China's Cyberspace Administration (CAC) and Ministry of Public Security issued the Provisions on Simplified Personal Information Protection Measures for Small-Scale Personal Information Handlers on July 22, 2026 (Order No. 25). They took effect on September 1, according to the CAC's published text. The 22-article text lowers compliance costs for handlers processing personal information of fewer than 100,000 individuals. It leaves the localisation and cross-border architecture of the Cybersecurity Law, Data Security Law and PIPL where it was.
The case for strict rules on everyone
The strongest argument against a small-handler carve-out is that harm does not scale with headcount. A neighbourhood clinic app or a merchant's customer list can leak health or payment data just as damagingly as a large platform's. A regime that thins out obligations by size could create a soft underbelly of weakly protected data. Regulators also worry about fragmentation: one large firm can split itself into many small handlers.
The Provisions answer much of this. The threshold is defined by the number of individuals whose data is processed, not by revenue or headcount. According to Reed Smith's analysis, group companies must be assessed individually to see whether each entity qualifies on its own. The CAC's own release says the simplified measures apply only where handlers otherwise comply with personal information protection laws, regulations and national requirements.
What actually gets lighter
The relief is procedural. Under the CAC text, offline handlers can post notices in a conspicuous place instead of issuing individual notices. Online handlers can fold the required notice into service agreements, app pop-ups or website notices. Platform merchants can rely on the platform's policy if the platform is registered and compliant.
Compliance audits move to a floor of at least once every five years, using a simplified self-assessment checklist. Reed Smith contrasts this with the standard two-year cycle for larger entities. Records must be kept for five years or more. Reed Smith also reports that penalties may be waived for minor, promptly corrected violations that cause no harmful consequences, for first offences with limited harm, or where the handler shows it was not at fault. Regulators can still use interviews and reminder letters.
This is proportionate regulation. A five-person business running a loyalty programme should not need a full-scale audit apparatus built for a national platform. Paperwork burdens are regressive: they weigh most heavily on the firms least able to hire compliance counsel.
Cross-border: a streamlined path, not an exit
The cross-border provisions matter most for localisation. Article 10 lets small handlers skip the CAC security assessment, standard contract and certification routes in specified cases. Those cases include cross-border shopping, delivery and remittance needed to perform a contract, lawful employee transfers under labour rules, emergency protection of life or property, statutory duties, and cumulative provision of non-sensitive information on fewer than 100,000 people in a year.
The carve-out excludes important data, which stays subject to existing restrictions. Sensitive personal information still requires individual consent under Article 7. Article 4 requires specialised handling of information on children under 14.
For handlers that do need a CAC security assessment, Article 10 (paragraph 4) lets them ask their provincial cyberspace office to run an initial review and forward its conclusions to the national authority. This adds local guidance and completeness checking without changing who decides. The national assessment stays in place. Per Arnold & Porter, the general assessment triggers remain the transfer abroad within a year of personal information on more than one million individuals, or sensitive information on more than 10,000.
What this means for the localisation debate
Critics of China's data regime often treat it as monolithic: everything must stay onshore, and every exception is a loophole. The Provisions show a more differentiated design. Restrictions concentrate on categories where the state's stated interest is strongest: important data, sensitive information, minors' data and large-volume exports. Lower-risk, low-volume, contract-driven flows get easier treatment.
That is closer to how a proportionate regime should work, though it should not be overstated. The Provisions do not remove localisation for important data. They do not dilute the assessment regime for large exporters. Foreign firms with heavy China data flows gain little, since the relief is aimed at small domestic handlers and platform merchants.
The open question is definitional clarity. Whether a small handler's data counts as "important data" depends on catalogues and sector rules that businesses may struggle to read. A handler that guesses wrong loses the exemption and faces the full regime. Regulators should publish worked examples, and provincial offices, now handling initial reviews, are well placed to do this.
The five-year audit cycle is a real trade-off. It reduces cost, but it also lengthens the gap before a systemic weakness is found. Certification could offset this: the CAC text notes that certified small handlers can be exempt from audits during the certification's validity.
Bottom line
The Provisions are a modest but sensible correction. They cut fixed compliance costs for the smallest players and keep the security perimeter where policymakers care most about it. The test now is implementation: whether provincial reviews are actually faster, whether the important-data boundary is clear enough to rely on, and whether a light-touch approach survives the first serious small-handler breach. Other jurisdictions that regulate data uniformly by obligation, regardless of size or risk, should take note of the approach.