Skip to main content
Criminal Defense, Cyber Crime, Fraud and Embezzlement, Data Privacy & Cybersecurity
Personal information classification under China's PIPL
Personal information classification under China's PIPL

Under China's Personal Information Protection Law, personal information is information recorded electronically or otherwise that relates to an identified or identifiable natural person. The definition is broader than names and identity numbers and can cover online identifiers, device data, location, transaction records, workplace information and inferences when they relate to a person who can be identified.

The first classification question is not whether a field looks private or confidential. It is whether the information relates to an identified or identifiable natural person. The next questions are whether it is sensitive, whether it has merely been de-identified or has truly been anonymized, and what processing purpose and legal duties follow.

1. Apply the statutory definition

Article 4 of the PIPL covers various information related to an identified or identifiable natural person, recorded electronically or by other means. Anonymized information is expressly excluded. The definition focuses on relationship and identifiability rather than a closed list of data fields.

Ask whether the data identifies a person directly, or whether the holder or another reasonably relevant party can identify the person by combining it with additional information. Context matters. A number or code may be meaningless to the public yet identify a customer or employee inside the relevant system.

2. Direct and indirect identifiers

Direct identifiers can include a name, national identification number, passport number, photograph, voiceprint or personal contact detail. Indirect identifiers can include account IDs, cookie or device identifiers, IP addresses, precise location, employment details, purchasing patterns and combinations of demographic attributes.

A single field should not be assessed in isolation. A dataset containing age, role, worksite and shift may identify one employee even without a name. Persistent identifiers that allow an organization to single out, track or profile a person can remain personal information.

3. Inferences, profiles and generated data

Personal information is not limited to facts supplied by the individual. Scores, preferences, behavioral predictions, risk labels, inferred interests and automated profiles may relate to an identifiable person and therefore fall within the PIPL.

Organizations should inventory derived data as well as collected data. Deleting the original fields does not necessarily remove the profile, decision record or model output associated with a person.

4. Personal information versus privacy

Privacy and personal information overlap but are not identical concepts under Chinese law. Privacy under the Civil Code concerns a natural person's private life, peace and private space, activities and information that the person does not want others to know. Personal information under the PIPL can include information that is not intimate or secret.

A business contact address or work identifier may be personal information even if it is public or routine. Conversely, intrusion into private space or peace can raise privacy issues beyond a data-record analysis. Classify the conduct under both frameworks where relevant.

5. Publicly disclosed information

Information does not stop being personal information merely because the person or another lawful source disclosed it publicly. Article 27 permits reasonable processing of lawfully disclosed personal information within the scope allowed by the PIPL, unless the individual clearly refuses. Consent may still be required where the processing has a major impact on the individual's rights and interests.

Before reusing public data, examine the source, expected context, purpose, scale, impact, any expressed objection and applicable platform or sector rules. Public availability is not a general permission for unrestricted scraping, profiling or marketing.

6. Sensitive personal information

Sensitive personal information is a subset of personal information that, if leaked or unlawfully used, may readily infringe personal dignity or endanger personal or property safety. The PIPL lists biometrics, religious beliefs, specific identity, medical and health information, financial accounts, location tracking and the personal information of children under 14 among its examples.

Sensitivity depends on both category and context. A broad combination of otherwise ordinary fields may reveal health, religion, financial distress or precise movements. Sensitive processing requires a specific purpose, sufficient necessity, strict protection, additional notice and, where consent is the ground, separate consent.

7. De-identification is not anonymization

De-identification means processing that prevents identification of a person without the use of additional information. The party holding the additional key or capable of recombination may still identify the person. De-identified or pseudonymous data therefore generally remains personal information.

Anonymization means processing that makes it impossible to identify a specific natural person and impossible to restore the data. Only anonymized information falls outside the Article 4 definition. Renaming fields, hashing an identifier, tokenizing a customer number or removing a direct name does not automatically meet that standard.

8. Organizational and business data

Information solely about a legal entity is not personal information merely because it is commercially confidential. Company revenue, a corporate registration number or a generic departmental address may fall under other legal protections but is not necessarily information about a natural person.

Business records often contain a personal layer. Director names, employee contact details, signatures, account administrators, sole-trader information and correspondence linked to an identifiable individual can be personal information even inside a business-to-business transaction.

9. Household and purely personal activities

The PIPL does not apply to a natural person's processing of personal information for personal or household affairs. The exception should be read according to the actual activity. Organized commercial processing, workplace monitoring, publication to a broad audience or use on behalf of an organization should not be assumed to be household activity.

10. A practical classification test

  1. Identify each data field, derived value and associated identifier.
  2. Ask whether it relates to a natural person rather than only an organization or object.
  3. Determine whether the person is identified directly or identifiable in context.
  4. List the additional information, systems and parties that could enable identification.
  5. Test whether any claimed anonymization is irreversible in practice.
  6. Assess whether the information is sensitive by category, combination or likely harm.
  7. Record the people affected, purpose, source, recipients, retention and transfer path.
  8. Apply the appropriate notice, legal ground, security, rights and impact-assessment controls.

Examples requiring care

  • A vehicle identifier linked to a driver or journey history.
  • A device identifier connected with location or behavior.
  • A customer code that staff can resolve through another system.
  • CCTV footage in which individuals are recognizable.
  • A work email address identifying a named employee.
  • An anonymous survey with free-text answers that reveal the respondent.
  • Model scores or fraud labels attached to an account holder.
  • Aggregated statistics based on a group small enough to expose individuals.

What classification changes

If information is personal information, the handler needs a lawful processing ground, notice, purpose limitation, minimization, retention controls, security and a process for individual rights. Sensitive classification adds necessity, strict protection, impact-assessment and consent requirements where applicable. Provision to another handler or overseas can trigger further notice, assessment, contract and consent duties.

Classification should be revisited when datasets are combined, a new identifier is added, a model creates inferences, the purpose changes or data moves to another party. Information that appeared anonymous in one environment may become identifiable in another.

Primary sources and review date

Reviewed 8 September 2026. General information only; identifiability, sensitivity and anonymization depend on the data, systems, parties and realistic means available in the specific context.

Related guides: PIPL scope and compliance duties · Sensitive personal information · Personal information handlers · Consent · Impact assessments.