China's Cyberspace Administration (CAC) published a notice on September 20, 2026 naming 30 mobile apps that violate personal information rules and ordering their operators to complete rectification within 15 working days. The action rests on the Cybersecurity Law (CSL), the Personal Information Protection Law (PIPL), the Network Data Security Regulation, and the App Violation Identification Methods, and it is the first enforcement output of the 2026 Personal Information Protection Special Action Series jointly launched by the CAC, the Ministry of Industry and Information Technology (MIIT), and the Ministry of Public Security (MPS).

The 30 named apps and mini-programs were tested by the CAC for how they collect and use personal information. Operators must report remediation to the CAC, which will verify with partner agencies and pursue formal penalties where rectification is incomplete. The apps span four violation categories, each tied to a specific PIPL obligation.

What are the four violation categories, and how many apps fall into each?

The CAC grouped the 30 apps into four non-overlapping categories. Six apps, including Flow Fit and 滑板车背诵, failed to publish any personal information collection and use rules, meaning no usable privacy notice. Four apps, including iNAP Care and 中英翻译通, forced or frequently requested non-essential permissions. Nine apps, including GPS测亩仪 and ROI Calculator, did not completely or accurately disclose what personal information they collect and how they use it. Eleven apps, including 红卷乐读 and 道臣智运, failed to provide an effective account cancellation function.

Violation categoryApps namedPIPL obligation engaged
No published collection or use rules6 (Flow Fit, 滑板车背诵, others)Article 17 disclosure duty
Forced or frequent non-essential permissions4 (iNAP Care, 中英翻译通, others)Necessity and separate-consent rules
Incomplete or inaccurate disclosure9 (GPS测亩仪, ROI Calculator, others)Article 17 accuracy duty
No effective account cancellation11 (红卷乐读, 道臣智运, others)Deletion-rights obligations

Who must act, and by when?

Every named app operator must complete rectification within 15 working days of the September 20, 2026 publication date and submit a remediation report to the CAC. The 15 working day window runs to roughly three calendar weeks, but operators tracking it against the calendar should note that China's National Day Golden Week in early October falls inside the period and pushes the actual deadline later. The CAC lists a dedicated contact channel, phone 010-55635865 and email [email protected], for operators to file their reports.

The obligation is narrow: it binds the 30 named operators and their listed apps and mini-programs, not the app ecosystem at large. The report-back is mandatory, and the CAC states it will verify remediation with MIIT and MPS before pursuing penalties.

What penalties apply if an operator misses the deadline?

Under PIPL Article 66, the CAC can order correction, issue a warning, confiscate unlawful gains, and impose a fine on the handler of up to CNY 1 million for a standard violation, rising to CNY 50 million or 5 percent of the prior year's turnover for serious cases. Personal fines on responsible persons run from CNY 10,000 to CNY 100,000 in standard cases and from CNY 100,000 to CNY 1 million in serious ones. The Cybersecurity Law adds its own enforcement tools for network operators. The notice does not set individual penalty amounts for the 30 apps, but its framing signals that non-remediation will trigger formal handling and penalties rather than a further warning.

How does this notice fit the 2026 PIPL special action series?

The bulletin is the first enforcement output of the 2026 Personal Information Protection Special Action Series, announced jointly by the CAC, MIIT, and MPS. The series makes recurring app testing and public naming its core format, so consumer-app operators in mainland China should expect follow-on sweeps covering more apps and possibly new violation categories. The three-ministry framing also means enforcement is no longer CAC-only: MIIT and MPS will participate in verification and penalties, widening the operational surface a compliance team must monitor. Continuous, per-jurisdiction real-time monitoring of the CAC feed surfaces this kind of change the moment it publishes, giving compliance leads room to act inside the 15 working day window rather than after a penalty lands.

Subscribe to the free newsletter

China artificial intelligence and data governance: AI law, generative AI, algorithm and cross-border data rulesLive
Monitor the PRC artificial intelligence and data regime for the AI, data and digital governance industry, jurisdiction China.
Email report 40+ news
You will receive an email report each time something new happens on this topic. Free, no account required.
Subscribe to the newsletter

For named operators, the checklist is narrow: confirm whether your apps or mini-programs appear in the notice, map each finding to its PIPL obligation, complete the fix, and file the report to [email protected] before the 15 working day window closes. For operators not named this round, the four categories the CAC tested here are the audit checklist to self-assess against now, ahead of the next bulletin.