Cybersecurity Policy Report, Recommendations for Personal Information Protection Measures Offered in China, (Aug 14, 2026)
By Tony Foley
The Cyberspace Administration of China (CAC) has issued a series of questions and answers designed to guide personal information processors in properly handling public data and implementing appropriate security measure as required by the Personal Information Protection Law (PIPL).
Publicly available personal information. The guidance notes that PIPL article 27 permits the processing of personal information that an individual has voluntarily disclosed or that has been lawfully disclosed within a reasonable scope unless the individual expressly refuses to allow the processing. In cases where the processing of disclosed personal information has a significant impact on an individual’s rights or interests, the processor must obtain the individual’s consent.
Article 12 of the appendix to the “Administrative Measures for Compliance Audit of Personal Information Protection" outlines circumstances under which publicly disclosed personal information is handled illegally or in violation of regulations, including sending commercial information unrelated to the purpose of disclosure to e-mail addresses or mobile phone numbers, using publicly disclosed personal information to engage in cyberbullying, spreading online rumors, and disseminating false information, or collecting, retaining, or processing publicly disclosed personal information on a scale, for a period of time, for a purpose that exceeds a reasonable scope.
Personal information leaks. The Q&A document says that the most common causes of personal information leaks include storing and transmitting information in plain text without appropriate encryption, failing to implement appropriate security measures for databases containing personal information, and a lack of effective identity verification measures in data interfaces accessible via the Internet. PIPL article 51 specifies the steps that processors must take to ensure that processing complies with the law, including the following:
Formulating internal management systems and operating procedures;
Implementing classified management of personal information;
Adopting corresponding security technical measures like encryption and de-identification;
Reasonably determining the operating authority for personal information processing;
Formulating and organizing the implementation of emergency plans for security incidents; and
Other measures stipulated by law and administrative regulations.
News: InternationalLegislation DataSecurity DataBreach DataPrivacy