---
title: "China Finishes the Other End of PIPL: The Draft Provisions for Large Personal Information Handlers, Read Against Order No. 25"
author: "DCC Editorial"
published: 2026-08-07T10:00:00.000Z
url: https://datacompliancechina.com/posts/large-pi-handlers-draft-tiered-pipl/
description: "On 7 August 2026 the CAC published the Provisions on Personal Information Protection for Large Personal Information Handlers (Draft for Comment), consolidating its September 2025 supervision-committee draft and its November 2025 large-network-platform draft into one 50-article instrument, with comments due 7 September 2026. DCC has translated the full text and reads it against CAC/MPS Order No. 25, the small-handler regime published sixteen days earlier — because the pair is the story. Three shifts matter most. The subject changes from 'large network platform' to 'large personal information handler,' and the old registered-user and monthly-active-user tests give way to a three-factor test starting at 10 million data subjects, which reaches banks, insurers, carriers, hospitals and automakers that never thought of themselves as platforms. Designation is declared rather than automatic: a qualifying handler must self-declare through its provincial CAC and the national CAC publishes a public list, which puts the burden of self-identification on the company. And the obligations that follow are structural rather than procedural — absolute domestic storage under Article 13, a nationality requirement for data center controllers under Article 14, a protection officer drawn from management with a direct reporting line to the provincial CAC, and a supervision committee that is not a committee of the board. DCC sets out the full comparison table, the designation trap, and what the newly visible middle band means for foreign-invested subsidiaries."
tags: ["personal-information", "pipl", "large-platforms", "data-localization", "compliance-audit", "dpo", "pipo", "governance", "cac", "draft-for-comment", "cross-border-data", "minors-protection", "大型个人信息处理者"]
laws_cited: ["large-pi-handlers-protection-provisions-draft", "small-pi-handlers-simplified-measures", "pipl", "network-data-security-regulations", "personal-info-audit-measures", "minors-online-protection-regulations", "data-export-security-assessment-measures"]
domains: ["personal-information", "cross-border", "data-security"]
account: "wangxin-china"
original_title: "国家互联网信息办公室关于《大型个人信息处理者个人信息保护规定（征求意见稿）》公开征求意见的通知"
original_author: "国家互联网信息办公室 (Cyberspace Administration of China)"
original_publication: "网信中国 (Cyberspace Administration of China official channel)"
original_url: "https://mp.weixin.qq.com/s/BeNitCJ468LFRu6D0rE-7Q"
source_language: "zh"
---

> **Source: Data Compliance China** — https://datacompliancechina.com/posts/large-pi-handlers-draft-tiered-pipl/ · China data law, translated and annotated for overseas counsel. Cite as: Data Compliance China, "China Finishes the Other End of PIPL: The Draft Provisions for Large Personal Information Handlers, Read Against Order No. 25", https://datacompliancechina.com/posts/large-pi-handlers-draft-tiered-pipl/
> *Editor's Note — DCC.*
>
> On **7 August 2026** the Cyberspace Administration of China published the
> [*Provisions on Personal Information Protection for Large Personal
> Information Handlers* (Draft for Comment)](/laws/large-pi-handlers-protection-provisions-draft/)
> — 50 articles and an annex, with comments due **7 September 2026** to
> shujuju@cac.gov.cn. DCC has translated the full text.
>
> The draft consolidates two earlier consultations that never issued: the
> *Provisions on the Establishment of Personal Information Protection
> Supervision Committees by Large Network Platforms* (12 September 2025) and
> the *Provisions on Personal Information Protection for Large Network
> Platforms* (22 November 2025). Both are superseded by this text.
>
> We read it against [Order No. 25](/posts/small-pi-handlers-simplified-measures/),
> the small-handler regime published sixteen days earlier, because the pair is
> the story. Within one month CAC has proposed the ceiling and finalized the
> floor of the same statute. PIPL is becoming a tiered law, and the tier a
> company lands in now matters more than almost any individual obligation
> inside it.
>
> One reading note. This is a draft, and a consolidated one: thresholds and
> article numbers moved between the 2025 consultations and this text, and may
> move again. Nothing here is in force. The comment window closes 7 September.

## The two ends, one month apart

| | **Small handlers** — [Order No. 25](/laws/small-pi-handlers-simplified-measures/) | **Large handlers** — [this draft](/laws/large-pi-handlers-protection-provisions-draft/) |
|---|---|---|
| Status | Final. Effective 1 September 2026 | Draft for comment. Effective date left blank |
| Issued | CAC + MPS, 22 July 2026 | CAC, 7 August 2026 |
| PIPL hook | Article 62(2) — specialized rules for small handlers | Article 58 — large-platform obligations |
| Threshold | Fewer than 100,000 people | 10 million people **and** two qualitative conditions |
| How you enter | Automatically, by falling below the line | **By self-declaration and official designation**; CAC publishes the list |
| How you leave | Automatically | Apply for change of determination after 6 consecutive months below |
| Processing rules | Three-item minimum, satisfiable by posted notice | Seven-item itemized structured list, including a full SDK inventory |
| Consent | Inferred from voluntary provision of necessary information | Separate consent in five scenarios; guardian consent under 14 |
| Storage | No localization rule; six cross-border exemptions in Article 10 | **All PRC-collected and PRC-generated PI stored domestically** (Art. 13) |
| Infrastructure | — | Data center in China; **legal representative or actual controller must hold PRC nationality** (Art. 14) |
| Protection officer | — | **A member of management**, with a direct reporting line to the provincial CAC (Arts. 25–26) |
| Impact assessment | One-page form | Full assessment, **filed with the national CAC** within 15 working days (Art. 31) |
| Compliance audit | Once every five years; waived while certified | **At least every two years**, plus annual risk assessment, plus annual minors audit |
| Governance body | — | **Supervision committee**: ≥7 members, ≥2/3 external, external chair (Ch. 4) |
| Public reporting | — | **Annual personal information protection social responsibility report** |
| Penalty posture | Mandatory no-penalty and mitigated-penalty outcomes | Standard PIPL liability, plus dissolution of the committee, plus forced third-party hosting |

Read down that table and the design intent is plain. Order No. 25 asks whether
an obligation is worth its cost to a business with 40 employees. This draft asks
what a company should look like from the inside when the consequences of its
failure are national. The two instruments are not the same rule at different
volumes. They are different regulatory theories applied to different risk.

## The subject changed, and that is the headline

The predecessor drafts governed **大型网络平台** — large network platforms — and
tested for them the way platform regulation usually does: registered users and
monthly actives. The November 2025 draft reportedly drew the line at 50 million
registered users or 10 million monthly active users.

This draft governs **大型个人信息处理者**, large personal information *handlers*,
and Article 2 replaces the user metrics with three factors weighed together:

1. processing the personal information of **more than 10 million natural
   persons**;
2. providing **important network services** involving personal information
   processing, **or** having a business scope covering **multiple lines of
   business** that involve it;
3. personal information processing activities having a **significant impact on
   national security, economic operation, social stability, public health and
   safety**.

Two consequences follow, and neither is cosmetic.

**The perimeter is no longer platforms.** A national bank, an insurer, a
telecoms carrier, a hospital group, a connected-vehicle manufacturer, a payroll
processor — none of these is a network platform, and all of them can clear 10
million data subjects with a qualitative case for factors two and three. The
draft keeps its platform-specific duty in Article 29, governing in-platform
product and service providers, but that is now one article inside a regime that
no longer presumes a platform.

**The count is of people, not accounts.** Ten million *natural persons* whose
personal information is processed is a materially different measure from
registered users, and it does not net out dormant accounts, nor does it require
that those people be customers. Employees, applicants, patients, passengers and
the counterparties in someone else's transaction all count.

## Designation is declared, and that is the trap

This is the operational difference that most deserves attention during the
comment window, because it has no analogue in the small-handler regime.

You do not become a small handler by applying. You simply are one. Designation
as a large handler runs the other way. Under **Article 3**, a handler that
processes the personal information of more than 10 million people **and** that,
**on self-assessment**, considers itself to meet factors two and three, must
declare for determination to the national CAC through its provincial CAC. The
provincial body runs a 15-working-day completeness check; the national CAC,
with the telecoms authority and public security department, settles the list and
**announces it to society**.

Three features of that architecture are worth pausing on.

**The self-assessment is the company's.** Factors two and three are qualitative
and unquantified. "Important network services," "multiple lines of business,"
"significant impact on economic operation" — a company must form its own view
and act on it. Get it wrong in the permissive direction and Article 3's third
paragraph applies: authorities that consider you qualify but have not declared
"shall urge" you to. The draft does not say what follows persistent
non-declaration, which is one of the more obvious things to raise in comments.

**The list is public.** Designation is not a private status letter. It is an
announced membership, which makes it visible to counterparties, competitors,
plaintiffs and the press, and which makes the annual social responsibility
report under Article 30 a genuinely public document.

**Exit is slow and discretionary.** Six consecutive months below the conditions
merely entitles a handler to *apply* for a change of determination. Article 42
then permits — not requires — dissolution of the supervision committee once the
application is approved. A company that shrinks does not automatically shed the
regime.

For any group at or near 10 million data subjects in China, the practical
sequence starts now: run the Article 2 assessment, document the reasoning
whichever way it comes out, and decide whether to say anything in the comment
window about factors two and three. A company that later declares late will be
explaining a judgment it made today.

## The three obligations that change infrastructure, not paperwork

Most of Chapter II and Chapter III restates or tightens familiar PIPL duties.
Three provisions are different in kind, because complying with them requires
changing how the business is built rather than what it writes down.

**Article 13 — absolute domestic storage.** A large handler "shall store within
the territory personal information collected and generated in the course of
operations within the territory." There is no volume trigger, no importance
test, and no carve-out. PIPL Article 40 imposes localization on CIIOs and on
handlers above a CAC-set volume; this extends the same rule to every designated
large handler as a condition of designation. Article 20 still permits export
through the assessment, standard contract or certification routes — export and
localization coexist, as they always have — but the copy that stays in China is
now mandatory, and a global-first architecture with a China cache is not
compliant.

**Article 14 — nationality of the data center's controller.** The data center
storing that personal information must be established in China, must meet
national policy and standards, and its management organization's **legal
representative or actual controller must hold PRC nationality**. This is the
sharpest edge in the draft for foreign-invested business. It does not restrict
who may own the *handler*; it restricts who may control the *facility*. A
wholly foreign-owned enterprise designated as a large handler will need to
examine whether its captive China data center satisfies the test, and if not,
whether it moves to a domestic provider. Note also the drafting shift: the
November 2025 draft was reported to require the responsible personnel to be
Chinese nationals without foreign permanent residency. The test has moved from
personnel residency to the legal representative or actual controller's
nationality — narrower in one direction, broader in another, and worth
commenting on precisely because the phrase "actual controller" is undefined
here.

**Article 44 — hosting as a remedy.** Where a handler fails to rectify, CAC
together with the telecoms, public security and national security departments
"may require the large personal information handler to adopt measures such as
hosting personal information with a third-party data center." That is a
structural remedy, not a fine: it separates the data from the operator by
regulatory order. DCC is not aware of a precedent for it in the PIPL family,
and it belongs on any risk register that currently ends at monetary penalties.

## Governance: two independent lines that report outside the company

The draft builds an internal check with two limbs, and both can escalate past
the people they check.

**The protection officer is management, with an escape hatch.** Article 25
requires a *member of management* to serve as the person responsible for
personal information protection. Article 26(3) then gives that person the right,
where the company fails without justified reason to act on a compliance opinion
or handles it unlawfully, to **report directly to the provincial CAC**. Article
26(4) requires immediate reporting of major incidents to the provincial CAC and
other authorities, to public security where a crime is suspected, and to the
national security organ where national security may be affected. This sharpens a
role DCC has compared with the GDPR analogue before — see
[PIPO vs. DPO](/posts/pipo-vs-dpo-pi-protection-officer-comparison/) — and it
moves further from the European model, where the DPO's independence is a
protection against dismissal rather than a channel to the regulator.

**The supervision committee is not a board committee.** Chapter 4 requires a
committee within six months of designation: an odd number of members, at least
seven, **at least two-thirds external**, chaired by an external member who must
hold senior compliance-audit capability. External members are capped at three
concurrent engagements, need three years' relevant experience, must pass a
security background check for which the company may request police assistance,
and must satisfy detailed independence tests — no employment or close-relative
relationship, no holding above 1% of shares or top-ten natural-person
shareholder status, no employment with a 5%-plus shareholder or top-five
shareholder entity. Independence is self-examined annually, assessed by the
board, and **disclosed in the public social responsibility report**, as are
external members' allowances.

The annex makes the committee operational: three-year terms renewable once,
regular meetings at least every six months, interim meetings on the proposal of
one-third of members where there is evidence of unlawful processing, a quorum of
half, and resolutions requiring **two-thirds of all members** with dissents
recorded. Resolutions go to the board; the board must handle them and report
back; and where the board declines a compliance opinion without justified
reason, the committee itself may report to the provincial CAC.

Set against Order No. 25, where a handler under 100,000 people may discharge its
notice obligation with a posted sign, this is a different world. It is closest in
spirit to a statutory audit committee, staffed by outsiders the company must pay
but cannot control, with a reporting line the company cannot close.

## The middle band, defined by subtraction

The most useful thing many overseas counsel will take from this draft is where
their client is *not*.

Below 100,000 people: Order No. 25 applies, effective 1 September 2026, and
almost everything gets lighter. At or above 10 million people plus the
qualitative factors: this draft, if adopted. Between those lines — which is
where the large majority of foreign-invested Chinese subsidiaries sit — neither
specialized regime applies, and baseline PIPL governs unchanged.

That band is not a gap in the law; it is the law's default, now visible for the
first time because both edges have been drawn. It is worth telling clients
plainly, because the coverage of both instruments has tended to imply that
everyone is affected. Most companies are not. What changed for the middle is
that the ceiling and floor now exist, and movement toward either has
consequences that can be planned for rather than discovered.

Three groups should act during the comment window. Companies near 10 million
data subjects should run the Article 2 assessment and consider commenting on
factors two and three. Foreign-invested companies with captive China data
centers should test Article 14 against their actual corporate structure and
press on the undefined "actual controller." And anyone who would be designated
should price the supervision committee honestly — seven-plus members, two-thirds
external, paid allowances disclosed publicly, meeting at least twice a year — as
a standing governance cost rather than a compliance project.

Comments close **7 September 2026**.

---

**Source:** 《国家互联网信息办公室关于〈大型个人信息处理者个人信息保护规定（征求意见稿）〉公开征求意见的通知》,
网信中国 (CAC official channel), 7 August 2026 —
[original](https://mp.weixin.qq.com/s/BeNitCJ468LFRu6D0rE-7Q). DCC's full
translation of the 50 articles and the annex is
[here](/laws/large-pi-handlers-protection-provisions-draft/). The notice date,
comment deadline and consolidation of the two 2025 drafts were verified against
the Xinhua reproduction of the CAC notice; the September 2025 and November 2025
predecessor drafts and the reported user thresholds of the latter are drawn from
contemporaneous reporting of those consultations, not from this text.

— Not legal advice.
