Since 1 September 2026, a business in China that processes the personal information of fewer than 100,000 people can meet its obligations under the Personal Information Protection Law (PIPL) with a lighter toolkit. Plenty of foreign-owned subsidiaries pass that headcount test. Fewer pass the second one: the biggest simplification is only available if the data is not provided to any other processor — and a subsidiary wired into its group's HR or CRM systems usually is. The cross-border rules barely change at all.
- The Provisions on Simplified Personal Information Protection Measures for Small Personal Information Processors (Order No. 25 of the Cyberspace Administration of China and the Ministry of Public Security) apply from 1 September 2026 to processors handling personal information of fewer than 100,000 individuals.
- Size is not enough for the main benefit. Giving notice simply by publishing your privacy rules requires that the data is non-sensitive, necessary for your product or service, and neither provided to another processor nor made public (Article 6).
- What gets lighter: a short-form privacy rule that can be posted; a compliance audit at least once every five years using a self-check form; a simplified impact assessment form kept for three years; and statutory grounds for no or reduced penalties.
- What does not: separate consent for sensitive personal information, dedicated rules for children under 14, and the cross-border regime — the export exemptions in Article 10 are the familiar ones, and important data is excluded.
- Recruitment data got stricter in July 2026. The CAC says sending Chinese applicants' CVs to an overseas headquarters that takes no part in the hiring decision is not necessary — so those CVs should stay in China.
1. Who counts as a small processor
Article 2 of Order No. 25 defines a small personal information processor as one that processes the personal information of fewer than 100,000 individuals. The measure was adopted on 26 June 2026, issued jointly by the Cyberspace Administration of China (CAC) and the Ministry of Public Security, and runs to 22 articles. Its stated purpose is to support small and micro enterprises by scaling obligations to their size and capacity; it does not displace the PIPL, which still applies in full wherever the Order offers no simplification.
The count is made by the processor — under the PIPL, the organisation that decides the purposes and means of processing — so each Chinese legal entity looks at its own numbers. The Order does not specify a counting period, in contrast with the cross-border exemption discussed below, which counts from 1 January of each year. Commentary from CMS and others reads the threshold as the number of individuals whose information the processor currently holds, excluding information already deleted. For a B2B subsidiary — employees, customer and supplier contacts, visitors, event attendees — the total is often well below 100,000. A consumer-facing business with a loyalty programme or an app can pass it quickly.
2. The second test: how your data moves
The most valuable simplification is in Article 6: a small processor may satisfy its duty to inform individuals solely by publishing its personal information processing rules, displayed prominently — bold type, larger font or a different colour — and easy to consult and save. Two conditions must both be met:
- the processing of personal information, excluding sensitive personal information, is necessary to provide the product or service; and
- the processor does not provide the personal information to other personal information processors and does not make it public, and says so in its rules.
The second condition is where group structures fall out. The PIPL distinguishes between a vendor processing data on your behalf under an entrustment arrangement (Article 21) and providing data to another processor that uses it for its own purposes (Article 23). A payroll provider acting on instructions is the first. A parent company that pulls China employee records into a global HR system it runs, or customer contacts into a group CRM it controls, is usually the second. Once that happens, the subsidiary cannot rely on Article 6 and is back to the PIPL's ordinary notice rules — including the specific notice that Article 23 requires when information is provided to another processor.
Two narrower routes exist for businesses that rarely describe a foreign subsidiary: a park or commercial property manager may publish one set of rules for small processors running the same offline business on its premises (Article 5), and a processor operating only through an online platform can rely on the platform’s rules, audits and impact assessments (Article 8).
3. What genuinely gets lighter
For a processor that qualifies, the Order replaces open-ended obligations with defined, proportionate ones:
| Obligation | Simplified measure | Article |
|---|---|---|
| Privacy rules | Minimum content: the processor's name; who handles rights requests and how to contact them; purposes, methods, categories of information and retention periods. Offline, a notice posted prominently at the business premises; online, service terms, an app pop-up or a website notice. | 4 |
| Rights requests | A published contact point is enough to set up the request-handling mechanism. | 11 |
| Compliance audit | At least once every five years, using the self-check form annexed to the Order; keep the form for at least five years. Certified processors need not audit while the certification is valid. | 13, 17 |
| Impact assessment (PIPIA) | May be done on the simplified form annexed to the Order; keep it for at least three years. | 14 |
| Policies and incident plan | Can be written into existing organisational management documents. | 15 |
| Breach notification | Remedial steps and notice to individuals remain mandatory; a posted or on-screen notice is allowed where objective constraints make other methods impossible. Regulators must still be notified. | 16 |
| Merger, division, dissolution | The recipient's name and contact details may be given by public notice, published at least 30 working days in advance and kept up for at least 30 working days. | 9 |
The enforcement provisions matter as much as the paperwork. Under Article 18, a small processor must not be penalised where a violation is minor, promptly corrected and caused no harm, or where it can prove it was not at fault; a first violation with minor consequences that is promptly corrected may go unpunished, with the regulator using an interview or a reminder letter instead. Article 19 requires lighter or mitigated penalties where the processor limits the harm, volunteers violations the regulator did not know about, or notifies individuals and authorities promptly after an incident. The flip side is Article 21: spot checks are expressly authorised, and repeated incidents go on the processor's credit record and are made public.
4. What does not get easier
- Sensitive personal information. To process it for a specific purpose, the processor must explain in its rules why it is necessary and how it affects the individual, and obtain separate consent (Article 7). Employee files — ID and passport numbers, bank details, health information — usually contain it.
- Children. Processing the information of children under 14 requires dedicated rules (Article 4), and any special audit requirements for minors' data continue to apply (Article 13).
- Cross-border transfers. Article 10 exempts a small processor from the security assessment, the standard contract and certification where the transfer is necessary to conclude or perform a contract with the individual (cross-border shopping, delivery, remittances, payments, account opening, travel bookings, visas, examinations); necessary for cross-border HR management under lawful labour rules and collective contracts; necessary to protect life, health or property in an emergency; necessary to perform a statutory duty or obligation; or, for a processor that is not a critical information infrastructure operator, where fewer than 100,000 people's non-sensitive information is transferred cumulatively since 1 January of the year. Important data is excluded, and notice and separate consent are still required where the law requires them.
That exemption list is, in substance, the one already available to every processor under the CAC's March 2024 Provisions on Promoting and Regulating Cross-Border Data Flows and the Network Data Security Management Regulations. The only small-processor-specific change is procedural: where a small processor does need a security assessment, the provincial CAC may form the recommended conclusion and submit it to the national CAC for approval. The export analysis in our guides to the three transfer routes and HR data therefore still applies unchanged.
5. Recruitment: the July 2026 Q&A narrows the HR route
On 24 July 2026 — the same day it posted the text of Order No. 25 — the CAC released its Q&A on data export security management policies and regulations (July 2026). Its third answer deals with a common multinational practice: sending the CVs of candidates in China to an overseas headquarters or affiliate.
The CAC's position is that necessity must be judged by how closely the transfer relates to the recruitment, how many people are involved, and which data fields are sent. If the overseas headquarters or affiliate does not take part in the hiring decision, the export is not necessary. If it does take part directly, the number of candidates and the data fields must be cut to the minimum the overseas decision requires, and the transfer must be handled in line with the March 2024 Provisions — the answer names the security assessment, the standard contract and certification — with notice, separate consent and a personal information protection impact assessment.
The HR-management exemption described above refers to employees' personal information under labour rules and collective contracts. The CAC's answer on applicants does not rely on it, and practitioners such as AllBright read it as confirming that candidates, who have no employment relationship yet, fall outside it. The practical fix is organisational rather than legal: keep screening in China, send only shortlisted finalists to the people who actually decide, strip the CV to the fields they need, and build separate consent into the application flow. Our guide to hiring in China covers the employment side.
6. A five-question self-test for a China subsidiary
- Count. Does the Chinese entity process the personal information of fewer than 100,000 individuals in total — employees, candidates, customers, supplier contacts and visitors?
- Flow. Is any of it provided to another processor — the parent, a group HR or CRM platform the group controls, a partner using it for its own purposes — or made public? If so, Article 6 notice is off the table.
- Sensitivity. Which records are sensitive, and is separate consent in place? Is any child under 14 involved?
- Export. For each overseas flow, which Article 10 exemption applies, and is the annual count tracked from 1 January? For recruitment, does headquarters really take the decision?
- Paperwork. Is the self-check audit scheduled (at least once every five years, kept five years), the impact assessment form on file (kept three years), and the policies and incident plan written down?
Qualifying is worthwhile: it turns vague obligations into forms and fixed intervals, and it gives a small operation real protection against penalties for a first, minor mistake. But the Order rewards a particular shape of business — local, self-contained, non-sensitive — and most foreign subsidiaries will find that some of their data fits it and some does not. Mapping which is which is part of the corporate compliance and data work we do for foreign companies.
Frequently asked questions
Under Order No. 25 of the Cyberspace Administration of China and the Ministry of Public Security, in force from 1 September 2026, it is a processor that handles the personal information of fewer than 100,000 individuals. Such processors may use simplified privacy rules, a compliance audit at least once every five years on a self-check form, and a simplified impact assessment form, while the PIPL otherwise continues to apply.
Usually not. Article 6 allows notice by publishing privacy rules alone only where the processing is necessary, excludes sensitive information, and the data is neither provided to another processor nor made public. A parent company that uses the data in a group HR or CRM system it controls is normally another processor, so ordinary PIPL notice rules apply to that data.
Only on the familiar grounds. Article 10 lists the exemptions already available under the March 2024 Provisions and the Network Data Security Management Regulations: contracts with the individual, cross-border HR management, emergencies, statutory duties, and fewer than 100,000 people’s non-sensitive information transferred since 1 January of the year. Important data is excluded, and notice and separate consent are still required where the law requires them.
At least once every five years. Order No. 25 lets small processors use an annexed self-check form and requires them to keep it for at least five years. A processor holding a valid personal information protection certification need not carry out the audit during the certification period.
Only where it is necessary. The CAC’s July 2026 Q&A says the export is not necessary if the overseas headquarters or affiliate takes no part in the hiring decision. Where it does, send only the minimum number of candidates and data fields, handle the transfer under the March 2024 Provisions, and give notice, obtain separate consent and carry out an impact assessment.
Sources
- Cyberspace Administration of China — Provisions on Simplified Personal Information Protection Measures for Small Personal Information Processors (Order No. 25) (official text, Chinese; adopted 26 June 2026, effective 1 September 2026; 22 articles and two annexed forms).
- Cyberspace Administration of China — Q&A on data export security management policies and regulations (July 2026) (official text, Chinese; question 3 on job applicants’ CVs).
- CMS — China releases the provisions on simplified measures for small-scale personal information processors (threshold reading, simplified notice, audit frequency, penalty relief).
- AllBright Law Offices — three questions on data export: reading the CAC’s July 2026 Q&A (Chinese; applicants outside the HR exemption).
- State Council — Network Data Security Management Regulations (official text, Chinese; Article 35 on exemptions for providing personal information abroad).
- Internal: PIPL cross-border data transfer — the three routes; PIPL for HR data; Shanghai's data export negative list; hiring employees in China.
This article is general information for foreign companies, not legal advice on any specific matter. Rules and practice change; please take advice on your facts.
