The Personal Information Protection Law of the People's Republic of China (PIPL) is a comprehensive statutory framework enacted to regulate the processing of personal data within China. It was adopted by the National People's Congress on August 20, 2021 and entered into force on November 1, 2021, coinciding with the promulgation of the Data Security Law and the Cybersecurity Law amendments, forming a triad of data governance legislation.
Legal Context and Objectives
- Purpose: The PIPL aims to protect the rights and interests of individuals regarding their personal information, promote the reasonable use of personal data, and safeguard national security, social public interests, and the legitimate rights of organizations.
- Scope: The law applies to the processing of personal information of individuals within the territory of the PR C, regardless of the location of the data processor. It also covers certain activities of foreign entities that target Chinese individuals or handle data collected in China.
Key Definitions
| Term | Definition (as per PIPL) |
|---|---|
| Personal Information | Any information that can identify a natural person alone or in combination with other information, such as name, ID number, biometric data, health records, etc. |
| Sensitive Personal Information | Information that, if disclosed or used improperly, could lead to personal harms, such as biometrics, race, religion, health, location, financial accounts, etc. |
| Processing | Collection, storage, usage, transmission, provision, disclosure, deletion, or any other act concerning personal information. |
| Data Processor | A natural person, legal entity, or other organization that processes personal information on behalf of a data controller. |
Core Obligations
-
Lawful Basis for Processing
- Consent (explicit for sensitive data) is the primary lawful basis.
- Alternative bases include necessity for contract performance, legal obligations, protection of vital interests, public interest tasks, and legitimate business interests (subject to balancing tests).
-
Data Minimization and Purpose Limitation
- Processors must collect only data necessary for the specified purpose and retain it no longer than required.
-
Transparency and Rights of Data Subjects
- Data subjects have rights to know, decide, consult, correct, delete, and obtain copies of their personal information.
- Controllers must provide clear privacy policies, disclose purposes, methods, and third‑party transfers.
-
Cross‑Border Data Transfer
- Transfers outside China require a security assessment by the Cyberspace Administration of China (CAC) or certification by a recognized body, unless an adequacy decision or statutory exception applies.
-
Data Security Measures
- Requirements for encryption, anonymization, de-identification, and regular security assessments.
- Mandatory breach notification to authorities and affected individuals within a reasonable time frame.
-
Special Protections for Sensitive Information
- Additional safeguards, higher standards for consent, and restrictions on processing for profiling or automated decision‑making.
Enforcement and Penalties
- Supervisory Authorities: Primarily the Cyberspace Administration of China, alongside sector‑specific regulators (e.g., Ministry of Industry and Information Technology).
- Administrative Fines: Up to 5 % of a company's annual revenue in China or RMB 50 million (≈ US 7 million) for serious violations.
- Criminal Liability: In cases of severe misconduct, individuals may face criminal prosecution under related statutes.
Impact on Domestic and International Entities
- Domestic Companies: Must revise data handling practices, implement data protection officers (DPOs), and conduct impact assessments.
- Foreign Companies: Entities offering services to Chinese users or handling data of Chinese residents must comply with the PIPL’s cross‑border transfer regime and may need to establish a local legal presence or appoint a representative in China.
- Industry Sectors: High‑impact sectors such as fintech, e‑commerce, healthcare, and telecommunications have issued sector‑specific guidelines to align with PIPL requirements.
Relationship with Other Chinese Data Laws
- Data Security Law (DSL) (effective September 2021): Focuses on the security of data deemed important to national security and economic development, complementing PIPL’s emphasis on personal privacy.
- Cybersecurity Law (CSL) (effective June 2017, amended 2022): Governs network security and critical information infrastructure, providing a broader regulatory environment within which PIPL operates.
Recent Developments
- Regulatory Guidance: Since 2022, the CAC and other ministries have issued interpretive notices clarifying consent standards, data classification, and cross‑border assessment procedures.
- Judicial Interpretation: Chinese courts have begun applying PIPL provisions in civil litigation concerning data breaches and unlawful processing, setting precedents for damages and injunctive relief.
Summary
The Personal Information Protection Law of the People's Republic of China constitutes the nation's principal legislation governing the collection, use, storage, and transfer of personal data. By establishing stringent consent requirements, data subject rights, and cross‑border transfer controls, the PIPL aligns Chinese data protection standards with global trends such as the European Union’s General Data Protection Regulation (GDPR), while also reflecting China’s specific regulatory priorities concerning national security and social governance. Compliance requires both strategic policy adjustments and operational changes for entities handling personal information of individuals located in China.