English中文
China flag

China

China Data Privacy Laws: PIPL, CSL & DSL Compliance Guide (2026)

By Recording Law Editorial TeamReviewed July 23, 202622 min read
China Data Privacy Laws: PIPL, CSL & DSL Compliance Guide (2026)

Frequently Asked Questions

Does China's PIPL apply to companies outside China?

Yes. The PIPL has explicit extraterritorial reach. It applies to foreign entities that process personal information of people within China for the purpose of providing products or services to them or analyzing and assessing their behavior. Such entities must designate a representative or establish a legal entity in China to handle personal information protection matters and must comply with the same substantive requirements as domestic handlers.

What are the three cross-border data transfer mechanisms under China's PIPL?

The three mechanisms are: (1) a CAC security assessment, which is mandatory for Critical Information Infrastructure Operators, handlers of important data, and handlers that have processed personal information of more than 1 million individuals; (2) standard contractual clauses using the CAC-prescribed template, available for lower-volume or lower-risk transfers; and (3) personal information protection certification by a CAC-accredited institution, which became fully operational effective January 1, 2026. All three mechanisms require separate consent from data subjects and completion of a Personal Information Protection Impact Assessment before any transfer.

What changed in China's Cybersecurity Law effective January 1, 2026?

The October 2025 amendments to the Cybersecurity Law -- effective January 1, 2026 -- significantly raised fines. For Critical Information Infrastructure Operators, the maximum penalty increased to CNY 10 million where violations cause particularly serious consequences. For general network operators, the ceiling for serious violations rose to CNY 2 million. The amendments also broadened extraterritorial enforcement beyond critical infrastructure to cover any overseas activity that endangers China's cybersecurity, and added provisions addressing AI and algorithmic security.

What are China's mandatory compliance audit requirements for data processors?

Under the PIPL Compliance Audit Measures (effective May 1, 2025), entities processing personal information of more than 10 million individuals must audit at least once every two years. Entities processing fewer than 10 million must audit regularly, with frequency determined by the entity based on risk. Any entity processing minors' personal information -- regardless of volume -- must conduct an annual audit and file results with the CAC by January 31 each year. The CAC may also order a mandatory audit after a serious incident or when it identifies high-risk processing.

How long does a company have to report a data breach in China?

Under the Cybersecurity Incident Reporting Measures effective November 1, 2025, the timeline depends on the type of operator. Critical Information Infrastructure Operators must report to the CII protection department and Public Security Bureau within one hour. State organs must report within two hours. Other network operators must report to the provincial CAC within four hours of identifying an in-scope incident. Failure to report or delayed reporting is an independent PIPL violation subject to additional penalties.

Does China require data localization?

Mandatory localization applies to Critical Information Infrastructure Operators, which must store personal information and important data collected in China on servers physically located in mainland China. For non-CIIOs, general data localization is not required under the PIPL or DSL, though sector-specific rules in finance, healthcare, and telecommunications may impose additional storage requirements. Transfers out of China by non-CIIOs are permitted through the approved cross-border mechanisms.

What is the largest data privacy fine China has issued?

The CAC fined Didi Chuxing CNY 8.026 billion (approximately USD 1.2 billion) in July 2022 for violations spanning seven years. The investigation found that Didi illegally processed more than 64.7 billion pieces of personal information, including excessive collection of user data and unlawful processing of vehicle data. Didi's chairman and president were each personally fined CNY 1 million. The fine remains the largest data protection penalty issued by any regulator globally, surpassing the EUR 746 million fine imposed on Amazon under the GDPR.

What is legitimate interest and why does it matter for China compliance?

Legitimate interest is a legal basis for processing personal information under the GDPR that allows controllers to process data when their interests outweigh the privacy interests of the data subject, without requiring consent. China's PIPL does not recognize legitimate interest as a valid basis. Companies that rely on legitimate interest under GDPR for activities like fraud prevention, network security monitoring, or marketing analytics must identify a different PIPL-compliant basis -- typically consent or contractual necessity -- for those same activities in China.

Updates

Corrected the cross-border transfer threshold tiers under the CAC's cross-border data provisions (Order 16): added the previously-missing under-100,000-individuals exemption for non-CIIO handlers, clarified that transfers of 100,000 to under 1 million individuals' non-sensitive personal information (or under 10,000 individuals' sensitive personal information) qualify for Standard Contractual Clauses or certification rather than a mandatory CAC security assessment, corrected the mandatory-assessment threshold to 1 million or more non-sensitive individuals or 10,000 or more sensitive individuals cumulatively per calendar year, and corrected CAC security assessment validity from two years to three years. Softened the GB/T 46068-2025 certification standard reference given a pending CAC/SAMR notice that may revise its technical basis. Added the CAC-MIIT-MPS April 2, 2026 special enforcement campaign and the CAC's April 27, 2026 public naming of 33 apps for personal information violations.

Expanded to cover the amended Cybersecurity Law (effective January 1, 2026) raising maximum fines to CNY 10 million; the Certification Measures for Cross-Border Data Transfers (effective January 1, 2026) and GB/T 46068-2025 standard (effective March 1, 2026); the PIPL Compliance Audit Measures (effective May 1, 2025) with revised 10-million-individual threshold; new Cybersecurity Incident Reporting Measures (effective November 1, 2025) introducing tiered 1-to-4-hour reporting timelines; the minors personal information audit annual filing requirement (initial deadline January 31, 2026); and updated 2025 enforcement actions including the first cross-border transfer penalty against a European luxury brand.

Original publication covering PIPL (Nov 2021), Data Security Law (Sept 2021), Cybersecurity Law (June 2017), CAC enforcement, Didi CNY 8.026 billion fine, Network Data Security Management Regulations (Jan 2025), and cross-border transfer framework.

Sources and References

  1. Personal Information Protection Law full text (Stanford DigiChina translation)(digichina.stanford.edu)
  2. China: Amended Cybersecurity Law Takes Effect (Library of Congress)(loc.gov).gov
  3. China Finalises Amendments to the Cybersecurity Law (Mayer Brown)(mayerbrown.com)
  4. Regulation on Network Data Security Management (PRC State Council)(english.www.gov.cn).gov
  5. Hong Kong PCPD overview of Mainland PIPL(pcpd.org.hk).gov
  6. CAC fines Didi RMB 8 billion for PIPL, CSL, and DSL violations(dataguidance.com)
  7. Measures for Personal Information Protection Compliance Audits (Mayer Brown)(mayerbrown.com)
  8. China Cross-Border Data Transfer Certification Measures (China Briefing)(china-briefing.com)
  9. China Data Privacy Enforcement: Cross-Border Transfer Cases (Arnold and Porter)(arnoldporter.com)
  10. China Annual Filing Requirement for Audits of Minors Personal Information (Arnold and Porter)(arnoldporter.com)
  11. New Cybersecurity Incident Reporting Measures in China (Bird and Bird)(twobirds.com)
  12. China DPO Reporting Requirement Now in Effect (Covington Inside Privacy)(insideprivacy.com)
  13. PIPL vs GDPR Key Differences (China Briefing)(china-briefing.com)
  14. Network Data Security Management Regulations (IAPP)(iapp.org)
  15. China Cybersecurity Law Amendments Increase Penalties (Latham and Watkins)(lw.com)
  16. CAC public notice naming 33 apps for personal information violations (April 27, 2026)(cac.gov.cn).gov
  17. CAC, MIIT, and MPS joint notice launching a 2026 special campaign on personal information violations in apps and SDKs (April 2, 2026)(cac.gov.cn).gov
  18. CAC Provisions on Promoting and Regulating Cross-Border Data Flows (Order 16, effective March 22, 2024) -- source for the corrected transfer-mechanism thresholds(cac.gov.cn).gov
Share: