China - Personal Information Protection Law (2021)
Personal Information Protection Law
个人信息保护法
China
RAI-CN-NA-PIPPRXX-2021The Personal Information Protection Law (PIPL) is China’s comprehensive national data protection statute, adopted on 20 August 2021 and effective 1 November 2021. It sets rules on lawful processing, sensitive personal information, cross-border transfers, data subject rights, processor obligations, enforcement mechanisms and penalties, and assigns lead regulatory responsibilities to Chinese cyberspace and sectoral authorities.
Summary
Read full text ↗Plain English
Overview
The Personal Information Protection Law (PIPL) is China’s landmark comprehensive personal data protection statute, enacted by the Standing Committee of the 13th National People’s Congress on 20 August 2021 and entering into force on 1 November 2021. The PIPL establishes a national legal framework for protecting the rights and interests of natural persons with respect to their personal information and for regulating personal information processing activities. The full official text is published by the National People’s Congress and by central government portals; see the official English text at National People’s Congress (English) and the government announcement at State Council / gov.cn">State Council / gov.cn for the promulgation and effective date details. The law consolidates principles from earlier laws (Civil Code, Cybersecurity Law, Data Security Law) into an omnibus regime that addresses consent, special categories of personal information, cross-border transfer controls, individual rights, processor obligations and significant administrative and criminal liabilities.
Definitions
The PIPL defines key terms that determine scope and obligations. "Personal information" means any information recorded electronically or otherwise, that identifies or can identify a natural person either alone or in combination with other information. "Personal information processor" is any organization or individual determining processing purposes and means. The law distinguishes "sensitive personal information" (biometrics, medical, financial, religious belief, specific identity, whereabouts, personal data of minors under 14, etc.) which requires heightened protection and separate consent. It also defines "automated decision-making," "de-identification" and "anonymization," and sets rules for each concept. The text frames processing activities that are out of scope (e.g., purely personal/household activities, or where other laws prevail for statistical/archive functions).
Governance and Institutional Framework
The PIPL creates a multi-agency governance architecture. The Cyberspace Administration of China (CAC) is designated as the national authority organizing and supervising personal information protection work—especially cross-border transfer security assessments, standard contract formulation, and certification mechanisms. Other entities with specific duties include the Ministry of Public Security (MPS) for public security enforcement, the State Administration for Market Regulation (SAMR) for market and certification roles, and relevant sectoral ministries for sector-specific supervision. The law also envisages coordination mechanisms among departments. Institutional responsibilities and coordination are elaborated in implementing rules and departmental measures issued after enactment; see the CAC and SAMR implementing instruments and official notices at Cyberspace Administration of China and State Administration for Market Regulation.
Key Focus Areas
The PIPL focuses on a set of interlocking regulatory areas. First, legal bases for processing: the law recognizes consent (including separate consent for sensitive data), contract performance, legal obligation, emergency protection of life safety, public interest missions, and legitimate interests subject to balancing tests. Second, individuals' rights: access, copy, correction, deletion, portability, restriction of processing, objection to profiling/automated decisions, and to withdraw consent. Third, processor obligations: purpose limitation, data minimization, lawful and fair processing, transparency and notification, data security and breach reporting, storage limitation, and record-keeping. Fourth, the PIPL imposes special protections for minors (under 14 require guardian consent) and for sensitive categories requiring necessity and strict protective measures. Fifth, cross-border transfers: only permitted via statutory mechanisms—security assessment organized by the CAC, approved certification, standard contracts meeting national templates, or other conditions set by law—and require specific notice to data subjects and separate consent. Finally, accountability and compliance: processors are required to adopt internal management systems, designate responsible persons, perform impact assessments, and maintain handling records. The law also addresses automated decision-making transparency and mandates measures to explain and allow human oversight where decisions materially affect people’s rights and interests.
Implementation Framework
Implementation of the PIPL has proceeded through a mix of administrative measures, technical standards, departmental rules and guidance issued by the CAC, SAMR, MPS and other ministries. Key follow-on instruments address cross-border transfer mechanisms (security assessment protocols, the standard contract template/measures, and PI protection certification schemes), detailed breach reporting procedures, and sectoral rules for finance, healthcare and telecommunications. Organizations subject to the PIPL must embed compliance into corporate governance: adopt written personal information protection policies, appoint responsible personnel, conduct data protection impact assessments (DPIAs) for high-risk processing, implement technical/organizational security measures, and train staff. Many implementing measures require registrations or filings (e.g., filing standard contracts with regulators) and provide thresholds (by volume or sensitivity) that determine which transfer pathway or measure applies. Industry standards and national standards (e.g., GB standards on de-identification and technical security) further guide enterprise practice.
Monitoring and Evaluation
The PIPL requires ongoing supervisory activities and empowers regulators to monitor compliance through inspections, audits and investigations. Regulators may require corrections, impose fines, confiscate illegal gains, suspend or revoke permits, and order cessation of illegal processing. The law mandates that processors keep records of processing activities and impact assessments to enable supervision. Administratively, CAC and other agencies issue guidance, audit results and sectoral enforcement campaigns; the PIPL also contemplates civil remedies, class actions and administrative complaints channels. Monitoring is supported by technical standards and certification programs to evaluate compliance; regulators may publish enforcement actions and guidance to signal priority risks (e.g., minors’ protections, biometric use, algorithmic profiling).
Penalties, Liability, and Appeals
The PIPL provides a graduated penalty regime. For serious violations, administrative fines can reach up to RMB 50 million or 5% of the prior year’s turnover for the responsible entity; other sanctions include confiscation of unlawful gains, suspension of business, revocation of business licenses or permits, and public naming. Violations may also trigger public security administrative penalties or criminal liability where conduct constitutes a crime (e.g., illegal provision, sale or leakage of personal information). Data subjects retain civil claims for damages, and the law contemplates relief via courts and administrative complaint channels. The statute provides procedural rules for administrative enforcement and avenues for administrative review and judicial appeal against regulator decisions.
Relationship to Other Instruments
The PIPL operates alongside and in coordination with China’s Cybersecurity Law and the Data Security Law. It integrates with sector-specific and administrative regulations (finance, telecommunications, healthcare, education), and supplements Civil Code privacy protections. Where other laws provide special rules for statistical, archival or state-organ processing, those provisions may prevail. Implementation of the PIPL has required a sequence of secondary measures—security assessment rules, standard contract measures, and certification rules—largely issued by the CAC, SAMR and other ministries, which together complete the operational regime for cross-border transfers and supervision.
International Alignment
While the PIPL is grounded in China’s legal context and national-security considerations, many elements echo international practices: rights-based data subject protections, purpose limitation, data minimization, and cross-border transfer safeguards. The PIPL’s cross-border mechanisms (security assessment, standard contracts, certification) are functionally similar to EU mechanisms (adequacy decisions, standard contractual clauses, binding corporate rules) though implemented under different institutional and substantive criteria. The PIPL also signals China’s intent to shape international rule‑making on personal information protection and to engage in cross-border regulatory dialogue; see official statements on international cooperation by Chinese authorities at National People’s Congress (English) and CAC materials at Cyberspace Administration of China.
Implementation Timeline
| Event | Date |
|---|---|
| Adoption by NPC Standing Committee | 2021-08-20 |
| Promulgation (Presidential Order) | 2021-08-20 |
| Entry into force / Effective date | 2021-11-01 |
| Measures for Cross-Border Security Assessment (CAC) | 2022-09-01 (Measures effective) |
| Measures for Standard Contract for Cross-Border Transfer (CAC) | 2023-06-01 (Measures effective) |
Compliance Checklist
| Action | Notes |
|---|---|
| Map personal data flows | Identify categories, purposes, storage locations and retention periods |
| Classify sensitive data | Apply separate consent and stricter controls for sensitive categories |
| Obtain lawful basis/consent | Use separate consent for sensitive processing and minors under 14 |
| Conduct DPIAs | For large-scale, high-risk, automated decision-making and cross-border transfers |
| Appoint responsible person | Designate a data protection officer or responsible manager and contact |
| Implement technical & organizational measures | Encryption, access controls, logs, incident response |
| Prepare breach notification procedures | Notify regulators and affected individuals as required |
| Establish cross-border transfer mechanism | Security assessment, certification or use standard contract as applicable |
| Maintain processing records | Retention for regulatory review and audits |
Sources and References
| Source | Type |
|---|---|
| Personal Information Protection Law (official English text at National People’s Congress) | Primary Source |
| State Council / gov.cn promulgation announcement | Primary Source |
| Cyberspace Administration of China (CAC) - regulatory measures and guidance | Primary Source (implementing measures) |
China's Personal Information Protection Law (PIPL) is a comprehensive data privacy law designed to protect the personal information of individuals and regulate how organizations process it, both within China and, in some cases, abroad. It applies to any organization or individual that processes personal information of natural persons in China. Crucially, it also reaches outside China, covering processing activities that aim to provide goods or services to individuals in China, or analyze their behavior.
The law, effective November 1, 2021, sets several key obligations. Processors must have a lawful basis for handling data, often requiring explicit consent. - Separate consent is needed for sensitive data like biometrics or financial details. - Separate consent is also required for processing personal information of minors under 14. Organizations must implement robust data security measures, conduct impact assessments for high-risk processing, and report data breaches promptly. A significant challenge is the strict regime for transferring data outside China, which generally requires either a security assessment by the Cyberspace Administration of China (CAC), an approved certification, or a standard contract.
Non-compliance carries substantial penalties, including administrative fines up to RMB 50 million or 5% of the prior year's turnover for serious violations. Other sanctions can include confiscation of illegal gains, business suspension, revocation of licenses, and even criminal liability. A practical pitfall for many international businesses is underestimating the law's extraterritorial reach and the specific, often complex, requirements for cross-border data transfers, which have been further detailed by subsequent regulations.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 15 marked completePlain-English obligations under China - Personal Information Protection Law (2021). Not legal advice — verify against the official text before relying on it.
- #1Critical
Applies to: Personal information processors.
“legal bases for processing: the law recognizes consent... contract performance, legal obligation...”
- #2Critical
Applies to: Personal information processors.
“"sensitive personal information" ... which requires heightened protection and separate consent.”
- #3Critical
Applies to: Personal information processors.
“special protections for minors (under 14 require guardian consent)”
- #4Critical
Applies to: Personal information processors.
“processor obligations: ... data security and breach reporting, storage limitation, and record-keeping.”
- #5Critical
Applies to: Personal information processors.
“processor obligations: ... data security and breach reporting, storage limitation, and record-keeping.”
- #6Critical
Applies to: Personal information processors transferring data outside China.
“cross-border transfers: only permitted via statutory mechanisms—security assessment... certification, standard contracts...”
- #7Critical
Applies to: Personal information processors transferring data outside China.
“cross-border transfers: ... and require specific notice to data subjects and separate consent.”
- #8Critical
Applies to: Personal information processors.
“perform impact assessments, and maintain handling records.”
- #9Important
Applies to: Personal information processors.
“individuals' rights: access, copy, correction, deletion, portability, restriction of processing, objection...”
- #10Important
Applies to: Personal information processors.
“processor obligations: purpose limitation, data minimization, lawful and fair processing...”
- #11Important
Applies to: Personal information processors.
“processor obligations: ... transparency and notification, data security and breach reporting...”
- #12Important
Applies to: Personal information processors.
“processor obligations: ... data security and breach reporting, storage limitation, and record-keeping.”
- #13Important
Applies to: Personal information processors.
“processor obligations: ... data security and breach reporting, storage limitation, and record-keeping.”
- #14Important
Applies to: Personal information processors.
“processors are required to adopt internal management systems, designate responsible persons...”
- #15Important
Applies to: Personal information processors using automated decision-making.
“automated decision-making transparency and mandates measures to explain and allow human oversight...”
Related Regulations
Data Security Law of the People's Republic of China
China92% similar
Cybersecurity Law of the People's Republic of China
China91% similar
Security Assessment Measures for Outbound Data Transfers (Measures for the Security Assessment of Outbound Data Transfers)
China90% similar
Regulations on Network Data Security Management (网络数据安全管理条例)
China89% similar
Personal Data Protection Act (PDPA)
Taiwan86% similar
© Regulations.AI — created on 13-Jun-2026