A covered app that processes personal information generally needs both tracks. identifies the app and its sponsor before a new app starts service; the app privacy rules govern whether and how the app may process personal information. Filing does not authorize data collection, and a compliant privacy notice does not replace filing. Existing apps were due to complete filing by the end of March 2024, and filing has been a normal ongoing requirement since July 2024.
Comparison
Mobile app filing vs App personal information rules
Use both tracks for most China app launches: filing records who operates the app, while personal-information rules control what the app collects and how it processes that information.
The MIIT notice covers apps that provide internet information services in China and expressly includes app distribution forms such as mini-programs and quick apps.
The 2021 necessary-information provisions apply to operators of covered mobile app types. PIPL and the 2022 app-service provisions apply more broadly when an app processes personal information or provides app information services in China.
A covered app that processes personal information normally needs both analyses. Neither filing nor the 39-type list displaces sector-specific permits or other data rules.
The submits through its network access service provider or distribution platform to the provincial communications administration for the sponsor's place of residence.
The app provider or owns the processing decision. Distribution platforms verify provider identity and app information and perform their own management duties.
Perform both checks before the first China release and repeat them for changes to the sponsor, app identity, network resources, features, data fields, permissions, or third parties.
Submit complete and accurate filing material. When the provincial authority receives compliant material, the MIIT notice provides a 20-working-day filing period and issuance of a public filing number.
Identify the processing purpose and basis, give the required notice, obtain consent where the applicable rule requires it, minimize collection, protect , support individual rights, and do not make basic service conditional on unnecessary information.
Put the filing number and privacy release approval in separate release gates. A filing number says nothing about whether a permission or data field is lawful or necessary.
Retain the submitted filing form, sponsor and service-provider records, domain and IP evidence, filing number, public-record check, distribution records, and later update submissions.
Retain the app-type and basic-function decision, data and permission inventory, necessity rationale, privacy notice versions, consent records, sensitive-information controls, review, rights requests, and any required personal information protection impact assessment.
The 2023 notice set September 2023 through March 2024 for existing-app filing, April through June 2024 for inspections, and July 2024 onward for normal supervision. New apps file before service.
The necessary-information provisions took effect on 1 May 2021, the app-service provisions on 1 August 2022, and PIPL on 1 November 2021. These are continuing duties, not annual filing dates.
Communications authorities inspect filing information, and access providers, platforms, and device manufacturers are expected to manage apps they connect, distribute, or preinstall. Consequences depend on the applicable underlying law and failure.
CAC and other competent authorities may act on unlawful processing or app-service failures under PIPL and related rules. The 2021 provisions specifically prohibit denying basic functions because a user refuses unnecessary personal information.
Maintain one product inventory with two linked decisions. Do not copy the filing approval into the privacy field or treat privacy approval as evidence of filing.
Run the filing track when an app, mini-program, or quick app will provide internet information services in China or its filed identity or network details change.
Run the personal-information track whenever the app processes personal information or changes a feature, permission, , recipient, retention period, or transfer route.
The MIIT notice covers apps that provide internet information services in China and expressly includes app distribution forms such as mini-programs and quick apps.
The 2021 necessary-information provisions apply to operators of covered mobile app types. PIPL and the 2022 app-service provisions apply more broadly when an app processes personal information or provides app information services in China.
A covered app that processes personal information normally needs both analyses. Neither filing nor the 39-type list displaces sector-specific permits or other data rules.
The submits through its network access service provider or distribution platform to the provincial communications administration for the sponsor's place of residence.
The app provider or owns the processing decision. Distribution platforms verify provider identity and app information and perform their own management duties.
Perform both checks before the first China release and repeat them for changes to the sponsor, app identity, network resources, features, data fields, permissions, or third parties.
Submit complete and accurate filing material. When the provincial authority receives compliant material, the MIIT notice provides a 20-working-day filing period and issuance of a public filing number.
Identify the processing purpose and basis, give the required notice, obtain consent where the applicable rule requires it, minimize collection, protect , support individual rights, and do not make basic service conditional on unnecessary information.
Put the filing number and privacy release approval in separate release gates. A filing number says nothing about whether a permission or data field is lawful or necessary.
Retain the submitted filing form, sponsor and service-provider records, domain and IP evidence, filing number, public-record check, distribution records, and later update submissions.
Retain the app-type and basic-function decision, data and permission inventory, necessity rationale, privacy notice versions, consent records, sensitive-information controls, review, rights requests, and any required personal information protection impact assessment.
The 2023 notice set September 2023 through March 2024 for existing-app filing, April through June 2024 for inspections, and July 2024 onward for normal supervision. New apps file before service.
The necessary-information provisions took effect on 1 May 2021, the app-service provisions on 1 August 2022, and PIPL on 1 November 2021. These are continuing duties, not annual filing dates.
Communications authorities inspect filing information, and access providers, platforms, and device manufacturers are expected to manage apps they connect, distribute, or preinstall. Consequences depend on the applicable underlying law and failure.
CAC and other competent authorities may act on unlawful processing or app-service failures under PIPL and related rules. The 2021 provisions specifically prohibit denying basic functions because a user refuses unnecessary personal information.
Maintain one product inventory with two linked decisions. Do not copy the filing approval into the privacy field or treat privacy approval as evidence of filing.
Run the filing track when an app, mini-program, or quick app will provide internet information services in China or its filed identity or network details change.
Run the personal-information track whenever the app processes personal information or changes a feature, permission, , recipient, retention period, or transfer route.
File before a new covered app begins service; for an already filed website sponsor, confirm which sponsor details can be reused and which app details must be added.
Map the app's , personal-information fields, permissions, SDKs, notices, consent flows, and refusal behavior against the 2021 provisions, the 2022 app-service provisions, and PIPL.
Release only after the filing record matches the production app and the privacy evidence matches the production data flows.
First confirm whether the app, mini-program, or quick app provides internet information services in China and identify the . A new covered app must complete filing before providing service. An app that already had an ICP filing generally supplements its app details rather than resubmitting the sponsor's identity information.
Then classify the app's and map every personal-information field and device permission. The 2021 necessary-information provisions list 39 common app types and the for their basic functions. An app may offer additional functions, but it may not refuse the basic function solely because a user declines personal information that is not necessary for that function.
A map and navigation app may need location, departure point, and destination for its . An online-shopping app may need a registered mobile number, recipient name, address and telephone number, and payment details. The listed basic functions for online video, short video, news browsing, browsers, input methods, app stores, photography tools, and utility apps such as calculators, flashlights, document tools, and smart-home assistants require no personal information. These examples set the no-refusal boundary for the listed basic function; they do not ban processing for a separate optional function when another lawful basis and the required notice or consent exist.
Apply the broader Personal Information Protection Law and the 2022 app-service provisions as well. First identify the and for each purpose. Consent is one PIPL basis, not the only one; separate consent is required for specified processing such as and provision to another processor, unless another rule changes the result. The laws also govern notice, individual rights, security controls, impact assessments, and app-distribution-platform verification. The 2021 list is a minimum-necessity rule, not a complete privacy checklist.
Filing owner: retain sponsor identity, app name and icon, domain and IP details, service-provider details, filing number, submission record, and material-change updates.
Privacy owner: retain the app-type decision, data and permission inventory, purpose and necessity analysis, , notice and consent records, and third-party disclosures, rights handling, and impact assessments where required. PIPL impact-assessment reports and processing records must be kept for at least three years.
Release owner or app store: block launch when filing is missing or the tested build collects data outside the approved privacy design.
Use for app provider and app distribution platform governance, content/security/data duties, platform filing and verification, and 1 August 2022 effective date.