On 22 July 2026, the Cyberspace Administration of China (CAC) and the Ministry of Public Security jointly issued the Provisions on Simplified Measures for Personal Information Protection by Small-Scale Personal Information Handlers (Simplified Measures), which will take effect on 1 September 2026. The Simplified Measures aim to provide small-scale personal information handlers with practicable and streamlined compliance pathways. Businesses focusing on corporate customers, small and medium-sized enterprises, and merchants operating on online platforms can benefit from these Simplified Measures. This article introduces the key provisions under the Simplified Measures and the steps to be taken by small-scale handlers.

Scope of applicability

The Simplified Measures apply to small-scale personal information handlers that process personal information of fewer than 100,000 individuals, regardless of the business size and revenue volume.

Businesses focusing on corporate customers and small and medium-sized enterprises are likely to fall within the scope, as their data processing activities are relatively straightforward and involve a limited number of data subjects.

The Simplified Measures are silent on how group companies can leverage these benefits. Where each member company processes personal information of fewer than 100,000 individuals but the group’s aggregate total exceeds the threshold, a further assessment will be needed to determine whether the member company independently qualifies as a small-scale personal information handler. That assessment should consider the purpose and method of processing, as well as whether data is managed at the group level or the individual company level.

Simplified notification and consent

The Simplified Measures have established a simplified notification mechanism for small-scale personal information handlers. Where a handler processes personal information solely as necessary to provide products or services, and neither shares the data with other parties nor publicly discloses it, the handler may fulfil its notification obligations simply by making its privacy notice publicly available, without needing to notify each individual.

The mandatory content of the privacy notice is also reduced. It need only include (i) the name of the personal information handler; (ii) the contact details for responding to individuals’ requests; and (iii) the purpose and method of processing, the types of personal information processed, and the retention period. The procedures for individuals to exercise their rights do not need to be included.

According to the Personal Information Protection Law (PIPL), regular personal information handlers generally obtain the consent of individuals before collecting personal information, unless another legal basis applies. As provided in the Simplified Measures, small-scale handlers do not need to obtain consent where individuals voluntarily and proactively provide their personal information as necessary to obtain a product or service.

However, where sensitive personal information is involved, handlers must also inform individuals of the necessity of processing such information and its impact on their rights. In this case, handlers must obtain the individual’s separate consent.

Simplified form for compliance audit and PIPIA

As required by the PIPL, personal information handlers must conduct compliance audits periodically. Under the Administrative Measures for Personal Information Protection Compliance Audits, large-scale personal information handlers (i.e., those processing the personal information of more than 10 million individuals) must conduct such audits at least once every two years. The Simplified Measures significantly extend this cycle for small-scale handlers, requiring compliance audits only once every five years.

To facilitate these audits, the Simplified Measures provide a standardised self-assessment form as an annex. Small-scale handlers need only tick the boxes in the form to confirm compliance with each requirement, without needing to draft assessment reports from scratch. This could greatly reduce the compliance burden for small-scale handlers.

Similarly, the Simplified Measures include a template report for personal information protection impact assessments (PIPIAs). Small-scale handlers need only complete the simplified form to conduct their assessments.

Reliance on online platform operators

Small-scale personal information handlers that operate on online platforms can also benefit from the Simplified Measures. Where the online platform has published privacy policies covering its operators’ processing activities, small-scale handlers are no longer required to formulate their own privacy policies or obtain consent from data subjects independently, provided they process personal information solely through the online platform and within the scope of the privacy policy published by the platform.

Similarly, small-scale handlers are not required to duplicate such efforts if the platform has conducted a personal information compliance audit and a PIPIA that cover the handlers’ processing activities conducted through the platform.

Notification for corporate restructuring 

Under the PIPL, personal information handlers must notify the affected data subjects if their personal information needs to be transferred in the event of corporate restructuring, such as a merger, division, dissolution, or declaration of bankruptcy. The Simplified Measures provide guidance on how small-scale handlers may satisfy this obligation. Handlers may provide notice by posting announcements at their business premises or on their website or app, sending SMS reminders, or displaying pop-up notifications.

Regardless of the notification method chosen, small-scale handlers must send the notice at least 30 working days in advance, and the notice must remain available for no fewer than 30 working days. This ensures that individuals whose personal information may be transferred have adequate time and opportunity to be informed of the transfer and the identity of the receiving party before the transfer takes effect.

Reduced administrative penalties

Small-scale personal information handlers can benefit from a more lenient enforcement approach under the Simplified Measures. Penalties may be waived where: (i) the violation is minor and promptly corrected without causing harmful consequences; (ii) there is sufficient evidence to demonstrate the absence of subjective fault; or (iii) the violation is a first-time offence with limited harm that is corrected in a timely manner.

However, even where penalties are not imposed, regulatory authorities may still adopt supervisory measures such as formal interviews or reminder letters. This ensures that small-scale handlers remain subject to oversight and receive guidance aimed at ensuring full compliance.

Practical takeaways

The Simplified Measures represent a significant compliance incentive for multinational companies operating in China, particularly those with B2B-focused business models. To capitalise on this opportunity, companies should take the following steps: 

  1. Assess eligibility and monitor the threshold dynamically. Businesses should evaluate whether their current data processing scale falls below the 100,000-individual threshold and establish an ongoing monitoring mechanism. Additional assessment will be needed to determine whether a member company of a group can independently qualify as a small-scale personal information handler. 
  2. Streamline notification and consent procedures. Handlers should review their data categories to determine which simplified procedures they can adopt. If no sensitive personal information is involved, small-scale handlers can update their notification and consent procedures accordingly.
  3. Leverage standardised templates for compliance audits and impact assessments. Although only required to conduct compliance audits once every five years, small-scale handlers should keep track of their audit deadlines, complete the standardised forms provided by the Simplified Measures, and retain records for the required retention periods.
  4. Take advantage of platform-level compliance. To leverage the platform’s compliance efforts, small-scale handlers should review and confirm whether the platform has formulated privacy policies, obtained consent from data subjects, and conducted a PIPIA and compliance audit that cover the handler’s processing activities. If processing falls outside the platform’s disclosed scope, the handler must independently fulfil its own compliance obligations.
  5. Establish rapid rectification procedures. Small-scale handlers should establish basic internal procedures to identify and correct non-compliance promptly. In the event of a violation, they should implement rectification immediately – prompt rectification could serve as a crucial mitigating factor in any enforcement action.

Client Alert 2026-159

Related Insights