HomeFounders News › Regulations
Regulations China Jul 24, 2026

China cuts data-compliance load for small processors, effective Sept 1, 2026

China cuts data-compliance load for small processors, effective Sept 1, 2026

The CAC and Ministry of Public Security jointly issued the Simplified Personal Information Protection Measures for Small-Scale Processors, published July 24, 2026 and effective September 1, 2026. It applies to processors handling personal information of fewer than 100,000 individuals, and streamlines disclosure, user notice, consent, deletion and impact-assessment duties. Qualifying small processors are also exempted from all three cross-border transfer routes: the data-export security assessment, the standard contract, and personal information protection certification.

Why this matters for founders

An early-stage founder whose app or SaaS touches under 100,000 users can drop the heavy PIPL cross-border filing and simplify consent and notice flows, cutting legal and audit spend; use the regulation's self-check compliance-audit table to document eligibility before shipping.

Source: Cyberspace Administration of China (CAC)

Related updates

More that helps you.

Get briefs like this tuned to you.

In the app, Founder Briefs are personalized to your country, industry and stage, and you can save the ones that matter.

See plans →
FoundersCheckList.AI app
Founders using FoundersCheckList.AI