Key contacts
On 22 July 2026, the Cyberspace Administration of China and the Ministry of Public Security jointly released the Provisions on Simplified Personal Information Protection Measures for Small-Scale Personal Information Processors ("Simplified Measures"). It will come into effect on 1 September 2026.
1. Why were the Simplified Measures released?
The Simplified Measures were released to implement Article 62 of the PRC Personal Information Protection Law ("PIPL"), which requires the formulation of tailored rules for small-scale personal information processors ("Small Processors"). The Simplified Measures do not aim to reduce the level of personal information protection but simplify certain compliance methods. For the Small Processors, the Simplified Measures are expected to reduce the compliance costs associated with the establishment and operation of data protection frameworks.
2. What is the scope of application?
The Simplified Measures apply to the Small Processors, namely those that process personal information of less than 100,000 individuals.
3. How is the threshold of 100,000 individuals calculated?
According to the official interpretation, the threshold should be calculated based on the cumulative number of natural persons whose personal information is currently being processed. Further, individuals whose personal information has been lawfully deleted shall not be counted toward the threshold. In addition, the threshold of "less than 100,000 individuals" does not include cases involving exactly 100,000.
4. How are personal information processing rules simplified and implemented in a simplified manner?
The Simplified Measures reduce the content requirements for personal information processing rules, commonly referred to in practice as privacy policies or personal information protection policies. The Small Processors only need to disclose basic content including the processor's name, the department or personnel responsible for processing individuals' requests and their contact details, as well as the purpose, method, categories and retention period of personal information processing. It should be noticed that a separate personal information processing rule must still be established for the processing of personal information of minors under the age of 14.
Regarding the implement of personal information processing rules, for offline collection scenarios, the rules may be implemented by posting notices in a prominent place at the business premises. For online collection scenarios, the rules may be implemented through service agreements, app pop-ups or website announcements.
Further, the Simplified Measures allow service and management entities, such as industrial parks, to establish and publicly disclose unified personal information processing rules. The Small Processors that agree to comply with such rules are not required to formulate separate rules of their own.
5. How are notification obligations fulfilled in a simplified manner?
The Small Processors can fulfill their notification obligations by publicly implementing a simplified personal information processing rule in a prominent manner, such as through bold text, enlarged font size or highlighted colors, if all of the following conditions are met:
- Processed personal information (excluding sensitive personal information) is necessary for providing products or services; and
- Processed personal information will neither be provided to other personal information processors nor disclosed to the public, and this will be expressly stated in the personal information processing rule.
6. How is consent obtained in a simplified manner?
Under the Simplified Measures, the Small Processors may process personal information in accordance with their publicly disclosed personal information processing rules without obtaining consent through pop-up notices, checkboxes or separate consent forms, if all of the following conditions are met:
- The personal information is provided by the individual for the purpose of obtaining products or services of the Small Processor;
- The individual is fully informed of the personal information processing rules; and
- The individual voluntarily and proactively provides, or cooperates in providing, the personal information necessary for obtaining the relevant products or services.
However, the above does not apply to processing of sensitive personal information.
7. How are personal information protection compliance audits and impact assessments conducted in a simplified manner?
In the appendices, the Simplified Measures provide a Self-Assessment Checklist for Personal Information Protection Compliance Audits for Small Processors and a Personal Information Protection Impact Assessment Form for Small Processors. The Small Processors can use these forms to conduct compliance audits and impact assessments in a simplified manner.
Further, the Simplified Measures clarify that the Small Processors are required to conduct a personal information protection compliance audit at least once every five years and retain the completed self-assessment checklist for at least five years. The Small Processors that have obtained personal information protection certification, i.e. a certification issued by an accredited certification body confirming compliance with China's personal information protection requirements, are exempt from conducting such audits during the validity period of the certification.
8. What simplified measures are available for the Small Processors operating through online platforms?
The Simplified Measures provide two simplified compliance measures for the Small Processors that conduct business through online platforms, e.g. Tmall or JD platforms.
Firstly, the Small Processors are exempt from establishing separate personal information processing rules and fulfilling notification obligations, if all of the following conditions are met:
- The Small Processors process personal information exclusively through an online platform and do not provide it to any third parties outside the platform;
- The online platform has established and published applicable personal information processing rules and the respective rights and obligations between the platform and the Small Processors are allocated; and
- The Small Processors declare compliance with such rules and their processing activities are necessary for providing products or services, as well as remain within the scope of the specified purposes, methods and categories of personal information.
Secondly, the Small Processors are also not required to conduct separate audits or assessments, if the personal information protection compliance audit and impact assessments conducted by the online platform already cover the Small Processors' processing activities.
9. What are the exemption and mitigation mechanisms for administrative penalties?
The Simplified Measures explicitly clarify the circumstances under which the Small Processors shall be or may be exempt from administrative penalties or subject to mitigated penalties. Specifically, no penalty shall be imposed if the violation is minor, corrected in a timely manner and causes no harmful consequences, or if the processor can demonstrate the absence of subjective fault. No penalty may be imposed for a first-time violation that causes only minor harm and is promptly rectified. Further, penalties shall be reduced or mitigated if the processor voluntarily eliminates or mitigates the harmful consequences, voluntarily discloses violations, promptly addresses a security incident properly, or provides assistance in the authority’s investigation of the violation.
The Simplified Measures will come into effect in less than one month. We recommend that relevant companies promptly assess whether they meet the applicable threshold for the Small Processors. If so, they should identify which compliance obligations may be subject to simplified compliance measures and which obligations must continue to be fully complied with. It should be particularly noted that the Simplified Measures simplify the manners in which certain compliance obligations are fulfilled, rather than removing or exempting those obligations. The compliance obligations relating to important data, sensitive personal information, minors’ personal information, or cross-border transfers must still be strictly fulfilled under applicable legal requirements.