China China Personal Information Protection Law PIPL

China's Naming-and-Shaming of HSBC and 72 Other Apps Shows PIPL Enforcement Shifting From Fines to Sunlight

Beijing named HSBC, Ping An Securities and 70 other apps for PIPL violations on July 9, 2026 — a lighter-touch tool than the $1.2B Didi fine, but recidivism raises doubts.

China's July 2026 App Privacy Sweep People of Internet Research · China 72 Apps named in notice Identified across app stores and W… 33 days Detection window length Scans ran May 20 to June 22, 2026 … 28 apps Repeat violators delisted Previously-flagged apps still nonc… 7 2026 campaign focus sectors CAC, MIIT and MPS set apps, ads, e… peopleofinternet.com
China's July 2026 App Privacy Sweep People of Internet Research · China 72 Apps named in notice 33 days Detection window length 28 apps Repeat violators delisted 7 2026 campaign focus sectors peopleofinternet.com

Key Takeaways

China's National Cybersecurity Information Notification Center published a notice on July 9, 2026 naming 72 mobile apps and mini-programs found to have violated personal-information rules — among them HSBC's mobile banking app, China Minsheng Bank's corporate account app, Ping An Securities, and Great Wall Securities. The findings came from scans run by the National Computer Virus Emergency Response Center between May 20 and June 22, 2026, and cite the Cybersecurity Law, the Personal Information Protection Law (PIPL), the Network Data Security Management Regulations, and the CAC's own methodology for identifying unlawful app data collection, according to the notice as republished on the Jiangsu government portal.

What the apps actually did wrong

The violations sort into a familiar taxonomy. Twenty-four apps failed to display privacy policies prominently at launch or relied on pre-checked default consent instead of an affirmative opt-in. Thirty-seven apps disclosed that they collected data but not the specific purpose, method, or scope of what they or their third-party partners gathered. Fourteen apps — including the flagged financial apps — shared personal data with third parties without separate, specific consent, a core PIPL requirement under Articles 13 and 23. Seventeen lacked adequate encryption or de-identification safeguards. Three collected data from children under 14 without verifiable parental consent. And one app used facial recognition as the sole means of identity verification, with no fallback option — a direct violation of the CAC and Ministry of Public Security's Security Management Measures for the Application of Facial Recognition Technology, which took effect June 1, 2025 and require that users always have a non-biometric alternative.

HSBC's app (version 3.68.13) was cited for undisclosed third-party data sharing. Minsheng Bank's corporate account app drew violations across multiple categories. Ping An Securities was flagged for inadequate privacy-policy disclosure, and Great Wall Securities for lacking a functioning consent-withdrawal mechanism. This is not a one-off sweep: the notice is the latest installment of a campaign the CAC, the Ministry of Industry and Information Technology, and the Ministry of Public Security jointly announced on April 2, 2026, which set seven priority sectors for 2026 — apps and SDKs, internet advertising, education, transport, healthcare, finance, and criminal enforcement.

The case for taking this seriously

The strongest argument for this kind of enforcement is straightforward: consent bundling and mandatory facial recognition are not abstract harms. When a banking app defaults users into third-party data sharing, or refuses service unless a customer submits to face scanning, the user has no real choice — and biometric data, unlike a password, cannot be reset once compromised. China's facial-recognition rule requiring a non-biometric fallback is, on its face, a reasonable, narrowly-targeted response to a real risk, and it tracks similar debates in the EU and US about biometric consent. Regulators naming specific apps by version number, rather than issuing vague guidance, also gives companies an unusually concrete compliance roadmap — arguably more useful than a large fine handed down after the fact.

Where the model still falls short

That said, the mechanism here is worth distinguishing from China's headline PIPL enforcement. This is not a Didi-style penalty — the ride-hailing company was fined CNY 8.026 billion (about $1.2 billion) in July 2022 for improperly processing more than 64 billion pieces of personal data, the largest data-protection fine issued by any regulator globally at the time. The July 9 action instead relies on public naming and app-store delisting, a comparatively proportionate tool: it corrects behavior through market pressure and platform removal rather than existential monetary penalties, and companies retain a path to relist once compliant.

But the notice itself undercuts confidence in that lighter approach. Twenty-eight apps previously flagged in an earlier notice were found still noncompliant on retest and delisted outright — meaning roughly a third of past violators didn't fix the problem the first time regulators asked. That's a real signal that naming-and-shaming alone isn't generating durable compliance, at least not on the timeline regulators expect. For multinational firms like HSBC, the deeper problem is compliance complexity: operating under PIPL's third-party-consent and minimization rules simultaneously with GDPR, Hong Kong's PDPO, and other regimes multiplies the ways an app can fall out of step with any one regulator's evolving methodology — especially when China is running seven overlapping enforcement campaigns in a single year.

The proportionality test

PIPL enforcement that trades blunt fines for specific, correctable findings — bad consent flows, missing fallback authentication, undisclosed third-party sharing — is the more defensible model of the two, and multinational firms operating in China should treat these notices as genuine compliance signals rather than political theater. The test going forward is whether Beijing follows through: if a third of named apps keep reappearing on these lists, sunlight alone isn't enough, and the CAC will face pressure to escalate toward the fines it has shown, with Didi, it is fully willing to use.

Sources & Citations

  1. CAC/MIIT/MPS 2026 Campaign Announcement
  2. Jiangsu Gov't Portal — July 9 Notice on 72 Apps
  3. China News Service — 72 Apps Notice
  4. IT Home — 72 Apps Violation Report
  5. Mayer Brown — Didi $1.2B Fine Analysis