Takeaways
- Cyberspace Administration of China (CAC) and the Ministry of Public Security (MPS) jointly issue the Provisions on Simplified Personal Information Protection Measures for Small-Scale Personal Information Processors, easing compliance requirements for entities that process the personal information of fewer than 100,000 individuals in China. The Provisions exempt such entities from certain obligations, including maintaining a standalone privacy policy and providing separate notice to each data subject, and introduce a self-assessment checklist that enables them to streamline internal compliance procedures.
- CAC releases the Administrative Measures for Internet Information Services (Draft Revision for Public Comments) for public consultation. Expanding the current 27-article framework into a six-chapter draft comprising 94 articles, it introduces dedicated chapters on intelligent information services and platform-based information services, establishing tailored requirements for AI service providers and online platforms. The draft also strengthens enforcement by introducing a range of measures, including credit management, temporary control measures, electronic evidence collection and account restrictions, thereby supporting full-chain regulation of internet information services.
- CAC released its July Q&A on security management of cross-border data transfers, clarifying that the necessity of transferring the personal information of China-based job applicants, such as résumés, to overseas affiliates or headquarters should be assessed based on whether the overseas entities directly participate in hiring decisions. If necessary, the transfer remains subject to notification and separate consent requirements.
- Several overseas data regulatory enforcement actions were concluded this month. The EU imposed an EUR 550 million fine on AliExpress over risks related to the sale of unsafe products on its platform, marking the largest penalty ever issued under the DSA.
Regulatory Highlights
CAC and MPS Jointly Issue the Provisions on Simplified Personal Information Protection Measures for Small-Scale Personal Information Processors
The Provisions on Simplified Personal Information Protection Measures for Small-Scale Personal Information Processors will take effect on September 1, 2026, which apply to small-scale China-based processors handling the personal information of fewer than 100,000 individuals. The Provisions introduce a series of simplified compliance arrangements covering the entire lifecycle of personal information processing. The final version largely retains the framework of the draft released for public consultation. It establishes simplified rules concerning the form and content of personal information processing rules, the obtaining of notification and consent, and the workflow for personal information protection compliance audits and impact assessments. However, the final version further emphasizes that, in specific scenarios such as cross-border data transfers or the processing of sensitive personal information, small-scale personal information processors must still obtain separate consent. Key provisions include:
- Simplified obligation to establish personal information processing rules: Content requirements are limited to three core elements, namely the processor’s name, contact details and processing rules, with details such as rights-exercise procedures simplified. Unless minors’ personal information is involved, the rules need not be set out in a standalone policy and may instead be communicated through on-site notices, service agreements, pop-ups or website announcements.
- Use of unified privacy policies prepared by service managers: Service managers of industrial parks, industry bases, commercial properties and online platforms may prepare and prominently publish a single privacy policy for participating small-scale personal information processors.
- Simplified notification and consent requirements: Notification and consent procedures may be streamlined in limited circumstances, including certain online-platform business activities (e.g. business-necessary collection of personal information by an e-commerce operator without third-party sharing), voluntary provision of personal information after published processing rules have been made available, and personal information security incidents where individual notification is objectively impracticable. Notably, under the final version, separate consent remains required for the processing of sensitive personal information for a specific purpose and for cross-border transfers of personal information – these exemptions do not apply.
- Simplified compliance management: Standardized self-assessment checklists for personal information compliance audits and personal information protection impact assessments have been introduced, enabling small-scale processors to complete audits (once every five years) and impact assessments through a simple tick-box process. Compliance remains subject to supervision by authorities such as the CAC and public security authorities through measures including spot checks, assessments and audit reports.
- Circumstances allowing exemption or mitigation of liability: The provisions set out factors for exempting, reducing or mitigating penalties, including minor violations, lack of subjective fault, first-time violations, voluntary remediation, and proactive cooperation with investigations. They also introduce enforcement and public credit disclosure mechanisms targeting unlawful processing activities and recurrent personal information security incidents.
Major Revisions Are Expected for the Administrative Measures for Internet Information Services
The current Administrative Measures for Internet Information Services (the Measures), revised in 2024, contain 27 articles. Following the 2025 amendments to the Cybersecurity Law taking effect, China’s regulatory framework for online ecosystem governance, internet account management and AI information services supervision has continued to evolve. CAC has therefore initiated a substantial revision of the Measures. The current Draft for public comment consists of 94 articles across six chapters. It comprehensively addresses emerging areas such as platform governance, AI, and data training. Compared with the existing Measures, which focus primarily on licensing content prohibition, the Draft shifts toward more granular, end-to-end regulatory supervision. The major changes include:
- Refined requirements for internet information service providers and enhanced regulation of online information services: The Draft refines market-entry requirements, regulates the use of network resources and strengthens oversight of personnel. It also tightens account management and clarifies content standards, including timely dynamic verification of registered account information. Data, algorithms, payment processing and other forms of support for activities such as disseminating illegal information or disrupting public order are expressly prohibited.
- New regulatory framework for intelligent information services, filling gaps in AI information service regulation: The Draft introduces a dedicated section on intelligent information services under Chapter III “Operation”, comprising 10 provisions. It imposes requirements on providers relating to AI-generated content labelling, lawful sourcing of training data, algorithm filing, prohibitions on mandating user adoption, and the protection of employees’ rights and interests.
- Enhanced platform responsibility for information disclosure and account verification: The Draft requires platforms to strengthen account governance through establishment of credit-record systems, verification and labelling of certain public accounts in news, finance, education and other specialized sectors, and disclosure of public account operator information. It also introduces a dedicated compliance regime for influential public internet accounts, covering regulatory filings, record retention and penalties for non-compliance.
- Enhanced liability framework and enforcement toolkit: A dedicated supervision chapter (Articles 65-73) introduces a broader range of enforcement measures, including joint enforcement actions, information sharing, regulatory interviews, temporary controls and electronic evidence collection. Additional tools include a blacklist for entities seriously breaching trust in the internet sector, account restrictions and bans on new account registrations – aligning with the Cybersecurity Law, the Minors Protection Law, the Administrative Penalty Law and other applicable legislation.
CAC Releases July Q&A on Cross-Border Data Transfers Policies
The Q&A primarily addresses three issues - methods for obtaining separate consent for cross-border data transfers, extensions of the validity period of security assessment results and the necessity of transferring résumés abroad in recruitment scenarios. Separate consent may be obtained through methods such as written signatures, pop-up confirmations or responses by email or text message, primarily by reference to GB/T 42574-2023, Information Security Technology: Implementation Guidelines for Notice and Consent in Personal Information Processing. The conditions for extending the validity period of cross-border data transfers security assessment results are set out in the Guidelines for Filing Cross-Border Data Transfers Security Assessments (Third Edition).
Most notably, the Q&A provides the first detailed guidance on assessing whether overseas transfers of China-based job applicants’ résumés are necessary in recruitment scenarios. Relevant factors include the transfer’s connection with the recruitment process, the number of applicants and the data fields involved. The transfer is unnecessary where the overseas organization has no role in hiring decisions concerning candidates in China. Where it participates directly, only the applicants and personal information strictly necessary for those decisions may be included. Depending on the number of applicants and the information transferred, companies must undergo a security assessment, conclude a standard contract or obtain cross-border transfer certification, as applicable. Separate consent, a personal information protection impact assessment and other relevant compliance requirements also apply.
Artificial Intelligence
On July 1, the National Cybersecurity Technical Committee of Standardization Administration released the Cybersecurity Standards Practice Guide - Security Guidelines for the Deployment and Use of Intelligent Agents. The Guide provides a table-format checklist for evaluating agent security across five stages, including assessment, preparation, deployment, use and decommissioning. Companies may use the checklist as a reference when conducting their own security reviews.
On July 6, CAC reported the results of the first phase of the Clear and Bright – Rectifying Misconduct in AI Applications special campaign, taking enforcement action against more than 14,000 AI websites, applications and agents, removing over 6 million illegal or noncompliant content items, handling more than 26,000 accounts, and delisting over 1,300 AI products and nine open-source datasets.
On July 8, National Vulnerability DataBase (NVDB) of Ministry of Industry and Information Technology (MIIT) identified a high-risk backdoor vulnerability in the AI coding tool Claude Code. NVDB advised relevant organizations and users to promptly identified affected devices and either uninstall vulnerable systems or upgrade them to a secure version. NVDB also recommended strengthening controls over external network access by development tools within core business network segments, along with enhanced traffic monitoring, to prevent any leak of sensitive data.
On July 15, the Office of MIIT released the 2025 Typical AI Application Cases, featuring 285 cases across five categories, including technology foundations, industry enablement, product applications, supporting infrastructure and special topics.
On July 15, CAC announced that seven on-device generative AI services for smartphones had completed the required regulatory filing, including Apple Intelligence, Huawei Celia AI, OPPO AndesGPT, vivo BlueLM, Xiaomi HyperAI, Samsung Galaxy AI and Nubia’s on-device large language model.
On July 17, CAC released the 18th batch of regulatory filings information of deep synthesis service algorithms, a total of 702 algorithms completed the filing process in this batch.
On July 17, MIIT together with other relevant authorities released the International Action Plan for AI Ethics Governance. The Plan expressly calls for ethical considerations to be integrated throughout the whole lifecycle of AI, including scientific research, technology development, product deployment, and operations and maintenance, focusing on the real-world risks generated from those stages.
Data Enforcement
On July 24, CAC released an update on its 2025 enforcement activities. Authorities at all levels publicly identified more than 1,100 apps and SDKs for illegally collecting or using personal information, addressed over 1,600 issues involving unlawful handling of facial recognition data, and resolved more than 8,300 cases concerning personal information violations in offline consumer settings.
Since July, routine supervision of mobile apps has continued steadily. On July 2, MIIT reported 32 apps and SDKs for user rights violations, followed by the Guangdong Cyberspace Administration’s report on personal information protection issues involving 18 locally operated apps on July 7. On July 9 and July 24, the National Computer Virus Emergency Response Center and MPS’s Computer Information System Product Quality Supervision and Inspection Center reported 72 and 35 apps, respectively, for unlawful personal information practices. In Shanghai, the Communications Administration removed 64 non-compliant apps and SDKs on July 22 and subsequently reported 25 additional cases on July 27.
On July 24, the Cyberspace Administration and Public Security Bureau Chongqing Wanzhou District jointly took enforcement action against a local company, imposing a fine of RMB 50,000 (about USD 7,439) for data and cybersecurity protection deficiencies.
Data System
On July 24, CAC released the National Informatization Report (2025). According to the Report, average processing time for security assessments of cross-border data transfers was less than 30 working days in 2025.
The Ministry of Transport, MIIT, the People's Bank of China and other authorities have successively issued policy documents including the Measures for the Administration of Data Security in Transport Section, the Guiding Opinions on Promoting the High-Quality Development of Internet Infrastructure Resources, and the Notice on Strengthening the Development and Utilization of Data in the Technology Finance Sector, further enhancing China’s framework for data security protection and data utilization.
Overseas
Chinese internet platforms have faced successive regulatory penalties in the EU and South Korea. On July 20, the European Commission fined AliExpress EUR 550 million under the Digital Services Act (DSA) for serious deficiencies in its assessment and mitigation of systemic risks associated with the sale of counterfeit, unsafe, and illegal products on its platform, marking the largest fine imposed since the DSA took effect. On July 23, South Korea’s Personal Information Protection Commission (PIPC) fined TikTok KRW 10.306 billion (about USD 7 million) for collecting users’ behavioral data through third-party tracking tools without obtaining valid consent and linking such data with device identifiers and user accounts for targeted advertising.
Data enforcement actions targeting U.S. companies, among others, have also been carried out in parallel. On July 23, the European Commission imposed fines totaling EUR 890 million on Google under the Digital Markets Act (DMA), including EUR 460 million for favoring its own shopping, hotel, transport and sports services over rival offerings in Google Search results, and EUR 430 million for restricting app developers from directing users to alternative purchasing channels through Google Play.
On July 30, South Korean telecom operator KT was sanctioned by the PIPC for inadequate management of indoor small-cell base stations, resulting in cyber intrusion and personal data breach. KT was fined a total of KRW 53.979 billion (about USD 39 million). The case was referred to prosecutors.
On July 14, personal genetic testing company 23andMe reached a settlement with the attorneys general of 43 U.S. states, agreeing to pay USD 18 million in connection with a 2023 cyberattack that exposed the genetic information of 6.9 million individuals. The company also committed to implementing additional security measures and strengthening safeguards for consumers’ right to delete their personal data. However, because 23andMe filed for bankruptcy in March 2025, the states’ recovery is constrained by the company’s remaining assets, limiting the amount recoverable to USD 18 million. Separately, on July 23, the Spanish Data Protection Agency found the same data breach affected 2,642 Spanish users and imposed a EUR 2.4 million fine on 23andMe.
On July 3, U.S. AI-powered virtual character chatbot Character.AI was fined EUR 158,000 in Italy. The Italian Data Protection Authority found several compliance issues, including inaccurate information provided to users and delays in conducting a data protection impact assessment. The authority also ordered Character.AI to ensure that its age-verification mechanism operates properly to fulfill its obligations to protect minors.
On July 20, Singapore’s Personal Data Protection Commission issued the Advisory Guidelines on Use of Personal Data in Generative AI Systems. The Guidelines note that, in Singapore, AI platforms generally do not need to obtain consent to use “publicly available” personal data for model training. However, organizations shall must obtain consent by providing “AI-Specific Notifications” when using data originally provided by users for registration or service-use purposes for model training. On the same day, Singapore’s Infocomm Media Development Authority issued the Transparency Guidelines for GenAI Chatbots, which primarily recommend that deployers use a “chatbot info card” to provide users with consolidated information on matters including the chatbot’s intended purpose, safety and limitations, data handling practices, and channels for user feedback and report. Neither set of Guidelines is legally binding.







