PIPL Compliance Audit Measures take effect 1 May 2025 (CAC)

Analysis

By UA Ledger staff2 min read

PIPL Compliance Audit Measures take effect 1 May 2025 (CAC)

CAC announced the Personal Information Protection Compliance Audit Measures on 14 February 2025, effective 1 May 2025. Processors of more than 10 million individuals’ PI must audit at least every two years.

On 14 February 2025, the Cyberspace Administration of China published a notice that the 个人信息保护合规审计管理办法 (Personal Information Protection Compliance Audit Measures) would take effect on 1 May 2025. The page we opened on 20 September 2026 summarises the measures’ two audit tracks, frequency rules and professional-institution duties.

What CAC states on this page

Self-initiated audits: processors must periodically audit compliance with laws and administrative regulations via an internal unit or a professional institution. Processors that handle personal information of more than 10 million individuals must conduct a personal-information protection compliance audit at least once every two years.

Regulator-required audits: where a personal-information protection authority finds large risk, possible mass rights harm, or a personal-information security incident, it may require the processor to commission a professional institution.

Professional institutions must have suitable capability, stay independent (no continuous three-times-plus audits of the same object by the same institution/affiliates/lead auditor), keep confidentiality, and must not subcontract the audit. An annexed 合规审计指引 is referenced as the checklist processors and institutions should follow.

What this notice is not

This CAC page is an official announcement of the measures’ publication and effective date. It is not a completed audit report for any named game or adtech vendor, not a list of certified auditors, and not a statement that every China UA vendor already filed an audit.

Operator action

Reference table
FieldEvidence
Announcement date2025-02-14
Effective date2025-05-01
>10M PI processorsAt least one compliance audit every two years
Regulator-ordered auditAllowed when large risk / mass harm / PI security incident
UA implicationDocument UA/MMP/ad-SDK data flows for China live ops before an audit window; do not invent an audit completion date

Download the measures card. Cross-check the later DPO information filing notice for the >1 million registration track.

Research checked 20 September 2026. Local draft; human editorial review pending.

Featured

Related posts

measurement

platforms

·

1 min read

When to turn rewarded ads off for payers (and how to measure the loss)

measurement

platforms

·

1 min read

When custom product pages need their own MMP campaign mapping

measurement

platforms

·

1 min read

Season pass refund rate versus standard IAP refund rate

measurement

platforms

·

1 min read

Pre-reg cohort quality vs post-launch paid cohort quality

More from the Measurement desk

measurement

platforms

·

2 min read

AppLovin Ad Review drops user-level journeys for aggregate-only reporting

measurement

platforms

·

2 min read

Apple adds an EU alternative ATT prompt from iOS 27.2 — mandatory in five markets

measurement

platforms

·

1 min read

Pity-adjusted expected value versus player-facing banner claims

measurement

platforms

·

1 min read

MMP install count vs store first-open: F2P reconciliation lab