Simplified personal information protection measures for small processors published
The joint CAC and Ministry of Public Security provisions define eligible small processors by a fewer-than-100,000-person threshold and establish proportionate compliance measures, including simplified audit, impact-assessment and selected cross-border data transfer arrangements. They take effect on 1 September 2026.
- Related framework
- PIPL / Network Data Security Regulation
- Impact
- high
- Effective
- 2026-09-01