China’s Cyberspace Administration is consulting on a 50 article draft that would impose tighter privacy governance on large personal information handlers; comments are due 7 September 2026, and the rules are not yet i... The proposal combines a more than 10 million person threshold with broader tests based on the im...
Research answer

Create a landscape editorial hero image for this Studio Global article: What does China’s Cyberspace Administration propose in its 50-article draft regulation on large platforms’ handling of personal information—. Article summary: China’s Cyberspace Administration (CAC) is consulting on a 50-article draft, the *Provisions on Personal Information Protection for Large Personal Information Handlers*. It consolidates two earlier proposals and is not y. Topic tags: general, general web. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clic
China’s Cyberspace Administration of China (CAC) has opened consultation on a 50-article draft titled the Provisions on Personal Information Protection for Large Personal Information Handlers. Published on 7 August 2026, the proposal consolidates two earlier CAC consultation texts and is not yet effective law.
The draft is aimed at organizations that process personal information at very large scale or whose activities could have significant effects on China’s national security, economy, society, public health or safety. Its practical impact would extend beyond day-to-day data collection: covered organizations would face new registration, storage, cross-border-transfer, reporting and independent-oversight expectations.
Comments must reach the CAC by 7 September 2026. Responses can be sent by email to shujuju@cac.gov.cn or by post to the CAC’s Network Data Management Bureau at 15 Fucheng Road, Haidian District, Beijing 100048. Postal submissions should identify the consultation on the envelope.
Because this is a draft for public comment, organizations should treat its requirements as proposed obligations rather than final compliance duties. Article 50 leaves the effective date blank.
The draft uses a comprehensive assessment rather than relying solely on a numerical threshold. Relevant factors include whether an organization:
Organizations processing information about more than 10 million people, as well as those that assess themselves as meeting the broader criteria, would need to apply for designation through the CAC at the provincial level. The national CAC, together with other relevant authorities, would determine and publicly announce the list. Authorities could also require an organization that appears to qualify but has not applied to complete the process.
This means the proposal could reach some influential platforms even where the organization’s user count alone does not settle the question.
The draft would give the national cyberspace regulator the ability to publicly list foreign organizations or individuals whose personal-information processing activities infringe the rights of Chinese citizens or endanger China’s national security or public interest. Listed entities could face restrictions or bans on receiving personal information from China.
The provision creates a potential compliance consequence for overseas recipients, not only for the Chinese platform transferring the data. It also makes the risk assessment around cross-border data flows broader than a conventional privacy review.
Covered handlers would be expected to process personal information according to the principles of legality, propriety, necessity and good faith. Collection would need to be limited to information necessary for the relevant product or service and could not be excessive.
Where consent is the legal basis, the draft would require separate consent for several higher-risk activities, including:
A change to the purpose, method or categories of processing would require renewed consent. The draft also calls for a convenient way for individuals to withdraw consent.
For children under 14, processing would require consent from a parent or other guardian, supported by an accessible mechanism for granting or withdrawing that consent.
Personal information collected or generated through operations in China would have to be stored within China. The data center would need to be located in China and comply with applicable national policies and standards. Its management body’s legal representative or actual controller would also need to be a Chinese citizen.
The proposal places responsibilities on data-center operators as well. They would be expected to maintain internal controls and incident-response plans, identify and fix security weaknesses, notify the platform and authorities where required, and assist with breach response.
For companies using external infrastructure providers, this would make data-center selection, contracting and operational oversight central parts of the compliance program rather than purely technical or procurement decisions.
The domestic-storage rule would not automatically eliminate every outbound transfer. The draft contemplates cross-border provision where it is genuinely needed for business, but requires the organization to follow China’s applicable export mechanisms and obtain the required separate consent.
In practice, large handlers would need to distinguish between storing data in China and providing data to an overseas recipient. The former would be the baseline storage requirement; the latter would trigger additional legal and procedural controls.
The draft would require a more formal privacy-compliance structure, including a personal-information-protection officer drawn from senior management. Reporting on the proposal also describes conditions for that role, including Chinese nationality, no foreign permanent-residency or long-term-residence status, professional personal-information-protection knowledge and relevant experience.
Other proposed governance measures include:
The draft also emphasizes dedicated safeguards for minors, including practical parental-consent and withdrawal processes.
Each covered handler would establish a personal-information-protection supervisory committee to oversee its data-handling practices independently.
The proposed committee would have to:
External members would need to be independent, reputable and experienced in relevant compliance work. They would generally be limited to serving no more than three large handlers at the same time.
The committee’s responsibilities would include supervising compliance and significant personal-information-protection matters, reviewing policies and high-risk processing, issuing opinions or recommendations, and supporting accountability through reporting and oversight arrangements. The handler would also need to provide sufficient resources for the committee to operate.
This is more than a requirement to appoint a privacy officer. It would create a separate oversight layer dominated by outside members and give privacy governance a formal place in the organization’s accountability structure.
The immediate action is to assess whether the organization could meet either the scale threshold or the broader importance-and-impact criteria, then prepare comments before the 7 September deadline. Companies that may fall within scope should also map:
The proposal remains subject to change. Its direction, however, is clear: China is considering a system that treats the largest and most consequential data handlers as organizations requiring heightened operational controls, domestic infrastructure, senior-level accountability and external privacy oversight.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
China’s Cyberspace Administration is consulting on a 50 article draft that would impose tighter privacy governance on large personal information handlers; comments are due 7 September 2026, and the rules are not yet i...
China’s Cyberspace Administration is consulting on a 50 article draft that would impose tighter privacy governance on large personal information handlers; comments are due 7 September 2026, and the rules are not yet i... The proposal combines a more than 10 million person threshold with broader tests based on the importance and societal impact of an organization’s services.
Major obligations would include domestic storage, stricter consent controls, senior level privacy accountability and an oversight committee with at least seven members, at least two thirds of them external.