China China Personal Information Protection Law PIPL

China's Weekly App-Naming Notices Show PIPL Enforcement Has Become Routine, Not Exceptional

Three CAC-led notices named 139 apps in three weeks, marking a shift from occasional PIPL rulings to a standing compliance-testing regime.

China's July 2026 PIPL App-Naming Rounds People of Internet Research · China 35 Apps named July 24 Third naming round in three weeks,… 72 Apps named July 9 Second round spanned banks, broker… 32 Apps/SDKs named July 2 MIIT's batch cited excessive permi… 11 of 40 Repeat violators on retest Apps from an earlier notice that s… peopleofinternet.com
China's July 2026 PIPL App-Naming Roun… People of Internet Research · China 35 Apps named July 24 72 Apps named July 9 32 Apps/SDKs named July 2 11 of 40 Repeat violators on retest peopleofinternet.com

Key Takeaways

China's National Cybersecurity Alert Center named 35 mobile apps and mini-programs on July 24, 2026, for violating the Personal Information Protection Law (PIPL) — mostly ride-hailing and bus-ticketing services such as Songguo Chuxing and Yueba Bus, cited for collecting user data without disclosing collection rules or obtaining consent (China News Service, July 24). It was the third such notice in three weeks: 32 apps and SDKs on July 2 from the Ministry of Industry and Information Technology (MIIT batch summary), and 72 apps — including brokerages, a hospital platform, and several banks — on July 9 (China News Service, July 9). All three sit inside the same campaign: the 2026 Personal Information Protection Special Action, jointly launched April 2, 2026 by the Cyberspace Administration of China (CAC), MIIT, and the Ministry of Public Security, targeting apps, advertising networks, education, transport, healthcare, and finance (CAC announcement).

From occasional rulings to a testing pipeline

What's changed is cadence, not law. PIPL has been in force since November 2021. What began this spring as periodic notices — 33 apps in April, 30 in June (CAC, June 11) — has compressed into a weekly drumbeat, with three rounds and 139 named apps in the space of three weeks. Regulators are running standardized third-party technical scans across sectors on a rolling schedule and publishing results almost as fast as the tests complete. The July 24 notice also disclosed that of 40 apps flagged in an earlier round, 11 still failed re-inspection — a roughly 28% recidivism rate that suggests the naming itself, not just the underlying fixes, is now a recurring compliance checkpoint companies have to budget for.

The case for the crackdown

The strongest argument for this approach is that it works where quieter enforcement didn't. Chinese consumers have had a private right of action under PIPL since 2021, but individual lawsuits against app developers are slow, costly, and rarely change platform behavior at scale. Public naming is cheap for the state, fast, and creates immediate commercial pressure — app stores and payment platforms routinely act on these notices within days, and the July 24 notice shows CAC is following through with re-tests rather than treating a name-and-shame as the end of the process. Transparency about what's being flagged and why — unpublished collection rules, missing parental consent for minors' data, apps that ignore account-deletion requests — gives consumers and smaller developers a genuine reference for what compliance looks like, something PIPL's broad statutory language alone doesn't provide. A regulator that tests continuously and publishes findings is, in principle, more accountable than one that acts opaquely behind closed-door investigations.

Where it becomes disproportionate

But the shift from quarterly to weekly naming changes the character of the sanction. A single high-profile notice functions as a warning shot; a standing pipeline that names dozens of apps every week starts to function as a parallel enforcement track that runs ahead of, and largely outside, PIPL's own formal procedures — administrative penalties, fines, and appeals under Articles 66 and 68. None of the three July notices disclose fines, and it's unclear from the published notices what due-process route a named developer has to contest a finding before its app is delisted by distribution platforms reacting to reputational pressure rather than a legal order. That matters most for the smaller entities dominating these lists: mini-programs built on Alipay and WeChat, regional bus-ticketing platforms, single-city taxi apps. These are exactly the developers least able to retain compliance counsel or run their own privacy audits before shipping — and the campaign's own design, hitting transport, education, and advertising in sequence, guarantees it will keep landing hardest on long-tail consumer apps rather than the largest platforms, which have compliance teams built for this cadence already.

The proportionate version of this policy

None of this argues against enforcing PIPL's core requirements — clear disclosure, real consent, working deletion mechanisms are baseline expectations, not onerous ones, and most violations cited across the three notices (undisclosed collection rules, no account-deletion function, third-party sharing without notice) are exactly the kind of low-cost fixes a functioning compliance regime should catch early. The proportionate version of this campaign would pair the current cadence with a published pre-clearance checklist and a short cure period before public naming for first-time, non-severe violations — preserving the deterrent effect for repeat offenders like the 11 apps that failed twice, while giving smaller developers a chance to fix disclosure gaps without a reputational hit that can kill a niche transport app's user base overnight. Predictable process, not slower enforcement, is what would make this campaign a durable compliance framework rather than a running list of casualties.

Sources & Citations

  1. CAC: 2026 Personal Information Protection Special Action announcement
  2. CAC: Notice on 30 apps' personal information issues (June 11)
  3. China News Service: 35 apps named for PIPL violations (July 24)
  4. China News Service: 72 apps named for personal information violations (July 9)
  5. MIIT app/SDK notification, 2026 batch 4 (July 2)
  6. ppc.land: China's 2026 privacy crackdown targets adtech, apps, facial recognition