On August 7, 2026, the Cyberspace Administration of China (CAC) opened a public consultation on a draft regulation on personal information protection by large-scale personal information processors. Comments closed on September 7. The notice says the text merges two drafts that were already out for comment: one on oversight committees for large network platforms and one on personal information protection by large network platforms. It sits under the Personal Information Protection Law (PIPL) and the Network Data Security Management Regulations.
The strongest case for the draft
The case for regulating the biggest processors harder is real. PIPL Article 58 already requires processors that provide important platform services, with a large number of users and complex business types, to set up an independent body, composed mainly of outside members, to supervise their personal information handling. It also requires them to publish platform rules and social responsibility reports (PIPL Article 58 text). A statute that says "independent body" without saying who qualifies, or how large is large, invites uneven compliance. Detailed rules fix that.
The scale argument also holds up. A breach or misuse at a firm holding data on tens of millions of people harms far more people than one at a start-up. A tiered system that spares small firms and puts the heaviest duties on the largest is a defensible design. Many regulators work this way, including the EU's gatekeeper approach.
What the draft actually does
The CAC text, as published, contains several notable provisions:
- Designation (Article 2). Regulators weigh three considerations together: processing the personal information of 10 million or more people; providing important network services involving personal information, or running multiple businesses that process it; and having a significant effect on national security, economic operations, social stability, or public health and safety. The wording is "comprehensively consider", not a bright-line test. Secondary summaries describe the thresholds differently, so the final text matters.
- Localisation (Article 13). Personal information collected and generated during operations in China must be stored within China.
- Data centres (Articles 14–16). Centres must be in China, have a Chinese-national legal representative or controller, and meet national standards. Handlers can outsource to third-party operators only under written contracts specifying purpose, duration, storage location and protections.
- Oversight committees (Article 37). Committees need an odd number of members, at least seven, with at least two-thirds external members and an external chair. External members are screened for independence and cannot hold more than 1% of the handler's shares.
- Minors (Articles 11, 32). Processing data of under-14s needs guardian consent, and handlers must use national identity authentication services to identify minors.
- Cross-border transfers (Article 20). Offshore transfers still need a CAC security assessment, standard contract, or certification. The draft adds a duty to assess the recipient's ability to comply and to suspend transfers if it cannot.
- Registration (Article 36). Within 30 working days of designation, handlers file their protection officer's details, safeguards, and data-centre arrangements with municipal authorities.
Law-firm analyses agree on the headline points: a 10-million-person threshold, an oversight committee of at least seven, and in-China storage, plus registration through provincial cyberspace departments.
Where the design goes wrong
The problem is not that China wants stronger privacy duties for large firms. The problem is what those duties are built from. An independent committee that is actually independent is a real accountability tool. Here, its members are vetted under rules the regulator writes, and the same regulator decides which firms are designated, when designation ends, and who sits on the list. The oversight body reports to the company, but the regulator frames its remit. That is closer to a compliance channel for the CAC than an independent check on it.
Localisation and nationality tests on data-centre controllers do little for privacy. A breach is no less likely in a domestic facility, and the draft's own cross-border article already regulates transfers. What localisation does is raise the cost of running one global architecture. Foreign and Chinese multinationals alike would need separate stacks, which is hard on smaller entrants that rely on shared cloud infrastructure. The result is less competition and fewer privacy-protective engineering choices, not more.
The age-verification mechanism carries a speech cost. Tying minor identification to national identity authentication services means that proving who you are becomes a condition of using large services. Child safety is a legitimate goal, and under-14 consent is common worldwide. But identity-linked access narrows room for anonymous speech, and it concentrates sensitive identity data with the state's verification infrastructure, which is the opposite of data minimisation.
A fairer test for any large-processor regime
Governments elsewhere should not feel superior here. Several democracies are drafting platform rules with vague designation criteria and age-verification mandates of their own. The useful question is whether a rule can be checked by someone outside the regulator.
By that standard, the draft's weak points are specific. Designation is discretionary, with no published numeric floor. Oversight members are vetted by the body that designates. Penalties point back to existing laws, including criminal liability, rather than to graduated, reviewable sanctions. A proportionate version would publish clear designation criteria, give committees real appeal and disclosure rights, and replace blanket localisation with risk-based transfer controls.
What to watch
The draft leaves its effective date blank, so the final text and timetable are still open. Watch three things: whether the CAC turns "comprehensively consider" into numeric criteria, whether the final version keeps the Chinese-national data-centre requirement, and whether the identity-authentication duty for minors is narrowed. For firms operating in China, the practical advice is to map where personal data is stored and who controls the facilities now, before designation arrives.