China China Personal Information Protection Law PIPL

China's Draft Rules for Large Data Processors Fold Privacy Protection Into State Oversight of Platform Governance

The CAC's consolidated draft for processors with 10 million+ users' data uses PIPL's gatekeeper clause to mandate localisation, oversight committees and ID-based minor checks.

China's Large-Processor Draft at a Glance People of Internet Research · China 10M+ Individuals' data threshold One designation consideration for … 7 Minimum committee members Odd-numbered committee, with at le… 30 days Registration filing deadline Working days after designation to … peopleofinternet.com
China's Large-Processor Draft at a Gla… People of Internet Research · China 10M+ Individuals' data threshold 7 Minimum committee members 30 days Registration filing deadline peopleofinternet.com

Key Takeaways

On August 7, 2026, the Cyberspace Administration of China (CAC) opened a public consultation on a draft regulation on personal information protection by large-scale personal information processors. Comments closed on September 7. The notice says the text merges two drafts that were already out for comment: one on oversight committees for large network platforms and one on personal information protection by large network platforms. It sits under the Personal Information Protection Law (PIPL) and the Network Data Security Management Regulations.

The strongest case for the draft

The case for regulating the biggest processors harder is real. PIPL Article 58 already requires processors that provide important platform services, with a large number of users and complex business types, to set up an independent body, composed mainly of outside members, to supervise their personal information handling. It also requires them to publish platform rules and social responsibility reports (PIPL Article 58 text). A statute that says "independent body" without saying who qualifies, or how large is large, invites uneven compliance. Detailed rules fix that.

The scale argument also holds up. A breach or misuse at a firm holding data on tens of millions of people harms far more people than one at a start-up. A tiered system that spares small firms and puts the heaviest duties on the largest is a defensible design. Many regulators work this way, including the EU's gatekeeper approach.

What the draft actually does

The CAC text, as published, contains several notable provisions:

Law-firm analyses agree on the headline points: a 10-million-person threshold, an oversight committee of at least seven, and in-China storage, plus registration through provincial cyberspace departments.

Where the design goes wrong

The problem is not that China wants stronger privacy duties for large firms. The problem is what those duties are built from. An independent committee that is actually independent is a real accountability tool. Here, its members are vetted under rules the regulator writes, and the same regulator decides which firms are designated, when designation ends, and who sits on the list. The oversight body reports to the company, but the regulator frames its remit. That is closer to a compliance channel for the CAC than an independent check on it.

Localisation and nationality tests on data-centre controllers do little for privacy. A breach is no less likely in a domestic facility, and the draft's own cross-border article already regulates transfers. What localisation does is raise the cost of running one global architecture. Foreign and Chinese multinationals alike would need separate stacks, which is hard on smaller entrants that rely on shared cloud infrastructure. The result is less competition and fewer privacy-protective engineering choices, not more.

The age-verification mechanism carries a speech cost. Tying minor identification to national identity authentication services means that proving who you are becomes a condition of using large services. Child safety is a legitimate goal, and under-14 consent is common worldwide. But identity-linked access narrows room for anonymous speech, and it concentrates sensitive identity data with the state's verification infrastructure, which is the opposite of data minimisation.

A fairer test for any large-processor regime

Governments elsewhere should not feel superior here. Several democracies are drafting platform rules with vague designation criteria and age-verification mandates of their own. The useful question is whether a rule can be checked by someone outside the regulator.

By that standard, the draft's weak points are specific. Designation is discretionary, with no published numeric floor. Oversight members are vetted by the body that designates. Penalties point back to existing laws, including criminal liability, rather than to graduated, reviewable sanctions. A proportionate version would publish clear designation criteria, give committees real appeal and disclosure rights, and replace blanket localisation with risk-based transfer controls.

What to watch

The draft leaves its effective date blank, so the final text and timetable are still open. Watch three things: whether the CAC turns "comprehensively consider" into numeric criteria, whether the final version keeps the Chinese-national data-centre requirement, and whether the identity-authentication duty for minors is narrowed. For firms operating in China, the practical advice is to map where personal data is stored and who controls the facilities now, before designation arrives.

Sources & Citations

  1. CAC: Draft Regulations on Large Personal Information Handlers (Aug 7, 2026)
  2. PIPL Article 58 text
  3. Reed Smith: China proposes enhanced data protection rules for large-scale handlers
  4. China Briefing: Large-Scale PI Processors draft rules explained