100,000 People: A New Compliance Threshold
Starting September 1 this year, the "Simplified Measures for Personal Information Protection by Small-Scale Personal Information Processors" officially came into effect. Jointly issued by the Cyberspace Administration of China and the Ministry of Public Security, the 22-article document implements Article 62 of the Personal Information Protection Law: to uphold the bottom line of personal information security while reducing compliance costs for small and medium-sized enterprises.
What is "small-scale"? It refers to processors who handle personal information of fewer than 100,000 individuals. The number is exclusive, calculated based on the cumulative total of natural persons currently processed, excluding those already deleted. Therefore, most small and medium-sized enterprises and individual businesses fall below this threshold.
The simplified content is divided into three parts.
Part One: Processing Rules and Informed Consent.
Rules must clearly state at least four things: the name, contact information for exercising rights, the purpose and method of processing, and the types of information and retention periods. Posting notices offline, or placing service agreements, pop-ups, or website announcements online, all count as public disclosure.
There are also two "piggyback" channels: parks and commercial properties can uniformly formulate rules for similar merchants, and listed merchants do not need to write their own; for those operating solely on online platforms, if the platform has already published rules, conducted audits, and impact assessments, merchants do not need to repeat them.
But two bottom lines remain unchanged: if personal information of minors under 14 is involved, special rules must be formulated; processing sensitive personal information still requires separate consent.
Part Two: Compliance Obligations.
The Measures directly attach a self-inspection form and an assessment form; just fill them out accordingly. Audits must be conducted at least once every five years, with the two forms retained for five and three years respectively. Those who have obtained personal information protection certification are exempt from audits during the validity period.
Two more points: if information needs to be transferred due to merger, division, dissolution, bankruptcy, the receiving party must be publicly notified 30 working days in advance, with the notice displayed for no less than 30 working days; if services cease, personal information must be deleted, and if truly unable to delete, one can report to the cyberspace administration for assistance.
Part Three: Cross-Border Data Transfers.
Cross-border shopping, delivery, remittance, ticket and hotel booking, visa applications necessary for contracts, cross-border human resource management conducted in accordance with law, emergency situations, performance of legal duties, and cases where the cumulative annual outbound transfer involves fewer than 100,000 individuals and does not include sensitive information, are all exempt from security assessment filing, standard contract signing, and certification. However, important data is not included, and notification and separate consent obligations still apply.
Finally, the regulatory side.
If violations are minor, corrected in a timely manner, and cause no harmful consequences, no penalty will be imposed; for first-time violations with minor consequences that are promptly corrected, penalties may also be waived, but the violator may be summoned for talks or receive a reminder letter. Those who proactively remedy, promptly notify, and report will receive lighter or mitigated penalties.
But simplification does not mean exemption from liability. The cyberspace administration and public security may conduct spot checks, assessments, and review audit reports; illegal processing of personal information or repeated security incidents will still be handled according to law, recorded in credit files, and publicly disclosed.
It is less than a month before implementation. For small and micro enterprises, there is not much to do right now: review the two attached forms and make the processing rules public. The threshold has been lowered, but responsibilities are not waived.