July 2026

Interpretation of the Draft Provisions on Simplified Compliance Measures for Small-Scale Personal Information Processors (Exposure Draft) (Mainland China)

On 3 April 2026, the Cyberspace Administration of China issued the Draft Provisions on Simplified Measures for Personal Information Protection by Small-Scale Personal Information Processors (Exposure Draft) (hereinafter the “Draft Provisions”).  The Draft Provisions are implementing rules authorized by Article 62 of the Personal Information Protection Law of the People’s Republic of China (PIPL), marking a shift in China’s personal information protection regulation from a “one-size-fits-all” approach to a more refined governance framework based on processing scale.  Key provisions are interpreted as follows:

I. Clarification of Scope of Application

Article 2 of the Draft Provisions specifies that the simplified rules set out in the Draft Provisions apply to “personal information processors that process the personal information of fewer than 100,000 individuals.”  It is important to note that the criterion is not the number of employees or registered capital, but the actual number of individuals whose information has been processed.

II. Substantial Simplification of Notification and Consent Obligations

Path One: Publication in lieu of notification (Article 6): For non-sensitive personal information that is necessary for providing a product or service, and where the processor does not provide the information to other processors or publicly disclose it, the processor may fulfil its notification obligation merely by making the processing rules publicly available.

Path Two: Deemed consent by conduct (Article 7): When an individual proactively provides personal information necessary for obtaining a product or service, and the processor has already published its processing rules and fulfilled its notification obligation, the processor may process the information in accordance with those rules.

Path Three: Unified platform compliance (Article 8): Where a small-scale personal information processor handles personal information solely through an online platform, does not provide information outside the platform, and the platform has already established and published personal information processing rules and fulfilled notification obligations, the small-scale processor needs not separately formulate rules or provide duplicate notices.  In addition, where the platform has already conducted personal information protection compliance audits and impact assessments, the small-scale processor needs not conduct them again independently.

III. Sensitive Personal Information Processing: Simplified but with Risk Boundaries

Article 10 of the Draft Provisions provides that a small-scale personal information processor may, in its processing rules, give a one time notification of the necessity and impact of processing sensitive personal information.  If an individual, having been informed, proactively provides sensitive information such as facial data, the small-scale processor may process it in the manner and for the purposes already notified.

IV. Impact Assessment and Compliance Audit: Simplified but Not Waived

Articles 15 to 19 of the Draft Provisions clarify that the obligations to conduct a protection impact assessment and a compliance audit are not waived, but the procedures are significantly simplified.  Small-Scale processors must still carry out a personal information protection impact assessment under Article 55 of the PIPL, but may do so using the simplified Small-Scale Personal Information Processor Personal Information Protection Impact Assessment Form attached to the Draft Provisions.  The impact assessment form must be kept for at least three years.  Where the purpose or method of processing changes substantially, a new assessment is required.  The frequency of compliance audits is relaxed to at least once every five years, and small-scale processors may use the simplified Small-Scale Personal Information Processor Personal Information Protection Compliance Audit Self Check Form attached to the Draft Provisions.  In addition, obtaining personal information protection certification exempts the processor from an audit for the validity period of the certification.

V. Cross Border Data Transfers

Article 11 of the Draft Provisions substantially reduces compliance burdens for small-scale processors engaging in cross-border data transfers by exempting certain scenarios from mandatory procedures such as outbound security assessments, standard contracts, and personal information protection certifications.
The provision specifies that processors handling the personal information of fewer than 100,000 individuals (excluding sensitive personal information) may directly transfer personal information overseas without undergoing ordinary outbound data transfer approval procedures under the following circumstances:

A. Performance of cross-border contracts (e.g., shopping, delivery, payment, visa processing);

B. Cross-border human resources management;

C. Emergency avoidance;

D. Fulfillment of statutory duties or obligations; or

E. Annual outbound transfers involving fewer than 100,000 individuals and excluding sensitive personal information.

Although the Draft Provisions have not yet taken formal effect, relevant enterprises are advised to take note of these simplified rules.  It should be understood that simplified procedures do not constitute a complete waiver of statutory personal information protection obligations.  Enterprises are also advised to keep complete compliance records throughout their operations, to firmly uphold the legal baseline for personal information protection, and to guard against risks of administrative penalties and civil liability for compensation.

The contents of all newsletters of Shanghai Lee, Tsai & Partners (Content) available on the webpage belong to and remain with Shanghai Lee, Tsai & Partners. All rights are reserved by Shanghai Lee, Tsai & Partners, and the Content may not be reproduced, downloaded, disseminated, published, or transferred in any form or by any means, except with the prior permission of Shanghai Lee, Tsai & Partners.

The Content is for informational purposes only and is not offered as legal or professional advice on any particular issue or case. The Content may not reflect the most current legal and regulatory developments. Shanghai Lee, Tsai & Partners and the editors do not guarantee the accuracy of the Content and expressly disclaim any and all liability to any person in respect of the consequences of anything done or permitted to be done or omitted to be done wholly or partly in reliance upon the whole or any part of the Content. The contributing authors' opinions do not represent the position of Shanghai Lee, Tsai & Partners. If the reader has any suggestions or questions, please do not hesitate to contact Shanghai Lee, Tsai & Partners.