A mature, enacted omnibus statute (PIPL) with implementing regulations and an active, multi-agency enforcement apparatus is in force.
Primary frameworkPersonal Information Protection Law (PIPL, 2021) together with the Cybersecurity Law (CSL, 2017/amended 2025) and Data Security Law (DSL, 2021)
Traffic-light rationale — GreenA mature, enacted omnibus statute (PIPL) with implementing regulations and an active, multi-agency enforcement apparatus is in force.
Sub-modules (5)
Regulator And AuthorityGreen
CAC is the lead/coordinating supervisory authority; MIIT, MPS, SAMR and financial regulators exercise delegated enforcement in their respective domains, unlike the single-authority models of GDPR/CPRA.
Claims: CLM-CN-1a2b3c4d
Act And InstrumentsGreen
The CSL/DSL/PIPL triad forms the statutory core, implemented via the Network Data Security Management Regulations (eff. 1 Jan 2025) and numerous CAC secondary rules.
Claims: CLM-CN-2b3c4d5e
Material ScopeGreen
PIPL governs personal information handling activities undertaken by personal information handlers and entrusted parties (the processor-equivalent concept).
Claims: CLM-CN-3c4d5e6f
Territorial ScopeGreen
Article 3 gives PIPL extraterritorial reach, analogous to GDPR Art 3(2), covering overseas handling aimed at providing products/services to, or analyzing/assessing the behavior of, individuals in China.
Claims: CLM-CN-4d5e6f70
Regulator Registration And FilingAmber
Offshore handlers caught by Article 3 must establish a dedicated office or appoint a representative in China and report identifying details to the competent authority (Art 53).
Claims: CLM-CN-5e6f7081
Category narrative97 words
China's data protection regime rests on three interlocking national laws — the Cybersecurity Law (CSL, 2017, amended 2025), the Data Security Law (DSL, 2021) and the Personal Information Protection Law (PIPL, 2021, in force 1 Nov 2021) — supplemented by the Network Data Security Management Regulations (effective 1 Jan 2025). The Cyberspace Administration of China (CAC) holds the lead coordinating role but enforcement authority is shared across MIIT, the Ministry of Public Security, SAMR, financial regulators and their local counterparts. Material scope covers 'personal information handlers' and 'entrusted parties' (processor-equivalent), and the regime has explicit extraterritorial reach.
Sources and claims (5)
ConfirmedIAPP — The PIPL confers enforcement authority jointly on multiple governmental departments — CAC, MIIT, the Ministry of Public Security, SAMR and financial regulators, plus local counterparts — with CAC taking a leading and coordinating role rather than acting as a single unified supervisory authority as under GDPR or CPRA.
ConfirmedIAPP — China's data governance framework rests on three national laws (CSL 2017/amended 2025, DSL 2021, PIPL 2021), implemented at national level via the Regulations on Network Data Security Management, effective 1 January 2025.
ConfirmedOneTrust DataGuidance — PIPL is China's first comprehensive data protection legislation and regulates personal information handling activities by personal information handlers and entrusted parties.
ConfirmedIAPP — PIPL Article 3 extends its territorial scope to the handling of personal information conducted outside China where the purpose is to provide products or services to, or to analyze/assess the behavior of, individuals located in China, or other purposes specified by law.
ConfirmedIAPP — Offshore personal information handlers subject to PIPL under its extraterritorial provisions must establish a dedicated office or appoint a designated representative in China for personal information protection purposes (Art 53).
Lawful-basis and sensitive-data rules are enacted, detailed and actively enforced, though 'separate consent' remains only partially defined in official guidance.
Primary frameworkPIPL Chapter II, Arts 13–30; GB/T 35273 (Personal Information Security Specification, amendments proposed June 2026)
Traffic-light rationale — GreenLawful-basis and sensitive-data rules are enacted, detailed and actively enforced, though 'separate consent' remains only partially defined in official guidance.
Sub-modules (4)
Lawful BasesGreen
Article 13 lists non-consent lawful bases (contract performance/HR management, statutory duties, public-health emergencies, news reporting in the public interest, lawfully disclosed information); PIPL does not recognize a GDPR-style 'legitimate interests' basis.
Claims: CLM-CN-6f708192
Consent ThresholdsAmber
Consent must be informed, freely given, evidenced by clear action and revocable (Arts 14–15); 'separate consent' (a higher, purpose-specific standard) is required for sharing, public disclosure, sensitive-data processing and cross-border transfer (Arts 23, 25, 29, 39).
Claims: CLM-CN-70819a3b
Special CategoriesGreen
Article 28 defines sensitive personal information broadly — biometric identification, religious beliefs, specially-designated status, medical/health data, financial accounts, location/whereabouts data, and personal information of minors under 14 — a wider sweep than GDPR Art 9.
Claims: CLM-CN-8192a3b4
Pseudonymisation And AnonymisationGreen
Anonymized information (rendered permanently non-identifiable and non-restorable) falls outside PIPL's scope of 'personal information' (Arts 4 & 73); PIPL uses 'de-identification' as its pseudonymisation-equivalent concept.
Claims: CLM-CN-92a3b4c5
Category narrative90 words
PIPL Chapter II sets out non-consent lawful bases (contract performance, HR management, statutory duties, public health emergencies, news reporting, lawfully disclosed information) alongside consent; unlike GDPR, PIPL does not recognize 'legitimate interests'. Elevated 'separate consent' is required for sensitive categories, sharing, public disclosure and cross-border transfers. Sensitive personal information (Art 28) is broadly defined to include biometric data, religious beliefs, specially-designated status, health, financial accounts, location data and the personal information of minors under 14. Anonymized data is excluded from scope, and 'de-identification' (pseudonymisation) is recognized as a risk-mitigation concept.
Sources and claims (4)
ConfirmedIAPP — PIPL Article 13 permits processing without consent where necessary for contract performance or HR management under lawfully formulated labor policies, to perform legal responsibilities, to respond to public health emergencies, for public-interest news reporting, or for lawfully disclosed information; PIPL does not recognize 'legitimate interests' as a lawful basis, unlike GDPR.
ConfirmedIAPP — Consent under PIPL must be informed, freely given and evidenced by a clear affirmative action, with a standing right of withdrawal (Arts 14–15); a heightened 'separate consent' is additionally required when handlers share PI with other handlers, publicly disclose PI, process sensitive PI, or transfer PI abroad (Arts 23, 25, 29, 39).
ConfirmedIAPP — PIPL Article 28 defines sensitive personal information to include biometric identification information, religious beliefs, specially-designated status, medical health information, financial accounts, information on individuals' whereabouts, and personal information of minors under the age of 14.
ConfirmedIAPP — Anonymized information is not deemed personal information under PIPL; anonymization is defined (Arts 4 & 73) as processing that renders data non-identifying and non-restorable to a specific natural person, while 'de-identification' functions as PIPL's pseudonymisation-equivalent concept.
Substantive rights are enacted and broad, but the absence of a codified statutory response deadline creates residual ambiguity relative to GDPR-style regimes.
Traffic-light rationale — AmberSubstantive rights are enacted and broad, but the absence of a codified statutory response deadline creates residual ambiguity relative to GDPR-style regimes.
Sub-modules (5)
Access RightGreen
Individuals have the right to access and obtain copies of their personal information, which handlers must provide in a timely fashion.
Claims: CLM-CN-a3b4c5d6
Rectification And ErasureGreen
Individuals may request correction, supplementation or updating of inaccurate/incomplete/outdated personal information, and may request deletion.
Claims: CLM-CN-b4c5d6e7
Restriction And ObjectionGreen
Individuals may demand an explanation of automated-decision-making use and may refute decisions made solely via automated means where those decisions significantly affect them.
Claims: CLM-CN-c5d6e7f8
Data PortabilityGreen
PIPL provides a portability right allowing individuals to request transfer of their personal information to another handler; PIPL goes further than GDPR by permitting legal claims against handlers who reject rights requests.
Claims: CLM-CN-d6e7f809
Deadlines And Response WindowsAmber
PIPL requires handlers to respond to access requests 'in a timely fashion' but does not set a fixed statutory day-count deadline analogous to GDPR's one-month rule; no secondary source located specifying a harmonized numeric window across all right types.
Claims: CLM-CN-e7f8091a
Category narrative86 words
PIPL Chapter IV grants a GDPR-adjacent rights bundle: access/copy, rectification, erasure, restriction/objection (including a right to demand explanation of and refute automated decisions), and a portability right that in some respects exceeds GDPR by allowing individuals to sue handlers who refuse rights requests and by extending exercise of rights to close relatives of deceased individuals. However, PIPL does not codify a fixed numeric response-deadline analogous to GDPR's one-month rule; the statute only requires handlers to respond 'in a timely fashion,' leaving specific windows to sectoral/CAC guidance.
Sources and claims (5)
ConfirmedIAPP — Under PIPL, individuals have the right to access and make copies of their personal information, and personal information handlers must provide such information in a timely fashion.
ConfirmedIAPP — Individuals are entitled to correct, supplement and update incomplete, inaccurate or outdated personal information and may request deletion of their personal information from handlers.
ConfirmedIAPP — Data subjects have the right to request an explanation regarding the use of their personal information and to refute a decision made by a handler solely through automated decision-making where it significantly affects them.
ConfirmedIAPP — PIPL provides a right of portability whereby individuals may request that a personal information handler transfer their personal information to another handler; PIPL exceeds GDPR by granting individuals a right to bring claims against handlers who reject a rights request and a right to demand an explanation of handling rules.
UncertainIAPP — PIPL requires personal information handlers to respond to access requests 'in a timely fashion' rather than specifying a codified numeric response deadline equivalent to GDPR's one-month rule.
Core accountability, DPIA, security and breach-notification duties are enacted and enforced, but the PIPO appointment threshold and processor ('entrusted party') definitions remain under-specified in binding text.
Primary frameworkPIPL Chapter V (Arts 51–59); Regulations on Network Data Security Management (eff. 1 Jan 2025)
Traffic-light rationale — AmberCore accountability, DPIA, security and breach-notification duties are enacted and enforced, but the PIPO appointment threshold and processor ('entrusted party') definitions remain under-specified in binding text.
Sub-modules (7)
Accountability And DpiaAmber
PIPL lacks an express GDPR-style accountability principle but requires handlers to accept responsibility for their processing and adopt necessary safeguards; DPIAs (Art 55) are mandatory for sensitive-data processing, ADM, entrusting/sharing/disclosing PI, cross-border transfer, and other major-impact processing.
Claims: CLM-CN-f8091a2b
Dpo RequirementsAmber
PIPL requires appointment of a Personal Information Protection Officer (PIPO) above an as-yet-undefined processing-volume threshold; industry guidance points to organizations processing hundreds of thousands to millions of individuals' data.
Claims: CLM-CN-091a2b3c
Ropa RequirementsAmber
Unlike GDPR's blanket Art 30 requirement, PIPL imposes record-keeping only for the DPIA-triggering categories, with processing records and assessment reports retained for at least three years (Art 55).
Claims: CLM-CN-1a2b3c4e
Joint Controller ArrangementsAmber
PIPL does not define 'entrusted parties' as precisely as GDPR defines processors, but imposes obligations on them, including a duty to notify and assist the handler in the event of a breach affecting entrusted data.
Claims: CLM-CN-2b3c4d5f
Security MeasuresGreen
Handlers must adopt organizational and technical measures — internal management rules, PI classification, encryption/de-identification, access controls, periodic staff training, and incident-response mechanisms.
Claims: CLM-CN-3c4d5e70
Breach NotificationGreen
Article 57 requires handlers, on any actual or possible leak, distortion or loss of PI, to take remedial measures and notify regulators and affected individuals of incident categories, causes, possible harm, remedial steps and contact details, unless harm is effectively avoided.
Claims: CLM-CN-4d5e6f81
Retention And DisposalGreen
The 2025 Network Data Security Management Regulations require companies processing personal data of more than 10 million individuals to submit a data disposal plan to regulators in the event of a merger, acquisition, spin-off or insolvency affecting data security.
Claims: CLM-CN-5e6f7092
Category narrative100 words
PIPL Chapter V imposes DPIA obligations (Arts 55–56) triggered by sensitive-data processing, automated decision-making, entrusting/sharing/public disclosure of PI, cross-border transfers, and other 'major-impact' processing; a Personal Information Protection Officer (PIPO) requirement exists but the numeric threshold remains undefined in the statute itself. Record-keeping obligations are narrower than GDPR's blanket Art 30 ROPA, applying mainly to the DPIA-triggering categories, with 3-year minimum retention of assessment records. Breach notification (Art 57) requires remedial action plus notice to regulators and affected individuals unless harm is effectively neutralized. The 2025 Network Data Security Management Regulations add data-disposal-plan obligations for very-large-scale processors upon M&A/insolvency events.
Sources and claims (7)
ConfirmedIAPP — Under PIPL Article 55, a personal information handler must conduct a personal information protection impact assessment prior to handling sensitive personal information, using personal information for automated decision-making, entrusting/sharing/disclosing personal information, transferring personal information abroad, or engaging in other processing with a major influence on individuals; the assessment must evaluate lawfulness/necessity, impact on individuals' rights, and adequacy of protective measures.
ProbableIAPP — PIPL requires certain handlers to appoint a Personal Information Protection Officer (PIPO), but the precise processing-volume threshold triggering this requirement is not specified in the statute; analogous CAC draft measures reference thresholds around one million individuals' data.
ConfirmedOneTrust DataGuidance — Unlike GDPR's universal Article 30 record-keeping duty applicable to controllers and processors alike, PIPL imposes record-of-processing obligations on handlers only for the categories triggering a DPIA, and requires retention of impact-assessment processing records for at least three years (Art 55).
ProbableOneTrust DataGuidance — PIPL does not define 'entrusted parties' (the processor-equivalent role) as precisely as GDPR defines data processors, though it imposes obligations on such parties, including a duty to notify the handler and provide technical/administrative assistance in the event of a breach involving entrusted personal information.
ConfirmedIAPP — PIPL requires handlers to adopt organizational and technical measures to prevent unauthorized access, damage, leakage or loss of personal information, including internal management mechanisms, classification of personal information, encryption and de-identification, access controls, and periodic security training.
ConfirmedIAPP — Under PIPL Article 57, whenever a leak, distortion or loss of personal information occurs or might have occurred, handlers must adopt remedial measures and notify relevant departments and affected individuals of the information categories, causes and possible harm, the remedial measures taken and steps individuals can take to mitigate harm, and a method of contact; notification to individuals is excused where the handler adopts measures effectively avoiding harm.
ConfirmedIAPP — The Regulations on Network Data Security Management require a company processing personal data of more than 10 million individuals to establish a dedicated department and appoint a senior data-security executive, and to submit a data disposal plan to regulators upon a merger, acquisition, spin-off or insolvency affecting data security.
Transfer mechanisms are well-established and increasingly detailed, but thresholds have shifted multiple times since 2022 and important-data classification remains only partially settled, creating ongoing compliance uncertainty.
Primary frameworkPIPL Chapter III (Arts 38–43); Measures for Security Assessment of Outbound Data Transfers (2022); Chinese SCC Provisions (2023); Provisions on Promoting and Regulating Cross-Border Data Flows (2024)
Traffic-light rationale — AmberTransfer mechanisms are well-established and increasingly detailed, but thresholds have shifted multiple times since 2022 and important-data classification remains only partially settled, creating ongoing compliance uncertainty.
Sub-modules (6)
Transfer MechanismsAmber
Article 38 provides three transfer mechanisms: CAC-led security assessment (for CIIOs/large-volume processors), CAC-authorized certification, and the Chinese standard contract.
Claims: CLM-CN-6f70819b
Adequacy ReceivedRed
PIPL does not provide a mechanism for cross-border transfers premised on adequacy decisions from other jurisdictions, in contrast with GDPR Art 45.
Claims: CLM-CN-70819a3c
Adequacy GrantedRed
No evidence was found of China issuing formal 'adequacy' determinations toward other jurisdictions; its transfer regime is structured around security assessment, SCC and certification rather than a unilateral-adequacy concept.
Sccs And BcrsAmber
The Chinese SCCs (effective 1 June 2023) require Chinese law as the governing law, use a single universal contract template regardless of controller/processor role, and must be filed with the provincial CAC within 10 working days of effectiveness together with the impact assessment report.
Claims: CLM-CN-8192a3b5
Transfer Impact AssessmentAmber
SCC-based (and security-assessment-based) transfers require an accompanying impact assessment report; the assessment must be redone and re-filed with the provincial CAC upon material changes such as extended retention, altered purpose/scope/volume/sensitivity, or changes in the destination country's data protection laws.
Claims: CLM-CN-92a3b4c6
Data LocalisationAmber
CIIOs and processors handling large volumes of personal information must store personal information locally in China, with overseas transfer conditioned on passing a CAC security assessment (Art 40); the March 2024 CBDT relaxations raised numeric thresholds and exempted several transfer scenarios (e.g., employee data) from any CBDT mechanism.
Claims: CLM-CN-a3b4c5d7
Category narrative98 words
PIPL Article 38 offers three cross-border transfer mechanisms — CAC-led security assessment, PI-protection certification, or a CAC-standard-contract (Chinese SCC, effective 1 June 2023) — with applicability determined by processing volume/sensitivity thresholds progressively relaxed by the March 2024 CBDT Provisions and further eased by the 2025 Network Data Security Regulations (e.g., blanket exemption for employee-data transfers). PIPL does not recognize inbound adequacy decisions from other regimes, and no evidence was found of China granting outbound 'adequacy' status to other jurisdictions; its regime instead relies on bilateral security assessment/SCC/certification. CIIOs and large-volume processors remain subject to mandatory data localisation domestically.
Sources and claims (5)
ConfirmedIAPP — PIPL Article 38 offers three cross-border data transfer mechanisms depending on the characteristics of the exporting entity: a CAC-led security assessment (mandatory for CIIOs and large-volume processors), a PI-protection certification issued by CAC-authorized professional institutions, or a standard-contract agreement with the overseas recipient based on CAC-issued clauses.
ConfirmedOneTrust DataGuidance — Unlike GDPR, PIPL does not provide for cross-border transfers of personal information premised on a finding of 'adequate protection' in the recipient jurisdiction; all outbound transfers must instead satisfy one of PIPL's three domestic transfer mechanisms.
ConfirmedIAPP — The Chinese Standard Contractual Clauses, effective 1 June 2023, require the cross-border data transfer agreement to be governed by Chinese law, use a single universal template regardless of the parties' controller/processor role, and be filed with the provincial CAC together with the impact assessment report within 10 working days of effectiveness.
ConfirmedIAPP — Parties to an SCC-based cross-border transfer must redo the impact assessment, update the transfer agreement, and re-file with the provincial CAC where circumstances materially change, including extension of retention period, changes in processing purpose/scope/category/volume/storage location/sensitivity, or changes in the destination country's data protection laws affecting data subjects.
ConfirmedIAPP — CIIOs and entities processing large volumes of personal information must store citizens' personal information and important data locally in China, with overseas transfer conditioned on passing a CAC-led security assessment; the March 2024 CBDT Provisions relaxed thresholds so that non-CIIO handlers transferring between 100,000 and 1,000,000 individuals' data (or under 10,000 individuals' sensitive data) may use SCC/certification rather than a full security assessment, and exempted employee-data transfers from any CBDT mechanism regardless of volume where employment-law conditions are met.
Financial-sector and employment-data overlays are documented, but health, education and insurance sector-specific DP overlays were not located in this pass and are flagged as a research gap.
Traffic-light rationale — AmberFinancial-sector and employment-data overlays are documented, but health, education and insurance sector-specific DP overlays were not located in this pass and are flagged as a research gap.
Sub-modules (7)
Financial Sector OverlayAmber
PBOC's Financial Data Security — Data Security Classification Guidelines (2020) impose sector-specific classification duties, and the amended Anti-Money Laundering Law (effective 1 Jan 2025) requires financial institutions to protect KYC/AML data confidentiality consistent with CSL/DSL/PIPL and to report before cross-border KYC/transaction-record disclosures to foreign authorities.
Claims: CLM-CN-b4c5d6e8
Health Sector OverlayRed
No dedicated health-sector data protection statute distinct from PIPL's general treatment of 'medical health information' as sensitive personal information was identified.
Telecoms And EprivacyAmber
China lacks a discrete ePrivacy-style instrument; illustrative enforcement includes MIIT's 2021 sweep ordering WeChat, Tencent and other apps to rectify illegal transfer of contact-list and location data and pop-up harassment practices.
Claims: CLM-CN-c5d6e7f9
Employment DataGreen
Under the CBDT relaxations, employee-data transfers are exempt from all CBDT legal mechanisms irrespective of volume, provided underlying Chinese employment-law conditions (e.g., democratically consulted employee handbooks) are met.
Claims: CLM-CN-d6e7f80a
Credit And ScoringAmber
PIPL Article 67 allows violations to be recorded into a handler's 'credit files' under China's national social credit system, layering credit-scoring consequences onto ordinary administrative penalties.
Claims: CLM-CN-e7f8091b
EducationRed
No education-sector-specific data protection overlay was identified in this research pass.
InsuranceAmber
Insurance-sector data processing falls within the general financial-regulator enforcement lane under PIPL Arts 60/63; no insurance-specific data rule distinct from the general financial-sector overlay was located.
Claims: CLM-CN-f8091a2c
Category narrative107 words
Financial-sector data is subject to PBOC-issued classification guidelines (Financial Data Security — Data Security Classification Guidelines, 2020) and the amended Anti-Money Laundering Law (effective 1 Jan 2025), which requires KYC/AML information to be handled consistently with CSL/DSL/PIPL and imposes reporting obligations before cross-border KYC disclosures to foreign authorities. Employment data benefits from a specific CBDT exemption. Violations feed into China's national social-credit 'credit files' system (Art 67), giving credit-scoring consequences a cross-cutting role. No dedicated health-sector, education-sector or insurance-specific data protection overlay statute was identified in this research pass beyond PIPL's general 'medical health information' sensitive-category treatment and the shared multi-regulator enforcement structure under PIPL Arts 60/63.
Sources and claims (5)
ConfirmedIAPP — The People's Bank of China issued the Financial Data Security — Data Security Classification Guidelines establishing sector-specific data classification obligations for financial institutions, and the amended Anti-Money Laundering Law (effective 1 Jan 2025) requires financial institutions to protect the confidentiality of collected KYC/AML information consistent with CSL/DSL/PIPL and to report to the competent Chinese financial regulator before disclosing customers' KYC information or transactional records to foreign authorities.
ConfirmedIAPP — MIIT found that a batch of applications, including WeChat and other Tencent products, illegally transferred users' contact-list and location data and used pop-up harassment, ordering their parent companies to make rectifications.
ConfirmedIAPP — Under the CBDT regulations, employee data transfers are exempt from any of the CBDT legal mechanisms irrespective of data volume, provided companies meet relevant Chinese employment-law conditions extending beyond data protection rules (e.g., a democratically consulted employee handbook).
ConfirmedIAPP — PIPL Article 67 provides that violations may be recorded into the 'credit files' of the processing entity under China's national social credit system, in addition to monetary penalties.
ProbableIAPP — PIPL Article 60 designates financial regulators (which encompass insurance-sector oversight) among the sectoral supervisory authorities empowered to enforce PIPL within their respective designated areas.
Algorithm-transparency and anti-price-discrimination rules are enacted and enforced, but cookie-consent, opt-out-signal and clean-room-specific regimes are absent from China's framework.
Primary frameworkProvisions on the Management of Algorithmic Recommendations in Internet Information Services (2022); PIPL Art 24
Traffic-light rationale — AmberAlgorithm-transparency and anti-price-discrimination rules are enacted and enforced, but cookie-consent, opt-out-signal and clean-room-specific regimes are absent from China's framework.
Sub-modules (6)
Cookies And TrackersRed
No standalone ePrivacy-equivalent cookie/tracker consent statute was identified for China; tracking technologies are governed generally through PIPL's consent framework rather than a dedicated cookie law.
Dark PatternsAmber
Joint CAC/MIIT/MPS/SAMR enforcement campaigns have targeted apps for harassing pop-up windows and illegal collection of contact-list/location data, functioning as de facto anti-dark-pattern enforcement absent a codified prohibition.
Claims: CLM-CN-091a2b3d
Opt Out SignalsRed
No Global Privacy Control or DAA-equivalent standardized opt-out signal mechanism was identified in China's regulatory framework.
Clean Rooms And DcrRed
No data-clean-room or data-collaboration-room-specific regulatory regime was identified for China in this research pass.
Cross Context AdvertisingAmber
The 2022 Provisions on the Management of Algorithmic Recommendations regulate algorithms used for content recommendation and targeted advertising, requiring transparency and fairness and prohibiting practices that disrupt public order.
Claims: CLM-CN-1a2b3c4f
Direct MarketingGreen
PIPL Article 24 requires that where handlers use automated decision-making for business marketing or push notifications, they must simultaneously offer options not targeting an individual's personal characteristics, or provide a simple means of rejection.
Claims: CLM-CN-2b3c4d60
Category narrative65 words
China lacks a discrete ePrivacy-style cookie-consent statute; commercial-privacy governance instead runs through PIPL's ADM/marketing rule (Art 24) and the CAC's 2022 Provisions on Algorithmic Recommendations, which mandate algorithm transparency/fairness and prohibit practices disrupting public order, including personalized price discrimination. Dark-pattern-style practices (e.g., harassing pop-ups, undisclosed data collection) have been targeted by joint MIIT/SAMR/CAC/MPS enforcement sweeps. No Global-Privacy-Control-equivalent opt-out signal or dedicated clean-room/data-collaboration-room regime was identified.
Sources and claims (3)
ConfirmedIAPP — MIIT, CAC, MPS and SAMR jointly conducted enforcement campaigns (2020–2021) against apps engaging in illegal collection and use of personal information and harassing pop-up notifications, functioning as enforcement against dark-pattern-style practices absent a codified statutory prohibition.
ProbableCyberspace Administration of China — The Provisions on the Management of Algorithmic Recommendations in Internet Information Services (effective 1 March 2022) regulate algorithms used for content recommendation, requiring transparency and fairness and prohibiting practices that disrupt public order, including personalized price discrimination.
ConfirmedIAPP — PIPL requires that personal information processors conducting business marketing to individuals through automated decision-making simultaneously provide options that do not target an individual's personal characteristics, or offer ways for individuals to reject such marketing.
AI- and biometric-specific rules are extensive and rapidly evolving (including a 2025 CSL amendment), but genetic-data specificity is absent and state-surveillance carve-outs remain structurally unconstrained by PIPL's private-sector-facing rules.
Primary frameworkPIPL Art 24; Provisions on Algorithmic Recommendations (2022); Provisions on Deep Synthesis (2023); Interim Measures for Generative AI Services (2023); amended Cybersecurity Law (2025)
Traffic-light rationale — AmberAI- and biometric-specific rules are extensive and rapidly evolving (including a 2025 CSL amendment), but genetic-data specificity is absent and state-surveillance carve-outs remain structurally unconstrained by PIPL's private-sector-facing rules.
Sub-modules (6)
Profiling RestrictionsAmber
PIPL Article 24 prohibits unreasonable differential treatment via automated decision-making (e.g., algorithmic price discrimination) and requires non-targeted or opt-out marketing options.
Claims: CLM-CN-3c4d5e71
Automated Decision Making TransparencyGreen
Individuals may request an explanation of automated-decision-making use and challenge decisions made solely by automated means where those decisions significantly affect them.
Claims: CLM-CN-4d5e6f82
Ai Risk AssessmentsAmber
The amended Cybersecurity Law (passed October 2025) brings AI governance within CSL's scope and raises maximum penalties; the 2023 Interim Measures for Generative AI Services separately require security assessments for generative AI services with 'public opinion attributes.'
Claims: CLM-CN-5e6f7093
Biometric RegimeAmber
Biometric identification information is classified as sensitive personal information under PIPL Art 28, requiring separate consent, and is further governed by CAC measures on the security of facial recognition technology.
Claims: CLM-CN-6f70819c
Genetic DataRed
No standalone genetic-data regime distinct from PIPL's general 'medical health information' sensitive-category treatment was identified in this research pass.
State Surveillance CarveoutsRed
PIPL's consumer-facing protections do not constrain the PRC central government's own data access; independent legal commentary observed little indication of legal limits on state surveillance activity notwithstanding PIPL's commercial-sector rules.
Claims: CLM-CN-70819a3d
Category narrative153 words
PIPL Article 24 restricts algorithmic price-discrimination and mandates non-targeted or opt-out marketing options; individuals may demand explanations of and refute significant automated decisions. China layers AI-specific instruments atop this base — the 2022 Algorithmic Recommendation Provisions, the 2023 Deep Synthesis Provisions, and the 2023 Interim Measures for Generative AI Services (security assessments for public-opinion-attribute services) — and the amended Cybersecurity Law (passed October 2025) newly brings AI governance within CSL's scope while raising maximum penalties to CNY50 million/5% of turnover for companies and CNY1 million for individuals. Biometric data (including facial recognition) is treated as sensitive personal information requiring separate consent, reinforced by CAC facial-recognition security measures. Genetic data is not called out as a standalone category distinct from 'medical health information.' State-surveillance carve-outs are structurally significant: PIPL's consumer-facing protections do not extend to constrain central-government data access, and independent legal commentary has noted the absence of clear legal limits on government surveillance.
Sources and claims (5)
ConfirmedIAPP — PIPL Article 24 requires personal information processors engaging in automated-decision-making-based marketing to provide non-targeted options or simple rejection mechanisms, addressing algorithmic price discrimination and profiling-driven differential treatment.
ConfirmedIAPP — Data subjects have the right to request an explanation regarding the use of personal information in automated decision-making and to refute a decision made solely by automated means where it significantly affects them.
ConfirmedIAPP — China's amended Cybersecurity Law, passed in October 2025, brings artificial intelligence governance within the CSL's scope and raises the maximum fine for companies to CNY50 million or 5% of the previous year's turnover, with individual penalties up to CNY1 million.
ProbableOneTrust DataGuidance — PIPL Article 28 classifies biometric identification information as sensitive personal information requiring separate consent for processing, and CAC has issued dedicated measures governing the security of facial recognition technology deployment.
ProbableIAPP — PIPL's private-sector-facing protections do not prevent the PRC central government from accessing data, and legal commentators have observed little indication of legal limits on government surveillance or meaningful civil-society oversight mechanisms in this area.
Minors' data receives clear sensitive-category and parental-consent treatment with active 2025-2026 filing enforcement, but dependent-adult protections and minor-specific profiling bans were not located in this research pass.
Primary frameworkProvisions on Cyber Protection of Children's Personal Information (2019); PIPL Art 28
Traffic-light rationale — AmberMinors' data receives clear sensitive-category and parental-consent treatment with active 2025-2026 filing enforcement, but dependent-adult protections and minor-specific profiling bans were not located in this research pass.
Sub-modules (5)
Age VerificationAmber
The operative age threshold for heightened protection is 14 years; the December 2025 CAC directive requires filings on the nature, categories and volume of minors' personal information collected, implying an age-identification/verification compliance step, though no standalone age-verification technical mandate was located.
Claims: CLM-CN-8192a3b6
Parental ConsentGreen
PIPL treats personal information of minors under 14 as sensitive personal information, requiring parental or guardian consent for processing, building on the 2019 Provisions on Cyber Protection of Children's Personal Information.
Claims: CLM-CN-8192a3b6
Minor Profiling BansRed
No standalone algorithmic-profiling ban specific to minors, distinct from PIPL's general ADM transparency/opt-out rules, was identified in this research pass.
Education SettingsRed
No education-setting-specific children's data protection rule was identified in this research pass.
Dependent AdultsRed
PIPL allows close relatives to exercise a deceased individual's data protection rights, but no dedicated regime for living dependent adults (elderly or mentally incapacitated persons) was identified.
Claims: CLM-CN-a3b4c5d8
Category narrative96 words
PIPL treats the personal information of minors under 14 as sensitive personal information, requiring parental/guardian consent, building on the standalone 2019 Provisions on Cyber Protection of Children's Personal Information (China's COPPA-equivalent). A December 2025 CAC directive newly requires companies collecting minors' personal information to complete compliance audits and file materials (data categories/volume, impact assessment, signed undertaking letter) with local CAC offices by 31 January 2026, signaling heightened 2026 enforcement focus. No standalone minor-specific profiling ban, education-setting-specific rule, or dependent-adult (elderly/incapacitated) regime was identified beyond PIPL's general provision allowing close relatives to exercise a deceased individual's rights.
Sources and claims (2)
ConfirmedIAPP — PIPL classifies the personal information of minors under the age of 14 as sensitive personal information, and CAC's 2019 Provisions on Cyber Protection of Children's Personal Information (China's COPPA-equivalent) requires parental/guardian consent for handling children's data; a CAC directive issued 28 December 2025 further requires companies collecting minors' personal information to complete compliance audits and file supporting materials with local CAC offices by 31 January 2026.
UncertainOneTrust DataGuidance — PIPL permits close relatives of a deceased individual to exercise that individual's data protection rights, but no equivalent statutory protection specific to living dependent adults (e.g., elderly or mentally incapacitated persons) was identified.
China maintains an active, multi-agency enforcement apparatus with substantial recent fines, an evolving penalty ceiling (raised again via the 2025 CSL amendment), and continuous rulemaking activity through mid-2026.
Primary frameworkPIPL Chapter VII (Arts 60–71); amended Cybersecurity Law (2025)
Traffic-light rationale — GreenChina maintains an active, multi-agency enforcement apparatus with substantial recent fines, an evolving penalty ceiling (raised again via the 2025 CSL amendment), and continuous rulemaking activity through mid-2026.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
Article 63 grants broad investigatory powers; a two-tier (general/grave) administrative penalty structure applies, with grave violations reaching RMB50 million or 5% of prior-year turnover plus business-suspension/license-revocation powers.
Claims: CLM-CN-c5d6e7fa
Enforcement Activity IndexGreen
Landmark fines include RMB8.026 billion against Didi Global (2022) for CSL/DSL/PIPL violations and RMB50 million against academic database provider CNKI (2023) for PIPL/CSL violations.
Claims: CLM-CN-d6e7f80b
Regulator Funding And CapacityRed
No specific data on CAC budget or headcount was located in this research pass.
Collective Redress And Class ActionsGreen
Article 70 grants standing for public-interest actions (China's equivalent of class actions) to the People's Procuratorate, statutorily designated consumer organizations, and CAC-designated organizations.
Claims: CLM-CN-e7f8091c
Private Right Of ActionGreen
PIPL Article 69 shifts the burden of proof to the defendant handler once an individual demonstrates an infringement, and courts may calculate damages by reference to the handler's gains rather than only the individual's actual losses.
Claims: CLM-CN-f8091a2d
Recent Developments 180DAmber
Within the last 180 days: the amended Cybersecurity Law (passed October 2025) raised maximum penalties and folded AI governance into CSL; a CAC directive of 28 December 2025 mandated minors'-data compliance audits and filings by 31 January 2026; and TC260 released draft amendments to the (non-binding) GB/T 35273 national standard on 17 June 2026, introducing new AI-governance and legal-basis chapters, with public comment open until 16 August 2026.
Claims: CLM-CN-091a2b3e
Category narrative189 words
PIPL Article 63 grants supervisory authorities broad investigatory powers (interviews, document review, on-site inspection, equipment seizure/confiscation). A two-tier penalty structure applies: general violations up to RMB1 million for handlers/RMB100,000 for responsible officers; grave violations up to RMB50 million or 5% of prior-year revenue for handlers, RMB100,000–1 million for officers, plus rectification orders, business suspension or license revocation. Landmark enforcement includes the RMB8.026 billion Didi fine (2022) and the RMB50 million CNKI fine (2023) for PIPL/CSL violations. Article 70 permits public-interest actions (China's class-action equivalent) by the People's Procuratorate, designated consumer organizations, or CAC-designated bodies; Article 69 shifts the burden of proof to the defendant handler once an infringement is shown, and courts may base damages on the handler's gains rather than only the individual's proven losses. Recent developments (within 180 days of this run) include the October 2025 amended CSL raising maximum penalties and bringing AI within CSL's scope, a 28 December 2025 CAC directive on minors'-data compliance filings (deadline 31 January 2026), and June 2026 TC260 draft amendments to the non-binding GB/T 35273 national standard introducing new AI-governance and legal-basis guidance (comment period open to 16 August 2026).
Sources and claims (5)
ConfirmedIAPP — PIPL Article 63 grants supervisory authorities investigatory powers including interviews, document review, on-site inspections, and equipment seizure/confiscation; the law creates a two-tier penalty structure with general violations fined up to RMB1 million for handlers and RMB100,000 for responsible officers, and grave violations fined up to RMB50 million or 5% of the previous year's annual revenue for handlers and RMB100,000–1 million for officers, alongside rectification orders, business suspension, and license revocation powers.
ConfirmedOneTrust DataGuidance — CAC fined Didi Global approximately RMB8.026 billion in 2022 for violations of the CSL, DSL and PIPL, and separately fined academic database provider CNKI RMB50 million for PIPL and CSL violations in 2023, illustrating sustained large-scale enforcement activity.
ConfirmedIAPP — PIPL Article 70 grants standing to file public-interest actions — China's functional equivalent of class actions — to the People's Procuratorate, statutorily designated consumer organizations, and organizations designated by CAC, where a handler's infringement affects a large number of individuals.
ConfirmedIAPP — PIPL Article 69 shifts the burden of proof to the defendant handler once a data subject demonstrates an infringement of their personal-information rights, and courts assessing damages are not limited to actual losses but may instead rely on the gains the handler obtained from the infringing conduct.
ConfirmedIAPP — Within the 180 days preceding this run: China's amended Cybersecurity Law (passed October 2025) raised the maximum corporate fine to CNY50 million or 5% of prior-year turnover and folded AI governance into CSL's scope; a CAC directive dated 28 December 2025 required companies collecting minors' personal information to complete compliance audits and submit filings to local CAC offices by 31 January 2026; and on 17 June 2026 TC260 released draft amendments to the non-binding GB/T 35273 national standard, adding a new chapter on legal-basis guidance and AI-driven governance updates, with public comment open until 16 August 2026.
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for China (mainland)
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 46 claim(s), 19 source(s) in the cumulative register.