|
Issued by:
|
Cyberspace Administration of China, Ministry of Public Security of the People's Republic of China
|
|
Issue No.:
|
Order No. 25 of the Cyberspace Administration of China and the Ministry of Public Security of the People's Republic of China
|
|
Release Date:
|
July 24, 2026
|
|
Effective Date:
|
September 1, 2026
|
|
Links:
|
https://www.cac.gov.cn/2026-07/24/c_1786638889704872.htm
|
The Provisions are China's first departmental rules specifically targeting small personal information processors, aiming to reduce compliance burdens on small and micro-entities and establish a differentiated compliance system for personal information protection. The main contents are as follows:
- 1. Scope of Application: These Provisions apply only to small‑scale processors whose cumulative processing of personal information involves fewer than 100,000 individuals. Personal information that has been deleted shall not be counted in the statistics.
- 2. Simplification of Obligations for Formulating Personal Information Processing Rules and Providing Notices
- 1)Small processors are not required to draft lengthy privacy policies; they only need to publicly disclose the core items stipulated in these Provisions.
- 2)Offline, rules for personal information processing can be made public via notices posted in prominent locations at business premises; online, they can be made public via service agreements, pop-up windows, etc.
- 3)Service management units such as those in industrial parks or commercial properties can formulate unified rules for small businesses engaged in similar offline operations within their premises; compliant operators do not need to formulate separate rules. Merchants operating solely on online platforms, who promise to comply with platform rules and do not process information beyond the platform's scope, are exempt from formulating their own rules, fulfilling notification obligations, and may share the results of the platform's compliance audits and impact assessments.
- 3. Exemptions Related to Data Export: Qualified small processors who provide personal information (excluding important information) overseas are exempt from applying for security assessments for data exports, signing standard contracts, or obtaining certifications regarding data export. However, they still need to fulfill the obligations of notification and obtaining separate consent from individuals.
- 4. Reduced Burden for Compliance Audits and Impact Assessments: Small processors may use official simplified templates to conduct compliance audits and personal information protection impact assessments independently. The audit cycle is extended to at least once every five years.
- 5. Implementation of Inclusive and Prudent Supervision: Specific circumstances where minor or occasional violations shall not be penalized, or shall be subject to lighter or mitigated penalties, are clarified.