Beijing Tightens the Screws: China’s Privacy Standard Overhaul Targets AI and Sensitive Data
China has released a draft update to its national privacy standard that imposes new compliance requirements on AI developers and tightens rules for handling sensitive personal information, with public comment open until August 2026.

China’s data and AI governance machine is shifting into a higher gear. On June 29, 2026, the National Technical Committee 260 on Cybersecurity (TC260) published a draft overhaul of the country’s flagship national personal‑information protection standard—a voluntary GB/T standard that, in practice, functions as the de facto compliance rulebook for companies operating in China. The revision introduces specific new obligations for AI developers, tightens rules for sensitive personal information, and even offers guidance for multinationals caught between conflicting data laws. The public consultation window runs through 16 August 2026.
What happened
The draft, issued by TC260, is a major update to China’s core privacy standard—the technical elaboration of the Personal Information Protection Law (PIPL) that has been in force since November 2021. While formally voluntary, the standard is routinely cited by regulators during enforcement, making it effectively mandatory for any company processing personal data in China.
The two biggest changes target artificial intelligence and sensitive data. First, the draft introduces new compliance requirements for AI developers, covering how AI systems collect, use, and train on personal data. It also regulates automated decision‑making and other AI-related processing that touches personal information, building on PIPL’s existing prohibitions against unfair differential treatment, such as price discrimination through profiling.
💡 This is the first time China’s baseline privacy standard has explicitly addressed AI training pipelines and automated decision‑making, signaling that regulators intend to apply the same rigor to AI as they do to traditional data processing.
Second, the draft tightens the handling of sensitive personal information, aligning with the detailed national standard GB/T 45574‑2025, which took effect on 1 November 2025. That standard defines sensitive data broadly—including biometric data, religious beliefs, medical records, financial accounts, location tracking, and children’s data—and imposes strict controls: separate consent, encrypted storage and transmission, field‑level access control, dedicated management systems, and monthly audits with logs retained for three years. It also prohibits web crawling to collect sensitive data.
The draft privacy standard folds these obligations into the baseline expectations for all personal‑information handlers, including AI developers. For companies already grappling with the 2025 sensitive data standard, the update provides clarity: the rules are now explicitly part of the core privacy compliance framework.
Why it matters
China’s data governance landscape has been rapidly hardening. The amendment to the Cybersecurity Law took effect on 1 January 2026, and the PIPL has been in force for nearly five years. Yet the TC260 draft is notable because it directly addresses the gap between statutory law and technical implementation—especially for AI, which has exploded in use since PIPL was enacted.
The IAPP notes that this revision is part of a “strong start to 2026” for China’s data and AI governance, combining statutory rules with technical standards and guidance. The draft also sits alongside other AI-specific measures, such as security assessment requirements for algorithmic services and standards for AI safety. This coordinated push suggests that Chinese authorities are moving beyond broad principles toward granular, enforceable rules.
💡 The draft’s timing—mid-2026—reflects a deliberate effort to codify learnings from the first wave of AI regulation, forcing companies to embed compliance into product design rather than bolting it on later.
For multinationals, the draft includes a significant new feature: fresh guidance on navigating conflicting data laws across jurisdictions. This directly addresses the friction between Chinese requirements (such as cross‑border transfer restrictions) and regimes like the GDPR. Companies that must simultaneously comply with Chinese and foreign privacy obligations now have a clearer operational roadmap—though the draft still requires foreign data recipients to meet protections equivalent to PIPL’s standards.
What it means for business
For AI developers, the impact is immediate and practical. The draft standard is likely to be used by regulators in enforcement actions, meaning companies cannot afford to wait for the final version. Key action items include:
For all personal‑information handlers in China, the revised standard will become the reference for compliance programs, data protection impact assessments, and system design. The higher bar for sensitive data is particularly important: the definition is broad, and the controls are specific. Companies that treat sensitive data as a checkbox exercise will face increased scrutiny.
💡 The most cost‑effective move for most companies is to treat the draft as final and start compliance work now. The consultation period is long—until August 2026—but the final version is unlikely to weaken the core requirements.
Multinationals, meanwhile, should use the draft’s conflict‑of‑laws guidance to reassess their cross‑border data transfer strategies. The draft acknowledges that companies may face conflicting obligations, but it does not relax Chinese requirements. Instead, it provides a framework for documenting compliance decisions—a subtle but important shift for legal teams.
What to watch next
After the public comment period ends on 16 August 2026, TC260 will revise the draft and issue a final version, likely by late 2026 or early 2027. The final standard will remain formally voluntary but will almost certainly be treated as mandatory by regulators. Companies should also watch for parallel moves: the Cybersecurity Law amendment is already in effect, and AI-specific rules continue to evolve. The IAPP’s framing of this draft as part of a “strong start to 2026” suggests more is coming—including potentially sector-specific guidance for healthcare, finance, and smart devices.
For now, the message from Beijing is clear: if you process personal data—especially if you use AI—you need to build compliance into the architecture, not the patch notes.
Want automation like this for your business?
Get in touch and we'll show you exactly what's possible for your setup.