Cyberspace Administration of China, Measures for the Administration of Compliance Audits of the Protection of Personal Information (Draft for Comments)

国家互联网信息办公室个人信息保护合规审计管理办法 (征求意见稿)

August 15, 2023 | BY

Susan Mok

Companies that collect a large amount of personal information are required to conduct a compliance audit of its protection of personal information annually

Issued: August 3, 2023

Applicability: These Measures shall govern the compliance audits of the protection of personal information regularly conducted by personal information handlers, the compliance audits of the personal information processing activities of personal information handlers conducted by professional firms engaged at the request of a department tasked with the duty of protecting personal information, as well as the oversight of compliance audit activities of personal information protection (Article 2).

For the purposes of these Measures, the phrase "compliance audit of the protection of personal information" means the oversight activity of examining and assessing whether the personal information processing activities of a personal information handler comply with laws and administrative regulations (Article 3).

This premium content is reserved for
China Law & Practice Subscribers.

  • A database of over 3,000 essential documents including key PRC legislation translated into English
  • A choice of newsletters to alert you to changes affecting your business including sector specific updates
  • Premium access to the mobile optimized site for timely analysis that guides you through China's ever-changing business environment
For enterprise-wide or corporate enquiries, please contact our experienced Sales Professionals at +44 (0)203 868 7546 or [email protected]