Data Protection Atlas

China

Tier 2 Comprehensive law Asia-Pacific

Principal framework: PIPL (2021). Regulator: CAC. Cross-border transfers need a CAC security assessment, certification or standard contract; the 2024 provisions eased thresholds and free-trade zones keep negative lists.

At a glance

Principal law
Personal Information Protection Law, in force 1 Nov 2021
Regulator
Cyberspace Administration of China
Breach notification
Immediate remediation plus notice to the CAC and affected individuals
Maximum penalty
Up to RMB 50m or 5% of prior-year turnover; personal fines to RMB 1m
DPO required
PIPL officer above CAC thresholds; local representative for foreign handlers
Digital consent age
14 — under-14s’ data is sensitive and needs guardian consent
Extraterritorial reach
Yes — Art 3 PIPL

Structure

Structural pattern
Not assessed
Sub-jurisdictions
None — no sub-national axis
ISO code
CN

A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.

Transfers and adequacy

EU member
No
EEA member
No

Instruments

Sources

Never independently verified — seeded from the prototype.