Filed under separate-consent
Every brief tagged "separate-consent".
- § 01 · ENFORCEMENT
CVERC Names 82 Apps for PI Violations, and 28 From Its August Batch Are Now Off the Stores
On 23 September 2026 the National Computer Virus Emergency Response Center (国家计算机病毒应急处理中心, CVERC) named 82 mobile apps whose collection and use of personal information failed its testing, carried out between 29 July and 4 September under the 2026 CAC + MIIT + MPS joint special campaign. The notice is published as text, and DCC translates it in full: twelve violation categories, 118 findings, and every app, consolidated into one table. Three things set it apart from the MIIT and CAC notices in DCC's tracker. First, a published retest loop: of the 75 apps CVERC named in August, 28 still failed on retest and have been taken down by the distribution platforms. Second, the taxonomy has moved past the 2019 Identification Method into PIPL's statutory text. Five categories track PIPL Articles 23, 24, 30, 31 and 51 almost word for word: separate consent for sharing with another handler, an opt-out from automated-decision push, notice of why sensitive personal information is needed, dedicated rules for children under 14, and security measures. Third, the perimeter: 29 mini-programs on WeChat, Baidu and Alipay, three WeChat service accounts, two TV apps, a standalone ad SDK, and twelve builds downloaded from third-party download sites. Eight hospital channels are named, among them United Family Healthcare's mini-program, and hospitals account for four of the eleven findings of sharing personal information without separate consent.
- § 02 · GBT-35273
From Consent to Governance: What the 2026 Draft Revision of GB/T 35273 Changes Against the 2020 Standard
On June 17, 2026 the National Cybersecurity Standardization Technical Committee (TC260), with CESI as drafting lead, released for public comment a systematic revision of GB/T 35273 — China's most-cited personal-information standard, the de-facto 'small PIPL.' The draft retitles the standard from 'Information Security Technology' to 'Data Security Technology' and expands its normative references from one standard to eight. DCC reads the revision as a role change, not a clause count: the standard moves from a consent-and-notice manual into a governance-capability framework. The substantive increments against GB/T 35273-2020: a new Chapter 5 importing PIPL Article 13's seven lawful bases as a standalone chapter with hard boundaries on each (contract-necessity, HR, public-disclosure) plus an evidence-chain duty; a sensitive-PI redefinition aligned to PIPL Article 28 with a new aggregation rule (multiple items that together meet the threshold are treated as sensitive as a whole); a formal 'separate consent' definition (3.7) with a negative list; a new eighth basic principle, 'quality assurance' (Chapter 4(f)); dedicated AI clauses on the collection side (6.7), in minimum-necessity (6.1 d–f), in aggregation/training (8.4), and a new generative-AI use clause (8.5.4) with output review and a 15-working-day deletion SLA; a unified-account-system clause (8.6) aimed at one-account-many-products groups; a terminal/IoT collection clause (6.8); a wholly new Chapter 11 on overseas-jurisdiction determination and conflict handling; and a systematized internal-control chapter (13) covering the person in charge of personal information protection, working body, processing-activity records, impact assessment, and a GB/T 46903-anchored compliance audit. Subject-rights response time tightens from 30 days to 15 working days. Clause numbers are from the comment draft and are not final; formal release is expected after 2027.
- § 03 · ENFORCEMENT
Ctrip's ¥10 Million Fine: China's First Publicly Disclosed Cross-Border Data Penalty — and the 'Necessity' Doctrine Behind Four Cases
In June 2026 Shanghai's cyberspace authority fined Shanghai Ctrip Commerce ¥10 million for unlawfully exporting personal information without implementing data-export security-assessment requirements — the first time a Chinese cross-border data penalty amount has been made public. DCC reads the fine against the three earlier Shanghai / MPS cross-border cases compiled by HexCode in 数据何规 (a hotel company that exported fields the CAC assessment had rejected, a property company that exported accommodation and financial-account data with no approval at all, and the Dior breach case) to surface the doctrine all four share: building a CRM or central-reservation system offshore does not make the bulk transfer of customer PI to headquarters 'necessary,' so it cannot escape the security-assessment / standard-contract / certification gate or PIPL's separate-consent and individual-notification requirements. The enforcement gradient — the assessment-rejected exporter was fined while the no-approval exporter was only warned — signals that subjective culpability is weighing on penalty severity.