Law Atlas

How The Law Decides
Articles

China's Answer to the GDPR Question

Citation Formats

General Reference

APA Style

BibTeX

Learn More
China's Answer to the GDPR Question

This article records tradition as it has been passed down and reported. Its sources are not yet part of the atlas's verified catalogue.

By the time China's Standing Committee of the National People's Congress passed the Personal Information Protection Law on August 20, 2021, the European Union's General Data Protection Regulation had been in force for more than three years and had already become the reference point every other jurisdiction's privacy statute got measured against. PIPL, effective from November 1, 2021, borrows enough of that reference point's structure that comparing the two is the fastest way to see both what China's law does and what makes its own legal tradition distinctive.

The family resemblance is real. Like GDPR, PIPL requires a lawful basis for processing personal information, generally the individual's clear and specific consent, imposes a stricter separate-consent requirement for sensitive categories such as biometric, financial and health data, and reaches beyond its own borders: an online retailer in another country selling to customers in China, or an app tracking their behavior, falls under PIPL exactly as a company outside the European Union falls under GDPR the moment it processes an EU resident's data. The penalties echo Brussels too, up to fifty million yuan or five percent of a company's prior year global revenue for the most serious violations, a structure clearly modeled on GDPR's own turnover-based fines.

Where the two laws part company is in what put them there. GDPR is a directly effective regulation of a supranational body, adopted by the European Parliament and Council and binding uniformly across twenty-seven member states without any national transposition law required, itself a distinctive feature of the civil law tradition's approach to regional integration. PIPL is an ordinary national statute of a single sovereign state, enforced chiefly by the Cyberspace Administration of China, part of a legislative apparatus that also produced China's 2020 Civil Code and its 2017 Cybersecurity Law in the same few years, each layered onto the others rather than growing out of centuries of accumulated judicial doctrine the way common law privacy torts did in England and the United States. Comparative lawyers generally place contemporary Chinese law inside the broader civil law family, as a socialist legal system retaining features, state primacy over private law chief among them, that mark it as its own distinct branch rather than a simple copy of French or German codification. PIPL is a clean illustration of that lineage: a law that looks, on the page, remarkably like GDPR, produced by a legislative and regulatory process that looks nothing like the one that produced it.

Cross-Tradition Connections

Article On

Sources
Personal Information Protection Law of the People's Republic of China (Wikipedia)
LawAtlas Long-Form Articles, First Edition
editorial: review disposition
Top 5 Operational Impacts of China's PIPL, Part 4: Penalties and Enforcement Mechanisms (IAPP)
Penalties and enforcement mechanisms
Quote, Penalties and enforcement mechanisms
the Cyberspace Administration of China ("CAC"), the Ministry of Industry and Information Technology, the Ministry of Public Security, the State Administration for Market Regulation, financial regulators, as well as their respective counterparts at local levels.
View the Source
Comments (0)
No comments yet. Be the first to share a thought.
Reader Challenges (0 open reader challenges)
No disputes yet. Spotted an error or a better source? Open the first one.

View At A Past Year

The atlas records no dated fact of its own for this entry, so there is no other year to choose.