Skip to main content
Data Privacy & Cybersecurity

9 min read Last reviewed 2 Aug 2026

Privacy vs. Personal Information Under Chinese Law

Ruiqing Long explains how Chinese law distinguishes personal information from privacy and what the PIPL requires of businesses processing personal data.

Statute Art. 1032
Process Litigation
Privacy vs. Personal Information Under Chinese Law

Chinese law draws a meaningful distinction between privacy and personal information, and that distinction shapes how individuals protect their rights and how businesses manage compliance. Understanding the difference matters for anyone operating in China, whether you are an individual whose data has been mishandled or an enterprise designing a data governance framework.

Privacy, in the Chinese legal context, centres on the right to a peaceful private life, the protection of intimate matters from public exposure, and personal autonomy over one's private affairs. The law treats privacy violations primarily as unlawful disclosure and harassment. Personal information, by contrast, is about control and self-determination over data that can identify a person — who collects it, how it is used, and who else may access it.

A client recently came to my Beijing office with a folder of screenshots. A health app had shared his workout records with a third-party marketing firm, and a separate platform had published a photograph he had deleted from his own account months earlier. He described both incidents as "a violation of my privacy." He was partly right and partly wrong — and the distinction matters far more than most people realize, because it determines which law applies, which remedies are available, and who must prove what in court. Under the framework built around the Civil Code and the Personal Information Protection Law (PIPL), privacy and personal information are related but distinct legal interests. In this article, I explain the difference in practical terms, drawing on the way Chinese courts and regulators actually treat these claims.

Background & legal framework

What Privacy Protects: The Right to Be Left Alone

Privacy, as a legal concept in China, centers on the protection of private life. Its content primarily includes safeguarding the peace and tranquility of one's private life, keeping private matters from being made public, and the right to make autonomous decisions about one's own private life. The Civil Code captures this in Article 1032, which defines privacy as the peace of a natural person's private life, together with the private space, private activities and private information that the person does not wish to be known to others. The right of privacy attaches to the person as an aspect of human dignity and personality, which is why the Civil Code locates it among the personality rights.

The key word in the Chinese conception of privacy is concealment. Privacy law is fundamentally oriented toward secrecy and seclusion, and this orientation has two dimensions. On the one hand, it protects a person's state of solitude — the ability to live one's private life undisturbed, including one's private affairs. On the other hand, it protects the secrets of private life from unlawful disclosure by others. Consistent with this orientation, the typical forms of privacy infringement are unlawful disclosure and harassment: publishing a person's intimate photographs, revealing their medical condition to others, or intruding into their seclusion through unwanted contact. Under Article 1033 of the Civil Code, acts such as sending harassing or disturbing communications, intruding into another's private space, photographing or recording another's private space or activities, and disclosing or processing another's private information without consent are expressly prohibited unless otherwise provided by law or consented to by the person concerned.

What Personal Information Rights Protect: Control and Self-Determination

Personal information is a broader and more operational concept. Article 4 of the PIPL defines personal information as any information relating to an identified or identifiable natural person, recorded by electronic or by other means, excluding information that has been anonymized. Names, telephone numbers, identity document numbers, biometric data, location data, browsing records and consumption histories all fall within the definition, whether they are stored on a server, in a paper file or on a mobile device.

The right to personal information is essentially the right to control and self-determine one's own information. Its content includes the right to know how one's information is being collected and used, and the right to decide whether to use the information oneself or to authorize others to use it. Importantly, even with respect to personal information that can lawfully be made public — or that must be made public, such as certain statutory registration disclosures — the individual retains a degree of control. The data subject is entitled to know the extent to which the information will be disclosed, the parties to whom it will be disclosed, and the purposes for which others intend to use it. Civil-law scholars describe this bundle of rights as the right to information self-determination, a concept that entered Chinese legal discourse from continental European doctrine and has become standard in academic writing and increasingly influential in judicial practice.

How the dispute was handled

Where the Two Overlap — and Where They Diverge

There is genuine overlap between the two institutions. Private information — such as medical records, sexual orientation, religious belief and precise whereabouts — is simultaneously a component of privacy and a category of personal information. That is why the PIPL, in Article 28, treats such material as sensitive personal information and imposes special rules: processing it requires a separate, specific consent from the individual as well as a necessity assessment and a personal information protection impact assessment. The two institutions nevertheless have different centers of gravity. The privacy right focuses on preventing secrets from being unlawfully disclosed; it is not primarily concerned with who may control and use the information. The personal information right, by contrast, is precisely about control and use — who collects, who processes, who sells, and on what lawful basis.

The practical test I give clients is simple: ask where the harm comes from. If the injury is that a fact about you was exposed to others against your wishes, the claim sounds in privacy. If the injury is that your data was taken, used, altered or sold without authorization — even if nothing was ever exposed — the claim sounds in personal information rights. A leaked address book is a privacy problem; a consumer profile quietly assembled from your browsing history and resold to advertisers is a personal information problem, even though both may feel equally invasive to the person affected.

How Infringement Actually Happens: Different Interests, Different Violations

Because the two interests differ, their infringement patterns differ as well. Infringement of privacy is committed mainly through unlawful disclosure and harassment. Infringement of the right to personal information, in contrast, is committed mainly through the collection and use of personal information without authorization. In practice this takes recurring forms: unlawful collection, unlawful use, unlawful storage, unlawful processing, and unlawful resale or trafficking of personal information. One point frequently overlooked by non-specialists is that a very large share of personal information violations in China manifest as unlawful tampering and processing — data altered, rewritten or rearranged without any lawful basis. This is why the PIPL requires processors to ensure the accuracy and completeness of personal information and to correct or complete it where it is inaccurate or incomplete, as Article 46 provides.

The statutory prohibitions are broad. Article 10 of the PIPL states that no organization or individual may illegally collect, use or process personal information, or illegally trade in personal information. Where conduct is serious enough to cross into criminal territory, Article 253-1 of the Criminal Law criminalizes the sale or unlawful provision of citizens' personal information, carrying penalties of up to three years' imprisonment for serious circumstances and three to seven years' imprisonment where the circumstances are extremely serious.

Practical implications

Why the Distinction Matters in Practice: Remedies, Burden of Proof and Evidence

The distinction drives litigation strategy. Under Article 13 of the PIPL, processing personal information requires one of several lawful bases: the consent of the individual; necessity for concluding or performing a contract to which the individual is a party; necessity for performing statutory duties or obligations; necessity for public-interest news reporting or public-opinion supervision conducted within a reasonable scope; processing, within a reasonable scope, of information that the individual has disclosed themselves or that has otherwise been lawfully disclosed; or other circumstances prescribed by laws and regulations. A company that cannot point to one of these bases for a given processing activity is processing unlawfully, regardless of how innocuous the data appears.

For individuals, the most important feature of the dispute framework is the burden of proof. Article 69 of the PIPL provides that a personal information processor which violates the law, infringes the lawful rights and interests of individuals in their personal information, and causes harm shall bear tort liability, unless it can prove that it was not at fault. In other words, in a personal information dispute it is the processor — not the individual — who must demonstrate that a lawful basis existed and that security measures were adequate. This is markedly more favorable to claimants than ordinary fault-based tort claims, and it is one of the reasons the Beijing Internet Court, which handles a large volume of online privacy and data disputes, has seen a steady stream of successful claims. The individual's evidentiary burden is nevertheless real: preserve the privacy notice or policy in force at the time, screenshots of the collection or disclosure, records of any data subject request you submitted, and evidence of the damage suffered, whether reputational, financial or emotional.

Litigation is not the only channel. Individuals may file complaints with the cyberspace administration authorities, which can order correction, confiscate unlawful gains and impose fines under Chapter VI of the PIPL; they may demand correction and deletion under Articles 46 and 47; and where conduct affects a large number of people, the procuratorates may bring public-interest litigation under Article 70. For businesses, the practical lesson is that a privacy policy which merely describes collection practices is not enough. Each processing activity must be mapped to a genuine lawful basis under Article 13; consent mechanisms must be designed to withstand scrutiny, particularly for sensitive personal information under Article 28; and records of consent and processing must be kept, because those records become the evidence on which the company's liability will be decided if a dispute arises.

Conclusion

Privacy and personal information are often used interchangeably in everyday conversation, but Chinese law treats them as distinct interests with distinct protections. Privacy shields the peace and secrecy of private life, and it is violated mainly by disclosure and harassment. Personal information rights give the individual control over the collection, use and ultimate fate of their data, and they are violated mainly by unauthorized collection, use, storage, processing and sale — with unlawful tampering and processing accounting for a substantial share of the violations seen in practice. The overlap between the two is real, and sensitive personal information sits precisely at their intersection, which is why the PIPL gives it special treatment. A well-advised individual or company will determine which regime applies before acting. In a jurisdiction where the PIPL, the Data Security Law and the Cybersecurity Law now form a comprehensive data protection framework, treating privacy and personal information as the same thing is no longer merely imprecise — it can be the difference between a successful claim and a dismissed one, or between a compliant business and one facing an enforcement order.

What parties should remember

Sources & trust

How to use this article

This insight is general information for orientation on China-related legal topics. It is not legal advice and does not create an attorney–client relationship. Prefer primary statutes, courts, and official guidance when making decisions.

Editorial Policy · AI Content Policy · Lawyer Verification Policy · Listing standards · Disclaimer · Request a consultation

Share LinkedIn X Email
Ruiqing Long

About the author

Ruiqing Long

Beijing Zhong Lun Law Firm. Verified listing on China Legal Portal. Insights are educational and do not create an attorney–client relationship.

Discussion

Join the conversation

Share a professional question or experience. This is not legal advice — no attorney–client relationship is formed by posting here.

Next step

Need counsel on this topic?

Connect with verified data privacy & cybersecurity lawyers across China, or ask a free initial question.

Educational information only — not legal advice. Laws change; consult qualified counsel for your situation. No attorney–client relationship is formed by using this site. See our Disclaimer, Editorial Policy, and AI Content Policy.