Law Atlas

How The Law Decides
Articles

A Law Passed by Statute, Not Grown by Precedent

Citation Formats

General Reference

APA Style

BibTeX

Learn More
A Law Passed by Statute, Not Grown by Precedent

This article records tradition as it has been passed down and reported. Its sources are not yet part of the atlas's verified catalogue.

American privacy law, to the extent the United States can be said to have one coherent body of it, grew up almost entirely through the common law, tort claims for intrusion on seclusion, a scattering of sector-specific statutes for health records or credit reports, and no single comprehensive federal law comparable to what China passed in a single sitting of its Standing Committee in August 2021. That contrast is not an accident of politics; it is exactly what each system's own legal tradition would predict.

China's Personal Information Protection Law arrived complete, in one statute, with its scope, its consent requirements, its cross-border transfer rules and its penalty structure all specified in the text itself, effective on a fixed date, November 1, 2021, that every covered organization could plan around in advance. That is how law is built inside a civil law tradition generally, and inside China's own socialist variant of it specifically: the legislature enacts a comprehensive code addressing a subject, and courts and regulators apply and interpret that code, rather than building the substantive rule up gradually from one dispute to the next the way a common law court builds a body of doctrine case by case. PIPL did not emerge alone; it took its place beside the personal-information provisions the National People's Congress had already written into China's 2020 Civil Code and the data-security rules in the 2017 Cybersecurity Law, three legislative instruments passed within roughly five years of each other, each filling in a different part of one deliberately constructed regulatory structure.

The practical consequence for a company operating under PIPL is that the text itself, not a body of case law interpreting it, is where an answer to a compliance question is meant to be found. Ambiguity gets resolved through implementing regulations and guidance from the Cyberspace Administration of China rather than through years of litigated precedent narrowing an open-ended standard. That is a genuinely different way of building consumer protection than a country like the United States has taken with privacy, and holding PIPL up next to that tradition, rather than only next to GDPR, is what actually shows a reader which parts of PIPL are borrowed from Europe's example and which parts are simply how Chinese civil law builds any new area of regulation at all.

Cross-Tradition Connections

Article On

Sources
Personal Information Protection Law of the People's Republic of China (Wikipedia)
LawAtlas Long-Form Articles, First Edition
editorial: review disposition
Top 5 Operational Impacts of China's PIPL, Part 4: Penalties and Enforcement Mechanisms (IAPP)
Penalties and enforcement mechanisms
Quote, Penalties and enforcement mechanisms
the Cyberspace Administration of China ("CAC"), the Ministry of Industry and Information Technology, the Ministry of Public Security, the State Administration for Market Regulation, financial regulators, as well as their respective counterparts at local levels.
View the Source
Comments (0)
No comments yet. Be the first to share a thought.
Reader Challenges (0 open reader challenges)
No disputes yet. Spotted an error or a better source? Open the first one.

View At A Past Year

The atlas records no dated fact of its own for this entry, so there is no other year to choose.