Personal Information Protection Compliance Audit Is About to Be Implemented: The “Operation Manual” That Every Enterprise Needs
Personal Information Protection Compliance Audit Is About to Be Implemented: The “Operation Manual” That Businesses Must Have
Author: Ma Yunhe
Introduction to the Article
PREFACE TO THE ARTICLE
Since the Personal Information Protection Law of 2021 explicitly mandated compliance audits for personal information processors, personal information protection compliance audits have drawn considerable attention. On September 30, 2024, the "Regulations on the Security Management of Network Data" were released, once again making personal information protection compliance audits a hot topic. But when exactly will these regulations be finalized? Everyone has been eagerly awaiting their release, yet they remain shrouded in mystery, “half-hidden behind a veil.” On February 14, 2025, the Cyberspace Administration of China officially issued the "Administrative Measures for Compliance Audits of Personal Information Protection," which will take effect on May 1, 2025. This means that all personal information processors meeting the statutory conditions for “personal information protection audits” will be required to conduct such audits.
I. What is a Personal Information Protection Compliance Audit?
Article 2 of the “Administrative Measures for Compliance Audits on Personal Information Protection” stipulates that a compliance audit on personal information protection refers to the supervisory activity of examining and evaluating whether the personal information processing activities conducted by personal information processors within the territory of the People’s Republic of China comply with laws and administrative regulations.
A personal data compliance audit is an independent, objective oversight, evaluation, and verification activity designed to examine and assess the personal data processing activities or internal controls of the audited entity, with the aim of determining whether such activities are authentic, lawful, and effective, and to provide relevant stakeholders with insights and recommendations. The purpose of the audit is to identify potential issues through professional inspection and analysis, mitigate risks, and promote the standardized conduct of personal data processing activities.
During the audit process, personal information compliance auditors determine whether the personal information processing activities of the audited entity comply with applicable standards. The basis for these audits typically includes relevant laws, regulations, and industry-specific normative standards in the field of personal information protection.
From a regulatory perspective, personal data compliance audits are supervisory measures used by regulatory authorities to standardize the handling of personal information. From the perspective of personal information processors, both personal data compliance audits and personal information protection risk assessments serve as internal governance mechanisms aimed at enhancing the level of compliance with personal information processing regulations. From the perspective of data subjects, personal data audits provide an effective safeguard for the protection of individuals’ rights and interests in their personal information.
II. Which personal information processors are included in the scope of the audit?
Article 3 of the Personal Information Protection Law of the People’s Republic of China states: “Activities involving the processing of personal information of natural persons within the territory of the People’s Republic of China shall be governed by this Law. Activities involving the processing of personal information of natural persons within the territory of the People’s Republic of China outside its borders shall also be governed by this Law if any of the following circumstances apply: (1) the purpose is to provide products or services to natural persons within the territory; (2) the purpose is to analyze and assess the behavior of natural persons within the territory; (3) other circumstances prescribed by laws and administrative regulations.”
Therefore, all “personal information processors” within the territory of the People’s Republic of China are obligated to undergo compliance audits under the Personal Information Protection Law, including overseas processors that meet specific conditions. These specific conditions include: providing products or services to natural persons within the territory; analyzing and assessing the behavior of natural persons within the territory; and other circumstances prescribed by laws and administrative regulations.
All “personal information processors” are obligated to undergo compliance audits for personal data protection. However, depending on factors such as the importance, sensitivity, risk level, and volume of personal information processed, there are varying requirements regarding whether a mandatory audit should be initiated and the frequency of such audits. Specifically, personal data protection compliance audits are also required for state organs and organizations authorized by laws and regulations to perform public administration functions; however, compliance audits for these entities are not subject to the provisions of this regulation.
III. Under what circumstances is a personal data compliance audit required?
Compliance audits for personal information protection include two types: voluntary audits and mandatory audits. Among these, the circumstances requiring mandatory audits include:
1. Personal information processors handling the personal information of more than 10 million individuals shall conduct a personal information protection compliance audit at least once every two years.
2. With regard to the processing of personal information of minors, in accordance with the “Regulations on the Protection of Minors Online,” personal information processors shall, either independently or by entrusting a specialized agency, conduct annual compliance audits to assess their adherence to laws and administrative regulations in the processing of minors’ personal information, and promptly report the audit results to the cyber administration and other relevant authorities.
3. When the national cyberspace administration and other departments responsible for protecting personal information identify significant risks—such as serious impacts on individuals’ rights or severe deficiencies in security measures—in personal information processing activities; when personal information processing activities may infringe upon the rights and interests of numerous individuals; or when a personal information security incident occurs resulting in the leakage, alteration, loss, or damage of personal information affecting more than one million individuals or sensitive personal information affecting more than 100,000 individuals, these authorities may require the personal information processor to engage a professional organization to conduct a compliance audit of its personal information processing activities.
Unless the national cyberspace administration and other departments responsible for protecting personal information require personal information processors to commission professional organizations to conduct compliance audits of their personal information processing activities, personal information processors may carry out compliance audits on their own.
IV. Main Contents of the Audit
The main contents of the audit of laws and administrative regulations such as the “Personal Information Protection Law of the People’s Republic of China” and the “Regulations on the Security Management of Network Data” include:
1. The legal basis for processing personal information;
2. Conduct a compliance audit of personal information processing rules;
3. Conduct a compliance audit on personal information processors’ fulfillment of their obligation to provide information about the rules governing the processing of personal information;
4. Conduct compliance audits on the joint processing of personal information by personal information processors and other personal information processors.
5. Conduct a compliance audit on personal information processors’ entrusted processing of personal information;
6. Conduct a compliance audit on personal information processors’ provision of the personal information they process to other personal information processors.
7. Conduct compliance audits on personal information processors’ use of automated decision-making to process personal information;
8. Conduct a compliance audit on personal information processors’ public disclosure of personal information based on individuals’ consent.
9. A compliance audit of the installation of image collection and personal identification devices by personal information processors in public places;
10. Conduct a compliance audit on the processing of publicly available personal information by personal information processors.
11. Conduct compliance audits on personal information processors’ handling of sensitive personal information;
12. Conduct a compliance audit on personal information processors’ handling of personal information of minors under the age of 14.
13. Conduct compliance audits on personal information processors’ provision of personal information to overseas entities;
14. Conduct a compliance audit on the status of safeguarding the right to erasure of personal information;
15. Conduct compliance audits on personal information processors’ fulfillment of their obligations to safeguard individuals’ rights in personal information processing activities.
16. Conduct a compliance audit to determine whether the personal information processor has established internal management systems and operational procedures in accordance with the provisions of laws and administrative regulations, clearly defined the organizational structure and job responsibilities, established work processes, improved internal control systems, and ensured compliance and security in the processing of personal information.
17. Whether the personal information processor has adopted security technical measures that are commensurate with the scale and types of personal information processed, and whether the effectiveness of the technical measures adopted by the personal information processor has been evaluated.
18. Conduct a compliance audit on the formulation and implementation of the personal information processor’s education and training plan;
19. Conduct a compliance audit on the performance of duties by the personal information protection officer designated by the personal information processor.
20. Conduct a compliance audit on the implementation of personal information protection impact assessments conducted by personal information processors.
21. Compliance audits shall be conducted on personal information processors to ensure that they have formulated emergency response plans for personal information security incidents.
22. Conduct compliance audits of platform rules formulated by personal information processors that provide critical internet platform services, have a huge user base, and operate in complex business types.
23. Conduct compliance audits of social responsibility reports on personal information protection issued by personal information processors that provide critical internet platform services, have a huge user base, and operate in complex business types.
V. How to Choose a Professional Audit Firm?
To ensure audit quality, the “Administrative Measures for Compliance Audits on Personal Information Protection” sets forth clear requirements for the qualifications of audit institutions. Professional institutions must possess the capability to conduct compliance audits on personal information protection and have auditors, premises, facilities, and financial resources that are appropriate for the services they provide.
Relevant professional organizations are encouraged to obtain certification. The certification of professional organizations shall be carried out in accordance with the relevant provisions of the "Regulations of the People's Republic of China on Certification and Accreditation."
When conducting compliance audits for personal information protection, professional organizations shall comply with applicable laws and regulations, act with integrity and honesty, and make professional compliance audit judgments in a fair and objective manner. They shall, in accordance with the law, keep confidential any personal information, trade secrets, and other confidential business information obtained in the course of performing their compliance audit duties, and shall neither disclose such information nor illegally provide it to others. Upon completion of the compliance audit work, they shall promptly delete all relevant information.


Ma Yunhe
Attorney at Tongfang Law Firm, Doctor of Law
Director of the Digital Rule of Law and Digital Economy Specialized Committee of the Liaoning Provincial Lawyers Association
Professional Expertise: Fair Competition and Antitrust Law,
Digital Economy, Digital Rule of Law, and Criminal Defense
Prev: Several Key Compliance Issues in the Reform of Mixed-Ownership Structure of State-Owned Enterprises
Next: The Value Dimension and Rule Application of the Exception System for Fair Competition Review





