惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Apple Machine Learning Research
Apple Machine Learning Research
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
G
Google Developers Blog
博客园 - 司徒正美
J
Java Code Geeks
aimingoo的专栏
aimingoo的专栏
A
About on SuperTechFans
博客园 - 三生石上(FineUI控件)
WordPress大学
WordPress大学
T
The Blog of Author Tim Ferriss
D
Docker
大猫的无限游戏
大猫的无限游戏
D
DataBreaches.Net
腾讯CDC
V
Visual Studio Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
C
Check Point Blog
M
MIT News - Artificial intelligence
Jina AI
Jina AI
I
InfoQ
雷峰网
雷峰网
The Cloudflare Blog
美团技术团队
Engineering at Meta
Engineering at Meta

Privacy & Cybersecurity Law Blog

EU Cyber Resilience Act Reporting Obligations Take Effect for Manufacturers Delaware Expands State Privacy Law Dutch DPA Fines Uber Over Automated Decisions Affecting Drivers European Commission Designates ChatGPT, Reddit, and Roblox Under the Digital Services Act China Issues New Rules on Cyberspace Security Inspection Court Approves Meta Settlement With 29 States Over Alleged Harms to Children and Teens FTC Proposes Enforcement Policy Statement on Personalized Pricing New Jersey Enacts the Kids Code Act with Privacy-by-Default and Safety-by-Design Obligations White House Memorandum Establishes Framework for Government-Directed Private-Sector Cyber Operations FTC, California and Utah Sue Telehealth Company Hims & Hers for Deceptive and Unlawful Privacy Practices CalPrivacy Settles with Two Data Brokers over Registration Failures and Privacy Violations New York Attorney General Releases Final Rules for SAFE for Kids Act EDPB Adopts Guidelines on Anonymous Data, Web Scraping, and Blockchain China Publishes Official Q&A on Administrative Policies for Cross-Border Data Transfers Hawaii Enacts AI Companion Disclosure and Safety Law EDPB Calls for Review of EU-U.S. Data Privacy Framework After U.S. Supreme Court Decision on FTC Independence CNIL Issues FAQs on Recommendation for Tracking Pixels in Emails European Commission Issues Guidance on the Cyber Resilience Act European Commission Issues EU AI Act Transparency Guidelines EU Digital Omnibus on AI Enters Into Force Connecticut AG Leads Multistate Settlement With 23andMe Over 2023 Data Breach CalPrivacy Targets Gig Economy Tech Platforms in First CCPA Compliance Audit New Jersey Adopts New Data Broker Registration Regime and Sensitive Data Sale and Licensing Restrictions CISA Plans to Finalize Cyber Incident Reporting Regulations in September 2026 Illinois Governor Signs Frontier AI Model Law New Hampshire Amends the NHDPA to Prohibit the Sale of Children’s Personal Data Canada’s Proposed Social Media Ban for Children and Chatbot Regulation: Bill C-34’s Impact on Platforms European Commission Unveils Cybersecurity and AI Action Plan European Commission Refers Four Member States to CJEU Over NIS2 Transposition Delays EDPB Opens Public Consultation on New Personal Data Breach Notification Template
China CAC Issues Guidance on Conducting Audits
2026-06-10 · via Privacy & Cybersecurity Law Blog

On April 29, 2026, China's Cyberspace Administration (“CAC”) released an official Q&A document (only available in Chinese) (the “Guidance”) on personal data audits intended to help data handlers (i.e., controllers) understand and comply with the personal data audit-related framework under Chinese data protection laws (certain of which are listed below).

The Guidance answers several practical questions relating to personal data audits, including how to count the number of individuals whose personal data is being processed, the required frequency of personal data audits, and the content for audits on the processing of children’s personal data. The Guidance details the following:

  • Several key regulations in China (including the Network Data Security Management Regulations, the Personal Information Protection Compliance Audit Management Measures, and the rules on cross-border data transfers) use thresholds based on how many individuals’ personal data a data handler processes. The CAC clarified that these thresholds are inclusive of the stated number (e.g., “more than 10 million” includes exactly 10 million). The count should reflect the number of natural persons whose data is currently being processed. Deleted records are excluded from the count.
  • The Guidance addresses how often data handlers must conduct personal information protection compliance audits. The Personal Information Protection Law (“PIPL”) requires all personal data handlers to conduct regular compliance audits. The Compliance Audit Management Measures set out specific minimum frequencies based on scale: (1) more than 10 million individuals: at least once every two years; (2) between 1 million and 10 million individuals: at least once every three to four years (per national standard guidance); and (3) up to 1 million individuals: at least once every five years. Data handlers are expected to formalize these timelines in an internal compliance audit policy, and may reference the relevant national standards when determining the exact cadence.
  • The Guidance also states what data handlers must cover when auditing how they handle the personal data of minors (defined as individuals under 18 years old under Chinese civil law). Under the Regulations on the Protection of Minors in Cyberspace, any data handler that processes the personal information of minors must conduct a dedicated compliance audit annually (either internally or through an accredited third party) and report the results to the CAC and other relevant authorities. This obligation applies regardless of whether the data handler formally identifies or verifies the status of users as minors. If there is any possibility that the personal data of minors is being processed, the audit requirement is triggered. The scope of such audits should align with PIPL, the Network Data Security Management Regulations, the Provisions on the Protection of Children's Personal Information Online, and the Compliance Audit Management Measures, and may draw on national technical standards for detailed audit criteria.