虎嗅

"Veto Power Withdrawn: New Innovations in the 'Regulations on Personal Information Protection for Large-scale Personal Information Processors (Draft for Comments)'"

原文:“否决权”被撤回:《大型个人信息处理者个人信息保护规定(征求意见稿)》制度新意

Summary of Key Points

The "Regulations on the Protection of Personal Information by Large Personal Information Processors (Draft for Comment)" issued by the National Internet Information Office in August 2026 represents a Chinese approach to addressing the issue of "lack of corporate self-discipline" in global AI governance. The regulations consolidate existing regulatory frameworks, with key changes including:

  • Expansion of Regulatory Scope: The focus is no longer solely on "large platforms" but extends to all entities that process over 10 million pieces of personal information, including AI companies and smart device manufacturers.
  • Abandonment of the 'Veto Power': The outdated concept of a single individual with veto authority has been replaced by a comprehensive regulatory framework.
  • Incentives for Innovation: New provisions encourage technological innovation and participation in international standards setting.

This approach aims to move beyond relying solely on corporate self-discipline, seeking a balance between "minimum regulatory requirements" and incentives for innovation.

1. Expanded Regulatory Scope: Not Just Platforms

Previous regulations targeted mainly large internet platforms with massive user bases (such as WeChat and Taobao). However, AI companies require vast amounts of personal data for model training, smart cars collect owner information, and smartphone manufacturers process user privacy data—these entities were not previously clearly regulated. The new rules define "large personal information processors" as any organization that handles over 10 million pieces of personal information, regardless of its nature. This means AI companies like OpenAI must now comply with the regulations.

2. Abandonment of the 'Veto Power'

The draft regulation previously included a provision giving the person in charge of personal information protection the power to veto decisions. However, this was impractical: How could an executive, paid by the company, truly override profit-making decisions without facing consequences? The new regulations replace this with a more practical system:

  • The person in charge must be part of the company's management team to have decision-making authority.
  • Risks can be reported directly to the internet information authorities without fear of retaliation from superiors.
  • Special protection agencies are established for regular compliance audits.
  • Detailed records of data collection (what is collected and for what purposes) must be maintained for external inspection.

This creates a dual-layered safety net: internal oversight and external regulation, making it more feasible to ensure compliance than relying on one individual to make final decisions.

3. Incentives for Innovation

The new regulations include two specific incentives:

  • Technical Guidance: Companies are encouraged to use data labeling and authentication technologies, with the state providing support for compliant practices to avoid unnecessary spending on trial-and-error efforts.
  • International Standard Setting: Chinese companies are encouraged to participate in setting global privacy standards, which can give them a competitive advantage in the international market.
  • Compliance as a Competitive Advantage: Compliance is no longer just about avoiding fines; it has become a means to lead the industry. For example, companies that develop more secure privacy protection technologies can set new standards and gain financial benefits.

4. A Chinese Solution in a Global Context

Global AI governance faces significant challenges: Corporate-defined "ethical guidelines" (such as Google's AI Principles) often fail in the face of commercial interests. For instance, Google removed anti-weapons clauses from its policies for a contract with the Pentagon, leading to the departure of key employees; OpenAI also deviated from its initial principles. China's new regulations aim to overcome these shortcomings by combining external supervision, mandatory requirements, and incentives for innovation, creating a framework that ensures technology development within safe boundaries.

5. The Significance of the New Regulations

These regulations are not just about privacy protection; they represent a broader approach to digital governance. Laws cannot always keep up with rapid technological advancements, but by targeting key entities, establishing effective mechanisms, and fostering innovation, we can guide technology towards safer and more sustainable paths. The goal is not to restrict companies but to balance the protection of personal privacy with the promotion of AI innovation. After all, only safe AI can achieve long-term success.

In summary, China's new regulations provide a practical framework for managing personal information in the digital age, offering a valuable model for global AI governance.