China Proposes New Data Rules for Large Handlers
China’s cyberspace regulator has unveiled a significant tightening of data protection rules for major tech companies. The Cyberspace Administration of China (CAC) published Draft Provisions on Personal Information Protection for Large-Scale Personal Information Handlers, signaling a new era of strict oversight. The move follows recent measures aimed at smaller data handlers, completing a tiered regulatory framework that now covers companies of every size.

The Draft Regulation’s Timeline

The Draft Regulation was released on August 7, 2026, and is open for public comment until September 7, 2026. It targets what the CAC calls “large-scale personal information handlers,” imposing detailed, prescriptive requirements that contrast sharply with the Simplified Measures for small-scale handlers, which take effect September 1, 2026.

Who Counts as “Large-Scale”

An entity qualifies as a Large-scale PI Handler if it processes personal information for 10 million or more individuals. It must also provide significant internet services or operate multiple data-intensive businesses, and its data processing activities must significantly impact national security, economic operations, social stability, or public health.

Given China’s vast population, many companies in sectors like smart devices, healthcare, finance, and e-commerce will likely meet these criteria. Companies must self-assess and apply for formal designation with the CAC, though regulators can also mandate an application if a company appears to qualify without applying on its own.

Privacy Policies Get a Structural Overhaul

The Draft Regulation mandates heightened transparency in privacy policies. Large-scale handlers must present key information in structured checklists covering:

  • Purposes and methods of data collection
  • Data categories and permissions required
  • Access frequency
  • Sensitive data collection needs

Policies must also list embedded third-party SDKs, including developer names, versions, and privacy policy links. Transfers to third-party controllers require explicit disclosure of recipients, reasons, and data categories involved. Failure to comply with these formatting rules presents a significant enforcement risk on its own, separate from any underlying data handling violations.

A New Layer of Internal Oversight

Large-scale handlers must designate a senior management member as the Personal Information Protection Officer (PIPO). This role oversees policy, guides business units, and participates in corporate decisions involving personal information. Notably, the PIPO can report directly to provincial CAC authorities if compliance concerns go unaddressed internally.

Companies must also establish a personal information protection supervisory committee with at least seven members. External members must make up two thirds of that committee and chair it, adding an independent oversight layer that reinforces external accountability rather than leaving compliance entirely in-house.

Data Must Stay Within China’s Borders

Personal information collected and generated domestically must now be stored within China. Data centers handling this information must be physically located in mainland China, and their management entity’s legal representative or ultimate controller must hold PRC nationality.

Cross-border data transfers still require compliance with the CBDT Provisions, and exemptions from the CBDT Mechanism apply in less sensitive scenarios. However, these new criteria narrow the pool of eligible storage providers, potentially forcing organizations to reassess existing data center arrangements they’ve relied on for years.

Preparing for Compliance

The Draft Regulation is expected to be finalized soon, and companies should act now rather than wait for the final version. Immediate priorities include:

  • Assessing eligibility against the 10 million individual threshold
  • Overhauling privacy policies to meet new formatting and disclosure requirements
  • Designating a PIPO and establishing the required supervisory committee
  • Reviewing data infrastructure and localization arrangements
  • Migrating overseas-stored personal information to domestic data centers that meet the new criteria

Hashlytics Take

The real story here isn’t the rules themselves, it’s the enforcement architecture built around them. Requiring a PIPO who can bypass internal leadership and report straight to provincial regulators, combined with a supervisory committee where outsiders hold the majority, is a deliberate check against companies quietly managing compliance internally without real accountability. For multinational firms operating in China, the data localization requirements are likely to matter more in practice than the privacy policy formatting rules, since migrating infrastructure takes months, not a policy rewrite.

Follow Hashlytics on Bluesky, Facebook, LinkedIn , Telegram and X to Get Instant Updates