Posted in

China’s PIPL Compliance Audit Regime: What Foreign-Invested Enterprises Must Do in 2026

  • CAC Order No. 18, the Measures for the Administration of Personal Information Protection Compliance Audits, was published on 14 February 2025 and took effect on 1 May 2025.
    《个人信息保护合规审计管理办法》以国家互联网信息办公室令第18号于2025年2月14日公布,自2025年5月1日起施行。
  • A handler processing the personal information of more than 10 million people must run a self-initiated audit at least once every two years.
    处理超过1000万人个人信息的处理者,应当每两年至少开展一次自行审计。
  • Regulators may order an external audit where there is major risk, possible harm to numerous individuals, or a breach hitting 1 million people or 100,000 sensitive records.
    存在较大风险、可能侵害众多个人权益,或发生100万人以上个人信息、10万人以上敏感个人信息泄露事件的,保护部门可责令委托专业机构审计。
  • Below the top band the ladder is three or four years for 1–10 million people and five years for up to 1 million, counted on current holdings and net of deleted data.
    最高档以下分层为:100万至1000万人每3年或4年一次,不超过100万人每5年一次;按当前处理量统计,均包含本数,已删除的不计入。
  • Above 1 million people a personal information protection officer must own the audit, and major platforms need a supervisory body composed mainly of external members.
    处理100万人以上个人信息的须指定个人信息保护负责人负责审计;重要互联网平台还须成立主要由外部成员组成的独立机构进行监督。
  • Subcontracting is banned, no firm or audit lead may serve the same client more than three consecutive times, and an ordered audit needs a rectification report within 15 working days.
    不得转委托;同一机构或同一合规审计负责人不得连续三次以上审计同一对象;责令审计的,整改完成后15个工作日内须报送整改情况报告。

China’s PIPL Compliance Audit Regime: What Foreign-Invested Enterprises Must Do in 2026 | 中国个人信息保护合规审计制度:2026年外资企业的实操要求

Why the Audit Rule Matters to Foreign-Invested Enterprises

Most foreign-invested enterprises (FIEs) in China already run a PIPL programme. The audit regime asks a different question: not whether controls exist, but whether you can prove, on a fixed cycle and to an evidentiary standard, that they work. For consumer-facing FIEs it is now the most predictable interaction they will have with China’s data regulators.

The Legal Basis and Effective Date

The duty comes from Article 54 of the Personal Information Protection Law and the Regulations on Network Data Security Management. The operative rule is the *Measures for the Administration of Personal Information Protection Compliance Audits*, issued by the Cyberspace Administration of China (CAC) as Order No. 18 on 14 February 2025, effective 1 May 2025; the annexed *Compliance Audit Guidelines* are the working checklist. State organs and legally authorised public-affairs bodies are excluded; every commercial FIE is in scope.

Two Triggers: Self-Initiated and Regulator-Ordered

Self-initiated. A handler processing the personal information of more than 10 million people must audit at least once every two years, in-house or through an outside firm; no regulator instruction is needed.

Regulator-ordered. A protection authority may require an external audit where processing carries major risk — serious impact on individual rights, or a serious lack of security measures — where it may infringe the rights of numerous individuals, or where an incident has leaked, altered, lost or destroyed the personal information of 1 million or more people, or the sensitive personal information of 100,000 or more. Duplicate orders for one incident or risk are barred.

How Often: The Tiered Frequency Ladder

The Measures fix only the top band; the tiers beneath come from the national standard *Data Security Technology — Personal Information Protection Compliance Audit Requirements*, confirmed in the CAC’s April 2026 *Q&A on Personal Information Protection Policies and Regulations*.

Volume of individuals processedMinimum audit frequency
More than 10 millionAt least once every 2 years
1 million to 10 millionAt least once every 3 or 4 years
Not more than 1 millionAt least once every 5 years
Minors’ personal information (any volume)Annually

The last row is separate law: Article 37 of the Regulations on the Protection of Minors Online requires an annual audit of minors’ data handling, reported promptly to the CAC.

Counting Headcount: The April 2026 Clarification

The April 2026 Q&A settled three points: every figure is inclusive of the stated number; the count covers natural persons whose personal information is currently processed, not a historical total; and already-deleted data is excluded. Disciplined deletion can move a business down a tier.

Governance: The DPO and the Independent Supervisory Body

Above 1 million people, a handler must designate a personal information protection officer who owns the audit. Handlers providing important internet platform services, with very large user numbers and complex business types, must also set up an independent body composed mainly of external members to supervise it.

Choosing and Rotating the Professional Auditor

An engaged firm needs auditors, premises, facilities and funding commensurate with the service and may not subcontract; it must keep what it learns confidential and delete it once the audit closes. Rotation is mandatory: the same firm, its affiliates, or the same audit lead may not audit the same client more than three consecutive times.

The Regulator-Ordered Workflow and the 15-Working-Day Clock

The chain is fixed: select the firm as the authority requires; finish within the stipulated period, extendable with approval where matters are complex; submit the report, signed by the firm’s principal and the audit lead and stamped with the official seal; rectify; and file a rectification report within 15 working days of completing remediation. The handler bears the cost; violations are handled under the PIPL and the Network Data Security Regulations.

What the Audit Guidelines Actually Check

The Guidelines cover lawful basis, processing rules, notification, joint and entrusted processing, provision to third parties, automated decision-making, public disclosure, image collection in public places, sensitive personal information, the data of minors under 14, cross-border provision, deletion, rights requests and internal management. For FIEs, Article 15 — cross-border provision — carries the most exposure.

Outbound scenarioRequired route
CIIO transferring any personal information abroadCAC security assessment
Non-CIIO: 1 million people or more non-sensitive, or 10,000 or more sensitive, cumulative in the yearCAC security assessment
Non-CIIO: 100,000 to under 1 million non-sensitive, or under 10,000 sensitiveCertification, or standard contract filed with the provincial CAC
Provision to a foreign judicial or law-enforcement bodyPrior approval of the competent authority

That last row is the scenario multinationals meet in overseas litigation, and skipping approval is a discrete violation.

Practical Steps for a Foreign-Invested Enterprise

  1. Count first: current natural persons, net of deletions, then place the entity on the ladder.
  2. Name the owner above 1 million people and write the audit into their mandate.
  3. Re-test the outbound route against cumulative annual export volumes.
  4. Pre-build evidence: retention logs, consent records, entrusted-processing agreements, rights-response times.
  5. Plan rotation before the third consecutive engagement, and check the under-14 overlay.
  6. Reserve the remediation window; the 15-working-day clock starts when rectification is complete.

Related Reading

For the underlying duties — lawful basis, consent, localisation, the standard contract — see our separate article *PIPL Compliance for Foreign Companies*.


中国个人信息保护合规审计制度:2026年外资企业的实操要求

合规审计为何对外资企业重要

在华外资企业大多已建立个人信息保护体系。合规审计制度提出的是另一个问题:不问你是否有控制措施,而问能否按固定周期、以可举证的标准证明其有效。对消费类外资企业而言,这已是其与中国数据监管部门最可预期的常态化互动。

法律依据与施行日期

义务源自《个人信息保护法》第54条与《网络数据安全管理条例》。具体规范是《个人信息保护合规审计管理办法》,由国家互联网信息办公室以第18号令于2025年2月14日公布,自2025年5月1日起施行;其附件《个人信息保护合规审计指引》是实操清单。《办法》不适用于国家机关及法律法规授权的公共事务管理组织;商业性外资企业均在范围内。

两种触发情形:自行审计与责令审计

自行审计。 处理超过1000万人个人信息的处理者,应当每两年至少开展一次,可自行进行或委托外部机构,无需监管指令。

责令审计。 处理活动存在严重影响个人权益或严重缺乏安全措施等较大风险、可能侵害众多个人权益,或发生安全事件导致100万人以上个人信息、10万人以上敏感个人信息泄露、篡改、丢失、毁损的,保护部门可要求委托专业机构审计。针对同一事件或同一风险,不得重复要求。

频度:分层审计频率阶梯

《办法》仅明确最高一档,其下分层来自国家标准《数据安全技术 个人信息保护合规审计要求》,并经国家网信办2026年4月《个人信息保护政策法规问答》确认。

处理个人信息涉及人数最低审计频度
超过1000万人每2年至少一次
100万人至1000万人每3年或4年至少一次
不超过100万人每5年至少一次
未成年人个人信息(不论规模)每年一次

最后一行源自《未成年人网络保护条例》第37条:处理者应每年对处理未成年人个人信息的合规情况审计,并及时向网信等部门报告。

人数计数口径:2026年4月的澄清

2026年4月问答厘清三点:各项人数标准均包含本数;按处理者当前处理个人信息所涉及的自然人数量统计,而非历史累计;已删除的个人信息不计入。规范的删除策略可使企业下降一档。

治理架构:个人信息保护负责人与独立监督机构

处理100万人以上个人信息的,应指定个人信息保护负责人,由其负责合规审计工作。提供重要互联网平台服务、用户数量巨大、业务类型复杂的处理者,还应成立主要由外部成员组成的独立机构监督合规审计情况。

专业机构的选择与强制轮换

受托机构应具备与服务相适应的审计人员、场所、设施和资金,不得转委托;对履职中知悉的个人信息、商业秘密依法保密,审计结束后及时删除。轮换是强制的:同一专业机构及其关联机构、同一合规审计负责人,不得连续三次以上对同一审计对象开展审计。

责令审计的程序链条与15个工作日时限

链条固定:按保护部门要求选定专业机构;在规定期限内完成,情况复杂经批准可延长;报送审计报告,须由专业机构主要负责人、合规审计负责人签字并加盖公章;按要求整改;并在整改完成后15个工作日内报送整改情况报告。费用由处理者承担;违反规定的,依照《个人信息保护法》《网络数据安全管理条例》处理,构成犯罪的追究刑责。

《审计指引》实际检查什么

《指引》覆盖合法性基础、处理规则、告知义务、共同处理与委托处理、对外提供、自动化决策、公共场所图像采集、已公开及敏感个人信息、不满十四周岁未成年人个人信息、向境外提供、删除、个人权利响应与内部管理制度等条线。对外资企业而言,第十五条跨境条线风险最集中。

出境情形应走路径
关键信息基础设施运营者出境任何个人信息通过安全评估
非关基:当年累计100万人以上非敏感,或1万人以上敏感通过安全评估
非关基:累计10万人以上不满100万人非敏感,或不满1万人敏感保护认证,或订立标准合同并向省级网信部门备案
向外国司法或执法机构提供须经主管机关批准

最后一行正是跨国企业在境外诉讼中会遇到的场景,未经批准提供即构成独立违规。

外资企业的实操步骤

  1. 先算人数: 当前处理的自然人数量(扣除已删除部分),据此定位频度档位。
  2. 明确责任人: 超过100万人的指定个人信息保护负责人,并将审计职责写入其职权范围。
  3. 复核出境路径,以当年累计出境量与上表门槛比对。
  4. 预先积累证据: 留存期日志、同意记录、委托处理协议、权利响应时限。
  5. 规划机构轮换,并核查未成年人叠加规则。
  6. 预留整改窗口: 15个工作日自整改完成之日起算。

延伸阅读

基础实体义务(合法性基础、同意、本地化、标准合同)见本站《PIPL Compliance for Foreign Companies》一文。

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *