🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
CN v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing19 sources retrieved model claude-sonnet-5 · 2026-08-03

Not every instrument is backed by its official text yet. At least one law or rulebook covered here has no official source (tier 1) retrieved for it yet. No finding on this page is shown with confidence above “Probable” until stronger sources are retrieved.

China

CN schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 46 claims · 33 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
46Claimsbaseline..claims[]
2Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 13 sub-modules are flagged red.

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

China's data protection and cybersecurity architecture underwent its most substantial revision since 2017 this cycle. The amended Cybersecurity Law, effective 1 January 2026, is reported to constitute the most substantial amendment to the CSL since its original 2017 adoption, and it broadens overseas-conduct enforcement beyond the law's former scope, which had been limited to conduct endangering critical information infrastructure. This extraterritorial-scope expansion is a genuinely new development this cycle rather than a restatement of the existing framework, and it means that overseas conduct not touching critical information infrastructure may now fall within the amended law's enforcement reach, a expansion with direct relevance for multinational entities whose China-related data-processing activity occurs partly or wholly outside mainland China.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A mature, enacted omnibus statute (PIPL) with implementing regulations and an active, multi-agency enforcement apparatus is in force.

Primary frameworkPersonal Information Protection Law (PIPL, 2021) together with the Cybersecurity Law (CSL, 2017/amended 2025) and Data Security Law (DSL, 2021)
Traffic-light rationale — GreenA mature, enacted omnibus statute (PIPL) with implementing regulations and an active, multi-agency enforcement apparatus is in force.

Sub-modules (5)

Regulator And AuthorityGreen

CAC is the lead/coordinating supervisory authority; MIIT, MPS, SAMR and financial regulators exercise delegated enforcement in their respective domains, unlike the single-authority models of GDPR/CPRA.

Claims (1):

  • The PIPL confers enforcement authority jointly on multiple governmental departments — CAC, MIIT, the Ministry of Public Security, SAMR and financial regulators, plus local counterparts — with CAC taking a leading and coordinating role rather than acting as a single unified supervisory authority as under GDPR or CPRA.

Act And InstrumentsGreen

The CSL/DSL/PIPL triad forms the statutory core, implemented via the Network Data Security Management Regulations (eff. 1 Jan 2025) and numerous CAC secondary rules.

Claims (1):

  • China's data governance framework rests on three national laws (CSL 2017/amended 2025, DSL 2021, PIPL 2021), implemented at national level via the Regulations on Network Data Security Management, effective 1 January 2025.

Material ScopeGreen

PIPL governs personal information handling activities undertaken by personal information handlers and entrusted parties (the processor-equivalent concept).

Claims (1):

  • PIPL is China's first comprehensive data protection legislation and regulates personal information handling activities by personal information handlers and entrusted parties.

Territorial ScopeGreen

Article 3 gives PIPL extraterritorial reach, analogous to GDPR Art 3(2), covering overseas handling aimed at providing products/services to, or analyzing/assessing the behavior of, individuals in China.

Claims (1):

  • PIPL Article 3 extends its territorial scope to the handling of personal information conducted outside China where the purpose is to provide products or services to, or to analyze/assess the behavior of, individuals located in China, or other purposes specified by law.

Regulator Registration And FilingAmber

Offshore handlers caught by Article 3 must establish a dedicated office or appoint a representative in China and report identifying details to the competent authority (Art 53).

Claims (1):

  • Offshore personal information handlers subject to PIPL under its extraterritorial provisions must establish a dedicated office or appoint a designated representative in China for personal information protection purposes (Art 53).
Category narrative97 words

China's data protection regime rests on three interlocking national laws — the Cybersecurity Law (CSL, 2017, amended 2025), the Data Security Law (DSL, 2021) and the Personal Information Protection Law (PIPL, 2021, in force 1 Nov 2021) — supplemented by the Network Data Security Management Regulations (effective 1 Jan 2025). The Cyberspace Administration of China (CAC) holds the lead coordinating role but enforcement authority is shared across MIIT, the Ministry of Public Security, SAMR, financial regulators and their local counterparts. Material scope covers 'personal information handlers' and 'entrusted parties' (processor-equivalent), and the regime has explicit extraterritorial reach.

Periodic update · new data 2026-09-28

Regulator & Framework

Enforcement authority in China's data-protection landscape remains distributed across the Cyberspace Administration of China, the Ministry of Public Security and the State Administration for Market Regulation, a standing structural feature rather than a new development this cycle. What is new is the amended Cybersecurity Law, effective 1 January 2026, which is reported to constitute the most substantial amendment to the CSL since its original 2017 adoption. The amendment's most consequential feature for the regulator-and-framework module is its broadening of overseas-conduct enforcement beyond the law's former scope, which had been limited to conduct endangering critical information infrastructure. This is a genuine territorial-scope expansion, not a restatement: overseas conduct that does not touch critical information infrastructure may now fall within the amended law's enforcement reach, a materially broader jurisdictional claim than the pre-amendment framework asserted.

This territorial expansion sits within a distributed-authority structure in which no single regulator holds exclusive enforcement power, meaning that the amended CSL's broadened scope will likely be operationalised through coordinated action across the three named bodies rather than through a single regulator's independent enforcement programme. The evidence base for the amendment's content and its territorial-scope implications derives from secondary legal-commentary sources rather than direct retrieval of the primary amended statutory text, a limitation that should be borne in mind when assessing the precision of the scope-expansion claim.

Outlook

Watch for primary-text confirmation of the amended CSL's exact territorial-scope language, which would allow more precise assessment of how far beyond critical-information-infrastructure conduct the new overseas-enforcement reach actually extends. Watch also for the first enforcement action under the amended law against an entity with no critical-information-infrastructure nexus, which would be the clearest practical test of the new scope.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (5)
  1. ProbableIAPP — The PIPL confers enforcement authority jointly on multiple governmental departments — CAC, MIIT, the Ministry of Public Security, SAMR and financial regulators, plus local counterparts — with CAC taking a leading and coordinating role rather than acting as a single unified supervisory authority as under GDPR or CPRA.observed
  2. ProbableIAPP — China's data governance framework rests on three national laws (CSL 2017/amended 2025, DSL 2021, PIPL 2021), implemented at national level via the Regulations on Network Data Security Management, effective 1 January 2025.observed
  3. ProbableOneTrust DataGuidance — PIPL is China's first comprehensive data protection legislation and regulates personal information handling activities by personal information handlers and entrusted parties.observed
  4. ProbableIAPP — PIPL Article 3 extends its territorial scope to the handling of personal information conducted outside China where the purpose is to provide products or services to, or to analyze/assess the behavior of, individuals located in China, or other purposes specified by law.observed
  5. ProbableIAPP — Offshore personal information handlers subject to PIPL under its extraterritorial provisions must establish a dedicated office or appoint a designated representative in China for personal information protection purposes (Art 53).observed

#

Lawful-basis and sensitive-data rules are enacted, detailed and actively enforced, though 'separate consent' remains only partially defined in official guidance.

Primary frameworkPIPL Chapter II, Arts 13–30; GB/T 35273 (Personal Information Security Specification, amendments proposed June 2026)
Traffic-light rationale — GreenLawful-basis and sensitive-data rules are enacted, detailed and actively enforced, though 'separate consent' remains only partially defined in official guidance.

Sub-modules (4)

Lawful BasesGreen

Article 13 lists non-consent lawful bases (contract performance/HR management, statutory duties, public-health emergencies, news reporting in the public interest, lawfully disclosed information); PIPL does not recognize a GDPR-style 'legitimate interests' basis.

Claims (1):

  • PIPL Article 13 permits processing without consent where necessary for contract performance or HR management under lawfully formulated labor policies, to perform legal responsibilities, to respond to public health emergencies, for public-interest news reporting, or for lawfully disclosed information; PIPL does not recognize 'legitimate interests' as a lawful basis, unlike GDPR.

Special CategoriesGreen

Article 28 defines sensitive personal information broadly — biometric identification, religious beliefs, specially-designated status, medical/health data, financial accounts, location/whereabouts data, and personal information of minors under 14 — a wider sweep than GDPR Art 9.

Claims (1):

  • PIPL Article 28 defines sensitive personal information to include biometric identification information, religious beliefs, specially-designated status, medical health information, financial accounts, information on individuals' whereabouts, and personal information of minors under the age of 14.

Pseudonymisation And AnonymisationGreen

Anonymized information (rendered permanently non-identifiable and non-restorable) falls outside PIPL's scope of 'personal information' (Arts 4 & 73); PIPL uses 'de-identification' as its pseudonymisation-equivalent concept.

Claims (1):

  • Anonymized information is not deemed personal information under PIPL; anonymization is defined (Arts 4 & 73) as processing that renders data non-identifying and non-restorable to a specific natural person, while 'de-identification' functions as PIPL's pseudonymisation-equivalent concept.
Category narrative90 words

PIPL Chapter II sets out non-consent lawful bases (contract performance, HR management, statutory duties, public health emergencies, news reporting, lawfully disclosed information) alongside consent; unlike GDPR, PIPL does not recognize 'legitimate interests'. Elevated 'separate consent' is required for sensitive categories, sharing, public disclosure and cross-border transfers. Sensitive personal information (Art 28) is broadly defined to include biometric data, religious beliefs, specially-designated status, health, financial accounts, location data and the personal information of minors under 14. Anonymized data is excluded from scope, and 'de-identification' (pseudonymisation) is recognized as a risk-mitigation concept.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (4)
  1. ProbableIAPP — PIPL Article 13 permits processing without consent where necessary for contract performance or HR management under lawfully formulated labor policies, to perform legal responsibilities, to respond to public health emergencies, for public-interest news reporting, or for lawfully disclosed information; PIPL does not recognize 'legitimate interests' as a lawful basis, unlike GDPR.observed
  2. ProbableIAPP — Consent under PIPL must be informed, freely given and evidenced by a clear affirmative action, with a standing right of withdrawal (Arts 14–15); a heightened 'separate consent' is additionally required when handlers share PI with other handlers, publicly disclose PI, process sensitive PI, or transfer PI abroad (Arts 23, 25, 29, 39).observed
  3. ProbableIAPP — PIPL Article 28 defines sensitive personal information to include biometric identification information, religious beliefs, specially-designated status, medical health information, financial accounts, information on individuals' whereabouts, and personal information of minors under the age of 14.observed
  4. ProbableIAPP — Anonymized information is not deemed personal information under PIPL; anonymization is defined (Arts 4 & 73) as processing that renders data non-identifying and non-restorable to a specific natural person, while 'de-identification' functions as PIPL's pseudonymisation-equivalent concept.observed

#

Substantive rights are enacted and broad, but the absence of a codified statutory response deadline creates residual ambiguity relative to GDPR-style regimes.

Primary frameworkPIPL Chapter IV, Arts 44–50
Traffic-light rationale — AmberSubstantive rights are enacted and broad, but the absence of a codified statutory response deadline creates residual ambiguity relative to GDPR-style regimes.

Sub-modules (5)

Access RightGreen

Individuals have the right to access and obtain copies of their personal information, which handlers must provide in a timely fashion.

Claims (1):

  • Under PIPL, individuals have the right to access and make copies of their personal information, and personal information handlers must provide such information in a timely fashion.

Rectification And ErasureGreen

Individuals may request correction, supplementation or updating of inaccurate/incomplete/outdated personal information, and may request deletion.

Claims (1):

  • Individuals are entitled to correct, supplement and update incomplete, inaccurate or outdated personal information and may request deletion of their personal information from handlers.

Restriction And ObjectionGreen

Individuals may demand an explanation of automated-decision-making use and may refute decisions made solely via automated means where those decisions significantly affect them.

Claims (1):

  • Data subjects have the right to request an explanation regarding the use of their personal information and to refute a decision made by a handler solely through automated decision-making where it significantly affects them.

Data PortabilityGreen

PIPL provides a portability right allowing individuals to request transfer of their personal information to another handler; PIPL goes further than GDPR by permitting legal claims against handlers who reject rights requests.

Claims (1):

  • PIPL provides a right of portability whereby individuals may request that a personal information handler transfer their personal information to another handler; PIPL exceeds GDPR by granting individuals a right to bring claims against handlers who reject a rights request and a right to demand an explanation of handling rules.

Deadlines And Response WindowsAmber

PIPL requires handlers to respond to access requests 'in a timely fashion' but does not set a fixed statutory day-count deadline analogous to GDPR's one-month rule; no secondary source located specifying a harmonized numeric window across all right types.

Claims (1):

  • PIPL requires personal information handlers to respond to access requests 'in a timely fashion' rather than specifying a codified numeric response deadline equivalent to GDPR's one-month rule.
Category narrative86 words

PIPL Chapter IV grants a GDPR-adjacent rights bundle: access/copy, rectification, erasure, restriction/objection (including a right to demand explanation of and refute automated decisions), and a portability right that in some respects exceeds GDPR by allowing individuals to sue handlers who refuse rights requests and by extending exercise of rights to close relatives of deceased individuals. However, PIPL does not codify a fixed numeric response-deadline analogous to GDPR's one-month rule; the statute only requires handlers to respond 'in a timely fashion,' leaving specific windows to sectoral/CAC guidance.

Sources and claims (5)
  1. ProbableIAPP — Under PIPL, individuals have the right to access and make copies of their personal information, and personal information handlers must provide such information in a timely fashion.observed
  2. ProbableIAPP — Individuals are entitled to correct, supplement and update incomplete, inaccurate or outdated personal information and may request deletion of their personal information from handlers.observed
  3. ProbableIAPP — Data subjects have the right to request an explanation regarding the use of their personal information and to refute a decision made by a handler solely through automated decision-making where it significantly affects them.observed
  4. ProbableIAPP — PIPL provides a right of portability whereby individuals may request that a personal information handler transfer their personal information to another handler; PIPL exceeds GDPR by granting individuals a right to bring claims against handlers who reject a rights request and a right to demand an explanation of handling rules.observed
  5. UncertainIAPP — PIPL requires personal information handlers to respond to access requests 'in a timely fashion' rather than specifying a codified numeric response deadline equivalent to GDPR's one-month rule.observed

#

Core accountability, DPIA, security and breach-notification duties are enacted and enforced, but the PIPO appointment threshold and processor ('entrusted party') definitions remain under-specified in binding text.

Primary frameworkPIPL Chapter V (Arts 51–59); Regulations on Network Data Security Management (eff. 1 Jan 2025)
Traffic-light rationale — AmberCore accountability, DPIA, security and breach-notification duties are enacted and enforced, but the PIPO appointment threshold and processor ('entrusted party') definitions remain under-specified in binding text.

Sub-modules (7)

Accountability And DpiaAmber

PIPL lacks an express GDPR-style accountability principle but requires handlers to accept responsibility for their processing and adopt necessary safeguards; DPIAs (Art 55) are mandatory for sensitive-data processing, ADM, entrusting/sharing/disclosing PI, cross-border transfer, and other major-impact processing.

Claims (1):

  • Under PIPL Article 55, a personal information handler must conduct a personal information protection impact assessment prior to handling sensitive personal information, using personal information for automated decision-making, entrusting/sharing/disclosing personal information, transferring personal information abroad, or engaging in other processing with a major influence on individuals; the assessment must evaluate lawfulness/necessity, impact on individuals' rights, and adequacy of protective measures.

Dpo RequirementsAmber

PIPL requires appointment of a Personal Information Protection Officer (PIPO) above an as-yet-undefined processing-volume threshold; industry guidance points to organizations processing hundreds of thousands to millions of individuals' data.

Claims (1):

  • PIPL requires certain handlers to appoint a Personal Information Protection Officer (PIPO), but the precise processing-volume threshold triggering this requirement is not specified in the statute; analogous CAC draft measures reference thresholds around one million individuals' data.

Ropa RequirementsAmber

Unlike GDPR's blanket Art 30 requirement, PIPL imposes record-keeping only for the DPIA-triggering categories, with processing records and assessment reports retained for at least three years (Art 55).

Claims (1):

  • Unlike GDPR's universal Article 30 record-keeping duty applicable to controllers and processors alike, PIPL imposes record-of-processing obligations on handlers only for the categories triggering a DPIA, and requires retention of impact-assessment processing records for at least three years (Art 55).

Joint Controller ArrangementsAmber

PIPL does not define 'entrusted parties' as precisely as GDPR defines processors, but imposes obligations on them, including a duty to notify and assist the handler in the event of a breach affecting entrusted data.

Claims (1):

  • PIPL does not define 'entrusted parties' (the processor-equivalent role) as precisely as GDPR defines data processors, though it imposes obligations on such parties, including a duty to notify the handler and provide technical/administrative assistance in the event of a breach involving entrusted personal information.

Security MeasuresGreen

Handlers must adopt organizational and technical measures — internal management rules, PI classification, encryption/de-identification, access controls, periodic staff training, and incident-response mechanisms.

Claims (1):

  • PIPL requires handlers to adopt organizational and technical measures to prevent unauthorized access, damage, leakage or loss of personal information, including internal management mechanisms, classification of personal information, encryption and de-identification, access controls, and periodic security training.

Breach NotificationGreen

Article 57 requires handlers, on any actual or possible leak, distortion or loss of PI, to take remedial measures and notify regulators and affected individuals of incident categories, causes, possible harm, remedial steps and contact details, unless harm is effectively avoided.

Claims (1):

  • Under PIPL Article 57, whenever a leak, distortion or loss of personal information occurs or might have occurred, handlers must adopt remedial measures and notify relevant departments and affected individuals of the information categories, causes and possible harm, the remedial measures taken and steps individuals can take to mitigate harm, and a method of contact; notification to individuals is excused where the handler adopts measures effectively avoiding harm.

Retention And DisposalGreen

The 2025 Network Data Security Management Regulations require companies processing personal data of more than 10 million individuals to submit a data disposal plan to regulators in the event of a merger, acquisition, spin-off or insolvency affecting data security.

Claims (1):

  • The Regulations on Network Data Security Management require a company processing personal data of more than 10 million individuals to establish a dedicated department and appoint a senior data-security executive, and to submit a data disposal plan to regulators upon a merger, acquisition, spin-off or insolvency affecting data security.
Category narrative100 words

PIPL Chapter V imposes DPIA obligations (Arts 55–56) triggered by sensitive-data processing, automated decision-making, entrusting/sharing/public disclosure of PI, cross-border transfers, and other 'major-impact' processing; a Personal Information Protection Officer (PIPO) requirement exists but the numeric threshold remains undefined in the statute itself. Record-keeping obligations are narrower than GDPR's blanket Art 30 ROPA, applying mainly to the DPIA-triggering categories, with 3-year minimum retention of assessment records. Breach notification (Art 57) requires remedial action plus notice to regulators and affected individuals unless harm is effectively neutralized. The 2025 Network Data Security Management Regulations add data-disposal-plan obligations for very-large-scale processors upon M&A/insolvency events.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (7)
  1. ProbableIAPP — Under PIPL Article 55, a personal information handler must conduct a personal information protection impact assessment prior to handling sensitive personal information, using personal information for automated decision-making, entrusting/sharing/disclosing personal information, transferring personal information abroad, or engaging in other processing with a major influence on individuals; the assessment must evaluate lawfulness/necessity, impact on individuals' rights, and adequacy of protective measures.observed
  2. ProbableIAPP — PIPL requires certain handlers to appoint a Personal Information Protection Officer (PIPO), but the precise processing-volume threshold triggering this requirement is not specified in the statute; analogous CAC draft measures reference thresholds around one million individuals' data.observed
  3. ProbableOneTrust DataGuidance — Unlike GDPR's universal Article 30 record-keeping duty applicable to controllers and processors alike, PIPL imposes record-of-processing obligations on handlers only for the categories triggering a DPIA, and requires retention of impact-assessment processing records for at least three years (Art 55).observed
  4. ProbableOneTrust DataGuidance — PIPL does not define 'entrusted parties' (the processor-equivalent role) as precisely as GDPR defines data processors, though it imposes obligations on such parties, including a duty to notify the handler and provide technical/administrative assistance in the event of a breach involving entrusted personal information.observed
  5. ProbableIAPP — PIPL requires handlers to adopt organizational and technical measures to prevent unauthorized access, damage, leakage or loss of personal information, including internal management mechanisms, classification of personal information, encryption and de-identification, access controls, and periodic security training.observed
  6. ProbableIAPP — Under PIPL Article 57, whenever a leak, distortion or loss of personal information occurs or might have occurred, handlers must adopt remedial measures and notify relevant departments and affected individuals of the information categories, causes and possible harm, the remedial measures taken and steps individuals can take to mitigate harm, and a method of contact; notification to individuals is excused where the handler adopts measures effectively avoiding harm.observed
  7. ProbableIAPP — The Regulations on Network Data Security Management require a company processing personal data of more than 10 million individuals to establish a dedicated department and appoint a senior data-security executive, and to submit a data disposal plan to regulators upon a merger, acquisition, spin-off or insolvency affecting data security.observed

#

Transfer mechanisms are well-established and increasingly detailed, but thresholds have shifted multiple times since 2022 and important-data classification remains only partially settled, creating ongoing compliance uncertainty.

Primary frameworkPIPL Chapter III (Arts 38–43); Measures for Security Assessment of Outbound Data Transfers (2022); Chinese SCC Provisions (2023); Provisions on Promoting and Regulating Cross-Border Data Flows (2024)
Traffic-light rationale — AmberTransfer mechanisms are well-established and increasingly detailed, but thresholds have shifted multiple times since 2022 and important-data classification remains only partially settled, creating ongoing compliance uncertainty.

Sub-modules (6)

Transfer MechanismsAmber

Article 38 provides three transfer mechanisms: CAC-led security assessment (for CIIOs/large-volume processors), CAC-authorized certification, and the Chinese standard contract.

Claims (1):

  • PIPL Article 38 offers three cross-border data transfer mechanisms depending on the characteristics of the exporting entity: a CAC-led security assessment (mandatory for CIIOs and large-volume processors), a PI-protection certification issued by CAC-authorized professional institutions, or a standard-contract agreement with the overseas recipient based on CAC-issued clauses.

Adequacy ReceivedRed

PIPL does not provide a mechanism for cross-border transfers premised on adequacy decisions from other jurisdictions, in contrast with GDPR Art 45.

Claims (1):

  • Unlike GDPR, PIPL does not provide for cross-border transfers of personal information premised on a finding of 'adequate protection' in the recipient jurisdiction; all outbound transfers must instead satisfy one of PIPL's three domestic transfer mechanisms.

Adequacy GrantedRed

No evidence was found of China issuing formal 'adequacy' determinations toward other jurisdictions; its transfer regime is structured around security assessment, SCC and certification rather than a unilateral-adequacy concept.

Sccs And BcrsAmber

The Chinese SCCs (effective 1 June 2023) require Chinese law as the governing law, use a single universal contract template regardless of controller/processor role, and must be filed with the provincial CAC within 10 working days of effectiveness together with the impact assessment report.

Claims (1):

  • The Chinese Standard Contractual Clauses, effective 1 June 2023, require the cross-border data transfer agreement to be governed by Chinese law, use a single universal template regardless of the parties' controller/processor role, and be filed with the provincial CAC together with the impact assessment report within 10 working days of effectiveness.

Transfer Impact AssessmentAmber

SCC-based (and security-assessment-based) transfers require an accompanying impact assessment report; the assessment must be redone and re-filed with the provincial CAC upon material changes such as extended retention, altered purpose/scope/volume/sensitivity, or changes in the destination country's data protection laws.

Claims (1):

  • Parties to an SCC-based cross-border transfer must redo the impact assessment, update the transfer agreement, and re-file with the provincial CAC where circumstances materially change, including extension of retention period, changes in processing purpose/scope/category/volume/storage location/sensitivity, or changes in the destination country's data protection laws affecting data subjects.

Data LocalisationAmber

CIIOs and processors handling large volumes of personal information must store personal information locally in China, with overseas transfer conditioned on passing a CAC security assessment (Art 40); the March 2024 CBDT relaxations raised numeric thresholds and exempted several transfer scenarios (e.g., employee data) from any CBDT mechanism.

Claims (1):

  • CIIOs and entities processing large volumes of personal information must store citizens' personal information and important data locally in China, with overseas transfer conditioned on passing a CAC-led security assessment; the March 2024 CBDT Provisions relaxed thresholds so that non-CIIO handlers transferring between 100,000 and 1,000,000 individuals' data (or under 10,000 individuals' sensitive data) may use SCC/certification rather than a full security assessment, and exempted employee-data transfers from any CBDT mechanism regardless of volume where employment-law conditions are met.
Category narrative98 words

PIPL Article 38 offers three cross-border transfer mechanisms — CAC-led security assessment, PI-protection certification, or a CAC-standard-contract (Chinese SCC, effective 1 June 2023) — with applicability determined by processing volume/sensitivity thresholds progressively relaxed by the March 2024 CBDT Provisions and further eased by the 2025 Network Data Security Regulations (e.g., blanket exemption for employee-data transfers). PIPL does not recognize inbound adequacy decisions from other regimes, and no evidence was found of China granting outbound 'adequacy' status to other jurisdictions; its regime instead relies on bilateral security assessment/SCC/certification. CIIOs and large-volume processors remain subject to mandatory data localisation domestically.

Periodic update · new data 2026-09-28

Cross-Border & Adequacy

China's cross-border personal information transfer framework reached structural completion this cycle. The Measures for Certification of Cross-Border Personal Information Transfer, effective 1 January 2026, complete the three-pathway framework under PIPL: security assessment, standard contract, and certification. This is a confirmed, materially significant development: prior to this measure, the certification pathway existed in name but lacked the operational detail now supplied, and the framework's completion gives data controllers a genuine choice among three distinct compliance routes rather than a binary choice between the two previously-operational pathways.

From the same 1 January 2026 effective date, data controllers otherwise required to use China's Standard Contractual Clauses now have the option of obtaining certification instead, introducing a new compliance-pathway optionality that did not previously exist in practice. This is probably significant for multinational data controllers who had defaulted to the Standard Contractual Clauses route in the absence of an operational certification alternative, and who may now find certification a more suitable pathway depending on their specific transfer profile and volume.

A further requirement reported this cycle, though on weaker single-source evidence, holds that every PIPL cross-border transfer requires a current Personal Information Protection Impact Assessment on file. This claim rests on uncorroborated secondary compliance guidance rather than independently verified primary-source confirmation, so it should be read as an unconfirmed compliance expectation rather than a settled requirement pending further verification. Separately, the precise current volume thresholds distinguishing which of the three pathways applies to a given transfer were reported inconsistently across secondary sources this cycle and were not verified against the primary Cyberspace Administration of China measures text directly, a gap that limits the precision with which controllers can currently map their own transfer volumes to the correct compliance pathway.

Outlook

Watch for primary-source verification of the current cross-border transfer volume thresholds governing pathway selection, and for whether the reported PIPIA-for-every-transfer requirement is corroborated by additional independent sourcing or clarified as a narrower requirement applying only to certain transfer categories. The completion of the three-pathway framework itself is not expected to change further in the near term absent a fresh regulatory intervention.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (5)
  1. ProbableIAPP — PIPL Article 38 offers three cross-border data transfer mechanisms depending on the characteristics of the exporting entity: a CAC-led security assessment (mandatory for CIIOs and large-volume processors), a PI-protection certification issued by CAC-authorized professional institutions, or a standard-contract agreement with the overseas recipient based on CAC-issued clauses.observed
  2. ProbableOneTrust DataGuidance — Unlike GDPR, PIPL does not provide for cross-border transfers of personal information premised on a finding of 'adequate protection' in the recipient jurisdiction; all outbound transfers must instead satisfy one of PIPL's three domestic transfer mechanisms.observed
  3. ProbableIAPP — The Chinese Standard Contractual Clauses, effective 1 June 2023, require the cross-border data transfer agreement to be governed by Chinese law, use a single universal template regardless of the parties' controller/processor role, and be filed with the provincial CAC together with the impact assessment report within 10 working days of effectiveness.observed
  4. ProbableIAPP — Parties to an SCC-based cross-border transfer must redo the impact assessment, update the transfer agreement, and re-file with the provincial CAC where circumstances materially change, including extension of retention period, changes in processing purpose/scope/category/volume/storage location/sensitivity, or changes in the destination country's data protection laws affecting data subjects.observed
  5. ProbableIAPP — CIIOs and entities processing large volumes of personal information must store citizens' personal information and important data locally in China, with overseas transfer conditioned on passing a CAC-led security assessment; the March 2024 CBDT Provisions relaxed thresholds so that non-CIIO handlers transferring between 100,000 and 1,000,000 individuals' data (or under 10,000 individuals' sensitive data) may use SCC/certification rather than a full security assessment, and exempted employee-data transfers from any CBDT mechanism regardless of volume where employment-law conditions are met.observed

#

Financial-sector and employment-data overlays are documented, but health, education and insurance sector-specific DP overlays were not located in this pass and are flagged as a research gap.

Traffic-light rationale — AmberFinancial-sector and employment-data overlays are documented, but health, education and insurance sector-specific DP overlays were not located in this pass and are flagged as a research gap.

Sub-modules (7)

Financial Sector OverlayAmber

PBOC's Financial Data Security — Data Security Classification Guidelines (2020) impose sector-specific classification duties, and the amended Anti-Money Laundering Law (effective 1 Jan 2025) requires financial institutions to protect KYC/AML data confidentiality consistent with CSL/DSL/PIPL and to report before cross-border KYC/transaction-record disclosures to foreign authorities.

Claims (1):

  • The People's Bank of China issued the Financial Data Security — Data Security Classification Guidelines establishing sector-specific data classification obligations for financial institutions, and the amended Anti-Money Laundering Law (effective 1 Jan 2025) requires financial institutions to protect the confidentiality of collected KYC/AML information consistent with CSL/DSL/PIPL and to report to the competent Chinese financial regulator before disclosing customers' KYC information or transactional records to foreign authorities.

Health Sector OverlayRed

No dedicated health-sector data protection statute distinct from PIPL's general treatment of 'medical health information' as sensitive personal information was identified.

Telecoms And EprivacyAmber

China lacks a discrete ePrivacy-style instrument; illustrative enforcement includes MIIT's 2021 sweep ordering WeChat, Tencent and other apps to rectify illegal transfer of contact-list and location data and pop-up harassment practices.

Claims (1):

  • MIIT found that a batch of applications, including WeChat and other Tencent products, illegally transferred users' contact-list and location data and used pop-up harassment, ordering their parent companies to make rectifications.

Employment DataGreen

Under the CBDT relaxations, employee-data transfers are exempt from all CBDT legal mechanisms irrespective of volume, provided underlying Chinese employment-law conditions (e.g., democratically consulted employee handbooks) are met.

Claims (1):

  • Under the CBDT regulations, employee data transfers are exempt from any of the CBDT legal mechanisms irrespective of data volume, provided companies meet relevant Chinese employment-law conditions extending beyond data protection rules (e.g., a democratically consulted employee handbook).

Credit And ScoringAmber

PIPL Article 67 allows violations to be recorded into a handler's 'credit files' under China's national social credit system, layering credit-scoring consequences onto ordinary administrative penalties.

Claims (1):

  • PIPL Article 67 provides that violations may be recorded into the 'credit files' of the processing entity under China's national social credit system, in addition to monetary penalties.

EducationRed

No education-sector-specific data protection overlay was identified in this research pass.

InsuranceAmber

Insurance-sector data processing falls within the general financial-regulator enforcement lane under PIPL Arts 60/63; no insurance-specific data rule distinct from the general financial-sector overlay was located.

Claims (1):

  • PIPL Article 60 designates financial regulators (which encompass insurance-sector oversight) among the sectoral supervisory authorities empowered to enforce PIPL within their respective designated areas.
Category narrative107 words

Financial-sector data is subject to PBOC-issued classification guidelines (Financial Data Security — Data Security Classification Guidelines, 2020) and the amended Anti-Money Laundering Law (effective 1 Jan 2025), which requires KYC/AML information to be handled consistently with CSL/DSL/PIPL and imposes reporting obligations before cross-border KYC disclosures to foreign authorities. Employment data benefits from a specific CBDT exemption. Violations feed into China's national social-credit 'credit files' system (Art 67), giving credit-scoring consequences a cross-cutting role. No dedicated health-sector, education-sector or insurance-specific data protection overlay statute was identified in this research pass beyond PIPL's general 'medical health information' sensitive-category treatment and the shared multi-regulator enforcement structure under PIPL Arts 60/63.

Sources and claims (5)
  1. ProbableIAPP — The People's Bank of China issued the Financial Data Security — Data Security Classification Guidelines establishing sector-specific data classification obligations for financial institutions, and the amended Anti-Money Laundering Law (effective 1 Jan 2025) requires financial institutions to protect the confidentiality of collected KYC/AML information consistent with CSL/DSL/PIPL and to report to the competent Chinese financial regulator before disclosing customers' KYC information or transactional records to foreign authorities.observed
  2. ProbableIAPP — MIIT found that a batch of applications, including WeChat and other Tencent products, illegally transferred users' contact-list and location data and used pop-up harassment, ordering their parent companies to make rectifications.observed
  3. ProbableIAPP — Under the CBDT regulations, employee data transfers are exempt from any of the CBDT legal mechanisms irrespective of data volume, provided companies meet relevant Chinese employment-law conditions extending beyond data protection rules (e.g., a democratically consulted employee handbook).observed
  4. ProbableIAPP — PIPL Article 67 provides that violations may be recorded into the 'credit files' of the processing entity under China's national social credit system, in addition to monetary penalties.observed
  5. ProbableIAPP — PIPL Article 60 designates financial regulators (which encompass insurance-sector oversight) among the sectoral supervisory authorities empowered to enforce PIPL within their respective designated areas.observed

#

Algorithm-transparency and anti-price-discrimination rules are enacted and enforced, but cookie-consent, opt-out-signal and clean-room-specific regimes are absent from China's framework.

Primary frameworkProvisions on the Management of Algorithmic Recommendations in Internet Information Services (2022); PIPL Art 24
Traffic-light rationale — AmberAlgorithm-transparency and anti-price-discrimination rules are enacted and enforced, but cookie-consent, opt-out-signal and clean-room-specific regimes are absent from China's framework.

Sub-modules (6)

Cookies And TrackersRed

No standalone ePrivacy-equivalent cookie/tracker consent statute was identified for China; tracking technologies are governed generally through PIPL's consent framework rather than a dedicated cookie law.

Dark PatternsAmber

Joint CAC/MIIT/MPS/SAMR enforcement campaigns have targeted apps for harassing pop-up windows and illegal collection of contact-list/location data, functioning as de facto anti-dark-pattern enforcement absent a codified prohibition.

Claims (1):

  • MIIT, CAC, MPS and SAMR jointly conducted enforcement campaigns (2020–2021) against apps engaging in illegal collection and use of personal information and harassing pop-up notifications, functioning as enforcement against dark-pattern-style practices absent a codified statutory prohibition.

Opt Out SignalsRed

No Global Privacy Control or DAA-equivalent standardized opt-out signal mechanism was identified in China's regulatory framework.

Clean Rooms And DcrRed

No data-clean-room or data-collaboration-room-specific regulatory regime was identified for China in this research pass.

Cross Context AdvertisingAmber

The 2022 Provisions on the Management of Algorithmic Recommendations regulate algorithms used for content recommendation and targeted advertising, requiring transparency and fairness and prohibiting practices that disrupt public order.

Claims (1):

  • The Provisions on the Management of Algorithmic Recommendations in Internet Information Services (effective 1 March 2022) regulate algorithms used for content recommendation, requiring transparency and fairness and prohibiting practices that disrupt public order, including personalized price discrimination.

Direct MarketingGreen

PIPL Article 24 requires that where handlers use automated decision-making for business marketing or push notifications, they must simultaneously offer options not targeting an individual's personal characteristics, or provide a simple means of rejection.

Claims (1):

  • PIPL requires that personal information processors conducting business marketing to individuals through automated decision-making simultaneously provide options that do not target an individual's personal characteristics, or offer ways for individuals to reject such marketing.
Category narrative65 words

China lacks a discrete ePrivacy-style cookie-consent statute; commercial-privacy governance instead runs through PIPL's ADM/marketing rule (Art 24) and the CAC's 2022 Provisions on Algorithmic Recommendations, which mandate algorithm transparency/fairness and prohibit practices disrupting public order, including personalized price discrimination. Dark-pattern-style practices (e.g., harassing pop-ups, undisclosed data collection) have been targeted by joint MIIT/SAMR/CAC/MPS enforcement sweeps. No Global-Privacy-Control-equivalent opt-out signal or dedicated clean-room/data-collaboration-room regime was identified.

Sources and claims (3)
  1. ProbableIAPP — MIIT, CAC, MPS and SAMR jointly conducted enforcement campaigns (2020–2021) against apps engaging in illegal collection and use of personal information and harassing pop-up notifications, functioning as enforcement against dark-pattern-style practices absent a codified statutory prohibition.observed
  2. ProbableCyberspace Administration of China — The Provisions on the Management of Algorithmic Recommendations in Internet Information Services (effective 1 March 2022) regulate algorithms used for content recommendation, requiring transparency and fairness and prohibiting practices that disrupt public order, including personalized price discrimination.observed
  3. ProbableIAPP — PIPL requires that personal information processors conducting business marketing to individuals through automated decision-making simultaneously provide options that do not target an individual's personal characteristics, or offer ways for individuals to reject such marketing.observed

#

AI- and biometric-specific rules are extensive and rapidly evolving (including a 2025 CSL amendment), but genetic-data specificity is absent and state-surveillance carve-outs remain structurally unconstrained by PIPL's private-sector-facing rules.

Primary frameworkPIPL Art 24; Provisions on Algorithmic Recommendations (2022); Provisions on Deep Synthesis (2023); Interim Measures for Generative AI Services (2023); amended Cybersecurity Law (2025)
Traffic-light rationale — AmberAI- and biometric-specific rules are extensive and rapidly evolving (including a 2025 CSL amendment), but genetic-data specificity is absent and state-surveillance carve-outs remain structurally unconstrained by PIPL's private-sector-facing rules.

Sub-modules (6)

Profiling RestrictionsAmber

PIPL Article 24 prohibits unreasonable differential treatment via automated decision-making (e.g., algorithmic price discrimination) and requires non-targeted or opt-out marketing options.

Claims (1):

  • PIPL Article 24 requires personal information processors engaging in automated-decision-making-based marketing to provide non-targeted options or simple rejection mechanisms, addressing algorithmic price discrimination and profiling-driven differential treatment.

Automated Decision Making TransparencyGreen

Individuals may request an explanation of automated-decision-making use and challenge decisions made solely by automated means where those decisions significantly affect them.

Claims (1):

  • Data subjects have the right to request an explanation regarding the use of personal information in automated decision-making and to refute a decision made solely by automated means where it significantly affects them.

Ai Risk AssessmentsAmber

The amended Cybersecurity Law (passed October 2025) brings AI governance within CSL's scope and raises maximum penalties; the 2023 Interim Measures for Generative AI Services separately require security assessments for generative AI services with 'public opinion attributes.'

Claims (1):

  • China's amended Cybersecurity Law, passed in October 2025, brings artificial intelligence governance within the CSL's scope and raises the maximum fine for companies to CNY50 million or 5% of the previous year's turnover, with individual penalties up to CNY1 million.

Biometric RegimeAmber

Biometric identification information is classified as sensitive personal information under PIPL Art 28, requiring separate consent, and is further governed by CAC measures on the security of facial recognition technology.

Claims (1):

  • PIPL Article 28 classifies biometric identification information as sensitive personal information requiring separate consent for processing, and CAC has issued dedicated measures governing the security of facial recognition technology deployment.

Genetic DataRed

No standalone genetic-data regime distinct from PIPL's general 'medical health information' sensitive-category treatment was identified in this research pass.

State Surveillance CarveoutsRed

PIPL's consumer-facing protections do not constrain the PRC central government's own data access; independent legal commentary observed little indication of legal limits on state surveillance activity notwithstanding PIPL's commercial-sector rules.

Claims (1):

  • PIPL's private-sector-facing protections do not prevent the PRC central government from accessing data, and legal commentators have observed little indication of legal limits on government surveillance or meaningful civil-society oversight mechanisms in this area.
Category narrative153 words

PIPL Article 24 restricts algorithmic price-discrimination and mandates non-targeted or opt-out marketing options; individuals may demand explanations of and refute significant automated decisions. China layers AI-specific instruments atop this base — the 2022 Algorithmic Recommendation Provisions, the 2023 Deep Synthesis Provisions, and the 2023 Interim Measures for Generative AI Services (security assessments for public-opinion-attribute services) — and the amended Cybersecurity Law (passed October 2025) newly brings AI governance within CSL's scope while raising maximum penalties to CNY50 million/5% of turnover for companies and CNY1 million for individuals. Biometric data (including facial recognition) is treated as sensitive personal information requiring separate consent, reinforced by CAC facial-recognition security measures. Genetic data is not called out as a standalone category distinct from 'medical health information.' State-surveillance carve-outs are structurally significant: PIPL's consumer-facing protections do not extend to constrain central-government data access, and independent legal commentary has noted the absence of clear legal limits on government surveillance.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. ProbableIAPP — PIPL Article 24 requires personal information processors engaging in automated-decision-making-based marketing to provide non-targeted options or simple rejection mechanisms, addressing algorithmic price discrimination and profiling-driven differential treatment.observed
  2. ProbableIAPP — Data subjects have the right to request an explanation regarding the use of personal information in automated decision-making and to refute a decision made solely by automated means where it significantly affects them.observed
  3. ProbableIAPP — China's amended Cybersecurity Law, passed in October 2025, brings artificial intelligence governance within the CSL's scope and raises the maximum fine for companies to CNY50 million or 5% of the previous year's turnover, with individual penalties up to CNY1 million.observed
  4. ProbableOneTrust DataGuidance — PIPL Article 28 classifies biometric identification information as sensitive personal information requiring separate consent for processing, and CAC has issued dedicated measures governing the security of facial recognition technology deployment.observed
  5. ProbableIAPP — PIPL's private-sector-facing protections do not prevent the PRC central government from accessing data, and legal commentators have observed little indication of legal limits on government surveillance or meaningful civil-society oversight mechanisms in this area.observed

#

Minors' data receives clear sensitive-category and parental-consent treatment with active 2025-2026 filing enforcement, but dependent-adult protections and minor-specific profiling bans were not located in this research pass.

Primary frameworkProvisions on Cyber Protection of Children's Personal Information (2019); PIPL Art 28
Traffic-light rationale — AmberMinors' data receives clear sensitive-category and parental-consent treatment with active 2025-2026 filing enforcement, but dependent-adult protections and minor-specific profiling bans were not located in this research pass.

Sub-modules (5)

Age VerificationAmber

The operative age threshold for heightened protection is 14 years; the December 2025 CAC directive requires filings on the nature, categories and volume of minors' personal information collected, implying an age-identification/verification compliance step, though no standalone age-verification technical mandate was located.

Claims (1):

  • PIPL classifies the personal information of minors under the age of 14 as sensitive personal information, and CAC's 2019 Provisions on Cyber Protection of Children's Personal Information (China's COPPA-equivalent) requires parental/guardian consent for handling children's data; a CAC directive issued 28 December 2025 further requires companies collecting minors' personal information to complete compliance audits and file supporting materials with local CAC offices by 31 January 2026.

Minor Profiling BansRed

No standalone algorithmic-profiling ban specific to minors, distinct from PIPL's general ADM transparency/opt-out rules, was identified in this research pass.

Education SettingsRed

No education-setting-specific children's data protection rule was identified in this research pass.

Dependent AdultsRed

PIPL allows close relatives to exercise a deceased individual's data protection rights, but no dedicated regime for living dependent adults (elderly or mentally incapacitated persons) was identified.

Claims (1):

  • PIPL permits close relatives of a deceased individual to exercise that individual's data protection rights, but no equivalent statutory protection specific to living dependent adults (e.g., elderly or mentally incapacitated persons) was identified.
Category narrative96 words

PIPL treats the personal information of minors under 14 as sensitive personal information, requiring parental/guardian consent, building on the standalone 2019 Provisions on Cyber Protection of Children's Personal Information (China's COPPA-equivalent). A December 2025 CAC directive newly requires companies collecting minors' personal information to complete compliance audits and file materials (data categories/volume, impact assessment, signed undertaking letter) with local CAC offices by 31 January 2026, signaling heightened 2026 enforcement focus. No standalone minor-specific profiling ban, education-setting-specific rule, or dependent-adult (elderly/incapacitated) regime was identified beyond PIPL's general provision allowing close relatives to exercise a deceased individual's rights.

Sources and claims (2)
  1. ProbableIAPP — PIPL classifies the personal information of minors under the age of 14 as sensitive personal information, and CAC's 2019 Provisions on Cyber Protection of Children's Personal Information (China's COPPA-equivalent) requires parental/guardian consent for handling children's data; a CAC directive issued 28 December 2025 further requires companies collecting minors' personal information to complete compliance audits and file supporting materials with local CAC offices by 31 January 2026.observed
  2. UncertainOneTrust DataGuidance — PIPL permits close relatives of a deceased individual to exercise that individual's data protection rights, but no equivalent statutory protection specific to living dependent adults (e.g., elderly or mentally incapacitated persons) was identified.observed

#

China maintains an active, multi-agency enforcement apparatus with substantial recent fines, an evolving penalty ceiling (raised again via the 2025 CSL amendment), and continuous rulemaking activity through mid-2026.

Primary frameworkPIPL Chapter VII (Arts 60–71); amended Cybersecurity Law (2025)
Traffic-light rationale — GreenChina maintains an active, multi-agency enforcement apparatus with substantial recent fines, an evolving penalty ceiling (raised again via the 2025 CSL amendment), and continuous rulemaking activity through mid-2026.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

Article 63 grants broad investigatory powers; a two-tier (general/grave) administrative penalty structure applies, with grave violations reaching RMB50 million or 5% of prior-year turnover plus business-suspension/license-revocation powers.

Claims (1):

  • PIPL Article 63 grants supervisory authorities investigatory powers including interviews, document review, on-site inspections, and equipment seizure/confiscation; the law creates a two-tier penalty structure with general violations fined up to RMB1 million for handlers and RMB100,000 for responsible officers, and grave violations fined up to RMB50 million or 5% of the previous year's annual revenue for handlers and RMB100,000–1 million for officers, alongside rectification orders, business suspension, and license revocation powers.

Enforcement Activity IndexGreen

Landmark fines include RMB8.026 billion against Didi Global (2022) for CSL/DSL/PIPL violations and RMB50 million against academic database provider CNKI (2023) for PIPL/CSL violations.

Claims (1):

  • CAC fined Didi Global approximately RMB8.026 billion in 2022 for violations of the CSL, DSL and PIPL, and separately fined academic database provider CNKI RMB50 million for PIPL and CSL violations in 2023, illustrating sustained large-scale enforcement activity.

Regulator Funding And CapacityRed

No specific data on CAC budget or headcount was located in this research pass.

Collective Redress And Class ActionsGreen

Article 70 grants standing for public-interest actions (China's equivalent of class actions) to the People's Procuratorate, statutorily designated consumer organizations, and CAC-designated organizations.

Claims (1):

  • PIPL Article 70 grants standing to file public-interest actions — China's functional equivalent of class actions — to the People's Procuratorate, statutorily designated consumer organizations, and organizations designated by CAC, where a handler's infringement affects a large number of individuals.

Private Right Of ActionGreen

PIPL Article 69 shifts the burden of proof to the defendant handler once an individual demonstrates an infringement, and courts may calculate damages by reference to the handler's gains rather than only the individual's actual losses.

Claims (1):

  • PIPL Article 69 shifts the burden of proof to the defendant handler once a data subject demonstrates an infringement of their personal-information rights, and courts assessing damages are not limited to actual losses but may instead rely on the gains the handler obtained from the infringing conduct.

Recent Developments 180DAmber

Within the last 180 days: the amended Cybersecurity Law (passed October 2025) raised maximum penalties and folded AI governance into CSL; a CAC directive of 28 December 2025 mandated minors'-data compliance audits and filings by 31 January 2026; and TC260 released draft amendments to the (non-binding) GB/T 35273 national standard on 17 June 2026, introducing new AI-governance and legal-basis chapters, with public comment open until 16 August 2026.

Claims (1):

  • Within the 180 days preceding this run: China's amended Cybersecurity Law (passed October 2025) raised the maximum corporate fine to CNY50 million or 5% of prior-year turnover and folded AI governance into CSL's scope; a CAC directive dated 28 December 2025 required companies collecting minors' personal information to complete compliance audits and submit filings to local CAC offices by 31 January 2026; and on 17 June 2026 TC260 released draft amendments to the non-binding GB/T 35273 national standard, adding a new chapter on legal-basis guidance and AI-driven governance updates, with public comment open until 16 August 2026.
Category narrative189 words

PIPL Article 63 grants supervisory authorities broad investigatory powers (interviews, document review, on-site inspection, equipment seizure/confiscation). A two-tier penalty structure applies: general violations up to RMB1 million for handlers/RMB100,000 for responsible officers; grave violations up to RMB50 million or 5% of prior-year revenue for handlers, RMB100,000–1 million for officers, plus rectification orders, business suspension or license revocation. Landmark enforcement includes the RMB8.026 billion Didi fine (2022) and the RMB50 million CNKI fine (2023) for PIPL/CSL violations. Article 70 permits public-interest actions (China's class-action equivalent) by the People's Procuratorate, designated consumer organizations, or CAC-designated bodies; Article 69 shifts the burden of proof to the defendant handler once an infringement is shown, and courts may base damages on the handler's gains rather than only the individual's proven losses. Recent developments (within 180 days of this run) include the October 2025 amended CSL raising maximum penalties and bringing AI within CSL's scope, a 28 December 2025 CAC directive on minors'-data compliance filings (deadline 31 January 2026), and June 2026 TC260 draft amendments to the non-binding GB/T 35273 national standard introducing new AI-governance and legal-basis guidance (comment period open to 16 August 2026).

Periodic update · new data 2026-09-28

Enforcement & Redress

Enforcement activity in China's data-protection landscape escalated this cycle on two fronts. First, the Cyberspace Administration of China, the Ministry of Industry and Information Technology, and the Ministry of Public Security launched a joint nationwide enforcement campaign targeting PIPL violations across six sectors on 2 April 2026. This is characterised in the evidence as marking a shift toward routine, rather than merely exemplary or high-profile, enforcement, a distinction with real significance: exemplary enforcement targets a small number of high-visibility violators to signal broader deterrence, while routine sector-wide enforcement implies sustained, ongoing compliance-checking activity across a much larger population of regulated entities.

Second, the amended Cybersecurity Law, effective 1 January 2026, raises the maximum penalty for Critical Information Infrastructure Operators to CNY 10 million where violations cause particularly serious consequences. This substantially raised penalty ceiling increases the financial stakes for Critical Information Infrastructure Operators specifically, distinguishing their exposure from that of ordinary data controllers not designated as such operators.

As standing reference context, the Cyberspace Administration of China's historical RMB 8 billion fine against Didi Global for serious violations of PIPL, the Data Security Law, and the Cybersecurity Law illustrates the outer scale of available regulatory sanction in China's enforcement landscape, even though that action predates this cycle and is not itself a new development; it remains the reference point against which the current cycle's six-sector campaign and raised CIIO penalty ceiling should be read for scale comparison.

Outlook

Watch for enforcement outcomes and any published penalty decisions arising from the 2 April 2026 six-sector campaign, which would provide the clearest evidence of whether the shift toward routine enforcement is being sustained with material financial consequences for violators. Watch also for the first application of the amended CSL's CNY 10 million penalty ceiling against a Critical Information Infrastructure Operator, which would test the raised ceiling in practice for the first time.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (5)
  1. ProbableIAPP — PIPL Article 63 grants supervisory authorities investigatory powers including interviews, document review, on-site inspections, and equipment seizure/confiscation; the law creates a two-tier penalty structure with general violations fined up to RMB1 million for handlers and RMB100,000 for responsible officers, and grave violations fined up to RMB50 million or 5% of the previous year's annual revenue for handlers and RMB100,000–1 million for officers, alongside rectification orders, business suspension, and license revocation powers.observed
  2. ProbableOneTrust DataGuidance — CAC fined Didi Global approximately RMB8.026 billion in 2022 for violations of the CSL, DSL and PIPL, and separately fined academic database provider CNKI RMB50 million for PIPL and CSL violations in 2023, illustrating sustained large-scale enforcement activity.observed
  3. ProbableIAPP — PIPL Article 70 grants standing to file public-interest actions — China's functional equivalent of class actions — to the People's Procuratorate, statutorily designated consumer organizations, and organizations designated by CAC, where a handler's infringement affects a large number of individuals.observed
  4. ProbableIAPP — PIPL Article 69 shifts the burden of proof to the defendant handler once a data subject demonstrates an infringement of their personal-information rights, and courts assessing damages are not limited to actual losses but may instead rely on the gains the handler obtained from the infringing conduct.observed
  5. ProbableIAPP — Within the 180 days preceding this run: China's amended Cybersecurity Law (passed October 2025) raised the maximum corporate fine to CNY50 million or 5% of prior-year turnover and folded AI governance into CSL's scope; a CAC directive dated 28 December 2025 required companies collecting minors' personal information to complete compliance audits and submit filings to local CAC offices by 31 January 2026; and on 17 June 2026 TC260 released draft amendments to the non-binding GB/T 35273 national standard, adding a new chapter on legal-basis guidance and AI-driven governance updates, with public comment open until 16 August 2026.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metwaived
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct10.53
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for China
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 46 claim(s) (46 category placement(s)), 33 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacydata localisation
Art. 49Cross-Border & Adequacytransfer impact assessment
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules populated with T1 (CAC official instrument pages for Algorithmic Recommendation Provisions and Generative AI Measures) and predominantly T2 (IAPP, DataGuidance) secondary analysis grounded in specific PIPL/CSL/DSL articles. Strongest coverage (T1/T2, high confidence): regulator_and_framework, lawful_processing_and_special_data, controller_processor_duties, cross_border_and_adequacy, enforcement_and_redress. Weaker coverage with explicit gaps: sectoral_watch (health/education sub-modules empty), adtech_and_commercial_privacy (cookies/opt-out-signals/clean-rooms empty), algorithmic_biometric_and_surveillance_governance (genetic_data empty), children_and_vulnerable_groups (minor_profiling_bans/education_settings empty, dependent_adults thin). No T3/T4 sources were used as sole support for any binding claim; one T3 academic source (arxiv) was consulted for context only and not cited as a claim source.

Unresolved questions (5):

  • Exact numeric PIPO (Personal Information Protection Officer) appointment threshold remains undefined in binding PIPL text — only draft/analogous CAC measures suggest ~1 million individuals.
  • Precise coming-into-force date of the October 2025 amended Cybersecurity Law was not confirmed against an official gazette text.
  • Whether China has issued or intends to issue formal outbound 'adequacy' determinations toward any other jurisdiction remains unconfirmed — no evidence of such a mechanism was found.
  • No dedicated health-sector, education-sector, or standalone genetic-data regime was located; unclear whether these are addressed solely through general PIPL sensitive-category treatment or through as-yet-unlocated sectoral rules.
  • Statutory day-count deadline (if any) for responding to PIPL access/rectification/erasure requests was not located beyond general 'timely' language.

Escalate to primary-source review: yes