Personal Information Protection Law (China)
Tier 2 In forceEight chapters, 74 articles. GDPR-shaped in places — but with no legitimate-interests basis, hard localisation triggers, and a state-security spine. One of three pillars alongside the Cybersecurity Law and the Data Security Law.
Identity
- Citation
- Personal Information Protection Law of the PRC
- Jurisdiction
- China
- Type
- comprehensive
Adopted 20 Aug 2021; in force 1 Nov 2021
Amended by: Supplemented by CAC measures, incl. the 2024 cross-border facilitation provisions
Structure
What each Part or Chapter does, and the provisions worth knowing inside it. An orientation to the shape of the instrument — not a substitute for reading the official text.
Chapter I — General provisions (Arts 1–12)
Scope and principles, with a long extraterritorial arm.
- Art 3 Applies abroad when providing products or services into China or analysing people in China.
Chapter II — Processing rules (Arts 13–37)
Legal bases, consent mechanics, sensitive data and state organs.
- Art 13 Legal bases — notably no legitimate-interests ground.
- Arts 28–32 Sensitive information — includes all data of under-14s; separate consent.
Chapter III — Cross-border provision (Arts 38–43)
The transfer gates: CAC security assessment, certification or the standard contract.
- Art 38 The three transfer routes.
- Art 41 No handover to foreign authorities without Chinese approval — a direct conflict point with foreign discovery.
Chapter IV — Individual rights (Arts 44–50)
Access, correction, deletion, explanation — plus rights of deceased persons’ relatives.
- Art 44–47 Core rights.
- Art 49 Relatives’ rights over a deceased person’s data.
Chapter V — Handler obligations (Arts 51–59)
Officers, audits, impact assessments, breach and platform gatekeeper duties.
- Art 52 Personal information protection officer above thresholds.
- Art 55–56 Impact assessments.
- Art 58 Extra duties for very large platforms.
Chapters VI–VIII — Authorities, liability, misc (Arts 60–74)
Enforcement structure and the penalty ceiling.
- Art 66 Fines — up to RMB 50m or 5% of prior-year turnover; personal liability to RMB 1m.
Regulatory enforcement
Interactions and conflicts
Sits atop the Cybersecurity Law (2017) and Data Security Law (2021) — the ‘three pillars’ — plus a thick layer of CAC measures. Article 41 collides head-on with foreign litigation discovery and law-enforcement requests. The 2024 facilitation provisions eased transfer thresholds without changing the architecture.
Sources
Never independently verified — seeded from the prototype.