Skip to content
World Watch/China/Data & Privacy

Data & Privacy ยท China

Data protection & privacy law in China (2026)

Comprehensive lawCountry index 81 ยท B+

China shaded by its data & privacy status

Data protection in China: comprehensive law.

FrameworkPersonal Information Protection Law (PIPL, effective 1 November 2021), operating alongside the Cybersecurity Law (CSL, 2017; first amendment effective 1 January 2026) and the Data Security Law (DSL, 2021), with the Cyberspace Administration of China (CAC) as lead regulator.

China has an in-force, GDPR-style omnibus personal-data regime centered on the PIPL, complemented by the DSL (data classification, national/important data) and the CSL (network security, cross-border rules). The CAC leads enforcement and rulemaking, and the cross-border transfer framework was finalized on 1 January 2026 with the Measures for Certification of Cross-Border Personal Information Transfer, completing the three legal pathways (security assessment, standard contract, certification). Enforcement in 2026 has been active, with a January 2026 CAC Q&A tightening operational expectations and joint CAC/MIIT/MPS campaigns targeting non-compliant apps.

Key points

Primary law and effective date

The Personal Information Protection Law (PIPL), passed 20 August 2021 and in force since 1 November 2021, is China's first omnibus personal-data statute; it applies to processing of PI of individuals in China and has extraterritorial reach where the purpose is to provide products/services to, or to analyze, individuals in China.

Supervisory authority

The Cyberspace Administration of China (CAC) is the lead regulator, coordinating with MIIT, the Ministry of Public Security, SAMR and sector regulators. The CAC issues implementing rules, runs security assessments, conducts audits, imposes fines, and orders takedowns of non-compliant apps and services.

Core obligations and individual rights

Handlers must have a lawful basis (typically consent), give clear notice, run personal-information protection impact assessments, appoint a DPO where thresholds are met, and secure the data; sensitive personal information (biometrics, health, financial account, religion, geolocation, minors under 14) requires separate, informed consent and strict safeguards. Individuals have rights of access, copy, correction, deletion, restriction, portability and withdrawal of consent.

Cross-border data transfers (framework completed Jan 2026)

PIPL provides three legal pathways for exporting personal information: a CAC-led security assessment (valid three years), CAC-approved Standard Contractual Clauses, and CAC certification. The Measures for Certification of Cross-Border Personal Information Transfer (CAC/SAMR, 14 Oct 2025) took effect 1 January 2026, completing the framework; GB/T 46068-2025 certification technical requirements take effect 1 March 2026.

Penalties

For serious violations, administrative fines can reach RMB 50 million or 5% of the prior year's turnover, alongside confiscation of illegal gains, service suspension, and revocation of business licenses. Directly responsible individuals can be fined up to RMB 1 million and barred from senior/DPO roles; serious data misuse can trigger criminal liability under the Criminal Law (up to 7 years).

2026 enforcement and rule-making activity

In January 2026 the CAC published a Q&A tightening expectations on facial recognition, PIPIAs and DPO duties; a Filing of Compliance Audits for Minors' Personal Information (Dec 2025) set an annual audit-filing duty with the first deadline 31 January 2026; and CAC/MIIT/MPS jointly issued the Measures for the Administration of Cybersecurity Labels in May 2026, while continuing the 2026 special campaign against non-compliant apps.

Timeline - major decisions & events

Jan 1, 2026lawofficial
Amended Cybersecurity Law takes effect

The first major overhaul of the 2017 CSL raises maximum fines to RMB 10 million, aligns penalties with the PIPL, broadens extraterritorial enforcement, and adds AI governance provisions. It marks a tightening and consolidation of China's data/cyber enforcement regime.

U.S. Library of Congress (Global Legal Monitor) โ†—
Jan 1, 2025lawofficial
Network Data Security Management Regulations take effect

Issued by the State Council on Sept 30, 2024, these administrative regulations operationalize the CSL, DSL and PIPL together, clarifying personal-information rules, important-data management and cross-border obligations for domestic and foreign processors.

State Council (gov.cn) โ†—
Mar 22, 2024guidanceofficial
CAC eases cross-border data transfer rules

The Provisions on Promoting and Regulating Cross-Border Data Flows introduced volume thresholds and broad exemptions (e.g. employee data, contract-necessary transfers, <100,000 individuals), substantially relaxing the export-compliance burden to attract investment.

U.S. Library of Congress (Global Legal Monitor) โ†—
Jun 1, 2023guidance
Standard Contract for outbound personal information takes effect

The CAC's Standard Contractual Clauses Measures created a China-specific SCC mechanism (alongside security assessment and certification) as a lawful route for exporting personal information overseas under the PIPL.

China Briefing โ†—
Sep 1, 2022guidance
Security Assessment Measures for outbound data take effect

The CAC's Measures required mandatory government security review for large-scale or sensitive cross-border data exports and by critical information infrastructure operators, the first hard implementation of the PIPL/DSL export regime.

China Briefing โ†—
Jul 21, 2022enforcement
Didi Global fined RMB 8.026 billion (~$1.2bn)

The CAC concluded a year-long probe finding 16 violations of the CSL, DSL and PIPL, including illegal collection of 64.7 billion records and sensitive data. It remains China's largest data-protection penalty and signaled aggressive enforcement.

DigiChina (Stanford), translating CAC โ†—
Nov 1, 2021law
Personal Information Protection Law (PIPL) takes effect

Adopted Aug 20, 2021, the PIPL is China's first comprehensive national personal-data law, a GDPR-style regime establishing consent rules, individual rights, processing principles and cross-border transfer requirements. It is the cornerstone of the current framework.

DigiChina (Stanford), translating NPC โ†—
Jan 1, 2021law
Civil Code privacy and personal-information chapter takes effect

Adopted May 28, 2020, China's first Civil Code dedicated a chapter (Book IV) to privacy and personal information, defining the right to privacy and consent-based processing as civil rights and laying groundwork for the PIPL.

China.org.cn โ†—
Jun 1, 2017law
Cybersecurity Law takes effect

China's first overarching cyber law introduced data-localization for critical information infrastructure, network-operator security duties and early personal-information protection rules, the foundation of the data-governance architecture.

Wikipedia (CSL overview) โ†—
Dec 28, 2012lawofficial
NPC Decision on Strengthening Network Information Protection

This 12-clause NPC Standing Committee decision was China's first national instrument with the force of law to protect citizens' electronic personal data, requiring consent, real-name registration and limits on disclosure, an early privacy milestone.

U.S. Library of Congress (Global Legal Monitor) โ†—

China - other topics

Data & Privacy in other countries

Last verified 8/26/2026 ยท Orientation, not legal advice - verify against the primary sources linked above. Methodology & how to cite ยท State of Technology Regulation 2026 ยท Explore the full world map โ†’