---
title: "China Writes PIPL a Small-Business Exit Ramp: The Simplified Measures for Small Personal Information Handlers"
author: "DCC Editorial"
published: 2026-07-24T11:00:00.000Z
url: https://datacompliancechina.com/posts/small-pi-handlers-simplified-measures/
description: "On 22 July 2026 the CAC and the Ministry of Public Security jointly issued Order No. 25, the Provisions on Simplified Personal Information Protection Measures for Small Personal Information Handlers, effective 1 September 2026. It is the first instrument to make PIPL's obligations formally proportionate: a handler processing the personal information of fewer than 100,000 people gets a three-item processing-rules template it can satisfy with a posted notice, notice discharged through those published rules alone, consent inferred from voluntary provision of necessary information, compliance audit cut to once every five years — or waived entirely if certified — and a one-page impact assessment. Article 8 lets a handler operating solely through a network platform drop its own rules, notice, audit and assessment altogether, riding on the platform's. Article 10 extends the cross-border exemption architecture to small handlers, with important data carved out. Articles 18 and 19 make no-penalty and mitigated-penalty outcomes mandatory rather than discretionary. DCC reads it for overseas counsel whose Chinese counterparties, franchisees, merchants and portfolio companies sit under the 100,000-person line — and explains why the threshold, not the relief, is the thing to watch."
tags: ["personal-information", "pipl", "small-business", "compliance-audit", "cross-border-data", "platform-responsibility", "cac", "sme"]
laws_cited: ["small-pi-handlers-simplified-measures", "pipl", "small-pi-processor-protection-guide-draft", "network-data-security-regulations", "cross-border-data-flows-provisions", "personal-info-audit-measures"]
domains: ["personal-information", "cross-border"]
account: "data-he-gui"
original_title: "《小型处理者个保简化措施规定》发布"
original_author: "国家互联网信息办公室、公安部"
original_publication: "网信中国 (Cyberspace Administration of China official channel), reposted via 数据何规 WeChat Official Account"
original_url: "https://mp.weixin.qq.com/s/xBIuQYJZUcDsB9hupz2w6g"
source_language: "zh"
---

> **Source: Data Compliance China** — https://datacompliancechina.com/posts/small-pi-handlers-simplified-measures/ · China data law, translated and annotated for overseas counsel. Cite as: Data Compliance China, "China Writes PIPL a Small-Business Exit Ramp: The Simplified Measures for Small Personal Information Handlers", https://datacompliancechina.com/posts/small-pi-handlers-simplified-measures/
> *Editor's Note — DCC.*
>
> On **22 July 2026** the Cyberspace Administration of China and the Ministry
> of Public Security jointly published
> [Order No. 25, the *Provisions on Simplified Personal Information Protection
> Measures for Small Personal Information Handlers*](/laws/small-pi-handlers-simplified-measures/),
> adopted at the CAC's 14th office meeting of 2026 on 26 June and effective
> **1 September 2026**. DCC has translated the full 22-article text; this brief
> is our reading of it.
>
> The instrument answers a mandate that has been outstanding since 2021.
> **PIPL Article 62** told the CAC to write *dedicated personal information
> protection rules and standards* for small handlers. Until now only the
> standards half existed, in draft — the TC260
> [Guide for Personal Information Protection by Small Personal Information
> Processors](/laws/small-pi-processor-protection-guide-draft/), whose own
> Introduction says it was written to implement these then-forthcoming
> Provisions. The rules half has now landed, and the pair are meant to be read
> together.
>
> **— Not legal advice.**

## What it does

PIPL has always applied the same obligations to a neighborhood supermarket and
to a national platform. Order No. 25 is the first instrument to make those
obligations formally **proportionate** — and it does so not by carving small
handlers out of PIPL, but by specifying a cheaper way to satisfy each duty.

A **small personal information handler** is one processing the personal
information of **fewer than 100,000 people** (Article 2). For that population:

- **Processing rules** need contain only three things (Article 4): the
  handler's name; the department or person who receives rights requests, with
  contact details; and the purpose, method, categories, and retention period.
  Offline handlers may publish them by **posting a notice at the premises**;
  online handlers by service agreement, client pop-up, or website notice.
- **Notice** is discharged by publishing those rules alone (Article 6), where
  the processing is necessary to the product or service, excludes sensitive
  personal information, and nothing is provided onward or publicly disclosed.
- **Consent** follows from conduct (Article 7): once rules are published and
  notice given, an individual who — fully informed — voluntarily and actively
  provides the personal information necessary to obtain the product or service
  has consented. Sensitive personal information still requires **separate
  consent**, and the necessity and rights-impact must be stated in the rules.
- **Compliance audit** drops to **once every five years**, on an annexed
  self-check table, retained five years (Article 13).
- **Impact assessment** becomes an annexed one-page form, retained three years
  (Article 14).
- **Management systems** may live as a section inside existing organizational
  documents rather than as standalone policies (Article 15).
- **Breach notification** may be given by posted notice or client pop-up where
  individual notification is genuinely impossible (Article 16).

Two carve-outs survive intact: handlers processing the personal information of
**minors under 14** must still write dedicated rules (Article 4), and the
minors compliance-audit regime prevails where it says otherwise (Article 13).

## The three provisions that actually matter

Most of the above is welcome cost relief. Three articles do something more
structural.

### Article 8 — the platform absorbs the obligation

A small handler that operates **solely through a network platform**, and
provides personal information to no one outside it, need not formulate
processing rules or give notice at all — provided the platform has published
rules covering the handler's processing, has agreed rights and obligations with
it, and the handler declares compliance and stays within the stated purposes,
methods and categories. Where the platform has run its own compliance audit and
impact assessment covering that activity, **the small handler need not repeat
either**.

This is the most consequential provision in the instrument. It converts a
diffuse population of millions of merchants into a compliance problem the
platform owns, and it gives the platform a supervisory role it must now
discharge: if the platform changes its rules, it must **promptly notify** the
affected small handlers. Step outside the platform's stated scope — a different
purpose, an extra data category, provision to an off-platform recipient — and
the full set of obligations snaps back.

For overseas counsel, the practical read is that diligence on a Chinese
merchant's PI compliance increasingly means diligence on **its platform's**
published rules, audit and assessment.

### Article 10 — the cross-border exemptions reach the small end

Article 10 gives small handlers the same six-condition escape from the
[Data Export Security Assessment](/laws/data-export-security-assessment-measures/),
the Standard Contract and
[certification](/laws/cross-border-pi-certification-measures/) that the
[Cross-Border Data Flows Provisions](/laws/cross-border-data-flows-provisions/)
established generally: contract necessity (cross-border shopping, delivery,
remittance, payment, account opening, ticketing, visas, examinations), HR
management under lawful labor rules, emergencies, statutory duties, the
cumulative sub-100,000-person volume route for non-CIIOs, and a residual
catch-all.

Three limits deserve emphasis, because they are where the exemption stops:

1. **Important data is excluded** outright from the exemption.
2. **Notice and separate consent still apply.** The exemption removes the
   *mechanism* (assessment / SCC / certification), not the underlying PIPL
   consent architecture.
3. Where an assessment *is* still required, the **provincial** CAC may now form
   a proposed conclusion for national-level approval — a procedural
   decentralization that should shorten the path.

### Articles 18–19 — penalty relief becomes mandatory

Article 18 provides that **no penalty shall be imposed** where the violation is
minor, timely corrected and harmless; where there is sufficient evidence of no
subjective fault; or in other statutory no-penalty circumstances. A first-time
violation with minor consequences, timely corrected, **may** escape penalty.
Where no penalty is imposed, the regulator must still act — by **regulatory
interview** (约谈) or **reminder letter** (提示函).

Article 19 makes a **lighter or mitigated penalty** mandatory across five
circumstances, including voluntary confession of conduct the regulator did not
yet know about, and prompt individual notification plus remediation plus
voluntary reporting after an incident.

These are drafted as "shall," not "may." That is a meaningful shift from
regulatory discretion toward an entitlement — and it builds an explicit
incentive to self-report.

## The threshold is the thing to watch

The relief is real, but it is switched entirely by one number, and the number
repays close reading. The CAC's accompanying Q&A is explicit about the counting
method: **fewer than 100,000 people** counts the natural persons whose personal
information the handler *currently* processes, accumulated across its
activities, **excluding personal information already deleted** — and 100,000
itself is *outside* the range (不包含10万人本数).

Three consequences follow that overseas counsel should price in:

- **It is a headcount, not a record count or a volume.** One person with a
  thousand transactions is one person.
- **Deletion is load-bearing.** Because deleted personal information drops out
  of the count, retention discipline directly determines whether an
  organization stays inside the regime. A handler near the line has a concrete
  reason to delete on schedule.
- **There is no stated transition on crossing it.** Nothing in the Provisions
  gives a grace period to a handler that grows past 100,000 people. It moves
  back to undiluted PIPL — full processing rules, full notice and consent,
  the general audit cadence, standalone impact assessments, and the ordinary
  cross-border machinery. A fast-growing Chinese subsidiary or portfolio
  company can therefore lose this entire regime in the middle of a financial
  year, and the compliance build-out has to be ready before it does.

## What this signals

Read against the [Network Data Security Regulations](/laws/network-data-security-regulations/)
and the audit measures, Order No. 25 shows a regulator that has finished
building the heavy machinery and is now tuning it for the bottom of the market.
The policy framing in the Q&A is explicit — supporting micro, small and
medium-sized enterprises — and the instrument matches the framing: it cuts
process cost while leaving the substantive floor (security, minors, sensitive
personal information, important data, and liability under Article 21) untouched.

For overseas counsel the practical takeaways are narrow but real. Chinese
counterparties below the line are now cheaper to bring into compliance, and
their documentation will look thinner **by design** — a posted notice and a
five-yearly self-check table is now a compliant posture, not a red flag. Where
a counterparty sits on a platform, the platform's rules are the operative
document. And the one number that governs all of it — 100,000 people, currently
processed, deletions excluded — is worth writing into the reps rather than
assuming.

**— Not legal advice.**
