Posted in

China’s Draft Rule for Large Personal-Information Processors: What Foreign-Invested Platforms and Apps Need to Know

  • China’s cyberspace regulator has released a draft rule for “large personal-information processors,” consolidating two earlier platform-focused drafts into one accountability regime for the biggest data holders.
    国家网信部门发布《大型个人信息处理者个人信息保护规定(征求意见稿)》,将早前两份聚焦平台的规定整合为面向最大规模数据处理者的统一责任制度。
  • A processor handling over 10 million individuals’ personal information, or meeting other significance tests, must self-assess and file a recognition application through its provincial cyberspace authority.
    处理超过1000万人个人信息的处理者,或符合其他重大影响标准的,须自评估并通过省级网信部门申报大型个人信息处理者认定。
  • Core duties include data minimisation, encryption, de-identification, access control, minor-protection safeguards and use of the national online identity authentication public service.
    核心义务涵盖最小必要、加密、去标识化、访问控制、未成年人保护,以及应用国家网络身份认证公共服务。
  • The consultation closes on 7 September 2026, giving foreign-invested platforms and apps a clear compliance horizon to assess exposure.
    征求意见截至2026年9月7日,为外资平台与App提供了评估合规敞口的明确窗口。
  • The draft sits atop the Personal Information Protection Law and the Network Data Security Management Regulation, signalling converging oversight of super-platforms.
    征求意见稿置于《个人信息保护法》与《网络数据安全管理条例》之上,预示着对超级平台的趋同监管。
  • Practical step: map data-volume and business-footprint triggers now, and pre-position a recognition filing before the threshold is crossed.
    实操建议:立即对照数据量与业务足迹触发条件制图,并在越过门槛前预先准备认定申报。

China’s Draft Rule for Large Personal-Information Processors: What Foreign-Invested Platforms and Apps Need to Know | 大型个人信息处理者规定征求意见:外资平台与App须知

On 7 August 2026, the Cyberspace Administration of China (CAC) published the *Draft Provisions on the Personal Information Protection of Large Personal-Information Processors (for public comment)*. The draft consolidates two earlier consultation documents — the rules on establishing personal-information protection supervisory committees for large online platforms and the rules on large online platforms’ personal-information protection — into a single, broader regime that reaches any “large personal-information processor,” not only classic internet platforms.

For foreign-invested businesses operating consumer apps, e-commerce storefronts, ride-hailing or delivery services, social products, or any service that scales to millions of Chinese users, the draft is a material compliance event. This article explains who is captured, what changes, and the practical steps to take during the consultation window.

Who is a “large processor”

The draft applies a multi-factor test rather than a single mechanical threshold. Under Article 2, a “large personal-information processor” is a processor whose personal-information protection and supervision are subject to the provisions. Recognition is triggered when any of the following conditions is met:

  1. Scale: the processor handles the personal information of more than 10 million natural persons.
  2. Importance of service: it provides important online services involving personal-information processing, or its business scope covers multiple lines of business that involve personal-information processing.
  3. Impact: its personal-information processing activities have an important influence on national security, economic operation, social stability, public health and safety, or similar interests.

Article 3 obliges processors that handle more than 10 million individuals’ data, and those that self-assess into the second or third condition, to file a recognition application through the provincial cyberspace authority to the national cyberspace authority. Provincial authorities must complete a completeness check within 15 working days of receiving the materials; if complete, they forward the materials and a preliminary opinion to the national authority. Authorities may also urge a processor that meets the conditions but has not filed to do so.

Key compliance duties

The draft imposes obligations that go well beyond the baseline PIPL duties:

  • Data minimisation. Collection must be limited to what is necessary to provide the product or service; over-collection is prohibited.
  • Technical and organisational safeguards. Processors should adopt encryption, de-identification, access control and anonymisation, may apply the national data-label/identification technology, and are encouraged to obtain personal-information protection certification.
  • Minor protection. Processing personal information of minors under 14 requires the consent of a parent or guardian, and convenient channels must be provided for giving and withdrawing that consent.
  • National identity service. Processors are encouraged to use the national online identity authentication public service.
  • Monitoring and response. Processors must build internal management systems and operating procedures covering processing activities, rights-response and security obligations, strengthen monitoring and early warning of personal-information security, and detect and dispose of security incidents in a timely manner.
  • International engagement. The draft encourages large processors to participate in international standards and rule-making on personal-information protection and to promote mutual recognition of rules and standards with other countries and regions.

Consultation timeline and process

The CAC notice sets the comment deadline at 7 September 2026. Feedback may be submitted by email to shujuju@cac.gov.cn or by post to the Cyberspace Administration of China’s Network Data Administration Bureau in Beijing, with the envelope marked “大型个人信息处理者个人信息保护规定征求意见.” Because the draft is still at the consultation stage, the final obligations, recognition form and timetable may shift — but the direction is clear: accountability for the largest data holders is being formalised.

Practical steps for foreign-invested platforms

  1. Size the footprint. Quantify the number of natural persons whose personal information you process in China; if you are near or above 10 million, assume you are in scope.
  2. Assess the qualitative triggers. Even below 10 million, multi-line consumer businesses with systemic reach should self-assess the “importance” and “impact” prongs.
  3. Pre-position the filing. Prepare the recognition application materials (data-scale evidence, processing-activity description, safeguard design) so a filing can be lodged promptly if triggered.
  4. Harden the baseline. Encrypt and de-identify at rest and in transit, restrict access on least-privilege, and stand up a minor-consent workflow.
  5. Engage the consultation. Where group policy allows, submit comments through the recognised industry association channel before 7 September 2026.

大型个人信息处理者规定征求意见:外资平台与App须知

2026年8月7日,国家互联网信息办公室发布《大型个人信息处理者个人信息保护规定(征求意见稿)》。该稿将早前两份文件——关于大型网络平台设立个人信息保护监督委员会的规定、以及关于大型网络平台个人信息保护的规定——整合为一项覆盖任何”大型个人信息处理者”、而非仅限传统互联网平台的统一制度。

对于运营消费类App、电商店面、网约车或配送服务、社交产品,或任何在中国拥有数百万用户规模的外商投资企业而言,该征求意见稿是一项重要的合规事件。本文说明谁被纳入、有何变化,以及在征求意见窗口期应采取的实操步骤。

何为”大型个人信息处理者”

该稿采用的是多因素测试,而非单一机械门槛。根据第二条,大型个人信息处理者的个人信息保护及其监督管理适用本规定。符合下列条件之一的,应认定属于大型个人信息处理者:

  1. 规模: 处理1000万人以上自然人个人信息。
  2. 服务重要性: 提供涉及个人信息处理的重要网络服务,或者经营范围涵盖多种业务且涉及个人信息处理。
  3. 影响: 个人信息处理活动对国家安全、经济运行、社会稳定、公共健康和安全等具有重要影响。

第三条规定,处理1000万人以上自然人个人信息,以及自评估认为符合第二条第二款第二、三项条件的处理者,应当通过所在地省级网信部门向国家网信部门申报大型个人信息处理者认定并按要求提交材料。省级网信部门应自收到申报材料之日起15个工作日内完成完备性查验;材料齐全的,将材料与初步认定意见报送国家网信部门。省级以上网信、电信主管部门、公安机关等部门认为符合认定条件但未主动申报的,应督促其申报。

核心合规义务

该稿施加了超出《个人信息保护法》基线的义务:

  • 最小必要。 收集个人信息应限于提供产品或者服务所必需,不得过度收集。
  • 技术与组织保障。 采取加密、去标识化、访问控制、匿名化等措施;可应用国家数据标签标识技术;鼓励通过个人信息保护认证。
  • 未成年人保护。 处理不满十四周岁未成年人个人信息应取得监护人同意,并提供便捷的同意与撤回渠道。
  • 国家身份服务。 鼓励应用国家网络身份认证公共服务。
  • 监测与响应。 围绕处理活动、权利响应、安全义务建立健全内部管理制度与操作规程,加强监测预警,及时发现处置安全事件。
  • 国际参与。 鼓励参与个人信息保护国际标准和规则制定,推动与其他国家、地区规则标准协调互认。

征求意见时间与程序

网信办通知设定意见反馈截止时间为2026年9月7日。可通过电子邮件发送至 shujuju@cac.gov.cn,或邮寄至北京市海淀区阜成路15号国家互联网信息办公室网络数据管理局(信封注明”大型个人信息处理者个人信息保护规定征求意见”)。该稿尚处征求意见阶段,最终义务、认定表单与时间表可能调整,但方向明确:最大数据持有者的责任正在制度化。

外资平台实操步骤

  1. 测算足迹。 量化在华处理的自然人个人信息数量;若接近或高于1000万,应假定自身落入范围。
  2. 评估定性触发条件。 即便低于1000万,具有系统性触达的多线消费业务也应自评估”重要性”与”影响”两项。
  3. 预先准备申报。 备妥认定申报材料(数据规模证据、处理活动说明、保障措施设计),以便在触发时及时提交。
  4. 夯实基线。 对静态与传输中数据加密、去标识化,按最小权限限制访问,并建立未成年人同意工作流。
  5. 参与征求意见。 在集团政策允许范围内,于2026年9月7日前通过认可的行业协会议事渠道提交意见。

Practitioner Quick Reference

  • One regime, broader reach: the draft folds two platform rules into a single “large processor” regime covering 10M+ individuals or systemic-impact handlers.
    一项制度、更广覆盖:该稿将两份平台规则整合为覆盖1000万以上或具系统影响处理者的”大型处理者”制度。
  • File through the province: recognition applications go via the provincial cyberspace authority to the national CAC; completeness check is 15 working days.
    经省级申报:认定申请由省级网信部门报送国家网信办;完备性查验为15个工作日。
  • Deadline 7 September 2026: the consultation window is the time to assess and, if eligible, comment.
    截止2026年9月7日:征求意见窗口是评估并(如符合)提交意见的时机。
  • Baseline must rise: minimisation, encryption, de-identification, access control and minor-consent are explicit duties.
    基线须抬高:最小必要、加密、去标识化、访问控制与未成年人同意均为明示义务。

Common Pitfalls

  • Assuming “platform” only means social media: the test reaches any processor at 10M individuals or with systemic impact, including e-commerce and on-demand apps.
    误以为”平台”仅指社交媒体:测试覆盖任意达1000万或具系统影响的处理者,含电商与按需服务App。
  • Waiting for the final text: the recognition filing and safeguard build-out take months; starting during consultation is cheaper than scrambling after promulgation.
    等待终稿:认定申报与保障体系建设需数月;在征求意见期启动比颁布后仓促应对更划算。
  • Treating PIPL compliance as sufficient: the draft adds duties (minimisation, national identity service, minor workflows) beyond the PIPL baseline.
    以为符合个保法即足够:该稿新增了超出个保法基线的义务(最小必要、国家身份服务、未成年人流程)。

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *