Skip to content
DCC · DATA COMPLIANCE CHINA China data law, for overseas counsel.
§ 088 · PERSONAL-INFORMATION

China Writes PIPL a Small-Business Exit Ramp: The Simplified Measures for Small Personal Information Handlers

On 22 July 2026 the CAC and the Ministry of Public Security jointly issued Order No. 25, the Provisions on Simplified Personal Information Protection Measures for Small Personal Information Handlers, effective 1 September 2026. It is the first instrument to make PIPL's obligations formally proportionate: a handler processing the personal information of fewer than 100,000 people gets a three-item processing-rules template it can satisfy with a posted notice, notice discharged through those published rules alone, consent inferred from voluntary provision of necessary information, compliance audit cut to once every five years — or waived entirely if certified — and a one-page impact assessment. Article 8 lets a handler operating solely through a network platform drop its own rules, notice, audit and assessment altogether, riding on the platform's. Article 10 extends the cross-border exemption architecture to small handlers, with important data carved out. Articles 18 and 19 make no-penalty and mitigated-penalty outcomes mandatory rather than discretionary. DCC reads it for overseas counsel whose Chinese counterparties, franchisees, merchants and portfolio companies sit under the 100,000-person line — and explains why the threshold, not the relief, is the thing to watch.

Editor’s Note — DCC.

On 22 July 2026 the Cyberspace Administration of China and the Ministry of Public Security jointly published Order No. 25, the Provisions on Simplified Personal Information Protection Measures for Small Personal Information Handlers, adopted at the CAC’s 14th office meeting of 2026 on 26 June and effective 1 September 2026. DCC has translated the full 22-article text; this brief is our reading of it.

The instrument answers a mandate that has been outstanding since 2021. PIPL Article 62 told the CAC to write dedicated personal information protection rules and standards for small handlers. Until now only the standards half existed, in draft — the TC260 Guide for Personal Information Protection by Small Personal Information Processors, whose own Introduction says it was written to implement these then-forthcoming Provisions. The rules half has now landed, and the pair are meant to be read together.

— Not legal advice.

What it does

PIPL has always applied the same obligations to a neighborhood supermarket and to a national platform. Order No. 25 is the first instrument to make those obligations formally proportionate — and it does so not by carving small handlers out of PIPL, but by specifying a cheaper way to satisfy each duty.

A small personal information handler is one processing the personal information of fewer than 100,000 people (Article 2). For that population:

  • Processing rules need contain only three things (Article 4): the handler’s name; the department or person who receives rights requests, with contact details; and the purpose, method, categories, and retention period. Offline handlers may publish them by posting a notice at the premises; online handlers by service agreement, client pop-up, or website notice.
  • Notice is discharged by publishing those rules alone (Article 6), where the processing is necessary to the product or service, excludes sensitive personal information, and nothing is provided onward or publicly disclosed.
  • Consent follows from conduct (Article 7): once rules are published and notice given, an individual who — fully informed — voluntarily and actively provides the personal information necessary to obtain the product or service has consented. Sensitive personal information still requires separate consent, and the necessity and rights-impact must be stated in the rules.
  • Compliance audit drops to once every five years, on an annexed self-check table, retained five years (Article 13).
  • Impact assessment becomes an annexed one-page form, retained three years (Article 14).
  • Management systems may live as a section inside existing organizational documents rather than as standalone policies (Article 15).
  • Breach notification may be given by posted notice or client pop-up where individual notification is genuinely impossible (Article 16).

Two carve-outs survive intact: handlers processing the personal information of minors under 14 must still write dedicated rules (Article 4), and the minors compliance-audit regime prevails where it says otherwise (Article 13).

The three provisions that actually matter

Most of the above is welcome cost relief. Three articles do something more structural.

Article 8 — the platform absorbs the obligation

A small handler that operates solely through a network platform, and provides personal information to no one outside it, need not formulate processing rules or give notice at all — provided the platform has published rules covering the handler’s processing, has agreed rights and obligations with it, and the handler declares compliance and stays within the stated purposes, methods and categories. Where the platform has run its own compliance audit and impact assessment covering that activity, the small handler need not repeat either.

This is the most consequential provision in the instrument. It converts a diffuse population of millions of merchants into a compliance problem the platform owns, and it gives the platform a supervisory role it must now discharge: if the platform changes its rules, it must promptly notify the affected small handlers. Step outside the platform’s stated scope — a different purpose, an extra data category, provision to an off-platform recipient — and the full set of obligations snaps back.

For overseas counsel, the practical read is that diligence on a Chinese merchant’s PI compliance increasingly means diligence on its platform’s published rules, audit and assessment.

Article 10 — the cross-border exemptions reach the small end

Article 10 gives small handlers the same six-condition escape from the Data Export Security Assessment, the Standard Contract and certification that the Cross-Border Data Flows Provisions established generally: contract necessity (cross-border shopping, delivery, remittance, payment, account opening, ticketing, visas, examinations), HR management under lawful labor rules, emergencies, statutory duties, the cumulative sub-100,000-person volume route for non-CIIOs, and a residual catch-all.

Three limits deserve emphasis, because they are where the exemption stops:

  1. Important data is excluded outright from the exemption.
  2. Notice and separate consent still apply. The exemption removes the mechanism (assessment / SCC / certification), not the underlying PIPL consent architecture.
  3. Where an assessment is still required, the provincial CAC may now form a proposed conclusion for national-level approval — a procedural decentralization that should shorten the path.

Articles 18–19 — penalty relief becomes mandatory

Article 18 provides that no penalty shall be imposed where the violation is minor, timely corrected and harmless; where there is sufficient evidence of no subjective fault; or in other statutory no-penalty circumstances. A first-time violation with minor consequences, timely corrected, may escape penalty. Where no penalty is imposed, the regulator must still act — by regulatory interview (约谈) or reminder letter (提示函).

Article 19 makes a lighter or mitigated penalty mandatory across five circumstances, including voluntary confession of conduct the regulator did not yet know about, and prompt individual notification plus remediation plus voluntary reporting after an incident.

These are drafted as “shall,” not “may.” That is a meaningful shift from regulatory discretion toward an entitlement — and it builds an explicit incentive to self-report.

The threshold is the thing to watch

The relief is real, but it is switched entirely by one number, and the number repays close reading. The CAC’s accompanying Q&A is explicit about the counting method: fewer than 100,000 people counts the natural persons whose personal information the handler currently processes, accumulated across its activities, excluding personal information already deleted — and 100,000 itself is outside the range (不包含10万人本数).

Three consequences follow that overseas counsel should price in:

  • It is a headcount, not a record count or a volume. One person with a thousand transactions is one person.
  • Deletion is load-bearing. Because deleted personal information drops out of the count, retention discipline directly determines whether an organization stays inside the regime. A handler near the line has a concrete reason to delete on schedule.
  • There is no stated transition on crossing it. Nothing in the Provisions gives a grace period to a handler that grows past 100,000 people. It moves back to undiluted PIPL — full processing rules, full notice and consent, the general audit cadence, standalone impact assessments, and the ordinary cross-border machinery. A fast-growing Chinese subsidiary or portfolio company can therefore lose this entire regime in the middle of a financial year, and the compliance build-out has to be ready before it does.

What this signals

Read against the Network Data Security Regulations and the audit measures, Order No. 25 shows a regulator that has finished building the heavy machinery and is now tuning it for the bottom of the market. The policy framing in the Q&A is explicit — supporting micro, small and medium-sized enterprises — and the instrument matches the framing: it cuts process cost while leaving the substantive floor (security, minors, sensitive personal information, important data, and liability under Article 21) untouched.

For overseas counsel the practical takeaways are narrow but real. Chinese counterparties below the line are now cheaper to bring into compliance, and their documentation will look thinner by design — a posted notice and a five-yearly self-check table is now a compliant posture, not a red flag. Where a counterparty sits on a platform, the platform’s rules are the operative document. And the one number that governs all of it — 100,000 people, currently processed, deletions excluded — is worth writing into the reps rather than assuming.

— Not legal advice.

— Not legal advice.


§ SUBSCRIBE

The Monday brief.

One short email every Monday. New briefs on Chinese data-compliance rules from the previous week, with the source law cited.

Opt-in only. Unsubscribe anytime by replying "unsubscribe" to any issue.

SUPPORT DCC

Keep the publication free to read. Suggested support is $19.99, or choose your own amount.

Support →