World Watch/China/Data & Privacy

Data & Privacy · China

Data protection & privacy laws in China (2026)

Comprehensive lawPersonal Information Protection Law (PIPL, effective 1 Nov 2021), reinforced by the Data Security Law (2021) and the Cybersecurity Law (amended, effective 1 Jan 2026); supervised by the Cyberspace Administration of China (CAC).Country index 76 · B+

China shaded by its data & privacy status

China operates a comprehensive, GDPR-influenced personal-data regime anchored by the PIPL, which sets out legal bases for processing, individual rights, consent rules, and cross-border transfer mechanisms. It sits alongside two other 'pillar' laws — the Data Security Law (governing data classification and 'important data') and the Cybersecurity Law (governing network security and critical information infrastructure). The CAC is the lead regulator, with enforcement intensifying in 2025-2026 through amended CSL penalties and new cross-border certification measures.

Key points

Comprehensive statute (PIPL)

The PIPL, effective 1 November 2021, is China's dedicated, omnibus personal-data law establishing legal bases for processing, consent (including 'separate consent' for sensitive data and transfers), and individual rights such as access, correction, deletion, and portability.

Supervisory authority

The Cyberspace Administration of China (CAC) leads overall planning, coordination, and enforcement of personal-information protection, issuing implementing rules, conducting investigations, levying fines, and ordering suspension of non-compliant services; relevant ministries and county-level-and-above departments share sectoral supervision.

Three-pillar framework

The PIPL (personal data) operates alongside the Data Security Law (data classification and 'important data' protection) and the Cybersecurity Law (network security and critical information infrastructure operators), forming China's integrated data-governance architecture.

Cross-border transfer rules

Transfers of personal data abroad require one of three routes — a CAC security assessment, certification by an accredited body, or CAC standard contractual clauses — plus separate notice and consent; new Measures on Certification for Cross-Border Transfer of Personal Information took effect 1 January 2026.

Processor obligations

Handlers must adopt internal management systems and technical security measures, conduct personal-information protection impact assessments for high-risk processing, and notify the supervisory authority and affected individuals of data breaches with remedial action.

Strengthened enforcement (2026)

Amendments to the Cybersecurity Law, effective 1 January 2026, raise the general administrative fine cap from RMB 1 million to RMB 10 million, broaden extraterritorial reach, and remove the prior-warning requirement, allowing immediate fines; the CAC's January 2026 PIPL Q&A signals a shift toward documentation and accountability enforcement.

Timeline - major decisions & events

Jan 1, 2026lawofficial
Amended Cybersecurity Law takes effect

The first major overhaul of the 2017 CSL raises maximum fines to RMB 10 million, aligns penalties with the PIPL, broadens extraterritorial enforcement, and adds AI governance provisions. It marks a tightening and consolidation of China's data/cyber enforcement regime.

U.S. Library of Congress (Global Legal Monitor)
Jan 1, 2025lawofficial
Network Data Security Management Regulations take effect

Issued by the State Council on Sept 30, 2024, these administrative regulations operationalize the CSL, DSL and PIPL together, clarifying personal-information rules, important-data management and cross-border obligations for domestic and foreign processors.

State Council (gov.cn)
Mar 22, 2024guidanceofficial
CAC eases cross-border data transfer rules

The Provisions on Promoting and Regulating Cross-Border Data Flows introduced volume thresholds and broad exemptions (e.g. employee data, contract-necessary transfers, <100,000 individuals), substantially relaxing the export-compliance burden to attract investment.

U.S. Library of Congress (Global Legal Monitor)
Jun 1, 2023guidance
Standard Contract for outbound personal information takes effect

The CAC's Standard Contractual Clauses Measures created a China-specific SCC mechanism (alongside security assessment and certification) as a lawful route for exporting personal information overseas under the PIPL.

China Briefing
Sep 1, 2022guidance
Security Assessment Measures for outbound data take effect

The CAC's Measures required mandatory government security review for large-scale or sensitive cross-border data exports and by critical information infrastructure operators, the first hard implementation of the PIPL/DSL export regime.

China Briefing
Jul 21, 2022enforcement
Didi Global fined RMB 8.026 billion (~$1.2bn)

The CAC concluded a year-long probe finding 16 violations of the CSL, DSL and PIPL, including illegal collection of 64.7 billion records and sensitive data. It remains China's largest data-protection penalty and signaled aggressive enforcement.

DigiChina (Stanford), translating CAC
Nov 1, 2021law
Personal Information Protection Law (PIPL) takes effect

Adopted Aug 20, 2021, the PIPL is China's first comprehensive national personal-data law—a GDPR-style regime establishing consent rules, individual rights, processing principles and cross-border transfer requirements. It is the cornerstone of the current framework.

DigiChina (Stanford), translating NPC
Jan 1, 2021law
Civil Code privacy and personal-information chapter takes effect

Adopted May 28, 2020, China's first Civil Code dedicated a chapter (Book IV) to privacy and personal information, defining the right to privacy and consent-based processing as civil rights and laying groundwork for the PIPL.

China.org.cn
Jun 1, 2017law
Cybersecurity Law takes effect

China's first overarching cyber law introduced data-localization for critical information infrastructure, network-operator security duties and early personal-information protection rules—the foundation of the data-governance architecture.

Wikipedia (CSL overview)
Dec 28, 2012lawofficial
NPC Decision on Strengthening Network Information Protection

This 12-clause NPC Standing Committee decision was China's first national instrument with the force of law to protect citizens' electronic personal data, requiring consent, real-name registration and limits on disclosure—an early privacy milestone.

U.S. Library of Congress (Global Legal Monitor)

China - other topics

Last verified 5/23/2026 · Orientation, not legal advice - verify against the primary sources linked above. Explore the full world map →