Jurisdiction Guides / Asia-Pacific
China Privacy & Data Protection Laws
Every regime below can apply to a business handling China residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
Article 3 applies PIPL to all processing of personal information within China's borders, and separately extends extraterritorially to processing outside China where it is for the purpose of providing products/services to individuals in China, or analyzing/evaluating their behavior — a dual offering-goods/monitoring-behavior test distinct from but similar in effect to GDPR Art. 3. Article 72 exempts natural persons' purely personal/household processing; state organs are subject to a distinct chapter of obligations rather than being exempted, and health/financial data are treated as sensitive personal information requiring heightened, not reduced, protection. Two implementing instruments materially changed day-to-day compliance: the Network Data Security Management Regulations (State Council, effective January 1, 2025) consolidated data-classification, breach-reporting, and cross-border rules across PIPL, the Cybersecurity Law and the Data Security Law; and the Administrative Measures for Personal Information Protection Compliance Audits (effective May 1, 2025) require handlers of large volumes of personal information to conduct periodic compliance audits. Foreign handlers caught by Art. 3 must also designate a China-based representative and file its details with the regulator.
Sector-Specific Law · 1
The PIPL is only one leg of China's data regime, and for many businesses it is not the binding one. The Cybersecurity Law imposes security, real-name registration, incident-reporting and cooperation duties on 'network operators' — a definition broad enough in practice to reach almost any business that owns or administers its own network in mainland China — and imposes markedly heavier obligations on operators of critical information infrastructure, including annual security evaluations, procurement security reviews for products affecting national security, and domestic storage of personal information and important data. The Data Security Law adds a classification-and-grading regime across ALL data, not just personal data, with the heaviest duties attaching to 'important data' and to data with a bearing on national security, plus a rule against providing data stored in China to foreign judicial or law-enforcement authorities without Chinese approval. Marked 'check': sectoral 'important data' catalogues are issued by individual regulators and the CII identification rules are set sector by sector, so whether either regime binds a given business is a fact-specific question this atlas cannot answer.
Children & Minors Protections · 1
Three instruments stack. PIPL Art. 31 classifies the personal information of minors under 14 as sensitive personal information, requiring the consent of a parent or other guardian and a dedicated set of processing rules. The 2019 CAC Provisions supply the operational detail for that under-14 group, including notice, consent, and deletion duties. The 2023 State Council Regulations on the Protection of Minors in Cyberspace — 60 articles across seven chapters, in force January 1, 2024, and China's first comprehensive minors-online legislation — go wider than personal data, covering content governance, prevention of internet addiction, cyberbullying, and the responsibilities of platforms and of government departments. A business scoping only to the under-14 personal-data rules will miss the Regulations' broader platform duties, which reach minors generally rather than just under-14s.
Cross-Border Data Transfer · 1
Art. 38 requires a handler exporting personal information to satisfy one of three routes first: a CAC security assessment, the CAC's standard contract with the overseas recipient, or certification by a CAC-accredited body. Art. 40 layers a data-localisation requirement on top for critical information infrastructure operators and for handlers processing above the volume threshold — they must store personal information collected in China domestically, and pass a security assessment to export it. The March 2024 Provisions materially relaxed the middle of that regime by raising the volume thresholds and creating exemptions: transfers of non-sensitive personal information covering fewer than 100,000 individuals, counted cumulatively from January 1 of the current year, need none of the three mechanisms. The thresholds are cumulative annual figures, not per-transfer, which is the detail businesses most often get wrong. Free-trade-zone negative lists can vary the position further, so confirm against the relevant FTZ list before relying on an exemption.
Data Security & Breach Notification · 1
Art. 57 requires a handler to take remedial measures immediately where personal information is or may be leaked, tampered with, or lost, and to notify both the departments performing personal information protection duties and the affected individuals, stating the categories of information involved, the cause and possible harm, the remedial and mitigation measures taken, and contact details. Two features distinguish it from the GDPR model. First, there is no hour-count: the statute says 'immediately', with operational timing left to subordinate measures, so a reviewer should check current CAC rules rather than assuming a 72-hour analogue. Second, the individual-notification duty can be switched off — if the handler's measures can effectively avoid the harm, it need not notify individuals, unless the regulator decides otherwise. PIPL Art. 57 also sits alongside the incident-reporting duties in the Cybersecurity Law and Data Security Law, which may bite first for network operators and important-data handlers.
Other Asia-Pacific jurisdictions