Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

China drafts new rules to tighten app data privacy

China released draft rules to regulate how personal data is collected and used by internet apps, aiming to boost user privacy and transparency.

The Cyberspace Administration of China proposed that apps must clearly explain data collection, get informed user consent, and only use data for necessary purposes.

The draft, announced on January 10, will be open for public feedback until February 9.

The proposed rules call for detailed permission settings, bans on unnecessary or unauthorized data collection, and extra safeguards for minors and biometric information.

The draft also states that apps can access camera and microphone data only during active use of related features, such as taking photos or recording audio, and must stop once those activities end.

🔗 Source: Bloomberg

🧠 Food for thought

Implications, context, and why it matters.

Draft rules add concrete app controls to broader privacy laws

  • Cyberspace Administration of China (CAC) proposals add details to China’s 2021 Personal Information Protection Law (PIPL), the baseline privacy statute 1. They set cutoffs for camera or microphone use and spell out permission toggles to close gaps apps exploit.
  • Device makers and app platforms, such as app stores, would run audits 1. That shared duty gives regulators leverage, and app stores risk penalties for hosting non-compliant apps, as seen with cleanups of 700 plus apps without Internet Content Provider (ICP) filings 2.
  • The draft also names third-party software development kits (SDKs), a common embedded component 3. Ministry of Industry and Information Technology (MIIT) sweeps in 2024 flagged SDKs with apps for illegal data grabs.

Privacy-tech vendors see demand for app audits and SDK checks

  • Vendors with SDK scanners and consent tools see near-term demand 4. One MIIT batch named 42 apps and SDKs with excessive permissions or intrusive pop-ups.
  • Consultancies in Chinese privacy compliance can add services on permission gates and biometric safeguards across sectors like gaming and finance 4. Sector playbooks that map camera or microphone rules to uses like video calls or photo filters cut confusion.
  • Foreign vendors face the same scrutiny 4. Hong Kong-based Picfun Inc. landed on violation lists 4, and Apple now requires ICP filing numbers before China App Store listings 2. Cross-border tools that align General Data Protection Regulation (GDPR) controls with Chinese rules can stand out.

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.