The Cyberspace Administration of China (CAC) and the Ministry of Public Security jointly issued the Provisions on the Simplified Measures for Personal Information Protection by Small-scale Personal Information Processors (the “Provisions”), on 22 July 2026. They will come into force on 1 September 2026.
The Provisions were introduced pursuant to Article 62 of the Personal Information Protection Law (PIPL), which authorises the CAC to co-ordinate with relevant government departments in developing specific personal information protection rules and standards for small-scale personal information processors.
Since the PIPL came into effect on 1 November 2021, it has imposed a comprehensive set of compliance obligations on personal information processors. These include requirements relating to transparency and consent, periodic compliance audits, personal information protection impact assessments (PIPIAs) and cross-border data transfer obligations.
For organisations engaged in only limited personal information processing activities, these requirements may in some cases result in a disproportionate compliance burden.
The Provisions seek to reduce the compliance burden on smaller processors without lowering the underlying standards of personal information protection. The objective is to support innovation and business development among small and micro enterprises, sole proprietors and other small businesses.
With upcoming implementation of the Provisions – together with the proposed Provisions on Personal Information Protection for Large-Scale Personal Information Processors (currently under public consultation) and other planned supporting measures such as the Data Security Technology Guide on Personal Information Protection for Small-Scale Personal Information Processors – the Chinese Mainland’s personal information protection framework is expected to become increasingly sophisticated.
The regulatory approach is gradually shifting away from a uniform “one-size-fits-all” model towards a more nuanced and tiered regime based on the scale of personal information processing activities.
This series of articles will examine key features of the Provisions, including,
- Qualification criteria for a “small-scale personal information processor” and the scope of application of the regime
- Simplified compliance measures available to such processors
- Relevant supervisory and enforcement arrangements
Helping organisations assess their position under the new regime, this first article in the series examines the qualification criteria for “small-scale personal information processors” and scope of application of the Provisions.
Is your organisation considered a small-scale personal information processor?
Small-scale personal information processors
Definition
Under the PIPL, although certain categories of personal information processors are subject to additional obligations in specific circumstances, the law generally does not distinguish between different types of personal information processor at the level of legal obligations.
As a result, the PIPL’s requirements apply broadly to all personal information processors.
Although Article 62 of the PIPL authorises the CAC and other competent authorities to formulate specific personal information protection rules and standards for small-scale personal information processors, the PIPL itself does not define the term “small-scale personal information processor”. Article 2 of the Provisions addresses this gap by introducing, for the first time, a clear threshold.
A small-scale personal information processor is defined under Article 2 of the Provisions as a personal information processor that processes the personal information of fewer than 100,000 individuals. The classification is based on the number of individuals whose personal information is processed, rather than the processor’s revenue, headcount or asset size.
In practical terms, a personal information processor will qualify as a small-scale processor if it processes the personal information of fewer than 100,000 individuals. If that threshold is exceeded, the processor will not qualify.
Accordingly, an internet start-up with only a small number of employees but a large user base may not fall within the scope of the Provisions. Conversely, a manufacturing company with a relatively large workforce but which mainly processes personal information relating to employees may qualify as a small-scale processor.
Organisations should therefore not assume they qualify simply because they are categorised as a “micro”, “small” or “medium-sized” enterprise under other regulatory or statistical classifications.
Territorial scope
The Provisions apply only to small-scale personal information processors located within the People’s Republic of China (PRC) when carrying out personal information protection activities.
Where the relevant entity is located outside the PRC, the Provisions do not apply, regardless of the scale of the personal information processing activities undertaken.
Such entities must instead comply with the PIPL and other applicable requirements, including the principle of international co-operation and mutual recognition set out in Article 12 of the PIPL.
Practical considerations
The threshold of fewer than 100,000 individuals is based on the number of natural persons whose personal information is being processed by the processor at the time of assessment. Individuals whose personal information has already been deleted are not counted.
Although the threshold itself is clear, questions may arise as to how the number of individuals should be calculated in practice. In our view, the calculation should be approached as follows:
- All categories of data subjects should be included.
The calculation should cover all natural persons whose personal information is processed by the organisation, including customers and their contacts, employees, job applicants, suppliers and supplier contacts, former employees, visitors and any other categories of data subject.
- The focus is on individuals, not data records.
The relevant measure is the number of natural persons, rather than the number of personal information records. Accordingly, an individual should be counted only once, even if their personal information is stored across multiple systems or processed for different purposes.
- Deleted data is excluded, but retained data remains relevant.
If the organisation no longer actively uses an individual’s personal information but continues to retain it, that individual should still be counted. An individual should only be excluded once all their personal information has been permanently deleted.Similarly, where personal information has been irreversibly anonymised so that it no longer constitutes personal information under the PIPL, the relevant individual should no longer be included in the calculation.
Under the Provisions, the number of individuals whose personal information is processed is the key criterion for determining whether an organisation qualifies as a small-scale personal information processor.
Organisations should therefore establish a monitoring mechanism to regularly track the number of individuals whose personal information they process. Where that number approaches the 100,000-person threshold, they should begin preparing to transition to the compliance framework applicable to general personal information processors.