Skip to Content
ANALYSISMEMBER

China proposes significant amendments to the National Standard on Personal Information Protection

The proposed amendments, although nonbinding, introduce new AI governance requirements and are likely to shape compliance expectations and regulatory enforcement in China.

Published
Subscribe to IAPP Newsletters

Contributors:

Barbara Li

CIPP/E

Partner

Reed Smith

Amaya Zhou

Senior Associate

Reed Smith

On 17 June 2026, China's National Information Security Standardization Technical Committee, known as TC260, released draft amendments to the Data Security Technology — Personal Information Security Specification (GB/T 35273) seeking public comment. Originally issued in 2017 and last revised in 2020, GB/T 35273 is a recommended national standard without legally binding force, but it is widely referenced by both business and Chinese regulators as a benchmark for compliance with China's Personal Information Protection Law. 

The 2026 amendments are driven by the rapid development of artificial intelligence, increasingly complex cross-border data flows, and the global trend toward stricter governance of personal data. Multinational companies operating in China are strongly advised to review and understand the key changes in the draft amendments and implement appropriate mitigation measures. The public comment period is open until 16 Aug. 2026.

Stricter approach to legal bases for personal data collection

The draft amendments introduce an entirely new Chapter 5, which provides practical guidance on the appropriate legal basis for personal data collection. In addition, the draft amendments include a new Appendix D (Legal Basis Example Scenarios), which provides concrete, industry-specific illustrations of how different legal bases should be applied in practice. 

According to the PIPL, a data controller is generally required to obtain the consent of data subjects for the collection and processing of their personal data. However, consent is not required where the data is collected for contract performance, HR management, the performance of statutory duties or other recognized legal bases. The PIPL does not provide further guidance on the scope of these legal bases. In practice, business entities often have questions about which scenarios are covered. 

The draft amendments provide greater clarity by illustrating different legal bases with examples.

Contributors:

Barbara Li

CIPP/E

Partner

Reed Smith

Amaya Zhou

Senior Associate

Reed Smith

MEMBER

Unlock this exclusive content and more

Join the IAPPAlready a member? Sign in

Membership opens up a world of resources

In-depth knowledge

From original research reports and daily news coverage to legislative trackers and infographics, we have the information you need to stay ahead of change.

A global network

Make valuable professional connections through more than 160 local IAPP KnowledgeNet chapters in 70 countries.

Access to the experts

Connect with top thinkers in privacy, AI governance and cybersecurity for fresh ideas and insights.

Learn what you get from membership