PIPL is often described as China’s GDPR, and structurally it is close: extraterritorial scope, lawful bases, individual rights, breach duties, big turnover-based fines. The compliance experience is harsher in three places: consent does almost all the work (no legitimate interests), “separate consent” gates the sensitive operations, and cross-border transfers are a regulated event requiring a filing, assessment, or certification rather than paperwork you self-manage. A roadmap that sequences those three correctly covers most of the risk.
| Regulation | PIPL (adopted 20 August 2021; effective 1 November 2021) |
|---|---|
| Max penalty | RMB 50M or 5% of prior year’s turnover |
| Enforcing authority | Cyberspace Administration of China |
| Benchmark enforcement | Didi, RMB 8.026 billion (July 2022) |
The roadmap in order
1. Scope and inventory. Map what personal information of people in China you touch, where it flows, and whether any of it is sensitive under Article 28 (biometrics, religion, medical, financial accounts, whereabouts, minors under 14). Sensitive data drags in separate consent, necessity justification, and impact assessments.
2. Lawful basis audit. Every processing purpose gets an Article 13 basis. Anything currently justified as “legitimate interests” in your GDPR records needs a new answer in China, usually consent, occasionally contract or HR necessity.
3. Consent rebuild. Implement separate consent flows for the four gated acts (sensitive data, third-party provision, public disclosure, export). Notices must be truthful, accurate, and complete in clear language (Article 17); consent must be revocable, and refusing consent cannot block service beyond what is necessary (Article 16).
4. Transfer mechanism. Pick the lane the volumes dictate, detailed in the PIPL cross-border transfer guide: CAC security assessment, standard contract filing, or certification, and run the required personal information protection impact assessment for each transfer scenario.
5. Governance. Appoint a personal information protection officer if you process above the designated volume; foreign processors appoint the China representative. Adopt internal management systems, classification, encryption or de-identification, access controls, training, and incident plans (Article 51), and run compliance audits, mandatory on regulator demand under the 2025 audit measures.
6. Rights and breaches. Build handling for access, copy, correction, deletion, portability (to designated handlers), and explanation of automated decisions, and notify authorities and individuals of incidents per Article 57. Automated decision-making, including algorithmic pricing, must not impose unreasonable differential treatment.
How it interlocks with the rest of Chinese data law
PIPL is one leg of a triad: the Cybersecurity Law (2017) governs network operators and CIIOs, and the Data Security Law (2021) classifies and protects data by importance, covered in the DSL and PIPL overlap guide. Multinationals should reconcile the program with GDPR using the PIPL vs. GDPR comparison: the frameworks rhyme, but Chinese consent and export rules are stricter in exactly the places EU programs relax. Baseline your consumer-facing surfaces first, what your site collects and sends before any consent, with a free scan.