Asia-Pacific China

PIPL Compliance Roadmap: China's Privacy Law Step by Step

A practical sequence for PIPL compliance: scope analysis, consent rebuild, cross-border transfer filings, local representative, and CAC audit readiness.

Regulation

Personal Information Protection Law (PIPL), effective 1 November 2021

Max Penalty

RMB 50 million or 5% of prior year's turnover; personal fines to RMB 1 million

Enforcing Authority

Cyberspace Administration of China (CAC)

Official Source

www.cac.gov.cn

Executive Summary

  • PIPL took effect on 1 November 2021 and applies extraterritorially: processing personal information of people in China to provide products or services, or to analyze their behavior, is in scope from anywhere.
  • Consent is the workhorse lawful basis, and PIPL demands 'separate consent' for sensitive information, cross-border transfers, disclosure to third parties, and public disclosure. There is no legitimate-interests basis.
  • Cross-border transfers require one of three mechanisms: a CAC security assessment, the CAC standard contract with filing, or certification, with thresholds relaxed by the March 2024 facilitation rules.
  • Foreign processors in scope must establish a dedicated entity or appoint a representative in China and report its details to the authorities.
  • Enforcement is real: the CAC fined Didi RMB 8.026 billion in 2022 under PIPL, CSL, and DSL, and app-store takedowns are a routine sanction.

PIPL is often described as China’s GDPR, and structurally it is close: extraterritorial scope, lawful bases, individual rights, breach duties, big turnover-based fines. The compliance experience is harsher in three places: consent does almost all the work (no legitimate interests), “separate consent” gates the sensitive operations, and cross-border transfers are a regulated event requiring a filing, assessment, or certification rather than paperwork you self-manage. A roadmap that sequences those three correctly covers most of the risk.

RegulationPIPL (adopted 20 August 2021; effective 1 November 2021)
Max penaltyRMB 50M or 5% of prior year’s turnover
Enforcing authorityCyberspace Administration of China
Benchmark enforcementDidi, RMB 8.026 billion (July 2022)

The roadmap in order

1. Scope and inventory. Map what personal information of people in China you touch, where it flows, and whether any of it is sensitive under Article 28 (biometrics, religion, medical, financial accounts, whereabouts, minors under 14). Sensitive data drags in separate consent, necessity justification, and impact assessments.

2. Lawful basis audit. Every processing purpose gets an Article 13 basis. Anything currently justified as “legitimate interests” in your GDPR records needs a new answer in China, usually consent, occasionally contract or HR necessity.

3. Consent rebuild. Implement separate consent flows for the four gated acts (sensitive data, third-party provision, public disclosure, export). Notices must be truthful, accurate, and complete in clear language (Article 17); consent must be revocable, and refusing consent cannot block service beyond what is necessary (Article 16).

4. Transfer mechanism. Pick the lane the volumes dictate, detailed in the PIPL cross-border transfer guide: CAC security assessment, standard contract filing, or certification, and run the required personal information protection impact assessment for each transfer scenario.

5. Governance. Appoint a personal information protection officer if you process above the designated volume; foreign processors appoint the China representative. Adopt internal management systems, classification, encryption or de-identification, access controls, training, and incident plans (Article 51), and run compliance audits, mandatory on regulator demand under the 2025 audit measures.

6. Rights and breaches. Build handling for access, copy, correction, deletion, portability (to designated handlers), and explanation of automated decisions, and notify authorities and individuals of incidents per Article 57. Automated decision-making, including algorithmic pricing, must not impose unreasonable differential treatment.

How it interlocks with the rest of Chinese data law

PIPL is one leg of a triad: the Cybersecurity Law (2017) governs network operators and CIIOs, and the Data Security Law (2021) classifies and protects data by importance, covered in the DSL and PIPL overlap guide. Multinationals should reconcile the program with GDPR using the PIPL vs. GDPR comparison: the frameworks rhyme, but Chinese consent and export rules are stricter in exactly the places EU programs relax. Baseline your consumer-facing surfaces first, what your site collects and sends before any consent, with a free scan.

Frequently Asked Questions

Does PIPL apply to my company if we have no China entity?

Yes, if you process personal information of natural persons in China to provide them products or services or to analyze or evaluate their behavior (Article 3). In-scope foreign processors must also set up a dedicated institution or designate a representative in China and file its contact details.

What is 'separate consent' under PIPL?

A standalone, specific consent action distinct from general acceptance of a privacy policy. It is required for processing sensitive personal information, providing data to other handlers, public disclosure, and cross-border transfers. Bundled or pre-ticked consent fails; regulators and courts have treated blanket policies as invalid for these acts.

Which cross-border mechanism do we need?

Depends on volume and data type: CAC security assessment for CIIOs, important data, or personal information of more than 1 million people per year (100,000 for sensitive); the CAC standard contract or certification below those lines. The March 2024 rules exempt low-volume transfers (under 100,000 non-sensitive individuals per year) and certain contract-necessity transfers.

How large are PIPL penalties?

Grave violations: up to RMB 50 million or 5% of the previous year's turnover, plus business suspension and license revocation. Directly responsible individuals face fines up to RMB 1 million and can be barred from serving as directors or senior managers. Didi's RMB 8.026 billion penalty is the benchmark.

Does PIPL have a legitimate-interests basis like GDPR?

No. Article 13 lists consent, contract necessity (including HR management under labor rules), legal obligations, emergencies, limited news/public-interest processing, and lawfully disclosed data. The absence of legitimate interests means marketing, analytics, and profiling nearly always ride on consent in China.

Regulatory Crosswalk

GDPRChina DSLChina CSL

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.