CybersecurityChina

China app filing vs personal information rules

A China app can need MIIT filing and separate privacy controls. Completing one does not complete the other.

Use the filing track for the app's operating record and the privacy track for each data field, permission, notice, consent flow, and refusal rule.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 25, 2026
Sections
1

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 25, 2026
Overview

A covered app that processes personal information generally needs both tracks. identifies the app and its sponsor before a new app starts service; the app privacy rules govern whether and how the app may process personal information. Filing does not authorize data collection, and a compliant privacy notice does not replace filing. Existing apps were due to complete filing by the end of March 2024, and filing has been a normal ongoing requirement since July 2024.

Comparison

Mobile app filing vs App personal information rules

Use both tracks for most China app launches: filing records who operates the app, while personal-information rules control what the app collects and how it processes that information.

Review all sources
First framework
Mobile app filing

Use for the that identifies a covered app, its sponsor, network resources, and service-provider relationships before service begins.

Second framework
App personal information rules

Use for data minimization, notice, , consent where required, sensitive-information safeguards, user rights, and app-platform governance.

Comparison row 1

Scope boundary

Mobile app filing

The MIIT notice covers apps that provide internet information services in China and expressly includes app distribution forms such as mini-programs and quick apps.

App personal information rules

The 2021 necessary-information provisions apply to operators of covered mobile app types. PIPL and the 2022 app-service provisions apply more broadly when an app processes personal information or provides app information services in China.

Operational implication

A covered app that processes personal information normally needs both analyses. Neither filing nor the 39-type list displaces sector-specific permits or other data rules.

Comparison row 2

Covered actors

Mobile app filing

The submits through its network access service provider or distribution platform to the provincial communications administration for the sponsor's place of residence.

App personal information rules

The app provider or owns the processing decision. Distribution platforms verify provider identity and app information and perform their own management duties.

Operational implication

Name a filing owner and a privacy owner. The same person may coordinate both, but the regulator, evidence, and release decision remain different.

Comparison row 3

Trigger event

Mobile app filing

A new covered app must file before providing service. The transition for apps already operating when the 2023 notice was issued ended in March 2024.

App personal information rules

Screen whenever a build collects, uses, stores, shares, or exports personal information, requests a device permission, adds an , or changes a .

Operational implication

Perform both checks before the first China release and repeat them for changes to the sponsor, app identity, network resources, features, data fields, permissions, or third parties.

Comparison row 4

Core obligations

Mobile app filing

Submit complete and accurate filing material. When the provincial authority receives compliant material, the MIIT notice provides a 20-working-day filing period and issuance of a public filing number.

App personal information rules

Identify the processing purpose and basis, give the required notice, obtain consent where the applicable rule requires it, minimize collection, protect , support individual rights, and do not make basic service conditional on unnecessary information.

Operational implication

Put the filing number and privacy release approval in separate release gates. A filing number says nothing about whether a permission or data field is lawful or necessary.

Comparison row 5

Evidence package

Mobile app filing

Retain the submitted filing form, sponsor and service-provider records, domain and IP evidence, filing number, public-record check, distribution records, and later update submissions.

App personal information rules

Retain the app-type and basic-function decision, data and permission inventory, necessity rationale, privacy notice versions, consent records, sensitive-information controls, review, rights requests, and any required personal information protection impact assessment.

Operational implication

Link both files to the same released build and version. A later feature or change can leave the filing unchanged while requiring a new privacy review.

Comparison row 6

Timing and refresh points

Mobile app filing

The 2023 notice set September 2023 through March 2024 for existing-app filing, April through June 2024 for inspections, and July 2024 onward for normal supervision. New apps file before service.

App personal information rules

The necessary-information provisions took effect on 1 May 2021, the app-service provisions on 1 August 2022, and PIPL on 1 November 2021. These are continuing duties, not annual filing dates.

Operational implication

Do not treat the expired transition as an exemption. Calendar filing updates and privacy reviews around actual product changes.

Comparison row 7

Enforcement exposure

Mobile app filing

Communications authorities inspect filing information, and access providers, platforms, and device manufacturers are expected to manage apps they connect, distribute, or preinstall. Consequences depend on the applicable underlying law and failure.

App personal information rules

CAC and other competent authorities may act on unlawful processing or app-service failures under PIPL and related rules. The 2021 provisions specifically prohibit denying basic functions because a user refuses unnecessary personal information.

Operational implication

Test the production build against both the filed identity and the approved data map before distribution, and preserve the dated result.

Comparison row 8

Overlap and routing

Mobile app filing

Filing and privacy reviews can share the app name, sponsor, package identity, service providers, domain, release version, and distribution channels.

App personal information rules

Only the privacy review determines whether particular data fields, permissions, transfers, retention periods, or cross-border transfers are permitted.

Operational implication

Maintain one product inventory with two linked decisions. Do not copy the filing approval into the privacy field or treat privacy approval as evidence of filing.

Comparison row 9

Practical decision rule

Mobile app filing

Run the filing track when an app, mini-program, or quick app will provide internet information services in China or its filed identity or network details change.

App personal information rules

Run the personal-information track whenever the app processes personal information or changes a feature, permission, , recipient, retention period, or transfer route.

Operational implication

For a normal consumer app launch in China, plan for both. Record a reason only when a track is found not to apply.

Practical decision rule

When to run one track or both

  • File before a new covered app begins service; for an already filed website sponsor, confirm which sponsor details can be reused and which app details must be added.
  • Map the app's , personal-information fields, permissions, SDKs, notices, consent flows, and refusal behavior against the 2021 provisions, the 2022 app-service provisions, and PIPL.
  • Release only after the filing record matches the production app and the privacy evidence matches the production data flows.
Section 1

How to use this comparison

First confirm whether the app, mini-program, or quick app provides internet information services in China and identify the . A new covered app must complete filing before providing service. An app that already had an ICP filing generally supplements its app details rather than resubmitting the sponsor's identity information.

Then classify the app's and map every personal-information field and device permission. The 2021 necessary-information provisions list 39 common app types and the for their basic functions. An app may offer additional functions, but it may not refuse the basic function solely because a user declines personal information that is not necessary for that function.

A map and navigation app may need location, departure point, and destination for its . An online-shopping app may need a registered mobile number, recipient name, address and telephone number, and payment details. The listed basic functions for online video, short video, news browsing, browsers, input methods, app stores, photography tools, and utility apps such as calculators, flashlights, document tools, and smart-home assistants require no personal information. These examples set the no-refusal boundary for the listed basic function; they do not ban processing for a separate optional function when another lawful basis and the required notice or consent exist.

Apply the broader Personal Information Protection Law and the 2022 app-service provisions as well. First identify the and for each purpose. Consent is one PIPL basis, not the only one; separate consent is required for specified processing such as and provision to another processor, unless another rule changes the result. The laws also govern notice, individual rights, security controls, impact assessments, and app-distribution-platform verification. The 2021 list is a minimum-necessity rule, not a complete privacy checklist.

  • Filing owner: retain sponsor identity, app name and icon, domain and IP details, service-provider details, filing number, submission record, and material-change updates.
  • Privacy owner: retain the app-type decision, data and permission inventory, purpose and necessity analysis, , notice and consent records, and third-party disclosures, rights handling, and impact assessments where required. PIPL impact-assessment reports and processing records must be kept for at least three years.
  • Release owner or app store: block launch when filing is missing or the tested build collects data outside the approved privacy design.
Primary sources

References and citations

Related guides

Explore more topics

China cybersecurity and data security requirements
China cybersecurity requirements by actor: network operators, data processors, CII operators, platforms, app providers, and distribution platforms.
China cybersecurity compliance checklist
A China cybersecurity checklist for scoping network duties, data security, CII procurement review, app rules, MIIT filing, and supporting standards.
China cybersecurity deadlines and compliance calendar
Separate China cybersecurity commencement dates from recurring duties, filing lead times, review periods, and event-driven response deadlines.
China Cybersecurity Law FAQ
Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.
China Cybersecurity Law vs EU Cyber Resilience Act
Compare China's network-operator rules with the EU CRA's product duties, including scope, actors, evidence, reporting dates, and launch decisions.
China Cybersecurity Law vs EU NIS2 Directive
Compare China's network-operator duties with NIS2 entity duties, including scope, management accountability, incident reporting, evidence, and enforcement.
China cybersecurity penalties and fines
Compare current China Cybersecurity Law and Data Security Law fines by actor, breach, severity, and enforcement consequence.
China Cybersecurity Review vs Data Export Assessment
Separate China's cybersecurity-review triggers from CAC data-export assessment triggers, thresholds, filings, evidence, timing, and reapplication rules.
China cybersecurity review workflow
Determine whether CII procurement, platform data processing, or a qualifying foreign listing triggers China's Cybersecurity Review Measures.
China mobile app filing and app governance
Identify the China app sponsor, complete MIIT filing before service, and separate provider, platform, privacy, content, and security duties.
China Smart-Home Security vs Telecom and Radio Approval
Separate GB/T 41387-2022 smart-home security evidence from China telecom network-access and radio approval decisions for connected products.
CII and network operator role triage
How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
Does an app need MIIT filing and CAC app governance review?
An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.
GB/T 22239-2019 classified protection baseline
How to scope and document a GB/T 22239-2019 classified protection baseline without treating the recommended standard as a standalone law.
GB/T 41387-2022 smart home security standard
How connected-device teams can scope and document GB/T 41387-2022 without treating it as an automatic certification or product-approval duty.
How do smart home security standards fit with China cybersecurity law?
GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.
How does important data change China cybersecurity obligations?
Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.
Is every company a network operator under China Cybersecurity Law?
No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.
MLPS classified protection evidence map
Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence.
What is MLPS classified protection evidence?
MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.
When does China cybersecurity review apply?
China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.