Posted in

App personal-information collection compliance in China (2026): the CAC draft rules and what FIEs must do

  • The CAC’s January 2026 draft “Rules on Personal Information Collection and Use by Internet Applications” codifies consent, separate consent for sensitive data, and minimal collection for apps, SDKs, distribution platforms and device makers.
    国家网信办2026年1月《互联网应用程序个人信息收集使用规定(征求意见稿)》将同意、敏感信息单独同意与最小必要等要求成文化,覆盖App、SDK、分发平台与终端厂商。
  • Sensitive personal information (face, fingerprint, voiceprint) requires separate consent and, except where lawful, must be stored on-device and never transmitted over the internet.
    敏感个人信息(人脸、指纹、声纹)须取得单独同意,除法定情形外须存储于生物识别设备内、不得通过互联网对外传输。
  • Apps must not deny service for refusing non-essential data, must gate permissions to the active function, and must give a one-tap rules-access and an easy account-deletion within 15 working days.
    App不得以拒绝非必要信息为由拒绝服务,权限须限定当前功能,并提供一键查阅规则与15个工作日内注销账号。
  • Publishing platforms must vet apps on-board and clear non-compliant in-store apps within 6 months of the rules taking effect.
    分发平台须上架审核,并在规定生效起6个月内完成存量App审核、不合规则下架。
  • Processing 1 million+ individuals’ personal information triggers a duty to designate a personal-information protection officer and to file that officer’s information with the CAC.
    处理100万人以上个人信息须指定个人信息保护负责人,并向网信办报送负责人信息。
  • Foreign-invested apps must localize consent flows, SDK audits and biometric handling to meet the draft’s transparency and on-device storage demands.
    外资App须将同意流程、SDK审计与生物识别处理本地化,以符合征求意见稿的透明与设备内存储要求。
  • The separate-consent and minimal-necessity principles also govern cross-border transfer, dovetailing with the PIPL export certification and negative-list routes.
    单独同意与最小必要原则同时约束跨境传输,与个保法出境认证及负面清单路径相衔接。

App personal-information collection compliance in China (2026): the CAC draft rules and what FIEs must do | 2026年中国App个人信息收集合规:网信办征求意见稿与外资企业义务

Overview: from principle to procedure

China’s Personal Information Protection Law (PIPL) sets broad principles — lawfulness, necessity, informed consent. In January 2026, the Cyberspace Administration of China (CAC) published the “Rules on Personal Information Collection and Use by Internet Applications (Draft for Comment)”, turning those principles into concrete app-level duties. For foreign-invested apps, SaaS and device makers, this draft is the practical compliance blueprint for 2026.

The legal basis and scope

Drafted under the Cybersecurity Law, the PIPL and the Network Data Security Regulation, the CAC draft applies to collecting/using personal information by internet applications within China, and to SDKs, distribution platforms and smart terminals that serve them. It also reaches apps operated outside China that collect personal information of individuals inside China where Article 3(2) PIPL applies. Collection must follow lawful, legitimate, necessary and good-faith principles; sensitive personal information requires the data subject’s separate consent.

Consent, separate consent and no coercion

Article 3 of the draft requires fully informing the collection rules and obtaining consent; for sensitive information, separate consent is mandatory. Apps may not refuse to provide services because a user refuses non-essential data or withdraws consent (except where the data is essential). The rules push transparency: key items must be highlighted in bold or color, and a one-tap access to the rules must sit on the settings page. Where an app has 50 million+ registered or 10 million+ monthly-active users and a complex business, rule changes need a ≥7-working-day public comment period.

Minimal collection and permission gating

The draft limits collection to what each function needs, at the minimum frequency and scope. Apps must request a permission only when the user uses the specific function, inform the purpose, and stop calling it when no longer needed (Articles 12–14). Calling contacts, call logs or SMS to collect others’ information is barred unless for communications. Biometric collection (face, fingerprint, voiceprint) needs specific purpose and necessity, strict protection, and — except as lawful or with separate consent — storage on the biometric device and no internet transmission (Article 15).

Sensitive data, minors and automated decisions

Collecting personal information of children under 14 requires a dedicated rules and parental consent (Article 16). Automated decision-making (e.g., recommendations) must offer an easy-to-close personalization switch (Article 17). Account deletion must be convenient, completed within 15 working days with deletion or anonymization, and must not demand new excess information (Article 18).

Distribution platforms and device makers

Distribution platforms must vet apps on onboarding, record personal-information issues and penalty history, and within 6 months of the rules taking effect, audit in-store apps and remove non-compliant ones (Article 26). They must show permission lists and rules links on download pages and flag apps penalized by authorities. Smart-terminal makers must verify app identities before preinstalling and surface real-time permission indicators (Articles 29–32).

The protection-officer and CAC filing duty

The PIPL and the CAC’s 2025 announcement on filing personal-information protection-officer information converge here: processors of 1 million or more individuals’ personal information must designate a protection officer; the Compliance Audit Measures add that processors of 1 million+ must also designate an officer for compliance audit. Filing is online via the CAC “Personal Information Protection Business System.” Foreign-invested apps crossing the threshold must name and file the officer.

How this dovetails with cross-border transfer

The same separate-consent and minimal-necessity principles govern outbound transfer under the PIPL. Our separate articles cover the three export routes — the negative list / standard contract, the PIPL export certification (open 1 January 2026) and the security assessment. Apps that collect biometrics or sensitive data domestically and wish to process abroad must satisfy both this draft’s on-device storage expectation and the export-route obligation.

Practical steps for foreign-invested apps

  1. Map data to functions; cut non-essential collection and over-broad permissions.
  2. Build separate-consent flows for biometrics and other sensitive data; default to on-device storage.
  3. Gate permissions to active functions; add one-tap rules access and 15-day deletion.
  4. Audit embedded SDKs against declared behavior; keep a compliance record.
  5. Designate and file a protection officer if processing 1 million+ individuals.
  6. Align export with the certification / negative-list / assessment route.

Related reading

Cross-border data transfer rules (PIPL), the PIPL compliance audit regime, and personal-information export certification are covered in separate articles; this piece is the app-collection briefing plus the action list.


2026年中国App个人信息收集合规:网信办征求意见稿与外资企业义务

概览:从原则到程序

中国《个人信息保护法》(PIPL)确立了合法、必要、知情同意义务等宽泛原则。2026年1月,国家互联网信息办公室(网信办)公布《互联网应用程序个人信息收集使用规定(征求意见稿)》,将这些原则落为具体的App级义务。对外资App、SaaS与终端厂商,该征求意见稿是2026年的实操合规蓝图。

法律依据与适用范围

征求意见稿依《网络安全法》《个人信息保护法》《网络数据安全管理条例》起草,适用于在中国境内运营App收集使用个人信息,以及为App提供服务的SDK、分发平台与智能终端。对境外运营、依个保法第三条第二款收集境内自然人个人信息的App同样适用。收集须遵循合法、正当、必要、诚信原则;敏感个人信息须取得个人单独同意。

同意、单独同意与禁止胁迫

征求意见稿第三条要求充分告知收集规则并取得同意;敏感信息须取得单独同意。App不得以个人拒绝非必要信息或撤回同意为由拒绝提供服务(信息为必需的除外)。规则推动透明:重点内容须加粗或变色提示,设置页须提供一键查阅规则。注册用户5000万以上或月活1000万以上且业务复杂的App,规则变更须不少于7个工作日公开征求意见。

最小收集与权限限定

征求意见稿将收集限于各功能所必需,以最低频度与最小范围。App须仅在用户使用具体功能时索要对应权限、告知目的,不再需要时停止调用(第12–14条)。除通信联系等除外,不得调用通讯录、通话记录、短信收集他人信息。生物识别(人脸、指纹、声纹)须有特定目的与充分必要性、严格保护,且除法定或取得单独同意外,须存储于生物识别设备内、不得通过互联网对外传输(第15条)。

敏感数据、未成年人与自动化决策

收集不满14周岁未成年人个人信息须制定专门规则并取得监护人同意(第16条)。自动化决策(如推荐)须提供易于关闭的个性化开关(第17条)。账号注销须便捷,15个工作日内完成删除或匿名化,且不得要求新增超额信息(第18条)。

分发平台与终端厂商

分发平台须上架审核,记录个人信息问题与处罚历史,并在规定生效起6个月内完成存量App审核、下架不合规范例(第26条)。下载页须展示权限清单与规则链接,并对被通报处罚的App作风险提示。智能终端厂商须在上架前核验App身份,并实时提示权限调用(第29–32条)。

保护负责人与网信办报送义务

个保法与网信办2025年《关于开展个人信息保护负责人信息报送工作的公告》在此汇合:处理100万人以上个人信息的处理者须指定个人信息保护负责人;合规审计办法亦要求100万人以上者指定审计负责人。报送通过网信办”个人信息保护业务系统”线上进行。跨阈值的外资App须指定并报送负责人。

与跨境传输的衔接

同样的单独同意与最小必要原则约束个保法下的出境。本站另文覆盖三条出境通道——负面清单/标准合同、2026年1月1日启用的个保法出境认证与安全评估。境内收集生物识别或敏感数据、欲境外处理的App,须同时满足本征求意见稿的设备内存储预期与出境路径义务。

外资App的实操步骤

  1. 将数据映射到功能,削减非必要收集与过宽权限。
  2. 为生物识别等敏感数据建立单独同意流程,默认设备内存储。
  3. 将权限限定于活跃功能,增加一键查阅规则与15天注销。
  4. 审计嵌入的SDK是否符合声明行为,留存合规记录。
  5. 处理100万人以上者指定并报送保护负责人。
  6. 将出境对齐认证/负面清单/评估路径。

延伸阅读

跨境数据传输规则(个保法)、个保法合规审计制度与个人信息出境认证本站另有专文;本文为App收集简报加行动清单。

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *