China Justice Observer

中司观察

EnglishArabicChinese (Simplified)DutchFrenchGermanHindiItalianJapaneseKoreanPortugueseRussianSpanishSwedishHebrewIndonesianVietnameseThaiTurkishMalay

China Tightens Corporate Personal Data Audit Rules

Thu, 08 May 2025
Categories: China Legal Trends

On 14 Feb. 2025, China’s Cyberspace Administration released the “Measures for the Administration of Personal Information Protection Compliance Audits” (个人信息保护合规审计管理办法, hereinafter the “Measures”), which shall come into force on 1 May 2025. The Measures clarifies corporate obligations in compliance audits to strike a balance between data utilization and personal information protection.

In recent years, China has established a data protection framework through the “Personal Information Protection Law” (个人信息保护法) and the “Regulations on Network Data Security Management” (网络数据安全管理条例), which require companies to conduct regular compliance audits.

The Measures provides detailed implementation guidelines, specifying audit procedures, institutional qualifications, and rectification obligations to enhance the transparency and legality of personal data processing.

The highlights of the Measures are as follows.

  • Companies that process the personal information of more than 10 million individuals shall conduct audits at least once every two years, while other companies can determine a reasonable frequency.
  • If regulatory authorities identify major risks (e.g., data breaches or user rights violations), they may require the company to commission a third-party professional audit.
  • The same professional institution or any of its affiliated institutions or the same person in charge of compliance audits shall not conduct personal information protection compliance audits for the same auditee for three or more times in a row.

 

 

Photo by manos koutras on Unsplash

Contributors: CJO Staff Contributors Team

Save as PDF

You might also like

Beyond the Memorandum: Shanghai Court Enforces Singapore Judgment by Confirming “Reciprocal Consensus” Under China’s New Framework

On January 8, 2025, the Shanghai International Commercial Court recognized and enforced a Singapore High Court monetary judgment in Zhao v Ye (2023) Hu 01 Xie Wai Ren No. 28. It marks the first judicial confirmation of “reciprocal consensus” between China and Singapore under the 2022 reciprocity criteria, based on the China-Singapore Memorandum of Guidance (MOG).

SPC Issues New Rules for Government Information Disclosure Cases

In May 2025, China's Supreme People's Court (SPC) issued a new judicial interpretation, replacing its 2011 predecessor to standardize adjudication of government information disclosure cases and safeguard citizens' right to know by clarifying trial standards, defendant identification, burden of proof, and preventive relief.

China's Top Court Releases Minor Protection Cases

China's Supreme People's Court (SPC) released five typical cases to strengthen holistic judicial protection for minors, exemplifying the "best interests of the child" principle through integrated criminal, civil, and administrative proceedings.

China Enacts Landmark Private Economy Promotion Law

China enacted its landmark first Private Economy Promotion Law, effective May 20, 2025, to guarantee fair competition, streamline market access via a unified negative list, and bolster private enterprises through financing, innovation, and service support.

China Strengthens Criminal IP Protection with New Rules

In April 2025, China’s top court and procuratorate jointly issued a new judicial interpretation to clarify standards for handling criminal intellectual property infringement cases, aiming to strengthen IP protection, particularly in the service sector.