---
title: "China App Filing vs Personal Information Rules"
canonical_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/mobile-app-filing-vs-app-personal-information-rules"
source_url: "https://www.sorena.io/artifacts/apac/china-cybersecurity-law/mobile-app-filing-vs-app-personal-information-rules"
author: "Sorena AI"
description: "Decide whether a China mobile app needs MIIT filing, personal-information controls, or both, with current triggers, duties, dates, and evidence."
published_at: "2026-07-05"
updated_at: "2026-07-25"
keywords:
  - "China Cybersecurity Law"
  - "Data Security Law"
  - "Cybersecurity Review Measures"
  - "Mobile app filing"
  - "MLPS"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# China App Filing vs Personal Information Rules

Decide whether a China mobile app needs MIIT filing, personal-information controls, or both, with current triggers, duties, dates, and evidence.

*Cybersecurity* *China*

## China app filing vs personal information rules

A China app can need MIIT filing and separate privacy controls. Completing one does not complete the other.

Use the filing track for the app's operating record and the privacy track for each data field, permission, notice, consent flow, and refusal rule.

A covered app that processes personal information generally needs both tracks. MIIT filing identifies the app and its sponsor before a new app starts service; the app privacy rules govern whether and how the app may process personal information. Filing does not authorize data collection, and a compliant privacy notice does not replace filing. Existing apps were due to complete filing by the end of March 2024, and filing has been a normal ongoing requirement since July 2024.

## Definitions

### MIIT mobile app filing

**Term:** MIIT filing

MIIT filing is the pre-service record required for an app organizer providing app internet information services in China. The organizer submits its identity, app, network-resource, and related information through a network access provider or app distribution platform to the provincial communications administration where the organizer is domiciled.

**Why it matters here:** A filing number identifies the organizer and filed app; it is not a privacy approval, content licence, security certification, or authorization to collect personal information. New covered apps file before service, and changes or cancellation go to the original filing authority.

Sources:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io)

### App sponsor or organizer

**Term:** app sponsor

The app sponsor is the organization or individual responsible for the app internet information service and named in the MIIT filing. The official notice uses the Chinese actor label commonly translated as app organizer or sponsor.

**Why it matters here:** The sponsor must provide truthful filing material, display and link the filing number, and file changes or cancellation. A network access provider or distribution platform verifies and submits information but does not replace the sponsor's responsibility.

Sources:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io)

### Personal information processor

A personal information processor is the organization or individual that independently decides the purposes and methods of personal-information processing. This PIPL role is similar to a controller in some other privacy laws, but the duties and terminology come from Chinese law.

**Why it matters here:** Identify the processor for each app data flow. A sponsor, app provider, SDK provider, platform, or other party may be a processor, joint processor, or entrusted processor depending on who decides the purpose and method; the contract label alone does not settle the role.

Sources:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io)

### Necessary personal information for an app's basic function

**Term:** necessary personal information

Necessary personal information is the consumer-side personal information without which an app cannot provide its defined basic function. The 2021 provisions state the basic function and allowed necessary fields for 39 common app types; they do not declare every listed field necessary for every optional feature or every app with a similar marketing label.

**Why it matters here:** A covered app may not deny its basic function because a user refuses non-necessary personal information. Record the app type, basic function, each field, and why the function cannot operate without that field.

Sources:

- [Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io)

### App basic function

**Term:** basic function

A basic function is the core service assigned to a common app type by the 2021 necessary-information provisions, such as location and navigation for a map app or purchasing goods for an online-shopping app. Optional personalization, marketing, analytics, or convenience features do not become basic merely because they appear in the same app.

**Why it matters here:** The selected basic function sets the no-refusal test and the listed necessary-information ceiling for that function. A multi-function app may need a separate analysis for each service rather than one blanket category.

Sources:

- [Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io)

### Sensitive personal information

Sensitive personal information is information that, if leaked or illegally used, could readily harm a person's dignity or personal or property safety. PIPL examples include biometric, religious-belief, specific-identity, medical-health, financial-account, and precise-location or movement information, plus all personal information of children under 14.

**Why it matters here:** An app may process it only for a specific purpose with sufficient necessity and strict safeguards. PIPL generally requires separate consent, additional notice about necessity and impact, and a prior personal information protection impact assessment.

Sources:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io)

### Software development kit

**Term:** SDK

An SDK is a bundle of code and tools integrated into an app to provide a function such as analytics, advertising, maps, payments, messaging, or crash reporting. It can collect or transmit personal information from the production app even when the app team did not write that code.

**Why it matters here:** Inventory each SDK by version, provider, purpose, data fields, device permissions, recipients, network destinations, retention, and update behaviour. Determine the parties' PIPL roles and processing basis instead of treating the SDK vendor's documentation as release approval.

Sources:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io)
- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io)

### PIPL processing basis

**Term:** processing basis

A processing basis is the Article 13 condition that permits a personal information processor to process information. Consent is one basis; others include necessity for a contract with the individual, qualifying human-resources management, a legal duty, an emergency, limited public-interest news or supervision, and reasonable processing of lawfully public information.

**Why it matters here:** Do not build every app flow around consent by default. Document the applicable basis for each purpose, give the required notice, and obtain separate or written consent where PIPL or another rule specifically requires it.

Sources:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io)

## Mobile app filing vs App personal information rules

Use both tracks for most China app launches: filing records who operates the app, while personal-information rules control what the app collects and how it processes that information.

- **Mobile app filing**: Use for the MIIT filing that identifies a covered app, its sponsor, network resources, and service-provider relationships before service begins.
- **App personal information rules**: Use for data minimization, notice, processing basis, consent where required, sensitive-information safeguards, user rights, and app-platform governance.

| Dimension | Mobile app filing | App personal information rules | Operational implication | Sources |
| --- | --- | --- | --- | --- |
| Scope boundary | The MIIT notice covers apps that provide internet information services in China and expressly includes app distribution forms such as mini-programs and quick apps. | The 2021 necessary-information provisions apply to operators of covered mobile app types. PIPL and the 2022 app-service provisions apply more broadly when an app processes personal information or provides app information services in China. | A covered app that processes personal information normally needs both analyses. Neither filing nor the 39-type list displaces sector-specific permits or other data rules. | [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for MIIT mobile app filing phases, registration, supervision, normalization, and operational filing evidence.<br>[Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Use for app category, basic-function, minimum necessary personal information, no-refusal rule, and 1 May 2021 effective date.<br>[PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Use for processing bases, notice, consent, sensitive personal information, individual rights, processor duties, impact assessments, and 1 November 2021 effective date. |
| Covered actors | The app sponsor submits through its network access service provider or distribution platform to the provincial communications administration for the sponsor's place of residence. | The app provider or personal information processor owns the processing decision. Distribution platforms verify provider identity and app information and perform their own management duties. | Name a filing owner and a privacy owner. The same person may coordinate both, but the regulator, evidence, and release decision remain different. | [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for MIIT mobile app filing phases, registration, supervision, normalization, and operational filing evidence.<br>[Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Use for app category, basic-function, minimum necessary personal information, no-refusal rule, and 1 May 2021 effective date.<br>[PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Use for processing bases, notice, consent, sensitive personal information, individual rights, processor duties, impact assessments, and 1 November 2021 effective date. |
| Trigger event | A new covered app must file before providing service. The transition for apps already operating when the 2023 notice was issued ended in March 2024. | Screen whenever a build collects, uses, stores, shares, or exports personal information, requests a device permission, adds an SDK, or changes a basic function. | Perform both checks before the first China release and repeat them for changes to the sponsor, app identity, network resources, features, data fields, permissions, or third parties. | [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for MIIT mobile app filing phases, registration, supervision, normalization, and operational filing evidence.<br>[Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Use for app category, basic-function, minimum necessary personal information, no-refusal rule, and 1 May 2021 effective date.<br>[PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Use for processing bases, notice, consent, sensitive personal information, individual rights, processor duties, impact assessments, and 1 November 2021 effective date. |
| Core obligations | Submit complete and accurate filing material. When the provincial authority receives compliant material, the MIIT notice provides a 20-working-day filing period and issuance of a public filing number. | Identify the processing purpose and basis, give the required notice, obtain consent where the applicable rule requires it, minimize collection, protect sensitive personal information, support individual rights, and do not make basic service conditional on unnecessary information. | Put the filing number and privacy release approval in separate release gates. A filing number says nothing about whether a permission or data field is lawful or necessary. | [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for MIIT mobile app filing phases, registration, supervision, normalization, and operational filing evidence.<br>[Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Use for app category, basic-function, minimum necessary personal information, no-refusal rule, and 1 May 2021 effective date.<br>[PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Use for processing bases, notice, consent, sensitive personal information, individual rights, processor duties, impact assessments, and 1 November 2021 effective date. |
| Evidence package | Retain the submitted filing form, sponsor and service-provider records, domain and IP evidence, filing number, public-record check, distribution records, and later update submissions. | Retain the app-type and basic-function decision, data and permission inventory, necessity rationale, privacy notice versions, consent records, sensitive-information controls, SDK review, rights requests, and any required personal information protection impact assessment. | Link both files to the same released build and version. A later feature or SDK change can leave the filing unchanged while requiring a new privacy review. | [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for MIIT mobile app filing phases, registration, supervision, normalization, and operational filing evidence.<br>[Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Use for app category, basic-function, minimum necessary personal information, no-refusal rule, and 1 May 2021 effective date.<br>[PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Use for processing bases, notice, consent, sensitive personal information, individual rights, processor duties, impact assessments, and 1 November 2021 effective date. |
| Timing and refresh points | The 2023 notice set September 2023 through March 2024 for existing-app filing, April through June 2024 for inspections, and July 2024 onward for normal supervision. New apps file before service. | The necessary-information provisions took effect on 1 May 2021, the app-service provisions on 1 August 2022, and PIPL on 1 November 2021. These are continuing duties, not annual filing dates. | Do not treat the expired transition as an exemption. Calendar filing updates and privacy reviews around actual product changes. | [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for MIIT mobile app filing phases, registration, supervision, normalization, and operational filing evidence.<br>[Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Use for app category, basic-function, minimum necessary personal information, no-refusal rule, and 1 May 2021 effective date.<br>[PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Use for continuing personal-information duties and the 1 November 2021 effective date. |
| Enforcement exposure | Communications authorities inspect filing information, and access providers, platforms, and device manufacturers are expected to manage apps they connect, distribute, or preinstall. Consequences depend on the applicable underlying law and failure. | CAC and other competent authorities may act on unlawful processing or app-service failures under PIPL and related rules. The 2021 provisions specifically prohibit denying basic functions because a user refuses unnecessary personal information. | Test the production build against both the filed identity and the approved data map before distribution, and preserve the dated result. | [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for MIIT mobile app filing phases, registration, supervision, normalization, and operational filing evidence.<br>[Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Use for app category, basic-function, minimum necessary personal information, no-refusal rule, and 1 May 2021 effective date.<br>[PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Use for supervisory powers, corrective measures, and penalties tied to unlawful personal-information processing. |
| Overlap and routing | Filing and privacy reviews can share the app name, sponsor, package identity, service providers, domain, release version, and distribution channels. | Only the privacy review determines whether particular data fields, permissions, SDK transfers, retention periods, or cross-border transfers are permitted. | Maintain one product inventory with two linked decisions. Do not copy the filing approval into the privacy field or treat privacy approval as evidence of filing. | [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for MIIT mobile app filing phases, registration, supervision, normalization, and operational filing evidence.<br>[Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Use for app category, basic-function, minimum necessary personal information, no-refusal rule, and 1 May 2021 effective date.<br>[PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Use for processing decisions involving data fields, recipients, retention, and cross-border transfers. |
| Practical decision rule | Run the filing track when an app, mini-program, or quick app will provide internet information services in China or its filed identity or network details change. | Run the personal-information track whenever the app processes personal information or changes a feature, permission, SDK, recipient, retention period, or transfer route. | For a normal consumer app launch in China, plan for both. Record a reason only when a track is found not to apply. | [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for MIIT mobile app filing phases, registration, supervision, normalization, and operational filing evidence.<br>[Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Use for app category, basic-function, minimum necessary personal information, no-refusal rule, and 1 May 2021 effective date.<br>[PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Use for the broader personal-information processing trigger and lifecycle duties. |

Sources for Scope boundary - Mobile app filing:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for MIIT mobile app filing phases, registration, supervision, normalization, and operational filing evidence.

Sources for Scope boundary - App personal information rules:

- [Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Use for app category, basic-function, minimum necessary personal information, no-refusal rule, and 1 May 2021 effective date.
- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Use for processing bases, notice, consent, sensitive personal information, individual rights, processor duties, impact assessments, and 1 November 2021 effective date.

Sources for Scope boundary - operational implication:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for MIIT mobile app filing phases, registration, supervision, normalization, and operational filing evidence.
- [Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Use for app category, basic-function, minimum necessary personal information, no-refusal rule, and 1 May 2021 effective date.
- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Use for processing bases, notice, consent, sensitive personal information, individual rights, processor duties, impact assessments, and 1 November 2021 effective date.

Sources for Covered actors - Mobile app filing:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for MIIT mobile app filing phases, registration, supervision, normalization, and operational filing evidence.

Sources for Covered actors - App personal information rules:

- [Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Use for app category, basic-function, minimum necessary personal information, no-refusal rule, and 1 May 2021 effective date.
- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Use for processing bases, notice, consent, sensitive personal information, individual rights, processor duties, impact assessments, and 1 November 2021 effective date.

Sources for Covered actors - operational implication:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for MIIT mobile app filing phases, registration, supervision, normalization, and operational filing evidence.
- [Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Use for app category, basic-function, minimum necessary personal information, no-refusal rule, and 1 May 2021 effective date.
- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Use for processing bases, notice, consent, sensitive personal information, individual rights, processor duties, impact assessments, and 1 November 2021 effective date.

Sources for Trigger event - Mobile app filing:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for MIIT mobile app filing phases, registration, supervision, normalization, and operational filing evidence.

Sources for Trigger event - App personal information rules:

- [Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Use for app category, basic-function, minimum necessary personal information, no-refusal rule, and 1 May 2021 effective date.
- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Use for processing bases, notice, consent, sensitive personal information, individual rights, processor duties, impact assessments, and 1 November 2021 effective date.

Sources for Trigger event - operational implication:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for MIIT mobile app filing phases, registration, supervision, normalization, and operational filing evidence.
- [Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Use for app category, basic-function, minimum necessary personal information, no-refusal rule, and 1 May 2021 effective date.
- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Use for processing bases, notice, consent, sensitive personal information, individual rights, processor duties, impact assessments, and 1 November 2021 effective date.

Sources for Core obligations - Mobile app filing:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for MIIT mobile app filing phases, registration, supervision, normalization, and operational filing evidence.

Sources for Core obligations - App personal information rules:

- [Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Use for app category, basic-function, minimum necessary personal information, no-refusal rule, and 1 May 2021 effective date.
- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Use for processing bases, notice, consent, sensitive personal information, individual rights, processor duties, impact assessments, and 1 November 2021 effective date.

Sources for Core obligations - operational implication:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for MIIT mobile app filing phases, registration, supervision, normalization, and operational filing evidence.
- [Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Use for app category, basic-function, minimum necessary personal information, no-refusal rule, and 1 May 2021 effective date.
- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Use for processing bases, notice, consent, sensitive personal information, individual rights, processor duties, impact assessments, and 1 November 2021 effective date.

Sources for Evidence package - Mobile app filing:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for MIIT mobile app filing phases, registration, supervision, normalization, and operational filing evidence.

Sources for Evidence package - App personal information rules:

- [Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Use for app category, basic-function, minimum necessary personal information, no-refusal rule, and 1 May 2021 effective date.
- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Use for processing bases, notice, consent, sensitive personal information, individual rights, processor duties, impact assessments, and 1 November 2021 effective date.

Sources for Evidence package - operational implication:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for MIIT mobile app filing phases, registration, supervision, normalization, and operational filing evidence.
- [Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Use for app category, basic-function, minimum necessary personal information, no-refusal rule, and 1 May 2021 effective date.

Sources for Timing and refresh points - Mobile app filing:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for MIIT mobile app filing phases, registration, supervision, normalization, and operational filing evidence.

Sources for Timing and refresh points - App personal information rules:

- [Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Use for app category, basic-function, minimum necessary personal information, no-refusal rule, and 1 May 2021 effective date.
- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Use for continuing personal-information duties and the 1 November 2021 effective date.

Sources for Timing and refresh points - operational implication:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for MIIT mobile app filing phases, registration, supervision, normalization, and operational filing evidence.
- [Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Use for app category, basic-function, minimum necessary personal information, no-refusal rule, and 1 May 2021 effective date.

Sources for Enforcement exposure - Mobile app filing:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for MIIT mobile app filing phases, registration, supervision, normalization, and operational filing evidence.

Sources for Enforcement exposure - App personal information rules:

- [Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Use for app category, basic-function, minimum necessary personal information, no-refusal rule, and 1 May 2021 effective date.
- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Use for supervisory powers, corrective measures, and penalties tied to unlawful personal-information processing.

Sources for Enforcement exposure - operational implication:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for MIIT mobile app filing phases, registration, supervision, normalization, and operational filing evidence.
- [Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Use for app category, basic-function, minimum necessary personal information, no-refusal rule, and 1 May 2021 effective date.

Sources for Overlap and routing - Mobile app filing:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for MIIT mobile app filing phases, registration, supervision, normalization, and operational filing evidence.

Sources for Overlap and routing - App personal information rules:

- [Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Use for app category, basic-function, minimum necessary personal information, no-refusal rule, and 1 May 2021 effective date.
- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Use for processing decisions involving data fields, recipients, retention, and cross-border transfers.

Sources for Overlap and routing - operational implication:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for MIIT mobile app filing phases, registration, supervision, normalization, and operational filing evidence.
- [Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Use for app category, basic-function, minimum necessary personal information, no-refusal rule, and 1 May 2021 effective date.

Sources for Practical decision rule - Mobile app filing:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for MIIT mobile app filing phases, registration, supervision, normalization, and operational filing evidence.

Sources for Practical decision rule - App personal information rules:

- [Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Use for app category, basic-function, minimum necessary personal information, no-refusal rule, and 1 May 2021 effective date.
- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Use for the broader personal-information processing trigger and lifecycle duties.

Sources for Practical decision rule - operational implication:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for MIIT mobile app filing phases, registration, supervision, normalization, and operational filing evidence.
- [Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Use for app category, basic-function, minimum necessary personal information, no-refusal rule, and 1 May 2021 effective date.

### When to run one track or both

- File before a new covered app begins service; for an already filed website sponsor, confirm which sponsor details can be reused and which app details must be added.
- Map the app's basic function, personal-information fields, permissions, SDKs, notices, consent flows, and refusal behavior against the 2021 provisions, the 2022 app-service provisions, and PIPL.
- Release only after the filing record matches the production app and the privacy evidence matches the production data flows.

Sources for the practical decision rule:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for MIIT mobile app filing phases, registration, supervision, normalization, and operational filing evidence.
- [Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Use for app category, basic-function, minimum necessary personal information, no-refusal rule, and 1 May 2021 effective date.

## How to use this comparison

First confirm whether the app, mini-program, or quick app provides internet information services in China and identify the app sponsor. A new covered app must complete filing before providing service. An app that already had an ICP filing generally supplements its app details rather than resubmitting the sponsor's identity information.

Then classify the app's basic function and map every personal-information field and device permission. The 2021 necessary-information provisions list 39 common app types and the necessary personal information for their basic functions. An app may offer additional functions, but it may not refuse the basic function solely because a user declines personal information that is not necessary for that function.

A map and navigation app may need location, departure point, and destination for its basic function. An online-shopping app may need a registered mobile number, recipient name, address and telephone number, and payment details. The listed basic functions for online video, short video, news browsing, browsers, input methods, app stores, photography tools, and utility apps such as calculators, flashlights, document tools, and smart-home assistants require no personal information. These examples set the no-refusal boundary for the listed basic function; they do not ban processing for a separate optional function when another lawful basis and the required notice or consent exist.

Apply the broader Personal Information Protection Law and the 2022 app-service provisions as well. First identify the personal information processor and processing basis for each purpose. Consent is one PIPL basis, not the only one; separate consent is required for specified processing such as sensitive personal information and provision to another processor, unless another rule changes the result. The laws also govern notice, individual rights, security controls, impact assessments, and app-distribution-platform verification. The 2021 list is a minimum-necessity rule, not a complete privacy checklist.

- Filing owner: retain sponsor identity, app name and icon, domain and IP details, service-provider details, filing number, submission record, and material-change updates.
- Privacy owner: retain the app-type decision, data and permission inventory, purpose and necessity analysis, processing basis, notice and consent records, SDK and third-party disclosures, rights handling, and impact assessments where required. PIPL impact-assessment reports and processing records must be kept for at least three years.
- Release owner or app store: block launch when filing is missing or the tested build collects data outside the approved privacy design.

Sources for this answer:

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for MIIT mobile app filing phases, registration, supervision, normalization, and operational filing evidence.
- [Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Use for app category, basic-function, minimum necessary personal information, no-refusal rule, and 1 May 2021 effective date.
- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io) - Use for app provider and app distribution platform governance, content/security/data duties, platform filing and verification, and 1 August 2022 effective date.
- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Articles 13, 17, 23, 28-31, and 55-56 support processing bases, notice, separate consent, sensitive-information duties, impact-assessment triggers, and the three-year minimum retention period for impact-assessment reports and processing records.

*Next step*

*Placement: Before primary sources*

## Tie each app release to both records

Track the filing number and the approved privacy design against the exact app version released in China.

- [Map official sources to evidence](/solutions/research-copilot.md): Link each filing and privacy decision to its official source, owner, evidence, and change history.
- [Review the China route](/contact.md): Review unresolved filing, privacy, and release questions for the China app.

## Primary sources

- [MIIT notice on mobile app filing work](https://www.miit.gov.cn/zwgk/zcwj/wjfb/tz/art/2023/art_920db564162e4312916a01bed6540ad8.html?ref=sorena.io) - Use for MIIT mobile app filing phases, registration, supervision, normalization, and operational filing evidence.
- [Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Use for app category, basic-function, minimum necessary personal information, no-refusal rule, and 1 May 2021 effective date.
- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io) - Use for app provider and app distribution platform governance, content/security/data duties, platform filing and verification, and 1 August 2022 effective date.
- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Use for the broader personal-information processing trigger and lifecycle duties.

## Related Topic Guides

- [China cybersecurity and data security requirements](/artifacts/apac/china-cybersecurity-law/requirements.md): China cybersecurity requirements by actor: network operators, data processors, CII operators, platforms, app providers, and distribution platforms.
- [China cybersecurity compliance checklist](/artifacts/apac/china-cybersecurity-law/checklist.md): A China cybersecurity checklist for scoping network duties, data security, CII procurement review, app rules, MIIT filing, and supporting standards.
- [China cybersecurity deadlines and compliance calendar](/artifacts/apac/china-cybersecurity-law/deadlines-and-compliance-calendar.md): Separate China cybersecurity commencement dates from recurring duties, filing lead times, review periods, and event-driven response deadlines.
- [China Cybersecurity Law FAQ](/artifacts/apac/china-cybersecurity-law/faq.md): Practical answers on China network-operator scope, MLPS evidence, important data, cybersecurity review, app filing and governance, and smart-home standards under the law in force from 1 January 2026.
- [China Cybersecurity Law vs EU Cyber Resilience Act](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-eu-cyber-resilience-act.md): Compare China's network-operator rules with the EU CRA's product duties, including scope, actors, evidence, reporting dates, and launch decisions.
- [China Cybersecurity Law vs EU NIS2 Directive](/artifacts/apac/china-cybersecurity-law/china-cybersecurity-law-vs-nis2.md): Compare China's network-operator duties with NIS2 entity duties, including scope, management accountability, incident reporting, evidence, and enforcement.
- [China cybersecurity penalties and fines](/artifacts/apac/china-cybersecurity-law/penalties-and-fines.md): Compare current China Cybersecurity Law and Data Security Law fines by actor, breach, severity, and enforcement consequence.
- [China Cybersecurity Review vs Data Export Assessment](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-vs-data-export-security-assessment.md): Separate China's cybersecurity-review triggers from CAC data-export assessment triggers, thresholds, filings, evidence, timing, and reapplication rules.
- [China cybersecurity review workflow](/artifacts/apac/china-cybersecurity-law/cybersecurity-review-workflow.md): Determine whether CII procurement, platform data processing, or a qualifying foreign listing triggers China's Cybersecurity Review Measures.
- [China mobile app filing and app governance](/artifacts/apac/china-cybersecurity-law/mobile-app-filing-and-app-governance.md): Identify the China app sponsor, complete MIIT filing before service, and separate provider, platform, privacy, content, and security duties.
- [China Smart-Home Security vs Telecom and Radio Approval](/artifacts/apac/china-cybersecurity-law/smart-home-security-vs-telecom-wireless-launch.md): Separate GB/T 41387-2022 smart-home security evidence from China telecom network-access and radio approval decisions for connected products.
- [CII and network operator role triage](/artifacts/apac/china-cybersecurity-law/critical-information-infrastructure-and-network-operators.md): How to separate ordinary network operator duties from CII, procurement, and review-risk questions under China cybersecurity sources.
- [Does an app need MIIT filing and CAC app governance review?](/artifacts/apac/china-cybersecurity-law/faq/does-an-app-need-miit-filing-and-cac-app-governance-review.md): An app sponsor providing internet information services through an app in China must complete MIIT filing. CAC rules separately govern app providers and distribution platforms without creating one routine CAC approval for every app.
- [GB/T 22239-2019 classified protection baseline](/artifacts/apac/china-cybersecurity-law/classified-protection-baseline.md): How to scope and document a GB/T 22239-2019 classified protection baseline without treating the recommended standard as a standalone law.
- [GB/T 41387-2022 smart home security standard](/artifacts/apac/china-cybersecurity-law/smart-home-security-standard.md): How connected-device teams can scope and document GB/T 41387-2022 without treating it as an automatic certification or product-approval duty.
- [How do smart home security standards fit with China cybersecurity law?](/artifacts/apac/china-cybersecurity-law/faq/how-do-smart-home-security-standards-fit-with-china-cybersecurity-law.md): GB/T 41387-2022 can organize smart-home security evidence, but it is a recommended standard, not a product approval. Check app, data, MLPS, telecom access, and radio requirements separately.
- [How does important data change China cybersecurity obligations?](/artifacts/apac/china-cybersecurity-law/faq/how-does-important-data-change-cybersecurity-obligations.md): Once data is officially identified as important data, the processor needs named governance, periodic risk assessments and reports, incident controls, and a separate export decision. An internal sensitivity label alone does not establish the legal category.
- [Is every company a network operator under China Cybersecurity Law?](/artifacts/apac/china-cybersecurity-law/faq/is-every-company-a-network-operator-under-china-cybersecurity-law.md): No. Under China's Cybersecurity Law, a network operator is an owner or administrator of a network or a network service provider. Apply that definition to each China network or service, then test CII and other roles separately.
- [MLPS classified protection evidence map](/artifacts/apac/china-cybersecurity-law/mlps-classified-protection-evidence-map.md): Classify a China network under MLPS, complete level 2 or above filing, map controls, and retain assessment, remediation, and change evidence.
- [What is MLPS classified protection evidence?](/artifacts/apac/china-cybersecurity-law/faq/what-is-mlps-classified-protection-evidence.md): MLPS evidence shows how a defined China network or system was graded and protected. Keep the scope, grading rationale, filing or assessment records where applicable, control mapping, test results, remediation, and reassessment history.
- [When does China cybersecurity review apply?](/artifacts/apac/china-cybersecurity-law/faq/when-does-china-cybersecurity-review-apply.md): China cybersecurity review applies to CII procurement or network-platform data processing that affects or may affect national security, plus a mandatory pre-filing trigger for certain foreign listings involving more than one million users' personal information.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-cybersecurity-law/mobile-app-filing-vs-app-personal-information-rules.md
