🧔♂️ A friendly human may check it before it goes live. More news here
China drafts new rules to tighten app data privacy
China released draft rules to regulate how personal data is collected and used by internet apps, aiming to boost user privacy and transparency.
The Cyberspace Administration of China proposed that apps must clearly explain data collection, get informed user consent, and only use data for necessary purposes.
The draft, announced on January 10, will be open for public feedback until February 9.
The proposed rules call for detailed permission settings, bans on unnecessary or unauthorized data collection, and extra safeguards for minors and biometric information.
The draft also states that apps can access camera and microphone data only during active use of related features, such as taking photos or recording audio, and must stop once those activities end.
🔗 Source: Bloomberg
🧠 Food for thought
Implications, context, and why it matters.
Draft rules add concrete app controls to broader privacy laws
- Cyberspace Administration of China (CAC) proposals add details to China’s 2021 Personal Information Protection Law (PIPL), the baseline privacy statute 1. They set cutoffs for camera or microphone use and spell out permission toggles to close gaps apps exploit.
- Device makers and app platforms, such as app stores, would run audits 1. That shared duty gives regulators leverage, and app stores risk penalties for hosting non-compliant apps, as seen with cleanups of 700 plus apps without Internet Content Provider (ICP) filings 2.
- The draft also names third-party software development kits (SDKs), a common embedded component 3. Ministry of Industry and Information Technology (MIIT) sweeps in 2024 flagged SDKs with apps for illegal data grabs.
Privacy-tech vendors see demand for app audits and SDK checks
- Vendors with SDK scanners and consent tools see near-term demand 4. One MIIT batch named 42 apps and SDKs with excessive permissions or intrusive pop-ups.
- Consultancies in Chinese privacy compliance can add services on permission gates and biometric safeguards across sectors like gaming and finance 4. Sector playbooks that map camera or microphone rules to uses like video calls or photo filters cut confusion.
- Foreign vendors face the same scrutiny 4. Hong Kong-based Picfun Inc. landed on violation lists 4, and Apple now requires ICP filing numbers before China App Store listings 2. Cross-border tools that align General Data Protection Regulation (GDPR) controls with Chinese rules can stand out.
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.




