Consent under PIPL does more work than under any comparable privacy law, because China deliberately omitted a legitimate-interests basis. Everything a European program justifies with a balancing test, personalization, analytics, ad measurement, rides on consent in China, and PIPL grades consent strictly: informed, voluntary, explicit, revocable, and, for the four most dangerous operations, “separate.”
| Regulation | PIPL Articles 13-18, 23, 25-26, 29, 39 |
|---|---|
| Max penalty | RMB 50M or 5% of prior year’s turnover |
| Enforcing authority | CAC |
| Key concept | Separate consent for four gated operations |
The baseline standard
Article 14: consent must be given voluntarily and explicitly, with full information, and re-obtained when purposes, methods, or categories change. Article 15: withdrawal must be provided in a convenient way, and withdrawal does not invalidate prior processing. Article 16: handlers may not refuse products or services for non-consent unless the processing is genuinely necessary. Article 17 requires notice of the handler’s identity, purposes, methods, categories, retention periods, and rights procedures, truthfully, accurately, completely, and in clear, easily understood language.
The four separate-consent gates
- Sensitive personal information (Article 29). Biometrics, religion, specific identity, medical health, financial accounts, whereabouts and location tracks, plus anything about minors under 14 (which also needs parental consent). Processing sensitive data additionally requires specific purpose, sufficient necessity, strict protections, and an impact assessment.
- Providing data to another handler (Article 23). Sharing with business partners, group companies, or ad platforms needs a standalone consent naming the recipient, purposes, and categories.
- Public disclosure (Article 25). Publishing personal information requires its own consent.
- Cross-border provision (Article 39). Exporting data needs separate consent naming the overseas recipient, purposes, methods, categories, and how individuals exercise rights against the foreign recipient, on top of the transfer mechanism itself.
The design consequence: a Chinese consent stack is layered, a general notice acceptance plus discrete prompts at the moment each gated operation occurs. Global CMP templates built for GDPR granularity usually miss the standalone-action requirement.
Enforcement reality
Consent is where Chinese enforcement concentrates. The MIIT and CAC run continuous app-audit campaigns, publishing batches of apps cited for collecting beyond stated purposes, coercive consent, or missing separate consent, with rectification deadlines and store delisting for laggards. The Didi decision (RMB 8.026 billion, 2022) itemized illegal collection of clipboard data, location, and facial recognition information among sixteen violation categories. The Guangzhou Internet Court’s 2023 judgment against a multinational’s cookie-consent flow found separate consent missing for transfers, a warning shot for web properties, not just apps.
Sequence the fix inside the wider PIPL roadmap, compare the EU baseline in PIPL vs. GDPR, and test what your own site collects before any consent action with a free scan.