New China data processing rules let small-scale personal information processors meet their notification obligations through simplified public disclosure, rather than complex consent structures. This first part of a two-part series covers the simplified processing rules and disclosure methods.
China’s cybersecurity authorities have released new simplified rules for small companies to comply with the country’s personal information (PI) protection regulations.
China’s PI protection regime, underpinned by the 2021 Personal Information Protection Law (PIPL), includes often onerous and complex regulations on PI processing, notification and consent, and audit requirements, which are difficult for small companies with limited resources and legal capabilities to meet.
The new rules, which come into effect on 1 September 2026, allow small-scale PI processors to use simplified data processing rules, user or customer notification methods, and other simplified PI protection measures to comply with PI protection regulations, such as cross-border data transfer and PI protection audits.
In Part 1 of this two-part series, we cover the simplified methods for formulating and publicising PI processing rules. In Part 2, we cover the simplified measures for complying with other PI protection obligations, such as data exports and audits.
See Part 2 here: Simplified Personal Information Protection Compliance for Small Companies in China
Review Data Compliance
We help businesses assess their processor status and formulate compliant PI processing rules under China's PIPL.Who are small-scale processors?
Small-scale data processors are those that process the personal data of less than 100,000 people.
What are the simplified processing rules?
Under the simplified rules, small-scale processors can fulfil their obligation to inform individuals solely by publicly disclosing their processing rules, rather than having to carry out more complex notification and consent structures required by larger firms.
The rules must be presented to users in a prominent manner using methods such as bold text, larger font sizes, or distinct colours. They must also be easy to access and save.
The required processing rules themselves are also simplified, and at minimum need to contain the following information:
- The name of the small-scale processor;
- The department or personnel responsible for handling the exercise of rights by individuals, along with contact information; and
- The purposes and methods of processing the PI, the categories of PI processed, the retention period, and so on.
Exemptions from Formulating and Publishing the Processing Rules In certain scenarios, small-scale processors do not need to formulate and publish their own processing rules. For small-scale processors operating offline, if they are located within a serviced or managed area, such as an industrial park, industry base, or commercial property, that has established its own general-purpose processing rules and publicly displayed them in a prominent location, the small-scale processor is not required to formulate and publicise its own rules, provided it is operating the same type of offline business to which the rules pertain and it has agreed to abide by these rules. Small-scale processors operating online that meet all of the following conditions do not have to formulate and publicise their own processing rules:
When do the simplified processing rules apply?
Small-scale processors can only use the simplified processing rules and publication method under the following conditions:
- The processing of PI (excluding sensitive PI) is necessary for the provision of products or services;
- The PI is not provided to other PI processors or disclosed to the public, and this fact is explicitly stated in the PI processing rules.
What the Two Conditions Mean in Plain Terms Purpose-limited to service delivery, and non-sensitive only: The PI being processed must be necessary to actually deliver the product or service, not for secondary purposes like marketing, profiling, or unrelated analytics. It must also exclude sensitive PI, such as biometric data, health records, financial accounts, religious beliefs, precise location tracking, and information on minors. Sensitive PI always triggers stricter obligations regardless of company size. No third-party sharing or public disclosure, and this must be stated: The company can’t hand this PI off to any other PI processor, such as a data processor, an affiliate, a third-party vendor, or make it public in any way. Critically, it’s not enough to simply not share the data. Rather, the company must explicitly say so in its own PI processing rules by stating, for example, “We do not share your personal information with third parties” or equivalent language.
Strengthen Data Compliance
We support businesses with PIPL assessments, processing rules, data transfers, audits, and cybersecurity.How do the data processing rules have to be displayed?
If the PI is collected offline, the company can simply make its PI processing rules public through means such as posting a notice in a conspicuous location at its business premises.
If the data is collected online, it may make the rules public through service agreements, pop-up windows in product or service client applications, website announcements, or other similar means.
What are the rules for processing sensitive PI and PI of minors?
If a small-scale processor processes the PI of minors under 14, it must establish specific processing rules.
If sensitive PI is processed for a specific purpose, the small-scale processor must disclose the necessity of this activity and its impact on the individual’s rights and interests within the processing rules. It must also obtain the individual’s separate consent.
How small companies should prepare
Small companies should take the following steps to prepare ahead of the 1 September effective date:
- Review the total volume of PI processed to assess whether the company qualifies for small-scale processor status.
- If situated in a managed service area or an online third-party platform, review the platform or managing company’s processing rules to see whether it is possible to opt in.
- If no existing rules are in place, begin formulating rules in accordance with the template provided.
- Appoint personnel within the organisation to be responsible for PI protection compliance.
- Review which PI processing activity is currently being done that may be unnecessary to fulfil the product or service obligations.
- Consider staff training to ensure knowledge of and compliance with processing rules.
How Dezan Shira & Associates can help
Navigating China’s PIPL requirements, even under the new simplified rules for small-scale processors, requires careful assessment of eligibility, documentation, and ongoing compliance obligations. Dezan Shira & Associates offers cybersecurity and compliance advisory tailored to China’s regulatory landscape, helping businesses determine their processor status, formulate compliant PI processing rules, and prepare for cross-border data transfer and audit requirements. Contact us to discuss your PI protection strategy ahead of the 1 September 2026 effective date.