The law library · China · Departmental rules, in force 1 September 2026
China: Simplified PIPL measures for small personal information processors
Provisions on Simplified Personal Information Protection Measures for Small Personal Information Processors · CAC and Ministry of Public Security Order No. 25 · published 22 July 2026 · in force 1 September 2026
Page verified 13 August 2026 against the full Chinese text published on cac.gov.cn, including the Article 2 definition and the Article 22 effective-date clause, both quoted below in translation.
China’s de-burdening rules for small operators. A processor handling personal information of fewer than 100,000 individuals may use simplified notice, lighter cross-border paths, five-yearly self-assessment audits and simplified impact assessments, while breach notification and individuals’ rights stay at full strength. In force from 1 September 2026.
Status
- 26 Jun 2026Adopted at the CAC’s 14th office meeting, with the agreement of the Ministry of Public Security.
- 22 Jul 2026Published as Order No. 25 of the two authorities.
- 1 Sep 2026In force. Article 22: the provisions take effect from 1 September 2026.
Who it applies to
- Art. 2A small personal information processor is one processing the personal information of fewer than 100,000 individuals, within Chinese territory.
- NoteThe definition itself carries no sector carve-outs; other articles impose additional safeguards where sensitive personal information is involved.
What is simplified, and what is not
- Arts 4-6Notice: simplified disclosure, physical notices for offline collection, service agreements or pop-ups online; no individual notification where processing rules are publicly visible and the processing is necessary for the service.
- Art. 10Cross-border: five categories of transfer need no security assessment, including contractual necessity, emergency protection, legal obligations, and transfers under 100,000 individuals annually.
- Art. 13Compliance audit: at least once every five years, using simplified self-assessment forms.
- Art. 14Impact assessments: simplified methodology permitted.
- Still fullBreach notification, security incident reporting, and individuals’ rights mechanisms (Art. 11) remain at full PIPL strength, and violations feed credit records (Art. 21).
Why it is on this list
This is the counterweight to the PIPL: the obligations catalogue stays, but a small processor gets a lighter administrative path through it. For any vendor or firm processing modest volumes of Chinese personal information, the question from 1 September 2026 is which side of the 100,000-individual line the operation sits on, and being able to prove it.
What the signed record shows
A five-yearly self-assessment is only as strong as the records behind it.
The simplified regime replaces external checks with the processor’s own attestations: that the count stayed under 100,000, that the notices showed, that the incident duties were met. A signed, tamper-evident record made in the ordinary course is what turns those attestations into evidence rather than assertion. The connection here is the same as under the parent law, and the PIPL pack is the place to start.
Sources
Related
- The law library · AI rules by country
- China PIPL, the parent law these provisions simplify
- China Data Security Law · China Cybersecurity Law
Checked against the source 13 August 2026: the full Chinese text on cac.gov.cn. Translation of quoted provisions is ours. Information, not legal advice.
Information, not legal advice. Every entry is verified against the issuing body’s own document; where a source is reporting rather than the document, we say so.
