Data & Privacy ยท China
Data protection & privacy law in China (2026)
China shaded by its data & privacy status
Data protection in China: comprehensive law.
FrameworkPersonal Information Protection Law (PIPL, effective 1 November 2021), operating alongside the Cybersecurity Law (CSL, 2017; first amendment effective 1 January 2026) and the Data Security Law (DSL, 2021), with the Cyberspace Administration of China (CAC) as lead regulator.
China has an in-force, GDPR-style omnibus personal-data regime centered on the PIPL, complemented by the DSL (data classification, national/important data) and the CSL (network security, cross-border rules). The CAC leads enforcement and rulemaking, and the cross-border transfer framework was finalized on 1 January 2026 with the Measures for Certification of Cross-Border Personal Information Transfer, completing the three legal pathways (security assessment, standard contract, certification). Enforcement in 2026 has been active, with a January 2026 CAC Q&A tightening operational expectations and joint CAC/MIIT/MPS campaigns targeting non-compliant apps.
Key points
The Personal Information Protection Law (PIPL), passed 20 August 2021 and in force since 1 November 2021, is China's first omnibus personal-data statute; it applies to processing of PI of individuals in China and has extraterritorial reach where the purpose is to provide products/services to, or to analyze, individuals in China.
The Cyberspace Administration of China (CAC) is the lead regulator, coordinating with MIIT, the Ministry of Public Security, SAMR and sector regulators. The CAC issues implementing rules, runs security assessments, conducts audits, imposes fines, and orders takedowns of non-compliant apps and services.
Handlers must have a lawful basis (typically consent), give clear notice, run personal-information protection impact assessments, appoint a DPO where thresholds are met, and secure the data; sensitive personal information (biometrics, health, financial account, religion, geolocation, minors under 14) requires separate, informed consent and strict safeguards. Individuals have rights of access, copy, correction, deletion, restriction, portability and withdrawal of consent.
PIPL provides three legal pathways for exporting personal information: a CAC-led security assessment (valid three years), CAC-approved Standard Contractual Clauses, and CAC certification. The Measures for Certification of Cross-Border Personal Information Transfer (CAC/SAMR, 14 Oct 2025) took effect 1 January 2026, completing the framework; GB/T 46068-2025 certification technical requirements take effect 1 March 2026.
For serious violations, administrative fines can reach RMB 50 million or 5% of the prior year's turnover, alongside confiscation of illegal gains, service suspension, and revocation of business licenses. Directly responsible individuals can be fined up to RMB 1 million and barred from senior/DPO roles; serious data misuse can trigger criminal liability under the Criminal Law (up to 7 years).
In January 2026 the CAC published a Q&A tightening expectations on facial recognition, PIPIAs and DPO duties; a Filing of Compliance Audits for Minors' Personal Information (Dec 2025) set an annual audit-filing duty with the first deadline 31 January 2026; and CAC/MIIT/MPS jointly issued the Measures for the Administration of Cybersecurity Labels in May 2026, while continuing the 2026 special campaign against non-compliant apps.
Timeline - major decisions & events
The first major overhaul of the 2017 CSL raises maximum fines to RMB 10 million, aligns penalties with the PIPL, broadens extraterritorial enforcement, and adds AI governance provisions. It marks a tightening and consolidation of China's data/cyber enforcement regime.
U.S. Library of Congress (Global Legal Monitor) โIssued by the State Council on Sept 30, 2024, these administrative regulations operationalize the CSL, DSL and PIPL together, clarifying personal-information rules, important-data management and cross-border obligations for domestic and foreign processors.
State Council (gov.cn) โThe Provisions on Promoting and Regulating Cross-Border Data Flows introduced volume thresholds and broad exemptions (e.g. employee data, contract-necessary transfers, <100,000 individuals), substantially relaxing the export-compliance burden to attract investment.
U.S. Library of Congress (Global Legal Monitor) โThe CAC's Standard Contractual Clauses Measures created a China-specific SCC mechanism (alongside security assessment and certification) as a lawful route for exporting personal information overseas under the PIPL.
China Briefing โThe CAC's Measures required mandatory government security review for large-scale or sensitive cross-border data exports and by critical information infrastructure operators, the first hard implementation of the PIPL/DSL export regime.
China Briefing โThe CAC concluded a year-long probe finding 16 violations of the CSL, DSL and PIPL, including illegal collection of 64.7 billion records and sensitive data. It remains China's largest data-protection penalty and signaled aggressive enforcement.
DigiChina (Stanford), translating CAC โAdopted Aug 20, 2021, the PIPL is China's first comprehensive national personal-data law, a GDPR-style regime establishing consent rules, individual rights, processing principles and cross-border transfer requirements. It is the cornerstone of the current framework.
DigiChina (Stanford), translating NPC โAdopted May 28, 2020, China's first Civil Code dedicated a chapter (Book IV) to privacy and personal information, defining the right to privacy and consent-based processing as civil rights and laying groundwork for the PIPL.
China.org.cn โChina's first overarching cyber law introduced data-localization for critical information infrastructure, network-operator security duties and early personal-information protection rules, the foundation of the data-governance architecture.
Wikipedia (CSL overview) โThis 12-clause NPC Standing Committee decision was China's first national instrument with the force of law to protect citizens' electronic personal data, requiring consent, real-name registration and limits on disclosure, an early privacy milestone.
U.S. Library of Congress (Global Legal Monitor) โChina - other topics
Data & Privacy in other countries
Last verified 8/26/2026 ยท Orientation, not legal advice - verify against the primary sources linked above. Methodology & how to cite ยท State of Technology Regulation 2026 ยท Explore the full world map โ