Data Protection in China

Data protection laws in China

There is not a single comprehensive data protection law in the People's Republic of China (PRC). Instead, rules relating to personal information protection and data security are part of a complex framework and are found across various laws and regulations. That said, the three main pillars of the personal information protection framework in the PRC are the Personal Information Protection Law (PIPL), the Cybersecurity Law (CSL), and the Data Security Law (DSL).

On June 1, 2017, the CSL came into effect and became the first national–level law to address cybersecurity and data privacy protection. Draft Amendments to the CSL were issued on September 12, 2022, proposing enhanced liabilities for violating obligations of general network operation security, security protection of critical information infrastructure, network information security and personal information protection, etc.

The DSL came into force on September 1, 2021, and focuses on data security across a broad category of data (not just personal information).

Most significantly, the PIPL came into effect on November 1, 2021. The PIPL is the first comprehensive, national–level personal information protection law in the PRC. The PIPL does not replace — but instead enhances and clarifies — earlier personal information laws and regulations.

In addition to the PIPL, CSL and DSL, the following form the backbone of general personal information protection framework currently in the PRC:

  • The Decision on Strengthening Online Information Protection, effective from December 28, 2012 (Decision); 
  • The Draft Regulation of Network Data Security Management, published for consultation on November 14, 2021; 
  • The Measures for the Security Assessment of Outbound Data Transfers, effective from September 1, 2022; 
  • The Measures for the Standard Contract for the Outbound Transfer of Personal Information, effective from 1 June 2023;
  • The Regulations on Facilitating and Regulating the Cross–border Data Transfers, effective from 22 March 2024; and
  • The Network Data Security Management Regulation (Network Data Regulation) , effective from 1 January 2025.

In the past five years, there has also been an abundance of implementing regulations and guidelines (herein referred to as Guidelines) proposed, issued or revised to flesh out the essentials and concepts introduced under the personal information protection framework. These include, non–exhaustively:

  • National Standard of Information Security Technology — Personal Information Security Specification (PIS Specification), as amended and effective from October 1, 2020;
  • Guidelines on Internet Personal Information Security Protection, effective from April 19, 2019;
  • National Standard of Information Security Technology — Guidelines on Personal Information Security Impact Assessment, effective from June 1, 2021;
  • Draft National Standard of Information Security Technology — Requirements for Classification and Grading of Network Data, published for consultation on September 14, 2022; 
  • Practicing Guidelines for Network Security Standards — Technical Specification for Certification of Personal Information Cross-border Processing Activities (V2.0), effective from December 16, 2022; 
  • Standard Contract for Cross-boundary Flow of Personal Information Within the Guangdong–Hong Kong–Macao Greater Bay Area (Mainland, Hong Kong), effective from 10 December 2023;
  • Guidelines on the Filing of Standard Contracts for the Outbound Transfer of Personal Information (Second Edition), effective from 22 March 2024;
  • Guidelines on Application of Security Assessment of Cross-border Data Transfers (Second Edition), effective from 22 March 2024; and
  • National Standard of Data Security Technology – Rules for Data Classification and Grading, effective from March 21, 2024;
  • Draft National Standard of Data Security Technology – Personal Information Protection Compliance Audit Requirements, published for consultation on July 12, 2024; and
  • Guide for Sensitive Personal Information Identification, effective from September 18, 2024.

The Decision has the same legal effect as law, and its purpose is to protect online information security, safeguard the lawful rights and interests of citizens, legal entities or other organizations, and ensure national security and public interests. While the PIS Specification and other Guidelines are only technical guides (covering in detail key issues such as data transfers, sensitive personal information and data subject rights), and thus not legally binding, they have historically been highly persuasive. Although the PIPL takes precedence over the PIS Specification and other Guidelines, the PIS Specification and the Guidelines are still useful for the purposes of supplementing legislation, especially on any part that has not been addressed by the PIPL, CSL or DSL.

In addition to all of the above:

  • provisions found in laws such as the Tort Liability Law have generally been used to interpret data protection rights as a right of reputation or right of privacy. However, such interpretation is not explicit. The PRC Civil Code, effective on January 1, 2021 further reinforces the statutory right of privacy for individuals and establishes data protection principles; and 
  • provisions contained in other laws and regulations may also apply depending on the industry or type of information involved (for example, personal information obtained by financial institutions and e-commerce businesses, personal information collected by telecom or Internet service / content providers, healthcare and genetic information, etc.). Applicability of other laws or regulations (including provincial level laws), such as the PRC Criminal Law, PRC E-Commerce Law, PRC Consumer Rights Protection Law, PRC Anti-Money Laundering Law and the new local data laws at a provincial level will invariably depend on the factual context of each case and further independent analysis is recommended.

Given the personal information protection framework is still evolving, and further regulations accompanying the new PIPL and DSL are anticipated to be published in the coming months, it is recommended that organizations continue to monitor the developments of the PRC data protection regulatory framework.

Extra-territorial scope

The PIPL has extra–territorial effect, and applies both to:

  • data processing activities within the PRC; and
  • processing of PRC residents' data outside of PRC where:
    • for the purposes of providing products or services to PRC residents;
    • for analytics or evaluation of behavior of PRC residents; or
    • for any other reasons as required by law or regulations.

The PIPL applies to both the public and private sectors.

Continue reading

  • no results

Back to top