New simplified data compliance for small companies in China exempts eligible small-scale processors from standard cross-border data transfer rules and provides streamlined templates for compliance audits, impact assessments, and emergency response plans. This second part of a two-part series covers personal information exports, audits, and penalties for violations.


China’s cybersecurity authorities have released new provisions to make it easier for small companies to comply with personal information (PI) protection regulations.

Under China’s Personal Information Protection Law (PIPL) and its related implementing regulations, companies need to comply with complex requirements to protect the PI of individuals in the country, including obligations for formulating and publishing processing rules, gaining consent, exporting PI, and implementing emergency response procedures.

Review Data Compliance

We help businesses navigate cross-border data transfer, audits, and compliance requirements under China's PIPL.
Schedule a Free Consultation

The new simplified rules facilitate compliance with these obligations for small-scale PI processors by exempting them from the rules on PI export if they meet certain eligibility conditions and providing simplified templates for PI protection audits and impact assessments, among other measures. They also lower penalties for violations for small companies under certain conditions. 

The new provisions come into effect on 1 September 2026.

In Part 1 of this two-part series, we covered the simplified procedures for formulating and publicising processing rules for small-scale processors. In Part 2, we cover the simplified measures for complying with other PI protection obligations, such as data exports and audits. Read it here: China Simplifies Personal Information Processing Rules for Small Companies

Who are small-scale processors? 

Small-scale data processors are those that process the personal data of fewer than 100,000 people. 

PI export rules for small-scale processors 

Small-scale PI processors are exempt from the general rules on cross-border data transfer (undergoing a security assessment by the CAC, signing a standard contract, or undergoing third-party PI protection certification) if they meet at least one of the following conditions: 

  1. It is necessary to export the PI to conclude or perform a contract to which the individual is a party;
  2. It is necessary to export employees’ PI for required cross-border HR management;
  3. It is necessary to export PI to protect the life, health, or property safety of a natural person in an emergency;
  4. It is necessary to export PI to perform statutory duties or obligations; and
  5. The PI processor (other than critical information infrastructure operators) has exported the PI (excluding sensitive PI) of less than 100,000 individuals in aggregate since 1 January of the current year. 

Note that important data cannot be freely exported out of China, regardless of the size of the operations or export purposes. 

Small-scale processors still need to notify the individuals in question if they plan to export their PI overseas, such as by providing notice and obtaining their separate consent. 

PI protection compliance audits 

Small-scale processors can conduct a PI protection compliance audit at least once every five years. This is less frequent than for mid-size entities (at least every three to four years) and large entities (at least once every two years). 

The audit can be carried out using a simplified method set out in the Self-Checklist for PI Protection Compliance Audits by Small-Scale PI Processors attached to the provisions. The completed checklist must be retained for at least five years.  

Small-scale processors can get certifications from PI protection certification bodies, such as those provided for larger companies carrying out data export activities. If they get this certification, they may be exempted from conducting compliance audits during the certificate’s validity period. 

PI impact assessments 

Companies in China must carry out a PI protection impact assessment (PIPIA) in certain scenarios. Small-scale processors can conduct a PIPIA using the simplified method set out in the Assessment Checklist for PI Protection Impact by Small-Scale PI Processors (attached to the provisions). The checklist must be retained for at least three years.  

If a small-scale processor is operating on a platform that has already conducted compliance audits and a PIPIA covering the activities carried out by the small-scale processors, then it doesn’t have to conduct them again. 

Emergency response systems 

Small-scale processors can use simplified measures to establish management systems for PI protection and emergency response plans for security incidents. These include explicitly stipulating internal management requirements for PI protection and requirements for emergency response to PI security incidents within their organizational management documents. 

Security incident response 

In the event of an actual or potential leak, alteration, or loss of PI, small-scale processors must immediately take remedial measures and notify the affected individuals. If it is not possible to notify the individuals through other means, the company can instead post a public notice in a conspicuous location at the business premises, display a pop-up notification on the product or service client, or publish a notice on the website. The department responsible for PI protection duties must also be notified.  

If there is reason to suspect a crime, the matter must be reported to the public security authorities. 

Strengthen Data Compliance

We support businesses with PIPL, cross-border data transfers, audits, cybersecurity, and incident response.
Schedule a Free Consultation

Lenient penalties for violations for small-scale processors 

Small-scale processors are also subject to more lenient penalties compared to larger companies, if the violations are minor or the entity has taken prompt steps to rectify problems that have arisen. 

Under the PIPL, fines of up to RMB 1 million (US$148,070) can be given if an entity refuses to take action to rectify errors, or up to RMB 50 million (US$7.4 million) or 5 percent of the previous year’s turnover for serious violations. 

However, penalties will be waived or reduced for small-scale processors under the following circumstances: 

Penalty 

Conditions 

No penalty 

  • Minor violations with no harmful consequences that are promptly rectified
  • No subjective fault
  • First-time violations where there are no harmful consequences 

Lenient or reduced penalty 

  • Voluntary elimination or mitigation of harmful consequences
  • Voluntary confession to a previously unknown violation
  • Prompt notification of the affected individuals and remedial measures in the event of a security incident
  • Cooperation with the department responsible for personal information protection duties in the investigation 

How small companies can prepare 

The new provisions make it considerably easier for small companies with limited resources to abide by China’s PI protection regulations. However, the lower compliance bar also means that small businesses will not be able to avoid complying with the regulations under the pretext of ignorance of the rules. 

Small companies should take the following steps to prepare for the 1 September effective date: 

  • Review the total volume of PI processed to assess whether the company qualifies for small-scale processor status.
  • Review which PI processing activity is currently being done that may be unnecessary to fulfil the product or service obligations.
  • Review timelines for conducting PI protection audits and PIPIAs, if applicable.
  • Consider staff training to ensure understanding of rules and compliance timelines. 

How Dezan Shira & Associates can help 

As China’s PI protection regime continues to evolve, both large and small businesses should regularly review their data governance practices to ensure they remain compliant with the latest requirements. Taking a proactive approach can reduce compliance risks while strengthening customer trust and operational resilience. 

If you need guidance on navigating China’s PIPL or broader cybersecurity and data privacy requirements, Dezan Shira & Associates’ specialists can help assess your obligations and implement practical, compliant solutions tailored to your business.