Personal Information Protection Law
China
In force since 1 November 2021
Adopted on 20 August 2021 and supplemented by regulations that have continued to develop since, including the 2024 cross-border data flow rules and the 2025 compliance audit measures.
Asia & Africa
China
Personal Information Protection Law of the People's Republic of China
PIPL
20 August 2021
1 November 2021
Cyberspace Administration of China (CAC) and other competent authorities
One lawful processing basis
Enhanced requirements
Required in specified circumstances
Required
Yes
Required in specified high-risk processing situations
Required
Regulated
Required periodically for processors handling more than 10 million individuals
In force
PIPL applies to organisations processing personal information within China. It can also apply to organisations outside China where they process personal information of individuals located in China for purposes including providing products or services to individuals in China, analysing or evaluating the behaviour of individuals in China, and other circumstances provided by laws or administrative regulations. This means an organisation does not necessarily need to be incorporated in China to have PIPL obligations.
For violations of PIPL, ordinary violations can result in fines of up to RMB 1 million for the relevant organisation, with additional personal penalties for responsible personnel. For serious violations, fines can reach RMB 50 million or up to 5% of the previous year's turnover, depending on the applicable statutory calculation. Responsible individuals can also face personal fines and, in serious cases, restrictions on serving as directors, supervisors, senior executives or personal-information protection officers. The actual regulatory consequence depends on the nature, seriousness and circumstances of the violation.
PIPL is not simply a consent-only law. Article 13 provides several circumstances under which personal information may be processed, including consent, contractual necessity, human-resources management under applicable rules, legal obligations, public-health or emergency situations, public-interest processing, information made public by the individual, and other circumstances provided by law or administrative regulations.
The Personal Information Protection Law of the People's Republic of China is China's comprehensive personal-information protection statute.
The law aims to:
PIPL forms part of China's broader data-governance framework alongside laws and regulations concerning cybersecurity and data security.
Potentially affected organisations include:
PIPL defines personal information as information recorded electronically or through other means that relates to an identified or identifiable natural person.
It does not include information that has been anonymised. Examples can include:
China's CAC published updated guidance in January 2026 listing examples including identity information, biometric information, online identifiers, financial information, communications records, browsing records, device information, location information and user-profile information.
PIPL covers a broad range of processing activities. Processing can include:
The law therefore applies across the full personal-information lifecycle.
Article 5 requires personal information to be processed according to principles including:
These principles form the foundation of PIPL compliance.
Not for every processing activity.
Consent is one of the lawful circumstances under Article 13, but PIPL also recognises other processing grounds. These can include processing that is:
Therefore, organisations should identify the applicable legal basis for each processing activity rather than automatically requesting consent for everything.
Where consent is relied upon, it should be obtained on the basis of appropriate information and voluntary choice.
Organisations should avoid:
PIPL also establishes separate-consent requirements for specified processing activities.
Separate consent is particularly important for certain higher-risk processing activities. Examples can include:
For international transfers, current CAC guidance confirms that when personal information is provided overseas, the processor must comply with relevant notice and separate-consent requirements where applicable.
ConsentX can support separate consent experiences where a dedicated consent signal is required.
PIPL provides enhanced protection for sensitive personal information.
Sensitive personal information is information that, if leaked or illegally used, may easily cause harm to the dignity of a natural person or seriously endanger personal safety or property safety. Examples can include:
The exact classification depends on the nature and context of the information.
Before processing sensitive personal information, organisations should assess:
PIPL requires additional notification concerning the necessity of processing sensitive personal information and its impact on individuals' rights and interests.
Where consent is the legal basis, separate consent is required for sensitive personal information under PIPL, subject to applicable statutory exceptions.
PIPL provides enhanced protections for minors.
Personal information of individuals under 14 years of age is treated as sensitive personal information. Organisations processing such information must establish dedicated processing rules and apply additional safeguards. Where consent is required, parental or guardian consent may be necessary.
This is particularly relevant to:
PIPL requires personal-information processors to provide clear information to individuals.
Privacy information can include:
The information should be presented in a clear and understandable manner.
For sensitive personal information, organisations should additionally explain the necessity of processing and the impact on individual rights and interests.
A cookie or consent banner should not be treated as a replacement for a full PIPL privacy policy.
A compliant digital experience may require a privacy notice, purpose information, applicable consent, separate consent where required, technical enforcement and evidence.
ConsentX can support the technical consent layer while organisations maintain the broader privacy documentation required by PIPL.
Cookies, pixels and other tracking technologies should be assessed based on the personal-information processing they perform.
Organisations should consider:
Common technologies include:
Where consent is the appropriate legal basis, ConsentX can help prevent applicable trackers from executing before the required consent signal.
PIPL grants individuals extensive rights concerning their personal information. These include rights to:
PIPL also allows individuals to request that their rights be exercised through a designated person or institution under applicable conditions.
Individuals can exercise rights to access and copy their personal information.
Organisations should establish workflows to:
Individuals can request correction or supplementation of inaccurate or incomplete personal information.
Organisations should maintain mechanisms for:
Individuals can request deletion where statutory conditions are met.
Deletion may become relevant when:
Organisations should maintain documented deletion and retention procedures.
Where processing is based on consent, individuals have the right to withdraw consent.
Withdrawal should be practical and should not be made unnecessarily difficult. The organisation should be able to:
ConsentX can provide the technical infrastructure for managing these preference changes.
PIPL contains specific provisions concerning automated decision-making.
Where automated decision-making is used, organisations should consider:
The 2025 compliance-audit framework specifically instructs auditors to examine whether automated decision-making based on preferences or transaction habits results in unreasonable differential treatment.
This is relevant to:
PIPL requires a Personal Information Protection Impact Assessment (PIPIA) before certain high-risk processing activities.
Article 55 identifies circumstances including:
The assessment should examine:
PIPIA records must be retained for at least three years.
Consent management can form one part of a broader PIPIA.
For example, an organisation can document:
ConsentX can provide technical evidence for this part of the assessment.
Personal-information processors must implement appropriate measures to protect personal information.
Security controls can include:
PIPL requires processors to establish personal-information protection systems and take appropriate security measures based on the type and scale of processing.
PIPL requires certain processors handling personal information at the threshold prescribed by the national cyberspace authority to appoint a person responsible for personal-information protection.
That person is responsible for supervising personal-information processing activities and protective measures.
The processor must also disclose the relevant contact information and submit required information to the competent authorities. Organisations should determine whether their processing volume and activities trigger this obligation.
An organisation outside China that falls within the extraterritorial scope of PIPL must establish a dedicated institution or appoint a representative in China to handle personal-information protection matters where required by Article 53.
The organisation must submit the relevant information about the institution or representative to the competent authorities.
This is an important consideration for international businesses serving Chinese users.
China's compliance framework has developed significantly since the original PIPL came into force. The Personal Information Protection Compliance Audit Measures took effect on 1 May 2025.
The rules establish two main audit scenarios. Under the regular internal or professional audit, personal-information processors should periodically conduct compliance audits, and processors handling the personal information of more than 10 million individuals must conduct a personal-information protection compliance audit at least once every two years.
Under the regulatory-required audit, competent authorities can require an organisation to engage a professional institution for a compliance audit where significant risks, large-scale impacts on individuals or certain serious personal-information security incidents are identified.
This makes ongoing evidence and privacy governance increasingly important for large processors.
The compliance-audit framework covers areas including:
The 2025 audit rules also provide a detailed audit guide for evaluating these requirements.
International transfers are one of the most important parts of China's privacy framework.
Article 38 establishes several mechanisms for transferring personal information outside China, including:
China's Provisions on Facilitating and Regulating Cross-Border Data Flows came into force on 22 March 2024 and adjusted the thresholds and exemptions for cross-border personal-information transfers.
Under the current framework, certain transfers may be exempt from the security-assessment, standard-contract and certification requirements. Examples include specified transfers necessary for:
There is also an exemption for non-critical-information-infrastructure operators providing fewer than 100,000 individuals' personal information overseas in a calendar year, excluding sensitive personal information and subject to the applicable rules.
For organisations other than critical information infrastructure operators, the current framework broadly distinguishes among the following.
Less than 100,000 individuals. Certain transfers of fewer than 100,000 individuals' personal information in a calendar year may be exempt from the three principal outbound mechanisms, subject to the applicable conditions and exclusions.
100,000 to fewer than 1 million individuals. Where the applicable thresholds are met, the organisation generally needs to use either a personal-information export standard contract or personal-information protection certification, subject to applicable exemptions.
1 million or more individuals. A non-CIIO processor providing personal information of 1 million or more individuals overseas in the relevant period generally falls within the security-assessment requirement, subject to the applicable exemptions.
Sensitive personal information. The threshold for sensitive personal information is substantially lower: providing 10,000 or more individuals' sensitive personal information overseas can trigger the security-assessment framework, subject to applicable exemptions.
One route for qualifying international transfers is China's Personal Information Export Standard Contract framework. The contract establishes obligations between the Chinese personal-information processor and the overseas recipient.
Organisations using this mechanism should assess:
The standard-contract route should be evaluated alongside the current cross-border data-flow rules rather than treated as automatically necessary for every transfer.
China also provides a certification mechanism for qualifying cross-border transfers. The Personal Information Export Certification Measures were issued in 2025 and came into force on 1 January 2026.
The 2026 framework specifies conditions for non-CIIO processors that, during the relevant calendar year, provide overseas:
subject to the applicable rules. Organisations cannot artificially split data volumes to avoid a mandatory security assessment.
When PIPL requires consent for an international transfer, the consent must be appropriately separated from unrelated processing.
The CAC's July 2026 guidance states that separate consent for cross-border provision must be specific and clear and cannot be obtained through blanket authorisation bundled with other personal-information processing activities.
This is particularly relevant to:
PIPL requires certain personal information to be stored domestically.
Critical information infrastructure operators are subject to domestic storage requirements for personal information collected and generated in China. Other processors processing personal information up to the threshold prescribed by the national cyberspace authority can also be subject to domestic-storage and security-assessment requirements when exporting information.
Therefore, international organisations should not assume that personal information collected in China can automatically be transferred to global infrastructure.
PIPL requires personal information to be retained only for the shortest period necessary to achieve the processing purpose unless a longer retention period is required by applicable laws or regulations.
Organisations should establish:
The 2025 compliance-audit framework specifically requires auditors to examine whether organisations define retention periods or the method for determining them and whether the period is the shortest necessary for achieving the processing purpose.
Where personal information is or may be leaked, tampered with or lost, the processor must immediately take remedial measures and notify the competent authorities and relevant individuals as required by PIPL.
The incident-response process should cover:
Organisations should not assume that a generic global breach workflow automatically satisfies China's requirements.
Where a personal-information processor entrusts processing to another organisation, appropriate controls should address:
PIPL also requires personal-information protection impact assessment in circumstances involving entrusted processing and other specified third-party disclosures.
PIPL compliance should be incorporated into digital products and systems from the beginning.
A privacy-by-design programme can include:
Digital marketing can involve extensive personal-information processing. Examples include:
Organisations should assess:
Where consent is relied upon, organisations should maintain evidence showing what the individual consented to and when.
Artificial intelligence and profiling can create significant privacy risks.
PIPL's automated-decision provisions are relevant to:
The organisation should assess:
The 2025 compliance-audit framework specifically addresses automated decision-making and unreasonable differential treatment.
China's cyberspace administration and other competent authorities have powers to supervise and enforce personal-information protection requirements.
Regulatory measures can include:
The PIPL provides particularly significant sanctions for serious violations.
The Cyberspace Administration of China (CAC) plays a central role in China's personal-information protection framework.
Other competent departments can also have personal-information protection responsibilities depending on the sector and regulatory context.
The PIPL itself refers to departments responsible for performing personal-information protection duties rather than assigning every aspect of enforcement to a single regulator.
A practical programme should cover the following.
A modern website can involve dozens of technologies that collect, analyse or transmit information. Examples include:
PIPL compliance therefore requires more than publishing a privacy policy. Organisations need visibility into what technologies operate on their websites and how personal information is collected and shared.
ConsentX helps organisations discover, categorise, inform, obtain consent, block, record, manage preferences and demonstrate evidence.
Identify cookies, pixels, scripts and tracking technologies operating across your digital properties.
Collect consent where consent is the applicable legal basis.
Create dedicated consent flows for processing activities where a separate consent signal is required.
Prevent applicable non-essential trackers from executing before the required consent signal.
Maintain records showing what was accepted, when it was accepted, which purposes were covered, which consent version was presented and whether preferences were later changed.
Provide a mechanism for users to revisit and change applicable preferences.
Apply different privacy and consent configurations based on visitor location and business requirements.
Support operational workflows for access, correction, deletion and related data-subject requests.
Maintain records that can support internal compliance reviews and broader privacy governance.
Build a more transparent and auditable privacy experience for users in China. Discover cookies and trackers, configure China-specific consent experiences, support separate-consent workflows, block applicable trackers before consent, record consent choices, manage preference changes, support data-subject requests, maintain audit evidence and apply regional privacy rules. ConsentX helps turn privacy requirements into operational controls.
This page provides a plain-English summary of China's personal-information protection framework for general informational purposes and is not legal advice. No technology platform can independently make an organisation fully legally compliant. Organisations should assess their specific processing activities and consult qualified Chinese legal counsel where necessary.
Use ConsentX to identify:
This establishes visibility into the technologies operating on your website.
Classify technologies according to their purpose, such as:
Do not assume every technology requires consent. Assess whether the relevant processing relies on:
Where consent is required, provide a clear and informed consent experience. Where separate consent is required, create a dedicated consent interaction rather than relying on a single blanket choice.
Configure ConsentX to prevent applicable non-essential technologies from executing before the relevant consent signal.
Maintain evidence of:
Give individuals an accessible mechanism for changing applicable preferences.
Use structured workflows to manage:
Keep appropriate evidence showing how privacy and consent controls operate.