China’s Personal Information Protection Law (PIPL) comes into force today, completing a trio of data laws alongside the Cybersecurity Law and the Data Security Law.
Key points
- Applies extraterritorially to processing of personal information of people in China for providing products or services or analysing behaviour.
- Separate consent is required for sensitive data and cross-border transfers.
- Personal information protection impact assessments are required for high-risk processing.
- Breaches must be notified to regulators and individuals.
- Fines reach RMB 50 million or 5% of annual turnover.
UK organisations with Chinese customers or staff need to review transfer mechanisms, including standard contracts or certification. Overseas processors may need a representative in China.
Source: Personal Information Protection Law of the PRC (National People’s Congress)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.