Skip to main content

China Personal Information Protection Law (PIPL) — Key Rules

China's Personal Information Protection Law (PIPL), effective November 2021, is China's comprehensive data privacy law modeled on the GDPR but with distinct requirements for data processing, cross-border transfer, and enforcement.

  • Type Definition-first explainer
  • Read 1 min
  • Updated

Key Principles

  • Consent � Separate, informed consent required for most processing
  • Purpose limitation � Data must be processed only for specified purposes
  • Data minimization � Collect only data necessary for the purpose
  • Transparency � Clear privacy policies required

Cross-Border Data Transfer

Three mechanisms for transferring personal data out of China: (1) security assessment by CAC (for critical data operators), (2) standard contractual clauses (SCCs) with the data subject, (3) certification by a recognized body.

Penalties

Fines up to RMB 50M or 5% of prior year revenue for serious violations. Individuals can claim damages. Class actions are available through consumer associations and????.

Go deeper

Related guides & counsel

Move from this definition into full practice guidance, city markets, or a verified lawyer directory.

Educational information only — not legal advice. Laws and practice change; consult qualified counsel for your situation. No attorney–client relationship is formed by using this site.

China Legal Wiki

More plain-English China law explainers

Browse definition-first pages on WFOE, visas, trademarks, courts, tax, and more — then open full practice and city guides.