China’s cyberspace regulator on August 7 released draft rules that would force major personal-data handlers — including foreign companies with large China user bases — to install independent oversight committees, name senior privacy officers, and disclose more about third-party data collection tools. If your business processes personal data of more than 10 million people in China, this draft is written directly for you, and the public comment window closes September 7.
Why It Matters
The draft, published by the Cyberspace Administration of China (CAC, 国家互联网信息办公室), extends the governance apparatus built under the Personal Information Protection Law (PIPL). Since PIPL took effect in November 2021, foreign companies have already been subject to China’s data rules wherever they operate — PIPL applies extraterritorially to any organization processing the personal data of people in China. What is new here is structural: Beijing wants large processors to hand a meaningful share of privacy governance to outsiders.
That changes your compliance burden in three concrete ways. First, the threshold — 10 million people — is broad enough to catch many multinationals: consumer apps, e-commerce, connected devices, and B2B platforms with Chinese user bases all qualify. Second, an independent committee is not a formality; it requires recruiting external experts who meet independence criteria and giving them real oversight powers. Third, the draft retains a reporting channel for violations to authorities, which means employees and committee members have a direct line to regulators that bypasses your internal chain of command.
This is the same regulatory lane where the CAC has been most active in 2026 — platform governance, data rules, and AI accountability. It sits alongside the anti-cyberbullying law draft, which targets platforms with fines of up to ¥10 million, and the AI content labeling rules foreign tech companies are already implementing.
The Details
Under the draft, large data processors must establish a privacy oversight committee of at least seven members, with external members making up two-thirds of seats and meeting strict independence criteria. The committee’s remit covers data-collection and privacy practices — the CAC’s stated goal is independent scrutiny of how major technology companies handle personal information.
Notably, the latest version of the draft removes a contentious provision from an earlier iteration that would have given the data-protection officer (DPO) veto power over corporate data-processing decisions. The DPO loses the veto, but the obligation to report violations to regulators remains — a design that keeps accountability on the company while limiting a single internal role’s ability to block business decisions.
Two other requirements matter for implementation. Companies must name senior privacy officers, which raises the governance profile of the role beyond the DPO requirement PIPL already imposes on large processors. And they must disclose more about third-party data collection tools — meaning the SDKs, analytics libraries, and ad-tech integrations running inside your China-facing apps and websites become part of the regulatory record.
The timeline is short by Chinese regulatory standards: the draft was released August 7, comments are open through September 7, and final rules typically follow within months. For context on how far the data-compliance architecture has already come, our earlier breakdown of China’s cybersecurity law compliance requirements covers the baseline every foreign company already operates under.
What You Should Do
- Determine whether you are a “large data processor.” The 10-million-person threshold is the trigger. If you run consumer apps, e-commerce, or device fleets in China, assume you qualify until counsel says otherwise.
- Start scouting external committee members now. Two-thirds external seats with independence criteria means qualified candidates — academics, former regulators, privacy professionals — will be in short supply across the industry. Early is cheaper.
- Map your third-party data tools. Every SDK and analytics integration touching personal data becomes disclosable. You do not want to discover your exposure during the comment-period scramble.
- File a comment before September 7. The draft is open for public input, and foreign industry associations have successfully shaped CAC rulemaking before. This is your window to raise feasibility concerns.
- Coordinate with your AI compliance work. If you are already implementing China’s AI content labeling rules, the same data-governance owners should own this response.
One Data Point
The number to remember: 10 million — the personal-data threshold that would trigger the independent privacy oversight committee requirement, and roughly the size of a mid-tier consumer app’s China user base.
Where to Go From Here
Based on what you just read:
- Ready to act? Read China’s Cybersecurity Law: A Compliance Guide for Foreign Companies
- Still comparing? See China’s AI Content Labeling Rules — Compliance Guide for Foreign Tech Companies
- Need context? Try China’s Draft Anti-Cyberbullying Law: Fines Up to ¥10 Million Target Tech Platforms
— China Gateway 360 —
Remote China market entry support, built around execution.
