Research across the library

Search laws, regulations, standards and guides

Suggested searches

Current priorities

2026-07-03Revised Internet Information Service Measures draft2026-06-18Network data risk assessment: draft versus final

What changed

Material differences at a glance

The final provisions preserve the proportionate-compliance model for eligible small processors, confirm the fewer-than-100,000-person threshold, add the Ministry of Public Security as a joint issuer, and establish a fixed commencement date.

  • The consultation proposal became a joint CAC and Ministry of Public Security departmental rule.
  • The final text confirms that the threshold is fewer than 100,000 persons, not 100,000 or fewer.
  • The final provisions establish an effective date of 1 September 2026 and confirm simplified audit, impact-assessment and selected cross-border arrangements.

Source comparison

4 reviewed change records
Article / SectionPrevious TextUpdated TextTypePractical ImpactNotes
Legal status and issuing authoritiesThe April text was a CAC consultation proposal without binding effect.The final provisions are jointly issued by the CAC and Ministry of Public Security and take effect on 1 September 2026.~ ModifiedOrganizations should implement the final text and retain the draft only for version history.Official publication announcement and final provisions.Effective: 2026-09-01Previous sourceCurrent source
Eligibility thresholdThe proposal targeted qualifying small personal information processors.The final rule applies the stated small-processor framework to processors handling personal information of fewer than 100,000 persons, subject to the rule's exclusions and counting method.i ClarifiedThe threshold excludes a processor at exactly 100,000 persons; current natural persons are counted and deleted personal information is excluded as explained in the official Q&A.Read the final text together with the CAC Q&A issued on 24 July 2026.Effective: 2026-09-01Current source
Compliance auditThe draft proposed a proportionate audit arrangement.The final framework confirms a simplified audit cycle, with the official Q&A explaining an interval of at least once every five years and a certification-related exemption during validity.i ClarifiedEligible processors should document both threshold eligibility and the basis for using the simplified audit schedule.Official explanatory Q&A; the underlying conditions must be checked before reliance.Effective: 2026-09-01Current source
Impact assessment and cross-border arrangementsThe draft proposed simplification of selected assessment and data-export compliance steps.The final provisions retain proportionate treatment for specified personal information protection impact assessments and selected cross-border data transfer arrangements.~ ModifiedSimplification is conditional and does not eliminate the need to check the PIPL, network-data rules, sensitive-personal-information conditions or national data-export mechanisms.Use the official final text and annex self-check materials; do not generalize the simplifications beyond their stated scope.Effective: 2026-09-01Current source

Official sources

This website is for informational and educational purposes only. It does not constitute legal advice. The Chinese text shall prevail. Users should consult qualified legal counsel for specific matters.