Support Centre



Law: Personal Information Protection Law ('PIPL') (Enforcement date of 1 November 2021)

Regulator: The Cyberspace Administration of China ('the CAC').

Summary: On 20 August 2021 China approved the PIPL, the first comprehensive data protection legislation in the region. The Law entered into effect on 1 November 2021 and established personal information processing rules, data subject rights, and obligations for personal information processors, among other things. In addition to the PIPL, the NPC has also approved, on 10 June 2021, the Data Security Law, which entered into effect on 1 September 2021. The Data Security Law regulates data processing activities associated with personal and non-personal data.

There are also provisions related to personal data protection in several other pieces of legislation; most notably the Cybersecurity Law 2016 which came into effect in 2017 (official Chinese version available here; unofficial English available here) ('the Cybersecurity Law') which provides certain general requirements, and the regulations for the protection of children's personal information (only available in Chinese here) which contains obligations relating to the processing of children's personal data stipulated. In addition, there are numerous non-binding guidelines and standards, which provide best practice recommendations for the handling of personal data. The most notable of these is Standard GB/T 35273-2020 on Information Security Technology - Personal Information Security Specification.


The Cyberspace Administration of China (CAC) published the Regulations on Promoting and Regulating Cross-border Data Flows (only available in Chinese here) (the Regulations) on March 22, 2024, following their initial request for public comment in October 2023. The Regulations aim to clarify data transfer obligations under the Cyber Security Law (CSL), Data Security Law (DSL), and the Personal Information Protection Law (PIPL) including the data export security assessment, personal information export standard contract, and personal information protection certification. OneTrust DataGuidance provides an analysis of the Regulations with comments provided by Dr. Michael Tan, Partner at Taylor Wessing.

In an era dominated by digital connectivity, safeguarding the integrity of networks and information systems has become a global imperative. China, recognizing the critical importance of cybersecurity, has introduced the draft Management Measures for Cybersecurity Incident Reporting (the Measures). The Measures outline a comprehensive approach to reporting cybersecurity incidents, aiming to minimize losses, incentivize legal compliance, protect national cybersecurity, and align with existing legal frameworks. Samuel Yang, Chris Fung, and Bill Zhou, from AnJie Broad Law Firm, explore key provisions in the Measures, shedding light on the intricacies of China's evolving cybersecurity landscape.

While representing a new source of growth for China's economy, intelligent and connected vehicles (ICVs) are confronted with institutional uncertainties on multiple fronts, such as market access, data protection, liability allocation, and so forth, which may affect the development of ICVs. In this Insight, Dr. Annie Xue, Yang Chen, and Xiaoqian Sun, from GEN Law Firm, look at the legislation around the development of ICVs with a particular focus on liability allocation, data security, and fair competition.

On October 15, 2023, the public comment period closed for the Cyberspace Administration of China's (CAC) draft Provisions on Regulating and Promoting Cross-Border Data Flows (the Draft Provisions). In this Insight article, Kate M. Growley, Evan Y. Chuck, Zhiwei Chen, and Christiana State, from Crowell & Moring LLP, explore existing mechanisms in place and how the Draft Provisions could affect companies' data transfer obligations.

The rapid development of artificial intelligence (AI) in China has made it an important player on the global stage. In response to society's concerns over potential issues that could arise from this new technology, China has rolled out several sets of rules regarding the use of AI which will have an impact on companies that intend to integrate AI into their daily operations in the Chinese market. The Interim Measures for the Administration of Generative Artificial Intelligence Services (AI Measures), released on July 10, 2023, have become a hot topic of conversation. While they represent a significant milestone in China's efforts to regulate AI, they may only have a limited impact on the companies using AI technologies.  

There is now another set of rules, but the title does not refer to the term AI so could be easily overlooked: the Technology Ethics Review Measures (Trial), promulgated by the Ministry of Science and Technology (MOST) together with several other ministries and institutions on September 7, 2023, which entered into effect on December 1, 2023 (Review Measures). After comparing with the earlier AI Measures, the Review Measures appear to be more relevant to international companies that plan to apply AI technologies in the course of their business in China and will be subject to some statutory obligations, including actionable measures. Dr. Michael Tan and Julian Sun, from Taylor Wessing, analyze these measures, exploring their relevance and practical implications for organizations.  

In many aspects, the Personal Information Protection Law (PIPL), which became effective on November 1, 2021, looks very similar to the EU's General Data Protection Regulations (GDPR). However, many of these similarities remain as high-level principles under the PIPL, while more detailed content has been rolled out step by step. Earlier this year, the Cyberspace Administration of China (CAC), established export security assessment procedures and Standard Contractual Clauses (SCCs) for data exports. Now, the CAC is shifting its focus to compliance audits. On August 3, 2023, the CAC presented the draft Administrative Measures for Compliance Audit of Personal Information Protection (Draft Audit Measures) soliciting public comments. For Data Protection Officers (DPOs) and compliance officers, this topic will become another important task to include in their planning for implementation in 2024.

In this Insight article, Julian Sun, from Taylor Wessing, delves into the key provisions of the Draft Audit Measures and sheds light on the evolving compliance audit framework, highlighting its importance, nuances, and potential impacts for companies operating in China.

On April 11, 2023, the Cyberspace Administration of China (CAC) released draft Administrative Measures for Generative Artificial Intelligence (Draft Measures) on April 11, 2023. The Draft Measures, which comprise 21 articles, aim to promote a healthy development and standardized application of generative artificial intelligence (AI) technology, while allowing room for research and development in this area.

Kevin Duan, Partner at Han Kun Law Offices, analyzes the regulatory issues and potential challenges that the Draft Measures may pose in practice.

The requirements for personal information protection in the health and pharmaceutical industries are complex. Danjun Wu, Partner at Guantao Law Firm, provides a two-part overview: part one introduces the basic requirements for personal information protection to be met by medical institutions and pharmaceutical companies, and part two introduces the specific protection obligations to be fulfilled by medical institutions and pharmaceutical companies in the key contexts of processing personal information.

The requirements for personal information protection in the health and pharmaceutical industries are complex. Danjun Wu, Partner at Guantao Law Firm, provides a two-part overview: part one introduces the basic requirements for personal information protection to be met by medical institutions and pharmaceutical companies, and part two introduces the specific protection obligations to be fulfilled by medical institutions and pharmaceutical companies in the key contexts of processing personal information.

Since 2021, in the wake of the Provisional Regulations on Data Security Management of the Automotive (the Automotive Data Regulations), and under the purview of China’s data protection legislation landmark legislations - the Data Security Law (DSL) and the Personal Information Protection Law (PIPL), data protection and cybersecurity concerns have become increasingly prominent in the automotive industry. The strengthened rules in processing automotive data impose challenges for automotive companies, especially in the process of human-machine interaction, e.g., the function of 360° panoramic camera, interior remote monitoring, remote intelligent parking, etc. In this article, Sherry Gong and Tong Zhu, from Hogan Lovells, look at the key compliance requirements and challenges for automotive companies to consider when navigating data protection in China.

As the digital economy continues to expand globally and the legal regimes of data protection vary in different jurisdictions, multinational companies carrying out cross-border data transfer activities face challenges in complying with multi-jurisdictional data protection regulations. In this context, those relatively flexible approaches for cross-border data transfers with less regulatory involvement will become important instruments for multinational companies seeking to navigate the legal landscape.

In this Insight article, Dora Luo (Duoqun), Partner at Hunton Andrews Kurth LLP, examines the similarities and differences between the Standard Contract for Cross-border Transfer of Personal Information (the Standard Contract) under the Personal Information Protection Law (PIPL) and the Standard Contractual Clauses (SCCs) under the General Data Protection Regulation (GDPR), with a particular focus on requirements, steps that must be taken before their use, circumstances that may require revision, and general comments.

Part one of this series presents an overview of the Information Security Technology - Technical Requirements of Security Design for Cybersecurity Classification Protection (GB/T 25070-2019) ('the Security Design Requirements'), Part two looks at the Information Security Technology - Implementation Guide for Classified Protection of Cybersecurity (GB/T 25058-2019) ('the 2019 Implementation Guide'), and Part three explores the Information Security Technology - Evaluation Requirements for Cybersecurity Classification Protection (GB/T 28448-2019) ('the Evaluation Requirement'). In this Insight article, Jim Fitzsimmons, Principal at Control Risks Group Limited, looks specifically at the GB/T 22239-2019 Information Security Technology – Baseline for Classified Protection of Information System Security (the Baseline Standard).