Chinese Data Privacy Laws: Requirements, Transfers, and Penalties

China regulates data through three overlapping statutes: the Cybersecurity Law (2017), the Data Security Law (2021), and the Personal Information Protection Law (2021). Together, these Chinese data privacy laws govern how personal and non-personal data is collected, stored, processed, and moved across borders, and they reach foreign organizations that handle data belonging to people located in China even when those organizations have no office there. Compliance is demanding, penalties can reach 50 million RMB or 5% of annual revenue, and enforcement has been accelerating.

The Three Laws and What Each One Covers

The Cybersecurity Law focuses on network security. It requires operators to protect system integrity, prevent intrusions, and maintain the confidentiality and availability of online data.1DigiChina. Cybersecurity Law of the People’s Republic of China It also introduced the Multi-Level Protection Scheme, which classifies network systems into five tiers based on the potential impact of a breach and imposes corresponding security obligations, including periodic external security reviews for most commercial systems.

The Data Security Law treats data as a national strategic asset. It ranks all data by importance to economic development, public welfare, and national security, and it applies whether or not the data is personal.2DigiChina. Data Security Law of the People’s Republic of China Companies handling data classified as “important” or “core” face export restrictions, periodic risk assessments, and steeper penalties.

The Personal Information Protection Law (PIPL) is the closest Chinese equivalent to the EU’s GDPR. It governs the collection, processing, storage, and transfer of personal information, gives individuals enforceable rights over their data, and places substantive duties on the organizations that handle it.3National People’s Congress of the People’s Republic of China. Personal Information Protection Law of the People’s Republic of China

Who Has to Comply

The PIPL applies to any organization processing personal information of people located in China, regardless of where the organization is based. Two triggers reach foreign companies with no Chinese presence: processing data to provide products or services to people in China, and analyzing or evaluating the behavior of people in China.3National People’s Congress of the People’s Republic of China. Personal Information Protection Law of the People’s Republic of China An offshore e-commerce site shipping to Chinese consumers, a SaaS provider with Chinese users, or an analytics firm profiling Chinese browsing behavior all fall within scope.

Foreign organizations caught by these extraterritorial provisions must designate a local representative or establish an office in China to handle data protection matters, and must report the representative’s name and contact information to the relevant authorities.4National People’s Congress of the People’s Republic of China. Personal Information Protection Law of the People’s Republic of China The representative is the point of contact for regulators and bears responsibility for on-the-ground compliance.

How the Data Is Classified

The obligations that attach to any given dataset depend heavily on how it is classified. Misclassify, and you either waste compliance spending or take on serious legal exposure.

Personal Information and Sensitive Personal Information

Personal information is any recorded data relating to an identified or identifiable person, excluding data that has been properly anonymized.3National People’s Congress of the People’s Republic of China. Personal Information Protection Law of the People’s Republic of China Sensitive personal information is a subcategory that includes biometrics, medical records, financial accounts, location tracking, and any personal information of minors under 14. The test is whether a leak or misuse could result in discrimination or serious harm to a person’s safety or finances.

Processing sensitive personal information requires a “specific purpose and sufficient necessity,” and organizations must obtain separate consent rather than folding it into a general consent form. The individual must be told why the data is needed and what could happen if it is compromised.

Important Data and Core Data

The Data Security Law defines “important data” as information whose compromise could affect national security, public welfare, or critical economic sectors. “Core data” sits above that and relates to national security, economic lifelines, and major public interests.2DigiChina. Data Security Law of the People’s Republic of China Each industry and region maintains its own catalog of what qualifies as important data, so classification continues to evolve. Organizations handling important data must conduct periodic risk assessments and file reports with regulators.

Lawful Bases for Processing

Consent is the most commonly invoked basis under the PIPL, and it must be informed, voluntary, and explicit. But processing can also be lawful when necessary to perform a contract with the individual, carry out a statutory obligation, respond to a public health emergency, protect life or property in an emergency, process publicly available information within reasonable limits, or handle data for public-interest news reporting.5Personal Information Protection Law. Article 13

Choosing the right basis matters. If you rely on consent and the person later withdraws it, you cannot retroactively claim a different basis. Processing must stop unless another basis independently applied from the start. Withdrawal itself cannot be penalized or trigger degraded service.

Rights of Individuals

The PIPL gives individuals a set of enforceable rights that go further than many people expect:

  • Right to know and access what personal information an organization holds, how it is used, and who it has been shared with.
  • Right to correct inaccurate or incomplete data.
  • Right to delete data once the original purpose is fulfilled, when a service relationship ends, or when consent is withdrawn.
  • Right to withdraw consent at any time, without the process being made unreasonably difficult.
  • Right to data portability under certain conditions.
  • Right to an explanation of automated decisions that significantly affect the individual, and the right to refuse decisions made solely by algorithms.

The right to explanation applies broadly rather than being confined to credit scoring or a single industry, and these rights are now appearing in enforcement actions.3National People’s Congress of the People’s Republic of China. Personal Information Protection Law of the People’s Republic of China

What Data Processors Must Do

Internal Governance

Organizations must designate a specific person or department responsible for data protection. The role functions similarly to a GDPR Data Protection Officer, serving as the internal compliance lead and the contact for government audits. Large-scale processors and those handling sensitive personal information face elevated obligations, including regular compliance audits.

Impact Assessments

A Personal Information Protection Impact Assessment is required before:

  • Processing sensitive personal information
  • Using personal information for automated decision-making
  • Sharing personal information with third parties or making it public
  • Transferring personal information outside China
  • Any other processing that could significantly affect individual rights

Each assessment must document the purpose of the processing, the risks to individuals, and the safeguards in place. Reports must be kept on file for at least three years, and regulators can demand them during inspections.6Personal Information Protection Law. Article 55 Not having the record is itself a violation.

Breach Response

When a data breach happens or is likely to happen, organizations must immediately take remedial steps and notify both regulators and affected individuals. The notification must cover the types of personal information involved, the cause, the possible harm, what the organization is doing about it, and what individuals can do to protect themselves. An organization can skip notifying individuals only if it believes its measures effectively prevent harm, but regulators can override that judgment and order notification.

Cross-Border Data Transfers

Moving personal information or important data out of China is the most compliance-intensive area under the framework, and the rules changed significantly in 2024.

Data Localization

Critical information infrastructure operators (CIIOs) and personal information processors that meet volume thresholds set by the Cyberspace Administration of China (CAC) must store all personal information collected in China on domestic servers. Any transfer abroad requires a government-led security assessment.7Personal Information Protection Law. Article 40 For CIIOs, localization is absolute; there is no alternative pathway.

Three Transfer Mechanisms

Non-CIIOs have three primary routes for lawfully transferring personal information abroad:

  • A CAC security assessment, which is a government review of the transfer’s risks, the destination country’s legal protections, and the adequacy of contractual arrangements. This is mandatory for high-volume transfers.
  • A CAC-issued standard contract that dictates the terms between the Chinese entity and the overseas recipient.8China Law Translate. Measures on Standard Contracts for the Export of Personal Information
  • A personal information protection certification from a government-recognized professional institution.

All three require a prior impact assessment, and the individual whose data is being transferred must give separate consent.

When a Security Assessment Is Required

The CAC security assessment is mandatory when a CIIO transfers any personal information or important data abroad, or when a non-CIIO transfers the personal information of more than one million individuals, or the sensitive personal information of more than 10,000 individuals, in a calendar year. The count runs from January 1 and is deduplicated across individuals.

2024 Exemptions

In March 2024, the CAC finalized provisions that eased cross-border transfer requirements in several common scenarios. Transfers that do not involve personal information or important data, common in B2B trade and academic cooperation, are fully exempt from the security assessment, standard contract, and certification requirements. Personal data merely transiting through China without being combined with domestically sourced data is also exempt.

Several safe-harbor situations allow transfers of personal information without triggering the full mechanisms:

  • Non-sensitive personal information of fewer than 100,000 individuals in a calendar year, other than by CIIOs.
  • Employee data transferred as necessary for HR management under a labor contract or employment policy.
  • Personal data transferred to perform a contract with the individual, including cross-border commerce, international remittances, hotel bookings, and visa services.
  • Personal data transferred in an emergency to protect life or property.

These exemptions substantially reduced the compliance burden for small and mid-sized foreign companies that previously had to run every routine transfer through the full machinery.

Penalties

The penalty structure has two tiers, and the jump between them is steep.

Non-Serious Violations

Regulators can order corrections, issue warnings, confiscate illegal gains, and order apps to suspend or terminate services. Fines run up to 1 million RMB for the organization. Individual managers directly responsible face personal fines of 10,000 to 100,000 RMB.9China Law Translate. Personal Information Protection Law of the People’s Republic of China

Serious Violations

When regulators classify a violation as serious, the numbers escalate. Provincial-level or higher authorities can impose fines up to 50 million RMB or 5% of the previous year’s annual revenue, and can suspend or revoke business licenses. Individual managers face personal fines of 100,000 to 1 million RMB and can be banned from senior management positions for a designated period.3National People’s Congress of the People’s Republic of China. Personal Information Protection Law of the People’s Republic of China

The Data Security Law adds another layer. Mishandling core national data can result in fines of 2 million to 10 million RMB, plus suspension of operations or revocation of licenses.2DigiChina. Data Security Law of the People’s Republic of China

Civil Liability

Individuals can also sue for damages. The burden of proof is inverted: the data processor must prove it was not at fault, rather than the individual proving fault. Courts calculate compensation based on the individual’s actual losses or the processor’s gains from the infringement, and where neither figure can be determined, the court sets an amount at its discretion.10Personal Information Protection Law. Article 69 This reversed burden makes civil claims a realistic option for affected individuals.

Enforcement in Practice

Enforcement has been picking up. In recent actions, authorities penalized the Shanghai subsidiary of a European luxury brand for transferring personal information to its French headquarters without conducting a security assessment, signing standard contractual clauses, or obtaining certification. The subsidiary also failed to obtain separate consent for the cross-border transfer and neglected basic security measures such as encryption. Regulators have also targeted domestic companies for activating cloud synchronization on public-facing devices without adequate safeguards. Cross-border transfers are the most closely scrutinized area.

Employee and Workplace Data

Employers get a carve-out under the PIPL. When processing is necessary to perform a labor contract, manage social security, or carry out HR administration under legally adopted employment policies or collective contracts, separate individual consent is not required.5Personal Information Protection Law. Article 13 Routine payroll, benefits, and workforce management therefore do not need consent forms for each action.

The carve-out has limits. Processing sensitive employee information such as biometrics for access control, health screening results, or background check data still triggers the sensitive personal information rules: separate consent, documented necessity, and heightened security. Transferring employee data to a foreign parent for centralized HR falls under the cross-border transfer rules, though the 2024 exemption for HR-related transfers under a labor contract or employment policy eases that step for routine cases.