Regulations › Rest of world

PIPL

Personal Information Protection Law (China)

In force privacy transfers
WhenIn effect since 1 November 2021
Who enforces itCyberspace Administration of China
Who it applies toOrganizations processing personal information in China, or of people in China for certain purposes.

China's comprehensive privacy law, with strict rules on consent and cross-border transfers.

The law in brief

China's Personal Information Protection Law (PIPL), in force since 1 November 2021, is the country's comprehensive privacy law. It shares structure with the GDPR but is stricter in places: consent is central and often must be separate, sensitive personal information is tightly controlled, and cross-border transfers require one of a small set of state-approved mechanisms.

It sits within a wider framework with the Cybersecurity Law and Data Security Law, and a growing body of implementing regulations issued by the Cyberspace Administration of China (CAC).

Who it applies to

  • Processing of personal information within China.
  • Processing outside China of the personal information of individuals in China, where the purpose is to provide products or services to them, to analyze or assess their behavior, or in other cases set by law.
  • Overseas processors caught by these rules must set up a dedicated office or designate a representative in China.

What it requires

A legal basis, with separate consent where required

Process personal information only on a legal basis in Article 13. Obtain separate consent for processing sensitive personal information, providing it to another processor, public disclosure and cross-border transfer.

Impact assessments

Conduct a personal information protection impact assessment before processing sensitive information, automated decision-making, entrusting processing, providing to others, and transferring abroad, and keep the report for at least three years.

Cross-border transfer mechanisms

Transfer personal information abroad only after a CAC security assessment, certification, or the CAC standard contract, subject to the exemptions in the 2024 provisions; critical information infrastructure operators and large processors must localize data.

Protection officer and audits

Processors above the CAC's threshold appoint a personal information protection officer, and processors conduct regular compliance audits.

Incident response

Take immediate remedial measures after a leak, alteration or loss of personal information, and notify the authorities and affected individuals.

People's rights

Individuals can know and decide about the processing of their information, restrict or refuse it, access and copy their information, transfer it to another processor where conditions are met, correct and delete it, ask for explanations of processing rules, and refuse decisions made solely by automated means that significantly affect them.

Enforcement and penalties

For serious violations, fines of up to RMB 50 million or 5% of the previous year's turnover, confiscation of illegal gains, suspension of business, and revocation of licenses, plus fines and bans from senior roles for responsible individuals (Art. 66).

What's changing

Implementing rules keep arriving. The Network Data Security Management Regulations took effect on 1 January 2025, and measures on personal information protection compliance audits took effect on 1 May 2025. Rules issued in March 2024 relaxed some cross-border transfer requirements with thresholds and exemptions. Regulatory Watch reports new CAC measures.

What to do first

  1. Map processing of individuals in China, including from outside China.
  2. Identify a legal basis for each purpose, and where consent is the basis, collect separate consent where the law requires it.
  3. Run personal information protection impact assessments before sensitive processing, automated decision-making, disclosures to others and cross-border transfers.
  4. Choose a transfer mechanism: CAC security assessment, certification or the standard contract, or confirm an exemption applies.
  5. Plan compliance audits under the 2025 measures.
  6. Appoint a representative in China if you process from outside China within PIPL's scope.

Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.

Recent developments

Nothing reported yet. Regulatory Watch lists new rules, enforcement and court decisions as they arrive.

Sources

Primary sources are being added to this entry.