Alessandro Del Ninno
News
China: CAC clarifies the use of publicly available personal information and measures to prevent data breaches.
DATA PROTECTION
14/08/2026

 

The Cyberspace Administration of China (CAC) has published a new Q&A on personal information protection policies and regulatory requirements, aimed at providing practical guidance to personal information processors subject to the Personal Information Protection Law (PIPL).

Of particular relevance, the CAC addresses the processing of personal information that has already been made publicly available, clarifying that such information may be processed within a reasonable scope, having regard to the purposes and circumstances in which it was disclosed. This does not, however, amount to an unrestricted right of use. Personal information processors must respect any express objection raised by the individual concerned and, where the processing may have a significant impact on that individual’s rights and interests, must obtain the separate consent required under the PIPL.

The Q&A also focuses on the prevention of security incidents and personal information breaches, identifying the absence or inadequacy of encryption and, more generally, insufficient security safeguards among the recurring causes of unauthorised access, disclosure or loss of personal information. Recommended measures include the use of encryption, robust password policies and regular security awareness training for personnel.

For companies operating in China or otherwise processing personal information subject to the PIPL, the CAC’s guidance reinforces the need to review, in particular, processes involving the collection and re-use of information obtained from public sources, which should not be treated as automatically available for unrestricted processing. Businesses should also reassess the technical and organisational measures implemented to prevent unauthorised access, disclosure and data loss, and should document the criteria used to determine whether the processing of publicly available personal information remains within a reasonable scope and when separate consent from the individual is required.