What Is Personal Information Protection Law of the People's Republic of China?
The Personal Information Protection Law of the People's Republic of China (PIPL, 个人信息保护法) is China's first comprehensive personal-information protection statute. Passed by the Standing Committee of the National People's Congress on 20 August 2021 and in force 1 November 2021, PIPL operates alongside the Cybersecurity Law and Data Security Law in China's data-protection framework. PIPL has GDPR-like rights but also China-specific rules on lawful processing, sensitive personal information, automated decision-making, domestic storage, cross-border transfers, and regulator oversight. The CAC coordinates personal-information protection, while relevant State Council and local-government departments handle supervision within their assigned duties. Articles 38–43 set the statutory cross-border framework. The March 22, 2024 Regulations on Promoting and Regulating Cross-Border Data Flows added exemptions, annual-volume thresholds, and free-trade-zone negative-list options; the 2023 standard-contract measures and certification rules still matter. These rules do not turn every transfer into the same approval process. The Small Personal Information Processors Simplified Measures were published on July 24, 2026 and took effect on September 1, 2026; they simplify specified compliance steps for processors handling fewer than 100,000 individuals but do not replace the PIPL.
At a glance
- Full name
- Personal Information Protection Law of the People's Republic of China
- Short code
- PIPL
- Jurisdiction
- China
- Enacted
- 2021
- Last major update
- In force November 1, 2021; Regulations on Promoting and Regulating Cross-Border Data Flows effective March 22, 2024; Personal Information Protection Compliance Audit Measures effective May 1, 2025; Small Personal Information Processors Simplified Measures took effect on September 1, 2026
- Regulator
- Cyberspace Administration of China (CAC) + sectoral regulators
- Private right of action
- Limited
- Statutory citation
- Personal Information Protection Law of the People's Republic of China
Scope, who PIPL covers
Protected data
Data subject rights
Right to know the processing rules and make decisions about processing (Article 44)
Right to restrict or refuse processing by others (Article 44)
Right of access and copy of personal information (Article 45)
Right to correction and supplementation (Article 46)
Right to request deletion when an Article 47 circumstance or other applicable legal condition exists
Right to request transfer of personal information to a designated processor where Article 45 and applicable CAC conditions are met
Right to an explanation of the processing rules
Right to request an explanation of a significant automated decision and refuse a decision made only through automated decision-making (Article 24)
Right to use the processor's rights-request mechanism, complain or report illegal processing to a department with personal-information protection duties, and bring a lawsuit where the law permits
Notable features
PIPL's distinctive features include: (1) cross-border data-transfer mechanisms that can involve a CAC security assessment, a standard contract under CAC rules, certification, or another applicable legal/regulatory route; (2) domestic-storage and security-assessment rules for CIIOs and prescribed-volume processors; (3) burden allocation in civil damages claims under Article 69; and (4) coordination with the Cybersecurity Law and Data Security Law. The 2024 cross-border regulations and the small-processor measures that took effect on September 1, 2026 must be checked for the transfer or processor at issue.
Enforcement & penalties
Regulator: Cyberspace Administration of China (CAC) + sectoral regulators
Penalties: Article 66 distinguishes ordinary violations from serious violations. Ordinary measures can include correction orders, warnings, confiscation of illegal gains, app-service suspension or termination, and—when the violator refuses to correct—a fine of up to RMB 1 million plus fines for directly responsible people. Serious violations can carry a fine of up to RMB 50 million or 5% of the previous year's turnover, possible business suspension or license action, fines of RMB 100,000–1 million for directly responsible people, and possible management bans. Public-security or criminal liability can also apply under Article 71; outcomes depend on the conduct and authority involved.
Private right of action: Articles 50 and 69 support civil litigation in defined circumstances: a person whose rights request is rejected may sue under the law, and a processor that infringes personal-information rights and cannot prove it was not at fault can bear damages and other tort liability. Article 70 provides a public-interest litigation route for the people's procuratorate, qualifying consumer organizations, and an organization designated by the CAC when many individuals' rights are infringed; this is not a blanket individual class-action right.
Relevance to data brokers
PIPL's Article 3 can reach an overseas provider that offers products or services to people in China or analyzes their behavior. A data broker's exposure depends on the processing role, purpose, source, legal basis, location, outbound transfer, and applicable exceptions; the provider's location alone is not enough. As a dated enforcement example, the CAC stated that its July 2022 RMB 8.026 billion Didi penalty was based on violations of the Cybersecurity Law, Data Security Law, PIPL, and Administrative Penalty Law. That case does not establish a penalty or outcome for every foreign broker.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Does PIPL apply to foreign companies?+
Yes, when the Article 3 conditions apply. PIPL can cover processing outside China for offering products or services to people in China or analyzing or evaluating their behavior. A covered foreign handler must designate a China-based representative or institution and report the relevant information to the competent authority as required by the law; the exact compliance route depends on the activity and current rules.
What are PIPL cross-border transfer requirements?+
Article 38 lists a CAC security assessment, personal-information protection certification under CAC rules, a standard contract under CAC rules, or another applicable law, regulation, or CAC condition. The March 2024 cross-border regulations add important-data and volume thresholds, exemptions, and free-trade-zone negative-list rules: for example, non-CIIO processors generally face security-assessment thresholds at important data, 1 million or more non-sensitive individuals, or 10,000 or more sensitive individuals, while a lower band can use the standard-contract or certification route. Certain contract, employment, emergency, low-volume, and other listed cases can be exempt from those mechanisms, but notice, separate-consent, impact-assessment, and security duties may still apply.
What is a 'Critical Information Infrastructure Operator' (CIIO)?+
CIIOs are operators of critical information infrastructure identified under China's cybersecurity framework. PIPL requires CIIOs to store personal information collected and generated in China domestically; where it is truly necessary to provide that information overseas, Article 40 generally requires a CAC-organized security assessment, subject to later laws, regulations, or CAC provisions that make an assessment unnecessary. Do not treat the sector examples or the transfer outcome as automatic without checking the current designation and rules.
How do I file a PIPL complaint?+
Article 65 allows any organization or individual to complain or report illegal personal-information processing to a department with personal-information protection duties, which must handle the matter under law and publish contact information. Use the current CAC or relevant local/sectoral department route for the processing at issue. A rights request rejected by a processor can support a people's-court action under applicable law, while Article 69 damages and Article 70 public-interest litigation have their own statutory conditions.
Official sources & citations
- Supreme People's Procuratorate: official English PIPL text
- CAC: official Chinese PIPL text
- CAC: Regulations on Promoting and Regulating Cross-Border Data Flows
- CAC: Measures for Standard Contract for Cross-Border Transfer
- CAC: Personal Information Protection Compliance Audit Measures
- CAC: Small Personal Information Processors Simplified Measures
Other international privacy regimes
PIPL sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
