PIPL reads like a translation of GDPR until you try to operate under both. The skeleton matches: extraterritorial reach, lawful bases, data subject rights, impact assessments, breach notification, turnover-based fines. The joints bend differently in five places, and each one changes program design rather than just wording.
| Comparison | PIPL | GDPR |
|---|---|---|
| Effective | 1 November 2021 | 25 May 2018 |
| Max penalty | RMB 50M or 5% of turnover | EUR 20M or 4% of turnover |
| Legitimate interests | No | Yes |
| Transfers | CAC assessment / standard contract filing / certification | Adequacy / SCCs / BCRs |
| Official sources | CAC | EUR-Lex 32016R0679 |
The five differences that matter
1. No legitimate interests. PIPL Article 13’s bases are consent, contract/HR necessity, legal duties, emergencies, limited public-interest processing, and lawfully disclosed information. Everything a GDPR program parks under legitimate interests, ad measurement, enrichment, most analytics, needs consent in China.
2. Separate consent. Four operations require a standalone consent act, not a policy checkbox: handling sensitive personal information, providing data to another handler, public disclosure, and cross-border provision. This is the single most common PIPL gap in globally-templated consent flows.
3. Transfers as regulated events. GDPR exports run on self-executed SCCs and adequacy. PIPL requires a CAC security assessment above thresholds (CIIOs, important data, 1M+ individuals per year), or a CAC standard contract filed with the provincial regulator, or certification, each preceded by an impact assessment. The March 2024 facilitation rules carved out low-volume and contract-necessity exemptions but kept the architecture, detailed in the PIPL transfer guide.
4. Localization and state access. CIIOs and above-threshold handlers must store Chinese personal information domestically, exporting only after assessment. Article 41 blocks handing China-stored data to foreign courts or law enforcement without approval, which US-litigation-facing companies must reconcile with discovery obligations. GDPR mandates no localization.
5. Enforcement texture. Both regimes fine on turnover, but China adds rectification orders, app-store takedowns (a routine sanction for consent violations in mobile apps), suspension, and personal liability for responsible individuals. The CAC’s July 2022 Didi decision, RMB 8.026 billion plus RMB 1 million personal fines on the CEO and president, is the reference case.
Running both
Treat GDPR as the base program and add the China layer: consent-first basis mapping, standalone consent prompts for the four gated acts, a transfer mechanism with its filings, the China representative, and PIPL-specific rights handling. The PIPL roadmap sequences the build; a free scan shows what your site currently collects and transmits before any consent, the surface both regulators inspect first.