China's National Cybersecurity Alert Center named 35 mobile apps and mini-programs on July 24, 2026, for violating the Personal Information Protection Law (PIPL) — mostly ride-hailing and bus-ticketing services such as Songguo Chuxing and Yueba Bus, cited for collecting user data without disclosing collection rules or obtaining consent (China News Service, July 24). It was the third such notice in three weeks: 32 apps and SDKs on July 2 from the Ministry of Industry and Information Technology (MIIT batch summary), and 72 apps — including brokerages, a hospital platform, and several banks — on July 9 (China News Service, July 9). All three sit inside the same campaign: the 2026 Personal Information Protection Special Action, jointly launched April 2, 2026 by the Cyberspace Administration of China (CAC), MIIT, and the Ministry of Public Security, targeting apps, advertising networks, education, transport, healthcare, and finance (CAC announcement).
From occasional rulings to a testing pipeline
What's changed is cadence, not law. PIPL has been in force since November 2021. What began this spring as periodic notices — 33 apps in April, 30 in June (CAC, June 11) — has compressed into a weekly drumbeat, with three rounds and 139 named apps in the space of three weeks. Regulators are running standardized third-party technical scans across sectors on a rolling schedule and publishing results almost as fast as the tests complete. The July 24 notice also disclosed that of 40 apps flagged in an earlier round, 11 still failed re-inspection — a roughly 28% recidivism rate that suggests the naming itself, not just the underlying fixes, is now a recurring compliance checkpoint companies have to budget for.
The case for the crackdown
The strongest argument for this approach is that it works where quieter enforcement didn't. Chinese consumers have had a private right of action under PIPL since 2021, but individual lawsuits against app developers are slow, costly, and rarely change platform behavior at scale. Public naming is cheap for the state, fast, and creates immediate commercial pressure — app stores and payment platforms routinely act on these notices within days, and the July 24 notice shows CAC is following through with re-tests rather than treating a name-and-shame as the end of the process. Transparency about what's being flagged and why — unpublished collection rules, missing parental consent for minors' data, apps that ignore account-deletion requests — gives consumers and smaller developers a genuine reference for what compliance looks like, something PIPL's broad statutory language alone doesn't provide. A regulator that tests continuously and publishes findings is, in principle, more accountable than one that acts opaquely behind closed-door investigations.
Where it becomes disproportionate
But the shift from quarterly to weekly naming changes the character of the sanction. A single high-profile notice functions as a warning shot; a standing pipeline that names dozens of apps every week starts to function as a parallel enforcement track that runs ahead of, and largely outside, PIPL's own formal procedures — administrative penalties, fines, and appeals under Articles 66 and 68. None of the three July notices disclose fines, and it's unclear from the published notices what due-process route a named developer has to contest a finding before its app is delisted by distribution platforms reacting to reputational pressure rather than a legal order. That matters most for the smaller entities dominating these lists: mini-programs built on Alipay and WeChat, regional bus-ticketing platforms, single-city taxi apps. These are exactly the developers least able to retain compliance counsel or run their own privacy audits before shipping — and the campaign's own design, hitting transport, education, and advertising in sequence, guarantees it will keep landing hardest on long-tail consumer apps rather than the largest platforms, which have compliance teams built for this cadence already.
The proportionate version of this policy
None of this argues against enforcing PIPL's core requirements — clear disclosure, real consent, working deletion mechanisms are baseline expectations, not onerous ones, and most violations cited across the three notices (undisclosed collection rules, no account-deletion function, third-party sharing without notice) are exactly the kind of low-cost fixes a functioning compliance regime should catch early. The proportionate version of this campaign would pair the current cadence with a published pre-clearance checklist and a short cure period before public naming for first-time, non-severe violations — preserving the deterrent effect for repeat offenders like the 11 apps that failed twice, while giving smaller developers a chance to fix disclosure gaps without a reputational hit that can kill a niche transport app's user base overnight. Predictable process, not slower enforcement, is what would make this campaign a durable compliance framework rather than a running list of casualties.