Current-law scope and cautions
- MIIT/CAC enforcement focuses on excessive collection, forced permissions, undisclosed SDK behavior, background/self-start practices and consent defects.
- The app operator remains responsible for vendor/SDK governance and accurate disclosure of third-party processing.
- Technical testing should be performed on the deployed app/SDK version; documentation alone is insufficient.
Use: This is a screening/estimation tool, not a legal opinion. Confirm the latest primary authority, regulator practice, local rules and transaction documents before acting.
