China Justice Observer

中司观察

EnglishArabicChinese (Simplified)DutchFrenchGermanHindiItalianJapaneseKoreanPortugueseRussianSpanishSwedishHebrewIndonesianVietnameseThaiTurkishMalay

China Tightens Corporate Personal Data Audit Rules

Thu, 08 May 2025
Categories: China Legal Trends

On 14 Feb. 2025, China’s Cyberspace Administration released the “Measures for the Administration of Personal Information Protection Compliance Audits” (个人信息保护合规审计管理办法, hereinafter the “Measures”), which shall come into force on 1 May 2025. The Measures clarifies corporate obligations in compliance audits to strike a balance between data utilization and personal information protection.

In recent years, China has established a data protection framework through the “Personal Information Protection Law” (个人信息保护法) and the “Regulations on Network Data Security Management” (网络数据安全管理条例), which require companies to conduct regular compliance audits.

The Measures provides detailed implementation guidelines, specifying audit procedures, institutional qualifications, and rectification obligations to enhance the transparency and legality of personal data processing.

The highlights of the Measures are as follows.

  • Companies that process the personal information of more than 10 million individuals shall conduct audits at least once every two years, while other companies can determine a reasonable frequency.
  • If regulatory authorities identify major risks (e.g., data breaches or user rights violations), they may require the company to commission a third-party professional audit.
  • The same professional institution or any of its affiliated institutions or the same person in charge of compliance audits shall not conduct personal information protection compliance audits for the same auditee for three or more times in a row.

 

 

Photo by manos koutras on Unsplash

Contributors: CJO Staff Contributors Team

Save as PDF

You might also like

China Strengthens Criminal IP Protection with New Rules

In April 2025, China’s top court and procuratorate jointly issued a new judicial interpretation to clarify standards for handling criminal intellectual property infringement cases, aiming to strengthen IP protection, particularly in the service sector.

SPC’s 2024 Typical IP Cases Include AI Face-Swap Ruling

In April 2025, China’s Supreme People’s Court released eight typical IP cases, highlighting judicial responses to emerging issues in AI, gaming, and biotech, including a landmark ruling on AI face-swapping copyright infringement.

China Eases Tax Refunds to Boost Inbound Tourist Spending

In 2025, China has lowered its departure tax refund threshold from 500 RMB to 200 RMB and doubled cash refund limits to 20,000 RMB while expanding eligible stores and streamlining processes, aiming to boost inbound tourism spending and promote Chinese products.

Chinese Courts Bolster Pregnant Workers' Rights Protection

In April 2025, China's Ministry of Human Resources and Supreme People's Court released typical labor dispute cases emphasizing stronger protection of pregnant employees' rights, including a case where unlawful job reassignment and salary reduction were ruled illegal.

China Revises Marriage Registration Regulation

China's revised marriage registration rules, effective May 2025, eliminate location restrictions, simplify procedures by removing hukou requirements, and align divorce processes with the Civil Code's cooling-off period.

China’s SPC Issues Foreign State Immunity Case Guidelines

In March 2025, China's Supreme People's Court (SPC) issued procedural guidelines for handling civil cases involving foreign state immunity, implementing the country's shift from absolute to restrictive immunity under the new Foreign State Immunity Law.

SPC Issues Prepaid Consumption Rules & Typical Cases

In March 2025, China’s Supreme People’s Court (SPC) issued a judicial interpretation and six guiding cases to tackle prepaid consumption disputes, invalidating unfair terms, protecting consumer refunds, and penalizing merchants who abscond with prepayments.