Lighter compliance for small processors: CAC-MPS Provisions effective 1 September 2026
- The Cyberspace Administration of China (CAC) and the Ministry of Public Security jointly issued the Provisions on Simplified Personal Information Protection Measures for Small-Scale Personal Information Processors (Order No. 25), published 24 July 2026 and effective 1 September 2026.
国家互联网信息办公室、公安部联合公布《小型个人信息处理者个人信息保护简化措施规定》(第25号令),2026年7月24日发布,自2026年9月1日起施行。
- A “small-scale personal information processor” is defined as a processor currently handling the personal information of fewer than 100,000 individuals in China; the count is based on deduplicated natural persons and excludes information already deleted.
“小型个人信息处理者”被界定为在中国境内当前处理不满10万人个人信息的个人信息处理者;人数按去重后的自然人统计,已删除的个人信息不计入。
- The core simplification: the mandatory content of a personal-information processing rule is trimmed, and rule publication and the duty to inform may be satisfied by simpler means — an on-site notice for offline operators, or service agreements, pop-ups or website announcements for online collection.
核心简化在于:个人信息处理规则必备内容被精简;规则的公开与告知义务可通过更简便方式履行——线下经营者在经营场所醒目位置张贴公告即可,线上收集信息可通过服务协议、弹窗或网站公告等方式公开。
- Where a platform has already set rules and completed compliance audits and impact assessments covering its merchants’ processing, platform merchants need not duplicate that work — a major relief for small online sellers.
若平台已针对商户的个人信息处理活动制定规则并完成合规审计与影响评估,依托平台经营的小微商户可直接沿用,无需重复开展——这对小型网店是重大减负。
- Small-scale processors that transfer personal information abroad for ordinary cross-border shopping or payment needs are exempt from applying for security assessment, signing standard contracts or passing certification, subject to the stated conditions.
小型处理者因跨境购物、跨境支付等常见业务向境外提供个人信息的,在符合规定条件的情况下,免予申报数据出境安全评估、订立标准合同或通过认证。
- For foreign-invested SMEs and small app developers in China, the Provisions turn the PIPL’s heavy one-size-fits-all machinery into a proportionate regime — but the underlying duties (consent, minimum necessary, security) remain intact: simplification lowers text and process burden, not the protection baseline.
对在华外资中小企业与小型应用开发者而言,本规定把《个人信息保护法》沉重的”一刀切”机制转化为更成比例的规则——但同意、最小必要、安全保障等底层义务不变:简化降低的是文本与程序负担,而非保护底线。
Lighter compliance for small processors: CAC-MPS Provisions effective 1 September 2026 | 小型个人信息处理者”轻装合规”:网信办、公安部第25号令9月1日施行
Overview
On 24 July 2026 the Cyberspace Administration of China (CAC) and the Ministry of Public Security (MPS) published Order No. 25 — the Provisions on Simplified Personal Information Protection Measures for Small-Scale Personal Information Processors (小型个人信息处理者个人信息保护简化措施规定). The Provisions take effect on 1 September 2026.
They are the first dedicated departmental rule issued under Article 62 of the Personal Information Protection Law (PIPL), which authorised the CAC to make special rules and standards for small-scale processors. The policy aim is stated in Article 1: to support innovation and development of small and medium-sized enterprises by simplifying the measures through which small-scale processors perform their personal information protection obligations, while keeping the law’s safety baseline intact.
Who qualifies
Article 2 defines a small-scale personal information processor as a processor currently handling the personal information of fewer than 100,000 individuals within China. The headcount is the number of deduplicated natural persons whose information the enterprise is currently processing — customers, users, employees and job applicants combined — excluding personal information that has already been deleted. Enterprises above the threshold continue to operate under the general PIPL regime; those at or above a much larger scale (to be classified separately as large processors) face stricter obligations.
For a foreign-invested company, the practical question is whether each China entity qualifies on its own numbers. A small WFOE running a niche e-commerce store or a small app may sit under 100,000; a group entity consolidating data from a large user base will not.
What is simplified
1. The processing rule itself
The mandatory content of a personal-information processing rule is trimmed to the core items — the processor’s name; the department or person receiving individuals’ rights requests with contact details; and the purposes, methods, categories and retention periods of processing. Two points stand out:
- A processor handling the personal information of minors under 14 must still formulate a dedicated rule.
- Publication and the duty to inform can be met by lighter means: an offline operator may post a notice in a conspicuous place at its premises; online collection may be disclosed through service agreements, pop-ups or website announcements. Industry parks, industrial bases and commercial property managers may draft one unified rule for identical offline businesses in their area, and operators who agree to comply need not each draft their own.
2. No duplication where a platform leads
If a merchant operates on an internet platform and the platform has already formulated rules for merchants’ processing activities and completed the compliance audit and impact assessment, the merchant may follow the platform’s work directly instead of repeating it. This removes the most onerous compliance items for the large population of small online sellers and mini-program merchants whose data processing is effectively governed by the platform.
3. Data-outbound relief
Small-scale processors transferring personal information abroad for ordinary business such as cross-border shopping and cross-border payment are, under the stated conditions, exempt from applying for a data-outbound security assessment, signing standard contracts, or passing personal-information protection certification. This avoids requiring businesses to run a full risk assessment on each low-risk flow, protecting their normal operations.
4. Audit and impact assessment
Compliance audits may be conducted at intervals of at least five years (against the PIPL general rule of periodic audits), and impact assessments may be carried out using simplified forms — with the annexes providing a self-check table for compliance audits and a simplified assessment form for impact assessments.
5. Lenient enforcement
The Provisions carry forward the “first-violation leniency” spirit of the Administrative Penalty Law: where a violation is minor and promptly corrected with no harmful consequences, no penalty is imposed; and a first-time violation with minor consequences that is promptly corrected may also go unpunished. Notification duties on security incidents and deletion after service termination are confirmed, and supervisory authorities may provide infrastructure, tools and advisory services to lower compliance costs.
What is NOT simplified
The simplification is procedural and textual, not substantive. Small-scale processors must still:
- obtain consent on a lawful basis and provide special separate consent where sensitive personal information is processed for a specific purpose, informing the individual of the necessity and the impact on their rights and interests;
- observe the minimum-necessary principle in collection;
- implement security measures appropriate to their scale, with the underlying duties in the PIPL and the Network Data Security Management Regulations intact; and
- support individuals’ rights requests — access, correction, deletion, and the right to withdraw consent — through the receiving channel they must name in their rule.
Regulators were explicit in commentary that the goal is “burden reduction without responsibility reduction” (减负不减责): lighter paperwork, unchanged bottom line.
What foreign-invested SMEs should do
For foreign-invested small and medium enterprises, small app developers and WeChat-mini-program merchants in China, the September deadline is a good moment to re-baseline:
- Confirm status. Count the deduplicated individuals whose data you currently process. If under 100,000, your China entity qualifies for the simplified regime.
- Update the processing rule. Rewrite the rule to the trimmed mandatory content and publish it through the lightest valid channel (premises notice, service agreement, pop-up or website announcement). If you handle under-14 data, keep the dedicated minor rule.
- Check the platform route. If you sell through a platform, confirm whether the platform’s rule, audit and impact assessment cover your activities; if so, do not duplicate the work — but document the reliance.
- Review outbound flows. Map any transfers of personal information abroad for cross-border shopping or payment. If you meet the exemption conditions, keep the evidence; if a flow falls outside the exemption, the ordinary assessment/standard-contract/certification routes still apply.
- Schedule the lighter audit. Plan a compliance audit on the permitted five-year-plus cycle and use the annex self-check tables so the record is ready if asked.
- Keep the baseline duties working. Consent records, minimum-necessary collection, security measures and rights-request handling do not disappear; simplification only changes how the paperwork and the heavier procedural steps are performed.
Sources
- 国家互联网信息办公室(中国网信网) — 《小型个人信息处理者个人信息保护简化措施规定》全文(国家网信办、公安部令第25号): https://www.cac.gov.cn/2026-07/24/c_1786638889704872.htm
- 深圳市司法局 — 企业合规风险提示与预警信息【总第168期】(含本规定要点与合规建议): https://sf.sz.gov.cn/ztzl/hg/yjxx/zxxx/content/post_12948595.html
- 中工网/法治日报 — 减负不减责 守牢个人信息保护底线(评论解读): https://www.workercn.cn/c/2026-09-02/8883756.shtml
Related reading
- see also: China’s data-outbound negative list goes live — 2026 milestones and a compliance route map (360-data-outbound-negative-list)
- see also: Network data security risk assessment — the new annual obligation (305-network-data-security-risk-assessment)
小型个人信息处理者”轻装合规”:网信办、公安部第25号令9月1日施行
概述
2026年7月24日,国家互联网信息办公室与公安部联合公布《小型个人信息处理者个人信息保护简化措施规定》(第25号令),自2026年9月1日起施行。
这是《个人信息保护法》第六十二条授权国家网信部门针对小型个人信息处理者制定专门规则、标准后出台的首部配套部门规章。第一条即点明政策目标:支持中小微企业创新发展,简化小型个人信息处理者履行个人信息保护义务的措施,同时不突破法律安全底线。
谁算”小型”
第二条规定,小型个人信息处理者是指在中国境内当前处理不满10万人个人信息的个人信息处理者。人数按去重后的自然人统计——把企业当前仍在处理的客户、用户、员工、求职者等信息去重后合计,已删除的个人信息不计入。超过该门槛的企业继续适用一般个保制度;规模更大的处理者将被另行划分为大型个人信息处理者,承担更重义务。
对外资企业而言,实操问题是判断每个中国法律实体是否以自身数据规模达标。经营小众网店或小型应用的小型外资企业可能落在10万人之下;整合大规模用户数据的集团实体则不满足。
简化了什么
一、处理规则本身
个人信息处理规则必备内容被精简为三类核心事项——处理者名称;受理个人行权请求的部门或人员及联系方式;处理目的、方式、种类、保存期限等。两点值得注意:
- 处理不满14周岁未成年人个人信息的,仍须制定专门规则。
- 规则的公开与告知可用更简便方式履行:线下经营者在经营场所醒目位置张贴公告即可;线上收集信息可通过服务协议、弹窗或网站公告等方式公开。园区、产业基地、商业物业等可为区域内开展相同线下业务的小型处理者统一制定规则,经营者同意遵守的无需各自起草。
二、平台主导时不重复
若商户依托互联网平台经营,且平台已针对商户的个人信息处理活动制定规则并完成合规审计和影响评估,则商户可直接沿用,无需重复开展。这为数量庞大的小型网店与小程序商家卸下了最重的合规环节——他们的数据处理实际上由平台规则统辖。
三、数据出境豁免
小型处理者因跨境购物、跨境支付等常见业务向境外提供个人信息的,在符合规定条件的情况下,免予申报数据出境安全评估、订立标准合同或通过个人信息保护认证。这避免企业就每一笔低风险业务单独跑完整评估,保障其正常经营。
四、审计与影响评估
合规审计可以”至少每五年一次”的节奏开展(对照个保法一般性的定期审计要求),影响评估可用简化表进行——附件提供了《小型个人信息处理者个人信息保护合规审计自查表》和《小型个人信息处理者个人信息保护影响评估表》。
五、柔性执法
本规定将行政处罚法的”首违不罚”精神落实到个人信息保护领域:违法行为轻微并及时改正、未造成危害后果的,不予处罚;初次违法且危害后果轻微并及时改正的,也可以不予处罚。规定还确认了安全事件通知、停止服务后删除等义务,并鼓励监管部门为小型处理者提供基础设施、技术工具与咨询服务以降低合规成本。
什么没有被简化
简化的是程序与文本负担,不是实质义务。小型个人信息处理者仍须:
- 依法取得同意;因特定目的处理敏感个人信息的,须取得单独同意,并告知处理敏感个人信息的必要性及对个人权益的影响;
- 坚持最小必要原则采集;
- 实施与自身规模相适应的安全措施,《个人信息保护法》与《网络数据安全管理条例》的底层义务不变;
- 通过处理规则中必须载明的受理渠道,支持个人的查阅、复制、更正、删除与撤回同意等权利请求。
监管口径对此反复强调”减负不减责“:文本更轻,底线不变。
外资中小企业该做什么
对在华外资中小企业、小型应用开发者和微信小程序商家而言,9月1日是一个重新对齐基准的好时点:
- 确认资格。 统计当前正在处理(去重后)的自然人数量。若不足10万人,中国实体即适用简化制度。
- 更新处理规则。 按精简后的必备内容改写规则,并通过最简便的有效渠道公开(经营场所公告、服务协议、弹窗或网站公告)。若涉及未满14周岁信息,保留专门规则。
- 走平台通道。 若通过平台销售,确认平台的规则、审计与影响评估是否覆盖你的活动;若已覆盖,不必重复,但应留存依赖依据。
- 复核出境流。 梳理任何因跨境购物、支付而向境外提供个人信息的情形。满足豁免条件的留存证据;不在豁免范围内的流动,仍走普通评估/标准合同/认证路径。
- 安排轻量审计。 按允许的五年以上周期规划合规审计,使用附件自查表,确保需要时可随时出示记录。
- 守住底线义务。 同意记录、最小必要采集、安全措施与行权响应不会消失;简化只改变文书与更重程序环节的履行方式。
来源
- 国家互联网信息办公室(中国网信网) — 《小型个人信息处理者个人信息保护简化措施规定》全文(国家网信办、公安部令第25号): https://www.cac.gov.cn/2026-07/24/c_1786638889704872.htm
- 深圳市司法局 — 企业合规风险提示与预警信息【总第168期】(含本规定要点与合规建议): https://sf.sz.gov.cn/ztzl/hg/yjxx/zxxx/content/post_12948595.html
- 中工网/法治日报 — 减负不减责 守牢个人信息保护底线(评论解读): https://www.workercn.cn/c/2026-09-02/8883756.shtml
相关阅读
- 见:数据出境负面清单落地——2026年里程碑与合规路径图(360-data-outbound-negative-list)
- 见:网络数据安全风险评估——重要数据处理者新增年度义务(305-network-data-security-risk-assessment)