On 7 August 2026 the Cyberspace Administration of China (CAC) published draft Provisions on Personal Information Protection for Large-Scale Personal Information Handlers. Consultation closed on 7 September. The 50-article draft covers any handler that processes the data of 10 million or more individuals, and it does something earlier localisation rules did not: it regulates who runs the building as well as where the data sits.
What the draft says
Article 13, as published on the CAC consultation page, requires large handlers to store personal information "collected and generated during operations" within the PRC. Article 14 then sets conditions for the data centres: they must be established in China, the legal representative of the managing institution must hold Chinese nationality, and they must comply with national policy standards. China Briefing's reading describes the test as covering the operator's legal representative or actual controller. Article 15 adds internal-control, emergency-response and incident-reporting duties for data-centre operators, and Article 16 requires written contracts with third-party facilities.
A Reed Smith summary adds two features. Regulators can direct a handler to move to a "qualifying third-party data centre" if rectification fails. Handlers must also set up a supervisory committee of at least seven members, with external members making up two-thirds. China Briefing reports that companies must submit data-centre and governance information within 30 working days of being designated.
The strongest case for the rules
Regulators have a serious argument. Firms holding the data of 10 million people are systemic: a breach or a misuse reaches a large share of the population. Domestic storage keeps data within reach of Chinese courts and enforcement. A nationality requirement for data-centre management is meant to ensure that someone answerable to Chinese law controls the facility. The draft also consolidates two earlier proposals, one on oversight committees and one on large platforms, into a single graded regime. That reduces fragmentation, and some of its governance duties, such as structured privacy notices and a 15-working-day cap on complaint handling, would help ordinary users.
Where the draft overreaches
The localisation duty itself is not new. Article 40 of the Personal Information Protection Law, effective 1 November 2021, already requires critical information infrastructure operators and handlers above a CAC-set volume to store domestically collected personal information in China. Cross-border transfers require a CAC-organised security assessment. The 2026 draft finally supplies that threshold, 10 million individuals, and then layers on three things the statute does not mention.
- A nationality test on management. Storing data in China addresses jurisdiction. Requiring that the people running the facility be Chinese nationals addresses something else, which is control and loyalty. It has no clear link to data security. Security failures come from weak engineering, poor access controls and unpatched systems, none of which depend on a passport.
- Open-ended state direction of storage. Letting regulators move a handler's data to a designated third-party centre after a failed rectification gives the CAC a lever over firm architecture with no stated standard for when it applies. A proportionate regime would specify the trigger, the process and a route to appeal.
- Broad designation criteria. China Daily's report says large platforms include those processing the data of over 10 million people or providing significant network services. The draft also reaches handlers whose processing has a significant effect on national security, economic operations or social stability. Those qualitative tests leave much of the designation to regulator judgement, which makes compliance planning difficult.
Who bears the cost
The burden does not fall evenly. A domestic platform with its own PRC facilities can absorb the new rules at modest cost. A multinational using regional cloud tenancy, shared analytics or a global engineering team faces redesign. A cloud provider whose operating entity is not Chinese-led may find that the draft effectively decides who can host. The likely result is less competition among hosting providers and weaker incentives for foreign firms to bring advanced security tooling into the market. Chinese users would then have fewer and more uniform options.
There is also an innovation cost. China is trying to build sovereign AI and cloud stacks, as Rest of World reported on 29 September. Yet the same reporting shows Beijing tolerates workarounds that keep its developers connected to global research. Rules that tighten control over infrastructure while relying on those workarounds for frontier research pull in opposite directions.
A narrower alternative
A proportionate design would keep the PIPL's logic. It would require local storage or local accountability for the largest handlers. It would set objective security standards for data centres and test compliance by audit, not by nationality. It would define in advance when a regulator can compel a change of host. It would also let handlers use verified controls, such as encryption with locally held keys, as a substitute where full physical localisation is not workable.
What to watch
The consultation has closed and the final text has not yet been published. Three things matter in it. First, whether "ultimate controller" is defined as it is in China Briefing's reading, or limited to the legal representative as in the CAC page. Second, whether the third-party storage power gets procedural limits. Third, whether the list of designated handlers is published or kept confidential. The answers will show whether localisation stays a security tool or becomes a general instrument of industrial policy.