What Is PIPL (Personal Information Protection Law)?

Also called: China Personal Information Protection Law, China PIPL

Related problems: We have customers or staff in China and don't know what privacy rules apply; Moving personal data from China to our global CRM, HR or cloud systems; A Chinese partner asked for a standard contract filing or security assessment; Not sure whether our China operations need data stored locally

The Personal Information Protection Law (PIPL) is China’s main law on personal information. It sets out when an organization may collect and use information about people in China, what rights those people have, which processing needs special care, and on what conditions data may be sent abroad. It works alongside China’s Cybersecurity Law and Data Security Law, and the Cyberspace Administration of China (CAC) coordinates its enforcement. This entry is an overview for buyers, not legal advice.

At a glance

  • PIPL covers processing in China, and processing abroad aimed at providing products or services to people in China or analyzing their behavior.
  • Organizations need a legal basis for each use; consent is central, and separate consent is needed for some uses, such as sensitive data and overseas transfers.
  • Transfers abroad use a CAC security assessment, certification or a filed standard contract, depending on the organization and data volumes, unless an exemption applies.
  • Critical information infrastructure operators and high-volume handlers face local storage requirements.
  • Penalties for serious violations can reach a share of annual revenue, plus suspension of services and personal liability for responsible managers.

What problem it solves

Personal information about Chinese residents flows into ecommerce platforms, apps, CRMs, HR systems and global analytics tools, often operated or hosted abroad. PIPL brings that activity under one framework, with individual rights, accountability for organizations, and state control over what leaves the country.

For a mid-market buyer, PIPL shows up when a company opens an office or sells in China, runs a website or app for Chinese users, or wants employee and customer data from China in its global systems. The practical questions are what data is involved, which legal basis applies, whether it must stay in China, and which transfer route to use.

How it works

Roles. A personal information handler decides the purpose and method of processing. An entrusted party processes data on the handler’s behalf under an agreement covering purpose, duration, methods and protection, and may not sub-delegate without consent.

Legal bases and consent. Processing needs a legal basis, such as consent, necessity for a contract or for HR management, or legal duties. Sensitive personal information, such as biometrics, health, financial accounts, location tracks and data on minors under 14, needs a specific purpose, strict protection and generally separate consent.

Rights. Individuals can access, copy, correct and delete their data, withdraw consent and ask for explanations of processing rules.

Accountability. Handlers carry out personal information protection impact assessments for higher-risk activities, such as processing sensitive data, automated decisions, entrusting data to others and overseas transfers, and conduct regular compliance audits. Breaches must be remedied promptly and reported to the authorities and, in most cases, to affected people.

Transfers. Data leaving China needs a recognized route plus notice and separate consent where consent is the basis. Regulators have adjusted the volume thresholds and added exemptions since the law took effect, so the route depends on current rules.

Cross-border transfer routes

PIPL has no certification levels. Its most important structure for buyers is the set of roles above and the routes for sending personal information out of China.

Route Who it typically applies to What is required Typical evidence
CAC security assessment Critical information infrastructure operators, and handlers transferring large volumes or sensitive data above regulatory thresholds Government review and approval before transfer CAC approval
Standard contract Handlers below the assessment thresholds but above exemption levels Signed CAC standard contract with the recipient, impact assessment, filing with the local authority Filed contract and assessment
Certification Handlers below the assessment thresholds, often multinational groups transferring intra-group Certification by a recognized body Certification record
Exempt transfers Certain transfers, such as some necessary for contracts with the individual or cross-border HR management, or data not collected in China Notice, consent where needed, and other PIPL duties still apply Documented exemption analysis

When it matters for buyers

  • When operating or selling in China. Expect questions about legal bases, consent and where data is kept.
  • When connecting China offices to global systems. CRM, HR, collaboration and ticketing tools can all export personal information.
  • When choosing hosting for a China-facing site or app. Local hosting interacts with ICP filing and licensing and with data localization.
  • When a Chinese customer or partner asks for a transfer filing. Someone needs to own the route, the assessment and the paperwork.

Our governance, risk and compliance overview covers advisors for multi-country privacy programs; our public cloud and global WAN overviews cover China hosting and connectivity options.

Questions to ask vendors

  • Where is personal information from China stored and processed, including backups and support access?
  • Do you offer an in-China deployment, and who is the local operating entity?
  • Which transfer route do you support, and will you sign the CAC standard contract and help with the filing?
  • How will you help us obtain and record separate consent where it’s needed?
  • How quickly will you notify us of a breach involving data from China?
  • Which governments or courts could compel disclosure of our data, and how will you respond?

How it differs from GDPR

PIPL and the General Data Protection Regulation (GDPR) both set legal bases, individual rights, impact assessments and transfer controls, and both reach organizations abroad. PIPL leans more heavily on consent, ties into national security review of data exports, and requires local storage for some organizations, which GDPR does not. For some organizations in China, data residency is a legal requirement, not just a customer preference. Both define personal information more broadly than many US uses of personally identifiable information (PII), and a multi-country data breach can trigger both regimes, which a governance, risk and compliance (GRC) program tracks together.

Frequently Asked Questions

Does PIPL apply to companies outside China?
It can. Besides processing inside China, it covers processing abroad whose purpose is to provide products or services to people in China or to analyze their behavior. Covered foreign organizations are also expected to set up an entity or appoint a representative in China. Whether it applies to you depends on the facts; check with counsel. This is not legal advice.
Does PIPL require personal data to stay in China?
Not in every case. Critical information infrastructure operators, and organizations above volume thresholds set by regulators, must store data collected in China locally and pass a security assessment before exporting it. Others can transfer data abroad using a recognized route, such as the standard contract or certification, unless an exemption applies.
What are the ways to transfer personal information out of China?
PIPL recognizes a security assessment by the Cyberspace Administration of China (CAC), certification by a recognized body, and a standard contract with the overseas recipient, filed with the authorities. Which one applies depends on the type of organization, data volumes and sensitivity. The thresholds and exemptions have been changed by later regulations, so confirm the current rules.
Is PIPL the same as GDPR?
No. It borrows ideas from GDPR, such as legal bases, individual rights and impact assessments, but it relies more on consent, including separate consent for some uses and for overseas transfers, has its own transfer regime and sits alongside China's Cybersecurity Law and Data Security Law.
Do we need separate consent to send data abroad?
Generally, where consent is the legal basis. PIPL expects organizations to tell individuals about the overseas recipient and how to exercise their rights, and to obtain separate consent for the transfer. Other legal bases, such as necessity for a contract, can change the analysis, so check with counsel.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.