Asia-Pacific China

PIPL Data Subject Rights: What Individuals Can Demand in China

The individual rights in PIPL Chapter IV: access, copy, correction, deletion, portability, explanation of automated decisions, and rights of the deceased's relatives.

Regulation

PIPL Articles 44-50

Max Penalty

RMB 50 million or 5% of prior year's turnover

Enforcing Authority

Cyberspace Administration of China (CAC)

Official Source

www.cac.gov.cn

Executive Summary

  • PIPL Chapter IV grants individuals rights to know, decide, restrict, and refuse processing (Article 44), access and copy (Article 45), portability to designated handlers, correction (Article 46), and deletion (Article 47).
  • Deletion is partly automatic: handlers must delete on their own initiative when purposes are achieved, retention expires, services stop, or consent is withdrawn.
  • Article 24 gives rights against automated decision-making: transparency, no unreasonable differential treatment (algorithmic price discrimination), opt-out of personalized marketing, and explanation plus refusal of significant automated decisions.
  • Article 49 extends rights to the deceased: close relatives can exercise access, copy, correction, and deletion over a deceased person's information for their own lawful interests.
  • Handlers must build a convenient request mechanism and explain refusals; refusal can be challenged in court (Article 50).

PIPL’s rights chapter looks familiar to anyone who has run a GDPR rights program: know, access, copy, correct, delete, port. The differences sit at the edges, and two of them are genuinely novel: relatives inherit rights over a deceased person’s data, and algorithmic price discrimination is banned as a rights matter. For operators, the practical work is the same as in Europe: a request channel that works, identity verification, and deletion logic wired to real retention rules.

RegulationPIPL Chapter IV (Articles 44-50)
Max penaltyRMB 50M or 5% of prior year’s turnover
Enforcing authorityCAC
Court routeArticle 50: refusals are directly actionable

The rights, article by article

Know and decide (Article 44). The umbrella right: individuals may know about and decide on processing, and restrict or refuse it, except where law requires otherwise.

Access and copy (Article 45). Individuals can consult and copy their personal information, promptly provided, plus the portability channel to a designated handler where CAC conditions are met.

Correction (Article 46). Inaccurate or incomplete data must be corrected or completed after verification.

Deletion (Article 47). Request-based and proactive: purposes achieved, retention expired, service shuttered, consent withdrawn, or unlawful processing all trigger deletion without being asked. This proactive duty is stricter in form than GDPR Article 17 and turns retention schedules into deletion pipelines.

Automated decisions (Article 24). Decisions via automated processing must be transparent, fair, and just; no unreasonable differential treatment on price or terms (the anti-”big data killing familiarity” rule); marketing pushes need a non-personalized alternative; and decisions with a major effect on rights carry explanation and refusal rights. Compare the EU Article 22 regime.

Deceased persons (Article 49). Close relatives may access, copy, correct, and delete the deceased’s information for their own lawful and legitimate interests, absent contrary arrangements made by the deceased.

Enforcement lever (Article 50). Handlers must establish convenient mechanisms and explain refusals, and individuals can sue over refusals directly, no regulator complaint needed first.

Building the program

Route Chinese requests through the same DSAR machinery you run for GDPR, with three China additions: a verified-relative flow for deceased-person requests, deletion triggers wired to consent withdrawal and service termination events, and the recommendation-algorithm off switch on consumer surfaces. Consent quality upstream determines rights load downstream, per the PIPL consent guide, and the full compliance sequence lives in the PIPL roadmap.

Frequently Asked Questions

Which rights does PIPL grant that GDPR does not?

Two stand out: rights of close relatives over a deceased person's data (Article 49), which GDPR leaves to member-state law, and the explicit ban on unreasonable differential treatment in automated pricing (Article 24), aimed at 'big data swindling' of loyal customers. GDPR counters with objection and restriction rights PIPL lacks in general form.

Is there a response deadline for requests?

PIPL sets no fixed day-count; handlers must respond 'in a timely manner' and provide a convenient mechanism. Supporting standards (the Personal Information Security Specification) suggest 15-30 days as customary practice, and refusals must state reasons and are court-challengeable under Article 50.

How does PIPL portability work?

Article 45(3): where conditions set by the CAC are met, individuals can request transfer of their personal information to a handler they designate, and the transferring handler must provide a channel. Implementation details arrived through 2024-2025 standards work; scope in practice remains narrower than GDPR Article 20.

When must data be deleted without a request?

Article 47 obliges proactive deletion when the purpose is achieved or no longer necessary, the retention period expires, the product or service stops operating, consent is withdrawn, or processing was unlawful. If deletion is technically hard, processing must stop except for storage and protection.

Can users opt out of personalized recommendations in China?

Yes, twice over: PIPL Article 24 requires marketing via automated decision-making to offer a non-personalized option or a convenient refusal, and the 2022 algorithmic recommendation regulations require apps to provide an off switch for recommendation algorithms. Chinese super-apps all ship this toggle.

Regulatory Crosswalk

GDPR Chapter IIIPIPL

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.