Skip to content
DCC · DATA COMPLIANCE CHINA China data law, for overseas counsel.
§ 098 · PERSONAL-INFORMATION

China Finishes the Other End of PIPL: The Draft Provisions for Large Personal Information Handlers, Read Against Order No. 25

CAC draft of 7 August 2026, comments due 7 September. Sixteen days after Order No. 25 gave handlers under 100,000 people a lighter PIPL, the same regulator proposes 50 articles for handlers at 10 million and above: full domestic storage, data centers whose legal representative or actual controller must hold PRC nationality, a management-level protection officer who can report over management's head, impact assessments filed with the national CAC, audits every two years, and a supervision committee that is two-thirds external and chaired from outside. Read together, the two instruments turn PIPL into a three-tier statute — and quietly define a middle band by subtraction.

On 7 August 2026 the CAC published the Provisions on Personal Information Protection for Large Personal Information Handlers (Draft for Comment), consolidating its September 2025 supervision-committee draft and its November 2025 large-network-platform draft into one 50-article instrument, with comments due 7 September 2026. DCC has translated the full text and reads it against CAC/MPS Order No. 25, the small-handler regime published sixteen days earlier — because the pair is the story. Three shifts matter most. The subject changes from 'large network platform' to 'large personal information handler,' and the old registered-user and monthly-active-user tests give way to a three-factor test starting at 10 million data subjects, which reaches banks, insurers, carriers, hospitals and automakers that never thought of themselves as platforms. Designation is declared rather than automatic: a qualifying handler must self-declare through its provincial CAC and the national CAC publishes a public list, which puts the burden of self-identification on the company. And the obligations that follow are structural rather than procedural — absolute domestic storage under Article 13, a nationality requirement for data center controllers under Article 14, a protection officer drawn from management with a direct reporting line to the provincial CAC, and a supervision committee that is not a committee of the board. DCC sets out the full comparison table, the designation trap, and what the newly visible middle band means for foreign-invested subsidiaries.

Editor’s Note — DCC.

On 7 August 2026 the Cyberspace Administration of China published the Provisions on Personal Information Protection for Large Personal Information Handlers (Draft for Comment) — 50 articles and an annex, with comments due 7 September 2026 to shujuju@cac.gov.cn. DCC has translated the full text.

The draft consolidates two earlier consultations that never issued: the Provisions on the Establishment of Personal Information Protection Supervision Committees by Large Network Platforms (12 September 2025) and the Provisions on Personal Information Protection for Large Network Platforms (22 November 2025). Both are superseded by this text.

We read it against Order No. 25, the small-handler regime published sixteen days earlier, because the pair is the story. Within one month CAC has proposed the ceiling and finalized the floor of the same statute. PIPL is becoming a tiered law, and the tier a company lands in now matters more than almost any individual obligation inside it.

One reading note. This is a draft, and a consolidated one: thresholds and article numbers moved between the 2025 consultations and this text, and may move again. Nothing here is in force. The comment window closes 7 September.

The two ends, one month apart

Small handlersOrder No. 25Large handlersthis draft
StatusFinal. Effective 1 September 2026Draft for comment. Effective date left blank
IssuedCAC + MPS, 22 July 2026CAC, 7 August 2026
PIPL hookArticle 62(2) — specialized rules for small handlersArticle 58 — large-platform obligations
ThresholdFewer than 100,000 people10 million people and two qualitative conditions
How you enterAutomatically, by falling below the lineBy self-declaration and official designation; CAC publishes the list
How you leaveAutomaticallyApply for change of determination after 6 consecutive months below
Processing rulesThree-item minimum, satisfiable by posted noticeSeven-item itemized structured list, including a full SDK inventory
ConsentInferred from voluntary provision of necessary informationSeparate consent in five scenarios; guardian consent under 14
StorageNo localization rule; six cross-border exemptions in Article 10All PRC-collected and PRC-generated PI stored domestically (Art. 13)
InfrastructureData center in China; legal representative or actual controller must hold PRC nationality (Art. 14)
Protection officerA member of management, with a direct reporting line to the provincial CAC (Arts. 25–26)
Impact assessmentOne-page formFull assessment, filed with the national CAC within 15 working days (Art. 31)
Compliance auditOnce every five years; waived while certifiedAt least every two years, plus annual risk assessment, plus annual minors audit
Governance bodySupervision committee: ≥7 members, ≥2/3 external, external chair (Ch. 4)
Public reportingAnnual personal information protection social responsibility report
Penalty postureMandatory no-penalty and mitigated-penalty outcomesStandard PIPL liability, plus dissolution of the committee, plus forced third-party hosting

Read down that table and the design intent is plain. Order No. 25 asks whether an obligation is worth its cost to a business with 40 employees. This draft asks what a company should look like from the inside when the consequences of its failure are national. The two instruments are not the same rule at different volumes. They are different regulatory theories applied to different risk.

The subject changed, and that is the headline

The predecessor drafts governed 大型网络平台 — large network platforms — and tested for them the way platform regulation usually does: registered users and monthly actives. The November 2025 draft reportedly drew the line at 50 million registered users or 10 million monthly active users.

This draft governs 大型个人信息处理者, large personal information handlers, and Article 2 replaces the user metrics with three factors weighed together:

  1. processing the personal information of more than 10 million natural persons;
  2. providing important network services involving personal information processing, or having a business scope covering multiple lines of business that involve it;
  3. personal information processing activities having a significant impact on national security, economic operation, social stability, public health and safety.

Two consequences follow, and neither is cosmetic.

The perimeter is no longer platforms. A national bank, an insurer, a telecoms carrier, a hospital group, a connected-vehicle manufacturer, a payroll processor — none of these is a network platform, and all of them can clear 10 million data subjects with a qualitative case for factors two and three. The draft keeps its platform-specific duty in Article 29, governing in-platform product and service providers, but that is now one article inside a regime that no longer presumes a platform.

The count is of people, not accounts. Ten million natural persons whose personal information is processed is a materially different measure from registered users, and it does not net out dormant accounts, nor does it require that those people be customers. Employees, applicants, patients, passengers and the counterparties in someone else’s transaction all count.

Designation is declared, and that is the trap

This is the operational difference that most deserves attention during the comment window, because it has no analogue in the small-handler regime.

You do not become a small handler by applying. You simply are one. Designation as a large handler runs the other way. Under Article 3, a handler that processes the personal information of more than 10 million people and that, on self-assessment, considers itself to meet factors two and three, must declare for determination to the national CAC through its provincial CAC. The provincial body runs a 15-working-day completeness check; the national CAC, with the telecoms authority and public security department, settles the list and announces it to society.

Three features of that architecture are worth pausing on.

The self-assessment is the company’s. Factors two and three are qualitative and unquantified. “Important network services,” “multiple lines of business,” “significant impact on economic operation” — a company must form its own view and act on it. Get it wrong in the permissive direction and Article 3’s third paragraph applies: authorities that consider you qualify but have not declared “shall urge” you to. The draft does not say what follows persistent non-declaration, which is one of the more obvious things to raise in comments.

The list is public. Designation is not a private status letter. It is an announced membership, which makes it visible to counterparties, competitors, plaintiffs and the press, and which makes the annual social responsibility report under Article 30 a genuinely public document.

Exit is slow and discretionary. Six consecutive months below the conditions merely entitles a handler to apply for a change of determination. Article 42 then permits — not requires — dissolution of the supervision committee once the application is approved. A company that shrinks does not automatically shed the regime.

For any group at or near 10 million data subjects in China, the practical sequence starts now: run the Article 2 assessment, document the reasoning whichever way it comes out, and decide whether to say anything in the comment window about factors two and three. A company that later declares late will be explaining a judgment it made today.

The three obligations that change infrastructure, not paperwork

Most of Chapter II and Chapter III restates or tightens familiar PIPL duties. Three provisions are different in kind, because complying with them requires changing how the business is built rather than what it writes down.

Article 13 — absolute domestic storage. A large handler “shall store within the territory personal information collected and generated in the course of operations within the territory.” There is no volume trigger, no importance test, and no carve-out. PIPL Article 40 imposes localization on CIIOs and on handlers above a CAC-set volume; this extends the same rule to every designated large handler as a condition of designation. Article 20 still permits export through the assessment, standard contract or certification routes — export and localization coexist, as they always have — but the copy that stays in China is now mandatory, and a global-first architecture with a China cache is not compliant.

Article 14 — nationality of the data center’s controller. The data center storing that personal information must be established in China, must meet national policy and standards, and its management organization’s legal representative or actual controller must hold PRC nationality. This is the sharpest edge in the draft for foreign-invested business. It does not restrict who may own the handler; it restricts who may control the facility. A wholly foreign-owned enterprise designated as a large handler will need to examine whether its captive China data center satisfies the test, and if not, whether it moves to a domestic provider. Note also the drafting shift: the November 2025 draft was reported to require the responsible personnel to be Chinese nationals without foreign permanent residency. The test has moved from personnel residency to the legal representative or actual controller’s nationality — narrower in one direction, broader in another, and worth commenting on precisely because the phrase “actual controller” is undefined here.

Article 44 — hosting as a remedy. Where a handler fails to rectify, CAC together with the telecoms, public security and national security departments “may require the large personal information handler to adopt measures such as hosting personal information with a third-party data center.” That is a structural remedy, not a fine: it separates the data from the operator by regulatory order. DCC is not aware of a precedent for it in the PIPL family, and it belongs on any risk register that currently ends at monetary penalties.

Governance: two independent lines that report outside the company

The draft builds an internal check with two limbs, and both can escalate past the people they check.

The protection officer is management, with an escape hatch. Article 25 requires a member of management to serve as the person responsible for personal information protection. Article 26(3) then gives that person the right, where the company fails without justified reason to act on a compliance opinion or handles it unlawfully, to report directly to the provincial CAC. Article 26(4) requires immediate reporting of major incidents to the provincial CAC and other authorities, to public security where a crime is suspected, and to the national security organ where national security may be affected. This sharpens a role DCC has compared with the GDPR analogue before — see PIPO vs. DPO — and it moves further from the European model, where the DPO’s independence is a protection against dismissal rather than a channel to the regulator.

The supervision committee is not a board committee. Chapter 4 requires a committee within six months of designation: an odd number of members, at least seven, at least two-thirds external, chaired by an external member who must hold senior compliance-audit capability. External members are capped at three concurrent engagements, need three years’ relevant experience, must pass a security background check for which the company may request police assistance, and must satisfy detailed independence tests — no employment or close-relative relationship, no holding above 1% of shares or top-ten natural-person shareholder status, no employment with a 5%-plus shareholder or top-five shareholder entity. Independence is self-examined annually, assessed by the board, and disclosed in the public social responsibility report, as are external members’ allowances.

The annex makes the committee operational: three-year terms renewable once, regular meetings at least every six months, interim meetings on the proposal of one-third of members where there is evidence of unlawful processing, a quorum of half, and resolutions requiring two-thirds of all members with dissents recorded. Resolutions go to the board; the board must handle them and report back; and where the board declines a compliance opinion without justified reason, the committee itself may report to the provincial CAC.

Set against Order No. 25, where a handler under 100,000 people may discharge its notice obligation with a posted sign, this is a different world. It is closest in spirit to a statutory audit committee, staffed by outsiders the company must pay but cannot control, with a reporting line the company cannot close.

The middle band, defined by subtraction

The most useful thing many overseas counsel will take from this draft is where their client is not.

Below 100,000 people: Order No. 25 applies, effective 1 September 2026, and almost everything gets lighter. At or above 10 million people plus the qualitative factors: this draft, if adopted. Between those lines — which is where the large majority of foreign-invested Chinese subsidiaries sit — neither specialized regime applies, and baseline PIPL governs unchanged.

That band is not a gap in the law; it is the law’s default, now visible for the first time because both edges have been drawn. It is worth telling clients plainly, because the coverage of both instruments has tended to imply that everyone is affected. Most companies are not. What changed for the middle is that the ceiling and floor now exist, and movement toward either has consequences that can be planned for rather than discovered.

Three groups should act during the comment window. Companies near 10 million data subjects should run the Article 2 assessment and consider commenting on factors two and three. Foreign-invested companies with captive China data centers should test Article 14 against their actual corporate structure and press on the undefined “actual controller.” And anyone who would be designated should price the supervision committee honestly — seven-plus members, two-thirds external, paid allowances disclosed publicly, meeting at least twice a year — as a standing governance cost rather than a compliance project.

Comments close 7 September 2026.


Source: 《国家互联网信息办公室关于〈大型个人信息处理者个人信息保护规定(征求意见稿)〉公开征求意见的通知》, 网信中国 (CAC official channel), 7 August 2026 — original. DCC’s full translation of the 50 articles and the annex is here. The notice date, comment deadline and consolidation of the two 2025 drafts were verified against the Xinhua reproduction of the CAC notice; the September 2025 and November 2025 predecessor drafts and the reported user thresholds of the latter are drawn from contemporaneous reporting of those consultations, not from this text.

— Not legal advice.

— Not legal advice.


§ SUBSCRIBE

The Monday brief.

One short email every Monday. New briefs on Chinese data-compliance rules from the previous week, with the source law cited.

Opt-in only. Unsubscribe anytime by replying "unsubscribe" to any issue.

SUPPORT DCC

Keep the publication free to read. Suggested support is $19.99, or choose your own amount.

Support →