Research across the library

Search laws, regulations, standards and guides

Suggested searches

Current priorities

2026-07-03Revised Internet Information Service Measures draft2026-06-18Network data risk assessment: draft versus final
202607-24
UpcomingFinal rule01

Simplified personal information protection measures for small processors published

The joint CAC and Ministry of Public Security provisions define eligible small processors by a fewer-than-100,000-person threshold and establish proportionate compliance measures, including simplified audit, impact-assessment and selected cross-border data transfer arrangements. They take effect on 1 September 2026.

Related framework
PIPL / Network Data Security Regulation
Impact
high
Effective
2026-09-01
202607-24
GuidancePolicy Q&A02

CAC publishes July 2026 cross-border data transfer security management Q&A

The official Q&A addresses notification and separate-consent duties, extension conditions for security assessments for cross-border data transfers, and necessity questions for recruitment-related transfers. It is implementation guidance rather than a new binding rule.

Related framework
PIPL / DSL / Security Assessment for Cross-Border Data Transfer
Impact
high
202607-17
OperationalOperational03

CAC publishes July generative AI and deep-synthesis filing updates

July filing publications report service and algorithm filing activity. They are grouped as operational updates and do not create a new generally binding rule.

Related framework
Generative AI Interim Measures / Deep Synthesis Provisions
Impact
low
202607-03
DraftConsultation04

Revised Internet Information Service Measures released for consultation

A revised draft was released for public comment. It remains a consultation document and is not presented as current law.

Related framework
CSL / DSL / PIPL
Impact
high
202606-18
UpcomingFinal rule05

Final Network Data Security Risk Assessment Measures published

The final measures replace the 2025 consultation proposal and introduce a 20-working-day reporting period for specified assessments. They take effect on 20 August 2026.

Related framework
CSL / DSL / PIPL
Impact
high
Effective
2026-08-20
202606-18
DraftConsultation06

Draft Measures for Distributed Digital Identity Management released

The CAC released a consultation draft for distributed digital identity services. It is tracked as a draft and does not yet impose effective obligations.

Related framework
CSL / DSL / PIPL
Impact
medium
202606-17
DraftStandards consultation07

Draft revision of the Personal Information Security Specification opened for comment

TC260 opened a draft revision related to GB/T 35273-2020 for public comment. The draft is not an effective national standard and should be monitored as a possible successor framework.

Related framework
PIPL / GB/T 35273-2020
Impact
high
202605-29
UpcomingFinal rule08

Multi-Channel Distribution Provisions published

The joint provisions govern multi-channel distribution of internet information services and take effect on 1 September 2026.

Related framework
CSL / DSL / PIPL
Impact
medium
Effective
2026-09-01
202605-22
GuidancePolicy guidance09

AI Application Ethics and Security Guideline issued

The guideline is tracked as policy guidance for AI application governance, distinct from binding laws and departmental rules.

Related framework
CSL / DSL / PIPL
Impact
medium
202605-08
GuidancePolicy guidance10

Implementation opinion on regulated intelligent-agent applications issued

Five authorities issued policy guidance on the development and regulated application of intelligent agents. It is tracked as guidance rather than a binding departmental rule.

Related framework
CSL / DSL / PIPL
Impact
medium
202604-29
GuidancePolicy Q&A11

CAC publishes April personal information protection Q&A

The official Q&A addresses implementation questions and is classified as guidance, not a new binding rule.

Related framework
PIPL
Impact
medium
202604-10
EffectiveFinal rule12

Anthropomorphic AI Interaction Interim Measures published

The interim measures establish governance requirements for anthropomorphic AI interaction services and took effect on 15 July 2026.

Related framework
CSL / DSL / PIPL
Impact
high
Effective
2026-07-15
202604-10
EffectiveFinal rule13

Cybersecurity Label Management Measures published

The measures establish a cybersecurity labeling framework and took effect on 1 July 2026. Product-catalog announcements are tracked separately as operational updates.

Related framework
CSL
Impact
medium
Effective
2026-07-01
202604-03
DraftConsultation14

Draft rules for digital virtual human services released

The draft addresses governance of digital virtual human services and is presented as a consultation document rather than current law.

Related framework
CSL / DSL / PIPL
Impact
medium
202604-03
SupersededConsultation15

Consultation draft on simplified measures for small personal information processors superseded

The April consultation proposal was superseded by final joint CAC and Ministry of Public Security provisions published on 24 July 2026. It is retained only as version history.

Related framework
PIPL
Impact
medium
202604-02
EnforcementEnforcement16

2026 personal information protection campaign announced

The CAC announced a 2026 special enforcement campaign. This is classified as an enforcement update rather than a new source of generally binding rules.

Related framework
PIPL
Impact
medium
202602-28
EffectiveFinal rule17

Measures for identifying major online platforms serving minors published

The measures establish identification criteria for major platforms serving large numbers of minors and took effect on 1 April 2026.

Related framework
Minors Protection / Platform Governance
Impact
high
Effective
2026-04-01
202602-03
GuidanceIndustry guidance18

2026 Automotive Cross-Border Data Transfer Security Guideline issued

The industry guideline explains security practices for automotive cross-border data transfers. It complements rather than replaces the 2021 automotive-data provisions.

Related framework
DSL / PIPL / Automotive Data Provisions
Impact
high
202601-30
GuidancePolicy Q&A19

CAC publishes January cross-border data transfer Q&A

The Q&A provides official implementation guidance for cross-border data transfer pathways and is classified separately from binding rules.

Related framework
PIPL / DSL
Impact
high
202601-23
EffectiveFinal rule20

Minors' Online Information Classification Measures published

The measures establish a classification framework for online information affecting minors and took effect on 1 March 2026.

Related framework
Minors Protection / Platform Governance
Impact
high
Effective
2026-03-01
202601-10
DraftConsultation21

Draft provisions on personal information collection and use by apps released

The consultation draft addresses app collection and use of personal information. It remains a draft and is not described as current law.

Related framework
PIPL
Impact
high
202601-09
GuidancePolicy Q&A22

CAC publishes personal information protection policy Q&A

The official Q&A is tracked as interpretive guidance and is kept separate from binding laws and departmental rules.

Related framework
PIPL
Impact
medium
202512-31
EffectiveStandard publication23

Two personal information protection standards published

GB/T 46901-2025 addresses transfer based on an individual's request and GB/T 46903-2025 addresses personal information protection compliance audits. The site tracks official metadata and does not reproduce the standards.

Related framework
PIPL
Impact
medium
Effective
2026-07-01
202512-06
SupersededConsultation24

Network data security risk assessment draft released for consultation

This consultation draft was superseded by the June 2026 final measures. The comparison record preserves the procedural changes between the two versions.

Related framework
CSL / DSL / PIPL
Impact
high
202511-22
DraftConsultation25

Draft rules for personal information protection by large online platforms released

The proposal targets large online platforms and remains a consultation document pending a final rule.

Related framework
PIPL
Impact
high
202510-28
EffectiveAmendment26

2025 Cybersecurity Law amendments take effect

The amendment decision updates liability and enforcement provisions while preserving the law's broader structure. The amended text is now in force.

Related framework
CSL
Impact
high
Effective
2026-01-01
202510-17
EffectiveFinal rule27

Personal Information Export Certification Measures take effect

The measures create the binding departmental-rule layer for the certification route and retain the three-year validity and renewal timing already present in the 2022 implementation rules.

Related framework
PIPL
Impact
high
Effective
2026-01-01
202509-15
EffectiveFinal rule28

Network Security Incident Reporting Measures published

The measures establish reporting requirements for network security incidents. Dates and scope are presented only as stated in the official source.

Related framework
CSL
Impact
high
202507-18
OperationalOperational update29

CAC issues announcement on reporting personal information protection officers

The announcement is tracked as an operational compliance update concerning officer-information reporting, not as a new law.

Related framework
PIPL
Impact
medium
202505-23
EffectiveFinal rule30

National Network Identity Authentication Measures take effect

The six-authority measures governing the national network identity authentication public service took effect on 15 July 2025.

Related framework
PIPL / CSL
Impact
medium
Effective
2025-07-15
202503-21
EffectiveFinal rule31

Facial Recognition Security Measures take effect

The joint CAC and Ministry of Public Security measures governing facial-recognition applications took effect on 1 June 2025.

Related framework
PIPL
Impact
high
Effective
2025-06-01
202503-14
EffectiveFinal rule32

AI-generated and synthetic content labeling rules take effect

The joint labeling measures and mandatory national standard GB 45438-2025 took effect together and now form a verified part of the generative-AI source chain.

Related framework
CSL / DSL / PIPL
Impact
high
Effective
2025-09-01
202502-14
EffectiveFinal rule33

Personal Information Protection Compliance Audit Measures take effect

CAC Order No. 18 establishes the administrative framework for personal information protection compliance audits and took effect on 1 May 2025.

Related framework
PIPL
Impact
high
Effective
2025-05-01