China China Personal Information Protection Law PIPL

China's New Compliance Regime for Big Data Handlers Formalizes What Article 58 Left Vague

CAC's draft rules turn a five-year-old PIPL platform clause into a detailed registration, audit, and localization regime for any firm processing 10 million+ people's data.

China's Large Processor Threshold, By the Numbers People of Internet Research · China 10M+ Users triggers designation Threshold for 'large-scale persona… 7 members Minimum oversight committee size More than two-thirds must be exter… 6 months Deadline to form committee Time allowed after designation to … Every 2 years Mandatory compliance audit Plus an annual risk assessment, di… peopleofinternet.com
China's Large Processor Threshold, By … People of Internet Research · China 10M+ Users triggers designation 7 members Minimum oversight committee size 6 months Deadline to form committee Every 2 years Mandatory compliance audit peopleofinternet.com

Key Takeaways

A five-year-old clause finally gets teeth

On August 7, 2026, the Cyberspace Administration of China (CAC) opened public comment on the Regulations on Personal Information Protection for Large-Scale Personal Information Processors (Draft for Comments), with the window closing September 7, 2026. The draft is not a new law — it's the long-delayed implementing detail for Article 58 of the Personal Information Protection Law (PIPL), passed in 2021, which told "major" processors to build compliance systems and stand up an externally-staffed oversight body but left the thresholds, structure, and enforcement mechanics for later. Five years later, "later" has arrived, and it consolidates two earlier drafts — one on oversight committees, one on large-platform obligations — into a single regime, per CAC's official notice.

What the draft actually requires

A firm is designated a "large-scale personal information processor" if it processes data on more than 10 million individuals, provides an "important" network service involving personal data, or its processing activities could materially affect national security, economic operations, or public health. Once designated, a company has 30 working days to report its data-center and chief privacy officer (CPO) information to the CAC, and six months to stand up a supervisory committee of at least seven members — more than two-thirds external, chaired by an external member with compliance-audit expertise. The CPO must hold a management-level post, publish contact information, sit in on risk decisions, and report security incidents directly to regulators. Personal information must be stored inside China in data centers whose controlling parties are Chinese nationals. Firms must run a compliance audit every two years and an annual risk assessment, disclosing findings publicly "where feasible." China Briefing's breakdown of the draft is a useful plain-English map of these provisions for compliance teams outside China.

The case for it

The steelman here is real. Article 58 has sat unenforced for five years because nobody knew what "large-scale" meant or what an "independent" committee had to look like — ambiguity that let the biggest platforms treat the obligation as aspirational. A numeric threshold (10 million users) and a structural floor (seven members, two-thirds external) replace guesswork with an auditable standard, which is generally what regulated industries say they want. And unlike a blanket rule applied to every data controller, this one is explicitly tiered: the CAC published simplified rules for small-scale processors in parallel, so a regional e-commerce app isn't carrying the same compliance load as a national super-app. Proportionate-to-scale regulation is the right instinct, and China deserves credit for building the tiering into the rule rather than bolting it on after complaints.

Where it overshoots

The problem is what "independent oversight" means when the CAC also runs a mandatory registration system and requires incident reports to flow to the same regulator. An oversight committee is supposed to check management on behalf of users; here it also functions as a compliance conduit to the state, with external members subject to background vetting before they can serve. That's a materially different institution than an independent privacy board in the EU's GDPR sense — it's oversight for the regulator as much as of the company. MLex's coverage of the draft notes it dedicates "a substantial number of clauses" simply restating existing PIPL, Cybersecurity Law, and Data Security Law obligations — which suggests the real function of this draft is less new protection than a formal enumeration mechanism: a public list of which companies now sit under heightened state visibility into their data architecture, their CPO's identity, and their data-center ownership.

The localization clause is the tell

The requirement that data-center controllers be Chinese nationals goes further than data residency — a common, defensible requirement globally, including under GDPR's own transfer restrictions. It reaches into ownership and control of the infrastructure, not just the geography of storage. For foreign multinationals operating above the 10-million-user threshold in China, that's a real localization cost layered on top of biennial audits and a public-facing CPO, not merely a paperwork exercise. Combined with a 15-day CAC review window for registration applications, the practical effect is that any company processing data at meaningful scale in China now operates under continuous, structured regulatory line-of-sight — which may be exactly the point, five years after Article 58 was written to allow it but never enforced.

What to watch

The comment period runs through September 7, 2026. The two open questions are enforcement teeth — the draft doesn't yet specify penalties for missing the six-month committee deadline — and whether foreign cloud and AI firms above the threshold get a distinct compliance track or are folded into the same regime as domestic platforms.

Sources & Citations

  1. CAC official notice on draft rules (Aug 7, 2026)
  2. PIPL full text, Article 58 (CAC mirror)
  3. China Briefing: Large-Scale PI Processors draft explained
  4. MLex: China proposes rules for large personal-data handlers
  5. CAC: draft simplified PI rules for small-scale processors (public consultation)