AI Regulation Tracker / China / Binding law
China's simplified track for small data processors does not exempt automated decisions
CAC and the Ministry of Public Security jointly promulgated Order No. 25 on July 24, 2026. It lightens the paperwork for processors handling fewer than 100,000 people's data. It does not lighten anything about algorithmic decisions.
What did CAC and the Ministry of Public Security actually issue?
A joint order. The pairing tells you who will be knocking. CAC writes most of the data rules. The Ministry of Public Security has police powers and provincial reach into small merchants. When both sign, the track is not academic.
The signature block sets the dates:
《小型个人信息处理者个人信息保护简化措施规定》已经2026年6月26日国家互联网信息办公室2026年第14次室务会会议审议通过,并经公安部同意,现予公布,自2026年9月1日起施行。The Provisions on Simplified Personal Information Protection Measures for Small Personal Information Processors were reviewed and adopted at the 14th executive meeting of the Cyberspace Administration of China in 2026 on 26 June 2026, and agreed to by the Ministry of Public Security. They are hereby promulgated and shall take effect on 1 September 2026.Order No. 25, signature block
Five weeks of lead time from publication, which is short by the standards of any US compliance calendar.
Who counts as a small personal information processor?
Article 2 gives a single arithmetic test:
本规定所称小型个人信息处理者,是指处理不满10万人个人信息的个人信息处理者。For the purposes of these Provisions, a "small personal information processor" means a personal information processor that processes the personal information of fewer than 100,000 persons.Order No. 25, Article 2
Not employee count. Not revenue. Not entity size in any Western sense. The measure is the number of natural persons whose personal information the processor handles. A twelve-person consumer app can blow past 100,000 data subjects in a quarter. A 400-person industrial supplier with a handful of corporate contacts may sit under the line for years.
For a US company the counting boundary is the first real work. Registered users, prospects in a database, employees and their dependants, delivery recipients, and end customers of a hosted merchant are all natural persons. Anyone who has run a GDPR Article 30 exercise knows how fast the number moves once you stop counting accounts and start counting people.
The relief for those who qualify is procedural: a self-check list audit on a multi-year cycle, and a form-based impact assessment rather than a bespoke one. Platform operators that host small merchants do not get to look away. They carry platform-level processing rules and audit and assessment duties covering the processors they host.
What survives the simplification?
Automated decision-making. That is the point of the instrument for anyone reading it from an AI angle, and the opposite of what a busy founder would assume from a document titled "simplified measures".
Annex 1 item 8 sets out what the audit must examine when automated decision-making is in play:
对利用自动化决策处理个人信息进行合规审计的,应当重点审查下列事项:(一)自动化决策的透明度,以及自动化决策的结果是否公平、公正;(二)是否事前告知个人自动化决策处理个人信息的种类及可能带来的影响;(三)是否事前进行个人信息保护影响评估;(四)是否向用户提供保障机制,以便个人通过便捷方式拒绝通过自动化决策方式作出对个人权益有重大影响的决定…Where a compliance audit is conducted of the processing of personal information by automated decision-making, the following matters shall be examined as a priority: (1) the transparency of the automated decision-making and whether its outcomes are fair and just; (2) whether the individual was informed in advance of the categories of personal information processed by automated decision-making and the possible impacts; (3) whether a personal information protection impact assessment was carried out in advance; (4) whether a safeguard mechanism is provided so that individuals can conveniently refuse decisions made by automated decision-making that significantly affect their rights and interests…Order No. 25, Annex 1, item 8
Read item (3) again. The audit checks whether an impact assessment was done in advance, and Annex 2 item 2 keeps automated decision-making inside the assessment itself. The two annexes lock together. A processor that skipped the assessment believing the simplified track excused it fails the audit on that exact point.
The four items map onto product decisions, not paperwork. Transparency and fair outcomes are design questions. The refusal mechanism has to be convenient, which is an interface question. None of it is satisfied by a policy document in a drawer.
How does this compare with the EU and US state rules?
Small-entity relief exists in most modern privacy regimes. Almost none of it reaches algorithmic decisions. Order No. 25 makes that pattern explicit.
| Regime | Small-entity threshold or relief | Form of relief | Automated decisions carved out of the relief? |
|---|---|---|---|
| China, Order No. 25 (CAC and MPS) | Fewer than 100,000 persons whose personal information is processed (Article 2) | Self-checklist audit and form-based impact assessment | No relief. Annex 1 item 8 makes automated decision-making a priority audit item, Annex 2 item 2 keeps it in the impact assessment |
| EU, GDPR Article 22 | No size threshold for Article 22. The main size-based relief is the Article 30(5) records exemption under 250 employees, itself subject to carve-outs | Records of processing only | Not applicable. Rights over solely automated decisions with legal or similarly significant effects do not turn on size |
| EU AI Act | Microenterprise and SME accommodations, including simplified technical documentation | Documentation format, not scope of duty | No. High-risk classification and its duties do not turn on company size |
| US, Colorado Privacy Act | 100,000 consumers per calendar year, or 25,000 where the controller derives revenue from selling personal data | Below the threshold, the Act does not apply at all | No separate small-entity relief above the threshold. Profiling in furtherance of decisions with legal or similarly significant effects carries an opt-out and an assessment duty |
Note the coincidence between China and Colorado. Both use 100,000 people, which makes the pair easy to conflate. They are not the same test. In Colorado the threshold decides whether the statute applies at all. In China it decides only which procedure you follow, because the Personal Information Protection Law applies either way.
Only the China row traces to the primary source opened for this piece. The EU and US rows are orientation and should be checked against their own texts.
What should a US company with Chinese users do before September 1?
Two questions, in this order. The second one is what catches people.
First, count the people. Produce a defensible number of natural persons whose personal information the business processes in connection with China, and write down the counting method. Above 100,000, the simplified track is unavailable and the ordinary Personal Information Protection Law posture applies. Near the line, treat the line as movable, because it is.
Second, inventory the automated decisions. Pricing engines, credit and risk scoring, fraud screening, ranking systems that affect what a user sees or can buy, resume screening, and any model output that gates access to a service. For each, ask whether it makes a decision that significantly affects an individual's rights and interests. Where the answer is yes, the four items in Annex 1 item 8 are the checklist, and the impact assessment has to exist before the processing, not after the auditor asks.
Selling through a Chinese platform adds a third item. The platform carries audit and assessment duties reaching the merchants it hosts, so expect it to ask for evidence about your processing.
The judgment worth keeping in human hands is the significance test. Whether a given automated decision significantly affects rights and interests is not something a compliance tool settles for you, and it is the call that carries the consequence if it goes wrong.
What this order does not do
It does not exempt small processors from the Personal Information Protection Law. It does not create an AI-specific licensing regime. It does not set new penalty levels of its own. And on the text quoted above it does not relieve any processor of the substance of the automated decision-making duties. The relief runs to the form of the audit and the assessment, not their subject matter. Reading the title as a general AI exemption gets it wrong.
Frequently asked questions
What is a small personal information processor under Order No. 25?
Article 2 defines it as a processor that handles the personal information of fewer than 100,000 persons: 本规定所称小型个人信息处理者,是指处理不满10万人个人信息的个人信息处理者。The count of data subjects, not headcount or revenue, is the test.
Does the simplified track exempt small processors from automated decision-making duties?
No. Annex 1 item 8 keeps automated decision-making inside the compliance audit as a priority review item, and Annex 2 item 2 keeps it inside the impact assessment. The simplification goes to the form of the audit, not its subject matter.
What does the audit have to examine when a small processor uses automated decision-making?
Annex 1 item 8 lists four priority matters: transparency and whether outcomes are fair and just; prior notice to the individual of the data categories used and the possible impacts; a prior personal information protection impact assessment; and a safeguard mechanism letting individuals conveniently refuse automated decisions that significantly affect their rights and interests.
Last verified: July 28, 2026