China China Cybersecurity Law data localisation

China's Draft Large-Handler Rules Turn Data Localisation From a Narrow Duty Into a Nationality Test for Infrastructure

CAC's August 2026 draft would force 10M+ handlers to store data in PRC data centres run by PRC-national leaders, expanding localisation into a control test.

China's Large-Handler Draft at a Glance People of Internet Research · China 10M+ Handler threshold (individuals) Handlers processing this many peop… 50 Articles in the draft Consolidates earlier platform and … 7 Minimum supervisory committee size Two-thirds of members must be exte… 30 Days to file data-centre details Working days after designation as … peopleofinternet.com
China's Large-Handler Draft at a Glanc… People of Internet Research · China 10M+ Handler threshold (individuals) 50 Articles in the draft 7 Minimum supervisory comm… 30 Days to file data-centre deta… peopleofinternet.com

Key Takeaways

On 7 August 2026 the Cyberspace Administration of China (CAC) published draft Provisions on Personal Information Protection for Large-Scale Personal Information Handlers. Consultation closed on 7 September. The 50-article draft covers any handler that processes the data of 10 million or more individuals, and it does something earlier localisation rules did not: it regulates who runs the building as well as where the data sits.

What the draft says

Article 13, as published on the CAC consultation page, requires large handlers to store personal information "collected and generated during operations" within the PRC. Article 14 then sets conditions for the data centres: they must be established in China, the legal representative of the managing institution must hold Chinese nationality, and they must comply with national policy standards. China Briefing's reading describes the test as covering the operator's legal representative or actual controller. Article 15 adds internal-control, emergency-response and incident-reporting duties for data-centre operators, and Article 16 requires written contracts with third-party facilities.

A Reed Smith summary adds two features. Regulators can direct a handler to move to a "qualifying third-party data centre" if rectification fails. Handlers must also set up a supervisory committee of at least seven members, with external members making up two-thirds. China Briefing reports that companies must submit data-centre and governance information within 30 working days of being designated.

The strongest case for the rules

Regulators have a serious argument. Firms holding the data of 10 million people are systemic: a breach or a misuse reaches a large share of the population. Domestic storage keeps data within reach of Chinese courts and enforcement. A nationality requirement for data-centre management is meant to ensure that someone answerable to Chinese law controls the facility. The draft also consolidates two earlier proposals, one on oversight committees and one on large platforms, into a single graded regime. That reduces fragmentation, and some of its governance duties, such as structured privacy notices and a 15-working-day cap on complaint handling, would help ordinary users.

Where the draft overreaches

The localisation duty itself is not new. Article 40 of the Personal Information Protection Law, effective 1 November 2021, already requires critical information infrastructure operators and handlers above a CAC-set volume to store domestically collected personal information in China. Cross-border transfers require a CAC-organised security assessment. The 2026 draft finally supplies that threshold, 10 million individuals, and then layers on three things the statute does not mention.

Who bears the cost

The burden does not fall evenly. A domestic platform with its own PRC facilities can absorb the new rules at modest cost. A multinational using regional cloud tenancy, shared analytics or a global engineering team faces redesign. A cloud provider whose operating entity is not Chinese-led may find that the draft effectively decides who can host. The likely result is less competition among hosting providers and weaker incentives for foreign firms to bring advanced security tooling into the market. Chinese users would then have fewer and more uniform options.

There is also an innovation cost. China is trying to build sovereign AI and cloud stacks, as Rest of World reported on 29 September. Yet the same reporting shows Beijing tolerates workarounds that keep its developers connected to global research. Rules that tighten control over infrastructure while relying on those workarounds for frontier research pull in opposite directions.

A narrower alternative

A proportionate design would keep the PIPL's logic. It would require local storage or local accountability for the largest handlers. It would set objective security standards for data centres and test compliance by audit, not by nationality. It would define in advance when a regulator can compel a change of host. It would also let handlers use verified controls, such as encryption with locally held keys, as a substitute where full physical localisation is not workable.

What to watch

The consultation has closed and the final text has not yet been published. Three things matter in it. First, whether "ultimate controller" is defined as it is in China Briefing's reading, or limited to the legal representative as in the CAC page. Second, whether the third-party storage power gets procedural limits. Third, whether the list of designated handlers is published or kept confidential. The answers will show whether localisation stays a security tool or becomes a general instrument of industrial policy.

Sources & Citations

  1. CAC consultation notice and draft Provisions (Aug 2026)
  2. Personal Information Protection Law (CAC text, Art. 40)
  3. Reed Smith: enhanced rules for large-scale handlers
  4. China Briefing: large-scale PI processors draft rules
  5. China Daily: draft regulation on personal data
  6. Rest of World: China's open-source AI platforms