-time violations.

Businesses that fit the simplification profile are advised to review the Provisions carefully, assess through an internal compliance review whether the measures ease or add to their compliance burden, and adjust their PI protection frameworks accordingly.

 

If any further information is needed, or any question you may have, please contact us at: assistant@bestao-consulting.com


Related News