Asia-Pacific China

PIPL Consent Requirements: Separate Consent Explained

What valid consent looks like under China's PIPL: informed, voluntary, explicit, revocable, and 'separate' for sensitive data, sharing, disclosure, and exports.

Regulation

PIPL Articles 13-18, 23, 25-26, 29, 39

Max Penalty

RMB 50 million or 5% of prior year's turnover

Enforcing Authority

Cyberspace Administration of China (CAC)

Official Source

www.cac.gov.cn

Executive Summary

  • PIPL consent must be given voluntarily and explicitly by fully informed individuals (Article 14), be as easy to withdraw as to give (Article 15), and services cannot be refused for non-consent beyond necessity (Article 16).
  • Four operations require 'separate consent': processing sensitive personal information (Article 29), providing data to another handler (Article 23), public disclosure (Article 25), and cross-border transfers (Article 39).
  • Sensitive personal information includes biometrics, religious beliefs, specific identities, medical health, financial accounts, whereabouts, and any data of minors under 14, which also requires parental consent.
  • Because PIPL has no legitimate-interests basis, consent carries marketing, analytics, personalization, and most app permissions.
  • App-level enforcement is constant: the CAC and MIIT publicly name and delist apps for excessive collection and consent violations.

Consent under PIPL does more work than under any comparable privacy law, because China deliberately omitted a legitimate-interests basis. Everything a European program justifies with a balancing test, personalization, analytics, ad measurement, rides on consent in China, and PIPL grades consent strictly: informed, voluntary, explicit, revocable, and, for the four most dangerous operations, “separate.”

RegulationPIPL Articles 13-18, 23, 25-26, 29, 39
Max penaltyRMB 50M or 5% of prior year’s turnover
Enforcing authorityCAC
Key conceptSeparate consent for four gated operations

The baseline standard

Article 14: consent must be given voluntarily and explicitly, with full information, and re-obtained when purposes, methods, or categories change. Article 15: withdrawal must be provided in a convenient way, and withdrawal does not invalidate prior processing. Article 16: handlers may not refuse products or services for non-consent unless the processing is genuinely necessary. Article 17 requires notice of the handler’s identity, purposes, methods, categories, retention periods, and rights procedures, truthfully, accurately, completely, and in clear, easily understood language.

  1. Sensitive personal information (Article 29). Biometrics, religion, specific identity, medical health, financial accounts, whereabouts and location tracks, plus anything about minors under 14 (which also needs parental consent). Processing sensitive data additionally requires specific purpose, sufficient necessity, strict protections, and an impact assessment.
  2. Providing data to another handler (Article 23). Sharing with business partners, group companies, or ad platforms needs a standalone consent naming the recipient, purposes, and categories.
  3. Public disclosure (Article 25). Publishing personal information requires its own consent.
  4. Cross-border provision (Article 39). Exporting data needs separate consent naming the overseas recipient, purposes, methods, categories, and how individuals exercise rights against the foreign recipient, on top of the transfer mechanism itself.

The design consequence: a Chinese consent stack is layered, a general notice acceptance plus discrete prompts at the moment each gated operation occurs. Global CMP templates built for GDPR granularity usually miss the standalone-action requirement.

Enforcement reality

Consent is where Chinese enforcement concentrates. The MIIT and CAC run continuous app-audit campaigns, publishing batches of apps cited for collecting beyond stated purposes, coercive consent, or missing separate consent, with rectification deadlines and store delisting for laggards. The Didi decision (RMB 8.026 billion, 2022) itemized illegal collection of clipboard data, location, and facial recognition information among sixteen violation categories. The Guangzhou Internet Court’s 2023 judgment against a multinational’s cookie-consent flow found separate consent missing for transfers, a warning shot for web properties, not just apps.

Sequence the fix inside the wider PIPL roadmap, compare the EU baseline in PIPL vs. GDPR, and test what your own site collects before any consent action with a free scan.

Frequently Asked Questions

How is separate consent different from normal consent?

Normal consent can be collected through a well-built privacy notice acceptance. Separate consent must be a distinct, standalone action tied to the specific operation: its own dialog, checkbox, or signature for, say, exporting your data abroad, not a clause folded into the general policy. Courts and regulators have rejected bundled acceptance for the four gated operations.

When do we need parental consent?

For personal information of minors under 14, which PIPL classifies as sensitive per se: parental or guardian consent is required, plus specific processing rules for minors' data. This is stricter than GDPR's 13-16 age band and applies regardless of the service's audience.

Can we deny service if a user refuses consent?

Only where the data is genuinely necessary for the service (Article 16). Refusing to run a maps app without location is defensible; refusing without marketing consent is not. Chinese app regulators actively test this pattern and have delisted apps that coerce consent.

Is consent required for employee data in China?

Not always. Article 13 permits processing necessary for HR management under lawfully adopted labor rules and collective contracts, China's rough analogue to contract necessity. Sensitive employee data and cross-border HR transfers still commonly need separate consent, and the 2024 facilitation rules exempt some HR-necessity exports from the mechanism requirement.

What happens when consent standards are violated?

Rectification orders, warnings, confiscation of unlawful gains, and app-store removal at the routine end; fines to RMB 50 million or 5% of turnover for grave cases, plus personal fines to RMB 1 million for responsible individuals. Public naming by the CAC and MIIT is itself a sanction with real market impact.

Regulatory Crosswalk

GDPR Art. 7PIPL

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.