Skip to main content
China · Reviewed September 2026

What Is Personal Information Protection Law of the People's Republic of China?

The Personal Information Protection Law of the People's Republic of China (PIPL, 个人信息保护法) is China's first comprehensive personal-information protection statute. Passed by the Standing Committee of the National People's Congress on 20 August 2021 and in force 1 November 2021, PIPL operates alongside the Cybersecurity Law and Data Security Law in China's data-protection framework. PIPL has GDPR-like rights but also China-specific rules on lawful processing, sensitive personal information, automated decision-making, domestic storage, cross-border transfers, and regulator oversight. The CAC coordinates personal-information protection, while relevant State Council and local-government departments handle supervision within their assigned duties. Articles 38–43 set the statutory cross-border framework. The March 22, 2024 Regulations on Promoting and Regulating Cross-Border Data Flows added exemptions, annual-volume thresholds, and free-trade-zone negative-list options; the 2023 standard-contract measures and certification rules still matter. These rules do not turn every transfer into the same approval process. The Small Personal Information Processors Simplified Measures were published on July 24, 2026 and took effect on September 1, 2026; they simplify specified compliance steps for processors handling fewer than 100,000 individuals but do not replace the PIPL.

Rahul Kandoriya
Written byRahul Kandoriya·Founder, OfflistMe·Last updated September 7, 2026

At a glance

Full name
Personal Information Protection Law of the People's Republic of China
Short code
PIPL
Jurisdiction
China
Enacted
2021
Last major update
In force November 1, 2021; Regulations on Promoting and Regulating Cross-Border Data Flows effective March 22, 2024; Personal Information Protection Compliance Audit Measures effective May 1, 2025; Small Personal Information Processors Simplified Measures took effect on September 1, 2026
Regulator
Cyberspace Administration of China (CAC) + sectoral regulators
Private right of action
Limited

Scope, who PIPL covers

Activities of processing personal information of natural persons within the territory of China. Also applies extraterritorially (Article 3) to processing outside China where: (1) the purpose is providing products or services to individuals in China; (2) the activity involves analysis or evaluation of the behavior of individuals in China; (3) other circumstances as provided by law.

Protected data

Personal information: information related to an identified or identifiable natural person, recorded electronically or otherwise, excluding anonymized information. Sensitive personal information includes biometrics, religious belief, specific identity, medical or health information, financial accounts, whereabouts, and personal information of a minor under 14. It requires a specific purpose, necessity, strict safeguards, and separate consent unless another applicable legal rule governs; processing a minor's information also requires parent or guardian consent.

Data subject rights

Right to know the processing rules and make decisions about processing (Article 44)

Right to restrict or refuse processing by others (Article 44)

Right of access and copy of personal information (Article 45)

Right to correction and supplementation (Article 46)

Right to request deletion when an Article 47 circumstance or other applicable legal condition exists

Right to request transfer of personal information to a designated processor where Article 45 and applicable CAC conditions are met

Right to an explanation of the processing rules

Right to request an explanation of a significant automated decision and refuse a decision made only through automated decision-making (Article 24)

Right to use the processor's rights-request mechanism, complain or report illegal processing to a department with personal-information protection duties, and bring a lawsuit where the law permits

Notable features

PIPL's distinctive features include: (1) cross-border data-transfer mechanisms that can involve a CAC security assessment, a standard contract under CAC rules, certification, or another applicable legal/regulatory route; (2) domestic-storage and security-assessment rules for CIIOs and prescribed-volume processors; (3) burden allocation in civil damages claims under Article 69; and (4) coordination with the Cybersecurity Law and Data Security Law. The 2024 cross-border regulations and the small-processor measures that took effect on September 1, 2026 must be checked for the transfer or processor at issue.

Enforcement & penalties

Regulator: Cyberspace Administration of China (CAC) + sectoral regulators

Penalties: Article 66 distinguishes ordinary violations from serious violations. Ordinary measures can include correction orders, warnings, confiscation of illegal gains, app-service suspension or termination, and—when the violator refuses to correct—a fine of up to RMB 1 million plus fines for directly responsible people. Serious violations can carry a fine of up to RMB 50 million or 5% of the previous year's turnover, possible business suspension or license action, fines of RMB 100,000–1 million for directly responsible people, and possible management bans. Public-security or criminal liability can also apply under Article 71; outcomes depend on the conduct and authority involved.

Private right of action: Articles 50 and 69 support civil litigation in defined circumstances: a person whose rights request is rejected may sue under the law, and a processor that infringes personal-information rights and cannot prove it was not at fault can bear damages and other tort liability. Article 70 provides a public-interest litigation route for the people's procuratorate, qualifying consumer organizations, and an organization designated by the CAC when many individuals' rights are infringed; this is not a blanket individual class-action right.

Relevance to data brokers

PIPL's Article 3 can reach an overseas provider that offers products or services to people in China or analyzes their behavior. A data broker's exposure depends on the processing role, purpose, source, legal basis, location, outbound transfer, and applicable exceptions; the provider's location alone is not enough. As a dated enforcement example, the CAC stated that its July 2022 RMB 8.026 billion Didi penalty was based on violations of the Cybersecurity Law, Data Security Law, PIPL, and Administrative Penalty Law. That case does not establish a penalty or outcome for every foreign broker.

Generate requests in under 60 seconds

Generate removal requests for 1,034 US/global profiles, $9

OfflistMe helps draft opt-out requests using the details you choose. Review the provider route and legal basis, then send from your own inbox. The tool is not legal advice and does not guarantee a broker's response.

FAQ

Does PIPL apply to foreign companies?+

Yes, when the Article 3 conditions apply. PIPL can cover processing outside China for offering products or services to people in China or analyzing or evaluating their behavior. A covered foreign handler must designate a China-based representative or institution and report the relevant information to the competent authority as required by the law; the exact compliance route depends on the activity and current rules.

What are PIPL cross-border transfer requirements?+

Article 38 lists a CAC security assessment, personal-information protection certification under CAC rules, a standard contract under CAC rules, or another applicable law, regulation, or CAC condition. The March 2024 cross-border regulations add important-data and volume thresholds, exemptions, and free-trade-zone negative-list rules: for example, non-CIIO processors generally face security-assessment thresholds at important data, 1 million or more non-sensitive individuals, or 10,000 or more sensitive individuals, while a lower band can use the standard-contract or certification route. Certain contract, employment, emergency, low-volume, and other listed cases can be exempt from those mechanisms, but notice, separate-consent, impact-assessment, and security duties may still apply.

What is a 'Critical Information Infrastructure Operator' (CIIO)?+

CIIOs are operators of critical information infrastructure identified under China's cybersecurity framework. PIPL requires CIIOs to store personal information collected and generated in China domestically; where it is truly necessary to provide that information overseas, Article 40 generally requires a CAC-organized security assessment, subject to later laws, regulations, or CAC provisions that make an assessment unnecessary. Do not treat the sector examples or the transfer outcome as automatic without checking the current designation and rules.

How do I file a PIPL complaint?+

Article 65 allows any organization or individual to complain or report illegal personal-information processing to a department with personal-information protection duties, which must handle the matter under law and publish contact information. Use the current CAC or relevant local/sectoral department route for the processing at issue. A rights request rejected by a processor can support a people's-court action under applicable law, while Article 69 damages and Article 70 public-interest litigation have their own statutory conditions.

Official sources & citations

Other international privacy regimes

PIPL sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:

United Kingdom · enacted 2018What is UK GDPR?Canada · enacted 2000What is PIPEDA?Brazil · enacted 2018What is LGPD?India · enacted 2023What is DPDP Act?Australia · enacted 1988What is Privacy Act 1988?Japan · enacted 2003What is APPI?France · enacted 1978What is Loi Informatique et Libertés?Germany · enacted 2018What is BDSG?Argentina · enacted 2000What is Law 25.326?Philippines · enacted 2012What is RA 10173?South Africa · enacted 2013What is POPIA?Malaysia · enacted 2010What is Malaysia PDPA?United Arab Emirates · enacted 2021What is UAE PDPL?Republic of Korea · enacted 2011What is Korea PIPA?Netherlands · enacted 2018What is UAVG?Nigeria · enacted 2023What is NDPA?Pakistan · enacted 2016What is PECA + Art. 14?Peru · enacted 2011What is Law 29733?Saudi Arabia · enacted 2021What is PDPL?Thailand · enacted 2019What is Thai PDPA?Türkiye · enacted 2016What is KVKK?Viet Nam · enacted 2025What is Law No. 91/2025?Poland · enacted 2018What is Poland GDPR + UODO Act?Portugal · enacted 2019What is Portugal GDPR + Lei 58/2019?Romania · enacted 2018What is Romania GDPR + Law 190/2018?Bangladesh · enacted 2026What is Act No. 63 of 2026?Chile · enacted 2024What is Law 21.719?Colombia · enacted 2012What is Law 1581?Egypt · enacted 2020What is Law No. 151 of 2020?Indonesia · enacted 2022What is UU PDP?Israel · enacted 1981What is Privacy Law 5741-1981?Kazakhstan · enacted 2013What is Law No. 94-V?Mexico · enacted 2025What is LFPDPPP (2025)?Albania · enacted 2024What is Law 124/2024?Armenia · enacted 2015What is HO-49-N?Azerbaijan · enacted 2010What is Law 998-IIIQ?Bosnia and Herzegovina · enacted 2025What is Law 12/25?Hungary · enacted 2011What is Info tv. + GDPR?Iceland · enacted 2018What is Act No. 90/2018 + GDPR?Jamaica · enacted 2020What is Data Protection Act 2020?Kenya · enacted 2019What is Data Protection Act 2019?Kyrgyzstan · enacted 2025What is Digital Code?Latvia · enacted 2018What is PDL?Luxembourg · enacted 2018What is Law of 1 August 2018?Malta · enacted 2018What is Chapter 586?Republic of Moldova · enacted 2024What is Law no. 195/2024?Mongolia · enacted 2021What is Law on Personal Data Protection?Montenegro · enacted 2008What is Law on Personal Data Protection?Morocco · enacted 2009What is Law 09-08?Estonia · enacted 2018What is IKS?Georgia · enacted 2023What is Law No. 3144?Ghana · enacted 2012What is Act 843?Greece · enacted 2019What is Law 4624/2019?North Macedonia · enacted 2020What is Law 42/2020?Russian Federation · enacted 2006What is 152-FZ?Senegal · enacted 2008What is Law No. 2008-12?Serbia · enacted 2018What is Law 87/2018?Slovakia · enacted 2018What is Act No. 18/2018 Coll.?Slovenia · enacted 2022What is ZVOP-2?Sri Lanka · enacted 2022What is PDPA?Tunisia · enacted 2004What is Organic Law No. 2004-63?Ukraine · enacted 2010What is Law No. 2297-VI?Bulgaria · enacted 2001What is PDPA?Croatia · enacted 2018What is Act on the Implementation of the GDPR?Cyprus · enacted 2018What is Law 125(I)/2018?Czechia · enacted 2019What is Act No. 110/2019 Coll.?Austria · enacted 1999What is DSG?Belgium · enacted 2018What is Belgian Data Protection Act?Denmark · enacted 2018What is Databeskyttelsesloven?Finland · enacted 2018What is Data Protection Act 1050/2018?Norway · enacted 2018What is Personal Data Act?Afghanistan · enacted 2010What is Sectoral Privacy Protections?Algeria · enacted 2018What is Law No. 18-07 + Law No. 25-11?Andorra · enacted 2021What is LQPD?Angola · enacted 2011What is Law No. 22/11?Antigua and Barbuda · enacted 2013What is Data Protection Act 2013?Bahamas · enacted 2003What is DPA 2003?Bahrain · enacted 2018What is Law No. 30 of 2018?Barbados · enacted 2019What is Data Protection Act 2019-29?Belarus · enacted 2021What is Law No. 99-Z?Belize · enacted 2021What is Data Protection Act 2021?Benin · enacted 2018What is Code du numérique, Book V?Bhutan · enacted 2018What is ICM Act 2018 + NDGF 2025?Bolivia (Plurinational State of) · enacted 2009What is Art. 21(2), 25, 130–131 + Law 254?Botswana · enacted 2024What is Data Protection Act 2024?Brunei Darussalam · enacted 2025What is PDPO 2025?Burkina Faso · enacted 2021What is Loi n°001-2021/AN?Burundi · enacted 2026What is Law No. 1/03 of 2026?Cabo Verde · enacted 2001What is Lei n.º 133/V/2001?Cambodia · enacted 2019What is Fragmented privacy framework?Cameroon · enacted 2024What is Law No. 2024/017?Central African Republic · enacted 2024What is Law No. 24.001?Costa Rica · enacted 2011What is Ley 8968?Ecuador · enacted 2021What is LOPDP?El Salvador · enacted 2024What is LPDP?Dominican Republic · enacted 2013What is Ley 172-13?Sweden · enacted 2018What is GDPR + Data Protection Act?Malawi · enacted 2024What is Malawi DPA 2024?Mali · enacted 2013What is Mali Law 2013-015?Mauritania · enacted 2017What is Mauritania Law 2017-020?Mauritius · enacted 2017What is Mauritius DPA 2017?Monaco · enacted 2024What is Monaco Law 1.565?Nepal · enacted 2018What is Nepal Privacy Act 2075?Oman · enacted 2022What is Oman PDPL?Panama · enacted 2019What is Panama Ley 81/2019?Paraguay · enacted 2025What is Paraguay Law 7593/2025?Qatar · enacted 2016What is Qatar Law No. 13 of 2016?Rwanda · enacted 2021What is Rwanda Law 058/2021?Saint Lucia · enacted 2011What is Saint Lucia DPA 2011?Togo · enacted 2019What is Togo Law 2019-014?Turkmenistan · enacted 2017What is Turkmenistan Law 519-V?United Republic of Tanzania · enacted 2022What is Tanzania PDPA 2022?Uruguay · enacted 2008What is Uruguay Ley 18.331?Vanuatu · enacted 2024What is Vanuatu DPPA 2024?Zimbabwe · enacted 2021What is Zimbabwe Cyber and Data Protection Act?Chad · enacted 2015What is Chad Law 007/PR/2015?Comoros · not enacted in this profileWhat is Comoros Personal Data Law 2014?Congo · enacted 2019What is Congo Law 29-2019?Côte d'Ivoire · enacted 2013What is Côte d'Ivoire Law 2013-450?Cuba · enacted 2022What is Cuba Law 149/2022?Democratic People's Republic of Korea · enacted 2022What is DPRK Information Law materials?Democratic Republic of the Congo · enacted 2023What is DRC Digital Code 2023?Djibouti · enacted 2025What is Djibouti Digital Code 2025?Equatorial Guinea · enacted 2016What is Equatorial Guinea Law 1/2016?Eswatini · enacted 2022What is Eswatini Data Protection Act 2022?Ethiopia · enacted 2024What is Ethiopia Proclamation No. 1321/2024?Fiji · enacted 2018What is Fiji Privacy Framework?Gabon · enacted 2023What is Gabon Law 025/2023?Grenada · enacted 2023What is Grenada Data Protection Act 2023?Guinea · enacted 2016What is Guinea Law L/2016/037/AN?Guyana · enacted 2023What is Guyana Data Protection Act 2023?Haiti · enacted 2018What is Haiti 2018 Data Privacy Order?Iran (Islamic Republic of) · enacted 2003What is Iran Electronic Commerce Act 2003?Jordan · enacted 2023What is Jordan Personal Data Protection Law No. 24 of 2023?Kiribati · enacted 2025What is Kiribati Data Protection Act 2025?Kuwait · enacted 2024What is Kuwait CITRA Decision 2024/26?Lao People's Democratic Republic · enacted 2017What is Lao Law 25/NA?Lebanon · enacted 2018What is Lebanon Law 81/2018?Lesotho · enacted 2011What is Lesotho Data Protection Act 2011?Liberia · not enacted in this profileWhat is Liberia Data Protection Act 2024?Libya · enacted 2022What is Libya Law No. 6 of 2022?Liechtenstein · enacted 2026What is Liechtenstein DSG 2026?Madagascar · enacted 2015What is Madagascar Law 2014-038?Marshall Islands · enacted 2025What is Marshall Islands PDPA 2025?Mozambique · not enacted in this profileWhat is Mozambique Privacy Framework?Myanmar · enacted 2017What is Myanmar Privacy and Security Law?Nicaragua · enacted 2012What is Nicaragua Law No. 787?Niger · enacted 2022What is Niger Law No. 2022-59?Saint Kitts and Nevis · enacted 2018What is Saint Kitts and Nevis DPA No. 5 of 2018?Saint Vincent and the Grenadines · enacted 2003What is Saint Vincent and the Grenadines Privacy Act No. 18 of 2003?San Marino · enacted 2018What is San Marino Law No. 171/2018?Sao Tome and Principe · enacted 2016What is Lei n.º 03/2016?Seychelles · enacted 2023What is Seychelles Data Protection Act 2023?Somalia · enacted 2023What is Somalia Data Protection Act 2023?Syrian Arab Republic · enacted 2024What is Law No. 12 of 2024?Tajikistan · enacted 2018What is Law No. 1537?Tonga · enacted 2025What is Privacy Act 2025?Trinidad and Tobago · enacted 2011What is Trinidad and Tobago DPA 2011?Uganda · enacted 2019What is Uganda DPA 2019?United States of America · enacted 2013What is U.S. Privacy Law?Uzbekistan · enacted 2019What is Law No. O‘RQ-547?Venezuela (Bolivarian Republic of) · enacted 1999What is Constitution Article 28?Yemen · enacted 2012What is Law No. 13 of 2012?Zambia · enacted 2021What is Zambia Data Protection Act 2021?Holy See · enacted 2024What is Decree DCLVII?State of Palestine · not enacted in this profileWhat is Palestinian Data Protection Law (draft)?

Related concepts & guides