Policy & RegulationAnalysis

China's Cyberspace Regulator Names 30 Apps Over Data Privacy Violations

Developers are given 15 working days to fix issues spanning undisclosed rules, forced permissions, and missing account cancellation features.

Share
The phrase 'Cyber Threats' displayed on a textured dark background, emphasizing digital security.
Photo by Ann H on Pexels

The Brief

The Cyberspace Administration of China has publicly named 30 mobile applications and mini-programs for mishandling personal information, according to official notices released by the agency and state news agency Xinhua. The cited violations include failing to disclose data collection rules, forcibly or frequently requesting unnecessary permissions, inaccurately disclosing data practices, and failing to provide effective account cancellation mechanisms. The operators must complete rectifications within 15 working days and submit their compliance reports, after which authorities will verify fixes and apply administrative penalties or enforcement actions where appropriate.

Why it matters

The crackdown signals ongoing normalized regulatory pressure on consumer data privacy in China, zeroing in on recurring pain points such as excessive permission requests, opaque user agreements, and barriers to account deletion that keep user data locked in corporate databases.

China context

The joint enforcement action stems from a 2026 special enforcement campaign coordinated by the Cyberspace Administration of China, the Ministry of Industry and Information Technology, and the Ministry of Public Security. Grounded in the Personal Information Protection Law, the Cybersecurity Law, and the Regulations on Network Data Security Management, this inter-agency framework uses recurring public notices to pressure developers across diverse app categories into meeting statutory compliance standards.

Editor's View

EDITOR'S VIEW — Analysis and inference, not factual reporting. By targeting both standalone applications and lightweight mini-programs across niche verticals—ranging from fitness tracking to language translation and acreage measurement—the regulator demonstrates that enforcement reaches far beyond major consumer platforms. The inclusion of basic consumer rights, particularly the right to cancel an account, reinforces Beijing's intention to enforce the procedural safeguards established by the Personal Information Protection Law down to mid-sized and utility developers.

What to watch

  • Whether the 30 cited app operators complete compliance rectifications within the 15-working-day deadline in October 2026.
  • Potential app store removals or administrative penalties if regulators deem subsequent verifications unsatisfactory.
  • Follow-up inspections and sector-specific warnings issued under the 2026 inter-agency special privacy enforcement campaign.

Key Takeaways

  • 1The Cyberspace Administration of China cited 30 apps and mini-programs for non-compliant personal data collection and handling.
  • 2Infractions were grouped into four areas: undisclosed rules (6 apps), unnecessary permissions (4 apps), inaccurate disclosures (9 apps), and absence of valid account deletion (11 apps).
  • 3Affected operators have 15 working days from September 20, 2026, to rectify practices and submit reports before regulators conduct verification and consider administrative penalties.
China's top internet regulator has publicly cited 30 mobile applications and mini-programs for non-compliant collection and use of personal data, demanding that operators overhaul their data practices within 15 working days. According to an enforcement circular issued on September 20, 2026, by the Secretariat of the Cyberspace Administration of China (CAC) and carried by state news agency Xinhua, the inspections were conducted as part of a joint 2026 nationwide enforcement campaign launched alongside the Ministry of Industry and Information Technology (MIIT) and the Ministry of Public Security. The regulatory checks evaluated compliance against China's Cybersecurity Law, Personal Information Protection Law (PIPL), Regulations on Network Data Security Management, and operational assessment guidelines for illegal data collection. The regulatory notice divided the infractions across 30 apps into four major compliance categories: First, six apps—including fitness application Flow Fit and vocabulary study app Huabanche Beisong—failed to disclose their rules governing the collection and use of personal information. Second, four apps—including medical companion app iNAP Care and translation utility Zhongying Fanyitong—forcibly or frequently requested permissions that were not necessary for their core functionality. Third, nine apps—including land measurement tool GPS Cemuoyi and ROI Jisuanqi—failed to provide full and accurate disclosures regarding the scope and nature of the personal data they gather and use. Fourth, eleven apps—including reader app Hongjuan Ledu and logistics management tool Daochen Zhiyun—failed to offer users a valid, functional account cancellation mechanism. The cyberspace watchdog instructed all 30 app operators to complete necessary rectifications within 15 working days of the notice and report their remediation status directly to the CAC. The agency stated that it will coordinate with relevant ministries to verify compliance and will impose regulatory measures or administrative penalties on developers that fail to meet statutory standards.

Sources

  1. 中央网信办通报30款App个人信息收集使用问题 Xinhua News Agency · 9/20/2026
  2. 关于30款App个人信息收集使用问题的通报 Cyberspace Administration of China · 9/20/2026