Editor’s Note — DCC.
On 7 August 2026 the Cyberspace Administration of China published the Provisions on Personal Information Protection for Large Personal Information Handlers (Draft for Comment) — 50 articles and an annex, with comments due 7 September 2026 to shujuju@cac.gov.cn. DCC has translated the full text.
The draft consolidates two earlier consultations that never issued: the Provisions on the Establishment of Personal Information Protection Supervision Committees by Large Network Platforms (12 September 2025) and the Provisions on Personal Information Protection for Large Network Platforms (22 November 2025). Both are superseded by this text.
We read it against Order No. 25, the small-handler regime published sixteen days earlier, because the pair is the story. Within one month CAC has proposed the ceiling and finalized the floor of the same statute. PIPL is becoming a tiered law, and the tier a company lands in now matters more than almost any individual obligation inside it.
One reading note. This is a draft, and a consolidated one: thresholds and article numbers moved between the 2025 consultations and this text, and may move again. Nothing here is in force. The comment window closes 7 September.
The two ends, one month apart
| Small handlers — Order No. 25 | Large handlers — this draft | |
|---|---|---|
| Status | Final. Effective 1 September 2026 | Draft for comment. Effective date left blank |
| Issued | CAC + MPS, 22 July 2026 | CAC, 7 August 2026 |
| PIPL hook | Article 62(2) — specialized rules for small handlers | Article 58 — large-platform obligations |
| Threshold | Fewer than 100,000 people | 10 million people and two qualitative conditions |
| How you enter | Automatically, by falling below the line | By self-declaration and official designation; CAC publishes the list |
| How you leave | Automatically | Apply for change of determination after 6 consecutive months below |
| Processing rules | Three-item minimum, satisfiable by posted notice | Seven-item itemized structured list, including a full SDK inventory |
| Consent | Inferred from voluntary provision of necessary information | Separate consent in five scenarios; guardian consent under 14 |
| Storage | No localization rule; six cross-border exemptions in Article 10 | All PRC-collected and PRC-generated PI stored domestically (Art. 13) |
| Infrastructure | — | Data center in China; legal representative or actual controller must hold PRC nationality (Art. 14) |
| Protection officer | — | A member of management, with a direct reporting line to the provincial CAC (Arts. 25–26) |
| Impact assessment | One-page form | Full assessment, filed with the national CAC within 15 working days (Art. 31) |
| Compliance audit | Once every five years; waived while certified | At least every two years, plus annual risk assessment, plus annual minors audit |
| Governance body | — | Supervision committee: ≥7 members, ≥2/3 external, external chair (Ch. 4) |
| Public reporting | — | Annual personal information protection social responsibility report |
| Penalty posture | Mandatory no-penalty and mitigated-penalty outcomes | Standard PIPL liability, plus dissolution of the committee, plus forced third-party hosting |
Read down that table and the design intent is plain. Order No. 25 asks whether an obligation is worth its cost to a business with 40 employees. This draft asks what a company should look like from the inside when the consequences of its failure are national. The two instruments are not the same rule at different volumes. They are different regulatory theories applied to different risk.
The subject changed, and that is the headline
The predecessor drafts governed 大型网络平台 — large network platforms — and tested for them the way platform regulation usually does: registered users and monthly actives. The November 2025 draft reportedly drew the line at 50 million registered users or 10 million monthly active users.
This draft governs 大型个人信息处理者, large personal information handlers, and Article 2 replaces the user metrics with three factors weighed together:
- processing the personal information of more than 10 million natural persons;
- providing important network services involving personal information processing, or having a business scope covering multiple lines of business that involve it;
- personal information processing activities having a significant impact on national security, economic operation, social stability, public health and safety.
Two consequences follow, and neither is cosmetic.
The perimeter is no longer platforms. A national bank, an insurer, a telecoms carrier, a hospital group, a connected-vehicle manufacturer, a payroll processor — none of these is a network platform, and all of them can clear 10 million data subjects with a qualitative case for factors two and three. The draft keeps its platform-specific duty in Article 29, governing in-platform product and service providers, but that is now one article inside a regime that no longer presumes a platform.
The count is of people, not accounts. Ten million natural persons whose personal information is processed is a materially different measure from registered users, and it does not net out dormant accounts, nor does it require that those people be customers. Employees, applicants, patients, passengers and the counterparties in someone else’s transaction all count.
Designation is declared, and that is the trap
This is the operational difference that most deserves attention during the comment window, because it has no analogue in the small-handler regime.
You do not become a small handler by applying. You simply are one. Designation as a large handler runs the other way. Under Article 3, a handler that processes the personal information of more than 10 million people and that, on self-assessment, considers itself to meet factors two and three, must declare for determination to the national CAC through its provincial CAC. The provincial body runs a 15-working-day completeness check; the national CAC, with the telecoms authority and public security department, settles the list and announces it to society.
Three features of that architecture are worth pausing on.
The self-assessment is the company’s. Factors two and three are qualitative and unquantified. “Important network services,” “multiple lines of business,” “significant impact on economic operation” — a company must form its own view and act on it. Get it wrong in the permissive direction and Article 3’s third paragraph applies: authorities that consider you qualify but have not declared “shall urge” you to. The draft does not say what follows persistent non-declaration, which is one of the more obvious things to raise in comments.
The list is public. Designation is not a private status letter. It is an announced membership, which makes it visible to counterparties, competitors, plaintiffs and the press, and which makes the annual social responsibility report under Article 30 a genuinely public document.
Exit is slow and discretionary. Six consecutive months below the conditions merely entitles a handler to apply for a change of determination. Article 42 then permits — not requires — dissolution of the supervision committee once the application is approved. A company that shrinks does not automatically shed the regime.
For any group at or near 10 million data subjects in China, the practical sequence starts now: run the Article 2 assessment, document the reasoning whichever way it comes out, and decide whether to say anything in the comment window about factors two and three. A company that later declares late will be explaining a judgment it made today.
The three obligations that change infrastructure, not paperwork
Most of Chapter II and Chapter III restates or tightens familiar PIPL duties. Three provisions are different in kind, because complying with them requires changing how the business is built rather than what it writes down.
Article 13 — absolute domestic storage. A large handler “shall store within the territory personal information collected and generated in the course of operations within the territory.” There is no volume trigger, no importance test, and no carve-out. PIPL Article 40 imposes localization on CIIOs and on handlers above a CAC-set volume; this extends the same rule to every designated large handler as a condition of designation. Article 20 still permits export through the assessment, standard contract or certification routes — export and localization coexist, as they always have — but the copy that stays in China is now mandatory, and a global-first architecture with a China cache is not compliant.
Article 14 — nationality of the data center’s controller. The data center storing that personal information must be established in China, must meet national policy and standards, and its management organization’s legal representative or actual controller must hold PRC nationality. This is the sharpest edge in the draft for foreign-invested business. It does not restrict who may own the handler; it restricts who may control the facility. A wholly foreign-owned enterprise designated as a large handler will need to examine whether its captive China data center satisfies the test, and if not, whether it moves to a domestic provider. Note also the drafting shift: the November 2025 draft was reported to require the responsible personnel to be Chinese nationals without foreign permanent residency. The test has moved from personnel residency to the legal representative or actual controller’s nationality — narrower in one direction, broader in another, and worth commenting on precisely because the phrase “actual controller” is undefined here.
Article 44 — hosting as a remedy. Where a handler fails to rectify, CAC together with the telecoms, public security and national security departments “may require the large personal information handler to adopt measures such as hosting personal information with a third-party data center.” That is a structural remedy, not a fine: it separates the data from the operator by regulatory order. DCC is not aware of a precedent for it in the PIPL family, and it belongs on any risk register that currently ends at monetary penalties.
Governance: two independent lines that report outside the company
The draft builds an internal check with two limbs, and both can escalate past the people they check.
The protection officer is management, with an escape hatch. Article 25 requires a member of management to serve as the person responsible for personal information protection. Article 26(3) then gives that person the right, where the company fails without justified reason to act on a compliance opinion or handles it unlawfully, to report directly to the provincial CAC. Article 26(4) requires immediate reporting of major incidents to the provincial CAC and other authorities, to public security where a crime is suspected, and to the national security organ where national security may be affected. This sharpens a role DCC has compared with the GDPR analogue before — see PIPO vs. DPO — and it moves further from the European model, where the DPO’s independence is a protection against dismissal rather than a channel to the regulator.
The supervision committee is not a board committee. Chapter 4 requires a committee within six months of designation: an odd number of members, at least seven, at least two-thirds external, chaired by an external member who must hold senior compliance-audit capability. External members are capped at three concurrent engagements, need three years’ relevant experience, must pass a security background check for which the company may request police assistance, and must satisfy detailed independence tests — no employment or close-relative relationship, no holding above 1% of shares or top-ten natural-person shareholder status, no employment with a 5%-plus shareholder or top-five shareholder entity. Independence is self-examined annually, assessed by the board, and disclosed in the public social responsibility report, as are external members’ allowances.
The annex makes the committee operational: three-year terms renewable once, regular meetings at least every six months, interim meetings on the proposal of one-third of members where there is evidence of unlawful processing, a quorum of half, and resolutions requiring two-thirds of all members with dissents recorded. Resolutions go to the board; the board must handle them and report back; and where the board declines a compliance opinion without justified reason, the committee itself may report to the provincial CAC.
Set against Order No. 25, where a handler under 100,000 people may discharge its notice obligation with a posted sign, this is a different world. It is closest in spirit to a statutory audit committee, staffed by outsiders the company must pay but cannot control, with a reporting line the company cannot close.
The middle band, defined by subtraction
The most useful thing many overseas counsel will take from this draft is where their client is not.
Below 100,000 people: Order No. 25 applies, effective 1 September 2026, and almost everything gets lighter. At or above 10 million people plus the qualitative factors: this draft, if adopted. Between those lines — which is where the large majority of foreign-invested Chinese subsidiaries sit — neither specialized regime applies, and baseline PIPL governs unchanged.
That band is not a gap in the law; it is the law’s default, now visible for the first time because both edges have been drawn. It is worth telling clients plainly, because the coverage of both instruments has tended to imply that everyone is affected. Most companies are not. What changed for the middle is that the ceiling and floor now exist, and movement toward either has consequences that can be planned for rather than discovered.
Three groups should act during the comment window. Companies near 10 million data subjects should run the Article 2 assessment and consider commenting on factors two and three. Foreign-invested companies with captive China data centers should test Article 14 against their actual corporate structure and press on the undefined “actual controller.” And anyone who would be designated should price the supervision committee honestly — seven-plus members, two-thirds external, paid allowances disclosed publicly, meeting at least twice a year — as a standing governance cost rather than a compliance project.
Comments close 7 September 2026.
Source: 《国家互联网信息办公室关于〈大型个人信息处理者个人信息保护规定(征求意见稿)〉公开征求意见的通知》, 网信中国 (CAC official channel), 7 August 2026 — original. DCC’s full translation of the 50 articles and the annex is here. The notice date, comment deadline and consolidation of the two 2025 drafts were verified against the Xinhua reproduction of the CAC notice; the September 2025 and November 2025 predecessor drafts and the reported user thresholds of the latter are drawn from contemporaneous reporting of those consultations, not from this text.
— Not legal advice.