Legal e Conformidade
What is China PIPL (Personal Information Protection Law)?
What is China PIPL (Personal Information Protection Law)?
China’s Personal Information Protection Law (PIPL) is a major source of law on personal data protection; one of the three basic laws on data-related matters in China, along with the Cybersecurity Law and the Data Security Law. The PIPL came into effect on 1 November 2021. For SaaS companies and software developers with Chinese users, PIPL compliance is a requirement, and enforcement procedures have become more stringent.
Who does China's PIPL apply to?
PIPL has a very strong extra-territorial dimension. The provisions relate to any organization that processes personal information concerning individuals in China. This includes businesses without a physical presence in China; their activities involve providing products or services to Chinese users or analyzing their behavior patterns.
What does China's PIPL define as personal information?
| Categoria | Definição | Exemplos |
| Personal information | Any data relating to an identified or identifiable natural person (excluding anonymized data) | Name, email, device ID, location |
| Sensitive personal information | The management and distribution of these records can impact an individual’s reputation and subsequent conduct, with the degree of impact being influenced by the level of precise attention given | The range of included items covers biometric data, health-related data, financial information, religious beliefs, and data specific to children under 14 |
What are the core PIPL obligations for businesses?
The legal foundation for processing personal information under PIPL is consent, contractual necessity, statutory duty, and public interest (with consent by far the most common). Considering personal data handling practices could be a focus for businesses.
Processor obligations:
- Prepare the data management plans and procedures within the company.
- Differentiate protection measures for various categories of personal information
- Use technical safety measures: encryption, de-Identification, access control
- Conduct regular data privacy awareness training with the staff
- Carry out mandatory self-inspection of compliance; entities that process data of 10 million+ people are required to comply under the PIPL Compliance Audit Measures, which have been effective from May 1, 2025, and must be inspected at least once every two years
- Prepare and execute plans for data breach incidents, if any.
Individuals hold the following rights against data handlers:
- They can be informed, have access, get copies, have their personal data corrected, or have it deleted or transferred
- Individuals can limit or block the processing
- Ask for the reasoning behind the processing operations
What are the cross-border data transfer requirements under China's PIPL?
A gestão de PIPL concerning cross-border data transfers to third countries by foreign companies outside China presents aspects related to financial penalties or regulatory compliance. Since January 1st 2026, there are 3 formal pathways; companies must choose one.
| Pathway | Quando se aplica |
| CAC Security Assessment | Required for CII operators or large-volume processors |
| Standard Contract Filing | For most organizations transferring personal data |
| Certification | Issued by approved institutions; Certification Measures effective January 1, 2026 |
How Does China's PIPL Compare to the EU's GDPR?
| PIPL | GDPR | |
| Extraterritorial scope | Sim | Sim |
| Legal bases for processing | 7, no legitimate interests basis | 6; includes legitimate interests |
| Separate consent required | Yes — for sensitive data, third-party sharing, cross-border transfers | Not always |
| In-country representative | Required in some cases | EU representative required |
| Cross-border transfers | Stricter; 3 formal pathways | Adequacy decisions + SCCs |
| National security focus | Sim | Não |
What are the penalties for PIPL Non-Compliance?
Article 66 of the PIPL determines financial requirements for specific breaches, with maximum amounts of RMB 50 million (~$6.9M) or 5% of annual global revenue.
Enforcement measures application has shifted from a selective approach. A joint CAC-MIIT-MPS campaign launched in April 2026 publicly named 33 non-compliant apps and signaled a move toward routine enforcement.
Conclusão
Compliance with China’s new Data Privacy rules represents an area for businesses operating in or targeting the Chinese market to consider, given its relevance to legal operations and the potential for regulatory findings.