China - Personal Information Protection Law (2021)

Personal Information Protection Law

个人信息保护法

China

RAI-CN-NA-PIPPRXX-2021
Effective: November 1, 2021
In Force(In Force)
ActData Protection and PrivacyGovernance and OversightConformity Assessment and Registration
Export PDF

The Personal Information Protection Law (PIPL) is China’s comprehensive national data protection statute, adopted on 20 August 2021 and effective 1 November 2021. It sets rules on lawful processing, sensitive personal information, cross-border transfers, data subject rights, processor obligations, enforcement mechanisms and penalties, and assigns lead regulatory responsibilities to Chinese cyberspace and sectoral authorities.

Overview

The Personal Information Protection Law (PIPL) is China’s landmark comprehensive personal data protection statute, enacted by the Standing Committee of the 13th National People’s Congress on 20 August 2021 and entering into force on 1 November 2021. The PIPL establishes a national legal framework for protecting the rights and interests of natural persons with respect to their personal information and for regulating personal information processing activities. The full official text is published by the National People’s Congress and by central government portals; see the official English text at National People’s Congress (English) and the government announcement at State Council / gov.cn">State Council / gov.cn for the promulgation and effective date details. The law consolidates principles from earlier laws (Civil Code, Cybersecurity Law, Data Security Law) into an omnibus regime that addresses consent, special categories of personal information, cross-border transfer controls, individual rights, processor obligations and significant administrative and criminal liabilities.

Definitions

The PIPL defines key terms that determine scope and obligations. "Personal information" means any information recorded electronically or otherwise, that identifies or can identify a natural person either alone or in combination with other information. "Personal information processor" is any organization or individual determining processing purposes and means. The law distinguishes "sensitive personal information" (biometrics, medical, financial, religious belief, specific identity, whereabouts, personal data of minors under 14, etc.) which requires heightened protection and separate consent. It also defines "automated decision-making," "de-identification" and "anonymization," and sets rules for each concept. The text frames processing activities that are out of scope (e.g., purely personal/household activities, or where other laws prevail for statistical/archive functions).

Governance and Institutional Framework

The PIPL creates a multi-agency governance architecture. The Cyberspace Administration of China (CAC) is designated as the national authority organizing and supervising personal information protection work—especially cross-border transfer security assessments, standard contract formulation, and certification mechanisms. Other entities with specific duties include the Ministry of Public Security (MPS) for public security enforcement, the State Administration for Market Regulation (SAMR) for market and certification roles, and relevant sectoral ministries for sector-specific supervision. The law also envisages coordination mechanisms among departments. Institutional responsibilities and coordination are elaborated in implementing rules and departmental measures issued after enactment; see the CAC and SAMR implementing instruments and official notices at Cyberspace Administration of China and State Administration for Market Regulation.

Key Focus Areas

The PIPL focuses on a set of interlocking regulatory areas. First, legal bases for processing: the law recognizes consent (including separate consent for sensitive data), contract performance, legal obligation, emergency protection of life safety, public interest missions, and legitimate interests subject to balancing tests. Second, individuals' rights: access, copy, correction, deletion, portability, restriction of processing, objection to profiling/automated decisions, and to withdraw consent. Third, processor obligations: purpose limitation, data minimization, lawful and fair processing, transparency and notification, data security and breach reporting, storage limitation, and record-keeping. Fourth, the PIPL imposes special protections for minors (under 14 require guardian consent) and for sensitive categories requiring necessity and strict protective measures. Fifth, cross-border transfers: only permitted via statutory mechanisms—security assessment organized by the CAC, approved certification, standard contracts meeting national templates, or other conditions set by law—and require specific notice to data subjects and separate consent. Finally, accountability and compliance: processors are required to adopt internal management systems, designate responsible persons, perform impact assessments, and maintain handling records. The law also addresses automated decision-making transparency and mandates measures to explain and allow human oversight where decisions materially affect people’s rights and interests.

Implementation Framework

Implementation of the PIPL has proceeded through a mix of administrative measures, technical standards, departmental rules and guidance issued by the CAC, SAMR, MPS and other ministries. Key follow-on instruments address cross-border transfer mechanisms (security assessment protocols, the standard contract template/measures, and PI protection certification schemes), detailed breach reporting procedures, and sectoral rules for finance, healthcare and telecommunications. Organizations subject to the PIPL must embed compliance into corporate governance: adopt written personal information protection policies, appoint responsible personnel, conduct data protection impact assessments (DPIAs) for high-risk processing, implement technical/organizational security measures, and train staff. Many implementing measures require registrations or filings (e.g., filing standard contracts with regulators) and provide thresholds (by volume or sensitivity) that determine which transfer pathway or measure applies. Industry standards and national standards (e.g., GB standards on de-identification and technical security) further guide enterprise practice.

Monitoring and Evaluation

The PIPL requires ongoing supervisory activities and empowers regulators to monitor compliance through inspections, audits and investigations. Regulators may require corrections, impose fines, confiscate illegal gains, suspend or revoke permits, and order cessation of illegal processing. The law mandates that processors keep records of processing activities and impact assessments to enable supervision. Administratively, CAC and other agencies issue guidance, audit results and sectoral enforcement campaigns; the PIPL also contemplates civil remedies, class actions and administrative complaints channels. Monitoring is supported by technical standards and certification programs to evaluate compliance; regulators may publish enforcement actions and guidance to signal priority risks (e.g., minors’ protections, biometric use, algorithmic profiling).

Penalties, Liability, and Appeals

The PIPL provides a graduated penalty regime. For serious violations, administrative fines can reach up to RMB 50 million or 5% of the prior year’s turnover for the responsible entity; other sanctions include confiscation of unlawful gains, suspension of business, revocation of business licenses or permits, and public naming. Violations may also trigger public security administrative penalties or criminal liability where conduct constitutes a crime (e.g., illegal provision, sale or leakage of personal information). Data subjects retain civil claims for damages, and the law contemplates relief via courts and administrative complaint channels. The statute provides procedural rules for administrative enforcement and avenues for administrative review and judicial appeal against regulator decisions.

Relationship to Other Instruments

The PIPL operates alongside and in coordination with China’s Cybersecurity Law and the Data Security Law. It integrates with sector-specific and administrative regulations (finance, telecommunications, healthcare, education), and supplements Civil Code privacy protections. Where other laws provide special rules for statistical, archival or state-organ processing, those provisions may prevail. Implementation of the PIPL has required a sequence of secondary measures—security assessment rules, standard contract measures, and certification rules—largely issued by the CAC, SAMR and other ministries, which together complete the operational regime for cross-border transfers and supervision.

International Alignment

While the PIPL is grounded in China’s legal context and national-security considerations, many elements echo international practices: rights-based data subject protections, purpose limitation, data minimization, and cross-border transfer safeguards. The PIPL’s cross-border mechanisms (security assessment, standard contracts, certification) are functionally similar to EU mechanisms (adequacy decisions, standard contractual clauses, binding corporate rules) though implemented under different institutional and substantive criteria. The PIPL also signals China’s intent to shape international rule‑making on personal information protection and to engage in cross-border regulatory dialogue; see official statements on international cooperation by Chinese authorities at National People’s Congress (English) and CAC materials at Cyberspace Administration of China.

Implementation Timeline

EventDate
Adoption by NPC Standing Committee2021-08-20
Promulgation (Presidential Order)2021-08-20
Entry into force / Effective date2021-11-01
Measures for Cross-Border Security Assessment (CAC)2022-09-01 (Measures effective)
Measures for Standard Contract for Cross-Border Transfer (CAC)2023-06-01 (Measures effective)

Compliance Checklist

ActionNotes
Map personal data flowsIdentify categories, purposes, storage locations and retention periods
Classify sensitive dataApply separate consent and stricter controls for sensitive categories
Obtain lawful basis/consentUse separate consent for sensitive processing and minors under 14
Conduct DPIAsFor large-scale, high-risk, automated decision-making and cross-border transfers
Appoint responsible personDesignate a data protection officer or responsible manager and contact
Implement technical & organizational measuresEncryption, access controls, logs, incident response
Prepare breach notification proceduresNotify regulators and affected individuals as required
Establish cross-border transfer mechanismSecurity assessment, certification or use standard contract as applicable
Maintain processing recordsRetention for regulatory review and audits

Sources and References

SourceType
Personal Information Protection Law (official English text at National People’s Congress)Primary Source
State Council / gov.cn promulgation announcementPrimary Source
Cyberspace Administration of China (CAC) - regulatory measures and guidancePrimary Source (implementing measures)
Plain English

China's Personal Information Protection Law (PIPL) is a comprehensive data privacy law designed to protect the personal information of individuals and regulate how organizations process it, both within China and, in some cases, abroad. It applies to any organization or individual that processes personal information of natural persons in China. Crucially, it also reaches outside China, covering processing activities that aim to provide goods or services to individuals in China, or analyze their behavior.

The law, effective November 1, 2021, sets several key obligations. Processors must have a lawful basis for handling data, often requiring explicit consent. - Separate consent is needed for sensitive data like biometrics or financial details. - Separate consent is also required for processing personal information of minors under 14. Organizations must implement robust data security measures, conduct impact assessments for high-risk processing, and report data breaches promptly. A significant challenge is the strict regime for transferring data outside China, which generally requires either a security assessment by the Cyberspace Administration of China (CAC), an approved certification, or a standard contract.

Non-compliance carries substantial penalties, including administrative fines up to RMB 50 million or 5% of the prior year's turnover for serious violations. Other sanctions can include confiscation of illegal gains, business suspension, revocation of licenses, and even criminal liability. A practical pitfall for many international businesses is underestimating the law's extraterritorial reach and the specific, often complex, requirements for cross-border data transfers, which have been further detailed by subsequent regulations.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 15 marked complete

Plain-English obligations under China - Personal Information Protection Law (2021). Not legal advice — verify against the official text before relying on it.

  1. #1Critical

    Applies to: Personal information processors.

    legal bases for processing: the law recognizes consent... contract performance, legal obligation...
  2. #2Critical

    Applies to: Personal information processors.

    "sensitive personal information" ... which requires heightened protection and separate consent.
  3. #3Critical

    Applies to: Personal information processors.

    special protections for minors (under 14 require guardian consent)
  4. #4Critical

    Applies to: Personal information processors.

    processor obligations: ... data security and breach reporting, storage limitation, and record-keeping.
  5. #5Critical

    Applies to: Personal information processors.

    processor obligations: ... data security and breach reporting, storage limitation, and record-keeping.
  6. #6Critical

    Applies to: Personal information processors transferring data outside China.

    cross-border transfers: only permitted via statutory mechanisms—security assessment... certification, standard contracts...
  7. #7Critical

    Applies to: Personal information processors transferring data outside China.

    cross-border transfers: ... and require specific notice to data subjects and separate consent.
  8. #8Critical

    Applies to: Personal information processors.

    perform impact assessments, and maintain handling records.
  9. #9Important

    Applies to: Personal information processors.

    individuals' rights: access, copy, correction, deletion, portability, restriction of processing, objection...
  10. #10Important

    Applies to: Personal information processors.

    processor obligations: purpose limitation, data minimization, lawful and fair processing...
  11. #11Important

    Applies to: Personal information processors.

    processor obligations: ... transparency and notification, data security and breach reporting...
  12. #12Important

    Applies to: Personal information processors.

    processor obligations: ... data security and breach reporting, storage limitation, and record-keeping.
  13. #13Important

    Applies to: Personal information processors.

    processor obligations: ... data security and breach reporting, storage limitation, and record-keeping.
  14. #14Important

    Applies to: Personal information processors.

    processors are required to adopt internal management systems, designate responsible persons...
  15. #15Important

    Applies to: Personal information processors using automated decision-making.

    automated decision-making transparency and mandates measures to explain and allow human oversight...

© Regulations.AI — created on 13-Jun-2026