Home › Law library › PIPL
CN
PIPL
Personal Information Protection Law of the People's Republic of China
Sourced. Last verified 9 October 2026
China Privacy
- Status
- In force since 1 Nov 2021. Key implementing rules: cross-border data flow provisions (22 Mar 2024), network data security regulations (1 Jan 2025), compliance audit measures (1 May 2025), certification measures (1 Jan 2026).
- Who it applies to
- Processing in mainland China, plus processing abroad of data of people in China to offer them products or services, or to analyse or evaluate their behaviour. Covers private and public sectors.
- Size thresholds
- No size threshold. Volume thresholds trigger extra duties: protection officer above 1 million individuals; mandatory audit every 2 years above 10 million; transfer mechanism tiers at 100,000 / 1 million (sensitive: 10,000).
- Regulator
- Cyberspace Administration of China (CAC), with the Ministry of Public Security, MIIT, SAMR and sector regulators
- Breach or incident reporting
- PIPL: act immediately and notify regulators and affected people (individual notice can be skipped if harm is effectively avoided, unless regulators order it). National cybersecurity incident reporting measures (from 1 Nov 2025): report serious incidents within 4 hours for ordinary network operators, 1 hour for critical information infrastructure operators, 2 hours for state organs.
- Deadline to answer personal data requests
- PIPL sets no fixed number of days: requests (access, copy, correct, delete, portability, explanation) must be handled in a timely manner, with reasons given for refusals.
- Data protection officer
- Appoint a personal information protection officer if processing data of more than 1 million individuals; publish contact details and file them with the regulator.
- Local representative
- Overseas processors caught by the extraterritorial rule must set up a dedicated office or appoint a representative in China and file their details with the regulator (Art. 53).
- Sending data abroad
- Needs separate consent plus one route: CAC security assessment (CIIOs, important data, or >1m people / >10,000 sensitive since 1 Jan), or standard contract filing or certification (100,000-1m people / <10,000 sensitive). Exempt: <100,000 non-sensitive, contracts, HR, emergencies.
- Cookies and consent
- Consent is the main legal basis and must be informed and voluntary. Separate consent is needed for sensitive data, overseas transfers, sharing with another controller, and public disclosure.
- Maximum penalty
- Serious violations: up to RMB 50 million or 5% of the previous year's turnover, plus business suspension or licence revocation; responsible managers fined RMB 100,000-1 million and may be barred from senior roles.
Facts marked “Being verified” are still being confirmed and are not given as answers.
What you must do
- Get consent (separate consent for sensitive data, sharing and overseas transfers) after a full notice
- Run a personal information impact assessment before sensitive, automated-decision or cross-border processing
- Pick the correct transfer route (assessment, standard contract or certification) based on yearly volumes
- Appoint a protection officer above 1 million individuals and file the contact details
- Audit compliance at least every 2 years if processing data of more than 10 million people
- Appoint a China representative if you serve Chinese users from abroad
- Contain incidents immediately and report to the CAC and affected people
Recent changes
2024: Cross-border rules eased (exemptions for under 100,000 people, contracts, HR). 2025: network data regulations (1 Jan) and mandatory compliance audits (1 May). 1 Nov 2025: incident reporting measures. 1 Jan 2026: certification measures (CAC and SAMR) as a third transfer route.
Sources
- Primary source: http://en.npc.gov.cn.cdurl.cn/2021-12/29/c_694559_3.htm
- Second source: https://www.dlapiperdataprotection.com/index.html?t=law&c=CN
- Regulator: Cyberspace Administration of China (CAC), with the Ministry of Public Security, MIIT, SAMR and sector regulators
Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].