Don’t do SECURITY. Do business SECURELY.

China’s Personal Information Protection Law comes into force

China’s PIPL introduces consent-based processing, strict transfer rules and extraterritorial reach for personal information of people in China.

China’s Personal Information Protection Law (PIPL) comes into force today, completing a trio of data laws alongside the Cybersecurity Law and the Data Security Law.

Key points

  • Applies extraterritorially to processing of personal information of people in China for providing products or services or analysing behaviour.
  • Separate consent is required for sensitive data and cross-border transfers.
  • Personal information protection impact assessments are required for high-risk processing.
  • Breaches must be notified to regulators and individuals.
  • Fines reach RMB 50 million or 5% of annual turnover.

UK organisations with Chinese customers or staff need to review transfer mechanisms, including standard contracts or certification. Overseas processors may need a representative in China.

Source: Personal Information Protection Law of the PRC (National People’s Congress)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with a link to our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights