Authors
On 7 August 2026, the Cyberspace Administration of China (CAC) published the Draft Provisions on Personal Information Protection for Large-Scale Personal Information Handlers (Draft Regulation) for public comment, with the consultation period closing on 7 September 2026.
The Draft Regulation comes on the heels of the Provisions on Simplified Measures for Personal Information Protection for Small-Scale Personal Information Handlers, which will take effect on 1 September 2026 (Simplified Measures). For further analysis of the Simplified Measures, please see our previous client alert. Together, these two instruments reflect a clear regulatory strategy of tiered administration under which the CAC imposes differentiated compliance obligations on personal information handlers according to the scale and impact of their data processing activities. While the Simplified Measures reduce the compliance burden for small-scale PI handlers, the Draft Regulation moves in the opposite direction, layering detailed and prescriptive requirements on top of the principles-based framework under the PRC Personal Information Protection Law (PIPL) for the largest personal information handlers.
Given the pace of recent legislative activity in this area and the regulator’s evident intent to complete the tiered framework, the Draft Regulation is expected to be finalised in the near term. Organisations that may fall within scope are advised to begin assessing their readiness now, rather than taking a wait-and-see approach.
Scope of applicability
The Draft Regulation applies to “large-scale personal information handlers”, which refers to business entities meeting the following criteria: (i) the entity processes the personal information of 10 million or more individuals; (ii) it provides significant internet-based services involving personal information processing or conducts multiple lines of business that involve personal information processing; and (iii) its personal information processing activities have a significant impact on national security, economic operations, social stability, or public health and safety (Large-scale PI Handler).
Given China’s population of over 1.4 billion, the 10 million threshold is well within reach for many businesses. In practice, companies in sectors such as smart terminal devices, health care, and financial services, as well as e-commerce operators and businesses whose operations primarily serve individual consumers, are highly likely to fall within scope, given the number of data subjects whose personal information they process and the multiple business lines in which they typically operate.
Importantly, recognition as a Large-scale PI Handler is not automatic. Organisations that meet the qualifying criteria must conduct a self-assessment and file an application with the CAC for formal designation. Provincial authorities have 15 working days to complete a preliminary review and issue an opinion, after which the national-level CAC will make the final determination. Even if a company does not voluntarily apply, the CAC can require it to do so if it appears to meet the criteria. The regulators will publish an official list of designated Large-scale PI Handlers.
Privacy policies
The Draft Regulation imposes heightened transparency requirements on Large-scale PI Handlers when disclosing their data practices to users. Notably, privacy policies must present key information in a structured checklist format, listing for each function or service the purposes, methods, and categories of personal information, the permissions invoked, the frequency with which personal information is accessed, the need to collect sensitive personal information, and the potential impact on individuals’ rights. The privacy policy should also disclose embedded third-party SDKs, including developer names, versions, and links to their privacy policies, again in a structured checklist format. Where Large-scale PI Handlers transfer personal information to third-party controllers, they must specify who those parties are, why they receive the data, and what categories of data are involved.
The requirement to list information in checklist format was first introduced in the Regulation on Network Data Security Management, published in 2024. However, in practice, most enterprises, in particular small and medium-sized enterprises, have not strictly complied with this requirement. The restatement of this requirement in the Draft Regulation indicates that the regulators will pay particular attention to the format of privacy policies when assessing Large-scale PI Handlers’ privacy compliance. Failure to comply with this formatting requirement may therefore present a significant risk of enforcement.
Internal governance framework
The Draft Regulation requires Large-scale PI Handlers to establish a comprehensive internal governance framework covering the full lifecycle of personal information handling, including the collection and storage of personal information, the handling of individual rights requests, and incident response. At a minimum, Large-scale PI Handlers must adopt formal policies and operating procedures across these key areas: data classification; secure storage and access control; privacy impact assessments and compliance audits; minors’ data protection; complaint and whistleblower handling; and staff training and awareness.
This is a notably prescriptive approach compared to the more principles-based requirements under the PIPL. In particular, the Draft Regulation includes complaint and whistleblower handling as a standalone policy requirement, which aligns with a broader enforcement trend towards responding proactively to individual complaints. In addition, the explicit inclusion of technical and organisational measures, such as secure storage and access controls, audit trails, security monitoring and emergency response drills, reflects a growing regulatory focus on data security.
Personal information protection officers and supervisory committees
The Draft Regulation requires Large-scale PI Handlers to designate a member of senior management as the personal information protection officer (PIPO). The PIPO’s responsibilities are broad, including overseeing the development of internal data protection policies and emergency response plans, guiding business units on compliant data handling, participating in corporate decision-making on matters involving personal information, and supervising the organisation’s overall data protection compliance.
A particularly significant feature is the PIPO’s escalation authority. Where the PIPO raises compliance concerns and the organisation fails, without justification, to address them, the PIPO may report directly to the relevant provincial CAC authority. This effectively creates an internal whistleblower channel within the corporate governance structure, which goes beyond what is typically seen under the PIPL.
Large-scale PI Handlers must also establish a personal information protection supervisory committee composed of at least seven members, with external members making up no less than two-thirds of the committee and an external member also serving as its chair. The committee’s operating rules and membership details must be filed with the CAC. This requirement introduces an independent oversight layer that reinforces the regulator’s intent to embed external accountability within the data governance frameworks of Large-scale PI Handlers.
Data localisation
The Draft Regulation requires personal information collected and generated through domestic operations in China to be stored within the territory of the PRC. This establishes a clear data localisation obligation for Large-scale PI Handlers. However, this does not mean that Large-scale PI Handlers cannot benefit from the cross-border data transfer relaxations available under the Provisions on Promoting and Regulating Cross-Border Data Flows (CBDT Provisions) issued by the CAC in March 2024.
When transferring personal information outside China, Large-scale PI Handlers are required to follow the appropriate regulatory pathway, i.e., undergo a security assessment led by the CAC, execute the Chinese SCC or obtain certification by a qualified institution (CBDT Mechanism). Under the Draft Regulation, exemptions from the CBDT Mechanism also apply to Large-scale PI Handlers. As a result, in less sensitive data transfer scenarios and those that do not trigger heightened thresholds, Large-scale PI Handlers can still benefit from the more flexible cross-border data transfer pathways established under the CBDT Provisions.
Beyond the general localisation requirement, the Draft Regulation specifies that qualifying data centres must meet three conditions: (i) they must be physically located within mainland China; (ii) their management entity’s legal representative or ultimate controller must hold PRC nationality; and (iii) they must comply with applicable national policies and technical standards. These criteria effectively limit the pool of eligible storage providers and may require affected organisations to reassess their existing data centre arrangements.
Complaint handling mechanisms
Large-scale PI Handlers must establish accessible and user-friendly channels for individuals to lodge complaints. These channels must be clearly disclosed in the privacy policy, and Large-scale PI Handlers must establish a robust internal mechanism for handling complaints. Critically, the Draft Regulation imposes a hard deadline requiring complaints to be accepted and resolved within the specified timeframe, which in any event may not exceed 15 working days.
Legal liability and penalties
The Draft Regulation empowers the CAC and other regulatory authorities to take a range of enforcement actions against non-compliant Large-scale PI Handlers. These include on-site inspections, regulatory interviews, mandatory rectification orders, and orders to dissolve an organisation’s supervisory committee if it fails to function as required. Regulators can also escalate enforcement by requiring an organisation to entrust its personal information processing to a qualifying third-party data centre if it fails to take rectification measures.
The Draft Regulation makes clear that Large-scale PI Handlers may incur liabilities under existing laws and regulations, including the PIPL, the Regulation on Network Data Security Management, and other administrative regulations. Where violations rise to the level of criminal conduct, criminal liability may be pursued.
Practical steps
The Draft Regulation is likely to be finalised and adopted soon. Companies that fall within scope should start preparing and take the following steps:
- Assess eligibility. Multinational companies operating in China should promptly evaluate whether they meet the qualifying thresholds. Company groups should map their data flows and assess whether the thresholds are met at the entity, product, and business-line levels. If they qualify, companies should apply for designation with the competent CAC authority in a timely manner.
- Overhaul privacy policies. Large-scale PI Handlers should conduct a gap analysis of their existing privacy policies against the substantive and format requirements under the Draft Regulation. If the policies are not compliant, they should be updated accordingly.
- Strengthen internal governance and establish required roles. Large-scale PI Handlers should conduct a thorough health check of their current internal governance arrangements and update their data protection frameworks in line with the requirements under the Draft Regulation. In addition, they should designate a PIPO and establish a supervisory committee in accordance with the Draft Regulation.
- Revisit data infrastructure and localisation arrangements. Large-scale PI Handlers which currently store personal information on overseas servers should migrate the relevant personal information to a domestic data centre in China. Companies should conduct due diligence on their cloud service providers to confirm that they meet the criteria specified under the Draft Regulation.
In-depth 2026-167