China Issues Draft Rules on the "Scope of Necessary Personal Information Required for Common Types of Mobile Internet Applications"
Time 2 Minute Read

On December 1, 2020, the Cyberspace Administration of China released draft rules on the “Scope of Necessary Personal Information Required for Common Types of Mobile Internet Applications” (the “Draft Rules”) (in Chinese).

According to the Cybersecurity Law of China, collection of personal information must follow the principles of legitimacy, propriety and necessity. Under the Draft Rules, “necessary personal information” is defined as personal information that is necessary to ensure regular operation of the basic functions of mobile applications (“apps”), without which the apps could not provide their intended basic functions. So long as users consent to the collection of necessary personal information, an app cannot prevent users from installing and using the app.

The Draft Rules specify 38 common types of apps and the scope of necessary personal information these apps may collect and use, which varies depending on the type of app. The common types of apps include: (1) map navigation; (2) online car-hailing services; (3) instant messaging; (4) online communities; (5) online payment; (6) online shopping; (7) food and beverage delivery; (8) mail, express mail and posting and delivery; (9) transportation ticketing; (10) marriage and dating; (11) job search and recruitment; (12) online lending; (13) housing rental and sales; (14) used car trading; (15) doctor inquiries and appointments; (16) tourism services; (17) hotel services; (18) online gaming; (19) online education; (20) local living; (21) women’s health; (22) car services; (23) investment and financial management; (24) mobile banking; (25) email and cloud storage; (26) remote conferencing; (27) webcasting; (28) online audio and video; (29) music video clips; (30) news; (31) sports and health; (32) internet browsing; (33) input methods; (34) safety management; (35) e-books; (36) photography enhancement; (37) application stores; and (38) utilities and practical tools.

Some types of apps do not require the collection of personal information for basic functional services, such as webcasting, online audio and video, music video clips, news, sports and health, internet browsing, input methods, safety management, e-books, photography enhancement, application stores, and utilities and practical tools. For these apps, users should be able to install and use the apps’ basic functions without providing personal information.

The Draft Rules are open for public consultation until December 16, 2020.

You May Also Be Interested In

Time 3 Minute Read

The Connecticut Attorney General recently issued a legal memorandum regarding the application of existing Connecticut laws, such as the Connecticut Data Privacy Act, to the use of artificial intelligence.

Time 3 Minute Read

On March 20, 2026, Oklahoma Governor Kevin Stitt signed SB 546 into law, enacting the Oklahoma Consumer Data Privacy Act, which will take effect on January 1, 2027.

Time 2 Minute Read

On March 23, 2026, the UK Information Commissioner's Office released new guidance clarifying the use of the new recognized legitimate interest lawful basis for processing personal information under UK data protection law.

Time 2 Minute Read

On February 5, 2026, Alabama Governor Kay Ivey signed Alabama House Bill 161, the App Store Accountability Act, establishing age categorization, age verification and parental consent requirements for mobile application marketplace providers operating in Alabama, effective January 2027.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page