PIPL Compliance Audit Measures take effect 1 May 2025 (CAC)
Analysis
By UA Ledger staff — 2 min read

CAC announced the Personal Information Protection Compliance Audit Measures on 14 February 2025, effective 1 May 2025. Processors of more than 10 million individuals’ PI must audit at least every two years.
On 14 February 2025, the Cyberspace Administration of China published a notice that the 个人信息保护合规审计管理办法 (Personal Information Protection Compliance Audit Measures) would take effect on 1 May 2025. The page we opened on 20 September 2026 summarises the measures’ two audit tracks, frequency rules and professional-institution duties.
What CAC states on this page
Self-initiated audits: processors must periodically audit compliance with laws and administrative regulations via an internal unit or a professional institution. Processors that handle personal information of more than 10 million individuals must conduct a personal-information protection compliance audit at least once every two years.
Regulator-required audits: where a personal-information protection authority finds large risk, possible mass rights harm, or a personal-information security incident, it may require the processor to commission a professional institution.
Professional institutions must have suitable capability, stay independent (no continuous three-times-plus audits of the same object by the same institution/affiliates/lead auditor), keep confidentiality, and must not subcontract the audit. An annexed 合规审计指引 is referenced as the checklist processors and institutions should follow.
What this notice is not
This CAC page is an official announcement of the measures’ publication and effective date. It is not a completed audit report for any named game or adtech vendor, not a list of certified auditors, and not a statement that every China UA vendor already filed an audit.
Operator action
| Field | Evidence |
|---|---|
| Announcement date | 2025-02-14 |
| Effective date | 2025-05-01 |
| >10M PI processors | At least one compliance audit every two years |
| Regulator-ordered audit | Allowed when large risk / mass harm / PI security incident |
| UA implication | Document UA/MMP/ad-SDK data flows for China live ops before an audit window; do not invent an audit completion date |
Download the measures card. Cross-check the later DPO information filing notice for the >1 million registration track.
Research checked 20 September 2026. Local draft; human editorial review pending.
Featured
Related posts
measurement
platforms
·1 min read
When to turn rewarded ads off for payers (and how to measure the loss)
measurement
platforms
·1 min read
When custom product pages need their own MMP campaign mapping
measurement
platforms
·1 min read
Season pass refund rate versus standard IAP refund rate
measurement
platforms
·1 min read
Pre-reg cohort quality vs post-launch paid cohort quality
More from the Measurement desk
measurement
platforms
·2 min read
AppLovin Ad Review drops user-level journeys for aggregate-only reporting
measurement
platforms
·2 min read
Apple adds an EU alternative ATT prompt from iOS 27.2 — mandatory in five markets
measurement
platforms
·1 min read
Pity-adjusted expected value versus player-facing banner claims
measurement
platforms
·1 min read