China
ComprehensivePersonal Information Protection Law (PIPL)
Authority: Cyberspace Administration of China (CAC) | Enforcement: Active | Enacted: November 2021
Overview
China's PIPL, effective November 2021, alongside the Data Security Law and Cybersecurity Law, creates one of the world's most comprehensive (and strict) data governance frameworks. Notable for strong data localisation requirements, strict cross-border transfer rules, and significant penalties.
14-Topic Coverage
Data Protection Authority
Fully AddressedCAC is the primary regulator. Sector regulators (PBOC, MIIT) also have jurisdiction.
Consent Requirements
Fully AddressedIndividual consent is one of several bases. Separate consent required for sensitive data, cross-border transfer, and provision to third parties.
Data Subject Rights
Fully AddressedRights to know, decide, restrict, refuse, access, copy, correct, delete, and portability.
Cross-Border Transfer
Fully AddressedStrict rules: security assessment by CAC, standard contracts, or certification. Important data must undergo security assessment.
Breach Notification
Fully AddressedMust notify authorities and individuals. Remedial measures required immediately.
DPO Requirements
Fully AddressedPersonal information protection officer required for organisations processing above volume thresholds.
Children's Data
Fully AddressedParental consent required for children under 14. Classified as sensitive personal information.
Penalties & Enforcement
Fully AddressedUp to RMB 50 million or 5% of annual revenue. Responsible individuals can be fined and banned from executive positions.
Sector-Specific Rules
Fully AddressedCybersecurity Law, Data Security Law, financial data rules, automotive data rules, health data regulations.
Cookie/Tracking
Partially AddressedGeneral consent requirements apply. Mobile app regulations impose specific requirements.
AI & Automated Decisions
Fully AddressedRight to refuse automated decisions. Regulations on algorithmic recommendations, deep synthesis (deepfakes), and generative AI.
Data Localisation
Fully AddressedCritical Information Infrastructure Operators must store data locally. Important data subject to security assessment for export.
Significant Data Fiduciary
Fully AddressedConcept of "important data" and CII operators triggers enhanced obligations.
Government Data
Fully AddressedState organs have specific obligations under PIPL. National security exemptions apply.
Coverage Summary
Quick Navigation
Need Compliance Help?
Our data privacy team can help you navigate China's regulations.
Book a Consultation