Filed under cverc
Every brief tagged "cverc".
- § 01 · ENFORCEMENT
CVERC Names 82 Apps for PI Violations, and 28 From Its August Batch Are Now Off the Stores
On 23 September 2026 the National Computer Virus Emergency Response Center (国家计算机病毒应急处理中心, CVERC) named 82 mobile apps whose collection and use of personal information failed its testing, carried out between 29 July and 4 September under the 2026 CAC + MIIT + MPS joint special campaign. The notice is published as text, and DCC translates it in full: twelve violation categories, 118 findings, and every app, consolidated into one table. Three things set it apart from the MIIT and CAC notices in DCC's tracker. First, a published retest loop: of the 75 apps CVERC named in August, 28 still failed on retest and have been taken down by the distribution platforms. Second, the taxonomy has moved past the 2019 Identification Method into PIPL's statutory text. Five categories track PIPL Articles 23, 24, 30, 31 and 51 almost word for word: separate consent for sharing with another handler, an opt-out from automated-decision push, notice of why sensitive personal information is needed, dedicated rules for children under 14, and security measures. Third, the perimeter: 29 mini-programs on WeChat, Baidu and Alipay, three WeChat service accounts, two TV apps, a standalone ad SDK, and twelve builds downloaded from third-party download sites. Eight hospital channels are named, among them United Family Healthcare's mini-program, and hospitals account for four of the eleven findings of sharing personal information without separate consent.