TLDR; Below is the English-translated version of China’s Provisions on the Administration of Mobile Internet Application Program Information Services (移动互联网应用程序信息服务管理规定), issued by the Cyberspace Administration of China on June 14, 2022 and in effect since August 1, 2022.
If your company publishes a mobile app to users in mainland China — or distributes one through an app store, mini-program platform, or similar channel — these Provisions set the baseline duties you owe: verify users’ real identities, review the content you carry, protect data and personal information, safeguard minors, run a security assessment before launching opinion-shaping features, and, for app stores, file with the provincial cyberspace authority. They build directly on the Cybersecurity Law, the Data Security Law, and the Personal Information Protection Law (PIPL), and they assume you already hold the license or filing required to operate an internet information service in China at all.
Provisions on the Administration of Mobile Internet Application Program Information Services (Issued June 14, 2022 by the Cyberspace Administration of China; effective August 1, 2022 (repealing the 2016 version of the same name))
Chapter I — General Provisions
Article 1. These Provisions are formulated in accordance with the “Cybersecurity Law of the People’s Republic of China,” the “Data Security Law of the People’s Republic of China,” the “Personal Information Protection Law of the People’s Republic of China,” the “Law of the People’s Republic of China on the Protection of Minors,” the “Measures for the Administration of Internet Information Services,” the “Provisions on the Administration of Internet News Information Services,” the “Provisions on the Ecological Governance of Network Information Content,” and other laws, administrative regulations, and relevant State provisions, in order to regulate the information services of mobile internet application programs (hereinafter referred to as “applications”), protect the lawful rights and interests of citizens, legal persons, and other organizations, and safeguard national security and the public interest.
Article 2. These Provisions shall be observed when providing application information services, or engaging in application distribution services such as internet application stores, within the territory of the People’s Republic of China.
“Application information services” as referred to in these Provisions means activities that provide users, through applications, with services for the production, reproduction, publication, and dissemination of information such as text, images, audio, and video — including such types as instant messaging, news and information, knowledge Q&A, forums and communities, online live streaming, e-commerce, online audio and video, and life services.
“Application distribution services” as referred to in these Provisions means activities that provide, over the internet, services such as the release, download, and dynamic loading of applications — including such types as application stores, quick-app centers, internet mini-program platforms, and browser plug-in platforms.
Article 3. The national cyberspace administration department is responsible for the supervision and administration of application information content throughout the country. Local cyberspace administration departments are responsible, in accordance with their duties, for the supervision and administration of application information content within their respective administrative regions.
Article 4. Application providers and application distribution platforms shall abide by the Constitution, laws, and administrative regulations, promote the core socialist values, adhere to the correct political direction, guidance of public opinion, and value orientation, follow public order and good morals, fulfill their social responsibilities, and maintain a clean and healthy cyberspace.
Application providers and application distribution platforms shall not use applications to engage in activities prohibited by laws and regulations, such as endangering national security, disrupting social order, or infringing upon the lawful rights and interests of others.
Article 5. Application providers and application distribution platforms shall fulfill their principal responsibility for information content management, actively cooperate with the State’s implementation of the network trusted-identity strategy, establish and improve management systems for information content security management, information content ecosystem governance, data security and personal information protection, and the protection of minors, ensure cybersecurity, and maintain a sound network ecosystem.
Chapter II — Application Providers
Article 6. Where an application provider provides users with services such as information publishing or instant messaging, it shall, for users applying to register, carry out real-identity-information authentication based on means such as a mobile phone number, an identity document number, or a unified social credit code. Where a user does not provide real identity information, or carries out a false registration by fraudulently using the identity information of an organization or another person, the provider shall not provide the relevant services to that user.
Article 7. Where an application provider provides internet news information services through an application, it shall obtain an internet news information service license; conducting internet news information service activities without a license or beyond the scope of the license is prohibited.
Where an application provider provides other internet information services that, in accordance with law, require the examination and consent of the relevant competent authority or the obtaining of a relevant license, it may provide the services only after obtaining the examination and consent of the relevant competent authority or obtaining the relevant license.
Article 8. Application providers shall be responsible for the results of the information content they present, shall not produce or disseminate unlawful information, and shall conscientiously guard against and resist harmful information.
Application providers shall establish and improve mechanisms for the review and management of information content, establish and refine management measures for user registration, account management, information review, routine inspection, and emergency response, and be equipped with professional personnel and technical capabilities commensurate with the scale of their services.
Article 9. Application providers shall not induce users to download applications through conduct such as false advertising or bundled downloads, through means such as machine- or human-driven ranking manipulation, volume manipulation, or review manipulation, or by using unlawful and harmful information.
Article 10. Applications shall conform to the mandatory requirements of the relevant national standards. Where an application provider discovers that an application has risks such as security defects or vulnerabilities, it shall immediately take remedial measures and, in accordance with the provisions, promptly inform users and report to the relevant competent authority.
Article 11. Where an application provider carries out application data processing activities, it shall perform its data security protection obligations, establish and improve a whole-process data security management system, adopt technical measures and other security measures to safeguard data security, strengthen risk monitoring, refrain from endangering national security or the public interest, and refrain from harming the lawful rights and interests of others.
Article 12. Where an application provider processes personal information, it shall follow the principles of lawfulness, legitimacy, necessity, and good faith, have a clear and reasonable purpose and make its processing rules public, comply with the relevant provisions on the scope of necessary personal information, regulate its personal information processing activities, and take necessary measures to safeguard the security of personal information. It shall not, for any reason, compel users to consent to the processing of their personal information, nor shall it refuse to allow a user to use its basic functions and services on the ground that the user does not consent to providing non-essential personal information.
Article 13. Application providers shall adhere to the principle of the best interests of minors, pay attention to the healthy growth of minors, perform the various obligations for the online protection of minors, and strictly implement, in accordance with law, the requirements for registration and login of minor users’ accounts with real identity information. They shall not, in any form, provide minor users with related products or services that induce addiction, and shall not produce, reproduce, publish, or disseminate information containing content that endangers the physical or mental health of minors.
Article 14. Where an application provider launches new technologies, new applications, or new functions that have the attribute of shaping public opinion or the capacity for social mobilization, it shall conduct a security assessment in accordance with the relevant State provisions.
Article 15. Application providers are encouraged to actively adopt Internet Protocol version 6 (IPv6) to provide information services to users.
Article 16. Application providers shall, in accordance with laws and regulations and the relevant State provisions, formulate and make public their management rules, enter into service agreements with registered users, and clearly define the relevant rights and obligations of both parties.
With respect to registered users who violate these Provisions, the relevant laws and regulations, or the service agreement, the application provider shall, in accordance with law and the agreement, take disposal measures such as issuing a warning, restricting functions, or closing the account, keep records, and report to the relevant competent authority.
Chapter III — Application Distribution Platforms
Article 17. An application distribution platform shall, within 30 days of going online and commencing operations, file a record with the cyberspace administration department of the province, autonomous region, or municipality directly under the Central Government where it is located. When carrying out the record-filing, it shall submit the following materials:
(1) Basic information on the entity operating the platform;
(2) Information such as the platform’s name, domain name, access service, service qualifications, and the categories of applications it makes available;
(3) Materials such as the for-profit internet information service license or the non-profit internet information service record-filing obtained by the platform;
(4) The relevant system documents that Article 5 of these Provisions requires to be established and improved;
(5) The platform’s management rules, service agreements, and the like.
After the cyberspace administration department of a province, autonomous region, or municipality directly under the Central Government receives the record-filing materials, it shall grant the record-filing where the materials are complete.
The national cyberspace administration department shall promptly publish a list of the application distribution platforms that have completed record-filing formalities.
Article 18. Application distribution platforms shall establish a classification management system, carry out classified management of the applications they make available, and file the applications, by category, with the cyberspace administration department of the province, autonomous region, or municipality directly under the Central Government where the platform is located.
Article 19. Application distribution platforms shall adopt measures such as composite verification to carry out real-identity-information authentication of application providers applying to make their applications available, combining multiple means such as a mobile phone number, an identity document number, or a unified social credit code. According to the different nature of the application provider as a subject, they shall publicize information such as the provider’s name and unified social credit code, so as to facilitate public oversight and inquiry.
Article 20. Application distribution platforms shall establish and improve management mechanisms and technical means, and establish and refine management measures for listing review, routine management, and emergency response.
Application distribution platforms shall review applications that apply to be listed or updated; where they discover that an application’s name, icon, or description contains unlawful or harmful information, does not correspond to the registrant’s real identity information, or that the type of business involves violations of laws or regulations, they shall not provide services for it.
Where the information services provided by an application fall within the scope specified in Article 7 of these Provisions, the application distribution platform shall verify the relevant licenses and related matters; where they fall within the scope specified in Article 14 of these Provisions, the application distribution platform shall verify the status of the security assessment.
Application distribution platforms shall strengthen the routine management of the applications they carry; for applications that contain unlawful or harmful information, that falsify data such as download counts or evaluation indicators, that have hidden data security risks, that collect or use personal information in violation of laws or regulations, or that harm the lawful rights and interests of others, they shall not provide services.
Article 21. Application distribution platforms shall, in accordance with laws and regulations and the relevant State provisions, formulate and make public their management rules, enter into service agreements with application providers, and clearly define the relevant rights and obligations of both parties.
With respect to applications that violate these Provisions, the relevant laws and regulations, or the service agreement, the application distribution platform shall, in accordance with law and the agreement, take disposal measures such as issuing a warning, suspending services, or removing the application from the platform, keep records, and report to the relevant competent authority.
Chapter IV — Supervision and Administration
Article 22. Application providers and application distribution platforms shall consciously accept public oversight, set up conspicuous and convenient entry points for complaints and reports, publish the methods for making complaints and reports, improve mechanisms for acceptance, handling, and feedback, and promptly handle complaints and reports from the public.
Article 23. Internet industry organizations are encouraged to establish and improve industry self-discipline mechanisms, formulate and refine industry norms and self-discipline conventions, guide member units in establishing and improving service norms, provide information services in accordance with laws and regulations, safeguard market fairness, and promote the healthy development of the industry.
Article 24. The cyberspace administration departments, together with the relevant competent authorities, shall establish and improve working mechanisms to supervise and guide application providers and application distribution platforms in conducting information service activities in accordance with laws and regulations.
Application providers and application distribution platforms shall cooperate with the supervision and inspection lawfully carried out by the cyberspace administration departments and the relevant competent authorities, and shall provide the necessary support and assistance.
Article 25. Where an application provider or an application distribution platform violates these Provisions, the matter shall be handled by the cyberspace administration departments and the relevant competent authorities, within the scope of their duties, in accordance with the relevant laws and regulations.
Chapter V — Supplementary Provisions
Article 26. “Mobile internet application programs” as referred to in these Provisions means application software that runs on mobile smart terminals to provide information services to users.
“Mobile internet application program providers” as referred to in these Provisions means the owners or operators of mobile internet application programs that provide information services.
“Mobile internet application program distribution platforms” as referred to in these Provisions means internet information service providers that provide distribution services such as the release, download, and dynamic loading of mobile internet application programs.
Article 27. These Provisions shall take effect on August 1, 2022. The “Provisions on the Administration of Mobile Internet Application Program Information Services” promulgated on June 28, 2016 are repealed at the same time.
Closing
The original document was published in Chinese by the Cyberspace Administration of China; we translated it into English, which is what you read above. This translation is provided for quick comprehension only and should be used at your own discretion and risk — always confirm the current requirements with qualified legal counsel.
If you need further help from our team, contact us today, and our experts will help you keep your presence in China compliant from the ground up.