Skip to content
DCC · DATA COMPLIANCE CHINA China data law, for overseas counsel.
§ LAW · CAC PI PROTECTION Q&A (2026)

Policy and Regulatory Q&A on Personal Information Protection (2026 Batches).

个人信息保护政策法规问答(2026年)

Promulgated by: Cyberspace Administration of China (CAC).
Document No.: None (published as official policy Q&A batches).
Published January 9, 2026 (January batch); April 29, 2026 (April batch); August 12, 2026 (August batch).

Translation note — DCC. Translated in full from the official Chinese texts published by the CAC on cac.gov.cn and on the 网信中国 (Cyberspace China) WeChat channel. The three monthly batches are collected here in one entry; question numbering restarts within each batch as in the originals. Terminology follows DCC’s bilingual glossary. The answers construe the PIPL and the Administrative Measures for Personal Information Protection Compliance Audits.


January 2026 batch

The Cyberspace Administration of China continues to strengthen the dissemination of policies, laws and regulations on personal information protection, guiding and helping personal information handlers carry out personal information processing activities in a regulated manner and protecting personal information rights and interests. It hereby publishes a number of representative questions and answers as follows.

Q1. What is personal information?

A: Personal information is various kinds of information, recorded electronically or by other means, relating to an identified or identifiable natural person, excluding information that has been anonymized.

Personal information includes, but is not limited to, the following types: basic personal profile information such as name, date of birth and age; personal identity information such as identity card, military officer’s card and passport; biometric information such as face, genes, voiceprint, iris and fingerprints; network identity identifiers such as user accounts and user identifiers (user IDs); personal education and employment information such as educational history, occupation and position; personal property information such as financial accounts, consumption records, income status and borrowing information; identity authentication information such as account passwords and digital certificates; personal communications information such as communication records, text messages and emails; contact information such as address books and friend lists; personal internet browsing records such as web browsing history and software usage records; personal device information such as the International Mobile Equipment Identity (IMEI); personal location information such as transportation and travel information; personal tag information such as user tags and profiling information; personal exercise information such as step count and cadence; and all other kinds of information relating to an identified or identifiable natural person.

Q2. What is sensitive personal information?

A: Sensitive personal information is personal information which, once leaked or illegally used, is likely to result in infringement of a natural person’s personal dignity or harm to personal or property safety, including information on biometrics, religious belief, specific identity, medical health, financial accounts and whereabouts, as well as the personal information of minors under the age of fourteen.

The national standard GB/T 45574-2025, Data Security Technology — Security Requirements for Processing Sensitive Personal Information, sets out the method for identifying and delimiting sensitive personal information, and in Appendix A gives common categories of sensitive personal information, such as: biometric information such as face, genes and voiceprint; religious belief information such as the religion an individual believes in and the religious organizations the individual has joined; specific identity information such as the identity information of persons with disabilities and occupational identity information unsuitable for disclosure; medical health information such as illnesses, past medical history, medical consultation records and test and examination data; financial account information such as the account numbers and passwords of bank, securities, fund and insurance accounts; whereabouts information such as continuous precise positioning trajectory information and vehicle driving trajectory information; and other sensitive personal information such as resident identity card photographs, credit reporting information and criminal record information.

Q3. How is a personal information protection impact assessment conducted before facial recognition technology is applied to process facial information?

A: Article 9 of the Administrative Measures for the Application Security of Facial Recognition Technology provides that a personal information protection impact assessment shall be conducted before facial recognition technology is used, and the processing shall be recorded. The personal information protection impact assessment is organized and conducted by the personal information handler applying the facial recognition technology, and a third-party institution may participate. If a third-party institution participates, the assessment report must describe the basic particulars of the third-party institution and its participation in the assessment.

Four aspects are mainly assessed: first, whether the purpose and method of processing facial information are lawful, legitimate and necessary; second, the impact on individual rights and interests, and whether the measures to reduce adverse impact are effective; third, the risk of facial information being leaked, tampered with, lost, damaged or illegally obtained, sold or used, and the harm that may result; and fourth, whether the protective measures taken are lawful and effective and commensurate with the degree of risk.

Q4. Which personal information handlers must designate a person in charge of personal information protection and report that person’s information?

A: Article 52 of the Personal Information Protection Law of the People’s Republic of China provides that a personal information handler that processes personal information reaching the volume prescribed by the national cyberspace administration shall designate a person in charge of personal information protection (个人信息保护负责人), who is responsible for supervising personal information processing activities and the protective measures taken. Article 12 of the Administrative Measures for Personal Information Protection Compliance Audits provides that a personal information handler processing the personal information of 1 million or more persons shall designate a person in charge of personal information protection, who is responsible for the handler’s personal information protection compliance audit work.

On July 18, 2025, the Cyberspace Administration of China published the Announcement on Carrying Out the Reporting of Personal Information Protection Officer Information, specifying the requirements, timing and method for reporting information on persons in charge of personal information protection. The reporting is done online. Handlers may directly access the Personal Information Protection Business System (个人信息保护业务系统, https://grxxbh.cacdtsc.cn), prepare the relevant materials and complete the reporting formalities in accordance with the Instructions for Completing the Personal Information Protection Officer Information Reporting System (First Edition) provided on the system’s home page; the Personal Information Protection Business System may also be accessed from the “National Cyberspace Government Affairs Service Hall” section on the home page of the China Cyberspace website (https://www.cac.gov.cn).

April 2026 batch

The Cyberspace Administration of China continues to strengthen the dissemination of policies, laws and regulations on personal information protection, guiding and helping personal information handlers carry out personal information processing activities in a regulated manner and protecting personal information rights and interests. It hereby publishes a number of representative questions and answers as follows.

Q1. How are the personal information volumes referred to in the relevant provisions of the Regulation on Network Data Security Management, the Administrative Measures for Personal Information Protection Compliance Audits and other regulations and rules counted?

A: Article 28 of the Regulation on Network Data Security Management provides that a network data handler processing the personal information of 10 million or more persons shall also comply with the provisions of Articles 30 and 32 of the Regulation applicable to network data handlers processing important data. Article 4 of the Administrative Measures for Personal Information Protection Compliance Audits provides that a personal information handler processing the personal information of more than 10 million persons shall conduct a personal information protection compliance audit at least once every two years. The relevant provisions of the Measures for the Security Assessment of Data Export, the Measures on the Standard Contract for the Outbound Transfer of Personal Information, the Provisions on Promoting and Regulating Cross-border Data Flows, the Measures for the Certification of the Cross-border Provision of Personal Information and other rules also refer to personal information volumes.

The personal information volumes referred to in the relevant provisions of the above regulations and rules, such as “processing the personal information of more than 10 million persons”, are all inclusive of the stated number when counted; they are counted according to the number of natural persons involved in the personal information the personal information handler currently processes, and personal information that has already been deleted is not included in the count.

Q2. How often must a personal information handler conduct personal information protection compliance audits?

A: Article 54 of the Personal Information Protection Law of the People’s Republic of China provides that personal information handlers shall regularly conduct compliance audits of their compliance with laws and administrative regulations in processing personal information. Article 4 of the Administrative Measures for Personal Information Protection Compliance Audits provides that a personal information handler processing the personal information of more than 10 million persons shall conduct a personal information protection compliance audit at least once every two years. By reference to the national standard Data Security Technology — Requirements for Personal Information Protection Compliance Audits, a personal information handler processing the personal information of more than 1 million but not more than 10 million persons shall conduct a compliance audit at least once every three or four years, and a personal information handler processing the personal information of not more than 1 million persons shall conduct a compliance audit at least once every five years.

Personal information handlers shall establish a personal information protection compliance audit system and, in accordance with laws, administrative regulations and relevant State provisions, and with reference to the requirements of the relevant national standards, reasonably determine and specify in the corresponding system the frequency of regular personal information protection compliance audits, so as to raise the level of personal information protection compliance and promote the reasonable use of personal information.

Q3. What should a compliance audit of the protection of minors’ personal information cover?

A: Article 37 of the Regulations on the Protection of Minors in Cyberspace provides that personal information handlers shall, on their own or by entrusting a professional institution, conduct an annual compliance audit of their compliance with laws and administrative regulations in processing the personal information of minors, and shall promptly report the audit to the cyberspace administration and other departments. Article 17 of the Civil Code of the People’s Republic of China provides that a natural person under the age of eighteen is a minor.

A personal information handler that processes the personal information of minors shall, regardless of whether it identifies the minor status of the individuals concerned, conduct an annual compliance audit, on its own or by entrusting a professional institution, of its compliance with laws and administrative regulations in processing minors’ personal information, in accordance with the requirements of Article 37 of the Regulations on the Protection of Minors in Cyberspace.

In conducting a compliance audit of the protection of minors’ personal information, the personal information handler shall, in accordance with the requirements of the Personal Information Protection Law of the People’s Republic of China, the Regulations on the Protection of Minors in Cyberspace, the Regulation on Network Data Security Management, the Provisions on the Online Protection of Children’s Personal Information, the Administrative Measures for Personal Information Protection Compliance Audits and other laws, administrative regulations and departmental rules concerning personal information protection compliance audits and the protection of minors’ personal information, and with reference to national standards such as Data Security Technology — Requirements for Personal Information Protection Compliance Audits, comprehensively review and evaluate whether its processing activities involving minors’ personal information comply with laws, administrative regulations and the like.

August 2026 batch

The Cyberspace Administration of China continues to strengthen the dissemination of policies, laws and regulations on personal information protection, guiding and helping personal information handlers carry out personal information processing activities in a regulated manner and protecting personal information rights and interests. It hereby publishes a number of representative questions and answers as follows.

Q1. What are the requirements for processing personal information that has already been disclosed?

A: Article 27 of the Personal Information Protection Law provides: “A personal information handler may, within a reasonable scope, process personal information that the individual has disclosed on their own or that has otherwise already been lawfully disclosed, except where the individual has expressly refused. Where a personal information handler’s processing of disclosed personal information has a major impact on individual rights and interests, it shall obtain the individual’s consent in accordance with this Law.”

Article 12 of the Guidelines for Personal Information Protection Compliance Audits, annexed to the Administrative Measures for Personal Information Protection Compliance Audits, elaborates the circumstances of unlawful or non-compliant processing of disclosed personal information: (1) sending commercial information unrelated to the purpose of disclosure to email addresses, mobile phone numbers and the like contained in disclosed personal information; (2) using disclosed personal information to engage in activities such as cyber-violence or the spreading of online rumors and false information; (3) processing disclosed personal information the processing of which the individual has expressly refused; (4) failing to obtain the individual’s consent where the processing has a major impact on individual rights and interests; (5) collecting, retaining or processing disclosed personal information at a scale, for a duration or for a purpose of use that exceeds a reasonable scope.

Q2. What are the common causes of personal information leaks?

A: First, personal information is stored and transmitted in plaintext, without appropriate security technical measures such as encryption and de-identification; second, the information systems, databases and the like in which personal information is stored lack effective security measures, for example using weak passwords or having no login verification measures; third, data interfaces accessible via the internet lack effective identity verification measures; fourth, pages on internet websites contain the login accounts and passwords of information systems and databases associated with the website.

Article 51 of the Personal Information Protection Law provides: “Personal information handlers shall, according to the processing purpose, the processing method, the type of personal information, the impact on individual rights and interests, the security risks that may exist and other factors, take the following measures to ensure that personal information processing activities comply with laws and administrative regulations and to prevent unauthorized access and the leakage, tampering or loss of personal information: (1) formulating internal management systems and operating procedures; (2) implementing classified management of personal information; (3) taking corresponding security technical measures such as encryption and de-identification; (4) reasonably determining operational authority for personal information processing and regularly conducting security education and training for practitioners; (5) formulating and organizing the implementation of emergency response plans for personal information security incidents; (6) other measures provided by laws and administrative regulations.”

§ RELATED LAWS

See also.

§ COMMENTARY

Briefs on this law.

No briefs filed yet under this law.

§ SUBSCRIBE

The Monday brief.

One short email every Monday. New briefs on Chinese data-compliance rules from the previous week, with the source law cited.

Opt-in only. Unsubscribe anytime by replying "unsubscribe" to any issue.

SUPPORT DCC

Keep the publication free to read. Suggested support is $19.99, or choose your own amount.

Support →