Personal Information Protection Law of the People's Republic of China
Personal Information Protection Law of the People's Republic of China (PIPL, adopted by the NPCSC on 20 August 2021) is in force in China. This page holds what the official text states: dates, the named requirements, who supervises it and where the text is published.
- Personal Information Protection Law of the People's Republic of China names extraterritorial scope, grounds for processing, conditions for transfer out of china, impact assessment and duties of the handler.
- Personal Information Protection Law of the People's Republic of China does not settle whether a single shipment, transfer or service meets the requirement; that follows from the facts of the case and from the supervising body.
- Supervised by Standing Committee of the National People's Congress and Cyberspace Administration of China. Published by National People's Congress.
- EU: GDPR — Regulation (EU) 2016/679. Both texts govern personal data and both reach processing outside their own territory.
- US: CCPA / CPRA. Both texts give the individual rights over data held about them.
Identity
| Name in Chinese | 个人信息保护法 |
|---|---|
| Identifier | PIPL, adopted by the NPCSC on 20 August 2021 |
| Adopted | 2021-08-20 |
| Applies from | 2021-11-01 |
| Status as published | The law applies since 1 November 2021 and covers processing outside China aimed at people inside China. |
| Supervision | Standing Committee of the National People's Congress, Cyberspace Administration of China |
| Areas named | Personal data, Cross-border data transfer |
| Read against the source | 2026-08-17 |
Requirements in the text
- Extraterritorial scope — Reference: PIPL Article 3. Processing outside China of personal information of people inside China.
- Grounds for processing — Reference: PIPL Article 13. The seven listed grounds, with consent as the first named ground.
- Conditions for transfer out of China — Reference: PIPL Article 38. Security assessment, certification or standard contract before an outbound transfer.
- Impact assessment — Reference: PIPL Article 55. Assessment required before sensitive processing and before an outbound transfer.
- Duties of the handler — Reference: PIPL Article 51. Internal rules, classification, encryption, training and incident response.
Compared with the EU register
- GDPR — Regulation (EU) 2016/679: Both texts govern personal data and both reach processing outside their own territory.
Compared with the US register
- CCPA / CPRA: Both texts give the individual rights over data held about them.
Official sources
- 中华人民共和国个人信息保护法 — National People's Congress
The register states what the official texts say. It is not advice and it is not a verdict on any company.
ExploreWorldAI is operated by Valkiv Ventures AB (Reg. no. 556995-1311), Kungsgatan 8, 111 43 Stockholm, Sweden. EU-hosted, with data processing assessed against the GDPR. Contact: hello@exploreworldai.com.
Machine-readable summaries for AI agents: /llms.txt and /llms-full.txt.