Skip to main content

China Personal Information Protection Law (PIPL) — Key Rules

Authored by: Peter Zhu
30. July 2026
Overview (draft). This page is published for navigation and internal linking while we expand the full guide. For advice on a specific matter, browse verified lawyers.

China's Personal Information Protection Law (PIPL), effective November 2021, is China's comprehensive data privacy law modeled on the GDPR but with distinct requirements for data processing, cross-border transfer, and enforcement.

Key Principles

  • Consent � Separate, informed consent required for most processing
  • Purpose limitation � Data must be processed only for specified purposes
  • Data minimization � Collect only data necessary for the purpose
  • Transparency � Clear privacy policies required

Cross-Border Data Transfer

Three mechanisms for transferring personal data out of China: (1) security assessment by CAC (for critical data operators), (2) standard contractual clauses (SCCs) with the data subject, (3) certification by a recognized body.

Penalties

Fines up to RMB 50M or 5% of prior year revenue for serious violations. Individuals can claim damages. Class actions are available through consumer associations and????.

About the Author

Peter Zhu