Regulator unveils draft regulation to strengthen handling of personal information
By Cao Yin | chinadaily.com.cn | Updated: 2026-08-07 19:04
China's top internet regulator unveiled a draft regulation on Friday aimed at governing how large platforms handle personal information, seeking public input on the proposal.
The draft, comprising 50 articles, is available on the Cyberspace Administration of China's official website, with the consultation period open until Sept 7. The authority has also provided its office address and email, inviting feedback from all sectors of society.
The administration highlighted that the regulation is designed to standardize personal data processing activities by large platforms, safeguard individuals' legitimate rights and interests, and encourage the lawful and reasonable use of personal information.
Under the draft, large platforms are defined as those capable of processing the personal information of over 10 million individuals, offering significant network services involving personal data, or having a business scope that covers multiple areas of personal information processing. Platforms whose activities significantly impact national security, economic operations, social stability, and public health and safety are also included. These entities must register with the national level through their provincial cyberspace departments.
The draft clarifies that foreign organizations or individuals involved in activities infringing on the personal information rights of Chinese citizens or threatening China's national security and public interests may be placed on a list that restricts or prohibits the provision of personal information. The administration may announce this list and enforce measures to limit or ban the provision of personal information to these entities.
Large-scale personal information processors are required to adhere to the principles of lawfulness, legitimacy, necessity, and good faith. They must store personal data collected and generated within China on domestic servers. User consent is mandatory, and for users under 14, consent must be obtained from their parents or legal guardians.
The draft also mandates that data centers for large-scale personal information handlers be located within China, with the person in charge — a legal representative or actual controller — being a Chinese citizen. If a third-party data center operator is hired, a written contract must outline the purpose, term, methods, storage location, volume, categories, security measures, and the rights and obligations of both parties.
For transferring personal data abroad, processors must comply with China's laws and rules by applying for a security assessment, signing a standard contract for cross-border data transfers, or obtaining certification for personal information protection. They must enhance technical and management safeguards for outbound data security and address any risks or threats from illegal cross-border data flows promptly.
Additionally, the draft encourages large-scale information processors to establish and refine internal rules, including those on data category management, risk monitoring, emergency response, child protection, and complaint reporting.
It also urges these processors to set up a supervisory committee primarily composed of external members. The committee must have an odd number of at least seven members, with external representatives making up no less than two-thirds. Its main responsibilities include overseeing the platform's personal information protection framework, safeguards for sensitive data and minors' information, incident prevention and response, and compliance with cross-border data transfer rules.





















