Skip to main content
Category: Laws and Regulations

China Personal Information Protection Law

Also known as: PIPL, Personal Information Protection Law, Personal Information Protection Law of the People's Republic of China, China's version of the GDPR
Simply put

The PIPL is China's comprehensive national law governing how personal information is collected, used, and protected, primarily for people physically located in Mainland China. It was adopted on August 20, 2021, and took effect on November 1, 2021. Commentators often compare it to the EU's GDPR, though its specific rules and enforcement context differ and should not be treated as identical.

Formal definition

The PIPL is China's first comprehensive national-level legislation regulating the processing of personal information and sensitive personal information, including rules on legal bases for processing and disclosure. Adopted on August 20, 2021, and effective November 1, 2021, it builds on China's earlier Cybersecurity Law (CSL) and is intended to protect the personal information of persons physically located in Mainland China. While frequently characterized as China's counterpart to the GDPR, practitioners should not assume that compliance under one framework satisfies the other, as scope, definitions, and enforcement approaches differ. This entry covers the law's identity and origins only; the specifics of its consent requirements, cross-border transfer conditions, and any treatment of cookies or tracking technologies are outside its scope and depend on the statutory text and evolving regulatory guidance not detailed in the evidence provided.

Why it matters

The PIPL is China's first comprehensive national-level law governing the processing of personal information, and its adoption on August 20, 2021, with effect from November 1, 2021, marked a significant expansion of the global patchwork of data protection regimes. For organizations that handle the personal information of people physically located in Mainland China, the PIPL introduces a distinct legal framework that cannot be treated as interchangeable with the EU's GDPR, even though commentators frequently draw the comparison. Compliance decisions made under one regime should not be assumed to satisfy the other, because the scope, definitions, and enforcement context differ.

For privacy officers and legal counsel, the PIPL matters because it establishes rules on the legal bases for processing personal information and sensitive personal information, as well as on disclosure. It builds on China's earlier Cybersecurity Law rather than replacing it, so organizations operating in or interacting with Mainland China may need to consider how these instruments interact. Because the PIPL's specific obligations flow from the statutory text and evolving regulatory guidance, teams should approach it as a discrete compliance workstream rather than an extension of existing EU-focused programs.

Who it's relevant to

Privacy Officers and Data Protection Professionals
Those responsible for organizational compliance need to understand that the PIPL is a distinct comprehensive framework governing the processing of personal information of people located in Mainland China. They should not assume that existing GDPR-aligned programs automatically satisfy PIPL obligations, and should treat the two regimes separately when assessing scope and requirements.
Legal Counsel
Legal teams advising on multi-jurisdictional data protection matters should be aware that the PIPL, adopted August 20, 2021, and effective November 1, 2021, addresses legal bases for processing and disclosure of personal and sensitive information, and builds on China's Cybersecurity Law. Because specific obligations depend on the statutory text and evolving guidance, counsel should verify current requirements before advising.
Compliance Teams at Organizations Handling Mainland China Data
Any organization processing the personal information of persons physically located in Mainland China falls within the PIPL's intended protective scope. Compliance teams should treat the PIPL as a separate workstream from EU-focused efforts, recognizing that the details of consent, cross-border transfers, and tracking technologies are not covered by this entry and must be assessed against the law itself.

Inside PIPL

Personal Information Protection Law (PIPL)
China's comprehensive data protection statute governing the processing of personal information of natural persons within China, and in certain cases processing that occurs outside China where it relates to individuals located in China. It sits alongside other Chinese laws such as the Cybersecurity Law and the Data Security Law, and readers should consult the full legal framework rather than treating PIPL in isolation.
Consent-based processing
PIPL recognizes consent as one legal basis for processing personal information, and where consent is relied upon it is generally expected to be voluntary, explicit, and informed. In the context of cookies and similar tracking technologies, this can mean that non-essential tracking may require the individual's consent, though the precise application to web tracking depends on Chinese regulatory guidance and is subject to evolving interpretation.
Separate consent requirements
For certain higher-risk activities, PIPL is generally understood to require a distinct, separate consent rather than bundled consent. This may include processing of sensitive personal information and, in some circumstances, cross-border transfers. How this maps onto cookie banners and tracking SDKs is not fully settled and should be assessed against current guidance.
Cross-border transfer conditions
PIPL sets conditions for transferring personal information outside China, which may include mechanisms such as security assessments, certification, or standard contractual arrangements depending on the circumstances. Cookie and advertising technologies that route data to servers or vendors outside China can implicate these rules, though the applicable mechanism depends on facts not covered by a general definition.
Individual rights
PIPL provides individuals with rights concerning their personal information, which may include rights to access, correct, delete, and to withdraw consent. Practitioners deploying tracking technologies should consider how these rights are honored operationally.
Scope beyond literal cookies
Because PIPL regulates the processing of personal information generally, technologies that are not literally cookies, such as pixels, SDKs, local storage, and device or fingerprinting techniques, can fall within its scope where they involve personal information. It is distinct from the EU's ePrivacy Directive and GDPR model, and consent or compliance achieved under EU frameworks does not automatically satisfy PIPL.

Common questions

Answers to the questions practitioners most commonly ask about PIPL.

Does complying with the GDPR mean I automatically comply with China's PIPL for cookies?
No. Although the PIPL and the GDPR share some structural similarities, they are distinct legal regimes with different definitions, consent standards, and cross-border transfer requirements. Compliance with one does not establish compliance with the other. Organizations operating in or targeting individuals in mainland China should assess PIPL obligations separately, and specific consent, notice, and localization rules may differ from EU practice. Any assessment of PIPL's precise requirements for cookies and similar technologies should be confirmed with counsel familiar with Chinese law.
Is the PIPL just China's version of the EU ePrivacy rules for cookies?
Not exactly. In the EU, the placing of and access to information on a user's device is primarily governed by the ePrivacy Directive and its national implementations, while the GDPR governs any subsequent processing of personal data. The PIPL is a broad personal information protection law rather than a device-storage-specific rule modeled on ePrivacy. Where cookies or similar technologies process personal information, the PIPL's general rules on lawful basis, consent, and transparency may apply, but the framework and terminology differ from the EU's two-instrument structure. The exact treatment of cookies under the PIPL depends on Chinese regulatory interpretation, which is outside the scope of this entry.
Which organizations should consider whether the PIPL applies to their cookie practices?
The PIPL can have extraterritorial reach, meaning it may apply to organizations outside mainland China that handle the personal information of individuals in China, including where the purpose is to provide products or services to them. Organizations with a website or service accessible from China, or that intentionally target users there, should evaluate whether their use of cookies, pixels, SDKs, or similar technologies falls within scope. Because applicability turns on facts not covered by this definition, a jurisdiction-specific legal assessment is advisable.
How does consent under the PIPL differ from what I already collect for EU users?
Consent standards vary between regimes, so an EU consent flow should not be assumed to satisfy the PIPL. The PIPL contains its own consent and notice requirements, and certain activities may call for separate or more specific consent under Chinese rules. Practically, this may mean configuring your consent management platform to present distinct notices and choices to users identified as being in China, rather than reusing the EU experience. The precise consent mechanics required by the PIPL should be verified with local counsel, as regulatory guidance in this area continues to develop.
Do I need to treat cross-border transfers of cookie-derived data differently under the PIPL?
Potentially, yes. The PIPL imposes its own conditions on transferring personal information outside mainland China, which are distinct from the EU's transfer mechanisms. If cookies, pixels, or SDKs result in personal information about individuals in China being sent to servers or vendors abroad, those data flows may trigger PIPL transfer obligations. Mapping where cookie-derived data is stored and processed is a useful first step, but the specific transfer requirements and any localization considerations fall outside this entry and should be assessed with qualified advisers.
Can a consent management platform ensure my cookie practices comply with the PIPL?
A CMP can support PIPL compliance by helping present notices, capture and log user choices, and apply different consent experiences by region, but no tool guarantees compliance. Meeting PIPL obligations also depends on legal judgment about scope, lawful basis, consent quality, record-keeping, and cross-border transfers, which a platform alone cannot resolve. Treat a CMP as one component of a broader compliance program and confirm your configuration against current Chinese regulatory expectations with appropriate legal input.

Common misconceptions

PIPL is essentially China's version of the GDPR, so GDPR-compliant cookie practices will satisfy it.
While PIPL shares some concepts with the GDPR, it is a separate law with its own requirements, including distinct rules on separate consent and cross-border transfers. Compliance with EU frameworks such as the GDPR or ePrivacy Directive does not automatically establish compliance with PIPL, and each regime should be assessed on its own terms.
PIPL only applies to organizations physically located in China.
PIPL can apply, in certain circumstances, to processing that occurs outside China where it relates to individuals located in China. Organizations should not assume they are out of scope solely because they lack a physical presence there; the precise reach depends on facts and current interpretation.
A single bundled consent covers all cookie and tracking activities under PIPL.
PIPL is generally understood to require separate consent for certain higher-risk processing, which may include sensitive personal information and some cross-border transfers. A blanket, bundled consent may not be sufficient for these activities, though the exact application to web tracking remains subject to regulatory guidance.

Best practices

Treat PIPL as a distinct legal regime and assess cookie and tracking practices against its requirements separately from any GDPR, UK, or US state law analysis, rather than assuming cross-regime equivalence.
Map which cookies, pixels, SDKs, local storage, and fingerprinting techniques process personal information and where that data flows, since technologies beyond literal cookies can fall within PIPL's scope.
Where consent is relied upon, design consent mechanisms that aim to be voluntary, explicit, and informed, and evaluate whether separate consent may be required for sensitive personal information or cross-border transfers.
Identify any cross-border data flows created by tracking vendors and assess which transfer mechanism, if any, may be required, recognizing that the applicable approach depends on the specific facts.
Build operational processes to honor individual rights such as access, correction, deletion, and withdrawal of consent in the context of tracking technologies.
Consult current Chinese regulatory guidance and qualified local legal counsel, and use consent management tools to support rather than substitute for that legal judgment, since PIPL's application to web tracking continues to evolve.