The framework
The PIPL took effect 1 November 2021 and sits on top of the Cybersecurity Law (2017) and Data Security Law (2021). It applies extraterritorially to processing of individuals in China for the purpose of providing products or services or analyzing their behavior, and offshore handlers must appoint a local representative or entity.
Consent does the heavy lifting. The law lists other bases (contract, HR management, legal duties, emergencies, limited news and public-interest grounds) but omits anything like legitimate interests, so most commercial processing rests on consent, and 'separate consent', a distinct, specific act, is required for sensitive personal information, disclosure, sharing with third parties, and cross-border transfers. Automated decision-making used for marketing must offer an option not based on personal characteristics, which is why Chinese apps carry a personalization toggle.
The Network Data Security Management Regulations, effective 1 January 2025, consolidated and extended these duties across network data handlers, tightening breach reporting, platform obligations and important-data governance. In March 2024 the CAC's Provisions on Promoting and Regulating Cross-Border Data Flows eased transfer thresholds meaningfully: transfers below set volume thresholds, HR data, and data needed for cross-border contracts (travel, payments, shipping) were exempted from the heavier mechanisms, and free trade zones may run negative lists. DiDi's RMB 8.026B fine in 2022 remains the enforcement marker, the CAC runs repeated app crackdown campaigns, and transfer enforcement has arrived, with Shanghai's cyberspace regulator fining Trip.com RMB 10M in June 2026 for moving personal information abroad without the required assessment. An amended Cybersecurity Law in force since 1 January 2026 raised penalties and tied the statute more closely to the PIPL.
Key instruments
Personal Information Protection Law (PIPL)
Comprehensive national privacy statute: consent-centric bases, separate consent for sensitive data and transfers, data subject rights, DPO-style personnel, and fines to 5% of turnover.
Network Data Security Management Regulations
State Council regulations operationalizing PIPL, DSL and CSL duties for network data handlers, including platform rules, important-data obligations and incident reporting.
Provisions on Promoting and Regulating Cross-Border Data Flows
Relaxed the transfer regime: exemptions for low-volume transfers, HR data and contract-necessary transfers; raised thresholds for security assessment; enabled free trade zone negative lists.
Marketing and advertising
Consent is the workhorse basis, and 'separate consent' is required for sensitive data, cross-border transfers, and sharing with other handlers. No legitimate-interest basis exists. Treat the consent note above as the planning rule; the penalty line below is what mispricing it costs.
Quiet retargeting of Chinese users is off the table. Personalization requires disclosure and an off switch, third-party data sharing needs separate consent, and moving CRM or analytics data out of China needs a sanctioned transfer route unless an exemption applies. Most global brands regionalize their China stack entirely.
Cross-border transfers
Three routes: CAC security assessment, Chinese standard contract filing, or certification, whose implementing measures took effect January 1, 2026. Thresholds were relaxed in March 2024, but important data and large-volume transfers still need assessment.
Enforcement and penalties
Up to RMB 50M or 5% of the prior year's turnover, plus personal liability for responsible individuals and business suspension.