What it is
The Personal Information Protection Law (PIPL) is China's first comprehensive statute on personal information. It was adopted by the Standing Committee of the National People's Congress on 20 August 2021 and took effect on 1 November 2021. It works alongside the Cybersecurity Law and the Data Security Law, and it shares some features with the GDPR while differing in important ways.
Who it applies to
The PIPL applies to the processing of personal information of individuals within China. It also applies to processing outside China where the purpose is to provide products or services to people in China, or to analyze or assess their behavior. The organization that decides how and why data is processed is called a "personal information handler", and an organization acting on its behalf is an "entrusted party". Foreign handlers that fall within scope must set up a dedicated body or designate a representative in China.
Core principles
Processing must be lawful, legitimate, necessary and in good faith, and must not mislead or coerce people. It must have a clear and reasonable purpose, be limited to the minimum scope needed and the method least harmful to individual rights, and be open and transparent. Handlers must also keep data accurate and take responsibility for their processing activities and security.
Legal bases
A handler may process personal information only on a basis set out in the law. These include the individual's consent, necessity for a contract or for human resources management, performance of statutory duties, responding to public health emergencies or protecting life and property in an emergency, reasonable news reporting in the public interest, and reasonable use of information the person has made public. Unlike the GDPR, the PIPL has no general "legitimate interests" basis. Separate consent is required for certain activities, including processing sensitive personal information, sharing data with another handler, publishing data, and sending data abroad.
Individual rights
Individuals have the right to know about and decide on the processing of their information, and to restrict or refuse it. They may also access and copy their data, request portability where the conditions are met, correct and supplement it, and request deletion in defined cases. They may ask handlers to explain their processing rules and may challenge automated decision-making that significantly affects them.
Key obligations
Handlers must adopt internal management rules, classify data, apply technical safeguards such as encryption, train staff, and prepare incident response plans. They must carry out a personal information protection impact assessment in cases such as processing sensitive information, automated decision-making, entrusting or sharing data, and cross-border transfers. Handlers that reach thresholds set by the regulator must appoint a personal information protection officer, and all handlers must run periodic compliance audits. If a leak, tampering or loss occurs or may occur, the handler must take remedial steps and notify the authorities and the affected individuals.
Cross-border transfers
To send personal information outside China, a handler must meet one of several conditions: pass a security assessment organized by the Cyberspace Administration of China (CAC), obtain certification from a professional body, sign the standard contract formulated by the CAC, or satisfy another condition set by law or regulators. It must also tell individuals about the overseas recipient and obtain their separate consent. Operators of critical information infrastructure and handlers above regulator-set volume thresholds must store personal information collected in China within China, and can export it only after a security assessment. The CAC and other regulators have issued detailed implementing rules that change over time, so current guidance should be checked.
Enforcement and penalties
The CAC coordinates enforcement, together with other State Council departments and local authorities. Penalties include orders to correct, warnings, confiscation of illegal gains, and suspension of apps or services. For serious violations the law allows fines of up to RMB 50 million or up to 5% of the previous year's turnover, with personal fines for responsible managers and possible bans from serving as directors or senior managers. Individuals can sue, the burden of proving no fault falls on the handler, and prosecutors and designated organizations can bring public interest actions.
The official text
The authoritative version is the Chinese-language law published by the National People's Congress (npc.gov.cn). There is no official English version. English translations exist but are unofficial, so rely on the Chinese text, not on this summary or on a translation, for anything that matters.
Below is the source we understand to be the official text (Chinese, official). We cannot guarantee it is correct, current, complete, or the authoritative version, and we may have linked or labelled it wrong, so please check it yourself and do not rely on it or on our summary:
Go to the source →