Data Security & Breach Notification
Personal Information Protection Law — remedial measures and breach notification
China · November 1, 2021
Art. 57 requires a handler to take remedial measures immediately where personal information is or may be leaked, tampered with, or lost, and to notify both the departments performing personal information protection duties and the affected individuals, stating the categories of information involved, the cause and possible harm, the remedial and mitigation measures taken, and contact details. Two features distinguish it from the GDPR model. First, there is no hour-count: the statute says 'immediately', with operational timing left to subordinate measures, so a reviewer should check current CAC rules rather than assuming a 72-hour analogue. Second, the individual-notification duty can be switched off — if the handler's measures can effectively avoid the harm, it need not notify individuals, unless the regulator decides otherwise. PIPL Art. 57 also sits alongside the incident-reporting duties in the Cybersecurity Law and Data Security Law, which may bite first for network operators and important-data handlers.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.