{
 "jurisdiction_id": "CN",
 "jurisdiction": "China (mainland)",
 "url": "https://dataprotection.gi/jurisdictions/china-mainland/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 46,
  "sub_modules": 57,
  "source_register": 19
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/china-mainland/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "A mature, enacted omnibus statute (PIPL) with implementing regulations and an active, multi-agency enforcement apparatus is in force.",
   "claims": [
    {
     "statement": "The PIPL confers enforcement authority jointly on multiple governmental departments — CAC, MIIT, the Ministry of Public Security, SAMR and financial regulators, plus local counterparts — with CAC taking a leading and coordinating role rather than acting as a single unified supervisory authority as under GDPR or CPRA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/top-5-operational-impacts-of-chinas-pipl-part-4-penalties-and-enforcement-mechanisms",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "China's data governance framework rests on three national laws (CSL 2017/amended 2025, DSL 2021, PIPL 2021), implemented at national level via the Regulations on Network Data Security Management, effective 1 January 2025.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/china-issues-the-regulations-on-network-data-security-management-what-s-important-to-know",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PIPL is China's first comprehensive data protection legislation and regulates personal information handling activities by personal information handlers and entrusted parties.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_pipl_.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PIPL Article 3 extends its territorial scope to the handling of personal information conducted outside China where the purpose is to provide products or services to, or to analyze/assess the behavior of, individuals located in China, or other purposes specified by law.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/analyzing-chinas-pipl-and-how-it-compares-to-the-eus-gdpr",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Offshore personal information handlers subject to PIPL under its extraterritorial provisions must establish a dedicated office or appoint a designated representative in China for personal information protection purposes (Art 53).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/analyzing-chinas-pipl-and-how-it-compares-to-the-eus-gdpr",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "green",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/china-mainland/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Lawful-basis and sensitive-data rules are enacted, detailed and actively enforced, though 'separate consent' remains only partially defined in official guidance.",
   "claims": [
    {
     "statement": "PIPL Article 13 permits processing without consent where necessary for contract performance or HR management under lawfully formulated labor policies, to perform legal responsibilities, to respond to public health emergencies, for public-interest news reporting, or for lawfully disclosed information; PIPL does not recognize 'legitimate interests' as a lawful basis, unlike GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/top-5-operational-impacts-of-chinas-pipl-part-2-obligations-and-rights",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Consent under PIPL must be informed, freely given and evidenced by a clear affirmative action, with a standing right of withdrawal (Arts 14–15); a heightened 'separate consent' is additionally required when handlers share PI with other handlers, publicly disclose PI, process sensitive PI, or transfer PI abroad (Arts 23, 25, 29, 39).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/top-5-operational-impacts-of-chinas-pipl-part-2-obligations-and-rights",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PIPL Article 28 defines sensitive personal information to include biometric identification information, religious beliefs, specially-designated status, medical health information, financial accounts, information on individuals' whereabouts, and personal information of minors under the age of 14.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/analyzing-chinas-pipl-and-how-it-compares-to-the-eus-gdpr",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Anonymized information is not deemed personal information under PIPL; anonymization is defined (Arts 4 & 73) as processing that renders data non-identifying and non-restorable to a specific natural person, while 'de-identification' functions as PIPL's pseudonymisation-equivalent concept.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/analyzing-chinas-pipl-and-how-it-compares-to-the-eus-gdpr",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "amber",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/china-mainland/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Substantive rights are enacted and broad, but the absence of a codified statutory response deadline creates residual ambiguity relative to GDPR-style regimes.",
   "claims": [
    {
     "statement": "Under PIPL, individuals have the right to access and make copies of their personal information, and personal information handlers must provide such information in a timely fashion.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/top-5-operational-impacts-of-chinas-pipl-part-2-obligations-and-rights",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Individuals are entitled to correct, supplement and update incomplete, inaccurate or outdated personal information and may request deletion of their personal information from handlers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/top-5-operational-impacts-of-chinas-pipl-part-2-obligations-and-rights",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Data subjects have the right to request an explanation regarding the use of their personal information and to refute a decision made by a handler solely through automated decision-making where it significantly affects them.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/top-5-operational-impacts-of-chinas-pipl-part-2-obligations-and-rights",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PIPL provides a right of portability whereby individuals may request that a personal information handler transfer their personal information to another handler; PIPL exceeds GDPR by granting individuals a right to bring claims against handlers who reject a rights request and a right to demand an explanation of handling rules.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/top-5-operational-impacts-of-chinas-pipl-part-2-obligations-and-rights",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PIPL requires personal information handlers to respond to access requests 'in a timely fashion' rather than specifying a codified numeric response deadline equivalent to GDPR's one-month rule.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/top-5-operational-impacts-of-chinas-pipl-part-2-obligations-and-rights",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/china-mainland/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Core accountability, DPIA, security and breach-notification duties are enacted and enforced, but the PIPO appointment threshold and processor ('entrusted party') definitions remain under-specified in binding text.",
   "claims": [
    {
     "statement": "Under PIPL Article 55, a personal information handler must conduct a personal information protection impact assessment prior to handling sensitive personal information, using personal information for automated decision-making, entrusting/sharing/disclosing personal information, transferring personal information abroad, or engaging in other processing with a major influence on individuals; the assessment must evaluate lawfulness/necessity, impact on individuals' rights, and adequacy of protective measures.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/top-5-operational-impacts-chinas-pipl-part-3-personal-information-protection-officer",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PIPL requires certain handlers to appoint a Personal Information Protection Officer (PIPO), but the precise processing-volume threshold triggering this requirement is not specified in the statute; analogous CAC draft measures reference thresholds around one million individuals' data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/top-5-operational-impacts-chinas-pipl-part-3-personal-information-protection-officer",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Unlike GDPR's universal Article 30 record-keeping duty applicable to controllers and processors alike, PIPL imposes record-of-processing obligations on handlers only for the categories triggering a DPIA, and requires retention of impact-assessment processing records for at least three years (Art 55).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_pipl_.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PIPL does not define 'entrusted parties' (the processor-equivalent role) as precisely as GDPR defines data processors, though it imposes obligations on such parties, including a duty to notify the handler and provide technical/administrative assistance in the event of a breach involving entrusted personal information.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_pipl_.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PIPL requires handlers to adopt organizational and technical measures to prevent unauthorized access, damage, leakage or loss of personal information, including internal management mechanisms, classification of personal information, encryption and de-identification, access controls, and periodic security training.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/top-5-operational-impacts-of-chinas-pipl-part-2-obligations-and-rights",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under PIPL Article 57, whenever a leak, distortion or loss of personal information occurs or might have occurred, handlers must adopt remedial measures and notify relevant departments and affected individuals of the information categories, causes and possible harm, the remedial measures taken and steps individuals can take to mitigate harm, and a method of contact; notification to individuals is excused where the handler adopts measures effectively avoiding harm.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/top-5-operational-impacts-chinas-pipl-part-3-personal-information-protection-officer",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Regulations on Network Data Security Management require a company processing personal data of more than 10 million individuals to establish a dedicated department and appoint a senior data-security executive, and to submit a data disposal plan to regulators upon a merger, acquisition, spin-off or insolvency affecting data security.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/china-issues-the-regulations-on-network-data-security-management-what-s-important-to-know",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "amber",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/china-mainland/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Transfer mechanisms are well-established and increasingly detailed, but thresholds have shifted multiple times since 2022 and important-data classification remains only partially settled, creating ongoing compliance uncertainty.",
   "claims": [
    {
     "statement": "PIPL Article 38 offers three cross-border data transfer mechanisms depending on the characteristics of the exporting entity: a CAC-led security assessment (mandatory for CIIOs and large-volume processors), a PI-protection certification issued by CAC-authorized professional institutions, or a standard-contract agreement with the overseas recipient based on CAC-issued clauses.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/top-5-operational-impacts-of-the-pipl-part-5-international-data-transfers",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Unlike GDPR, PIPL does not provide for cross-border transfers of personal information premised on a finding of 'adequate protection' in the recipient jurisdiction; all outbound transfers must instead satisfy one of PIPL's three domestic transfer mechanisms.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_pipl_.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Chinese Standard Contractual Clauses, effective 1 June 2023, require the cross-border data transfer agreement to be governed by Chinese law, use a single universal template regardless of the parties' controller/processor role, and be filed with the provincial CAC together with the impact assessment report within 10 working days of effectiveness.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-look-at-whats-in-chinas-new-sccs",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Parties to an SCC-based cross-border transfer must redo the impact assessment, update the transfer agreement, and re-file with the provincial CAC where circumstances materially change, including extension of retention period, changes in processing purpose/scope/category/volume/storage location/sensitivity, or changes in the destination country's data protection laws affecting data subjects.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-look-at-whats-in-chinas-new-sccs",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "CIIOs and entities processing large volumes of personal information must store citizens' personal information and important data locally in China, with overseas transfer conditioned on passing a CAC-led security assessment; the March 2024 CBDT Provisions relaxed thresholds so that non-CIIO handlers transferring between 100,000 and 1,000,000 individuals' data (or under 10,000 individuals' sensitive data) may use SCC/certification rather than a full security assessment, and exempted employee-data transfers from any CBDT mechanism regardless of volume where employment-law conditions are met.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/chinas-new-cross-border-data-transfer-regulations-what-you-need-to-know-and-do",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/china-mainland/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Financial-sector and employment-data overlays are documented, but health, education and insurance sector-specific DP overlays were not located in this pass and are flagged as a research gap.",
   "claims": [
    {
     "statement": "The People's Bank of China issued the Financial Data Security — Data Security Classification Guidelines establishing sector-specific data classification obligations for financial institutions, and the amended Anti-Money Laundering Law (effective 1 Jan 2025) requires financial institutions to protect the confidentiality of collected KYC/AML information consistent with CSL/DSL/PIPL and to report to the competent Chinese financial regulator before disclosing customers' KYC information or transactional records to foreign authorities.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/notes-from-the-asia-pacific-region-privacy-and-ai-developments-in-greater-china",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "MIIT found that a batch of applications, including WeChat and other Tencent products, illegally transferred users' contact-list and location data and used pop-up harassment, ordering their parent companies to make rectifications.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/china-adopts-national-privacy-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under the CBDT regulations, employee data transfers are exempt from any of the CBDT legal mechanisms irrespective of data volume, provided companies meet relevant Chinese employment-law conditions extending beyond data protection rules (e.g., a democratically consulted employee handbook).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/chinas-new-cross-border-data-transfer-regulations-what-you-need-to-know-and-do",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PIPL Article 67 provides that violations may be recorded into the 'credit files' of the processing entity under China's national social credit system, in addition to monetary penalties.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/analyzing-chinas-pipl-and-how-it-compares-to-the-eus-gdpr",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PIPL Article 60 designates financial regulators (which encompass insurance-sector oversight) among the sectoral supervisory authorities empowered to enforce PIPL within their respective designated areas.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/top-5-operational-impacts-of-chinas-pipl-part-4-penalties-and-enforcement-mechanisms",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/china-mainland/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Algorithm-transparency and anti-price-discrimination rules are enacted and enforced, but cookie-consent, opt-out-signal and clean-room-specific regimes are absent from China's framework.",
   "claims": [
    {
     "statement": "MIIT, CAC, MPS and SAMR jointly conducted enforcement campaigns (2020–2021) against apps engaging in illegal collection and use of personal information and harassing pop-up notifications, functioning as enforcement against dark-pattern-style practices absent a codified statutory prohibition.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/chinas-key-enforcement-agencies-and-lessons-learned-from-recent-actions",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Provisions on the Management of Algorithmic Recommendations in Internet Information Services (effective 1 March 2022) regulate algorithms used for content recommendation, requiring transparency and fairness and prohibiting practices that disrupt public order, including personalized price discrimination.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Cyberspace Administration of China",
     "source_url": "http://www.cac.gov.cn/2022-01/04/c_1642894606364259.htm",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PIPL requires that personal information processors conducting business marketing to individuals through automated decision-making simultaneously provide options that do not target an individual's personal characteristics, or offer ways for individuals to reject such marketing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/china-adopts-national-privacy-law",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/china-mainland/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "AI- and biometric-specific rules are extensive and rapidly evolving (including a 2025 CSL amendment), but genetic-data specificity is absent and state-surveillance carve-outs remain structurally unconstrained by PIPL's private-sector-facing rules.",
   "claims": [
    {
     "statement": "PIPL Article 24 requires personal information processors engaging in automated-decision-making-based marketing to provide non-targeted options or simple rejection mechanisms, addressing algorithmic price discrimination and profiling-driven differential treatment.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/china-adopts-national-privacy-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Data subjects have the right to request an explanation regarding the use of personal information in automated decision-making and to refute a decision made solely by automated means where it significantly affects them.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/top-5-operational-impacts-of-chinas-pipl-part-2-obligations-and-rights",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "China's amended Cybersecurity Law, passed in October 2025, brings artificial intelligence governance within the CSL's scope and raises the maximum fine for companies to CNY50 million or 5% of the previous year's turnover, with individual penalties up to CNY1 million.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/notes-from-the-asia-pacific-region-strong-start-to-2026-for-china-s-data-ai-governance-landscape",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PIPL Article 28 classifies biometric identification information as sensitive personal information requiring separate consent for processing, and CAC has issued dedicated measures governing the security of facial recognition technology deployment.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/china-measures-security-facial-recognition-technology",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PIPL's private-sector-facing protections do not prevent the PRC central government from accessing data, and legal commentators have observed little indication of legal limits on government surveillance or meaningful civil-society oversight mechanisms in this area.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/china-adopts-national-privacy-law",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/china-mainland/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Minors' data receives clear sensitive-category and parental-consent treatment with active 2025-2026 filing enforcement, but dependent-adult protections and minor-specific profiling bans were not located in this research pass.",
   "claims": [
    {
     "statement": "PIPL classifies the personal information of minors under the age of 14 as sensitive personal information, and CAC's 2019 Provisions on Cyber Protection of Children's Personal Information (China's COPPA-equivalent) requires parental/guardian consent for handling children's data; a CAC directive issued 28 December 2025 further requires companies collecting minors' personal information to complete compliance audits and file supporting materials with local CAC offices by 31 January 2026.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/notes-from-the-asia-pacific-region-strong-start-to-2026-for-china-s-data-ai-governance-landscape",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PIPL permits close relatives of a deceased individual to exercise that individual's data protection rights, but no equivalent statutory protection specific to living dependent adults (e.g., elderly or mentally incapacitated persons) was identified.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_pipl_.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "green",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/china-mainland/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "China maintains an active, multi-agency enforcement apparatus with substantial recent fines, an evolving penalty ceiling (raised again via the 2025 CSL amendment), and continuous rulemaking activity through mid-2026.",
   "claims": [
    {
     "statement": "PIPL Article 63 grants supervisory authorities investigatory powers including interviews, document review, on-site inspections, and equipment seizure/confiscation; the law creates a two-tier penalty structure with general violations fined up to RMB1 million for handlers and RMB100,000 for responsible officers, and grave violations fined up to RMB50 million or 5% of the previous year's annual revenue for handlers and RMB100,000–1 million for officers, alongside rectification orders, business suspension, and license revocation powers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/top-5-operational-impacts-of-chinas-pipl-part-4-penalties-and-enforcement-mechanisms",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "CAC fined Didi Global approximately RMB8.026 billion in 2022 for violations of the CSL, DSL and PIPL, and separately fined academic database provider CNKI RMB50 million for PIPL and CSL violations in 2023, illustrating sustained large-scale enforcement activity.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/china-cac-fines-didi-rmb-8-billion-csl-dsl-and%C2%A0pipl",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PIPL Article 70 grants standing to file public-interest actions — China's functional equivalent of class actions — to the People's Procuratorate, statutorily designated consumer organizations, and organizations designated by CAC, where a handler's infringement affects a large number of individuals.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/top-5-operational-impacts-of-chinas-pipl-part-4-penalties-and-enforcement-mechanisms",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PIPL Article 69 shifts the burden of proof to the defendant handler once a data subject demonstrates an infringement of their personal-information rights, and courts assessing damages are not limited to actual losses but may instead rely on the gains the handler obtained from the infringing conduct.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/top-5-operational-impacts-of-chinas-pipl-part-4-penalties-and-enforcement-mechanisms",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Within the 180 days preceding this run: China's amended Cybersecurity Law (passed October 2025) raised the maximum corporate fine to CNY50 million or 5% of prior-year turnover and folded AI governance into CSL's scope; a CAC directive dated 28 December 2025 required companies collecting minors' personal information to complete compliance audits and submit filings to local CAC offices by 31 January 2026; and on 17 June 2026 TC260 released draft amendments to the non-binding GB/T 35273 national standard, adding a new chapter on legal-basis guidance and AI-driven governance updates, with public comment open until 16 August 2026.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/notes-from-the-asia-pacific-region-strong-start-to-2026-for-china-s-data-ai-governance-landscape",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}