China's Personal Information Protection Law (PIPL)
The Personal Information Protection Law (Geren Xinxi Baohu Fa, PIPL), effective 1 November 2021, is China’s comprehensive data protection legislation. The PIPL establishes a framework for the processing of personal information that draws on the EU’s General Data Protection Regulation (GDPR) while incorporating distinctive Chinese elements, including broader state interests, extensive data localization requirements, and strong enforcement mechanisms.
Scope and Jurisdiction
The PIPL applies to the processing of personal information of natural persons within China — regardless of the processor’s location — and to the processing of personal information of natural persons in China by processors outside China where the purpose is to provide products or services to persons in China, to analyze behavior of persons in China, or any other circumstances provided by law (Article 3). This extraterritorial scope mirrors the GDPR and captures the activities of foreign companies that process Chinese personal information.
Personal information (geren xinxi) is defined broadly as any information related to an identified or identifiable natural person, recorded electronically or by other means (Article 4). The PIPL distinguishes between general personal information and sensitive personal information (min’gan geren xinxi, Article 28), which includes biometric data, religious beliefs, financial account information, precise location data, health data, and information of minors under 14.
Consent and Data Processing Principles
Consent (tongyi) is the primary legal basis for processing personal information (Article 13). The PIPL requires that consent be freely given, specific, and informed. Separate consent is required for processing sensitive personal information (Article 29) and for transferring personal information to third parties or outside China (Article 39). Data subjects have the right to withdraw consent, and processing must cease upon withdrawal (Article 15).
The PIPL establishes processing principles, including: lawfulness, legitimacy, and necessity; purpose limitation; transparency; data minimization; accuracy; storage limitation; integrity and confidentiality; and accountability. These principles structure the obligations of data processors throughout the data lifecycle.
Data Processor Obligations
Processors must implement management, technical, and security measures to protect personal information (Article 51). Measures include internal management systems, staff training, security technologies, and emergency response plans. Processors processing significant volumes of personal information must designate a data protection officer (geren xinxi baohu fuzeren, Article 52) and conduct regular compliance audits (Article 54).
Processors must conduct personal information protection impact assessments (yingxiang pinggu, Article 55) before processing sensitive information, engaging in automated decision-making, entrusting processing to third parties, transferring data to other processors, or transferring data outside China. The assessment must record the processing purpose, methods, risks, and mitigation measures.
Cross-Border Transfer
The PIPL imposes strict conditions on cross-border transfer of personal information. Under Article 38, a processor may transfer personal information outside China only if it passes a security assessment organized by the CAC (for critical information infrastructure operators and processors processing large volumes of personal information), obtains certification from a professional body, or enters into a standard contract with the overseas recipient.
The CAC’s Measures on the Security Assessment of Cross-Border Data Transfer (2022) established thresholds for mandatory security assessment: processing personal information of more than 1 million individuals, transferring personal information of more than 100,000 individuals cumulatively, or transferring sensitive personal information of more than 10,000 individuals cumulatively. The Standard Contract for Cross-Border Transfer of Personal Information (2023) provides a mechanism for smaller-scale transfers. The PIPL also requires that data subjects whose personal information will be transferred be informed and provide separate consent.
Rights of Data Subjects
The PIPL grants data subjects extensive rights: the right to know and decide (Article 44); the right to access their personal information (Article 45); the right to correct inaccurate information (Article 46); the right to delete information where processing is no longer necessary (Article 47); the right to request explanation of processing rules (Article 48); and the right to data portability (Article 45). These rights are enforceable through complaints to the CAC and through court actions.
Data subjects also have the right to refuse automated decision-making (Article 24) and to demand that processors not use automated decision-making in ways that discriminate or unreasonably differentiate. Where decisions significantly affect the data subject’s interests, the subject has the right to request explanation and to refuse decisions based solely on automated processing.
Penalties and Enforcement
The PIPL imposes severe penalties for violations. Administrative penalties include: confiscation of illegal gains; fines up to RMB 50 million or 5% of annual turnover (Article 66); suspension of activities; rectification orders; and revocation of licenses. Responsible persons may be fined up to RMB 100,000 and prohibited from holding certain positions. Criminal liability applies for serious violations.
Enforcement is primarily the responsibility of the CAC, which has established specialized data protection enforcement divisions. The CAC has conducted high-profile enforcement actions, including investigations into mobile apps for illegal data collection and fining companies for violating consent requirements. The PIPL also provides a private right of action, and courts have accepted cases seeking damages for PIPL violations.
Comparison with GDPR
The PIPL shares many features with the GDPR, including consent requirements, data subject rights, and accountability obligations. However, significant differences exist: the PIPL allows processing for unspecified state interests, imposes stronger data localization requirements, provides for state interests as legitimate processing bases, and establishes a regulatory model with stronger government oversight and weaker individual enforcement.