Aug 03, 2026 · 7 min read
China Is Quietly Rewriting When Consent Is Optional
TC260's draft revision of GB/T 35273 adds a whole chapter on picking a legal basis and an appendix of worked examples by industry. Public comment closes August 16, 2026, and none of it is legally binding — which is exactly why compliance teams should read it.
China's Personal Information Protection Law has said since 2021 that consent is one of seven ways to lawfully process personal data. In practice, most companies operating in China treat it as the only one, because nobody in authority ever explained where the other six begin and end. On June 17, 2026, the standards body that writes China's privacy playbook finally tried. The result is a draft, it is voluntary, and it is probably the most consequential privacy document to come out of Beijing this year.
Key Takeaways
- TC260, China's National Information Security Standardization Technical Committee, released draft amendments to GB/T 35273 on June 17, 2026, with public comment closing August 16, 2026.
- The draft adds an entirely new Chapter 5 on choosing a legal basis for collecting personal data, plus a new Appendix D of legal basis example scenarios organised by industry.
- GB/T 35273 carries no legal force, but Chinese regulators and businesses use it as the working benchmark for PIPL compliance, so its interpretations tend to become the operating rule.
- The current version of the standard was published in 2020, more than a year before PIPL took effect in November 2021, meaning China's default compliance reference has never been written against the law it interprets.
- Chapter 5 reportedly bars companies from using contract necessity to justify personalised advertising or user profiling, pushing those activities back toward separate consent.
What Is GB/T 35273, and Why Does a Nonbinding Standard Matter?
GB/T 35273 is the Personal Information Security Specification, a recommended national standard first issued in 2017 and last revised in 2020. The "T" in the designation marks it as recommended rather than mandatory. No fine attaches to ignoring it. Companies ignore it anyway at their peril, because Chinese regulators reach for it when they need to decide whether a given data practice was reasonable, and Chinese companies reach for it when they need to argue that it was.
The standard predates the law it now serves. Stanford's DigiChina project published an English translation of the original specification back when it was the closest thing China had to comprehensive privacy rules. PIPL arrived later and took effect on November 1, 2021. Nobody updated the standard afterward. So for nearly five years, the document that Chinese compliance teams treat as the map has been describing terrain that changed underneath it. That gap is the real subject of this revision.
What Does the New Chapter 5 Actually Change?
Chapter 5 is a new section devoted entirely to selecting an appropriate legal basis for collecting personal data, and it comes with a new Appendix D of example scenarios showing how each basis applies across different industries. The IAPP's summary of the draft frames this as filling a gap PIPL left open: the law permits processing without consent for contract performance, human resources management and statutory duties, but says almost nothing about how far those categories stretch.
Chinese language analyses of the draft describe Chapter 5 as tightening as much as it loosens. Contract necessity is limited to what is genuinely required to achieve the core purpose of the contract, with an explicit carve out saying personalised advertising and user profiling unrelated to contract performance cannot ride on that basis. HR management is scoped to hiring, workforce administration, discipline, pay, performance and disputes, and only where a documented labour rule or collective agreement supports it. Consent itself gets stricter too: default, passive and coerced consent are called out as invalid, with a documentation requirement attached.
The broader revision is not limited to legal basis. A second IAPP analysis of the draft notes new material on AI and large language model integrations, expanded sensitive personal information treatment, supply chain accountability for third party and SDK providers, and a mechanism for handling conflicts between Chinese and foreign privacy law.
Why Is Consent Such a Bottleneck Under PIPL?
Because PIPL made consent the path of least resistance and then made consent expensive. Article 13 of the law, in DigiChina's translation, lists seven circumstances permitting processing and states that consent is not required for the second through seventh. On paper that is a menu. In practice, the other six were vague enough that risk averse counsel defaulted to consent for everything, then layered on separate consent for sensitive data, automated decision making and cross border transfers.
Consent maximalism has a failure mode that compliance teams know well: an individual can withdraw it. Build payroll, fraud checks or security logging on consent and any employee or customer can unilaterally break the process. That is the practical pressure Chapter 5 responds to. Give organisations a defensible way to say "this runs on contract necessity, not consent," and consent stops being load bearing for things that were never really optional.
How Does This Compare to GDPR Article 6?
Structurally it is close. Substantively there is one gap that changes everything. Article 6 of the GDPR gives six lawful bases, and the sixth is legitimate interests — an open ended balancing test that European companies lean on constantly for security, fraud prevention, analytics and, controversially, direct marketing. PIPL Article 13 has no equivalent. Every Chinese basis is enumerated and closed.
Most coverage of this draft reads it as China converging on the European model. The more interesting reading is the reverse. China is importing GDPR's structure while deliberately leaving out the one basis that gives controllers flexibility, and then using a voluntary technical standard to supply that flexibility through interpretation instead. Europe put the escape hatch in the regulation and spent a decade litigating its edges, as anyone following how EU regulators treat email tracking consent can attest. China is putting a narrower version in a document that can be revised without going through the legislature.
What This Means for Marketing Email and Analytics in China
If the draft is adopted as written, the "we process this under the contract" argument for behavioural marketing gets noticeably harder to make in China. Contract necessity is scoped to the core purpose of the agreement. A user who signs up for a service has contracted for the service, not for profiling, and the draft appears to say so directly. That pushes personalised recommendation, segmentation and profiling back toward separate consent.
Email marketing programmes inherit the same problem. Open tracking, click tracking and engagement scoring are profiling activities dressed as delivery telemetry, and they are rarely necessary to fulfil anything the recipient actually agreed to. European regulators reached that conclusion years ago — France's CNIL has been explicit that tracking pixels require consent like any other tracker. A Chapter 5 that tells Chinese marketers the same thing would align two of the world's three largest digital advertising markets on the question.
The consent quality rules matter just as much as the basis rules. Calling default, passive and coerced consent invalid is a direct shot at the prechecked box and the bundled agreement, which are the same patterns European enforcement has been dismantling. If you have already audited your signup flows against consent dark pattern findings, that work transfers.
What Compliance Teams Should Do Before August 16
The comment window closes August 16, 2026, and the standard is registered through China's national standards platform run by the State Administration for Market Regulation. Four things worth doing:
- Inventory what currently runs on consent. Separate the processing that genuinely needs a user's permission from the processing you put behind consent because nobody could name a better basis. The second pile is where Chapter 5 changes your posture.
- Pressure test your contract necessity claims. For each one, write down the specific contract clause and the specific data fields it justifies. The draft expects that mapping to exist on paper, and an argument you cannot write down is one you cannot defend.
- Isolate marketing and profiling from service delivery. If personalisation, segmentation and engagement tracking are bundled into the same consent as account creation, unbundle them now rather than after the standard lands.
- Read Appendix D against your own sector. The example scenarios are organised by industry. Where a listed example is close to something you do, it becomes the closest thing to a regulator's stated expectation you will get.
Looking Ahead
Drafts change, and this one may narrow or widen before it is finalised, so treat the Chapter 5 details as directional rather than settled. What is unlikely to change is the mechanism. China has chosen to resolve its biggest open question in privacy law — when consent is genuinely required — through a recommended standard rather than through amendment or judicial interpretation. That is faster, quieter and easier to revise, and it means the practical rules for handling personal data in China will keep arriving as technical documents from TC260 rather than as laws. Anyone tracking Chinese privacy compliance should be reading the standards pipeline, not just the statute book.