Chinese cybersecurity regulators have publicly cited 82 mobile applications and lightweight mini-programs for illegally harvesting and mishandling personal user data, targeting prominent financial platforms, healthcare providers, and travel services.
Among the most severe offenders, ride-sharing platform Didadishunfengche led the list by incurring citations across four separate infraction categories, including unauthorized data collection and critical security flaws. Other top violators included wearable app Fere Fit, smart mobility platform Weilaidian, Hexi Parking, and children's app Mengbao Picture Book Stories, each cited for three distinct privacy violations.
The regulatory notice was issued as part of a joint 2026 personal information protection campaign led by the Cyberspace Administration of China, the Ministry of Industry and Information Technology, and the Ministry of Public Security. The non-compliant apps were identified through technical evaluations conducted by China's National Computer Virus Emergency Response Center.
The crackdown flagged software operating across major Android app stores as well as mini-programs hosted on social platforms such as WeChat, Baidu, and Alipay. Notable entities cited in the notice include financial outlets Sina Finance and Cailian Press, job recruitment platform Liepin, medical platform Lilac Doctor, and online patient portals for several major university teaching hospitals.
According to regulatory findings, the most common infraction involved failing to disclose the scope, purpose, and methods of data collection by embedded third-party software development kits (SDKs), which affected 49 platforms. Another 20 applications failed to provide clear privacy notices before initial operation or relied on pre-ticked consent boxes to force user agreement.
Regulators also identified severe security vulnerabilities and non-compliance with data privacy laws across several key areas:
Security Vulnerabilities: 13 applications lacked essential technical safeguards to prevent unauthorized access, data leaks, tampering, or loss.
Third-Party Data Sharing: 11 platforms shared user personal information with external parties without disclosing the recipient's identity, purpose, or obtaining explicit individual consent.
Algorithmic Profiling and Marketing: Four apps failed to offer opt-out options for automated decision-making and targeted commercial marketing.
Protection of Minors: Three applications processed personal data from children under the age of 14 without establishing mandatory specialized privacy rules.
Lack of Transparency: Four platforms operated without any privacy policy, while others imposed unreasonable hurdles for account deletion or failed to provide mechanisms for users to withdraw data consent.
Authorities confirmed that enforcement action against non-compliant developers is escalating. Following a separate inspection sweep earlier this year that cited 75 non-compliant applications, regulators reported that 28 platforms failed follow-up technical re-evaluations and have been forcibly removed from domestic app stores.

