Policy & RegulationAnalysis

China Reports Results From 2026 Personal Information Protection Drive

Regulators inspect over 20,000 apps and 90,000 organizations across key sectors while preparing broader network identity service rollout.

Share
Laptop displaying a security lock icon on a table with a potted plant and clock.
Photo by Dan Nelson on Pexels

The Brief

Chinese regulatory authorities, led by the Cyberspace Administration of China, the Ministry of Industry and Information Technology, and the Ministry of Public Security, released interim results from their joint 2026 personal information protection campaign. The coordinated effort involved inspections of more than 20,000 mobile applications and software development kits, risk screenings across 90,000 organizations in sectors including healthcare and finance, and targeted scrutiny of personalized advertising practices. Authorities also reiterated plans to accelerate the deployment of the national network identity authentication public service.

Why it matters

The multi-agency campaign signals intensified enforcement against excessive data harvesting, non-compliant algorithmic profiling, and organizational data leaks in China. By targeting both mobile software ecosystems and traditional sector databases, regulators are enforcing stricter compliance baselines for commercial data processing while laying the groundwork for state-backed digital identity systems.

China context

Data security and personal information governance have become structural priorities within China's digital economy oversight. Joint actions uniting cyberspace regulators, industry overseers, and public security police reflect a transition from isolated software checks to an end-to-end enforcement model covering application code, enterprise backend management, and criminal liability for internal data leaks.

Editor's View

EDITOR'S VIEW — Analysis and inference, not factual reporting. The campaign demonstrates how Chinese regulators combine technical audits with industry-wide systemic inspections. While public attention often focuses on consumer-facing mobile apps and ad-targeting opt-outs, the extensive screening of 90,000 entities in critical sectors like education, transport, and finance addresses vulnerability at the enterprise storage and processing level. The explicit push to accelerate the National Network Identity Authentication Public Service alongside these enforcement statistics indicates that authorities view centralized identity infrastructure as an integral component of mitigating widespread private-sector data collection risks.

What to watch

  • Compliance rectifications and potential market re-entry of penalized or removed mobile applications
  • Adoption rates of the National Network Identity Authentication Public Service across major consumer platforms and public services
  • Judicial disclosures and enforcement actions targeting corporate insiders involved in data leaks or unauthorized data trade

Key Takeaways

  • 1Over 20,000 mobile apps and SDKs were inspected, resulting in more than 4,000 rectifications, 1,100 public notices, and over 400 app takedowns or penalties.
  • 2More than 1,000 enterprises were audited regarding non-transparent ad profiling and the absence of opt-out options for personalized advertising.
  • 3Risk screenings across 90,000 institutions in education, transportation, healthcare, and finance resolved over 12,000 data security vulnerabilities.
  • 4Authorities targeted illicit data-trading rings and internal corporate leakers while preparing to expand the National Network Identity Authentication Public Service.
Chinese regulatory authorities have announced interim results from their 2026 joint special campaign targeting personal data violations, reporting extensive enforcement actions across mobile software ecosystems and critical economic sectors. The coordinated campaign is led by the Cyberspace Administration of China (CAC), the Ministry of Industry and Information Technology (MIIT), and the Ministry of Public Security (MPS), alongside other relevant departments. According to an official release from the CAC, regulatory inspections have evaluated personal data collection and usage practices across more than 20,000 mobile applications and software development kits (SDKs). Following these reviews, authorities prompted over 4,000 apps and SDKs to complete compliance rectifications. Regulators publicly named more than 1,100 non-compliant apps and SDKs and imposed penalties on over 400 products, including ordering their removal from digital storefronts. Targeted enforcement also focused on algorithmic transparency and behavioral marketing. Regulators inspected and mandated rectifications for products from more than 1,000 enterprises and institutions found failing to explicitly disclose data processing rules related to advertising and user profiling, or neglecting to provide functional opt-out mechanisms for personalized advertisements. Beyond consumer-facing applications, authorities conducted systemic risk screenings across critical operational sectors. The inspections covered more than 90,000 enterprises and institutions operating in education, transportation, healthcare, and finance, identifying and prompting the remediation of over 12,000 distinct data security risks and vulnerabilities. Public security agencies concurrently intensified criminal investigations into data-related offenses. The campaign prioritized tracing information leaks, dismantling illicit data-trading networks, and penalizing internal corporate personnel who exploit privileged access to leak or sell institutional data. Looking ahead, the participating ministries stated they will deepen the campaign, advance governance against persistent violations, and accelerate the nationwide rollout and adoption of the National Network Identity Authentication Public Service to strengthen baseline personal information protection.

Sources

  1. 2026年个人信息保护系列专项行动取得阶段性成效 Cyberspace Administration of China · 8/19/2026