Provisions on Simplified Measures for Personal Information Protection by Small Personal Information Processors — Full English Translation (2026)

Adopted at the 14th executive meeting of the Cyberspace Administration of China in 2026 on June 26, 2026, and approved by the Ministry of Public Security

Promulgated by Decree No. 25 of the Cyberspace Administration of China and the Ministry of Public Security on July 22, 2026

Effective: September 1, 2026


Article 1 — These Provisions are formulated in accordance with the Personal Information Protection Law of the People’s Republic of China, the Regulations on the Administration of Network Data Security, and other laws and administrative regulations, for the purpose of supporting the innovation and development of micro, small, and medium-sized enterprises and simplifying the measures for small personal information processors to fulfill their personal information protection obligations.

Article 2 — These Provisions apply to the implementation of personal information protection by small personal information processors within the territory of the People’s Republic of China.

For the purposes of these Provisions, “small personal information processor” means a personal information processor that processes the personal information of fewer than 100,000 individuals.

Article 3 — Small personal information processors are supported in adopting, on the basis of complying with relevant laws, administrative regulations, and state provisions on personal information protection, simplified measures commensurate with their scale and capabilities in accordance with these Provisions to safeguard personal information security and protect personal information rights and interests.

Article 4 — The rules for processing personal information of a small personal information processor shall at least include the following content:

(1) the name of the small personal information processor;

(2) the department or personnel handling the exercise of rights by individuals, and their contact information;

(3) the purposes and methods of processing personal information, the categories of personal information processed, and the retention period.

A small personal information processor that collects personal information offline may make its rules for processing personal information public through simplified means such as posting notices in a conspicuous place at its business premises; a small personal information processor that collects personal information online may make its rules for processing personal information public through service agreements, pop-ups on the client of its products and services, website announcements, and other means.

A small personal information processor that processes the personal information of minors under the age of fourteen shall formulate specific rules for processing personal information.

Article 5 — Service management units such as industrial parks, industrial bases, and commercial properties are supported in uniformly formulating, and making public in a conspicuous place, rules for processing personal information for small personal information processors that carry out the same offline business within the scope of their service management. Small personal information processors that agree to abide by the unified rules for processing personal information and are listed in such rules may be exempted from formulating their own rules for processing personal information.

Article 6 — A small personal information processor that simultaneously meets the following conditions may fulfill its notification obligation to individuals merely by making its rules for processing personal information public, and the rules for processing personal information shall be brought to the attention of users through conspicuous means such as bold fonts, enlarged font size, and differently colored marks, and shall be easy to consult and save:

(1) the processing of personal information (excluding sensitive personal information) is necessary for providing products or services;

(2) it does not provide personal information to other personal information processors and does not disclose personal information to the public, and it expressly states this in its rules for processing personal information.

Where laws, administrative regulations, or departmental rules provide otherwise for the processing of sensitive personal information by small personal information processors, such provisions shall prevail.

Article 7 — Where, after a small personal information processor has made its rules for processing personal information public and fulfilled its notification obligation, an individual voluntarily and proactively provides, or voluntarily and proactively cooperates with the small personal information processor in providing, the personal information necessary for obtaining products or services, in order to obtain the products or services and on the basis of full knowledge, the small personal information processor may process the individual’s personal information in accordance with the published rules for processing personal information; where sensitive personal information is processed for specific purposes, the small personal information processor shall notify the individual of the necessity of processing sensitive personal information and the impact on personal rights and interests in its rules for processing personal information, and obtain the individual’s separate consent.

Where laws, administrative regulations, or departmental rules provide otherwise for the processing of sensitive personal information by small personal information processors, such provisions shall prevail.

Article 8 — A small personal information processor that simultaneously meets the following conditions may be exempted from formulating rules for processing personal information and from fulfilling the notification obligation:

(1) it conducts personal information processing activities only through online platforms, and does not provide personal information to other personal information processors outside the online platform;

(2) the online platform has formulated and published rules for processing personal information targeting the personal information processing activities of the small personal information processor, and has agreed with the small personal information processor on their respective rights and obligations;

(3) the small personal information processor declares that it will abide by the rules for processing personal information formulated by the online platform in accordance with these Provisions, and the processing of personal information is necessary for providing products or services and does not exceed the purposes, methods, and categories of personal information stated in the rules mentioned in the preceding item.

Where the conditions in the preceding paragraph are met, and the online platform has already conducted a personal information protection compliance audit and a personal information protection impact assessment covering the personal information processing activities conducted by the small personal information processor relying on the online platform, the small personal information processor may be exempted from conducting them again.

Where the purposes, methods, and categories of the processing of personal information by a small personal information processor exceed the scope of the rules for processing personal information of the online platform, it shall separately formulate rules for processing personal information in accordance with these Provisions and fulfill the notification, compliance audit, and impact assessment obligations.

Where an online platform adjusts its rules for processing personal information, it shall promptly notify the relevant small personal information processors.

Article 9 — Where a small personal information processor needs to transfer personal information due to merger, division, dissolution, declaration of bankruptcy, or other reasons, it may notify the name and contact information of the recipient through simplified means such as posting notices in a conspicuous place at its business premises and SMS reminders; where it independently provides online products or services, it shall also notify the name and contact information of the recipient through means such as pop-up notices on the client of its products and services; where it provides products or services relying on an online platform, it may notify through means such as notices on its merchant page or mini-program notices within the online platform.

A small personal information processor shall publicly publish the notification matters specified in the preceding paragraph at least 30 working days in advance, and the publication shall last for no less than 30 working days.

Article 10 — Where a small personal information processor provides personal information overseas and meets any of the following conditions, it shall be exempted from filing for a data export security assessment, concluding a standard contract for personal information, and passing personal information protection certification:

(1) it is genuinely necessary to provide personal information overseas for the conclusion or performance of a contract to which the individual is a party, such as cross-border shopping, cross-border delivery, cross-border remittance, cross-border payment, cross-border account opening, air ticket and hotel booking, visa processing, and examination services;

(2) it is genuinely necessary to provide employees’ personal information overseas for implementing cross-border human resources management in accordance with labor rules and regulations formulated in accordance with the law and collective contracts concluded in accordance with the law;

(3) it is genuinely necessary to provide personal information overseas for protecting the life, health, and property safety of natural persons in emergencies;

(4) it is genuinely necessary to provide personal information overseas for performing statutory duties or statutory obligations;

(5) a personal information processor other than an operator of critical information infrastructure has, since January 1 of the current year, provided overseas the personal information of fewer than 100,000 individuals in aggregate (excluding sensitive personal information);

(6) other conditions specified by laws, administrative regulations, or the national cyberspace administration department.

The personal information provided overseas as mentioned in the preceding paragraph does not include important data.

Where a small personal information processor provides personal information overseas, it shall fulfill obligations such as notification and obtaining the separate consent of individuals in accordance with laws and administrative regulations.

Where a small personal information processor genuinely needs to provide personal information outside the territory of the People’s Republic of China and applies to the cyberspace administration department for a data export security assessment in accordance with the law, the provincial-level cyberspace administration department at its locality may form an evaluation conclusion and recommendation and submit it to the national cyberspace administration department for approval.

Departments performing personal information protection duties, data cross-border service centers, and the like are encouraged to provide consulting and other services for the overseas provision of personal information by small personal information processors.

Article 11 — A small personal information processor may establish a mechanism for accepting and handling applications for the exercise of rights by individuals in personal information processing activities by making public the department or personnel handling the exercise of rights by individuals and their contact information.

Article 12 — A small personal information processor that ceases to provide products or services shall take necessary measures to delete personal information; where it genuinely has no capacity to delete the personal information, it may report to the relevant competent department at its locality and request assistance; where the competent department is unclear, it may report to the cyberspace administration department at the level of a city divided into districts at its locality.

Article 13 — A small personal information processor may, in the simplified manner specified in the Annex to these Provisions, the “Self-Inspection Form for Personal Information Protection Compliance Audits of Small Personal Information Processors,” conduct a personal information protection compliance audit at least once every five years, and keep the compliance audit self-inspection form for at least five years.

Where laws and administrative regulations provide otherwise for compliance audits concerning the processing of minors’ personal information, such provisions shall prevail.

Article 14 — A small personal information processor may, in the simplified manner specified in the Annex to these Provisions, the “Personal Information Protection Impact Assessment Form for Small Personal Information Processors,” conduct a personal information protection impact assessment, and keep the impact assessment form for at least three years.

Article 15 — A small personal information processor may establish a personal information protection management system and an emergency response plan for personal information security incidents through simplified means such as specifying in organizational management documents the internal management requirements for personal information protection and the requirements for emergency handling of personal information security incidents.

Article 16 — Where personal information is or is likely to be leaked, altered, or lost, a small personal information processor shall immediately take remedial measures and notify individuals in accordance with laws and administrative regulations; where it is genuinely impossible, due to objective conditions, to notify individuals through other means, it may notify individuals merely through simplified means such as posting notices in a conspicuous place at its business premises, pop-ups on the client of its products and services, and website announcements, and shall notify the departments performing personal information protection duties in accordance with the provisions; where a crime is suspected, it shall promptly report the case to the public security authorities.

Article 17 — Personal information protection certification institutions are supported in conducting certification work targeting small personal information processors to improve service quality. Small personal information processors that have passed personal information protection certification may be exempted from conducting personal information protection compliance audits during the validity period of the certification.

Article 18 — Where a small personal information processor falls under any of the following circumstances in conducting personal information processing activities, it shall not be penalized:

(1) the violation is minor and promptly corrected, and no harmful consequences have been caused;

(2) there is sufficient evidence to prove the absence of subjective fault; where laws and administrative regulations provide otherwise, such provisions shall prevail;

(3) other circumstances under which penalties shall not be imposed in accordance with the law.

Where a small personal information processor commits a first violation in conducting personal information processing activities, the harmful consequences are minor, and it promptly corrects the violation, it may be exempted from penalties. Where it is exempted from penalties in accordance with the law, the department performing personal information protection duties shall, as the circumstances require, take regulatory measures such as conducting talks and issuing reminder letters.

Article 19 — Where a small personal information processor falls under any of the following circumstances in conducting personal information processing activities, it shall be given lighter or mitigated penalties:

(1) it proactively eliminates or mitigates the harmful consequences of the violation;

(2) it proactively confesses violations of which the department performing personal information protection duties is not yet aware;

(3) when a personal information security incident occurs, it promptly notifies individuals and takes remedial measures, and proactively notifies the relevant departments;

(4) it performs meritorious service by cooperating with the department performing personal information protection duties in investigating and handling violations;

(5) other circumstances under which lighter or mitigated penalties shall be imposed in accordance with the law.

Article 20 — Enterprises, relevant social organizations, professional institutions, and the like are supported in helping small personal information processors improve their personal information protection capabilities through organizing training, lectures, legal publicity activities, consulting, and guidance.

Departments performing personal information protection duties are encouraged to provide small personal information processors with infrastructure, technical tools, consulting services, and the like for the safe and convenient processing of personal information, so as to reduce the compliance costs of small personal information processors.

Article 21 — Cyberspace administration departments, public security authorities, and other departments performing personal information protection duties may conduct supervision and inspection of the performance of personal information protection obligations by small personal information processors through means such as random inspections and assessments and audit reports, and small personal information processors shall cooperate.

Where cyberspace administration departments, public security authorities, and other departments performing personal information protection duties discover that a small personal information processor has processed personal information in violation of the law or has repeatedly experienced personal information security incidents, they shall handle the matter in accordance with the Personal Information Protection Law of the People’s Republic of China, the Regulations on the Administration of Network Data Security, and other relevant laws and administrative regulations, and record it in the credit archives and make it public in accordance with the relevant laws and administrative regulations.

Article 22 — These Provisions shall come into force on September 1, 2026.

Wechat

WhatsApp

WhatsApp

WhatsApp
[email protected]
+86 18565453956