TODAY: 1 NEW BREACH·LAST 30 DAYS: 4·RECORDS THIS YEAR: 5.6M·MOST TARGETED: GOVERNMENT·TOP ORIGIN: France·LARGEST BREACH: MedCore Systems — S3 Bucket Exposure (4.2M)·GLOBAL THREAT LEVEL: NORMAL·TODAY: 1 NEW BREACH·LAST 30 DAYS: 4·RECORDS THIS YEAR: 5.6M·MOST TARGETED: GOVERNMENT·TOP ORIGIN: France·LARGEST BREACH: MedCore Systems — S3 Bucket Exposure (4.2M)·GLOBAL THREAT LEVEL: NORMAL
🇨🇳

China Data Privacy Regulations

Personal Information Protection Law (PIPL)
Critical Severity
Enacted: 2021 (Amended: 2021)

Overview

The PIPL works alongside the Cybersecurity Law (CSL) and Data Security Law (DSL) to form China's robust data governance regime.It enforces strict national security reviews, localized data hosting, and significant cross - border transfer hurdles.

Scope of Application:

Processing of personal information inside China, and extraterritorial application similar to GDPR if targeting Chinese citizens.

Key Rules & Obligations

Breach Notification

Immediately upon discovery of risk or occurrence of a breach.

Maximum Penalties

Up to RMB 50 million or 5% of the preceding year's revenue; potential revocation of business licenses.

Data Transfers

Highly stringent. Requires CAC security assessment, standard contracts, or personal information protection certification depending on data volume.

Individual Rights

  • Close to GDPR rights
  • Right to withdraw consent
  • Right regarding automated decision-making
  • Rights of deceased persons

Enforcement Authority

Cyberspace Administration of China (CAC)

Contact: N/A

Visit Authority Website

Notable Breaches in China

CompanyYearRecords ExposedRegulation Violated
Didi Chuxing2022Unknown (Penalized for illegal collection)PIPL / CSL / DSL
Shanghai Police App20221,000,000,000Unknown

Official Sources

Frequently Asked Questions

Is PIPL stricter than GDPR?

In terms of national security, data localization, and cross-border data transfer, PIPL is significantly stricter. It also strongly emphasizes "separate consent" for actions like sharing data abroad.

Can foreign companies transfer data out of China?

Yes, but it requires passing a CAC security assessment or registering standard contracts, a process known to be administratively heavy and rigorous.

What happens if a company violates the PIPL?

Fines can reach 5% of annual revenue, matching GDPR scale, but authorities can also directly suspend business operations or block digital services entirely.

Last updated: March 5, 2026

Notice an error? Report a correction