An In-Depth Look at China's Personal Information Protection Law (PIPL) and Its Comparison with GDPR
Abstract
China's Personal Information Protection Law (PIPL) is a comprehensive law that went into effect on November 1, 2021. It is China's first law that specifically regulates the collection, use, and disclosure of personal information. The PIPL is similar to the European Union's General Data Protection Regulation (GDPR) in many ways.
It gives individuals the right to access, correct, and delete their personal data, and it requires businesses to obtain consent before collecting or using personal information.
The PIPL also includes stiff penalties for non-compliance, including fines of up to RMB50 million (about $7.4 million).
The PIPL applies to all businesses that collect or use the personal information of individuals located in China. This includes both domestic and foreign businesses. The law also applies to businesses that process the personal information of individuals located outside of China, but only if the processing is related to the provision of goods or services to individuals located in China, or if the processing is used to analyze or evaluate the activities of individuals located in China.
Overview
The PIPL sets forth several requirements for businesses that collect or use personal information.
These requirements include:
- Obtaining consent from individuals before collecting or using their personal information.
- Providing individuals with access to their personal information and the right to correct or delete it.
- Taking reasonable security measures to protect personal information from unauthorized access, use, disclosure, alteration, or destruction.
- Not transferring personal information outside of China without the individual's consent or taking appropriate safeguards.
The PIPL also gives individuals several rights, including:
- The right to access their personal information.
- The right to correct or delete their personal information.
- The right to object to the processing of their personal information.
- The right to withdraw their consent to the processing of their personal information.
- The right to file a complaint with the relevant authorities if they believe their personal information has been mishandled.
The PIPL is a significant development in China's data privacy landscape. It is the first law that specifically regulates the collection, use, and disclosure of personal information in China. The PIPL is similar to the GDPR in many ways, and it is likely to have a significant impact on businesses that collect or use the personal information of individuals located in China.
Key Differences between GDPR and PIPL
Scope
The GDPR applies to all businesses that process the personal data of individuals located in the European Economic Area (EEA), while the PIPL applies to all businesses that collect or use the personal information of individuals located in China.
Consent
The GDPR requires businesses to obtain explicit consent from individuals before collecting or using their personal information, while the PIPL allows businesses to collect or use personal information without consent only in certain limited, specifically listed circumstances, such as when the processing is necessary for the performance of a contract, for human resources management under lawfully established rules, or to comply with a statutory obligation. Notably, unlike the GDPR, the PIPL has no general "legitimate interests" legal basis, so organizations that rely on it under the GDPR need to reassess their legal basis for processing in China.
Data subject rights
The GDPR gives individuals a number of rights with respect to their personal data, such as the right to access, correct, and delete their personal data, and the right to object to the processing of their personal data. The PIPL also gives individuals a number of rights with respect to their personal data, but these rights are not as extensive as the rights under the GDPR.
Penalties
The GDPR imposes significant penalties for non-compliance, up to €20 million or 4% of global annual turnover, whichever is greater. The PIPL also imposes penalties for non-compliance, but the penalties are not as severe as the penalties under the GDPR.
This article is general information from Data Protection Matters, not legal advice. We aim to be accurate, but it may contain errors or omissions and we give no warranty as to its accuracy or completeness. It reflects the position at the time of writing; privacy laws change and vary by jurisdiction. Verify against official sources, seek advice for your own situation, and rely on it at your own risk.
