Data Protection in China

Definitions in China

Definition of personal information

The PIPL defines personal information as any kind of information relating to an identified or identifiable natural person, either electronically or otherwise recorded, but excluding information that has been anonymized.

Definition of sensitive personal information

The PIPL defines sensitive personal information as information that, once leaked or illegally used, will easily lead to infringement of human dignity or harm to the personal or property safety of a natural person, including (but not limited to):

  • biometric data;
  • religion;
  • specific social status;
  • medical health information;
  • financial accounts;
  • tracking / location information; and
  • minors' data.

That said, under the new "Guide for Sensitive Personal Information Identification" (published by the National Standardization Technical Committee for Information Security), which became effective on September 18, 2024, when assessing whether certain personal information constitutes sensitive personal information, data controllers must now focus more on the processing context, and the impact of the processing activities on data subjects, rather than referring to any prescribed lists of sensitive personal information. As such, going forward a case-by-case analysis may be required to identify sensitive personal information.  

Definition of network data

The Network Data Regulation governs electronic data processed and generated via networks (“network data”) and applies to all processing of network data within Mainland China. A “network” means a system composed of computers or other information terminals and related equipment that collects, stores, transmits, exchanges and processes information according to certain rules and procedures. So, in practice, this captures all electronic data processed or generated online (including personal information and non-personal information).

Continue reading

  • no results

Previous topic
Back to top