On August 7, 2026, the Cyberspace Administration of China (CAC) opened a public consultation on the Draft Provisions on the Protection of Personal Information by Large Personal Information Handlers, with comments due by September 7, 2026. The draft consolidates two earlier CAC consultation texts, the draft Provisions on Establishing Personal Information Protection Supervision Committees by Large Network Platforms and the draft Provisions on Personal Information Protection by Large Network Platforms, into a single departmental rule under the Personal Information Protection Law (PIPL) and the Network Data Security Regulation.
The consolidation is the real headline: for the first time, the "large personal information handler" category, anchored to a 10 million natural-person threshold, is operationalized as one binding regime, with a new self-declaration duty running through provincial cyberspace authorities to the national CAC. China's largest platforms and any foreign firm processing the data of more than 10 million Chinese users now have a 31-day window to shape, or at least prepare for, obligations that will attach once the text is finalized.
Who counts as a large personal information handler under the draft?
Article 2 defines a large personal information handler through three conditions assessed together: processing the personal information of 10 million or more natural persons; providing important network services involving personal information, or operating across multiple business lines that do; and personal information processing activities that have an important impact on national security, economic operation, social stability, or public health and safety. The 10 million figure is the hard trigger, but recognition depends on the combined picture, not headcount alone.
This matters because the threshold is deliberately broad enough to capture China's internet incumbents (Tencent, Alibaba, ByteDance, Baidu, Meituan, JD.com, Pinduoduo, Kuaishou) and big data processors, while leaving the CAC room to pull in any operator whose scale or cross-business reach raises systemic risk. A foreign service whose user base in China crosses 10 million is not exempt: the draft's scope follows the data, not the corporate domicile.
What must a large handler do, and by when?
The consultation itself closes on September 7, 2026; the compliance duties (self-declaration to the national cyberspace authority, and the personal information protection supervision committee obligations carried over from the merged supervision-committee draft) attach once the Provisions are adopted and enter into force, not on the consultation deadline. The practical deadline now is September 7 for submitting comments to [email protected] or by post to the CAC Network Data Management Bureau.
For in-scope firms, the strategic deadline is earlier: the self-declaration mechanism means the CAC will build a public list of recognized large handlers, and being on that list unlocks the full large-handler obligation stack under PIPL Article 58. Preparing the recognition file, mapping which business lines trigger the multi-business condition, and standing up or re-validating the supervision committee are the work items that cannot wait for final adoption.
How does the self-declaration and recognition process work?
Article 3 sets a proactive path. A handler that processes the personal information of 10 million or more natural persons and self-assesses as meeting the other two conditions must declare to the national cyberspace department through its provincial cyberspace authority, submitting the required materials. The provincial authority has 15 working days to check completeness: if the file is complete, it forwards the materials with a preliminary recognition opinion to the CAC; if not, it returns them once, with a single list of what to supplement.
Recognition is not purely voluntary. If provincial-level or higher cyberspace, telecom, or public security authorities conclude a handler meets the criteria but has not declared, they must urge it to do so. The CAC, together with the State Council telecom and public security departments, then determines and publishes the consolidated list of large personal information handlers.
| Stage | Actor | Action and timing |
|---|---|---|
| Self-assessment | Handler (10M+ natural persons) | Assess against the three Article 2 conditions |
| Declaration | Handler | File through provincial cyberspace authority to the CAC |
| Completeness check | Provincial cyberspace authority | 15 working days: forward, or return once with supplement list |
| Recognition | CAC with telecom and public security | Determine and publicly publish the large-handler list |
| Urging | Provincial+ cyberspace, telecom, public security | Push non-declaring handlers to declare |
Continuous, per-jurisdiction real-time monitoring surfaces this kind of consolidation the moment the CAC publishes, so exposed firms see the threshold and the declaration window before the trade press catches up.
Take advantage of this real-time watch
What to do next
First, confirm whether your China processing base crosses the 10 million natural-person mark, and document the self-assessment against all three Article 2 conditions. Second, file or prepare comments by September 7, 2026 via [email protected], flagging any condition that is ambiguous for your business model. Third, brief the personal information protection supervision committee, or the team standing one up, on the consolidated obligation set, and pre-assemble the recognition file for the provincial cyberspace authority. Obsidian tracks this consultation through to adoption so the recognition deadline does not arrive unannounced.


