---
title_en: "Provisions on Personal Information Protection for Large Personal Information Handlers (Draft for Comment)"
title_zh: "大型个人信息处理者个人信息保护规定（征求意见稿）"
abbreviation: "Large Handler Provisions (Draft)"
hierarchy: "draft"
issuing_body: "Cyberspace Administration of China (CAC)"
adopted_date: 2026-08-07
status: "draft"
source_url: "https://mp.weixin.qq.com/s/BeNitCJ468LFRu6D0rE-7Q"
related_laws: ["pipl", "network-data-security-regulations", "small-pi-handlers-simplified-measures", "personal-info-audit-measures", "minors-online-protection-regulations", "data-export-security-assessment-measures", "personal-info-standard-contract-measures", "cross-border-pi-certification-measures", "csl", "cii-protection-regulations"]
domains: ["personal-information", "cross-border", "data-security"]
url: https://datacompliancechina.com/laws/large-pi-handlers-protection-provisions-draft/
summary: "CAC's draft for comment, released 7 August 2026 with comments due 7 September 2026, is the counterweight to the small-handler regime: where Order No. 25 scales PIPL down for handlers under 100,000 people, these 50 articles scale it up for handlers at or above 10 million. It consolidates two earlier drafts — the Supervision Committee provisions of 12 September 2025 and the Large Network Platform provisions of 22 November 2025 — and in doing so renames the subject from 'large network platform' to 'large personal information handler,' replacing the old registered-user and monthly-active-user tests with a three-factor designation covering headcount of data subjects, systemic importance of the service, and impact on national security, economic operation, social stability and public health. Designation is not automatic: a qualifying handler must self-declare through its provincial CAC, and the national CAC publishes a public list. The obligations that follow are the heaviest in the PIPL system — full domestic storage of all personal information collected or generated in China (Article 13), data centers whose legal representative or actual controller must hold PRC nationality (Article 14), a personal information protection officer drawn from management with a direct reporting line to the provincial CAC (Articles 25–26), impact assessments filed with the national CAC (Article 31), compliance audits at least every two years (Article 33), an annual public social responsibility report (Article 30), and a Personal Information Protection Supervision Committee of at least seven members, two-thirds external, headed by an external member (Chapter 4). An annex supplies the committee's working-rules drafting guidelines."
---

> **Source: Data Compliance China** — https://datacompliancechina.com/laws/large-pi-handlers-protection-provisions-draft/ · English rendering and annotations by DCC; the Chinese original governs. Cite as: Data Compliance China, "Provisions on Personal Information Protection for Large Personal Information Handlers (Draft for Comment)", https://datacompliancechina.com/laws/large-pi-handlers-protection-provisions-draft/
**Issued by:** Cyberspace Administration of China, Network Data Management Bureau.
**Status:** Draft for public comment (征求意见稿) — not yet in force; Article 50 leaves the effective date blank.
**Published:** 7 August 2026. **Comments due:** 7 September 2026, to shujuju@cac.gov.cn.
**Legal basis:** PIPL (in particular Article 58) and the Regulations on the Administration of Network Data Security.
**Consolidates:** the *Provisions on the Establishment of Personal Information Protection Supervision Committees by Large Network Platforms (Draft for Comment)* (12 September 2025) and the *Provisions on Personal Information Protection for Large Network Platforms (Draft for Comment)* (22 November 2025).

---

> *DCC translation.* Translated from the official Chinese text published through
> 网信中国 (the CAC's official channel), against
> [DCC's bilingual glossary](/glossary) for terminology consistency. Note that
> 个人信息处理者 is rendered **personal information handler** per PIPL Article
> 73 — never "data controller" — and 大型个人信息处理者 as **large personal
> information handler**, which is deliberately broader than the
> 大型网络平台 ("large network platform") of the two predecessor drafts.
> This is a draft: article numbering and thresholds may change before adoption.

## Full text

### Chapter I — General Provisions

**Article 1.** These Provisions are formulated in accordance with the *Personal Information Protection Law of the People's Republic of China*, the *Regulations on the Administration of Network Data Security* and other laws and administrative regulations, in order to regulate the personal information processing activities of large personal information handlers, protect the lawful rights and interests in personal information, and promote the lawful and reasonable use of personal information.

**Article 2.** These Provisions apply to personal information protection by large personal information handlers and to the supervision and administration thereof.

The determination of a large personal information handler shall take the following conditions into comprehensive consideration:

(1) processing the personal information of more than 10 million natural persons;

(2) providing important network services involving the processing of personal information, or having a business scope covering multiple lines of business that involve the processing of personal information;

(3) the personal information processing activities have a significant impact on national security, economic operation, social stability, public health and safety, and the like.

**Article 3.** A personal information handler that processes the personal information of more than 10 million natural persons and that, on self-assessment, considers itself to meet the conditions in items (2) and (3) of the second paragraph of Article 2 of these Provisions shall declare for determination as a large personal information handler to the national cyberspace administration through the provincial cyberspace administration of its locality, and shall submit materials in accordance with the relevant requirements.

The provincial cyberspace administration shall complete a completeness check within 15 working days from the date of receipt of the declaration materials. Where the declaration materials are complete, it shall submit the declaration materials and a preliminary determination opinion to the national cyberspace administration; where the declaration materials are incomplete, it shall return them to the personal information handler and inform it on a one-time basis of the materials that need to be supplemented.

Where cyberspace administrations at or above the provincial level, telecommunications authorities, public security organs and other departments performing personal information protection duties consider on examination that a personal information handler meets the determination conditions but has not declared for determination on its own initiative, they shall urge it to declare for determination.

The national cyberspace administration, together with the telecommunications authority of the State Council, the public security department and other departments performing personal information protection duties, shall on the basis of the determination conditions study and settle the list of large personal information handlers, and shall announce it to society.

Where a determined large personal information handler considers that it has for six consecutive months ceased to meet the determination conditions, it may apply to the national cyberspace administration through the provincial cyberspace administration of its locality for a change of determination.

**Article 4.** The national cyberspace administration is responsible for the overall planning and coordination of personal information protection work and related supervision and administration work for large personal information handlers. The telecommunications authority of the State Council, the public security department and other departments performing personal information protection duties are responsible, within their respective scopes of duty and in accordance with these Provisions and relevant laws and administrative regulations, for personal information protection and supervision and administration in respect of large personal information handlers.

Local cyberspace administrations are responsible for the overall planning and coordination of personal information protection work and related supervision and administration work for large personal information handlers within their administrative areas. Local telecommunications authorities, public security organs and other relevant departments are responsible, according to their respective duties, for personal information protection and supervision and administration of large personal information handlers within their administrative areas.

Cyberspace administrations, telecommunications authorities, public security organs and other departments performing personal information protection duties shall strengthen the sharing of information and the coordination of work concerning large personal information handlers.

**Article 5.** A large personal information handler shall adopt measures such as encryption, de-identification, access control and anonymization to safeguard the security of the personal information it processes; it may apply the national public service for network identity authentication, and is encouraged to use data-label identification technologies and to obtain personal information protection certification, so as to raise the level of personal information protection.

**Article 6.** Large personal information handlers are encouraged to carry out innovation in personal information protection technologies, products and services, to participate actively in the formulation of international standards and rules on personal information protection, and to promote the coordination and mutual recognition of personal information protection rules and standards with other countries and regions.

**Article 7.** Where an overseas organization or individual engages in personal information processing activities that infringe the personal information rights and interests of citizens of the People's Republic of China, or that endanger the national security or public interest of the People's Republic of China, the national cyberspace administration may include it in a list of entities to which the provision of personal information is restricted or prohibited, announce the same, and adopt measures such as restricting or prohibiting the provision of personal information to it.

### Chapter II — Personal Information Processing Rules

**Article 8.** A large personal information handler processing personal information shall follow the principles of lawfulness, legitimacy, necessity and good faith, comply with laws and administrative regulations, and respect social morality and ethics.

**Article 9.** A large personal information handler collecting personal information shall adhere to the principle of minimum necessity, limit collection to what is necessary for providing the product or service, and shall not excessively collect personal information.

**Article 10.** Where a large personal information handler formulates and publishes personal information processing rules, it shall, in clear and readily understandable language, truthfully, accurately and completely set out the following matters item by item:

(1) the name of the large personal information handler, and the name and effective contact details of the person responsible for personal information protection;

(2) in the form of a structured list, the purpose, method and types of personal information collected and used by each functional service, the names and frequency of the permissions invoked, the necessity of collecting and using sensitive personal information, and the impact on the rights and interests of individuals;

(3) where software development kits are embedded, in the form of a structured list, the name (package name), version, main functions and operator's name of each embedded software development kit, the types of personal information collected and used, and the complete access path to the software development kit's personal information processing rules;

(4) where personal information is provided to other personal information handlers, the name and contact details of the recipient, the purpose and method of processing, and the types of personal information;

(5) the retention period of personal information and the method of disposal upon its expiry; where the retention period is difficult to determine, the method for determining the retention period shall be specified;

(6) the methods and channels by which an individual may consult, copy, transfer, correct, supplement, delete, restrict or refuse the processing of personal information, and may cancel an account or withdraw consent;

(7) other matters required to be disclosed by laws, administrative regulations or departmental rules.

Where the matters specified in the preceding paragraph change, the changed parts shall be notified to individuals.

**Article 11.** Where a large personal information handler processes personal information on the basis of an individual's consent, it shall adopt the method with the least impact on the individual's rights and interests; and in any of the following circumstances it shall obtain the individual's separate consent:

(1) providing the personal information it processes to other personal information handlers;

(2) providing personal information outside the territory of the People's Republic of China;

(3) making public the personal information it processes;

(4) processing sensitive personal information;

(5) other circumstances provided for by laws or administrative regulations.

Where a large personal information handler processes the personal information of a minor under the age of 14, it shall obtain the consent of the minor's parents or other guardian; the large personal information handler shall provide convenient channels for a guardian to give and to withdraw consent to the processing of the personal information of a minor under the age of 14.

**Article 12.** Where a large personal information handler processes personal information on the basis of an individual's consent, and the purpose of processing, the method of processing or the types of personal information processed change, it shall obtain the individual's consent anew.

Where a large personal information handler processes personal information on the basis of an individual's consent, it shall provide a convenient method for withdrawing consent, and shall set out in the form of a structured list the types of personal information the individual has consented to the large personal information handler processing, together with the purpose and method of processing, so as to facilitate the individual's choice.

**Article 13.** A large personal information handler shall store within the territory personal information collected and generated in the course of operations within the territory of the People's Republic of China.

**Article 14.** A large personal information handler shall select a data center meeting the following conditions to store personal information collected and generated in the course of operations within the territory of the People's Republic of China:

(1) it is established within the territory of the People's Republic of China;

(2) the legal representative or actual controller of the data center management organization holds the nationality of the People's Republic of China;

(3) it complies with relevant national policy and standard requirements.

**Article 15.** The data center management organization of a large personal information handler shall establish and improve internal management systems and operating procedures, and assist the large personal information handler in performing its personal information protection obligations; its specific duties include but are not limited to:

(1) formulating contingency plans for personal information security incidents;

(2) where it discovers that systems, network products or services present security defects, vulnerabilities or other risks affecting the large personal information handler's performance of its personal information protection obligations, immediately adopting remedial measures, notifying the large personal information handler, and reporting to the relevant departments performing personal information protection duties in accordance with regulations;

(3) where a personal information security incident occurs, immediately notifying the large personal information handler, promptly activating the contingency plan, adopting measures to prevent the harm from expanding and to eliminate security hazards, and reporting in accordance with regulations to the national cyberspace administration, the telecommunications authority of the State Council, the public security department and other departments performing personal information protection duties;

(4) promptly implementing the relevant requirements of the national cyberspace administration and of the telecommunications authority of the State Council, the public security department and other departments performing personal information protection duties.

**Article 16.** Where a large personal information handler entrusts a third-party data center management organization or the like with processing personal information, it shall enter into a written contract with it, stipulating the purpose, term, method, storage location, scale and types of the entrusted processing of personal information, the protection measures, and the rights and obligations of both parties, and requiring compliance with Articles 14 and 15 of these Provisions. The entrusted party shall assist the large personal information handler in the security management of personal information processing activities.

**Article 17.** Where a large personal information handler pushes information to individuals or conducts commercial marketing by means of automated decision-making, it shall adopt the following measures to protect the rights and interests of individuals:

(1) providing an option to switch off personalized recommendation that is easy to understand, access and operate;

(2) where a user elects to switch off personalized recommendation, the large personal information handler shall cease using the relevant personal information for personalized recommendation purposes;

(3) providing users with functions such as deletion of user tags directed at their personal characteristics;

(4) other measures provided for by laws, administrative regulations or the relevant departments of the State.

**Article 18.** Where a large personal information handler aggregates or fuses personal information, and the personal information so processed falls within Article 28 of the *Personal Information Protection Law of the People's Republic of China*, it shall be identified and protected as sensitive personal information.

**Article 19.** For a request to transfer personal information that meets the conditions of Article 25 of the *Regulations on the Administration of Network Data Security*, the large personal information handler shall, within 30 working days of completing verification of the individual's identity and of the request, transfer the personal information in a commonly used or machine-readable format, and inform the individual of the outcome by means such as email, telephone or text message; where it cannot provide a transfer channel, it shall explain the reasons to the individual. Where the processing period needs to be extended because of the number of requests, operational complexity or other reasons, it shall explain the reasons for the extension to the individual, and may extend the period by a further 30 working days where reasonable and necessary. Where laws, administrative regulations or departmental rules provide otherwise, those provisions shall apply.

A large personal information handler shall adopt security measures such as identity verification and encrypted transmission to safeguard the security of personal information transfers. Large personal information handlers are supported in providing transfer channels through application programming interfaces or other standardized technical means.

Where the number of requests to transfer personal information manifestly exceeds a reasonable range, the large personal information handler may charge necessary fees based on the cost of transferring the personal information, and the charging standard shall be open and transparent.

**Article 20.** Where a large personal information handler genuinely needs to provide personal information outside the territory of the People's Republic of China for business or other reasons, it shall, in accordance with relevant national provisions, declare a data export security assessment, enter into a standard contract for the export of personal information, or obtain personal information protection certification, and shall improve the technical and management measures relating to the security of personal information exports, and promptly guard against and dispose of security risks and threats of unlawful export of personal information.

A large personal information handler shall assess the management and technical measures of the overseas recipient; where it discovers that the overseas recipient is unable to perform the personal information protection obligations and responsibilities under laws, administrative regulations, departmental rules or the relevant contract, it shall suspend the provision of personal information to it.

Where laws, administrative regulations or relevant national provisions provide otherwise regarding exemption from declaring a data export security assessment, entering into a standard contract for the export of personal information, or obtaining personal information protection certification, those provisions shall apply.

**Article 21.** Where a large personal information handler provides personal information to other personal information handlers for business or other reasons, it shall give priority to measures such as de-identification and aggregate statistics, shall inform the individual of the name, contact details, purpose and method of processing, and types of personal information of the recipient, and shall, as required by Article 23 of the *Cybersecurity Law of the People's Republic of China*, adopt technical measures to monitor and record the outbound transmission of personal information, retaining the relevant logs for not less than six months.

The recipient shall process the personal information within the scope of the purpose of processing, method of processing and types of personal information referred to in the preceding paragraph. Where the recipient changes the original purpose or method of processing, it shall obtain the individual's consent anew.

**Article 22.** A large personal information handler shall not make public the personal information it processes, except where the individual's separate consent has been obtained; where personal information is made public, it shall be limited to the minimum scope for achieving the purpose of processing, technical measures such as de-identification shall be adopted to guard against the risk of infringing the rights and interests of individuals, and a personal information protection impact assessment shall be carried out before the personal information is made public.

A large personal information handler may, within a reasonable scope, process personal information that individuals have themselves made public or that has otherwise already been lawfully made public, except where the individual expressly refuses. Where a large personal information handler's processing of personal information already made public has a significant impact on the rights and interests of individuals, it shall obtain the individual's consent in accordance with laws and administrative regulations. A large personal information handler shall provide convenient channels for individuals to refuse the processing of their personal information that has been made public.

**Article 23.** The retention period for personal information processed by a large personal information handler shall be limited to the shortest period necessary for providing the product or service. In any of the following circumstances, the large personal information handler shall delete the personal information on its own initiative:

(1) the purpose of processing has been achieved, cannot be achieved, or is no longer necessary for achieving the purpose of processing;

(2) the large personal information handler ceases to provide the product or service, or the retention period has expired;

(3) the individual withdraws consent or refuses processing;

(4) the large personal information handler processes personal information in violation of laws or administrative regulations, or in breach of an agreement;

(5) other circumstances provided for by laws or administrative regulations.

Where an individual requests deletion of personal information, the large personal information handler shall delete it promptly; where there are genuine reasons why it cannot be deleted, it shall reply within 15 working days.

Where the retention period provided for by laws or administrative regulations has not expired, or deletion of the personal information is technically difficult to achieve, the large personal information handler shall cease processing other than storage and the adoption of necessary security protection measures.

### Chapter III — Obligations of Large Personal Information Handlers

**Article 24.** A large personal information handler shall, around the stages of personal information processing activities, response to the exercise of individual rights and performance of security obligations, establish and improve internal management systems and operating procedures, strengthen personal information security monitoring and early warning, promptly discover and dispose of personal information security problems and incidents, and guard against security risks. The management systems shall include at least the following:

(1) a personal information classification management system;

(2) systems for secure storage, authorized access, controllable transmission, external provision, conduct auditing and the like involved in personal information processing;

(3) systems for personal information security risk monitoring, emergency drills and emergency response;

(4) systems for personal information protection impact assessment and compliance auditing;

(5) a system for the protection of minors' personal information;

(6) a system for accepting and disposing of personal information complaints and reports;

(7) a system for publicity, education and training on personal information protection.

**Article 25.** A large personal information handler shall, in accordance with laws and administrative regulations, designate a member of management to serve as the person responsible for personal information protection, and shall publish the contact details of the person responsible for personal information protection.

The person responsible for personal information protection is encouraged to possess personal information protection compliance auditing capability.

**Article 26.** The person responsible for personal information protection shall perform the following duties:

(1) organizing the formulation of internal personal information protection management systems, operating procedures and contingency plans for personal information security incidents, and guiding the conduct of personal information security risk monitoring, risk assessment, compliance auditing, impact assessment, emergency drills, education and training and other activities;

(2) guiding relevant personnel of business departments in carrying out personal information processing activities in compliance, implementing the requirements of the departments performing personal information protection duties, and cooperating in supervision and inspection of personal information protection;

(3) participating in decision-making on the large personal information handler's personal information processing matters, and promptly raising opinions on decisions that present security risks. Where the large personal information handler fails without justified reason to act on a compliance opinion, or where the outcome of its handling violates laws, administrative regulations or relevant national provisions, the person responsible for personal information protection may report directly to the provincial cyberspace administration of its locality;

(4) supervising the large personal information handler's personal information processing activities and the protection measures adopted; where a security incident such as leakage, tampering or loss of personal information occurs or may occur, or where there exists any other major unlawful circumstance that may result in harm to personal information rights and interests on a large scale, immediately organizing the adoption of remedial measures and reporting to the provincial cyberspace administration of its locality and to the telecommunications authority, public security organ and other departments performing personal information protection duties; where a crime is suspected, reporting the case to the public security organ; and where it is discovered that national security may be endangered, reporting to the national security organ;

(5) organizing the formulation of dedicated personal information processing rules for minors under the age of 14, and the adoption of targeted personal information protection measures for minors who have reached the age of 14 but are under the age of 18;

(6) regularly reporting to the personal information protection supervision committee on the large personal information handler's personal information protection work.

A large personal information handler shall provide the necessary support for the person responsible for personal information protection to perform their duties.

**Article 27.** A large personal information handler shall designate personnel of its business departments who possess personal information protection compliance auditing capability to take charge of personal information protection work; the number of such personnel shall be commensurate with the business scale of the business department and the personal information protection obligations performed, and they shall, under the guidance of the person responsible for personal information protection, take charge of the security management of personal information processing activities in their department, specify the personal information processing norms of their department, and ensure the performance of personal information protection obligations.

**Article 28.** A large personal information handler shall configure operating permissions for personal information processing for its personnel on the principle of the minimum authorization needed to achieve business functions. Records of personal information processing operations, permission approval records and the like shall be retained for at least six months; those involving personal information protection impact assessment reports and records of handling shall be retained for at least three years.

**Article 29.** A large personal information handler providing network platform services shall specify the norms, permissions and personal information protection obligations of product or service providers on the platform in processing personal information, and shall urge them to establish and improve internal personal information protection management systems and operating procedures, carry out personal information processing activities in accordance with law, and perform personal information protection obligations.

Where a large personal information handler discovers that a product or service provider on the platform processes personal information in serious violation of laws or administrative regulations, it shall immediately adopt disposal measures such as ceasing to provide services, and report to cyberspace administrations at or above the provincial level and other departments performing personal information protection duties.

**Article 30.** A large personal information handler shall each year compile, and publish in the first half of the year, a personal information protection social responsibility report for the preceding year. The personal information protection social responsibility report shall include but not be limited to the following:

(1) the personal information protection organizational structure and internal management situation;

(2) the situation regarding personal information protection capability building;

(3) personal information protection measures and their effectiveness;

(4) the situation regarding protection of minors' personal information;

(5) the situation regarding acceptance of applications by individuals exercising their rights;

(6) the situation regarding performance of duties by the personal information protection supervision committee, and the allowance standards for external members;

(7) the situation regarding handling of major personal information security incidents;

(8) the situation regarding publicity, education and public-interest activities on personal information protection;

(9) other matters provided for by laws and administrative regulations.

**Article 31.** Where a large personal information handler launches a product, service or function that involves automated decision-making, the processing of sensitive personal information or the like and that may have a significant impact on the rights and interests of individuals, it shall carry out a personal information protection impact assessment in advance, and shall within 15 working days of completing the assessment file the impact assessment report with the national cyberspace administration through the provincial cyberspace administration of its locality.

The personal information protection impact assessment shall include the following:

(1) whether the purpose and method of processing personal information are lawful, legitimate and necessary, and whether the frequency of invoking relevant permissions, the precision of the data and the like are limited to the lowest frequency and minimum scope for achieving the business function;

(2) the impact of the personal information processing activities on the rights and interests of individuals, and the security risks;

(3) the measures by which the automated decision-making mechanism avoids precisely locating a specific individual, and their effectiveness;

(4) whether the protection measures adopted are lawful, effective and commensurate with the degree of risk;

(5) other matters provided for by laws, administrative regulations or departmental rules.

**Article 32.** A large personal information handler shall strictly protect the personal information of minors, identify minors by means such as the national public service for network identity authentication, and carry out an annual compliance audit of the protection of minors' personal information in accordance with the *Regulations on the Protection of Minors Online*.

A large personal information handler shall designate dedicated personnel to take charge of the protection of minors' personal information. Such personnel shall have received specialized training and shall be familiar with the characteristics of minors and the needs of protecting their healthy growth.

**Article 33.** A large personal information handler shall carry out a personal information protection compliance audit at least once every two years, and shall carry out a risk assessment of its personal information processing activities each year, and shall rectify the problems discovered. Large personal information handlers are encouraged to publicly display the results of compliance audits, risk assessments and the like in a prominent position.

**Article 34.** Where a large personal information handler entrusts a third-party professional institution to carry out a personal information protection compliance audit, risk assessment or the like, it shall cooperate with the third-party professional institution in performing its duties and provide the necessary safeguards for the third-party professional institution's work, including providing personnel designated by the third-party professional institution with the necessary permissions to access the large personal information handler's network data facilities, systems and operating logs.

A third-party professional institution entrusted by a large personal information handler to carry out a personal information protection compliance audit, risk assessment or the like shall be registered within the territory of the People's Republic of China. Where it discovers that the large personal information handler's personal information processing activities present relatively large security risks, it shall promptly notify the large personal information handler and put forward rectification recommendations.

**Article 35.** A large personal information handler shall establish convenient channels for personal information complaints and reports, provide effective and readily accessible complaint and report channels in its personal information processing rules, improve the mechanisms for accepting, disposing of and giving feedback on complaints and reports, and accept and dispose of personal-information-related complaints and reports within its undertaken time limit (the undertaken time limit shall not exceed 15 working days; where no time limit is undertaken, 15 working days shall be the limit).

**Article 36.** A large personal information handler shall, within 30 working days from the date of determination, report the following information to the cyberspace administration of the districted city of its locality:

(1) basic information on the person responsible for personal information protection;

(2) measures safeguarding the performance of duties by the person responsible for personal information protection;

(3) basic information on the data center storing personal information, including the data center management organization, internal management systems, security measures and other information; where a third-party data center management organization is entrusted with processing personal information, the contract text signed by both parties shall also be submitted.

Where basic information on the person responsible for personal information protection, the data center or the like changes, the large personal information handler shall report the changed information within 30 working days from the date of the change.

Where the large personal information handler and the third-party data center management organization stipulate the reporting entity by contract, the reporting entity stipulated in the contract may report the basic information on the data center.

### Chapter IV — Personal Information Protection Supervision Committee

**Article 37.** A large personal information handler shall, within six months from the date of determination, establish a personal information protection supervision committee composed mainly of external members (hereinafter the "supervision committee") to supervise the personal information protection situation, shall formulate the supervision committee's working rules in accordance with the requirements of the annex to these Provisions, and shall report to the national cyberspace administration, through the provincial cyberspace administration of its locality, basic information such as the establishment of the supervision committee, its working rules and the list of its members.

The members of the supervision committee shall be an odd number, shall be commensurate with the large personal information handler's business scale, user numbers and the like, and shall be not fewer than seven; external members shall account for not less than two-thirds. The supervision committee shall have a head and a secretary; the head shall be an external member and shall possess the capability of a senior personal information protection compliance auditor.

A large personal information handler shall provide the necessary support for the supervision committee to perform its duties.

**Article 38.** An external member shall meet the following conditions:

(1) meeting the independence requirements provided for in Article 39 of these Provisions;

(2) being concurrently engaged by not more than three large personal information handlers;

(3) possessing personal information protection compliance auditing capability, being familiar with personal-information-protection-related laws, regulations and national standards, and having engaged in personal-information-protection-related work for not less than three years;

(4) having a good reputation and being able to perform duties objectively, impartially, independently and with integrity;

(5) possessing the physical condition, working time and the like required to perform the duties;

(6) having good personal moral character, with no adverse record of unlawful or criminal conduct, serious dishonesty or the like;

(7) other conditions provided for by laws, administrative regulations or departmental rules.

Where a large personal information handler engages an external member, it shall conduct a security background check on the external member. In conducting the check, it may apply to the public security organ for assistance.

**Article 39.** An external member shall maintain independence of status and in the performance of duties. A person falling within any of the following circumstances within the most recent year shall not serve as an external member:

(1) a person holding a position with the engaging large personal information handler, and their close relatives;

(2) a person who directly or indirectly holds more than one percent of the issued shares of the engaging large personal information handler, or who is a natural-person shareholder among the top ten shareholders of the engaging large personal information handler, and their close relatives;

(3) a person holding a position with a shareholder entity that directly or indirectly holds more than five percent of the issued shares of the engaging large personal information handler, or with an entity among the top five shareholders of the engaging large personal information handler, and their close relatives;

(4) other persons lacking independence as provided for by laws, administrative regulations, departmental rules or the supervision committee's working rules.

An external member shall conduct an annual self-examination of their independence and submit the results to the board of directors or other decision-making body of the engaging large personal information handler, or to a body authorized by it. The board of directors or other decision-making body of the large personal information handler, or a body authorized by it, shall annually assess the independence of serving external members and issue a special opinion, which shall be disclosed in the personal information protection social responsibility report.

**Article 40.** A large personal information handler shall specify the allowances of external members through the supervision committee's working rules; the allowance standards shall be approved by the board of directors or other decision-making body of the large personal information handler, or by a body authorized by it.

Social organizations are supported in building and publishing a recommendation information database of external members for supervision committees, to provide a reference for large personal information handlers in selecting and engaging external members.

**Article 41.** The supervision committee shall focus its supervision on the following matters of the large personal information handler:

(1) the building of the personal information protection compliance system;

(2) the formulation and major revision of platform rules, personal information processing rules and the like;

(3) the protection of sensitive personal information, minors' personal information and the like;

(4) the organization and implementation of personal information protection impact assessments, compliance audits and risk assessments, the preparation of reports, and the rectification of problems;

(5) the prevention and disposal of personal information security incidents;

(6) compliance in the export of personal information;

(7) the use of personal information for automated decision-making;

(8) the acceptance of applications by individuals exercising personal information rights, and the disposal of complaints and reports by individuals;

(9) the performance of duties by the person responsible for personal information protection and other personal-information-protection-related personnel;

(10) the publication of the personal information protection social responsibility report;

(11) other supervision matters provided for by laws, administrative regulations or departmental rules.

**Article 42.** The national cyberspace administration and other departments performing personal information protection duties shall supervise and administer, in accordance with law, the activities of large personal information handlers in establishing and operating supervision committees, and may require large personal information handlers to give explanations or provide relevant materials on matters relating to the establishment and operation of supervision committees, with which large personal information handlers shall cooperate.

Where a determined large personal information handler applies to the national cyberspace administration for a change of determination and the application is approved, it may dissolve the supervision committee.

### Chapter V — Supervision, Administration and Legal Liability

**Article 43.** A large personal information handler shall, in the first quarter of each year, report to the national cyberspace administration through the provincial cyberspace administration of its locality on the supervision committee's performance of duties in the preceding year; and shall at least every two years report a personal information protection compliance audit report to the national cyberspace administration through the provincial cyberspace administration of its locality. The national cyberspace administration shall notify the telecommunications authority of the State Council and the public security department of the relevant situation.

**Article 44.** Where cyberspace administrations, telecommunications authorities, public security organs and other departments performing personal information protection duties discover that a large personal information handler's personal information processing activities violate relevant laws or administrative regulations, or that the reported situation regarding the supervision committee's performance of duties, the personal information protection compliance audit or the personal information protection impact assessment presents circumstances violating laws, administrative regulations, departmental rules or these Provisions, they may in accordance with law carry out on-site inspection, regulatory interview, requirements for rectification, urging dissolution of the supervision committee and other disposal measures.

Where a large personal information handler fails to rectify as required or fails to meet the rectification requirements, the national cyberspace administration and the telecommunications authority of the State Council, the public security department, the national security department and other departments may require the large personal information handler to adopt measures such as hosting personal information with a third-party data center to safeguard the security of personal information.

**Article 45.** Any organization or individual has the right to complain of or report to the departments performing personal information protection duties any activity of a large personal information handler, a supervision committee or its members that violates these Provisions. The department receiving the complaint or report shall handle it promptly in accordance with law and inform the complainant or reporter of the outcome.

**Article 46.** Staff of cyberspace administrations, telecommunications authorities, public security organs and other departments performing personal information protection duties, and of supervision committees, third-party professional institutions and third-party data center management organizations, shall keep confidential in accordance with law personal privacy, personal information, trade secrets, confidential business information and the like of which they become aware in their work, and shall not divulge the same or unlawfully provide it to others.

**Article 47.** Where a large personal information handler, a person responsible for personal information protection, a third-party professional institution or a data center management organization processes personal information unlawfully, or processes personal information without performing personal information protection obligations, the cyberspace administration, telecommunications authority, public security organ or other department performing personal information protection duties shall handle the matter in accordance with the *Personal Information Protection Law of the People's Republic of China*, the *Public Security Administration Punishments Law of the People's Republic of China*, the *Regulations on the Administration of Network Data Security* and other laws and administrative regulations; where a crime is constituted, criminal liability shall be pursued in accordance with law.

Where a member of a supervision committee causes damage to a large personal information handler in violation of these Provisions, they shall bear corresponding civil liability in accordance with the engagement contract entered into with the large personal information handler; where this results in a personal information security incident, unlawful processing of personal information or the like, the matter shall be handled in accordance with the *Personal Information Protection Law of the People's Republic of China* and other laws and administrative regulations; where a crime is constituted, criminal liability shall be pursued in accordance with law.

### Chapter VI — Supplementary Provisions

**Article 48.** Personal information processing activities involving state secrets or work secrets shall be governed by the *Law of the People's Republic of China on Guarding State Secrets* and other laws and administrative regulations.

A large personal information handler shall implement the relevant requirements on classified and hierarchical protection of data, cybersecurity multi-level protection, and commercial cryptography protection. A large personal information handler that is critical information infrastructure shall additionally comply with the relevant provisions of the State on the security of critical information infrastructure.

**Article 49.** For the purposes of these Provisions, the following terms have the meanings set out below:

(1) "data center management organization" means the organization responsible for full-lifecycle security management of a large personal information handler's personal information processing activities; it may be an internal body of the large personal information handler or an external third-party institution.

(2) "business department" means the relevant department within a large personal information handler responsible for the research and development, operation and the like of products and services.

**Article 50.** These Provisions shall come into force on [   ].

---

## Annex — Guidelines for Formulating the Working Rules of the Personal Information Protection Supervision Committee

These Guidelines are formulated in accordance with the *Personal Information Protection Law of the People's Republic of China*, the *Provisions on Personal Information Protection for Large Personal Information Handlers* and other laws, administrative regulations and departmental rules, in order to regulate the operation and management of personal information protection supervision committees, safeguard their efficient performance of duties, and raise the personal information protection compliance level of large personal information handlers.

The working rules of the personal information protection supervision committee (the "working rules") apply to the establishment and operation of supervision committees by large personal information handlers and to the regulated management of supervision committees and their members.

The working rules shall at a minimum meet the following requirements:

**1.** The supervision committee supervises the personal information protection situation of the large personal information handler, follows the principles of independence and impartiality and of professionalism and prudence, complies with laws, administrative regulations, the provisions of the national cyberspace administration and other departments performing personal information protection duties, and the working rules, and performs its duties diligently.

**2.** The supervision committee is an independent body of the large personal information handler, composed mainly of external members, and exercises its powers in accordance with laws, administrative regulations and the working rules.

**3.** The head of the supervision committee shall be an external member, elected by all members of the supervision committee, and shall preside over the work of the supervision committee.

The secretary of the supervision committee may be an internal member, or another person designated by the board of directors or other decision-making body of the large personal information handler or a body authorized by it, and shall handle the day-to-day affairs of the supervision committee.

**4.** External members shall be nominated and engaged by the board of directors or other decision-making body of the large personal information handler, or by a body authorized by it.

When nominating and engaging external members, the board of directors or other decision-making body of the large personal information handler, or a body authorized by it, shall fully understand the circumstances of the nominee and ensure compliance with Articles 38 and 39 of the *Provisions on Personal Information Protection for Large Personal Information Handlers*. The nominee shall make a written declaration that they meet the independence requirements and the other conditions for serving as an external member.

**5.** The term of office of an external member is three years; upon expiry of the term they may be reappointed, but not for more than two consecutive terms.

An external member may voluntarily submit a written resignation application to the board of directors or other decision-making body of the large personal information handler, or to a body authorized by it, before the expiry of their term. Where an external member no longer meets the requirements of the working rules, they shall immediately cease performing their duties and resign.

**6.** Where an external member falls within any of the following circumstances, the board of directors or other decision-making body of the large personal information handler, or a body authorized by it, shall dismiss them in accordance with the procedures:

(1) they no longer meet Articles 38 and 39 of the *Provisions on Personal Information Protection for Large Personal Information Handlers* and have not resigned;

(2) they have failed to attend supervision committee meetings (including regular and interim meetings) twice consecutively;

(3) they have violated confidentiality requirements;

(4) other circumstances provided for in the working rules.

Where a large personal information handler dismisses an external member in accordance with the provisions, it shall inform them of the reasons and basis, and shall disclose the same in the personal information protection social responsibility report. Where a dismissed external member considers the reasons for dismissal improper, they may raise an objection, and the large personal information handler shall reply promptly.

**7.** Internal members shall be appointed by the board of directors or other decision-making body of the large personal information handler, or by a body authorized by it. The term of office of an internal member is three years; upon expiry of the term, the board of directors or other decision-making body of the large personal information handler, or a body authorized by it, shall decide whether to reappoint them, and reappointment shall not exceed two consecutive terms.

**8.** Where the resignation or dismissal of an external member or the like results in the number of supervision committee members failing to meet the requirements of the working rules, or in external members accounting for less than two-thirds, the large personal information handler shall appoint a replacement external member within 30 working days. Pending completion of the replacement, the supervision committee shall continue to perform its corresponding duties.

Where an internal member is no longer suitable to continue serving as an internal member owing to departure, transfer or the like, the large personal information handler shall appoint a replacement internal member within 30 working days.

**9.** The supervision committee shall supervise the large personal information handler and perform its supervision duties in accordance with the requirements of Article 41 of the *Provisions on Personal Information Protection for Large Personal Information Handlers*.

**10.** Members of the supervision committee may perform their supervision duties by the following means:

(1) proposing matters to be deliberated at supervision committee meetings;

(2) making enquiries of the board of directors or other decision-making body of the large personal information handler, or a body authorized by it, and of other relevant bodies and personnel, regarding personal information protection matters, and requiring a reply;

(3) attending supervision committee meetings, expressing opinions on matters deliberated, and voting;

(4) attending as a non-voting participant meetings relating to the large personal information handler's personal information protection work to which they are invited;

(5) collecting and giving feedback on the opinions and suggestions of the large personal information handler's users regarding personal information protection work;

(6) putting forward professional recommendations for raising the large personal information handler's personal information protection compliance level;

(7) other means of performing duties provided for by laws, administrative regulations or departmental rules.

Where a member of the supervision committee performs duties by the means in items (1) and (2) of the preceding paragraph, the agreement of more than half of all members shall be obtained. Where none of the means of performing duties listed in the preceding paragraph can be used normally, the large personal information handler shall inform them of the specific circumstances and reasons.

**11.** The supervision committee shall hold a regular meeting at least once every six months, to hear the work report of the large personal information handler's person responsible for personal information protection and to deliberate relevant matters raised by the large personal information handler or the supervision committee.

Where there is evidence proving that the large personal information handler's personal information processing activities present unlawful circumstances, an interim meeting may be convened upon the proposal of more than one-third of the supervision committee's members.

**12.** A supervision committee meeting may be convened only where more than half of the members attend. Where a member genuinely cannot attend for a reason, they shall review the meeting materials in advance, put forward clear opinions, and entrust another supervision committee member in writing to vote on their behalf.

**13.** Members of the supervision committee shall fully discuss the matters deliberated at the meeting, express independent opinions, and form meeting resolutions. A meeting resolution shall obtain the agreement of more than two-thirds of all members; where a member raises a dissenting opinion, it shall be recorded in the resolution. Minutes shall be made of supervision committee meetings and shall be signed and confirmed by the members attending the meeting.

**14.** The supervision committee shall promptly submit meeting resolutions to the board of directors or other decision-making body of the large personal information handler, or to a body authorized by it. The board of directors or other decision-making body of the large personal information handler, or a body authorized by it, shall promptly handle the meeting resolutions and communicate progress to the supervision committee on a regular basis. The person responsible for personal information protection shall report to the next supervision committee meeting on the handling of the resolutions of the previous meeting.

Where the board of directors or other decision-making body of the large personal information handler, or a body authorized by it, fails without justified reason to act on a compliance opinion in a meeting resolution, or where the outcome of its handling violates laws, administrative regulations or relevant national provisions, the supervision committee may report to the provincial cyberspace administration of its locality.

**15.** The large personal information handler shall, in light of the work content, working hours, workload and the like, give external members allowances commensurate with the duties they undertake, but shall not violate relevant national provisions. Apart from the above allowances, external members shall not obtain any other benefit from the large personal information handler, its major shareholders, actual controller, or entities and persons having an interest therein.

External members shall declare, through the personal information protection social responsibility report published by the large personal information handler, that they have not obtained any other benefit as provided for in the preceding paragraph.

"Major shareholder" means a shareholder holding five percent or more of the shares of the large personal information handler, or holding less than five percent of the shares but having a significant influence on the large personal information handler.

**16.** In performing its duties, the supervision committee shall not interfere with the normal operation of the large personal information handler, shall not require access to information beyond the scope of its duties, and shall keep confidential, in accordance with the requirements of laws, administrative regulations and departmental rules, personal information, trade secrets, confidential business information and the like of which it becomes aware in performing its duties, and shall not divulge the same or unlawfully provide it to others.

**17.** The relevant bodies and personnel of the large personal information handler shall cooperate with supervision lawfully carried out by the supervision committee, shall not maliciously refuse, obstruct or conceal, and shall not interfere with its independent performance of duties.

Where the supervision committee encounters obstruction in lawfully performing its duties, it may explain the situation to the board of directors or other decision-making body of the large personal information handler, or to a body authorized by it, and require the relevant bodies and personnel to cooperate. Where the obstruction still cannot be eliminated, the supervision committee may report to the provincial cyberspace administration of its locality.

Members of the supervision committee shall, in the first quarter of each year, submit a report on their performance of duties in the preceding year to the board of directors or other decision-making body of the large personal information handler, or to a body authorized by it.

**18.** A large personal information handler may, in light of work needs, formulate more detailed requirements on the number of supervision committee members, the number of meetings, the means of performing supervision duties, internal members and their tenure, the independence requirements for and dismissal of external members, and other related matters.
