China's PIPL Audit Duty Waited Four Years for a Frequency, a Trigger List and an Annex of 27 Checks
Key Takeaways
- The Measures are CAC Order No. 18: adopted on 20 May 2024, signed on 12 February 2025, published on 14 February 2025 and in force from 1 May 2025
- A processor handling the personal information of more than 10 million people must audit at least once every two years; the CAC's Q&A says every other processor sets its own frequency
- A regulator may order an outside audit on three grounds, one of them an incident affecting 1 million people, or 100,000 people's sensitive personal information
- The same auditor, its affiliates or the same lead auditor may not audit the same processor three or more consecutive times, and may not subcontract the work
- An annexed guideline of 27 items is the reference standard for both kinds of audit, running from consent and notice design to platform social responsibility reports
About the Texts Quoted Here
Every instrument discussed below exists authoritatively only in Chinese. The English renderings are this publication's own working translations of the official texts published by the Cyberspace Administration of China (CAC) and the National People's Congress, and a phrase quoted in English is not a quotation of any official English version. Where a Chinese term carries weight, it is given alongside.
Where PIPL Article 54 Leaves the Audit Duty
The Personal Information Protection Law (PIPL) creates the audit in one sentence. Article 54 provides that a personal information processor shall regularly (定期) carry out compliance audits of its processing of personal information against laws and administrative regulations. It names no interval, no auditor, no scope and no filing.
Article 64 adds a second, regulator-driven route. Where a department performing personal information protection duties finds that processing carries a relatively large risk, or that a personal information security incident has occurred, it may summon the processor's legal representative or principal responsible person for an interview (约谈), or require the processor to engage a professional institution to audit its processing. The processor must then take measures, rectify, and eliminate the hidden risk.
The Regulations on Network Data Security Management, which took effect on 1 January 2025, restated the self-audit duty in Article 27 with one addition: the audit may be done by the processor itself or by a professional institution it commissions. Article 52 of those Regulations asks that personal information compliance audits, important-data risk assessments and data-export security assessments be coordinated so as to avoid duplicate audits and assessments. The Regulations themselves are covered separately in this publication's post on the network data rules.
The CAC Measures and Their Effective Date
The implementing instrument is the Measures for the Administration of Personal Information Protection Compliance Audits (个人信息保护合规审计管理办法), issued as CAC Order No. 18. The order's preamble records the timetable, and it is not a short one:
- 20 May 2024. Adopted at the CAC's 15th office meeting of 2024
- 12 February 2025. Order signed by CAC Director Zhuang Rongwen
- 14 February 2025. Published on the CAC website, with an announcement and a question-and-answer release
- 1 May 2025. In force, under Article 20
Nearly nine months separate adoption from publication. In that interval the State Council promulgated the network data Regulations, and Article 1 of the Measures, as published, cites both the PIPL and those Regulations as its legal basis.
The Measures run to 20 articles plus an annex. Article 2 defines the audit as a supervisory activity that reviews and evaluates whether a processor's personal information processing complies with laws and administrative regulations. Article 19 takes state organs, and organisations authorised by law to administer public affairs, outside the Measures altogether.
Self-Initiated Audits and Their Frequency
Article 3 governs the audit a processor runs on its own initiative. It may be carried out by an internal department or by a professional institution the processor engages, and it must be periodic. The CAC's February 2025 Q&A states that the Measures impose no mandatory requirement on which of the two methods is used, or on which outside institution is chosen.
Article 4 supplies the only fixed interval: a processor handling the personal information of more than 10 million people must carry out a compliance audit at least once every two years. For everyone else, the Q&A says processors determine a reasonable audit frequency according to their own circumstances. The Measures do not require a self-initiated audit report to be filed with any authority.
Article 12 attaches a staffing rule at a lower threshold. A processor handling the personal information of 1 million people or more must designate a person in charge of personal information protection (个人信息保护负责人), who is responsible for the processor's compliance audit work. PIPL Article 52 had already required that designation from processors reaching "a quantity prescribed by the national cyberspace department", without stating the quantity in the statute; Article 12 of the Measures attaches a figure of 1 million to the audit role, though it does not say it is fixing the Article 52 number. Article 12's second paragraph requires processors that provide important internet platform services, have very large numbers of users and run complex business types to set up an independent body composed mainly of external members to supervise the audit, which tracks the language of PIPL Article 58.
Audits Ordered by a Regulator
Article 5 turns PIPL Article 64 into a closed list. The CAC and the other departments performing personal information protection duties, which the Measures call collectively the protection departments (保护部门), may require a processor to commission a professional institution to audit its processing where:
- processing is found to carry a relatively large risk, such as seriously affecting individuals' rights and interests or a serious lack of security measures
- processing may infringe the rights and interests of a large number of individuals
- a personal information security incident has caused the leakage, tampering, loss or destruction of the personal information of 1 million or more people, or the sensitive personal information of 100,000 or more people
The same article adds a limit on the regulator: an outside audit may not be required more than once for the same incident or risk.
Once ordered, the audit carries obligations the self-initiated version does not. Article 8 requires the processor to give the institution necessary support and to bear the audit fees. Article 9 requires it to select the institution as the protection department requires and to finish within the time limit set, which may be extended with the department's approval where the situation is complex. Article 10 requires the finished report to be submitted to the department, signed by the institution's principal responsible person and the audit lead and bearing the institution's official seal. Article 11 requires rectification of problems the audit finds, and a rectification report to the department within 15 working days after rectification is complete.
Article 16 gives the protection departments supervisory inspection over processors' audit work generally, and Article 17 lets any organisation or individual complain about or report unlawful conduct in an audit. Article 18 does not create new penalties; it routes violations of the Measures to the PIPL and the network data Regulations.
Who May Conduct the Audit
Article 7 sets a capability standard rather than a licence. A professional institution must have the ability to carry out personal information protection compliance audits, with auditors, premises, facilities and funds suited to the service. Certification is encouraged but voluntary, and runs under the PRC Regulations on Certification and Accreditation. The Q&A describes the approach as voluntary and market-based.
The CAC's second Q&A, on implementation, published on 27 May 2025, filled in the machinery. It states that three bodies have filed certification rules with the Certification and Accreditation Administration: the CAC's Data and Technology Support Centre, the China Cybersecurity Review, Certification and Market Regulation Big Data Centre, and Beijing CESI Certification. They certify against two practice guides issued by the secretariat of the National Cybersecurity Standardization Technical Committee (TC260), one on audit requirements and one on the service capability of professional institutions. Those guides grade auditors as junior, intermediate and senior, and the Cyberspace Security Association of China has compiled points for evaluating auditor competence and states it will carry out those evaluations.
Three conduct rules bind the institution itself:
- Confidentiality and deletion (Article 13). Personal information, trade secrets and confidential business information obtained in the audit must be kept confidential and deleted promptly once the audit work ends
- No subcontracting (Article 14). The engaged institution may not re-delegate the audit to another institution
- Rotation (Article 15). The same institution and its affiliates, and the same audit lead, may not audit the same subject 连续三次以上, three or more consecutive times. In Chinese statutory counting 以上 includes the number stated, so the rule allows at most two consecutive engagements
The Reference Guidelines Annexed to the Measures
The annex, Guidelines for Personal Information Protection Compliance Audits (个人信息保护合规审计指引), is the part of Order No. 18 with the most operational content. Article 6 requires processors to 参照 the Guidelines, to refer to them, for both self-initiated and ordered audits. The verb is weaker than one requiring compliance with a checklist, and the Q&A describes the Guidelines as a distillation of the key points of existing law, refined from an audit perspective.
The Guidelines run to 27 numbered items. Several go further into detail than the statute they audit:
- Item 4, notice. Whether the size, font and colour of the notice text make the whole of it easy to read, and whether offline notice uses signage and explanations
- Item 9, automated decision-making. Whether the fairness of outcomes is reviewed, whether a non-personalised option or an easy refusal is offered alongside targeted push and marketing, and whether effective measures prevent unreasonable differential treatment in transaction terms based on consumers' preferences or trading habits
- Item 11, cameras in public places. Whether image-collection and identity-recognition equipment is necessary for public security, carries prominent signage, and has separate consent for any use beyond public security
- Item 12, public information. Whether published email addresses or phone numbers receive commercial messages unrelated to the purpose of publication, and whether public information is used for online abuse or to spread rumours
- Item 15, export. Whether the export route matches the thresholds in the CAC's cross-border rules, charted in this publication's PIPL export guide, and whether any recipient is on a restricted or prohibited list
- Items 24 and 25, incidents. Whether an incident emergency plan exists, is trained and is drilled, and whether a notification channel was set up so that regulators and individuals were told promptly after an incident
The closing items reach the largest platforms. Item 26 audits platform rules, including sampling to verify they are enforced. Item 27 audits the personal information protection social responsibility report such platforms publish, checking disclosure of eight listed matters, among them requests received from individuals, the independent supervisory body's work and the handling of major incidents.
What the Measures do not contain is also worth recording. There is no template for the self-audit report and no requirement to file one. Those documents sit in the TC260 practice guides the implementation Q&A points to, which are recommended technical documents rather than CAC rules. This publication has relied on the CAC's description of those guides and has not reproduced their contents.
Frequently Asked Questions
How often does China require a personal information compliance audit?
Does the audit have to be done by an outside firm?
When can a Chinese regulator order a compliance audit?
What happens after an ordered audit?
Can the same audit firm be used every year?
Sources
Everything above is reported from these documents. Follow them to verify.
- 个人信息保护合规审计管理办法 (Measures for the Administration of Personal Information Protection Compliance Audits), CAC Order No. 18, with annexed Guidelines (February 14, 2025) regulation
- 国家互联网信息办公室公布《个人信息保护合规审计管理办法》 (CAC announcement of the Measures) (February 14, 2025) agency release
- 《个人信息保护合规审计管理办法》答记者问 (CAC Q&A on the Measures) (February 14, 2025) agency guidance
- 《个人信息保护合规审计管理办法》实施有关事项答记者问 (CAC Q&A on implementation of the Measures) (May 27, 2025) agency guidance
- 中华人民共和国个人信息保护法 (Personal Information Protection Law), National People's Congress (August 20, 2021) statute
- 网络数据安全管理条例 (Regulations on Network Data Security Management), State Council Decree No. 790 (September 30, 2024) regulation
Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.