Part of the AI Regulation News hub.
Three Chinese regulators have published interim results of the 2026 personal information protection campaign, including checks on more than 1,000 firms over advertising and profiling disclosures
Read past the app takedown numbers. The second item in this report is a sweep of more than a thousand organisations over one narrow question: whether their privacy notices admit that the data feeds advertising and profiling, and whether users can switch it off.
Bottom line: This is a progress report, not an instrument. It creates no new obligation. What it does is tell you where three regulators have been looking during 2026 and where they say they are going next.
Who this affects: Adtech and growth teams, mobile app publishers, SDK vendors, and the privacy counsel and DPOs who sign off their consent flows and privacy notices in China.
Issue date: Published 19 August 2026 on the CAC website. No deadline attached; the announcement says the campaign continues.
What changed: Nothing in law. The figures are new: more than 20,000 apps and SDKs checked, more than 4,000 pushed through rectification, more than 1,100 publicly named, more than 400 hit with removal or other penalties, and more than 90,000 organisations screened across four named sectors.
Analysis: The advertising item is the one to brief your product team on. It is not about data volume or breach; it is about whether the processing rules say the data is used for advertising and user profiling, and whether a personalised advertising off switch exists. That is a documentation and UI question, and it is cheap to fix before an inspection rather than after.
Primary sources: CAC announcement of interim campaign results (Chinese)
- Instrument (EN)
- The 2026 series of special actions on personal information protection has achieved phased results (announcement)
- Authority
- Cyberspace Administration of China, Ministry of Industry and Information Technology, Ministry of Public Security, working with other departments
- Jurisdiction
- People's Republic of China
- Status
- Published announcement of interim results; the campaign is described as continuing
- Bindingness
- None. An enforcement progress report, not a rule
- Issue date / next deadline
- 19 August 2026; no deadline stated
- Sectors named
- Education, transport, health, finance
- Primary source
- https://www.cac.gov.cn/2026-08/19/c_1788889479389148.htm
The four workstreams
The announcement organises the year's work into four items. The first is volume enforcement on mobile software: more than 20,000 apps and SDKs inspected for how they collect and use personal information, more than 4,000 brought through rectification, more than 1,100 publicly named for unlawful or non-compliant problems, and more than 400 subjected to removal from stores or other penalties.
The second is narrower and, for anyone running monetisation, more useful. The regulators say they inspected and pushed rectification at more than 1,000 enterprises and institutions over problems including processing rules that fail to state clearly that personal information is collected for advertising and user profiling, and the absence of an option to switch personalised advertising off.
Third comes a sector risk screen across education, transport, health and finance, covering more than 90,000 organisations and turning up more than 12,000 hidden problems that were then pushed through rectification. Fourth is the criminal track: intelligence monitoring and enforcement against leakage and resale of personal information, with the announcement singling out punishment of industry insiders.
Why the advertising item matters more than its headline number
A thousand organisations is a small number next to 20,000 apps. It is the specificity that carries the signal. The two defects named are both visible from outside the company: whether the published processing rules itemise advertising and profiling as purposes, and whether a user can find and use an off switch.
That pairing lines up with Article 17 of the draft regulation on large personal information processors that the CAC opened for comment on 7 August 2026, which would require an easily understood and accessible personalised recommendation off switch, an actual stop to the processing once it is used, and a way for users to delete the profile tags built on their characteristics. We note the alignment; we do not claim the announcement was sequenced to support the draft, because the announcement does not say so.
For a compliance team, the practical reading is that the disclosure and the control are being checked as a pair. A notice that mentions advertising while the switch is buried, or a switch that exists while the notice stays silent, is the shape of defect this sweep was looking for.
The insider problem
The fourth item is short but it names its target. Alongside leakage and resale of personal information, the regulators say they severely punished industry insiders, meaning employees who sell data out of the organisations that hold it.
No case numbers, defendants or outcomes appear in the announcement. If you need those, this page will not give them to you.
What it does support is a control question worth asking internally: who inside your organisation can export personal information at volume, and would you know within a day if they did.
Where the regulators say they are going
The closing paragraph lists four forward commitments: deepen the special actions, strengthen governance of typical violations, accelerate promotion and application of the national network identity authentication public service, and deepen public education on personal information protection.
The national network identity authentication service is worth flagging because it also appears in the 7 August draft, which permits large processors to apply it under Article 5 and requires it, among other methods, for identifying minors under Article 32. Two documents twelve days apart both pointing at the same public service is a reasonable thing to notice.
None of this is a deadline. Read it as a statement of direction and plan your own timetable accordingly.
What we did not verify
We opened and read the CAC announcement at cac.gov.cn dated 19 August 2026 in full. Every figure above is taken from that page, including the more than 20,000, 4,000, 1,100, 400, 1,000, 90,000 and 12,000 counts and the four named sectors.
We did not open the underlying notification lists, the app removal orders, or any MIIT or MPS publication of the same campaign. We did not identify a single named company, because the announcement names none.
We do not claim any causal link between this announcement and the 7 August draft regulation, and we do not claim the campaign has a stated end date. The announcement describes phased results and says the work continues.
The cheap defect to fix this quarter is the advertising disclosure pair: state in the processing rules that personal information is collected and used for advertising and user profiling, and give users a personalised advertising off switch they can actually find. More than a thousand organisations were checked on exactly that in 2026. Nothing in this announcement changes the law, but it tells you what a Chinese inspector opens first.
Source File
https://www.cac.gov.cn/2026-08/19/c_1788889479389148.htm
Open the CAC announcement at cac.gov.cn dated 19 August 2026 and confirm the four numbered workstreams, the counts attached to each, and that the second workstream is specifically about processing rules failing to state advertising and user profiling purposes and about missing personalised advertising off switches.
In response to problems such as personal information processing rules not making clear that personal information is collected for advertising and user profiling, and the failure to provide an option to turn off personalised advertising, relevant products of more than 1,000 enterprises and institutions were inspected and pushed to rectify. ยท CAC, MIIT and MPS, 19 August 2026 (TLY translation of the Chinese original)
FAQ
Is this announcement enforceable against my company?
No. It reports what enforcement has already happened under existing law. The obligations sit in the Personal Information Protection Law and its implementing rules, not in this page.
Does it name any companies?
No. The announcement gives aggregate counts only. If you need the list of publicly named apps and SDKs, you would have to go to the separate notification batches, which we did not open.
What does the personalised advertising point actually require today?
The announcement does not state a requirement; it describes a defect the regulators inspected for. The related obligations sit in the Personal Information Protection Law's rules on automated decision-making and on informed consent, and a fuller version appears in Article 17 of the CAC draft opened for comment on 7 August 2026, which is not yet binding.
Which sectors were screened?
Education, transport, health and finance, across more than 90,000 enterprises and institutions, with more than 12,000 hidden problems found and rectified.
Related briefings
Sponsored Training
Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.