China's National Cybersecurity Information Notification Center published a notice on July 9, 2026 naming 72 mobile apps and mini-programs found to have violated personal-information rules — among them HSBC's mobile banking app, China Minsheng Bank's corporate account app, Ping An Securities, and Great Wall Securities. The findings came from scans run by the National Computer Virus Emergency Response Center between May 20 and June 22, 2026, and cite the Cybersecurity Law, the Personal Information Protection Law (PIPL), the Network Data Security Management Regulations, and the CAC's own methodology for identifying unlawful app data collection, according to the notice as republished on the Jiangsu government portal.
What the apps actually did wrong
The violations sort into a familiar taxonomy. Twenty-four apps failed to display privacy policies prominently at launch or relied on pre-checked default consent instead of an affirmative opt-in. Thirty-seven apps disclosed that they collected data but not the specific purpose, method, or scope of what they or their third-party partners gathered. Fourteen apps — including the flagged financial apps — shared personal data with third parties without separate, specific consent, a core PIPL requirement under Articles 13 and 23. Seventeen lacked adequate encryption or de-identification safeguards. Three collected data from children under 14 without verifiable parental consent. And one app used facial recognition as the sole means of identity verification, with no fallback option — a direct violation of the CAC and Ministry of Public Security's Security Management Measures for the Application of Facial Recognition Technology, which took effect June 1, 2025 and require that users always have a non-biometric alternative.
HSBC's app (version 3.68.13) was cited for undisclosed third-party data sharing. Minsheng Bank's corporate account app drew violations across multiple categories. Ping An Securities was flagged for inadequate privacy-policy disclosure, and Great Wall Securities for lacking a functioning consent-withdrawal mechanism. This is not a one-off sweep: the notice is the latest installment of a campaign the CAC, the Ministry of Industry and Information Technology, and the Ministry of Public Security jointly announced on April 2, 2026, which set seven priority sectors for 2026 — apps and SDKs, internet advertising, education, transport, healthcare, finance, and criminal enforcement.
The case for taking this seriously
The strongest argument for this kind of enforcement is straightforward: consent bundling and mandatory facial recognition are not abstract harms. When a banking app defaults users into third-party data sharing, or refuses service unless a customer submits to face scanning, the user has no real choice — and biometric data, unlike a password, cannot be reset once compromised. China's facial-recognition rule requiring a non-biometric fallback is, on its face, a reasonable, narrowly-targeted response to a real risk, and it tracks similar debates in the EU and US about biometric consent. Regulators naming specific apps by version number, rather than issuing vague guidance, also gives companies an unusually concrete compliance roadmap — arguably more useful than a large fine handed down after the fact.
Where the model still falls short
That said, the mechanism here is worth distinguishing from China's headline PIPL enforcement. This is not a Didi-style penalty — the ride-hailing company was fined CNY 8.026 billion (about $1.2 billion) in July 2022 for improperly processing more than 64 billion pieces of personal data, the largest data-protection fine issued by any regulator globally at the time. The July 9 action instead relies on public naming and app-store delisting, a comparatively proportionate tool: it corrects behavior through market pressure and platform removal rather than existential monetary penalties, and companies retain a path to relist once compliant.
But the notice itself undercuts confidence in that lighter approach. Twenty-eight apps previously flagged in an earlier notice were found still noncompliant on retest and delisted outright — meaning roughly a third of past violators didn't fix the problem the first time regulators asked. That's a real signal that naming-and-shaming alone isn't generating durable compliance, at least not on the timeline regulators expect. For multinational firms like HSBC, the deeper problem is compliance complexity: operating under PIPL's third-party-consent and minimization rules simultaneously with GDPR, Hong Kong's PDPO, and other regimes multiplies the ways an app can fall out of step with any one regulator's evolving methodology — especially when China is running seven overlapping enforcement campaigns in a single year.
The proportionality test
PIPL enforcement that trades blunt fines for specific, correctable findings — bad consent flows, missing fallback authentication, undisclosed third-party sharing — is the more defensible model of the two, and multinational firms operating in China should treat these notices as genuine compliance signals rather than political theater. The test going forward is whether Beijing follows through: if a third of named apps keep reappearing on these lists, sunlight alone isn't enough, and the CAC will face pressure to escalate toward the fines it has shown, with Didi, it is fully willing to use.