China Personal Information Protection Law (PIPL) — Key Rules
Authored by: Peter Zhu
30. July 2026
Overview (draft). This page is published for navigation and internal linking while we expand the full guide. For advice on a specific matter, browse verified lawyers.
China's Personal Information Protection Law (PIPL), effective November 2021, is China's comprehensive data privacy law modeled on the GDPR but with distinct requirements for data processing, cross-border transfer, and enforcement.
Key Principles
- Consent � Separate, informed consent required for most processing
- Purpose limitation � Data must be processed only for specified purposes
- Data minimization � Collect only data necessary for the purpose
- Transparency � Clear privacy policies required
Cross-Border Data Transfer
Three mechanisms for transferring personal data out of China: (1) security assessment by CAC (for critical data operators), (2) standard contractual clauses (SCCs) with the data subject, (3) certification by a recognized body.
Penalties
Fines up to RMB 50M or 5% of prior year revenue for serious violations. Individuals can claim damages. Class actions are available through consumer associations and????.
About the Author
Peter Zhu
Blog Topics