- Confirms that the binding simplified-measures rules for processors in China handling personal information of fewer than 100,000 people take effect on 1 September 2026.
References and citations
- Sets the 1-million-person officer-reporting threshold, the 30-working-day deadlines after reaching the threshold or making a material change, the municipal reporting authority, and the online reporting route.
- Clarifies that current-person counts include the stated threshold, distinguishes the binding two-year and annual audit rules from recommended national-standard frequencies, and confirms the binding annual audit rule for processors handling minors' personal information.
- Confirms the five-year audit cadence, the certification and covered-platform exceptions, and the continuing annual rule for processors handling minors' personal information.
- Articles 3-6 require periodic compliance audits and set a minimum once-every-two-years cadence for processors handling personal information of 10 million or more people; the measures took effect on 1 May 2025.
- Binding measure for security-assessment preparation, filing materials, review, legal-instrument content, and reassessment triggers, as modified by the 2024 provisions.
- Articles 5-8 establish the export PIPIA, CAC form, contract effectiveness, 10-working-day filing, and refiling triggers, subject to the controlling 2024 provisions.
- Use for app provider and app distribution platform governance, content/security/data duties, platform filing and verification, and 1 August 2022 effective date.
- Defines basic functions and necessary personal information for 39 common app categories and prohibits denial of a basic function for refusal of non-necessary information.
- Articles 38-40, 55-57 establish overseas-transfer safeguards, notice and separate consent, PIPIA, and incident response.
- Articles 2-10 establish important-data treatment, exemptions, current-year thresholds, route bands, three-year assessment validity, and continuing PIPL duties.