DIGITAL PRIVACY REGULATIONSThe Worldwide Register of Data Privacy Law
Tracking 197 jurisdictions
Language: English
Asia-Pacific · In force · Opt-in

🇨🇳 China Data Privacy Laws

China's PIPL is stricter than the GDPR where it counts for marketers: there is no legitimate-interest basis, targeted advertising requires a non-personalized alternative, and cross-border transfers run through government-supervised channels.

Updated September 28, 2026 · digitalprivacyregs.com
Status
In force
Consent model
Opt-in
Primary law
Personal Information Protection Law (PIPL) + Data Security Law + Cybersecurity Law
Year
2021
Authority
Cyberspace Administration of China (CAC)
Marketing consent
Consent is the workhorse basis, and 'separate consent' is required for sensitive data, cross-border transfers, and sharing with other handlers. No legitimate-interest basis exists.
Transfers
Three routes: CAC security assessment, Chinese standard contract filing, or certification, whose implementing measures took effect January 1, 2026. Thresholds were relaxed in March 2024, but important data and large-volume transfers still need assessment.
Penalties
Up to RMB 50M or 5% of the prior year's turnover, plus personal liability for responsible individuals and business suspension.

The framework

The PIPL took effect 1 November 2021 and sits on top of the Cybersecurity Law (2017) and Data Security Law (2021). It applies extraterritorially to processing of individuals in China for the purpose of providing products or services or analyzing their behavior, and offshore handlers must appoint a local representative or entity.

Consent does the heavy lifting. The law lists other bases (contract, HR management, legal duties, emergencies, limited news and public-interest grounds) but omits anything like legitimate interests, so most commercial processing rests on consent, and 'separate consent', a distinct, specific act, is required for sensitive personal information, disclosure, sharing with third parties, and cross-border transfers. Automated decision-making used for marketing must offer an option not based on personal characteristics, which is why Chinese apps carry a personalization toggle.

The Network Data Security Management Regulations, effective 1 January 2025, consolidated and extended these duties across network data handlers, tightening breach reporting, platform obligations and important-data governance. In March 2024 the CAC's Provisions on Promoting and Regulating Cross-Border Data Flows eased transfer thresholds meaningfully: transfers below set volume thresholds, HR data, and data needed for cross-border contracts (travel, payments, shipping) were exempted from the heavier mechanisms, and free trade zones may run negative lists. DiDi's RMB 8.026B fine in 2022 remains the enforcement marker, the CAC runs repeated app crackdown campaigns, and transfer enforcement has arrived, with Shanghai's cyberspace regulator fining Trip.com RMB 10M in June 2026 for moving personal information abroad without the required assessment. An amended Cybersecurity Law in force since 1 January 2026 raised penalties and tied the statute more closely to the PIPL.

Key instruments

Personal Information Protection Law (PIPL)

2021 · In force

Comprehensive national privacy statute: consent-centric bases, separate consent for sensitive data and transfers, data subject rights, DPO-style personnel, and fines to 5% of turnover.

Official source →

Network Data Security Management Regulations

2024 · In force from 1 Jan 2025

State Council regulations operationalizing PIPL, DSL and CSL duties for network data handlers, including platform rules, important-data obligations and incident reporting.

Official source →

Provisions on Promoting and Regulating Cross-Border Data Flows

2024 · In force

Relaxed the transfer regime: exemptions for low-volume transfers, HR data and contract-necessary transfers; raised thresholds for security assessment; enabled free trade zone negative lists.

Official source →

Marketing and advertising

Consent is the workhorse basis, and 'separate consent' is required for sensitive data, cross-border transfers, and sharing with other handlers. No legitimate-interest basis exists. Treat the consent note above as the planning rule; the penalty line below is what mispricing it costs.

Quiet retargeting of Chinese users is off the table. Personalization requires disclosure and an off switch, third-party data sharing needs separate consent, and moving CRM or analytics data out of China needs a sanctioned transfer route unless an exemption applies. Most global brands regionalize their China stack entirely.

Cross-border transfers

Three routes: CAC security assessment, Chinese standard contract filing, or certification, whose implementing measures took effect January 1, 2026. Thresholds were relaxed in March 2024, but important data and large-volume transfers still need assessment.

Enforcement and penalties

Up to RMB 50M or 5% of the prior year's turnover, plus personal liability for responsible individuals and business suspension.

Primary sources

Cite this page: "China Data Privacy Laws." Digital Privacy Regulations, September 28, 2026, https://digitalprivacyregs.com/china.html. Accessed [date].