Back to Frameworks

China Personal Information Protection Law (PIPL)

People's Republic of China
v2021
8 domains
52 controls

China's comprehensive personal information protection statute (effective 1 November 2021), administered by the Cyberspace Administration of China. Establishes legal bases for handling personal information, sensitive-PI and minors' rules, cross-border transfer mechanisms, individual rights, handler obligations (PIPIA, DPO, breach notification, audits) and legal liability.

Unverified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (8)

PIPL: Cross-Border Provision (Ch III)

6 controls
Controls in the PIPL: Cross-Border Provision (Ch III) domain of China Personal Information Protection Law (PIPL)6 controls
CodeTitle
PIPL-Art38Cross-Border Transfer Legal Mechanisms
PIPL-Art39Notice and Separate Consent for Cross-Border
PIPL-Art40Data Localisation and Security Assessment for CIIOs
PIPL-Art41Foreign Authority Requests Require Approval
PIPL-Art42Blocklist of Overseas Recipients
PIPL-Art43Reciprocal Countermeasures

PIPL: General Provisions (Ch I)

7 controls
Controls in the PIPL: General Provisions (Ch I) domain of China Personal Information Protection Law (PIPL)7 controls
CodeTitle
PIPL-Art3Scope and Extraterritorial Application
PIPL-Art4Definition of Personal Information and Handling
PIPL-Art5Lawfulness, Good Faith, Necessity
PIPL-Art6Purpose Limitation and Minimisation
PIPL-Art7Openness and Transparency
PIPL-Art8Quality of Personal Information
PIPL-Art9Security Responsibility of Handlers

PIPL: Handler Obligations (Ch V)

8 controls
Controls in the PIPL: Handler Obligations (Ch V) domain of China Personal Information Protection Law (PIPL)8 controls
CodeTitle
PIPL-Art51Security Measures and Management System
PIPL-Art52Designation of a DPO
PIPL-Art53Domestic Representative for Overseas Handlers
PIPL-Art54Regular Compliance Audits
PIPL-Art55Personal Information Protection Impact Assessment
PIPL-Art56PIPIA Content and Retention
PIPL-Art57Breach Remediation and Notification
PIPL-Art58Large Platform Obligations

PIPL: Individual Rights (Ch IV)

7 controls
Controls in the PIPL: Individual Rights (Ch IV) domain of China Personal Information Protection Law (PIPL)7 controls
CodeTitle
PIPL-Art44Right to Know and Decide
PIPL-Art45Right to Access, Copy and Portability
PIPL-Art46Right to Correction and Completion
PIPL-Art47Right to Deletion
PIPL-Art48Right to Explanation of Handling Rules
PIPL-Art49Rights of Deceased's Next of Kin
PIPL-Art50Request-Handling Mechanism and Remedy

PIPL: Legal Liability (Ch VII)

4 controls
Controls in the PIPL: Legal Liability (Ch VII) domain of China Personal Information Protection Law (PIPL)4 controls
CodeTitle
PIPL-Art66Administrative Penalties
PIPL-Art69Civil Liability (Fault Presumed)
PIPL-Art70Public Interest Litigation
PIPL-Art71Public Security and Criminal Liability

PIPL: PI Handling Rules (Ch II)

14 controls
Controls in the PIPL: PI Handling Rules (Ch II) domain of China Personal Information Protection Law (PIPL)14 controls
CodeTitle
PIPL-Art13Legal Bases for Handling
PIPL-Art14Consent Requirements
PIPL-Art15Right to Withdraw Consent
PIPL-Art16No Coerced Consent / No Service Refusal
PIPL-Art17Notice Content Before Handling
PIPL-Art19Retention Period Limitation
PIPL-Art20Joint Handlers
PIPL-Art21Entrusted Handling (Processors)
PIPL-Art22Transfer Due to Merger or Restructuring
PIPL-Art23Provision of PI to Third Parties
PIPL-Art24Automated Decision-Making
PIPL-Art25Public Disclosure Prohibited Without Consent
PIPL-Art26Image Collection in Public Places
PIPL-Art27Handling Already-Disclosed PI

PIPL: Sensitive PI (Ch II Sec 2)

5 controls
Controls in the PIPL: Sensitive PI (Ch II Sec 2) domain of China Personal Information Protection Law (PIPL)5 controls
CodeTitle
PIPL-Art28Sensitive PI Definition and Threshold
PIPL-Art29Separate Consent for Sensitive PI
PIPL-Art30Enhanced Notice for Sensitive PI
PIPL-Art31Minors Under 14
PIPL-Art32Sectoral and Administrative Restrictions

PIPL: State Organs (Ch II Sec 3)

1 controls
Controls in the PIPL: State Organs (Ch II Sec 3) domain of China Personal Information Protection Law (PIPL)1 controls
CodeTitle
PIPL-Art35State Organs Handling for Statutory Duties

Your Compliance Coverage

If you comply with China Personal Information Protection Law (PIPL), you already cover:

Maps to 7 other frameworks

52 total controls
GDPR
27 source controls mapped|15 target controls covered
52%
CCPA/CPRA
7 source controls mapped|6 target controls covered
13%
China Cybersecurity Law (CSL)
4 source controls mapped|3 target controls covered
8%
NIST Cybersecurity Framework 2.0
4 source controls mapped|4 target controls covered
8%
ISO 27001:2022
4 source controls mapped|3 target controls covered
8%
China Data Security Law (DSL)
4 source controls mapped|3 target controls covered
8%
ISO/IEC 17050-2:2004
1 source controls mapped|1 target controls covered
2%

Frequently Asked Questions

What is China Personal Information Protection Law (PIPL)?

China Personal Information Protection Law (PIPL) is a compliance framework from People's Republic of China with 8 domains and 52 controls. China's comprehensive personal information protection statute (effective 1 November 2021), administered by the Cyberspace Administration of China. Establishes legal bases for handling personal information, sensitive-PI and minors' rules, cross-border transfer mechanisms, individual rights, handler obligations (PIPIA, DPO, breach notification, audits) and legal liability. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does China Personal Information Protection Law (PIPL) have?

China Personal Information Protection Law (PIPL) has 52 controls organised across 8 domains. The largest domains are PIPL: PI Handling Rules (Ch II) (14 controls), PIPL: Handler Obligations (Ch V) (8 controls), PIPL: General Provisions (Ch I) (7 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does China Personal Information Protection Law (PIPL) map to?

China Personal Information Protection Law (PIPL) maps to 7 other compliance frameworks. The top mapping partners are GDPR (52% coverage), CCPA/CPRA (13% coverage), China Cybersecurity Law (CSL) (8% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with China Personal Information Protection Law (PIPL) compliance?

Start your China Personal Information Protection Law (PIPL) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about China Personal Information Protection Law (PIPL) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 52 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 706 frameworks.

Get Started Free →

Free forever — no credit card required