Skip to content
DCC · DATA COMPLIANCE CHINA China data law, for overseas counsel.
§ 105 · ENFORCEMENT

CVERC Names 82 Apps for PI Violations, and 28 From Its August Batch Are Now Off the Stores

国家计算机病毒应急处理中心, 23 September 2026: 118 findings across 82 apps, mini-programs, WeChat service accounts, TV apps and one ad SDK, sorted into 12 categories written largely in PIPL's own words. Of the 75 apps named in August, 28 failed retest and were taken down by distribution platforms.

On 23 September 2026 the National Computer Virus Emergency Response Center (国家计算机病毒应急处理中心, CVERC) named 82 mobile apps whose collection and use of personal information failed its testing, carried out between 29 July and 4 September under the 2026 CAC + MIIT + MPS joint special campaign. The notice is published as text, and DCC translates it in full: twelve violation categories, 118 findings, and every app, consolidated into one table. Three things set it apart from the MIIT and CAC notices in DCC's tracker. First, a published retest loop: of the 75 apps CVERC named in August, 28 still failed on retest and have been taken down by the distribution platforms. Second, the taxonomy has moved past the 2019 Identification Method into PIPL's statutory text. Five categories track PIPL Articles 23, 24, 30, 31 and 51 almost word for word: separate consent for sharing with another handler, an opt-out from automated-decision push, notice of why sensitive personal information is needed, dedicated rules for children under 14, and security measures. Third, the perimeter: 29 mini-programs on WeChat, Baidu and Alipay, three WeChat service accounts, two TV apps, a standalone ad SDK, and twelve builds downloaded from third-party download sites. Eight hospital channels are named, among them United Family Healthcare's mini-program, and hospitals account for four of the eleven findings of sharing personal information without separate consent.

Editor’s Note — DCC.

This is the first notification from the National Computer Virus Emergency Response Center (国家计算机病毒应急处理中心, CVERC) in DCC’s enforcement tracker. CVERC is a national technical center in Tianjin; its notices name apps and report outcomes but impose no penalty themselves. Its app-testing notifications run as a series under the same 2026 CAC + MIIT + MPS joint campaign that produced the CAC 30-app notification and the MIIT Batch 57 bulletin. Chinese press reports put CVERC’s earlier 2026 batches at 71 apps (early June) and 75 apps (mid-August). This one was published on 23 September 2026.

The MIIT and Shanghai notices come as image tables. CVERC publishes its list as text, so the translation below is complete: all twelve violation categories in full, and every one of the 82 apps. DCC has merged the twelve per-category lists into a single table, one row per app with the categories it was named under, and added unofficial English renderings of the app names for identification. The category-to-law mapping and the analysis are DCC’s.

The notification

Translated in full. The app lists that follow each category in the original are consolidated in the table in the next section.

National Computer Virus Emergency Response Center Testing Finds 82 Mobile Apps Illegally or Excessively Collecting and Using Personal Information

Pursuant to the Announcement on Carrying Out the 2026 Personal Information Protection Series of Special Campaigns (关于开展2026年个人信息保护系列专项行动的公告), jointly issued by the Office of the Central Cyberspace Affairs Commission, the Ministry of Industry and Information Technology and the Ministry of Public Security, and in accordance with the Cybersecurity Law, the Personal Information Protection Law, the Regulation on Network Data Security Management, the Method for Identifying the Unlawful Collection and Use of Personal Information by Apps and other laws, regulations and relevant provisions, testing by the National Computer Virus Emergency Response Center found that 82 mobile apps engage in one or more forms of illegal or excessive collection and use of personal information. They are hereby notified as follows:

1. On the app’s first launch, users are not prompted in a conspicuous manner, such as a pop-up window, to read the privacy policy or other collection and use rules; user consent is sought by non-explicit means, such as agreement to the privacy policy being selected by default; the privacy policy is difficult to access; before processing personal information, the personal information handler does not truthfully, accurately and completely inform the individual, in a conspicuous manner and in clear and understandable language, of the handler’s name, its contact information, the retention period of the personal information and other matters. 20 apps.

2. The privacy policy does not list, item by item, the purposes, methods and scope of the collection and use of personal information by the app (including by entrusted third parties or embedded third-party code and plug-ins). 49 apps.

3. Where a personal information handler provides personal information it processes to another personal information handler, it does not inform the individual of the recipient’s name, contact information, purpose of processing, method of processing and categories of personal information, and obtain the individual’s separate consent. 11 apps.

4. Collection of personal information, or activation of permissions capable of collecting personal information, does not wait until the user’s consent has been obtained. Collection rules are displayed, but after the user taps “refuse” the app still collects personal information or activates permissions capable of collecting personal information, or it asks for consent repeatedly and interferes with the user’s normal use. 3 apps.

5. No effective function is provided for correcting or deleting personal information or for cancelling a user account; unnecessary or unreasonable conditions are imposed on correcting or deleting personal information or cancelling a user account. 2 apps.

6. Complaints and reports are not accepted and handled within the committed time limit. 1 app.

7. No channel or method is provided for users to withdraw consent to the collection of personal information; the personal information handler does not provide a convenient method of withdrawing consent. 7 apps.

8. Information push and commercial marketing are directed at individuals through automated decision-making without also providing an option that does not target the individual’s personal characteristics, or without providing the individual a convenient way to refuse. 4 apps.

9. In processing sensitive personal information, the personal information handler does not inform the individual of the necessity of processing the sensitive personal information and its impact on the individual’s rights and interests. 1 app.

10. In processing the personal information of minors under the age of fourteen, the personal information handler has not formulated specialized personal information processing rules. 3 apps.

11. Effective technical security measures are not adopted to prevent unauthorized access to personal information and its leakage, tampering or loss. 13 apps.

12. No privacy policy. 4 apps.

Of the 75 illegal or non-compliant mobile apps found by the National Computer Virus Emergency Response Center’s testing and notified in the previous issue, 28 still had problems on retest, and the relevant mobile-app distribution platforms have removed them (下架).

(Note: the mobile apps listed in this notification were tested between 29 July 2026 and 4 September 2026.)

The 82 apps

The original lists apps category by category, so an app with several findings appears several times. The table below lists each app once, in order of first appearance, with every category it was named under. The channel and version are the build CVERC tested; mini-programs and service accounts carry no version number. 29 apps were named under more than one category.

#AppChannel testedVersionCategories
1市值风云
Shizhi Fengyun
vivo App StoreV6.55.01, 2
2Fere fitXiaomi App StoreV 5.6.471, 8, 10
3鹏瑞利医信签
Pengruili Yixinqian
WeChat mini-program—1, 2
4徐州医科大学附属医院互联网医院
Affiliated Hospital of Xuzhou Medical University — Internet Hospital
WeChat mini-program—1, 2
5中山大学附属第一医院
First Affiliated Hospital, Sun Yat-sen University
WeChat mini-program—1, 3
6蘑菇宠医
Mogu Chongyi (pet clinic)
Baidu mini-program—1, 10
7滴答滴顺风车
Didadi Shunfengche (carpooling)
Baidu mini-program—1, 4, 7, 11
8我的花园世界
My Garden World
WeChat mini-program—1, 2
9莽过教育
Mangguo Education
WeChat mini-program—1
10苏大继续教育
Soochow University Continuing Education
WeChat mini-program—1
11蜗牛学苑IT教育
Woniu Xueyuan IT Education
WeChat mini-program—1
12高途-让学习更美好
Gaotu
WeChat mini-program—1
13百色出行
Baise Chuxing
WeChat mini-program—1
14艾来电
Ailaidian
WeChat mini-program—1, 2
15租车安心丨沃出行短租长租租购
Zuche Anxin / Wo Chuxing (car rental)
WeChat mini-program—1, 3
16诚赁租机
Chenglin Zuji (device rental)
Alipay mini-program—1
17小黄驴共享
Xiaohuanglü Gongxiang
WeChat mini-program—1, 11
18珂徕出行
Kelai Chuxing
WeChat mini-program—1, 2
19牛卡福万金油能源
Niukafu Wanjinyou Energy
WeChat service account—1
20南京银行鑫享贷
Bank of Nanjing Xinxiangdai (loans)
WeChat mini-program—1
21沙师弟司机
Shashidi — Driver
Huawei AppGalleryv6.0.02
22好轻
Haoqing
vivo App Store5.6.32
23车优多
Cheyouduo
Xiaomi App Store7.2.11.02
24橙果错题本
Chengguo Mistake Notebook
Xiaomi App Store8.9632
25全能手机扫描王
All-in-One Phone Scanner
Baidu Mobile Assistant6.0.42
26知源经络穴位
Zhiyuan Meridians and Acupoints
Baidu Mobile Assistant4.3.02
27六只脚
Liuzhijiao
Sogou Download4.32.52
28妙懂地理
Miaodong Geography
Sogou Download10.1.12
29约牛股票
Yueniu Stocks
PC下载网 (download site)4.7.52
30东南大学附属中大医院智慧医院
Zhongda Hospital, Southeast University — Smart Hospital
WeChat mini-program—2, 3
31江门市中心医院
Jiangmen Central Hospital
WeChat mini-program—2
32重庆高速ETC
Chongqing Expressway ETC
WeChat mini-program—2, 3, 9
33轻牛健康
Qingniu Health
PP Assistant4.20.02
34雅迪智行
Yadea Zhixing
Tencent Yingyongbao8.8.92, 4
35易公交
Yi Gongjiao (bus information)
PP Assistant4.0.22, 5
36PDF扫描全能王
PDF Scanner All-in-One
Xiaomi App Store6.1.02, 8
37橙啦
Chengla
PP AssistantV5.4.1 (338)2
38开盘啦
Kaipanla
PP Assistant6.2.20.52
39租租车
Zuzuche (car rental)
PP Assistant5.4.2608202
40智行旅行
Zhixing Travel
Tencent Yingyongbao10.24.82, 3
41万步健康
Wanbu Health
PP Assistant7.4.0.61832
42萌宝绘本故事
Mengbao Picture-Book Stories
Mi TV App CenterV5.0.4.02, 6, 8
43探奇动物界
Tanqi Animal World
Mi TV App CenterV4.00.002
44贪吃蛇乐园
Snake Paradise (game)
WeChat mini-program—2, 10
45华彩生活
Huacai Life
OPPO Software StoreV5.5.002, 3
46北京交通APP
Beijing Transport
OPPO Software StoreV2.0.72, 3
47广安门医院
Guang’anmen Hospital
OPPO Software StoreV4.3.02, 7
48家庭中医馆
Family TCM Clinic
单机100手游网 (download site)1.0.552
49库课网校
Kuke Online School
PC下载网 (download site)7.4.42
50五星智投
Wuxing Zhitou
PC下载网 (download site)1.31.02
51阿牛智投
Aniu Zhitou
3322软件下载站 (download site)6.9.792
52金斗云智投
Jindouyun Zhitou
PC下载网 (download site)9.3.62
53财联社
Cailian Press
当快软件园 (download site)8.8.22
54诊股宝
Zhengubao
17178下载站 (download site)1.4.132
55丁香医生
DXY Doctor (Dingxiang Yisheng)
多多软件站 (download site)11.63.02
56猎聘
Liepin
Wandoujia6.26.02
57超格教育
Chaoge Education
PC下载网 (download site)4.8.82
58每日瑜伽
Daily Yoga
脚本之家 (download site)9.85.1.02
59星河广告SDK
Xinghe Ad SDK
Official websitev2.6.12
60萝卜投研
Luobo Touyan
Huawei AppGallery5.4.8.02
61遇鹿出行
Yulu Chuxing
WeChat mini-program—2
62卫莱电
Weilaidian
WeChat mini-program—2, 5, 7
63上元教育
Shangyuan Education
PC下载网 (download site)2.9.62
64昆明医科大学第一附属医院
First Affiliated Hospital of Kunming Medical University
WeChat mini-program—3
65韭研公社
Jiuyan Gongshe
OPPO Software Store1.3.83
66班级小管家
Banji Xiaoguanjia (class management)
OPPO Software Store3.10.83, 7
67和睦家医疗UnitedFamily
United Family Healthcare
WeChat mini-program—3
68河西停车
Hexi Parking
WeChat mini-program—4, 7, 11
69健康160
Jiankang 160
vivo App StoreV7.8.7.17, 11
70十六番旅行
Shiliufan Travel
Huawei AppGallery9.5.17, 11
71月亮有约
Yueliang Youyue
Xiaomi App Store1.0.18, 11
72牛股王股票
Niuguwang Stocks
vivo App StoreV7.2.011
73新浪财经
Sina Finance
360 Mobile Assistant10.9.0.111
74兴盛优选
Xingsheng Youxuan
Huawei AppGalleryV2.60.0+1094311
75阿布睡前故事
Abu Bedtime Stories
vivo App StoreV1.2.9.511
76谷医堂商城
Guyitang Mall
vivo App Store1.9.1+202608120111
77一笑而过
Yixiao’erguo
Xiaomi App Store3.3.911
78山东高速ETC
Shandong Expressway ETC
WeChat mini-program—11
79天津市眼科医院视光中心
Tianjin Eye Hospital Optometry Center
WeChat service account—12
80伴学作文
Banxue Composition
Baidu mini-program—12
81久顺出行
Jiushun Chuxing
Baidu mini-program—12
82华山旅游服务平台
Huashan Tourism Service Platform
WeChat service account—12

Consolidated from the twelve per-category lists in the original, which is authoritative. English renderings of app names are DCC’s unofficial translations or transliterations, provided for identification only; they are not official names and may differ from an operator’s registered English name. The Chinese names are the operative identifiers.

Where each category comes from

The notice cites its legal bases as a group and does not tie any category to a provision. The mapping below is DCC’s, made by matching each category’s wording to the source text.

#Category, in shortAppsClosest legal source
1First-run notice, default consent, hard-to-reach policy, incomplete handler notice20Identification Method items (1)2, (1)3, (3)4; PIPL Art. 17
2Purposes, methods and scope not listed item by item, including SDKs49Identification Method item (2)1
3Providing PI to another handler without notice and separate consent11PIPL Art. 23. The Method’s item (5) asks only for consent
4Collecting before consent or after refusal; nagging for consent3Identification Method items (3)1, (3)2
5Correction, deletion and account cancellation2Identification Method items (6)1, (6)2
6Complaints not handled within the committed time1Identification Method item (6)5
7No way, or no convenient way, to withdraw consent7Identification Method item (3)8; PIPL Art. 15
8Automated-decision push without a non-targeted option or easy refusal4PIPL Art. 24 ¶2. The Method’s item (3)6 covers only the non-targeted option
9No notice of why sensitive PI is needed or how it affects the individual1PIPL Art. 30. No counterpart in the Method
10No specialized processing rules for children under 143PIPL Art. 31 ¶2. No counterpart in the Method
11No effective technical security measures13PIPL Art. 51. No counterpart in the Method
12No privacy policy4Identification Method item (1)1

What stands out

The retest loop is published. Of the 75 apps CVERC named in August, 28 failed retest (37%) and have been taken down by the distribution platforms. Each tier of the campaign handles the consequence differently. CAC’s June notice gave operators 15 working days to rectify and report. MIIT’s bulletins require rectification and threaten disposition otherwise. Shanghai issued a separate takedown notice. CVERC reports the outcome in its next naming. The notice does not name the 28, and it does not state a rectification deadline. The August naming and this report are under six weeks apart, and the notice does not say when the retest was run. An operator will not learn from the notice whether it passed. It will learn from the store.

The taxonomy has moved into PIPL’s statutory text. Five of the twelve categories (3, 8, 9, 10 and 11) are written in PIPL’s words almost verbatim. Three of them have no counterpart in the 2019 Identification Method at all: sensitive-PI notice, rules for under-14s, and security measures. The other two raise the Method’s bar. Sharing now requires the recipient’s name and contact details plus separate consent, not just consent. Personalized push now needs a non-targeted option or an easy refusal, not only the former. Category 1 also adds Article 17’s notice list (handler name, contact details, retention period) to the Method’s first-run test. Together these five categories produce 32 of the 118 findings. In practice, external testing now covers PIPL duties that were long treated as paper obligations, and most of them can be checked from the privacy policy and the user interface alone. Category 11 is the exception. It is a technical-security finding, and the notice does not say what the testers observed.

The volume is still in the basics. Categories 1 and 2, notice at first launch and item-by-item disclosure, account for 69 of the 118 findings. Category 2 alone, at 49 apps, sweeps in entrusted third parties and embedded SDKs. So does the one standalone SDK named, 星河广告SDK (Xinghe Ad SDK), tested from its official website.

The in-platform tier fails first. Of the 82 apps, 29 are mini-programs (24 on WeChat, 4 on Baidu, 1 on Alipay) and 3 are WeChat service accounts. Those 32 account for 18 of the 20 category-1 findings and all four apps with no privacy policy at all. CAC’s June notice brought mini-programs into the testing perimeter. CVERC’s perimeter goes further: WeChat service accounts (服务号), Baidu and Alipay mini-programs, two apps from Xiaomi’s TV app store, and the ad SDK.

Hospitals, and the sharing category. Eight hospital or clinic channels are named. Six are WeChat mini-programs, including those of the First Affiliated Hospital of Sun Yat-sen University, Zhongda Hospital of Southeast University and United Family Healthcare (和睦家医疗), the international private hospital group. Guang’anmen Hospital’s app was named under categories 2 and 7. Tianjin Eye Hospital’s optometry center runs a service account with no privacy policy. Four of the eleven category-3 findings, providing personal information to another handler without notice and separate consent, are hospitals. The notice does not say who the recipients were. Medical and health information is sensitive personal information under PIPL Article 28. Even so, the only app named for the sensitive-PI notice failure (category 9) was an expressway ETC mini-program, not a hospital.

Stock apps, and builds from third-party download sites. Twelve of the named apps provide stock-market information, research or investment advice, among them 新浪财经 (Sina Finance) and 财联社 (Cailian Press). Twelve builds were tested from third-party download sites rather than app stores, and half of them belong to that stock-app group. CVERC names the app on the strength of whatever build its testers obtained. In DCC’s reading, that includes builds on sites the operator may not control.

What overseas compliance teams should take from it

  • Audit the privacy policy against PIPL, not only the 2019 Method. For every onward provision: is each recipient named, with contact details, and is there a separate-consent step (Art. 23)? Does every personalized feed or marketing push offer a non-targeted option or a one-step refusal (Art. 24)? Is there a dedicated section on children under 14 (Art. 31)? Does each sensitive-PI field explain why it is needed and how it affects the user (Art. 30)? CVERC is now testing each of these.
  • Put every channel in scope. That means mini-programs on every host platform, WeChat service accounts, TV and large-screen apps, and any SDK you distribute yourself. The in-platform tier produced most of this batch’s basic notice failures.
  • Track your builds in the wild. Old or repackaged versions on third-party download sites can get the operator named. Know where your app is being distributed, and ask sites carrying stale builds to take them down.
  • Treat a CVERC naming as a countdown. The retest comes within weeks, the distribution platforms carry out the takedown, and the notice will not tell you whether you passed. Fix, re-verify against the cited category, and confirm your listing status with each store directly.
  • Healthcare operators: map onward flows from patient-facing mini-programs. Hospitals, including an international private group, made up more than a third of the sharing-without-separate-consent findings.

Sources.

  • Primary. National Computer Virus Emergency Response Center, 国家计算机病毒应急处理中心检测发现82款违法违规收集使用个人信息的移动应用, 国家计算机病毒应急处理中心 WeChat Official Account, 23 September 2026 — original. The notification text, the twelve categories and the app list above are translated from this notice.
  • Earlier batches. The 71-app (June 2026) and 75-app (August 2026) figures are from Chinese press coverage: Xinhua, 3 June 2026; China News Service, 14 August 2026.

Translation, the consolidated table, the category mapping and all commentary are DCC’s.

— Not legal advice.

— Not legal advice.


§ SUBSCRIBE

The Monday brief.

One short email every Monday. New briefs on Chinese data-compliance rules from the previous week, with the source law cited.

Opt-in only. Unsubscribe anytime by replying "unsubscribe" to any issue.

SUPPORT DCC

Keep the publication free to read. Suggested support is $19.99, or choose your own amount.

Support →