Editor’s Note — DCC.
This is the first notification from the National Computer Virus Emergency Response Center (国家计算机病毒应急处理中心, CVERC) in DCC’s enforcement tracker. CVERC is a national technical center in Tianjin; its notices name apps and report outcomes but impose no penalty themselves. Its app-testing notifications run as a series under the same 2026 CAC + MIIT + MPS joint campaign that produced the CAC 30-app notification and the MIIT Batch 57 bulletin. Chinese press reports put CVERC’s earlier 2026 batches at 71 apps (early June) and 75 apps (mid-August). This one was published on 23 September 2026.
The MIIT and Shanghai notices come as image tables. CVERC publishes its list as text, so the translation below is complete: all twelve violation categories in full, and every one of the 82 apps. DCC has merged the twelve per-category lists into a single table, one row per app with the categories it was named under, and added unofficial English renderings of the app names for identification. The category-to-law mapping and the analysis are DCC’s.
The notification
Translated in full. The app lists that follow each category in the original are consolidated in the table in the next section.
National Computer Virus Emergency Response Center Testing Finds 82 Mobile Apps Illegally or Excessively Collecting and Using Personal Information
Pursuant to the Announcement on Carrying Out the 2026 Personal Information Protection Series of Special Campaigns (关于开展2026年个人信息保护系列专项行动的公告), jointly issued by the Office of the Central Cyberspace Affairs Commission, the Ministry of Industry and Information Technology and the Ministry of Public Security, and in accordance with the Cybersecurity Law, the Personal Information Protection Law, the Regulation on Network Data Security Management, the Method for Identifying the Unlawful Collection and Use of Personal Information by Apps and other laws, regulations and relevant provisions, testing by the National Computer Virus Emergency Response Center found that 82 mobile apps engage in one or more forms of illegal or excessive collection and use of personal information. They are hereby notified as follows:
1. On the app’s first launch, users are not prompted in a conspicuous manner, such as a pop-up window, to read the privacy policy or other collection and use rules; user consent is sought by non-explicit means, such as agreement to the privacy policy being selected by default; the privacy policy is difficult to access; before processing personal information, the personal information handler does not truthfully, accurately and completely inform the individual, in a conspicuous manner and in clear and understandable language, of the handler’s name, its contact information, the retention period of the personal information and other matters. 20 apps.
2. The privacy policy does not list, item by item, the purposes, methods and scope of the collection and use of personal information by the app (including by entrusted third parties or embedded third-party code and plug-ins). 49 apps.
3. Where a personal information handler provides personal information it processes to another personal information handler, it does not inform the individual of the recipient’s name, contact information, purpose of processing, method of processing and categories of personal information, and obtain the individual’s separate consent. 11 apps.
4. Collection of personal information, or activation of permissions capable of collecting personal information, does not wait until the user’s consent has been obtained. Collection rules are displayed, but after the user taps “refuse” the app still collects personal information or activates permissions capable of collecting personal information, or it asks for consent repeatedly and interferes with the user’s normal use. 3 apps.
5. No effective function is provided for correcting or deleting personal information or for cancelling a user account; unnecessary or unreasonable conditions are imposed on correcting or deleting personal information or cancelling a user account. 2 apps.
6. Complaints and reports are not accepted and handled within the committed time limit. 1 app.
7. No channel or method is provided for users to withdraw consent to the collection of personal information; the personal information handler does not provide a convenient method of withdrawing consent. 7 apps.
8. Information push and commercial marketing are directed at individuals through automated decision-making without also providing an option that does not target the individual’s personal characteristics, or without providing the individual a convenient way to refuse. 4 apps.
9. In processing sensitive personal information, the personal information handler does not inform the individual of the necessity of processing the sensitive personal information and its impact on the individual’s rights and interests. 1 app.
10. In processing the personal information of minors under the age of fourteen, the personal information handler has not formulated specialized personal information processing rules. 3 apps.
11. Effective technical security measures are not adopted to prevent unauthorized access to personal information and its leakage, tampering or loss. 13 apps.
12. No privacy policy. 4 apps.
Of the 75 illegal or non-compliant mobile apps found by the National Computer Virus Emergency Response Center’s testing and notified in the previous issue, 28 still had problems on retest, and the relevant mobile-app distribution platforms have removed them (下架).
(Note: the mobile apps listed in this notification were tested between 29 July 2026 and 4 September 2026.)
The 82 apps
The original lists apps category by category, so an app with several findings appears several times. The table below lists each app once, in order of first appearance, with every category it was named under. The channel and version are the build CVERC tested; mini-programs and service accounts carry no version number. 29 apps were named under more than one category.
| # | App | Channel tested | Version | Categories |
|---|---|---|---|---|
| 1 | 市值风云 Shizhi Fengyun | vivo App Store | V6.55.0 | 1, 2 |
| 2 | Fere fit | Xiaomi App Store | V 5.6.47 | 1, 8, 10 |
| 3 | 鹏瑞利医信签 Pengruili Yixinqian | WeChat mini-program | — | 1, 2 |
| 4 | 徐州医科大学附属医院互联网医院 Affiliated Hospital of Xuzhou Medical University — Internet Hospital | WeChat mini-program | — | 1, 2 |
| 5 | 中山大学附属第一医院 First Affiliated Hospital, Sun Yat-sen University | WeChat mini-program | — | 1, 3 |
| 6 | 蘑菇宠医 Mogu Chongyi (pet clinic) | Baidu mini-program | — | 1, 10 |
| 7 | 滴答滴顺风车 Didadi Shunfengche (carpooling) | Baidu mini-program | — | 1, 4, 7, 11 |
| 8 | 我的花园世界 My Garden World | WeChat mini-program | — | 1, 2 |
| 9 | 莽过教育 Mangguo Education | WeChat mini-program | — | 1 |
| 10 | 苏大继续教育 Soochow University Continuing Education | WeChat mini-program | — | 1 |
| 11 | 蜗牛学苑IT教育 Woniu Xueyuan IT Education | WeChat mini-program | — | 1 |
| 12 | 高途-让学习更美好 Gaotu | WeChat mini-program | — | 1 |
| 13 | 百色出行 Baise Chuxing | WeChat mini-program | — | 1 |
| 14 | 艾来电 Ailaidian | WeChat mini-program | — | 1, 2 |
| 15 | 租车安心丨沃出行短租长租租购 Zuche Anxin / Wo Chuxing (car rental) | WeChat mini-program | — | 1, 3 |
| 16 | 诚赁租机 Chenglin Zuji (device rental) | Alipay mini-program | — | 1 |
| 17 | 小黄驴共享 Xiaohuanglü Gongxiang | WeChat mini-program | — | 1, 11 |
| 18 | 珂徕出行 Kelai Chuxing | WeChat mini-program | — | 1, 2 |
| 19 | 牛卡福万金油能源 Niukafu Wanjinyou Energy | WeChat service account | — | 1 |
| 20 | 南京银行鑫享贷 Bank of Nanjing Xinxiangdai (loans) | WeChat mini-program | — | 1 |
| 21 | 沙师弟司机 Shashidi — Driver | Huawei AppGallery | v6.0.0 | 2 |
| 22 | 好轻 Haoqing | vivo App Store | 5.6.3 | 2 |
| 23 | 车优多 Cheyouduo | Xiaomi App Store | 7.2.11.0 | 2 |
| 24 | 橙果错题本 Chengguo Mistake Notebook | Xiaomi App Store | 8.963 | 2 |
| 25 | 全能手机扫描王 All-in-One Phone Scanner | Baidu Mobile Assistant | 6.0.4 | 2 |
| 26 | 知源经络穴位 Zhiyuan Meridians and Acupoints | Baidu Mobile Assistant | 4.3.0 | 2 |
| 27 | 六只脚 Liuzhijiao | Sogou Download | 4.32.5 | 2 |
| 28 | 妙懂地理 Miaodong Geography | Sogou Download | 10.1.1 | 2 |
| 29 | 约牛股票 Yueniu Stocks | PC下载网 (download site) | 4.7.5 | 2 |
| 30 | 东南大学附属中大医院智慧医院 Zhongda Hospital, Southeast University — Smart Hospital | WeChat mini-program | — | 2, 3 |
| 31 | 江门市中心医院 Jiangmen Central Hospital | WeChat mini-program | — | 2 |
| 32 | 重庆高速ETC Chongqing Expressway ETC | WeChat mini-program | — | 2, 3, 9 |
| 33 | 轻牛健康 Qingniu Health | PP Assistant | 4.20.0 | 2 |
| 34 | 雅迪智行 Yadea Zhixing | Tencent Yingyongbao | 8.8.9 | 2, 4 |
| 35 | 易公交 Yi Gongjiao (bus information) | PP Assistant | 4.0.2 | 2, 5 |
| 36 | PDF扫描全能王 PDF Scanner All-in-One | Xiaomi App Store | 6.1.0 | 2, 8 |
| 37 | 橙啦 Chengla | PP Assistant | V5.4.1 (338) | 2 |
| 38 | 开盘啦 Kaipanla | PP Assistant | 6.2.20.5 | 2 |
| 39 | 租租车 Zuzuche (car rental) | PP Assistant | 5.4.260820 | 2 |
| 40 | 智行旅行 Zhixing Travel | Tencent Yingyongbao | 10.24.8 | 2, 3 |
| 41 | 万步健康 Wanbu Health | PP Assistant | 7.4.0.6183 | 2 |
| 42 | 萌宝绘本故事 Mengbao Picture-Book Stories | Mi TV App Center | V5.0.4.0 | 2, 6, 8 |
| 43 | 探奇动物界 Tanqi Animal World | Mi TV App Center | V4.00.00 | 2 |
| 44 | 贪吃蛇乐园 Snake Paradise (game) | WeChat mini-program | — | 2, 10 |
| 45 | 华彩生活 Huacai Life | OPPO Software Store | V5.5.00 | 2, 3 |
| 46 | 北京交通APP Beijing Transport | OPPO Software Store | V2.0.7 | 2, 3 |
| 47 | 广安门医院 Guang’anmen Hospital | OPPO Software Store | V4.3.0 | 2, 7 |
| 48 | 家庭中医馆 Family TCM Clinic | 单机100手游网 (download site) | 1.0.55 | 2 |
| 49 | 库课网校 Kuke Online School | PC下载网 (download site) | 7.4.4 | 2 |
| 50 | 五星智投 Wuxing Zhitou | PC下载网 (download site) | 1.31.0 | 2 |
| 51 | 阿牛智投 Aniu Zhitou | 3322软件下载站 (download site) | 6.9.79 | 2 |
| 52 | 金斗云智投 Jindouyun Zhitou | PC下载网 (download site) | 9.3.6 | 2 |
| 53 | 财联社 Cailian Press | 当快软件园 (download site) | 8.8.2 | 2 |
| 54 | 诊股宝 Zhengubao | 17178下载站 (download site) | 1.4.13 | 2 |
| 55 | 丁香医生 DXY Doctor (Dingxiang Yisheng) | 多多软件站 (download site) | 11.63.0 | 2 |
| 56 | 猎聘 Liepin | Wandoujia | 6.26.0 | 2 |
| 57 | 超格教育 Chaoge Education | PC下载网 (download site) | 4.8.8 | 2 |
| 58 | 每日瑜伽 Daily Yoga | 脚本之家 (download site) | 9.85.1.0 | 2 |
| 59 | 星河广告SDK Xinghe Ad SDK | Official website | v2.6.1 | 2 |
| 60 | 萝卜投研 Luobo Touyan | Huawei AppGallery | 5.4.8.0 | 2 |
| 61 | 遇鹿出行 Yulu Chuxing | WeChat mini-program | — | 2 |
| 62 | 卫莱电 Weilaidian | WeChat mini-program | — | 2, 5, 7 |
| 63 | 上元教育 Shangyuan Education | PC下载网 (download site) | 2.9.6 | 2 |
| 64 | 昆明医科大学第一附属医院 First Affiliated Hospital of Kunming Medical University | WeChat mini-program | — | 3 |
| 65 | 韭研公社 Jiuyan Gongshe | OPPO Software Store | 1.3.8 | 3 |
| 66 | 班级小管家 Banji Xiaoguanjia (class management) | OPPO Software Store | 3.10.8 | 3, 7 |
| 67 | 和睦家医疗UnitedFamily United Family Healthcare | WeChat mini-program | — | 3 |
| 68 | 河西停车 Hexi Parking | WeChat mini-program | — | 4, 7, 11 |
| 69 | 健康160 Jiankang 160 | vivo App Store | V7.8.7.1 | 7, 11 |
| 70 | 十六番旅行 Shiliufan Travel | Huawei AppGallery | 9.5.1 | 7, 11 |
| 71 | 月亮有约 Yueliang Youyue | Xiaomi App Store | 1.0.1 | 8, 11 |
| 72 | 牛股王股票 Niuguwang Stocks | vivo App Store | V7.2.0 | 11 |
| 73 | 新浪财经 Sina Finance | 360 Mobile Assistant | 10.9.0.1 | 11 |
| 74 | 兴盛优选 Xingsheng Youxuan | Huawei AppGallery | V2.60.0+10943 | 11 |
| 75 | 阿布睡前故事 Abu Bedtime Stories | vivo App Store | V1.2.9.5 | 11 |
| 76 | 谷医堂商城 Guyitang Mall | vivo App Store | 1.9.1+2026081201 | 11 |
| 77 | 一笑而过 Yixiao’erguo | Xiaomi App Store | 3.3.9 | 11 |
| 78 | 山东高速ETC Shandong Expressway ETC | WeChat mini-program | — | 11 |
| 79 | 天津市眼科医院视光中心 Tianjin Eye Hospital Optometry Center | WeChat service account | — | 12 |
| 80 | 伴学作文 Banxue Composition | Baidu mini-program | — | 12 |
| 81 | 久顺出行 Jiushun Chuxing | Baidu mini-program | — | 12 |
| 82 | 华山旅游服务平台 Huashan Tourism Service Platform | WeChat service account | — | 12 |
Consolidated from the twelve per-category lists in the original, which is authoritative. English renderings of app names are DCC’s unofficial translations or transliterations, provided for identification only; they are not official names and may differ from an operator’s registered English name. The Chinese names are the operative identifiers.
Where each category comes from
The notice cites its legal bases as a group and does not tie any category to a provision. The mapping below is DCC’s, made by matching each category’s wording to the source text.
| # | Category, in short | Apps | Closest legal source |
|---|---|---|---|
| 1 | First-run notice, default consent, hard-to-reach policy, incomplete handler notice | 20 | Identification Method items (1)2, (1)3, (3)4; PIPL Art. 17 |
| 2 | Purposes, methods and scope not listed item by item, including SDKs | 49 | Identification Method item (2)1 |
| 3 | Providing PI to another handler without notice and separate consent | 11 | PIPL Art. 23. The Method’s item (5) asks only for consent |
| 4 | Collecting before consent or after refusal; nagging for consent | 3 | Identification Method items (3)1, (3)2 |
| 5 | Correction, deletion and account cancellation | 2 | Identification Method items (6)1, (6)2 |
| 6 | Complaints not handled within the committed time | 1 | Identification Method item (6)5 |
| 7 | No way, or no convenient way, to withdraw consent | 7 | Identification Method item (3)8; PIPL Art. 15 |
| 8 | Automated-decision push without a non-targeted option or easy refusal | 4 | PIPL Art. 24 ¶2. The Method’s item (3)6 covers only the non-targeted option |
| 9 | No notice of why sensitive PI is needed or how it affects the individual | 1 | PIPL Art. 30. No counterpart in the Method |
| 10 | No specialized processing rules for children under 14 | 3 | PIPL Art. 31 ¶2. No counterpart in the Method |
| 11 | No effective technical security measures | 13 | PIPL Art. 51. No counterpart in the Method |
| 12 | No privacy policy | 4 | Identification Method item (1)1 |
What stands out
The retest loop is published. Of the 75 apps CVERC named in August, 28 failed retest (37%) and have been taken down by the distribution platforms. Each tier of the campaign handles the consequence differently. CAC’s June notice gave operators 15 working days to rectify and report. MIIT’s bulletins require rectification and threaten disposition otherwise. Shanghai issued a separate takedown notice. CVERC reports the outcome in its next naming. The notice does not name the 28, and it does not state a rectification deadline. The August naming and this report are under six weeks apart, and the notice does not say when the retest was run. An operator will not learn from the notice whether it passed. It will learn from the store.
The taxonomy has moved into PIPL’s statutory text. Five of the twelve categories (3, 8, 9, 10 and 11) are written in PIPL’s words almost verbatim. Three of them have no counterpart in the 2019 Identification Method at all: sensitive-PI notice, rules for under-14s, and security measures. The other two raise the Method’s bar. Sharing now requires the recipient’s name and contact details plus separate consent, not just consent. Personalized push now needs a non-targeted option or an easy refusal, not only the former. Category 1 also adds Article 17’s notice list (handler name, contact details, retention period) to the Method’s first-run test. Together these five categories produce 32 of the 118 findings. In practice, external testing now covers PIPL duties that were long treated as paper obligations, and most of them can be checked from the privacy policy and the user interface alone. Category 11 is the exception. It is a technical-security finding, and the notice does not say what the testers observed.
The volume is still in the basics. Categories 1 and 2, notice at first launch and item-by-item disclosure, account for 69 of the 118 findings. Category 2 alone, at 49 apps, sweeps in entrusted third parties and embedded SDKs. So does the one standalone SDK named, 星河广告SDK (Xinghe Ad SDK), tested from its official website.
The in-platform tier fails first. Of the 82 apps, 29 are mini-programs (24 on WeChat, 4 on Baidu, 1 on Alipay) and 3 are WeChat service accounts. Those 32 account for 18 of the 20 category-1 findings and all four apps with no privacy policy at all. CAC’s June notice brought mini-programs into the testing perimeter. CVERC’s perimeter goes further: WeChat service accounts (服务号), Baidu and Alipay mini-programs, two apps from Xiaomi’s TV app store, and the ad SDK.
Hospitals, and the sharing category. Eight hospital or clinic channels are named. Six are WeChat mini-programs, including those of the First Affiliated Hospital of Sun Yat-sen University, Zhongda Hospital of Southeast University and United Family Healthcare (和睦家医疗), the international private hospital group. Guang’anmen Hospital’s app was named under categories 2 and 7. Tianjin Eye Hospital’s optometry center runs a service account with no privacy policy. Four of the eleven category-3 findings, providing personal information to another handler without notice and separate consent, are hospitals. The notice does not say who the recipients were. Medical and health information is sensitive personal information under PIPL Article 28. Even so, the only app named for the sensitive-PI notice failure (category 9) was an expressway ETC mini-program, not a hospital.
Stock apps, and builds from third-party download sites. Twelve of the named apps provide stock-market information, research or investment advice, among them 新浪财经 (Sina Finance) and 财联社 (Cailian Press). Twelve builds were tested from third-party download sites rather than app stores, and half of them belong to that stock-app group. CVERC names the app on the strength of whatever build its testers obtained. In DCC’s reading, that includes builds on sites the operator may not control.
What overseas compliance teams should take from it
- Audit the privacy policy against PIPL, not only the 2019 Method. For every onward provision: is each recipient named, with contact details, and is there a separate-consent step (Art. 23)? Does every personalized feed or marketing push offer a non-targeted option or a one-step refusal (Art. 24)? Is there a dedicated section on children under 14 (Art. 31)? Does each sensitive-PI field explain why it is needed and how it affects the user (Art. 30)? CVERC is now testing each of these.
- Put every channel in scope. That means mini-programs on every host platform, WeChat service accounts, TV and large-screen apps, and any SDK you distribute yourself. The in-platform tier produced most of this batch’s basic notice failures.
- Track your builds in the wild. Old or repackaged versions on third-party download sites can get the operator named. Know where your app is being distributed, and ask sites carrying stale builds to take them down.
- Treat a CVERC naming as a countdown. The retest comes within weeks, the distribution platforms carry out the takedown, and the notice will not tell you whether you passed. Fix, re-verify against the cited category, and confirm your listing status with each store directly.
- Healthcare operators: map onward flows from patient-facing mini-programs. Hospitals, including an international private group, made up more than a third of the sharing-without-separate-consent findings.
Sources.
- Primary. National Computer Virus Emergency Response Center, 国家计算机病毒应急处理中心检测发现82款违法违规收集使用个人信息的移动应用, 国家计算机病毒应急处理中心 WeChat Official Account, 23 September 2026 — original. The notification text, the twelve categories and the app list above are translated from this notice.
- Earlier batches. The 71-app (June 2026) and 75-app (August 2026) figures are from Chinese press coverage: Xinhua, 3 June 2026; China News Service, 14 August 2026.
Translation, the consolidated table, the category mapping and all commentary are DCC’s.
— Not legal advice.