The Cyberspace Administration of China has put out for comment a draft regulation that would designate large personal information processors and force each one to seat an outside-majority supervision committee

CAC Drafts Rules for Large Personal Information Processors. The Leveraged Years regulation briefing card.

The headline number is 10 million data subjects. The provision that will cost the most to implement is the one requiring an outside-majority supervision committee that can report you to the provincial regulator.

The short version

Bottom line: Not binding. This is a draft circulated for public comment, and the effective-date clause in Article 50 is still blank. Nobody is obliged to do anything under it yet.

Who this affects: Data protection officers, in-house privacy counsel and compliance leads at Chinese platform operators, and at foreign groups whose China entities process data on large user populations.

Issue date: Dated 7 August 2026 by the CAC. Comments close 7 September 2026, by email to shujuju@cac.gov.cn or by post to the Network Data Management Bureau.

What changed: Two earlier drafts, one on supervision committees at large network platforms and one on personal information protection at large network platforms, have been merged and reworked into a single 50-article instrument covering large processors generally rather than platforms specifically.

Analysis: Article 14 does not merely say store the data in China. It says the data centre management body's legal representative or actual controller must hold PRC nationality. That is a condition on who runs the infrastructure, and it is a different kind of requirement from data localisation.

Primary sources: CAC consultation notice and full draft text (Chinese)

Instrument (EN)
Regulations on Personal Information Protection by Large Personal Information Processors (draft for comment)
Authority
Cyberspace Administration of China, with the State Council telecommunications department and public security department named as co-regulators
Jurisdiction
People's Republic of China
Status
Public consultation draft, 50 articles across six chapters, plus an annex of drafting guidance for supervision committee working rules
Bindingness
None. Draft text with an unfilled commencement date
Issue date / next deadline
Issued 7 August 2026; comments due 7 September 2026
Legal basis cited
Personal Information Protection Law; Network Data Security Management Regulations
Primary source
https://www.cac.gov.cn/2026-08/07/c_1787851071612596.htm

Who counts as large

Article 2 sets out three conditions to be weighed together: processing the personal information of 10 million or more natural persons; providing an important network service that involves personal information processing, or operating across multiple lines of business that involve it; and having a processing operation that materially affects national security, economic operation, social stability, or public health and safety.

The mechanism in Article 3 is self-declaration with a backstop. A processor that handles data on 10 million or more people and that self-assesses as meeting the second or third condition files through its provincial cyberspace department. The province has 15 working days to check the filing is complete, then passes it up with a preliminary opinion. If a processor that appears to qualify does not come forward, the provincial authorities are told to press it to file.

The national CAC then settles a list of large personal information processors and publishes it. There is an exit route: a designated processor that believes it has fallen below the conditions for six consecutive months may apply to have the designation changed.

The supervision committee

Chapter 4 is the part with no close analogue elsewhere. Within six months of designation, a large processor must stand up a personal information protection supervision committee composed mainly of outsiders, adopt working rules for it, and report the committee's composition and rules up through the province.

The composition rules are specific. An odd number of members, no fewer than seven, with external members at not less than two thirds. The chair must be an external member with senior compliance audit capability. External members need at least three years of relevant work, may serve at no more than three designated processors at once, and are subject to a security background check for which the company may ask the police for help.

Independence is defined by exclusion. Anyone who in the past year worked at the company, or is a close relative of someone who did, is out. So is anyone holding one percent or more of issued shares directly or indirectly, anyone in the top ten individual shareholders and their close relatives, and staff of shareholder entities holding five percent or more or sitting in the top five shareholders.

Localisation, and who may run the data centre

Article 13 requires personal information collected and generated in domestic operations to be stored in China. Article 14 then narrows the field of eligible data centres to those established in China, meeting relevant national policy and standard requirements, and whose management body's legal representative or actual controller holds PRC nationality.

Article 15 loads the data centre management body itself with duties: an incident response plan, immediate remediation and notification when a defect or vulnerability affecting the processor's obligations is found, and direct reporting to the CAC, telecoms and public security authorities when an incident occurs. Where the function is outsourced, Article 16 requires a written contract fixing purpose, term, method, storage location, scale, categories and protective measures, and requires the contractor to comply with Articles 14 and 15.

Article 44 gives the regulators a remedy worth reading twice. Where a processor fails to rectify, the CAC and the telecoms, public security and state security departments may require it to take measures including placing personal information in the custody of a third-party data centre.

The recurring duties

Portability gets a clock. Under Article 19, for a transfer request meeting Article 25 of the Network Data Security Management Regulations, the processor has 30 working days from identity and request verification to move the data in a common or machine-readable format, extendable by a further 30 working days with reasons given. Where the request count is plainly beyond reasonable range, the processor may charge a published, cost-based fee.

Article 31 requires a prior impact assessment before launching any product, service or function involving automated decision-making or sensitive personal information processing, and filing of the assessment report with the national CAC through the province within 15 working days of completion. Article 33 sets a compliance audit at least once every two years and a risk assessment annually.

Article 30 requires an annual personal information protection social responsibility report, published in the first half of the following year, disclosing among other things the supervision committee's performance and the allowance standard paid to its external members. Retention rules sit in Article 28: processing and permission approval records for at least six months, impact assessment reports and handling records for at least three years.

Article 17 addresses recommendation systems directly. A processor using automated decision-making to push content or market commercially must give an accessible off switch, must stop using the relevant personal information for personalised recommendation once the user switches it off, and must let users delete the profile tags built on their characteristics.

The reporting line inside the company

Article 25 requires the personal information protection officer to be a member of management, with contact details published. Article 26 then gives that person a route around their own employer.

Where the officer raises a compliance objection to a processing decision and the company declines to act on it without proper reason, or acts in a way that breaks the law, the officer may report directly to the provincial cyberspace department. The same escalation appears at committee level: if the board leaves a committee resolution's compliance points unaddressed, the committee may report to the province.

That escalation route is what separates this design from a purely advisory body, though the draft itself makes no claim about how effective the committee will be. Whether it works in practice depends on the allowance and removal provisions, which the draft leaves for each company's board to approve.

What we did not verify

We opened and read the CAC consultation notice at cac.gov.cn dated 7 August 2026, including the full 50-article draft text and the annexed drafting guidance for supervision committee working rules. All figures, article numbers, deadlines and thresholds above come from that page.

We did not open the two earlier drafts that this text consolidates, so we cannot say which provisions are carried over unchanged and which are new. We did not open any English translation, and we did not check whether any trade press summary matches ours.

We do not claim the draft will be adopted, adopted in this form, or adopted on any particular date. Article 50 leaves the commencement date blank and we refuse to guess it. We also make no claim about which companies would land on the published list.

Key compliance takeaway

If your China entity is anywhere near 10 million data subjects, the work that takes longest is not the paperwork. It is finding seven or more people who satisfy the independence test in Article 39, are not already serving three designated processors, and will sit on a committee with a statutory line to the provincial regulator. Start the search while the text is still a draft, and read Article 14 with your infrastructure team rather than only with counsel.

Source File

https://www.cac.gov.cn/2026-08/07/c_1787851071612596.htm

Open the CAC notice at cac.gov.cn dated 7 August 2026 and confirm three things: the 7 September 2026 comment deadline in the covering notice, the three designation conditions in Article 2 including the 10 million figure, and the committee composition rule in Article 37 requiring no fewer than seven members with external members at not less than two thirds.

Large personal information processors shall store personal information collected and generated in the course of operations within the territory of the People's Republic of China domestically. ยท Article 13, draft Regulations on Personal Information Protection by Large Personal Information Processors, CAC, 7 August 2026 (TLY translation of the Chinese original)

FAQ

Does the 10 million figure by itself make my company a large personal information processor?

No. Article 2 lists three conditions to be weighed together, and Article 3 asks a processor at or above 10 million people to self-assess against the second and third as well before filing. Designation is settled by the national CAC, which publishes a list.

Is there a penalty regime in this draft?

Not a new one. Article 47 routes violations back to the Personal Information Protection Law, the Public Security Administration Punishments Law and the Network Data Security Management Regulations. What the draft adds are supervisory measures in Article 44: on-site inspection, regulatory interviews, mandatory rectification, pressing the processor to dissolve the committee, and third-party custody of the data.

Can a foreign national sit on the supervision committee?

The draft does not say. Article 38 and Article 39 set conditions on independence, experience, reputation and background checks but do not mention nationality. The nationality condition in the draft applies to the data centre management body's legal representative or actual controller, under Article 14, not to committee members.

The comment window closes on 7 September 2026. Is it worth filing?

That is a judgement call we cannot make for you. What we can say is that the notice gives two channels, an email address and a postal address, and asks that posted submissions be marked on the envelope with the consultation name.

Sponsored Training

Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.

."}}]}