×

Open a micro letter and sweep a two-dimensional code
Subscribe to our WeChat public number

×

Turn on the phone and sweep the two-dimensional code
You can access the website and share it with your friends through a mobile phone

CN

New Rule Released to Reduce Compliance Burden of Small-scale Personal Information Processor

2026-08-0426

公众号头图3.png


China's Personal Information Protection Law (PIPL), effective in November 2021, generally requires cyberspace administration authorities to tailor-make rules and standards for small-scale personal information processors. Five years after PIPL's implementation, Cyberspace Administration of China (CAC), the watchdog of PIPL, has released the Provisions on Simplified Personal Information Protection Measures for Small-Scale Personal Information Processors (the "Provisions") together with two appendices, self-inspection form for personal information protection compliance audit of small-scale personal information processor and personal information protection impact assessment form of small-scale personal information processor, with an aim to promote innovative developments of small and medium-sized enterprises by simplifying protection measures that they are required to take for protecting personal information. The Provisions will come into force on September 1, 2026.


1. Who are small-scale personal information processors?


A "small -scale personal information processor"  refers to a personal information processor that processes personal information of less than 100,000 individuals. Any personal information processor may qualify as "small scale" as long as the total number of individuals whose personal information is processed is less than 100,000, no matter its corporate form, registered capital, number of employees, industry, revenue or whether there is sensitive personal information included.


Moreover, the Provisions highlight that only small-scale personal information processors that are within the territory of China will be eligible to enjoy the simplified measures.



2. "Informed consent"  mechanism is to be simplified


2.1 Small-scale personal information processors may utilize simplified processing rules or processing rules of industrial parks or network platforms to inform individuals of processing


As per the Provisions:


  • for offline collection of personal information, a small-scale personal information processor may make public its processing rules through posting them on notable location at its business place and such other simplified means; for online collection of personal information, it may do so through means such as service agreements, product & service client popup and website announcement.


  • A small-scale personal information processer may perform its obligation to inform individuals of processing only through making public its processing rules in an easily accessible and storable form and notifying users in a prominent manner by means of bold text, enlarged font sizes, varied color marking and other method if it meets all the following conditions:

      

 (i) to process personal information (sensitive personal information exclusive) is necessary for supplying products or services; and


(ii) it does not provide to any third-party processor or disclose publicly, any personal information, which has been stated expressly in its processing rules.


  • A small-scale personal information processor will not need to formulate its own processing rules, if:


(i) it agrees to be bound by processing rules released by service and management entities of industry parks, industry bases, commercial properties where it is located;


(ii)  it processes personal information only through network platform and does not provide personal information to any third party outside the platform; the network platform has released processing rules specifically for such type of small-scale personal information processors which provide their respective rights and obligations; it agrees to be bound by such processing rules released by the network platform; to process personal information is necessary for supplying products or services; and processing falls within the processing purposes, processing methods and scope of personal information as set out in the processing rules.


It is notable that such small-scale personal information processor may further be exempt from conducting its own compliance audit of personal information protection and personal information protection impact assessment if network platform has done so. However, it still needs to formulate its own processing rules and conduct its own compliance audit and protection impact assessment if its processing activities are beyond the processing purposes, processing methods or scope of personal information as set out in the network platform's processing rules.


  • A small-scale personal information processor is required to formulate processing rules specifically for processing personal information of minors under the age of 14.


2.2 Small-scale personal information processer may be exempt from obtaining "written consent" under certain circumstances which are originally required under PIPL


Under PIPL, after being fully informed, individuals may give their explicit consents on a voluntary basis, or each individual shall give his/her separate consent or written consent if laws and regulations require to do so.


However, the Provisions allow small-scale personal information processors to process personal information without "written consent" where an individual, for the purpose of obtaining products or services, voluntarily and proactively provides to a small-scale personal information processor, or voluntarily and proactively cooperates with the small-scale personal information, the personal information that is necessary for obtaining such products or services, after the small-scale personal information processor has made its personal information processing rules public and fulfilled its obligation to inform.


It is notable that small-scale personal information processors shall still clearly inform individuals of the necessity of processing the sensitive personal information and its impact on individuals'rights and interests in their processing rules and obtain individuals'separate consents.



3. Cross-border transfer of personal information will continue to enjoy exemptions from CAC security assessment, personal information protection certification and standard contract filing under certain circumstances.


On March 22, 2024, CAC issued the Provisions on Facilitating and Regulating Cross-border Data Flow which provides data exports exemptions from security assessment, personal information protection certification, and standard contract filing. The Provisions continue to offer the exemptions, highlighting that a small-scale personal information processor is exempted from security assessment, personal information protection certification, and standard contract filing under any of the following circumstances:


  • where it is necessary to provide personal information to overseas entities in order to enter into or perform contracts where individuals are one of the parties, such as cross-border shopping, cross-border mailings and deliveries, cross-border remittances, cross-border account openings, flight and hotel reservations, visa applications, and examination services;


  • where it is necessary to provide personal information of employees to overseas entities when implementing cross-border human resources management in accordance with labor regulations and collective contracts signed in accordance with the law;


  • where personal information must be provided to overseas entities in order to protect the life, health, and property safety of individuals in emergency situations;


  • where it is necessary to provide personal information to overseas entities when performing statutory responsibilities or obligations; and


  • where it (non-critical information infrastructure operator) has accumulatively provided personal information (excluding any sensitive personal information) to overseas entities of less than 100,000 individuals since January 1 of the current year.


The above exemption will not exempt small-scale personal information processors from obligation relating to informed consents for data export.


However, if any personal information above falls into the category of important data, cross-border transfer of such personal information will still require security assessment for exporting important data.



4. Personal information protection compliance audit will be simplified


PIPL requires personal information processors to conduct regulatory compliance audit on a regular basis. In general, a personal information processor may conduct the audit by its internal office or an external agency based on the Guidelines for the Personal Information Protection Compliance Audits released by CAC. The Guidelines provide a list of the focuses that compliance audit should cover. Completing such audit could be time-consuming and cost burdensome for small-scale personal information processors.


The Provisions provides a self-inspection form for personal information protection compliance audit of small-scale personal information processor, replacing full compliance audit as originally required by PIPL. The self-inspection form lists those audit focuses set out in the Guidelines, but small-scale personal information processors only need to simply answer "Yes" or "No" or "N/A" to each of the audit items, with no need to conduct comprehensive compliance audit or prepare full compliance audit report.


Small-scale personal information processors should conduct such self-inspection compliance audit once every five years and retain self-inspection forms for at least 5 years.



5. Personal information protection impact assessment will be simplifiedUnder 


PIPL, a processor should conduct personal information protection impact assessment prior to any of the following processing activities:


(1) processing sensitive personal information;

(2) automated decision by utilizing personal information;

(3) sub-processing personal information, providing personal information to other processors and making public personal information;

(4) transferring personal information overseas; and

(5) other personal information processing activities that may have significant impact interests of individuals.


Moreover, the impact assessment should cover the following: (i) whether the purpose and method of processing personal information are lawful, legitimate, and necessary; (ii) impact on personal rights and interests and security risks; and (iii) whether the protection measures taken are lawful, effective and commensurate with the degree of risks. Impact assessment reports and relevant records should be retained for a period of at least 3 years.


The Provisions largely simplify the impact assessment by requiring small-scale personal information processors to complete personal information protection impact assessment form. The form lists all five processing activities as summarized above with impact assessment items. Small-scale personal information processors only need to simply answer "Yes" or "No" or "N/A" to each of the impact assessment items, with no need to conduct comprehensive assessments or prepare full impact assessment report.


The impact assessment form should be retained for at least three years.



6.MHP Observation


The Provisions allow small-scale personal information processors to benefit from simplified compliance measures (e.g., streamlined notice and consent mechanisms), but such simplifications do not exempt them from other obligations under PIPL.


Entities that do not qualify as small-scale processors remain fully subject to PIPL's standard compliance framework without any relaxation.


The Provisions reflect a shift in CAC's regulatory approach and tendency from a standard framework under PIPL which is applicable to all processors to a tiered model, where processors are regulated based on the scale and impact of their data processing scale and activities. Large network platforms may face rigid compliance requirements, while small-scale personal information processors may benefit from simplified rules.


Previously the draft Provisions seeking public comments intend to exempt small-scale personal information processors from obtaining individuals'separate consents for processing their sensitive personal information such as facial information or biological samples. However, the formally released Provisions still require processors to fulfill informed consents obligations in terms of sensitive personal information, which reflects CAC's consistent prudence.

Contact Us

7F Wheelock Square, 1717 Nanjing West Road, Shanghai 200040, PRC
Zip Code:200040
Phone:+8621 61132988
Fax:61132913
Email:hr@mhplawyer.com