Law Atlas

How The Law Decides
Regulations

Personal Information Protection Law (PIPL)

Also Known As PIPL

Citation Formats

General Reference

APA Style

BibTeX

The Personal Information Protection Law is the People's Republic of China's first comprehensive national data protection statute, adopted by the Standing Committee of the 13th National People's Congress on August 20, 2021 and effective from November 1, 2021. It requires that personal information be processed only with a lawful basis and, for most processing, the individual's clear and specific consent, sets a stricter separate-consent requirement for sensitive personal information, biometric, financial, health and location data among it, and imposes security assessment and government approval requirements before personal information can be transferred outside mainland China. Like the European Union's General Data Protection Regulation, it applies extraterritorially, reaching any organization outside China that processes the personal information of individuals located in China for the purpose of providing them goods or services or analyzing their behavior, and it carries substantial penalties, up to fifty million yuan or five percent of the offending company's prior year annual revenue for serious violations. It is enforced principally by the Cyberspace Administration of China, alongside sector regulators. Comparatively, PIPL sits inside China's own civil-law-family legal system, developed through legislative codification rather than common-law judicial development, and was adopted alongside the personal-information provisions of China's 2020 Civil Code and its earlier 2017 Cybersecurity Law rather than as a stand-alone judicial doctrine; specialists in comparative law generally classify contemporary Chinese law as a socialist legal system within the broader civil-law family, retaining Soviet-influenced statist features distinct from the private-law tradition of France or Germany.

Facts
Era
China, adopted August 20, 2021, effective November 1, 2021 1
Promulgated By
The Standing Committee of the 13th National People's Congress of the People's Republic of China; enforced principally by the Cyberspace Administration of China 1
Jurisdiction Scope
Organizations and individuals processing the personal information of natural persons within mainland China, with extraterritorial reach to overseas processors handling the data of persons located there 1
Regulatory Domain
Personal data protection and privacy 1
Learn More
China's Answer to the GDPR Question

This article records tradition as it has been passed down and reported. Its sources are not yet part of the atlas's verified catalogue.

By the time China's Standing Committee of the National People's Congress passed the Personal Information Protection Law on August 20, 2021, the European Union's General Data Protection Regulation had been in force for more than three years and had already become the reference point every other jurisdiction's privacy statute got measured against. PIPL, effective from November 1, 2021, borrows enough of that reference point's structure that comparing the two is the fastest way to see both what China's law does and what makes its own legal tradition distinctive.

The family resemblance is real. Like GDPR, PIPL requires a lawful basis for processing personal information, generally the individual's clear and specific consent, imposes a stricter separate-consent requirement for sensitive categories such as biometric, financial and health data, and reaches beyond its own borders: an online retailer in another country selling to customers in China, or an app tracking their behavior, falls under PIPL exactly as a company outside the European Union falls under GDPR the moment it processes an EU resident's data. The penalties echo Brussels too, up to fifty million yuan or five percent of a company's prior year global revenue for the most serious violations, a structure clearly modeled on GDPR's own turnover-based fines.

Where the two laws part company is in what put them there. GDPR is a directly effective regulation of a supranational body, adopted by the European Parliament and Council and binding uniformly across twenty-seven member states without any national transposition law required, itself a distinctive feature of the civil law tradition's approach to regional integration. PIPL is an ordinary national statute of a single sovereign state, enforced chiefly by the Cyberspace Administration of China, part of a legislative apparatus that also produced China's 2020 Civil Code and its 2017 Cybersecurity Law in the same few years, each layered onto the others rather than growing out of centuries of accumulated judicial doctrine the way common law privacy torts did in England and the United States. Comparative lawyers generally place contemporary Chinese law inside the broader civil law family, as a socialist legal system retaining features, state primacy over private law chief among them, that mark it as its own distinct branch rather than a simple copy of French or German codification. PIPL is a clean illustration of that lineage: a law that looks, on the page, remarkably like GDPR, produced by a legislative and regulatory process that looks nothing like the one that produced it.

A Law Passed by Statute, Not Grown by Precedent

This article records tradition as it has been passed down and reported. Its sources are not yet part of the atlas's verified catalogue.

American privacy law, to the extent the United States can be said to have one coherent body of it, grew up almost entirely through the common law, tort claims for intrusion on seclusion, a scattering of sector-specific statutes for health records or credit reports, and no single comprehensive federal law comparable to what China passed in a single sitting of its Standing Committee in August 2021. That contrast is not an accident of politics; it is exactly what each system's own legal tradition would predict.

China's Personal Information Protection Law arrived complete, in one statute, with its scope, its consent requirements, its cross-border transfer rules and its penalty structure all specified in the text itself, effective on a fixed date, November 1, 2021, that every covered organization could plan around in advance. That is how law is built inside a civil law tradition generally, and inside China's own socialist variant of it specifically: the legislature enacts a comprehensive code addressing a subject, and courts and regulators apply and interpret that code, rather than building the substantive rule up gradually from one dispute to the next the way a common law court builds a body of doctrine case by case. PIPL did not emerge alone; it took its place beside the personal-information provisions the National People's Congress had already written into China's 2020 Civil Code and the data-security rules in the 2017 Cybersecurity Law, three legislative instruments passed within roughly five years of each other, each filling in a different part of one deliberately constructed regulatory structure.

The practical consequence for a company operating under PIPL is that the text itself, not a body of case law interpreting it, is where an answer to a compliance question is meant to be found. Ambiguity gets resolved through implementing regulations and guidance from the Cyberspace Administration of China rather than through years of litigated precedent narrowing an open-ended standard. That is a genuinely different way of building consumer protection than a country like the United States has taken with privacy, and holding PIPL up next to that tradition, rather than only next to GDPR, is what actually shows a reader which parts of PIPL are borrowed from Europe's example and which parts are simply how Chinese civil law builds any new area of regulation at all.

Cross-Tradition Connections

Associated With

In Legal System

Comparative law generally classifies contemporary Chinese law as a socialist legal system within the broader civil-law family, developed by legislative codification rather than common-law judicial precedent.

Sources
1. Personal Information Protection Law of the People's Republic of China (Wikipedia)
LawAtlas Long-Form Articles, First Edition
Long-Form Articles: China's Answer to the GDPR Question
LawAtlas Long-Form Articles, First Edition
Long-Form Articles: A Law Passed by Statute, Not Grown by Precedent
Comments (0)
No comments yet. Be the first to share a thought.
Reader Challenges (0 open reader challenges)
No disputes yet. Spotted an error or a better source? Open the first one.

View At A Past Year

The atlas records no dated fact of its own for this entry, so there is no other year to choose.