China’s Simplified Personal Information Protection Measures for Small-Scale Processors comes into effect
China’s Simplified Personal Information Protection Measures for Small-Scale Processors comes into effect
September 02, 2026
Asia
Asia
Asia
The Provisions on Simplified Measures for Personal Information Protection by Small-Scale Personal Information Processors (《小型个人信息处理者个人信息保护简化措施规定》) (the “Simplified Measures”), jointly issued by the Cyberspace Administration of China (“CAC”) and the Ministry of Public Security on 22 July 2026, is now in force (effective from 1 September 2026).
The Simplified Measures establish a dedicated simplified regime for organisations with smaller operational scale in China (such as small and medium-sized enterprises and micro-enterprises) to comply with personal information (“PI”) protection requirements, aimed at reducing compliance costs and complexity for those organisations while maintaining essential PI protection standards under the Personal Information Protection Law (the “PIPL”).
As at the date of this briefing, the CAC is also conducting a public consultation on the Provisions on Personal Information Protection by Large-Scale Personal Information Processors (Consultation Draft) (《大型个人信息处理者个人信息保护规定(征求意见稿)》), which proposes personal information protection requirements applicable to processors processing PI of 10 million individuals or more, providing important network services and having significant impact on national security, economy, social stability, public health and safety. Viewed holistically, China’s data protection regime appears to be moving towards a more risk-based framework, rather than applying unified compliance expectations to all personal information processors.
The key provisions and streamlined PI protection compliance measures under the Simplified Measures are summarised below.
Key Provisions
Topic
Key Requirements
Who does it apply to?
The Simplified Measures apply to “small-scale personal information processors” (“Small-scale Processors”), which is defined as PI processors that handles PI of less than 100,000 individuals, based on the current, cumulative number of individuals whose PI is being processed (excluding PI that was already deleted).
The threshold of 100,000 individuals is regardless of the business size and revenue volume of the PI processor. The Simplified Measures also do not explicitly set out the assessment method where a group’s aggregate PI processing exceeds the threshold but that of each member company remains below the threshold.
The Simplified Measures apply to implementation of PI protection by Small-scale Processors located within the territory of the PRC.
Processing Rules (Privacy Policy / Notice)
A Small-scale Processor’s PI processing rules (i.e. privacy policies / notices) are subject to fewer content requirements , and shall include: (i) the Small Processor’s name; (ii) the department / person responsible for handling individuals’ rights requests, and the relevant contact information; and (iii) the purpose, method, categories, and retention period of PI processed. Unlike Article 17, PIPL, the procedures and methods for individuals to exercise their rights do not need to be included as part of the content requirements for Small-scale Processors.
Small-scale Processors collecting PI offline may disclose their PI processing rules by way of posting a notice at a prominent location at its business premises; while those collecting PI online may do so via service agreements, pop-ups, or website notices.
Separate PI processing rules shall be formulated for processing PI of minors (under 14).
Notification
A Small-scale Processor may satisfy notification obligations by publicly disclosing its PI processing rules presented in a prominent manner if: (a) the PI processing (excluding sensitive PI) is necessary for providing the product/service; and (b) the PI will not be provided to other PI processors nor disclosed publicly (and this is expressly stated in the PI processing rules).
Small-scale Processors operating through online platforms are exempt from creating their own PI processing rules and fulfilling notice obligations if they declare compliance with the platform’s PI processing rules, process PI solely via the online platform, and do not provide PI to other PI processors.
Consent
Small-scale Processors may process PI without consent if (i) they process the PI in accordance with the PI processing rules disclosed and fulfil notification obligations as mentioned above, and (ii) the individuals, being fully informed, voluntarily provide (or cooperates in providing) PI necessary for obtaining the product / service.
However, where sensitive PI is processed for specific purposes, the Small-scale Processor must specify the necessity and impact on individual rights in its PI processing rules and obtain separate consent.
Cross-Border Data Transfer (“CBDT”)
The Simplified Measures do not appear to offer material relaxations to the existing CBDT requirements under the Provisions on Facilitating and Regulating Cross-border Data Flow, apart from a consolidated assessment process for security assessments from the local CAC level.
Compliance Audit & PIA
Compliance audits may be performed once every five years with a simplified “Small-Scale PI Processor Compliance Audit Self-Check Form” (except for compliance audits on processing minors’ PI).
PI protection impact assessments (PIAs) may also be conducted using a simplified assessment form.
Breach Notification
Upon occurrence or likely occurrence of PI leakage, tampering, or loss, Small-scale Processors may notify individuals by on-site notices in a prominent location at business premises, pop-up notices, or website announcements if notification by other means pursuant to the PIPL and relevant regulations are not possible due to objective constraints.
Penalty Relief
Small-scale Processors benefit from a more lenient penalty regime and enforcement approach under the Simplified Measures.
Penalty is waived for breaches which are minor, promptly corrected and caused no harmful consequences; or where there is sufficient evidence for absence of fault by the Small-scale Processor. That said, where penalties are waived, regulatory authorities may still adopt regulatory measures such as interviews or reminder letters to ensure Small-scale Processors’ compliance.
A lighter or mitigated penalty will be imposed if the Small-scale Processor has:
voluntarily eliminated or mitigated the harmful consequences of the breach;
voluntarily disclosed breaches not yet known to the regulator;
promptly notified individuals and took remedial measures, and voluntarily notified the relevant departments; or
cooperated with the regulator in investigating and handling breaches and demonstrated merit.
What’s Next?
With the Simplified Measures now in effect, organisations with operations in China should review their PI processing activities and consider whether they qualify as Small-scale Processors and could benefit from the streamlined compliance steps under the Simplified Measures. That said, some of the relaxations (e.g. around consent and notification requirements) are not applicable to processing of sensitive data and minors’ data.
In practical terms, the Simplified Measures create a significant compliance incentive for multinational corporations operating in China, especially B2B-focused businesses with limited direct individual-facing data processing. Key practical steps for multinationals with operations or entities in China include:
Taking active steps to confirm eligibility under the Simplified Measures and ongoingly monitoring processing volumes against the threshold of 100,000 individuals;
Reviewing and streamlining privacy notices, notification mechanisms and consent flows where the Simplified Measures permit;
Reviewing data categories, including checking whether sensitive PI, minors’ PI or transfers to other PI processors are involved, as these may continue to trigger enhanced notice, separate consent or other PIPL requirements; and
Maintaining an audit calendar and supporting records, notwithstanding the longer five-year audit cycle available to Small-scale Processors.
The materials on the Eversheds Sutherland website are for general information purposes only and do not constitute legal advice. While reasonable care is taken to ensure accuracy, the materials may not reflect the most current legal developments. Eversheds Sutherland disclaims liability for actions taken based on the materials. Always consult a qualified lawyer for specific legal matters. To view the full disclaimer, see our Terms and Conditions or Disclaimer section in the footer. Eversheds Sutherland is a provider of legal and other services operating through various separate and distinct legal entities. For further information about these entities and Eversheds Sutherlands' structure please see the Legal Notice page of this website.