China
Tier 2 Comprehensive law Asia-PacificPrincipal framework: PIPL (2021). Regulator: CAC. Cross-border transfers need a CAC security assessment, certification or standard contract; the 2024 provisions eased thresholds and free-trade zones keep negative lists.
At a glance
- Principal law
- Personal Information Protection Law, in force 1 Nov 2021
- Regulator
- Cyberspace Administration of China
- Breach notification
- Immediate remediation plus notice to the CAC and affected individuals
- Maximum penalty
- Up to RMB 50m or 5% of prior-year turnover; personal fines to RMB 1m
- DPO required
- PIPL officer above CAC thresholds; local representative for foreign handlers
- Digital consent age
- 14 — under-14s’ data is sensitive and needs guardian consent
- Extraterritorial reach
- Yes — Art 3 PIPL
Structure
- Structural pattern
- Not assessed
- Sub-jurisdictions
- None — no sub-national axis
- ISO code
- CN
A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.
Transfers and adequacy
- EU member
- No
- EEA member
- No
Instruments
Sources
- Primary Personal Information Protection Law, in force 1 Nov 2021
- Primary NPC — official text (Chinese)
- Regulator CAC — regulator
Never independently verified — seeded from the prototype.