WorldPrivacyAtlas
Laws by country

Comprehensive Privacy Law

Personal Information Protection Law of the People's Republic of China

PIPL

China · November 1, 2021

Article 3 applies PIPL to all processing of personal information within China's borders, and separately extends extraterritorially to processing outside China where it is for the purpose of providing products/services to individuals in China, or analyzing/evaluating their behavior — a dual offering-goods/monitoring-behavior test distinct from but similar in effect to GDPR Art. 3. Article 72 exempts natural persons' purely personal/household processing; state organs are subject to a distinct chapter of obligations rather than being exempted, and health/financial data are treated as sensitive personal information requiring heightened, not reduced, protection. Two implementing instruments materially changed day-to-day compliance: the Network Data Security Management Regulations (State Council, effective January 1, 2025) consolidated data-classification, breach-reporting, and cross-border rules across PIPL, the Cybersecurity Law and the Data Security Law; and the Administrative Measures for Personal Information Protection Compliance Audits (effective May 1, 2025) require handlers of large volumes of personal information to conduct periodic compliance audits. Foreign handlers caught by Art. 3 must also designate a China-based representative and file its details with the regulator.

PIPL, Arts. 3, 72, 74 (adopted August 20, 2021)Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.