Research across the library

Search laws, regulations, standards and guides

Suggested searches

Current priorities

2026-07-03Revised Internet Information Service Measures draft2026-06-18Network data risk assessment: draft versus final

This week's changes

Upcoming

Simplified personal information protection measures for small processors published

The joint CAC and Ministry of Public Security provisions define eligible small processors by a fewer-than-100,000-person threshold and establish proportionate compliance measures, including simplified audit, impact-assessment and selected cross-border data transfer arrangements. They take effect on 1 September 2026.

Official sourceWhat changed
Guidance

CAC publishes July 2026 cross-border data transfer security management Q&A

The official Q&A addresses notification and separate-consent duties, extension conditions for security assessments for cross-border data transfers, and necessity questions for recruitment-related transfers. It is implementation guidance rather than a new binding rule.

Official source
Operational

CAC publishes July generative AI and deep-synthesis filing updates

July filing publications report service and algorithm filing activity. They are grouped as operational updates and do not create a new generally binding rule.

Official source

Upcoming effective dates

Upcoming

Final Network Data Security Risk Assessment Measures published

The final measures replace the 2025 consultation proposal and introduce a 20-working-day reporting period for specified assessments. They take effect on 20 August 2026.

Official sourceWhat changed
Upcoming

Simplified personal information protection measures for small processors published

The joint CAC and Ministry of Public Security provisions define eligible small processors by a fewer-than-100,000-person threshold and establish proportionate compliance measures, including simplified audit, impact-assessment and selected cross-border data transfer arrangements. They take effect on 1 September 2026.

Official sourceWhat changed

Consultations to watch

Draft

Revised Internet Information Service Measures released for consultation

A revised draft was released for public comment. It remains a consultation document and is not presented as current law.

Official source
Draft

Draft Measures for Distributed Digital Identity Management released

The CAC released a consultation draft for distributed digital identity services. It is tracked as a draft and does not yet impose effective obligations.

Official source
Draft

Draft revision of the Personal Information Security Specification opened for comment

TC260 opened a draft revision related to GB/T 35273-2020 for public comment. The draft is not an effective national standard and should be monitored as a possible successor framework.

Official sourceWhat changed

Standards and sector guidance

Draft

Draft revision of the Personal Information Security Specification opened for comment

TC260 opened a draft revision related to GB/T 35273-2020 for public comment. The draft is not an effective national standard and should be monitored as a possible successor framework.

Official sourceWhat changed
Guidance

2026 Automotive Cross-Border Data Transfer Security Guideline issued

The industry guideline explains security practices for automotive cross-border data transfers. It complements rather than replaces the 2021 automotive-data provisions.

Official sourceWhat changed

Actions to consider

  1. Confirm the small-processor threshold and exclusions before simplifying an existing program.
  2. Review security-assessment renewal plans against the July Q&A.
  3. Separate binding AI duties from filing announcements in internal inventories.

Continue the research