Background
On 22 July 2026, the Cyberspace Administration of China (“CAC”), together with the Ministry of Public Security, issued the Provisions on Simplified Personal Information Protection Measures for Small-Scale Personal Information Handlers (the “Provisions on Small-Scale Handlers”). The Provisions on Small-Scale Handlers make limited adjustments to the draft for comments released on 3 April 2026 and include, as annexes, the Personal Information Protection Compliance Audit Self-Assessment Checklist for Small-Scale Personal Information Handlers and the Personal Information Protection Impact Assessment Form for Small-Scale Personal Information Handlers, providing simplified compliance measures for personal information handlers with relatively small processing volumes. The Provisions on Small-Scale Handlers will take effect on 1 September 2026.
In addition, on 7 August 2026, the CAC released the Provisions on Personal Information Protection for Large-Scale Personal Information Handlers (Draft for Comments) (the “Draft Provisions on Large-Scale Handlers”), which reorganise the compliance obligations applicable to handlers processing large volumes of personal information. The deadline for public comments is September 7, 2026.
This article provides a consolidated analysis of the changes introduced by the Provisions on Small-Scale Handlers and the Draft Provisions on Large-Scale Handlers, as compared with the existing laws and regulations, with a view to helping companies falling within their scope of application respond in a timely manner.
Provisions on Small-Scale Handlers
Scope of Application
According to Article 2 of the Provisions on Small-Scale Handlers, the Provisions apply to personal information handlers that process the personal information of fewer than 100,000 individuals. Unlike the relevant rules on cross-border transfers of personal information, the threshold of 100,000 individuals does not distinguish between personal information and sensitive personal information. This is a significant positive development for companies that only conduct B2B business.
Rules for Processing Personal Information
Article 4 of the Provisions on Small-Scale Handlers largely follows Article 17 of the Personal Information Protection Law (PIPL), meaning that personal information handlers are still required to inform individuals of the key contents of their personal information processing rules. In practice, most companies currently prepare privacy policies and similar documents by referring to the template set out in Appendix D of the Information Security Technology — Personal Information Security Specification, and such documents are generally relatively comprehensive and complex. We recommend that if a small-scale personal information handler (a “Small-Scale Handler”) has never formulated its own personal information processing rules, it may first refer to the contents of this article for a basic “from zero to one” compliance framework. If a Small-Scale Handler already has a publicly available and complete privacy policy or similar document, no immediate change is necessary for now.
At the same time, compared with the draft for comments, the Provisions on Small-Scale Handlers pay greater attention to the personal information of minors. According to Article 8 of the Provisions on the Cyber Protection of Children’s Personal Information, “network operators shall establish dedicated rules and user agreements for the protection of children’s personal information and designate dedicated personnel responsible for the protection of children’s personal information.” Therefore, the Provisions on Small-Scale Handlers require that where a Small-Scale Handler processes the personal information of minors under the age of 14, it must still formulate dedicated personal information processing rules separately.
Notice and Consent
According to Articles 5 and 6 of the Provisions on Small-Scale Handlers, even Small-Scale Handlers must apply the same standards as general personal information handlers when implementing a lawful basis for processing, including fulfilling the notice obligation in a prominent manner and obtaining consent in accordance with law, especially separate consent where required. However, Small-Scale Handlers benefit from a special relaxation in one scenario: if, in a specific context, the collection of personal information by a Small-Scale Handler is necessary only for providing products or services, and the relevant personal information will not be provided to any third party or disclosed publicly, the Small-Scale Handler only needs to make its rules public. On the premise that the individual has been fully informed, the individual’s voluntary use of the product or service will be deemed as consent, and the Small-Scale Handler does not need to obtain separate individual consent.
We understand that, for example, some companies sell terminal products or services with internet connectivity functions, which inevitably involves collecting consumers’ personal information. However, obtaining consent in accordance with the PIPL and related rules may be difficult in practice. The Provisions on Small-Scale Handlers therefore provide relaxed requirements for such scenarios: if the personal information processing rules are made public in a prominent manner, the consumer’s use of the relevant terminal product or service will be deemed as the Small-Scale Handler having obtained consent.
Reliance on Online Platforms
Small-Scale personal information handlers usually do not have their own systems or platforms to directly collect personal information, and in many cases rely on mechanisms provided by third-party online platforms to collect personal information. In this context, Article 8 of the Provisions on Small-Scale Handlers provides a “burden-reduction” approach for Small-Scale Handlers.
If a Small-Scale Handler conducts personal information processing activities solely by relying on an online platform, does not provide personal information to any third party, and the online platform’s personal information processing rules already cover the processing activities of the Small-Scale Handler, and the Small-Scale Handler has expressly declared that it will comply with those rules, then the Small-Scale Handler may rely on the online platform to fulfill the notice obligation without separately formulating a privacy policy or similar document. A common example is that the WeChat platform customizes personal information processing rules for each WeChat mini program. If the Small-Scale Handler satisfies the relevant requirements, it may not need to formulate a separate privacy policy.
In addition, if the online platform has already conducted a personal information protection compliance audit and personal information protection impact assessment (PIPIA) that fully cover the Small-Scale Handler’s scenario, the Small-Scale Handler will not need to conduct a separate assessment or audit.
Self-Assessment Template Documents
Articles 13 and 14 of the Provisions on Small-Scale Handlers, together with the annexes titled Personal Information Protection Compliance Audit Self-Assessment Checklist for Small-Scale Personal Information Handlers and Personal Information Protection Impact Assessment Form for Small-Scale Personal Information Handlers, provide template documents for personal information protection compliance audits and PIPIAs respectively. The work is mainly carried out by the person responsible for the compliance audit or impact assessment through a “checked conclusion plus supplementary explanation” approach. This significantly reduces the compliance burden on Small-Scale Handlers and makes the requirements to “conduct a personal information protection compliance audit at least once every five years” and “conduct a PIPIA” more operable in practice.
Circumstances Where No Penalty Shall Be Imposed
Given the relatively low risk of harm associated with the processing activities of Small-Scale Handlers, Article 18 of the Provisions on Small-Scale Handlers provides that no penalty shall be imposed in the following three circumstances:
- the violation is minor, is corrected in a timely manner, and causes no harmful consequences;
- there is sufficient evidence proving that there was no subjective fault, unless otherwise provided by laws or administrative regulations; and
- other circumstances where no penalty shall be imposed in accordance with law.
Spot Checks and Supervision
Although the Provisions on Small-Scale Handlers lower the compliance threshold for Small-Scale Handlers, regulatory authorities have still retained ex post supervision and enforcement powers: (1) competent authorities may supervise and inspect Small-Scale Handlers’ performance of personal information protection obligations through spot-check assessments, audit reports, and other means; and (2) where competent authorities find that a Small-Scale Handler has illegally processed personal information or has experienced repeated personal information security incidents, they may impose penalties in accordance with law, record the matter in the Small-Scale Handler’s credit file, and make it public.
Apart from the above requirements, the Provisions on Small-Scale Handlers do not substantially reduce the compliance requirements for Small-Scale Handlers in areas such as responses to requests for exercising personal information rights or cross-border transfers of personal information (in which the relevant transfer mechanisms remain a CAC-led security assessment, standard contractual clauses, and certification).
Draft Provisions on Large-Scale Handlers
Scope of Application
According to Article 2 of the Draft Provisions on Large-Scale Handlers, the determination of a large-scale personal information handler (a “Large-Scale Handler”) should take into comprehensive account the following conditions:
- processing the personal information of more than 10 million natural persons;
- providing important online services involving the processing of personal information, or having a business scope that covers multiple lines of business and involves the processing of personal information; and
- personal information processing activities having a significant impact on national security, economic operation, social stability, public health and safety, and other matters.
Based on the definition, a Large-Scale Handler is broadly comparable to an “important data processor” under the Regulations on the Administration of Network Data Security, while also overlapping with concepts such as “large online platforms” and “large internet companies”. Therefore, we consider that the Draft Provisions on Large-Scale Handlers are, by design, intertwined with the existing legal and regulatory framework, which may indirectly increase the compliance burden on companies falling within their scope of application.
Determination and Filing
According to Article 3 of the Draft Provisions on Large-Scale Handlers, if a company determines through self-assessment that it is a Large-Scale Handler, or if the relevant authorities consider that the company is a Large-Scale Handler, the company should submit relevant materials to the provincial-level cyberspace administration where it is located and complete the determination filing.
Personal Information Processing Rules
Article 10 of the Draft Provisions on Large-Scale Handlers sets out more detailed requirements for the formulation of privacy policies by Large-Scale Handlers that are more detailed than those listed under the PIPL. However, they are largely consistent with the standards currently applied by cyberspace authorities in enforcement inspections of privacy policies on platforms such as apps, websites and mini programs.
Localisation Management
Articles 13 and 14 of the Draft Provisions on Large-Scale Handlers impose very strict requirements on cross-border transfers of personal information. On the one hand, Large-Scale Handlers are required to store, within China, personal information collected and generated within China. On the other hand, they are required to store such personal information in data centers that meet the following requirements:
- being established within the territory of the People’s Republic of China;
- the legal representative or actual controller of the data center management institution having Chinese nationality; and
- complying with relevant national policy and standards requirements.
However, Article 20 of the Draft Provisions on Large-Scale Handlers still leaves room for Large-Scale Handlers to complete compliance procedures in accordance with law and, where genuinely necessary, transfer personal information across borders. Over the past three years of data export regulation, most foreign-invested companies with substantial to-C business have already completed, or are in the process of completing, localized storage of their China user data. The above localization requirements therefore should not be particularly difficult for them. For companies that have not previously considered or implemented localized storage, however, this would effectively require them to build or lease an additional data center in China, which would undoubtedly increase both financial costs and compliance costs. That said, since the Regulations on the Administration of Network Data Security established that the personal information of more than 10 million natural persons should be protected according to the standards applicable to important data, localized storage has already become a clear trend for many handlers with substantial to-C business.
Internal Management
Whether the data center is self-built or operated by a third party, the data center management institution must establish and improve internal management systems and operating procedures. In particular, where a personal information security incident or cybersecurity vulnerability may have a significant impact, it should make a timely report to the regulatory authorities.
Internal Management Systems
Article 24 of the Draft Provisions on Large-Scale Handlers consolidates the requirements under relevant laws and regulations and requires Large-Scale Handlers to establish comprehensive internal management systems covering at least the following matters:
- a classified management system for personal information;
- systems relating to secure storage, authorized access, controllable transmission, external provision and behavioral audit in connection with personal information processing;
- systems for personal information security risk monitoring, emergency drills and emergency response;
- systems for PIPIAs and compliance audits;
- systems for the protection of minors’ personal information;
- systems for accepting and handling personal information-related complaints and reports; and
- systems for publicity, education and training on personal information protection.
Personal Information Protection Officer
Previously, the functions and qualifications of personal information protection officers were scattered across different laws, regulations and national standards. Articles 25 and 26 of the Draft Provisions on Large-Scale Handlers expressly regulate the required seniority, functional scope and capabilities of the personal information protection officer of a Large-Scale Handler.
Social Responsibility Report
Article 30 of the Draft Provisions on Large-Scale Handlers implements Article 58 (which sets out obligations specific to providers of important Internet platform services) of the PIPL requiring Large-Scale Handlers to prepare and publish, in the first half of each year, a social responsibility report on personal information protection for the preceding year, and setting out the framework of the report in detail.
Personal Information Protection Impact Assessment
For products, services or functions that involve automated decision-making, processing of sensitive personal information, or other matters that may have a significant impact on personal rights and interests, Article 31 of the Draft Provisions on Large-Scale Handlers further raises the requirements on the basis of Article 55 of the PIPL. It expands the scope of matters to be covered in PIPIAs and adds more detailed assessment points. It also requires Large-Scale Handlers to file the assessment with the provincial-level cyberspace administration where they are located within 15 working days after completing the prior assessment. This means that PIPIAs will become regulatory documents subject to government review, not merely internal compliance records. Companies should consider whether their current PIPIA templates are suitable for regulatory filing.
Currently, PIPIA reports are only retained internally by companies and do not need to be filed. The purpose of this provision is to urge Large-Scale Handlers to perform PIPIAs more thoroughly by imposing a filing requirement. If these provisions are ultimately implemented, how to balance the quality of PIPIAs with operational efficiency will become an important issue in the personal information protection compliance work of Large-Scale Handlers.
Personal Information Protection Supervisory Committee
Articles 37 to 44 of the Draft Provisions on Large-Scale Handlers devote substantial space to detailing how Large-Scale Handlers should establish a personal information protection supervisory committee, how the committee should carry out its work, and how its work should be reported. These provisions further implement the principle-based requirements under Article 58 of the PIPL. It is foreseeable, however, that if the provisions on personal information protection supervisory committees are ultimately implemented, Large-Scale Handlers will need to procure or invest substantial human resources to maintain the operation of such committees.
Specifically, Article 38 of the Draft Provisions on Large-Scale Handlers require the external members of a personal information protection supervisory committee to meet the following conditions:
- meeting the independence requirements set out in Article 39 of the Draft Provisions on Large-Scale Handlers;
- being concurrently engaged by no more than three large-scale personal information handlers;
- having the capability to conduct personal information protection compliance audits, being familiar with laws, regulations, national standards and other requirements relating to personal information protection, and having engaged in personal information protection-related work for no less than three years;
- having a good reputation and being able to perform their duties objectively, impartially, independently and with integrity;
- having the physical capacity, working time and other conditions necessary to perform their duties;
- having good personal character and no adverse records such as violations of laws or crimes, or serious dishonesty; and
- meeting any other conditions prescribed by laws, administrative regulations or departmental rules.
Conclusion
Overall, the Provisions on Small-Scale Handlers and the Draft Provisions on Large-Scale Handlers reflect a further stratification of the regulatory approach. For personal information handlers with smaller processing volumes and relatively limited risks, the regulatory rules provide more practicable and simplified pathways in areas such as notice, assessment and audit. By contrast, for Large-Scale Handlers that process personal information on a large scale and have a higher social impact, the regulatory requirements are clearly becoming more stringent, with further emphasis on obligations such as localized storage, internal governance, filing of impact assessments, social responsibility reports and dedicated supervisory mechanisms. For those companies that process PI in the Chinese mainland but do not meet the threshold requirements, the existing regulatory framework will continue to apply.
Companies falling within the relevant scope of application should, as early as possible, review the scale of their personal information processing and their business scenarios, determine the regulatory tier to which they belong, and make timely adjustments in light of their own circumstances, so as to avoid being on the back foot once the new rules take effect or are formally issued.

For further information, please contact:
Dominic Edmondson, Partner, Dentons
dominic.edmondson@dentons.com




