China: Cyberspace Administration released Measures for Administration of Compliance Audits on Personal Information Protection including cross-border data transfer regulation

Description

Cyberspace Administration released Measures for Administration of Compliance Audits on Personal Information Protection including cross-border data transfer regulation

On 12 February 2025, the Cyberspace Administration of China (CAC) released the Measures for the Administration of Compliance Audits on Personal Information Protection. The measures establish a framework for auditing personal information processing activities in China and apply to all personal information processors operating within the country. Processors handling data of over 10 million individuals must conduct audits at least every two years. Authorities may mandate external audits if data processing poses significant risks, affects many individuals, or involves major security incidents. In such cases, professional institutions must conduct the audit. Professional audit institutions must meet competency standards and are encouraged to obtain certification. They cannot subcontract audits and must conduct them impartially while safeguarding confidential information. Processors handling data of over 1 million individuals must appoint a data protection officer. Large platforms with extensive users and complex operations should establish independent oversight bodies. Protection departments will supervise audits and investigate violations, while individuals and organisations can report non-compliance. Repeated audits by the same institution or individual are restricted to prevent conflicts of interest. The measures take effect on 1 May 2025.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cross-border data transfer regulation
Regulated Economic Activity
cross-cutting
Implementation Level
national
Government Branch
executive
Government Body
other regulatory body

Complete timeline of this policy change

Hide details
2023-08-03
in consultation

On 3 August 2023, the Cyberspace Administration of China (CAC) opened a consultation on the draft A…

2023-09-02
processing consultation

On 2 September 2023, the Cyberspace Administration of China (CAC) closed its consultation on the dr…

2024-05-20
adopted

On 20 May 2024, the Cyberspace Administration of China (CAC) adopted the Measures for the Administr…

2025-02-12
in grace period

On 12 February 2025, the Cyberspace Administration of China (CAC) released the Measures for the Adm…

2025-05-01
in force

On 1 May 2025, the Cyberspace Administration of China (CAC)’s Measures for the Administration of Co…

We use cookies and other technologies to perform analytics on our website. By opting in, you consent to the use by us and our third-party partners of cookies and data gathered from your use of our platform. See our Privacy Policy to learn more about the use of data and your rights.