China Personal Information Protection Law
The PIPL is China's comprehensive national law governing how personal information is collected, used, and protected, primarily for people physically located in Mainland China. It was adopted on August 20, 2021, and took effect on November 1, 2021. Commentators often compare it to the EU's GDPR, though its specific rules and enforcement context differ and should not be treated as identical.
The PIPL is China's first comprehensive national-level legislation regulating the processing of personal information and sensitive personal information, including rules on legal bases for processing and disclosure. Adopted on August 20, 2021, and effective November 1, 2021, it builds on China's earlier Cybersecurity Law (CSL) and is intended to protect the personal information of persons physically located in Mainland China. While frequently characterized as China's counterpart to the GDPR, practitioners should not assume that compliance under one framework satisfies the other, as scope, definitions, and enforcement approaches differ. This entry covers the law's identity and origins only; the specifics of its consent requirements, cross-border transfer conditions, and any treatment of cookies or tracking technologies are outside its scope and depend on the statutory text and evolving regulatory guidance not detailed in the evidence provided.
Why it matters
The PIPL is China's first comprehensive national-level law governing the processing of personal information, and its adoption on August 20, 2021, with effect from November 1, 2021, marked a significant expansion of the global patchwork of data protection regimes. For organizations that handle the personal information of people physically located in Mainland China, the PIPL introduces a distinct legal framework that cannot be treated as interchangeable with the EU's GDPR, even though commentators frequently draw the comparison. Compliance decisions made under one regime should not be assumed to satisfy the other, because the scope, definitions, and enforcement context differ.
For privacy officers and legal counsel, the PIPL matters because it establishes rules on the legal bases for processing personal information and sensitive personal information, as well as on disclosure. It builds on China's earlier Cybersecurity Law rather than replacing it, so organizations operating in or interacting with Mainland China may need to consider how these instruments interact. Because the PIPL's specific obligations flow from the statutory text and evolving regulatory guidance, teams should approach it as a discrete compliance workstream rather than an extension of existing EU-focused programs.
Who it's relevant to
Inside PIPL
Common questions
Answers to the questions practitioners most commonly ask about PIPL.