Skip to content
DCC · DATA COMPLIANCE CHINA China data law, for overseas counsel.
§ LAW · SMALL HANDLER SIMPLIFIED MEASURES

Provisions on Simplified Personal Information Protection Measures for Small Personal Information Handlers.

小型个人信息处理者个人信息保护简化措施规定

Promulgated by: Cyberspace Administration of China and the Ministry of Public Security, jointly. Document No.: Order No. 25 (第25号). Adopted: 26 June 2026, at the CAC’s 14th office meeting of 2026, with the concurrence of the Ministry of Public Security. Published: 22 July 2026. Effective: 1 September 2026. Signed: Zhuang Rongwen, Director of the Cyberspace Administration of China; Wang Xiaohong, Minister of Public Security.


DCC translation. Translated from the official Chinese text published through 网信中国 (the CAC’s official channel), against DCC’s bilingual glossary for terminology consistency. Note in particular that 个人信息处理者 is rendered personal information handler, per PIPL Article 73 — never “data controller.”

Full text

Article 1 (Purpose). These Provisions are formulated in accordance with the Personal Information Protection Law of the People’s Republic of China, the Regulations on the Administration of Network Data Security and other laws and administrative regulations, in order to support the innovative development of micro, small and medium-sized enterprises and to simplify the measures by which small personal information handlers discharge their personal information protection obligations.

Article 2 (Scope and definition). These Provisions apply to the implementation of personal information protection by small personal information handlers within the territory of the People’s Republic of China.

For the purposes of these Provisions, a small personal information handler means a personal information handler that processes the personal information of fewer than 100,000 people.

Article 3 (General principle). Small personal information handlers are supported in adopting, on the basis of compliance with personal-information-protection laws, administrative regulations and relevant national provisions, simplified measures commensurate with their scale and capability in accordance with these Provisions, so as to safeguard personal information security and protect personal information rights and interests.

Article 4 (Content and publication of processing rules). A small personal information handler’s personal information processing rules shall include, at minimum, the following:

(I) the name of the small personal information handler;

(II) the department or personnel that receives individuals’ requests to exercise their rights, and their contact details;

(III) the purpose and method of processing the personal information, and the categories of personal information processed, the retention period, and similar matters.

Where a small personal information handler collects personal information offline, it may publish its personal information processing rules by simple means such as posting a notice in a conspicuous position at its place of business; where it collects personal information online, it may publish its rules by means such as a service agreement, a pop-up on the product or service client, or a website announcement.

A small personal information handler that processes the personal information of minors under the age of fourteen shall formulate dedicated personal information processing rules.

Article 5 (Unified rules by service-management units). Support is given to service-management units such as parks, industrial bases and commercial properties in uniformly formulating, and publishing in a conspicuous position, personal information processing rules for small personal information handlers conducting the same offline business within their service-management scope. A small personal information handler that agrees to comply with the unified personal information processing rules and is listed in those rules need not formulate its own personal information processing rules.

Article 6 (Discharging the notice obligation). A small personal information handler that meets all of the following conditions may discharge its notice obligation to individuals solely by publishing its personal information processing rules; the rules shall be presented conspicuously to users by means such as bold typeface, enlarged font size or distinguishing colors, and shall be convenient to consult and retain:

(I) the processing of personal information (excluding sensitive personal information) is necessary for providing the product or service;

(II) the personal information is not provided to other personal information handlers and is not publicly disclosed, and this is expressly stated in the personal information processing rules.

Where laws, administrative regulations or departmental rules provide otherwise with respect to a small personal information handler’s processing of sensitive personal information, those provisions apply.

Article 7 (Consent). After a small personal information handler has published its personal information processing rules and discharged its notice obligation, where an individual, on the premise of being fully informed, voluntarily and actively provides to — or voluntarily and actively cooperates in providing to — the small personal information handler the personal information necessary to obtain a product or service, the small personal information handler may process that personal information in accordance with the published personal information processing rules. Where sensitive personal information is processed for a specific purpose, the small personal information handler shall inform the individual, in the personal information processing rules, of the necessity of processing the sensitive personal information and its impact on the individual’s rights and interests, and shall obtain the individual’s separate consent.

Where laws, administrative regulations or departmental rules provide otherwise with respect to a small personal information handler’s processing of sensitive personal information, those provisions apply.

Article 8 (Handlers operating through a network platform). A small personal information handler that meets all of the following conditions need not formulate personal information processing rules or discharge the notice obligation:

(I) the small personal information handler conducts personal information processing activities solely through a network platform, and does not provide personal information to other personal information handlers outside that platform;

(II) the network platform has formulated and published corresponding personal information processing rules addressing the small personal information handler’s personal information processing activities, and has agreed with the small personal information handler on their respective rights and obligations;

(III) the small personal information handler declares that it complies with the personal information processing rules formulated by the network platform in accordance with these Provisions, and its processing of personal information is necessary for providing the product or service and does not exceed the scope of the processing purposes, processing methods and categories of personal information set out in those rules.

Where the preceding paragraph’s conditions are met and the network platform has conducted a personal information protection compliance audit and a personal information protection impact assessment covering the small personal information handler’s personal information processing activities carried out through that platform, the small personal information handler need not repeat them.

Where the purpose, method or categories of a small personal information handler’s processing of personal information exceed the scope of the network platform’s personal information processing rules, it shall separately formulate personal information processing rules in accordance with these Provisions and discharge the notice, compliance-audit and impact-assessment obligations. Where a network platform adjusts its personal information processing rules, it shall promptly notify the relevant small personal information handlers.

Article 9 (Transfer of personal information). Where a small personal information handler needs to transfer personal information by reason of merger, division, dissolution, declaration of bankruptcy or similar cause, it may inform individuals of the name and contact details of the recipient by simple means such as posting a notice in a conspicuous position at its place of business or sending an SMS reminder; where it independently provides online products or services, it shall also inform individuals of the recipient’s name and contact details by means such as a pop-up announcement on its product or service client; where it provides products or services through a network platform, it may give notice by means such as an announcement on its operator page within the platform or a mini-program announcement.

A small personal information handler shall publish the matters set out in the preceding paragraph at least 30 working days in advance, and the publication shall remain available for no less than 30 working days.

Article 10 (Cross-border provision of personal information). Where a small personal information handler provides personal information outside the territory and meets any one of the following conditions, it is exempt from declaring a Data Export Security Assessment, executing a Standard Contract for the cross-border transfer of personal information, or obtaining Personal Information Protection Certification:

(I) it is genuinely necessary to provide personal information abroad in order to conclude or perform a contract to which the individual is a party — such as cross-border shopping, cross-border delivery, cross-border remittance, cross-border payment, cross-border account opening, air-ticket and hotel booking, visa processing, or examination services;

(II) it is genuinely necessary to provide employees’ personal information abroad in order to carry out cross-border human-resources management in accordance with labor rules and regulations formulated in accordance with law and a collective contract concluded in accordance with law;

(III) it is genuinely necessary to provide personal information abroad, in an emergency, in order to protect the life, health and property safety of natural persons;

(IV) it is genuinely necessary to provide personal information abroad in order to perform statutory duties or statutory obligations;

(V) the personal information handler, other than a critical information infrastructure operator, has cumulatively provided abroad, since 1 January of the current year, the personal information of fewer than 100,000 people (excluding sensitive personal information);

(VI) other conditions provided by laws, administrative regulations or the national cyberspace administration department.

The personal information provided abroad referred to in the preceding paragraph does not include important data.

Where a small personal information handler provides personal information abroad, it shall discharge the obligations of notice, obtaining the individual’s separate consent and similar obligations in accordance with laws and administrative regulations.

Where a small personal information handler genuinely needs to provide personal information outside the territory of the People’s Republic of China and applies in accordance with law to the cyberspace administration department for a Data Export Security Assessment, the provincial-level cyberspace administration department of its locality may form a proposed assessment conclusion and submit it to the national cyberspace administration department for approval.

Departments performing personal information protection duties, data cross-border service centers and similar bodies are encouraged to provide consultation and other services for small personal information handlers’ cross-border provision of personal information.

Article 11 (Individuals’ rights requests). A small personal information handler may establish a mechanism for receiving and handling applications by individuals to exercise their rights in personal information processing activities, by publishing the department or personnel that receives such requests together with their contact details.

Article 12 (Deletion on ceasing operations). A small personal information handler that ceases operating a product or service shall take necessary measures to delete personal information; where it genuinely lacks the capability to delete the personal information, it may report to and request assistance from the relevant competent department of its locality; where the competent department is unclear, it may report to the municipal-level cyberspace administration department of the districted city of its locality.

Article 13 (Compliance audit). A small personal information handler may, following the simplified approach of the annexed Personal Information Protection Compliance Audit Self-Check Table for Small Personal Information Handlers, conduct a personal information protection compliance audit at least once every five years, and shall retain the compliance-audit self-check table for at least five years.

Where laws or administrative regulations provide otherwise with respect to compliance audits for the processing of minors’ personal information, those provisions apply.

Article 14 (Impact assessment). A small personal information handler may, following the simplified approach of the annexed Personal Information Protection Impact Assessment Form for Small Personal Information Handlers, conduct a personal information protection impact assessment, and shall retain the impact assessment form for at least three years.

Article 15 (Internal management systems). A small personal information handler may establish its personal information protection management system and its emergency response plan for personal information security incidents by simple means such as specifying internal personal-information-protection management requirements and emergency-response requirements for personal information security incidents within its organizational management documents.

Article 16 (Security incidents). Where personal information has been or may have been leaked, tampered with or lost, the small personal information handler shall immediately take remedial measures and notify individuals in accordance with laws and administrative regulations; where, owing to objective limitations, it is genuinely unable to notify individuals by other means, it may notify individuals solely by simple means such as posting a notice in a conspicuous position at its place of business or issuing a pop-up announcement on its product or service client and a website announcement, and shall notify the departments performing personal information protection duties as required; where a crime is suspected, it shall promptly report the matter to the public security organs.

Article 17 (Certification). Personal information protection certification bodies are supported in carrying out certification work targeted at small personal information handlers and in improving service quality.

A small personal information handler that has obtained Personal Information Protection Certification may be exempted from conducting a personal information protection compliance audit during the validity period of the certification.

Article 18 (No penalty). Where a small personal information handler’s personal information processing activities involve any of the following circumstances, no penalty shall be imposed:

(I) the unlawful conduct is minor, has been corrected in a timely manner, and has caused no harmful consequences;

(II) there is sufficient evidence to prove the absence of subjective fault; where laws or administrative regulations provide otherwise, those provisions apply;

(III) other circumstances in which no penalty is to be imposed in accordance with law.

Where a small personal information handler’s personal information processing activities involve a first-time violation with minor harmful consequences that is corrected in a timely manner, no penalty may be imposed.

Where no penalty is imposed in accordance with law, the department performing personal information protection duties shall, as appropriate, adopt regulatory measures such as a regulatory interview or the issuance of a reminder letter.

Article 19 (Lighter or mitigated penalty). Where a small personal information handler’s personal information processing activities involve any of the following circumstances, a lighter or mitigated penalty shall be imposed:

(I) it has taken the initiative to eliminate or mitigate the harmful consequences of the unlawful conduct;

(II) it has voluntarily confessed unlawful conduct not yet known to the department performing personal information protection duties;

(III) upon the occurrence of a personal information security incident, it promptly notified individuals and took remedial measures, and voluntarily notified the relevant departments;

(IV) it performed meritoriously in cooperating with the department performing personal information protection duties in investigating and handling unlawful conduct;

(V) other circumstances warranting a lighter or mitigated penalty in accordance with law.

Article 20 (Support measures). Enterprises, relevant social organizations, professional bodies and others are supported in helping small personal information handlers raise their personal information protection capability through means such as organizing training, lectures, legal-education activities and consultation and guidance.

Departments performing personal information protection duties are encouraged to provide small personal information handlers with infrastructure, technical tools, consultation services and similar support for secure and convenient personal information processing, so as to reduce their compliance costs.

Article 21 (Supervision and inspection). Cyberspace administration departments, public security organs and other departments performing personal information protection duties may supervise and inspect small personal information handlers’ performance of personal information protection obligations by means such as spot-check assessments and audit reports, and small personal information handlers shall cooperate.

Where cyberspace administration departments, public security organs and other departments performing personal information protection duties discover that a small personal information handler has unlawfully processed personal information or has repeatedly experienced personal information security incidents, they shall handle the matter in accordance with the Personal Information Protection Law of the People’s Republic of China, the Regulations on the Administration of Network Data Security and other relevant laws and administrative regulations, record the matter in credit files in accordance with the provisions of relevant laws and administrative regulations, and publicize it.

Article 22 (Effective date). These Provisions take effect on 1 September 2026.

Annexes

The Provisions attach two working forms, summarized rather than reproduced:

  • Annex 1 — Personal Information Protection Compliance Audit Self-Check Table for Small Personal Information Handlers. The instrument that substitutes for a full compliance audit under Article 13, to be completed at least once every five years and retained for five years.
  • Annex 2 — Personal Information Protection Impact Assessment Form for Small Personal Information Handlers. The one-page instrument that substitutes for a standalone PIPIA report under Article 14, retained for three years.

How it fits the regime

These Provisions are the operative half of a two-document package that has been visible for some time. PIPL Article 62 directs the national cyberspace administration department to coordinate the formulation of dedicated personal information protection rules and standards for small personal information handlers. The rules half is this instrument; the standards half is the TC260 draft national standard, Guide for Personal Information Protection by Small Personal Information Processors, whose Introduction expressly states that it exists to provide technical implementation guidance for these then-forthcoming Provisions. The two are designed to be read together: the Provisions say what a small handler may lawfully stop doing; the draft Guide shows, scenario by scenario, what it should do instead.

The instrument sits downstream of the PIPL and the Regulations on the Administration of Network Data Security, which supply its legal basis and remain the source of any liability under Article 21. It intersects three other regimes directly:

  • Compliance audit. The Administrative Measures for Personal Information Protection Compliance Audits set the general audit cadence; Article 13 here reduces it to once every five years on an annexed self-check table, and Article 17 removes it altogether while a Personal Information Protection Certification is valid.
  • Cross-border transfer. Article 10 reproduces, for small handlers, the exemption architecture of the Provisions on Promoting and Regulating Cross-Border Data Flows — the contract-necessity, HR, emergency, statutory-duty and sub-100,000-person routes out of the Data Export Security Assessment, the Standard Contract, and certification — and carves important data out of the exemption entirely.
  • Platform responsibility. Article 8 shifts the compliance center of gravity onto network platforms: where a small handler operates only through a platform, the platform’s rules, audit and impact assessment discharge the small handler’s obligations, and the platform must notify it when those rules change.

The threshold to watch is the definitional one. “Fewer than 100,000 people” is a headcount of the natural persons whose personal information the handler currently processes, counted cumulatively and excluding personal information already deleted — and 100,000 itself is outside the range. Crossing that line moves an organization out of this regime and back into undiluted PIPL, with no transition period stated.

§ RELATED LAWS

See also.

§ COMMENTARY

Briefs on this law.

2 briefs reference this law.

  • § 01 · PERSONAL-INFORMATION

    China Finishes the Other End of PIPL: The Draft Provisions for Large Personal Information Handlers, Read Against Order No. 25

    On 7 August 2026 the CAC published the Provisions on Personal Information Protection for Large Personal Information Handlers (Draft for Comment), consolidating its September 2025 supervision-committee draft and its November 2025 large-network-platform draft into one 50-article instrument, with comments due 7 September 2026. DCC has translated the full text and reads it against CAC/MPS Order No. 25, the small-handler regime published sixteen days earlier — because the pair is the story. Three shifts matter most. The subject changes from 'large network platform' to 'large personal information handler,' and the old registered-user and monthly-active-user tests give way to a three-factor test starting at 10 million data subjects, which reaches banks, insurers, carriers, hospitals and automakers that never thought of themselves as platforms. Designation is declared rather than automatic: a qualifying handler must self-declare through its provincial CAC and the national CAC publishes a public list, which puts the burden of self-identification on the company. And the obligations that follow are structural rather than procedural — absolute domestic storage under Article 13, a nationality requirement for data center controllers under Article 14, a protection officer drawn from management with a direct reporting line to the provincial CAC, and a supervision committee that is not a committee of the board. DCC sets out the full comparison table, the designation trap, and what the newly visible middle band means for foreign-invested subsidiaries.

    personal-information · pipl · large-platforms
  • § 02 · PERSONAL-INFORMATION

    China Writes PIPL a Small-Business Exit Ramp: The Simplified Measures for Small Personal Information Handlers

    On 22 July 2026 the CAC and the Ministry of Public Security jointly issued Order No. 25, the Provisions on Simplified Personal Information Protection Measures for Small Personal Information Handlers, effective 1 September 2026. It is the first instrument to make PIPL's obligations formally proportionate: a handler processing the personal information of fewer than 100,000 people gets a three-item processing-rules template it can satisfy with a posted notice, notice discharged through those published rules alone, consent inferred from voluntary provision of necessary information, compliance audit cut to once every five years — or waived entirely if certified — and a one-page impact assessment. Article 8 lets a handler operating solely through a network platform drop its own rules, notice, audit and assessment altogether, riding on the platform's. Article 10 extends the cross-border exemption architecture to small handlers, with important data carved out. Articles 18 and 19 make no-penalty and mitigated-penalty outcomes mandatory rather than discretionary. DCC reads it for overseas counsel whose Chinese counterparties, franchisees, merchants and portfolio companies sit under the 100,000-person line — and explains why the threshold, not the relief, is the thing to watch.

    personal-information · pipl · small-business
§ SUBSCRIBE

The Monday brief.

One short email every Monday. New briefs on Chinese data-compliance rules from the previous week, with the source law cited.

Opt-in only. Unsubscribe anytime by replying "unsubscribe" to any issue.

SUPPORT DCC

Keep the publication free to read. Suggested support is $19.99, or choose your own amount.

Support →