Loading…
Loading…
The PIPL organises personal-information processing obligations around seven categories of legal basis (Art. 13), collapsing the prior patchwork of sector-specific rules:
1. Consent — the primary legal basis for most commercial processing; must be voluntary, informed, unambiguous, and specific. Separate consent is required for processing sensitive personal information (Art. 29), for cross-border transfers (Art. 39), and for use in automated decision-making that materially affects the individual (Art. 24). 2. Contract performance / pre-contract steps — processing necessary to conclude or perform a contract to which the individual is a party (Art. 13(2)). 3. Statutory or legally mandated duties — processing required for lawful compliance by the controller (Art. 13(3)). 4. Vital interests — processing necessary to protect life, health, or property in emergencies (Art. 13(4)). 5. Public interest / news reporting — limited carve-out for journalistic, academic, and public-health purposes (Art. 13(5)/(6)). 6. Public-domain data — personal information lawfully disclosed by the subject or otherwise already public, subject to purpose-consistency limits (Art. 13(7)). 7. Other circumstances prescribed by law — residual catch-all for sector-specific statutes.
Three compliance channels for transferring personal information out of China:
| Channel | Administered by | Trigger |
|---|---|---|
| CAC security assessment | Cyberspace Administration of China | CIIOs; handlers exceeding volume thresholds (1M+ individuals for non-sensitive PI, or 100K+ individuals for sensitive PI — thresholds raised by the 2024 CAC Cross-Border Data Flow Provisions) |
| PI protection certification | CAC-accredited third-party body | Voluntary alternative for regular transfers not meeting SA thresholds |
| Standard Contractual Clauses (PIPL SCCs) | CAC template (issued Jun 2022) | Default channel for SMEs and lower-volume transfers |
The 2024-03-22-cn-cac-cross-border-data-flow-provisions significantly relaxed the SA-trigger thresholds — raising the 100K-non-sensitive threshold to 1M — and created additional exemptions (e.g., necessary-for-contract-performance, necessary-for-HR-management for MNC employees) for routine business transfers.
The PIPL defines "sensitive personal information" to include biometrics, religious beliefs, specific identities (ethnicity, nationality), medical/health data, financial accounts, precise location data, and personal information of minors under 14. Processing sensitive PI requires:
non-sensitive data (Art. 28)
For minors under 14, a separate consent from the guardian is mandatory; the CAC issued dedicated rules for the protection of minors' personal information (effective 1 June 2023) under this PIPL parental-consent mandate.
The PIPL applies to personal-information processing activities outside China where the purpose is (a) offering products or services to PRC residents, or (b) analysing or assessing the behaviour of PRC residents. This is structurally equivalent to GDPR Art. 3 "targeting criterion" extraterritoriality. Foreign controllers subject to PIPL extraterritorial application must (Art. 53): establish a dedicated entity or designated representative in China, and report the entity/representative to the competent authority.
their personal information.
withdrawn, processing period expired, or processing unlawful. Analogous to GDPR Art. 17.
legal basis is legitimate interest or where processing causes harm.
push recommendations; controllers must offer a non-profiling alternative for price personalisation; decisions with significant personal effect must be subject to human review upon request.
(ii) using PI for automated decision-making, (iii) providing PI to third parties, (iv) cross- border transfers, (v) any processing that may have a "significant impact" on individuals (Art. 55). DPIAs must be retained for at least 3 years.
information processors" (CIIOs plus handlers regularly processing large volumes of PI — threshold set at 1M+ individuals by CAC implementing guidance). The PIPO must be a senior individual with actual authority; contact details must be publicly disclosed (Art. 52).
discovery of a PI breach; notification to affected individuals where the breach may cause material harm.
The PIPL is the third of three parent statutes constituting the modern Chinese data-governance legal framework:
Protection Scheme (MLPS), Art. 37 data-localisation for CIIOs — foundational pillar one.
national core data), data-export security review for important data, §36 blocking statute, data-trading intermediary licensing — pillar two.
mechanisms, extraterritorial application, sensitive-PI + minor-data heightened protection, DPIA + PIPO obligations — pillar three.
All three are operationalised by downstream subsidiary instruments: the 2022 CAC Outbound Data Transfer Security Assessment Measures, the 2022 CAC Standard Contractual Clauses, the 2024-03-22-cn-cac-cross-border-data-flow-provisions (which relaxed the SA-trigger thresholds), and sector-specific "important data" catalogues.
| Dimension | EU GDPR | CN PIPL |
|---|---|---|
| Extraterritoriality | Art. 3 targeting criterion | Art. 3 (near-identical) |
| Legal bases | 6 (Art. 6) | 7 (Art. 13; adds public-domain data) |
| Cross-border transfers | SCC + adequacy + BCR | PIPL SCC + SA + certification |
| Data-subject rights | Art. 15-22 (full suite) | Arts. 44-50 (near-equivalent) |
| DPA enforcement body | 27 national DPAs (EDPB coordination) | CAC + sectoral regulators (MPS, SAMR) |
| Max penalty | €20M or 4% global turnover | ¥50M or 5% prior-year revenue |
| DPO requirement | Art. 37 (for certain controllers) | Art. 52 PIPO (broader mandatory scope) |
| Adequacy decision framework | GDPR Art. 45 | No outbound adequacy framework (mirror-image to EU) |
data collected in the EU and China respectively — the cross-border tensions (especially the DSL §36 blocking statute vs. EU GDPR data-subject access requests and US e-discovery subpoenas) create structural compliance friction with no clean resolution.
for China-resident user data, but enforcement has primarily targeted domestic Chinese internet companies (BABA, TCEHY, DIDI — the Didi cybersecurity review and forced app delisting in July 2021 was the first high-profile enforcement event, pre-dating PIPL's effective date but operating under the CSL/DSL architecture).
function as localisation-compliance vehicles — the PIPO + SA requirements reinforce the regulatory logic of data-fiduciaries-at-arm's-length from US parent entities.
for pure offshore digital-service providers targeting Chinese users; non-compliance is an enforcement surface and a regulatory tool for requiring local establishment.
test, purpose limitation, extraterritoriality) has been explicitly studied by Vietnam (PDPD Decree 13/2023 + Law on Data 60/2024), Indonesia (PDP Law 27/2022), and Thailand (PDPA) as they build their own personal-data protection regimes.
government approval for SA-channel transfers) is difficult to reconcile with GDPR adequacy standards; no EU-China adequacy process is underway and none is likely under the current security-review architecture.
legitimate-interest legal basis. This forces commercial controllers to rely on contract performance or consent for processing that EU-based peers handle under legitimate interest — a structural compliance divergence for global MNCs.
domestic Chinese platforms (e.g., DiDi, Meituan, Alibaba Cloud data breach 2022); foreign- controller enforcement under the extraterritorial Art. 3 has not yet been publicly documented, raising questions about the practical enforcement perimeter for offshore-only providers.
countries' data-protection regimes as "adequate" for inbound-data purposes, unlike the GDPR Chapter V architecture. All inbound transfers to China are subject to Chinese receiving-party obligations regardless of the source-country adequacy status.