Data Protection Atlas

Personal Information Protection Law (China)

Tier 2 In force

Eight chapters, 74 articles. GDPR-shaped in places — but with no legitimate-interests basis, hard localisation triggers, and a state-security spine. One of three pillars alongside the Cybersecurity Law and the Data Security Law.

Identity

Citation
Personal Information Protection Law of the PRC
Jurisdiction
China
Type
comprehensive

Adopted 20 Aug 2021; in force 1 Nov 2021

Amended by: Supplemented by CAC measures, incl. the 2024 cross-border facilitation provisions

← China overview

Structure

What each Part or Chapter does, and the provisions worth knowing inside it. An orientation to the shape of the instrument — not a substitute for reading the official text.

Chapter I — General provisions (Arts 1–12)

Scope and principles, with a long extraterritorial arm.

  • Art 3 Applies abroad when providing products or services into China or analysing people in China.
Chapter II — Processing rules (Arts 13–37)

Legal bases, consent mechanics, sensitive data and state organs.

  • Art 13 Legal bases — notably no legitimate-interests ground.
  • Arts 28–32 Sensitive information — includes all data of under-14s; separate consent.
Chapter III — Cross-border provision (Arts 38–43)

The transfer gates: CAC security assessment, certification or the standard contract.

  • Art 38 The three transfer routes.
  • Art 41 No handover to foreign authorities without Chinese approval — a direct conflict point with foreign discovery.
Chapter IV — Individual rights (Arts 44–50)

Access, correction, deletion, explanation — plus rights of deceased persons’ relatives.

  • Art 44–47 Core rights.
  • Art 49 Relatives’ rights over a deceased person’s data.
Chapter V — Handler obligations (Arts 51–59)

Officers, audits, impact assessments, breach and platform gatekeeper duties.

  • Art 52 Personal information protection officer above thresholds.
  • Art 55–56 Impact assessments.
  • Art 58 Extra duties for very large platforms.
Chapters VI–VIII — Authorities, liability, misc (Arts 60–74)

Enforcement structure and the penalty ceiling.

  • Art 66 Fines — up to RMB 50m or 5% of prior-year turnover; personal liability to RMB 1m.

Regulatory enforcement

Interactions and conflicts

Sits atop the Cybersecurity Law (2017) and Data Security Law (2021) — the ‘three pillars’ — plus a thick layer of CAC measures. Article 41 collides head-on with foreign litigation discovery and law-enforcement requests. The 2024 facilitation provisions eased transfer thresholds without changing the architecture.

Sources

Never independently verified — seeded from the prototype.