China Personal Information Protection Law (PIPL)
China's comprehensive personal information protection statute (effective 1 November 2021), administered by the Cyberspace Administration of China. Establishes legal bases for handling personal information, sensitive-PI and minors' rules, cross-border transfer mechanisms, individual rights, handler obligations (PIPIA, DPO, breach notification, audits) and legal liability.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (8)
PIPL: Cross-Border Provision (Ch III)
| Code | Title |
|---|---|
| PIPL-Art38 | Cross-Border Transfer Legal Mechanisms |
| PIPL-Art39 | Notice and Separate Consent for Cross-Border |
| PIPL-Art40 | Data Localisation and Security Assessment for CIIOs |
| PIPL-Art41 | Foreign Authority Requests Require Approval |
| PIPL-Art42 | Blocklist of Overseas Recipients |
| PIPL-Art43 | Reciprocal Countermeasures |
PIPL: General Provisions (Ch I)
| Code | Title |
|---|---|
| PIPL-Art3 | Scope and Extraterritorial Application |
| PIPL-Art4 | Definition of Personal Information and Handling |
| PIPL-Art5 | Lawfulness, Good Faith, Necessity |
| PIPL-Art6 | Purpose Limitation and Minimisation |
| PIPL-Art7 | Openness and Transparency |
| PIPL-Art8 | Quality of Personal Information |
| PIPL-Art9 | Security Responsibility of Handlers |
PIPL: Handler Obligations (Ch V)
| Code | Title |
|---|---|
| PIPL-Art51 | Security Measures and Management System |
| PIPL-Art52 | Designation of a DPO |
| PIPL-Art53 | Domestic Representative for Overseas Handlers |
| PIPL-Art54 | Regular Compliance Audits |
| PIPL-Art55 | Personal Information Protection Impact Assessment |
| PIPL-Art56 | PIPIA Content and Retention |
| PIPL-Art57 | Breach Remediation and Notification |
| PIPL-Art58 | Large Platform Obligations |
PIPL: Individual Rights (Ch IV)
| Code | Title |
|---|---|
| PIPL-Art44 | Right to Know and Decide |
| PIPL-Art45 | Right to Access, Copy and Portability |
| PIPL-Art46 | Right to Correction and Completion |
| PIPL-Art47 | Right to Deletion |
| PIPL-Art48 | Right to Explanation of Handling Rules |
| PIPL-Art49 | Rights of Deceased's Next of Kin |
| PIPL-Art50 | Request-Handling Mechanism and Remedy |
PIPL: Legal Liability (Ch VII)
| Code | Title |
|---|---|
| PIPL-Art66 | Administrative Penalties |
| PIPL-Art69 | Civil Liability (Fault Presumed) |
| PIPL-Art70 | Public Interest Litigation |
| PIPL-Art71 | Public Security and Criminal Liability |
PIPL: PI Handling Rules (Ch II)
| Code | Title |
|---|---|
| PIPL-Art13 | Legal Bases for Handling |
| PIPL-Art14 | Consent Requirements |
| PIPL-Art15 | Right to Withdraw Consent |
| PIPL-Art16 | No Coerced Consent / No Service Refusal |
| PIPL-Art17 | Notice Content Before Handling |
| PIPL-Art19 | Retention Period Limitation |
| PIPL-Art20 | Joint Handlers |
| PIPL-Art21 | Entrusted Handling (Processors) |
| PIPL-Art22 | Transfer Due to Merger or Restructuring |
| PIPL-Art23 | Provision of PI to Third Parties |
| PIPL-Art24 | Automated Decision-Making |
| PIPL-Art25 | Public Disclosure Prohibited Without Consent |
| PIPL-Art26 | Image Collection in Public Places |
| PIPL-Art27 | Handling Already-Disclosed PI |
PIPL: Sensitive PI (Ch II Sec 2)
| Code | Title |
|---|---|
| PIPL-Art28 | Sensitive PI Definition and Threshold |
| PIPL-Art29 | Separate Consent for Sensitive PI |
| PIPL-Art30 | Enhanced Notice for Sensitive PI |
| PIPL-Art31 | Minors Under 14 |
| PIPL-Art32 | Sectoral and Administrative Restrictions |
PIPL: State Organs (Ch II Sec 3)
| Code | Title |
|---|---|
| PIPL-Art35 | State Organs Handling for Statutory Duties |
Your Compliance Coverage
If you comply with China Personal Information Protection Law (PIPL), you already cover:
GDPR
52%
27 controls mapped
Compare →CCPA/CPRA
13%
7 controls mapped
Compare →China Cybersecurity Law (CSL)
8%
4 controls mapped
Compare →+ 4 more: NIST Cybersecurity Framework 2.0 (8%), ISO 27001:2022 (8%)
See all 7 mapped frameworks ↓Maps to 7 other frameworks
Frequently Asked Questions
What is China Personal Information Protection Law (PIPL)?
China Personal Information Protection Law (PIPL) is a compliance framework from People's Republic of China with 8 domains and 52 controls. China's comprehensive personal information protection statute (effective 1 November 2021), administered by the Cyberspace Administration of China. Establishes legal bases for handling personal information, sensitive-PI and minors' rules, cross-border transfer mechanisms, individual rights, handler obligations (PIPIA, DPO, breach notification, audits) and legal liability. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does China Personal Information Protection Law (PIPL) have?
China Personal Information Protection Law (PIPL) has 52 controls organised across 8 domains. The largest domains are PIPL: PI Handling Rules (Ch II) (14 controls), PIPL: Handler Obligations (Ch V) (8 controls), PIPL: General Provisions (Ch I) (7 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does China Personal Information Protection Law (PIPL) map to?
China Personal Information Protection Law (PIPL) maps to 7 other compliance frameworks. The top mapping partners are GDPR (52% coverage), CCPA/CPRA (13% coverage), China Cybersecurity Law (CSL) (8% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with China Personal Information Protection Law (PIPL) compliance?
Start your China Personal Information Protection Law (PIPL) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about China Personal Information Protection Law (PIPL) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 52 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 706 frameworks.
Get Started Free →Free forever — no credit card required