Compliance China
Legal basis: PIPL — in force since Nov 1, 2021
Personal Information Protection Law of the People's Republic of China (PIPL) — consolidated text aligned to our global compliance.
CHAPTER I — GENERAL PROVISIONS
Art. 1–4. This Law is enacted pursuant to the Constitution to protect rights over personal information, regulate personal-information processing and promote its reasonable use. The personal information of any natural person is protected by law. The Law applies to processing carried out within China, and also to processing conducted outside China of the information of natural persons located in China where the purpose is to offer products/services to them or to analyze/evaluate their behavior. "Personal information" means all kinds of information, recorded electronically or otherwise, relating to identified or identifiable natural persons, excluding anonymized information; "processing" covers collection, storage, use, handling, transmission, provision, disclosure and deletion.
Art. 5–9. Processing must observe the principles of legality, legitimacy, necessity and good faith; it must have a clear and reasonable purpose, be directly related to it, and have the least possible impact, limited to the minimum scope; it must follow the principles of openness and transparency, disclosing the processing rules; data quality must be ensured; and personal-information controllers are responsible for their processing activities and must adopt the necessary security measures.
Art. 10–12. No organization or individual may unlawfully collect, use, process or transmit others' personal information, nor unlawfully trade, provide or disclose it, nor engage in processing that endangers national security or the public interest. The State establishes and improves the personal-information protection system and actively participates in the drafting of international rules and cooperation on the matter.
CHAPTER II — RULES FOR PROCESSING PERSONAL INFORMATION
Section 1 — General Provisions
Art. 13–17. A controller may process personal information only where: consent is obtained; it is necessary to conclude or perform a contract, or for human-resources management under lawful labor rules; it is necessary to fulfill statutory duties or obligations; it is necessary to respond to public-health emergencies or protect life, health and property in an emergency; it is carried out within reasonable limits for journalism and public-opinion supervision in the public interest; or the information was already lawfully made public. Consent must be given voluntarily, explicitly and on a fully informed basis and may require separate or written consent where the law so provides. The data subject has the right to withdraw consent at any time through a facilitated mechanism, and refusal or withdrawal cannot be used to deny products or services unless processing is strictly necessary for them. Before processing, the controller must truthfully and completely inform the subject of its identity and contact details, the purpose and method, the categories and retention period, and how to exercise rights.
Art. 18–27. Special rules cover: exemptions from notification where the law requires confidentiality or in emergencies; retention limited to the minimum necessary period; joint controllers agreeing on their rights and obligations (with joint liability for harm); entrustment to a processor under a contract with defined purpose, term, method, categories and protective measures, and no sub-entrustment without consent; transfer of information in corporate operations (merger, division, dissolution, bankruptcy) with notice to the subject; provision to another controller requiring separate consent and notice; automated decision-making that must ensure transparency and fairness, with no unreasonable differential treatment and an option to refuse profiling; a prohibition on public disclosure without separate consent; strict limits on image-capture and identification equipment in public places (only for public security, with clear signage); and reasonable processing of information the subject has voluntarily made public, unless the subject expressly refuses.
Section 2 — Rules for Processing Sensitive Personal Information
Art. 28–32. Sensitive personal information is information that, if leaked or unlawfully used, may easily harm a natural person's dignity or endanger their person or property — including biometric data, religious beliefs, specific identities, medical and health data, financial accounts, geolocation and tracking data, and the personal information of minors under 14. It may be processed only for specific purposes, with strict necessity and rigorous protective measures. Separate (or written, where required) consent must be obtained, and the subject must be informed of the necessity of the processing and its impacts. For minors under 14, the consent of a parent or guardian is required, and controllers must formulate specific processing rules.
Section 3 — Special Provisions on Processing by State Organs
Art. 33–37. This Law applies to processing by State organs, with the special provisions of this Section prevailing. Such processing, to fulfill statutory duties, must remain strictly within legal authority and procedures and not exceed the scope necessary. State organs must comply with the notification duty, save exceptions, and must store the information within China; where it is strictly necessary to provide it abroad, a security assessment is required. These provisions also apply to organizations authorized to manage public affairs.
CHAPTER III — RULES FOR THE CROSS-BORDER PROVISION OF PERSONAL INFORMATION
Art. 38–43. To provide personal information outside China for business needs, a controller must meet at least one condition: pass a security assessment organized by the State cyberspace administration; obtain personal-information protection certification from a specialized institution; conclude a contract with the overseas recipient based on the standard contractual clauses formulated by the State cyberspace administration; or meet other conditions set by law. The controller must adopt necessary measures to ensure the overseas recipient meets PIPL standards, and must inform the subject of the recipient's name, contact details, purpose, method and categories, obtaining separate consent. Critical-information-infrastructure operators and controllers processing volumes above the prescribed threshold must store data domestically and undergo a security assessment before any transfer. Requests from foreign judicial or law-enforcement bodies for information stored in China require approval from the competent Chinese authorities, and China may take reciprocal countermeasures.
CHAPTER IV — RIGHTS OF INDIVIDUALS IN PROCESSING ACTIVITIES
Art. 44–50. Individuals have the right to be informed of, and to make decisions about, the processing of their personal information, and to restrict or refuse processing by others. They have the right to consult and obtain a copy of their information and to request its portability to a designated controller. They may request correction or completion of inaccurate or incomplete information. Controllers must delete personal information on their own initiative — or the individual may request deletion — where the purpose has been achieved or is unattainable, the service ends or the retention period expires, consent is withdrawn, or the processing violates the law or agreement. Individuals may request explanations of the processing rules; and, upon a person's death, close relatives may exercise the rights of consultation, copy, correction and deletion for their own legitimate interests. Controllers must establish convenient mechanisms to handle rights requests, giving reasons for any refusal, against which the individual may bring an action before the People's Court.
CHAPTER V — OBLIGATIONS OF PERSONAL-INFORMATION CONTROLLERS
Art. 51–59. Controllers must adopt measures to ensure compliance and prevent unauthorized access, leakage, tampering or loss — including internal management systems and operating procedures, classified management of information, technical security measures (encryption, de-identification), reasonable access permissions with regular staff training, and security-incident response plans. Where processing exceeds the prescribed threshold, a person in charge of personal-information protection must be appointed and disclosed. Overseas controllers within the Law's scope must establish a dedicated body or designate a representative in China. Controllers must conduct periodic compliance audits and, in advance, a personal-information protection impact assessment (retained for at least three years) for the processing of sensitive data, automated decision-making, entrustment/provision/disclosure, cross-border transfers, and other high-impact activities. In the event of a leak, tampering or loss, remedial measures must be taken and the competent department and affected individuals notified. Large internet-platform providers bear additional obligations, including an independent oversight body, fair platform rules, cessation of services to serious violators and periodic social-responsibility reports.
CHAPTER VI — DEPARTMENTS PERFORMING PERSONAL-INFORMATION PROTECTION DUTIES
Art. 60–65. The State cyberspace administration coordinates personal-information protection, while relevant departments of the State Council are responsible for protection, supervision and enforcement within their respective areas of competence. Their duties include promoting awareness and education, receiving and handling complaints and reports, organizing audits and evaluations of applications, and investigating and sanctioning unlawful processing. In exercising their powers they may question the parties, access and copy relevant records, conduct on-site inspections, and — with written approval — seal or seize devices used unlawfully. Any organization or individual has the right to complain to the competent authorities, which must handle the matter promptly and publicize the contact channels.
CHAPTER VII — LEGAL LIABILITY
Art. 66–71. Unlawful processing or failure to fulfill security duties is subject to sanctions by the protection authorities: an order to rectify, a warning, confiscation of unlawful gains, and suspension or cessation of the offending service. Refusal to rectify adds a fine of up to RMB 1 million, with fines of RMB 10,000 to 100,000 for the directly responsible personnel. In severe cases, provincial-level (or higher) authorities may order rectification, confiscate unlawful gains and impose a corporate fine of up to RMB 50 million or up to 5% of the previous year's turnover, may suspend the business and notify the authorities to revoke the operating license; directly responsible individuals may be fined RMB 100,000 to 1 million and temporarily barred from senior management or DPO roles. Unlawful acts are recorded in the social-credit system. Violations that harm a large number of individuals may give rise to a public-interest civil action, and criminal liability is pursued where the conduct constitutes a crime.
CHAPTER VIII — SUPPLEMENTARY PROVISIONS
Art. 72–74. This Law does not apply to the processing of personal information by natural persons for strictly personal or family affairs. Definitions are provided for: personal-information controller; automated decision-making; de-identification; and anonymization (a technically irreversible process). This Law entered into force on November 1, 2021.
The original international text may be consulted directly on the official legislative-disclosure portal of the National People's Congress of China.
Access the Original Source Text (National People's Congress of China)