Skip to content
DCC · DATA COMPLIANCE CHINA China data law, for overseas counsel.
§ TAG · APP-TAKEDOWN

Filed under app-takedown

Every brief tagged "app-takedown".

  • § 01 · ENFORCEMENT

    CVERC Names 82 Apps for PI Violations, and 28 From Its August Batch Are Now Off the Stores

    On 23 September 2026 the National Computer Virus Emergency Response Center (国家计算机病毒应急处理中心, CVERC) named 82 mobile apps whose collection and use of personal information failed its testing, carried out between 29 July and 4 September under the 2026 CAC + MIIT + MPS joint special campaign. The notice is published as text, and DCC translates it in full: twelve violation categories, 118 findings, and every app, consolidated into one table. Three things set it apart from the MIIT and CAC notices in DCC's tracker. First, a published retest loop: of the 75 apps CVERC named in August, 28 still failed on retest and have been taken down by the distribution platforms. Second, the taxonomy has moved past the 2019 Identification Method into PIPL's statutory text. Five categories track PIPL Articles 23, 24, 30, 31 and 51 almost word for word: separate consent for sharing with another handler, an opt-out from automated-decision push, notice of why sensitive personal information is needed, dedicated rules for children under 14, and security measures. Third, the perimeter: 29 mini-programs on WeChat, Baidu and Alipay, three WeChat service accounts, two TV apps, a standalone ad SDK, and twelve builds downloaded from third-party download sites. Eight hospital channels are named, among them United Family Healthcare's mini-program, and hospitals account for four of the eleven findings of sharing personal information without separate consent.

    enforcement · cverc · app-compliance
  • § 02 · ENFORCEMENT

    From Naming to Takedown: Shanghai Pulls 46 Apps That Missed the Rectification Window

    On June 24, 2026 the Shanghai Communications Administration (上海市通信管理局, the MIIT's directly-administered local communications authority) issued a notification ordering the takedown of 46 apps and SDKs that, after public naming and a rectification window, still had not fixed user-rights and personal-information violations. DCC reads it as the next rung on the enforcement ladder above the CAC's 30-app naming notification: same 2026 CAC + MIIT + MPS special campaign, but the local communications-administration tier converting an unrectified naming into an operative sanction — removal from distribution, with further measures flagged (suspension of access, administrative penalty, inclusion in the telecom-business bad-record list). The legal basis is PIPL, the Cybersecurity Law, the Telecom Regulations, and the Telecom and Internet User PI Protection Provisions. The 46-app list — transcribed here from the notice's attached image — is almost entirely Shanghai-registered long-tail O2O lifestyle apps (moving, housekeeping and cleaning, pet services, local travel agencies, community group-buy food, fitness and restaurants), and several operators appear with multiple apps taken down at once. DCC's read for overseas counsel: the provincial communications administrations are where a missed rectification window becomes a removed app, and the takedown tier sweeps the small-operator long tail, not just big nationals.

    enforcement · app-compliance · miit
§ SUBSCRIBE

The Monday brief.

One short email every Monday. New briefs on Chinese data-compliance rules from the previous week, with the source law cited.

Opt-in only. Unsubscribe anytime by replying "unsubscribe" to any issue.

SUPPORT DCC

Keep the publication free to read. Suggested support is $19.99, or choose your own amount.

Support →