Legal updates 27 August 2026

Navigating the Chinese Mainland’s Simplified Personal Information Protection Measures for Small-Scale Personal Information Processors – Part 1

Other author(s): Elfie Wang and Heng Liang of Meng Bo Law Office, a PRC law firm based in Shanghai.

The Cyberspace Administration of China (CAC) and the Ministry of Public Security jointly issued the Provisions on the Simplified Measures for Personal Information Protection by Small-scale Personal Information Processors (the “Provisions”), on 22 July 2026. They will come into force on 1 September 2026.

The Provisions were introduced pursuant to Article 62 of the Personal Information Protection Law (PIPL), which authorises the CAC to co-ordinate with relevant government departments in developing specific personal information protection rules and standards for small-scale personal information processors.

Since the PIPL came into effect on 1 November 2021, it has imposed a comprehensive set of compliance obligations on personal information processors. These include requirements relating to transparency and consent, periodic compliance audits, personal information protection impact assessments (PIPIAs) and cross-border data transfer obligations.

For organisations engaged in only limited personal information processing activities, these requirements may in some cases result in a disproportionate compliance burden.

The Provisions seek to reduce the compliance burden on smaller processors without lowering the underlying standards of personal information protection. The objective is to support innovation and business development among small and micro enterprises, sole proprietors and other small businesses.

With upcoming implementation of the Provisions – together with the proposed Provisions on Personal Information Protection for Large-Scale Personal Information Processors (currently under public consultation) and other planned supporting measures such as the Data Security Technology Guide on Personal Information Protection for Small-Scale Personal Information Processors – the Chinese Mainland’s personal information protection framework is expected to become increasingly sophisticated.

The regulatory approach is gradually shifting away from a uniform “one-size-fits-all” model towards a more nuanced and tiered regime based on the scale of personal information processing activities.

This series of articles will examine key features of the Provisions, including,

  1. Qualification criteria for a “small-scale personal information processor” and the scope of application of the regime
  2. Simplified compliance measures available to such processors
  3. Relevant supervisory and enforcement arrangements

Helping organisations assess their position under the new regime, this first article in the series examines the qualification criteria for “small-scale personal information processors” and scope of application of the Provisions.

Is your organisation considered a small-scale personal information processor?

Small-scale personal information processors

Definition

Under the PIPL, although certain categories of personal information processors are subject to additional obligations in specific circumstances11, the law generally does not distinguish between different types of personal information processor at the level of legal obligations.

As a result, the PIPL’s requirements apply broadly to all personal information processors.

Although Article 62 of the PIPL authorises the CAC and other competent authorities to formulate specific personal information protection rules and standards for small-scale personal information processors, the PIPL itself does not define the term “small-scale personal information processor”. Article 2 of the Provisions addresses this gap by introducing, for the first time, a clear threshold.

A small-scale personal information processor is defined under Article 2 of the Provisions as a personal information processor that processes the personal information of fewer than 100,000 individuals22. The classification is based on the number of individuals whose personal information is processed, rather than the processor’s revenue, headcount or asset size.

In practical terms, a personal information processor will qualify as a small-scale processor if it processes the personal information of fewer than 100,000 individuals. If that threshold is exceeded, the processor will not qualify.

Accordingly, an internet start-up with only a small number of employees but a large user base may not fall within the scope of the Provisions. Conversely, a manufacturing company with a relatively large workforce but which mainly processes personal information relating to employees may qualify as a small-scale processor.

Organisations should therefore not assume they qualify simply because they are categorised as a “micro”, “small” or “medium-sized” enterprise under other regulatory or statistical classifications33.

Territorial scope

The Provisions apply only to small-scale personal information processors located within the People’s Republic of China (PRC) when carrying out personal information protection activities44.

Where the relevant entity is located outside the PRC, the Provisions do not apply, regardless of the scale of the personal information processing activities undertaken.

Such entities must instead comply with the PIPL and other applicable requirements, including the principle of international co-operation and mutual recognition set out in Article 12 of the PIPL55.

Practical considerations

The threshold of fewer than 100,000 individuals is based on the number of natural persons whose personal information is being processed by the processor at the time of assessment. Individuals whose personal information has already been deleted are not counted.

Although the threshold itself is clear, questions may arise as to how the number of individuals should be calculated in practice66. In our view, the calculation should be approached as follows:

  • All categories of data subjects should be included.

The calculation should cover all natural persons whose personal information is processed by the organisation, including customers and their contacts, employees, job applicants, suppliers and supplier contacts, former employees, visitors and any other categories of data subject.

  • The focus is on individuals, not data records.

The relevant measure is the number of natural persons, rather than the number of personal information records. Accordingly, an individual should be counted only once, even if their personal information is stored across multiple systems or processed for different purposes.

  • Deleted data is excluded, but retained data remains relevant.

If the organisation no longer actively uses an individual’s personal information but continues to retain it, that individual should still be counted. An individual should only be excluded once all their personal information has been permanently deleted.Similarly, where personal information has been irreversibly anonymised so that it no longer constitutes personal information under the PIPL, the relevant individual should no longer be included in the calculation.

Under the Provisions, the number of individuals whose personal information is processed is the key criterion for determining whether an organisation qualifies as a small-scale personal information processor.

Organisations should therefore establish a monitoring mechanism to regularly track the number of individuals whose personal information they process. Where that number approaches the 100,000-person threshold, they should begin preparing to transition to the compliance framework applicable to general personal information processors.

Remarks/Footnotes
  1. For example, Article 52 of the PIPL provides that personal information processors whose processing activities reach the threshold prescribed by the CAC must designate a person responsible for personal information protection to supervise personal information processing activities and the related protection measures. Article 58 further imposes additional obligations on personal information processors that provide important internet platform services, involving a large number of users and operate complex business models.
  2. Article 2 of the Provisions provides that a “small-scale personal information processor” means a personal information processor that processes the personal information of fewer than 100,000 individuals.
  3. See the Measures for the Statistical Classification of Large, Medium, Small and Micro Enterprises (2017) issued by the National Bureau of Statistics.
  4. Article 2 of the Provisions provides that the Provisions apply to the implementation of personal information protection by small-scale personal information processors within the territory of the PRC.
  5. Article 12 of the PIPL provides that the State (i.e. the PRC governments through its relevant authorities and institutions) shall actively participate in the development of international rules on personal information protection, promote international exchanges and cooperation in the field of personal information protection, and promote the mutual recognition of personal information protection rules and standards with other countries, regions and international organisations.
  6. See the official Q&A issued in connection with the Provisions on Simplified Personal Information Protection Measures for Small-Scale Personal Information Processors.
Subscribe

Follow our insights

Sign up for regular updates covering the latest news, regulations and case law relevant to your business.
View more
Johnson Stokes & Master - Sign up for JSM's regular updates covering the latest news, regulations and case law relevant to your business

Please scan the QR code and follow us on WeChat

Wechat ID: JSM_Legal
JSM WeChat QR code