Audit the operation, not just its policy documents
The Measures, effective from 1 May 2025, define an audit as reviewing and evaluating whether personal information processing complies with laws and administrative regulations. PIPL Article 54 already establishes a regular-audit duty. The 2025 framework supplies an operating structure; it is not satisfied merely because a privacy notice and a vendor contract exist.
Decide the entity, activities, systems and audit period first. Then identify the rules that apply and obtain evidence of actual behavior. The work should be capable of finding a gap between a written commitment and a live system. This article is an original preparation guide, not an audit opinion on any organization.
Read the numerical rules precisely
Article 4 applies its at-least-once-every-two-years rule to processors handling information of more than 10 million people. It does not say every business has that exact timetable, nor does a number below that threshold remove the regular-audit duty. Article 12 separately uses one million or more for designating the responsible personal information protection officer for audit work; the two thresholds serve different purposes.
Do not substitute registered accounts, staff headcount or turnover for the relevant processing population without a documented basis. At exactly 10 million, the wording 'more than' in Article 4 matters; that observation is not an exemption from other applicable duties or a reason to avoid a reasoned audit programme.
For a qualifying domestic small processor handling fewer than 100,000 people, the rules effective from 1 September 2026 permit the simplified self-check form, with at least one audit every five years and retention of the form for at least five years. Article 13 preserves different legal or administrative-regulation requirements for minors' information. Platform-coverage and certification provisions have their own conditions; do not present five years as a universal safe interval.
Separate routine audits from authority-required audits
Article 3 permits regular work by an internal unit or a commissioned professional organization. Article 5 permits the competent protection authority to require a professional audit for specified risks or incidents: substantial rights/security risk, possible harm to many people, or an incident involving at least one million people's information or at least 100,000 people's sensitive information being leaked, altered, lost or destroyed. The first two grounds are not conditional on reaching the incident numbers.
The authority-required track carries specific reporting and remediation steps. It is misleading to apply those steps automatically to every voluntary internal audit, or to treat an internal audit as a substitute for the professional audit that an authority has required.
| Step | Authority-required track | Preparation evidence |
|---|---|---|
| Scope and appointment | Select the professional organization as required by the authority. | Authority request, agreed scope, capability and independence records. |
| Completion time | Meet the authority's deadline; complex cases need approved extension. | Workplan, requests for evidence, deadline or approved extension. |
| Audit report | Report to the authority after completion, with required responsible signatures and the firm's seal. | Final signed report and proof of submission. |
| Remediation report | Submit within 15 working days after remediation is completed. | Findings, corrective actions, retest and completion date. |
Turn the official audit topics into tests
The annex covers legal bases, notices, entrustment, automated decisions and other processing duties. The original examples below show the difference between possessing a document and testing a control. They are selected tests, not the whole official audit checklist and not a universal sampling standard.
| Topic | Test the actual process | Preserve the result |
|---|---|---|
| Consent and notice | Compare the notice version shown at collection with the legal basis and recorded choices. | Version, timestamp, scenario and any exception rationale; minimize personal identifiers. |
| Entrusted processing | Match contractual scope with real recipient access and evidence of supervision. | Contract clause, access sample, review result and discrepancy owner. |
| Automated decisions | Test transparency, review/rejection mechanisms and significant decision explanations. | Scenario, expected behavior, actual behavior and remediation. |
| Retention and rights | Follow a deletion or access request through systems and relevant recipients. | Request timeline, completion evidence, exceptions and unresolved systems. |
| Prior impact assessments | Select a covered activity and compare its live facts with the recorded assessment. | Assessment version, changed facts and the action taken. |
Keep the professional-audit safeguards visible
The Measures require appropriate capability and resources, encourage certification, prohibit subcontracting the audit to another institution, and prohibit three or more consecutive audits of the same object by the same firm and its affiliates or the same audit lead. Certification is encouraged in Article 7, not expressed there as a universal compulsory credential. Keep the engagement history and actual personnel, not just the firm's marketing description.
Article 13 also imposes confidentiality and timely deletion of information obtained in professional audit work when that work ends. Set controlled access to evidence and agree how copies will be returned or deleted. Do not infer a universal three-year audit-file retention duty from PIPL Article 56: that article addresses impact-assessment reports and processing records. Distinguish the processor's lawful records from the auditor's copies.
Article 19 excludes state organs and organizations authorized by law or regulation to manage public affairs from these Measures. That scope exclusion should not be described as freedom from all personal information obligations.
Example: a retention promise fails in operation
Hypothetical example: a service promises deletion after twelve months, while an audit sample finds identifiable backups retained for thirty-six months and no tested rights-request workflow for those copies. The useful finding describes the affected systems, sample limitations, expected requirement and observed mismatch; simply writing 'update privacy policy' does not address the operational issue.
Assign a responsible owner, choose and implement the correction, test the result and record residual limitations. Revisit relevant impact assessments if their assumed safeguards or retention facts are no longer true. For an authority-required audit, keep the completion date needed for the 15-working-day remediation-report clock. These are two connected records, not one interchangeable 'compliance document'.
Official sources & revisions
- PIPL Articles 54–56: regular audits, prior impact assessment and records
- 2025 Compliance Audit Measures, Articles 2–15, 19–20 and the audit guidelines
- MOFCOM official republication of the 2026 small-processor rules: Articles 2, 8, 13–14, 17, 21–22
: Expanded the existing audit overview with precise population thresholds, regular versus authority-required workflows, 2026 small-processor limits, evidence tests, professional-firm safeguards and a hypothetical remediation case.
Examples and working tables are original research aids, not official forms or legal advice.
Suggest a correction