China’s cybersecurity regulator has released draft rules requiring large-scale PI processors to register with the CAC and establish an independent oversight committee for personal information protection. This article breaks down the new registration, data centre, and governance requirements for China large-scale PI processors, and what they mean for affected companies.
The Cybersecurity Administration of China has released a new draft of regulations outlining requirements for the protection of personal information (PI) for data processors, proposing new requirements such as mandatory registration with the Cybersecurity Administration of China (CAC) and the establishment of an independent oversight committee responsible for overseeing PI protection.
The draft consolidates two earlier drafts – one on PI protection oversight committees and one on large-platform PI obligations – into a single regime.
Find Cybersecurity Support
Get ahead of China's evolving PI protection requirements with tailored cybersecurity and compliance solutions.The draft regulations follow the release of a set of simplified regulations for small-scale PI processors, reflecting how China is building a stratified PI protection regime in which legal obligations are commensurate with company size and security risk.
The CAC is soliciting public comments on the draft until September.
Foreign companies that could be classified as a large-scale PI processor under the draft regulations should assess their exposure risk to the proposed requirements and prepare for possible enforcement in the coming months.
Who are large-scale PI processors?
Under the draft regulations, large-scale processors are assessed based on the following three criteria:
- Whether they process the PI of more than 10 million natural persons;
- Whether they provide important network services that involve the processing of PI, or their business scope covers multiple businesses involving PI processing;
- Whether they engage in PI processing activities that could significantly impact national security, economic performance, social stability, and public health and safety.
Registration as a large-scale processor with the CAC
Companies that process the PI of over 10 million people or meet one of the other two criteria based on self-assessment will be required to apply to the CAC for recognition as a large-scale PI processor through their local provincial-level cyberspace administration department. The CAC will review the application materials within 15 days.
Companies can apply to be delisted if they cease fulfilling the criteria to be deemed a large-scale PI processor for six consecutive months.
Companies that have been designated as a large-scale PI processor must submit the following information to the municipal-level cyberspace administration department where they are located within 30 working days of receiving their designation:
- Basic information of the person in charge of PI protection;
- Measures to ensure the person in charge of PI protection performs their duties; and
- Basic information on the data centre storing PI, including its operator, internal management system, security measures, and so on. If a third-party data centre operator is entrusted to process PI, the company must also submit the signed contract.
If any of this information changes, the company must report the change within 30 working days.
The company can also designate a reporting entity to report the above information on its behalf if this has been agreed upon in the contract with the data centre operator.
Storage and data centre management
As is stipulated in the PIPL, all PI collected from individuals in China must be stored in China.
However, the draft regulations now also specify requirements for the data centre in which PI is stored, namely:
- The data centre must be established in China;
- The legal representative or actual controller of the data centre operator must be a Chinese citizen; and
- The data centre must comply with relevant national policies and standards.
Large-scale PI processors are required to sign a written contract with any data centre management organisation that it entrusts to process PI. The contract must stipulate the purpose, duration, processing method, storage location, scale and type of PI being stored, protection measures, and the rights and obligations of both parties.
Establishing a PI protection oversight committee
Under the draft regulations, companies designated as large-scale PI processors will be required to establish a PI protection oversight committee within six months of receiving the designation.
The committee must be composed of an odd number of primarily external members. The exact number of members must be commensurate with the company’s scale of business and user numbers, with a minimum of seven.
Get IT Support
Find ERP solutions localised to meet China's compliance and data protection standards as you scale.The committee will be required to formulate a set of operating rules based on requirements released by the CAC (attached to the draft regulations).
The external members will need to meet certain conditions and must be able to maintain their independence, meaning they cannot be affiliated with the company.
Companies must conduct security background checks on all external members.
The company will also be required to set allowance standards for the external members, which must be approved by the board of directors or other decision-making bodies of the company.
Oversight committee’s responsibilities
The Oversight Committee will supervise the following matters in relation to the company’s PI protection duties:
- Establishment of a PI protection compliance system;
- Formulation and major revisions of platform and PI processing rules;
- Protection of sensitive PI and minors’ PI;
- Organisation and implementation of PI impact assessments, compliance audits and risk assessments;
- Prevention and handling of PI security incidents;
- Compliance with PI export requirements;
- Use of PI for automated decision-making;
- Handling of individual PI rights requests, complaints and reports;
- Performance of duties by the person in charge of PI protection and other relevant personnel;
- Publication of the PI protection social responsibility report; and
- Other supervisory matters required by applicable laws, administrative regulations and departmental rules.
In the first quarter of each year, the large-scale PI processor must submit a report on the supervision committee’s performance of duties in the preceding year through the provincial cyberspace administration authority
Compliance with general regulations
In addition to the new proposed requirements, the draft regulations dedicate a substantial number of clauses restating existing personal PI protection obligations under the PIPL, CSL, DSL, and related implementing rules. While these requirements are not new, the draft regulations expressly reaffirm their application to large-scale PI processors, thereby differentiating them from other types of companies, such as small-scale PI processors, which are subject to simpler rules.
The obligations cover, among other things, requirements relating to PI processing, formulating processing rules, obtaining consent, retention and deletion of PI, protection of sensitive PI and minors’ PI, third-party and cross-border transfers, internal PI governance, the appointment of a person responsible for PI protection, social responsibility reporting, compliance audits, and risk assessments.
What would the new requirements mean for large companies?
If passed in their current form, the draft regulations mean designation as a large-scale IP processor would trigger additional compliance requirements for companies.
As companies will be responsible for vetting, appointing, and remunerating the members of the oversight committee, this introduces a recurring governance cost on top of existing compliance headcount.
The proposed requirements for data centres could also mean some companies will have to switch providers if their current data centres do not meet the nationality requirement for the legal representative or actual controller, particularly for foreign-invested firms relying on offshore-linked or jointly managed data centre operators.
More generally, the draft regulations signal that large companies will come under more intense scrutiny for their PI protection practices, with a dedicated oversight body and direct CAC reporting lines replacing what was previously a more self-directed compliance model. In the wake of high-profile PI compliance cases, it is clear the authorities are moving to formalise and institutionalise oversight of the companies most at risk of causing large-scale harm if their PI protection measures fail, rather than relying solely on periodic audits and post-incident enforcement.
While the regulations are not final, companies processing large volumes of PI should begin assessing their designation risk and data centre arrangements now, and their possible implications for governance costs and resources, before the rules take final form.
How Dezan Shira & Associates can help
As China moves to formalise a distinct compliance tier for large-scale PI processors, Dezan Shira & Associates can help businesses assess their designation risk, review data centre and governance arrangements against the draft requirements, and monitor the regulation’s progress toward finalisation. Our team supports clients with ongoing compliance monitoring, PIPL assessments, and audit preparation, helping ensure your PI protection framework stays ahead of China’s evolving regulatory requirements. Contact us today for a free consultation.