verified_user
Standardful
首页chevron_right标准chevron_rightPIPL
有效国际标准update 最后更新:2021年11月

PIPL

个人信息保护法

apartment发布组织:国家互联网信息办公室 (CAC)

标准简介

PIPL 是由 国家互联网信息办公室 (CAC) 发布的有效标准,常用于科技、金融银行、零售、医疗健康、服务业等行业,并适用于中国等市场。

本页汇总了 PIPL 的官方文档、当前状态以及常见相关认证或评估机构,便于快速理解要求与落地路径。

public

Extraterritorial Application

Applies to processing of personal information of individuals within China, even when the data processor is located outside China — covering foreign companies offering products or services to Chinese residents.

warning

Severe Penalties

Grave violations can incur fines up to RMB 50 million or 5% of the previous year's annual revenue, plus personal liability for responsible individuals up to RMB 1 million and bans from senior positions.

lock

Strict Cross-Border Rules

Cross-border data transfers require security assessments, standard contracts, or certification — with mandatory CAC security assessment for critical information infrastructure operators and large-scale processors.

list_alt Core Principles

  • Lawfulness, legitimacy, necessity, and good faith
  • Purpose limitation and data minimization
  • Transparency and openness
  • Data quality and accuracy
  • Accountability and security
  • Separate consent for sensitive personal information
  • Restrictions on automated decision-making
  • Special protections for minors under 14

Who Needs to Comply?

groups

Any organization that processes personal information of individuals within China — including Chinese companies, foreign companies with operations in China, and foreign companies that offer products or services to or analyze behavior of individuals in China.

Key Requirements

1

Legal Basis for Processing

Establish a lawful basis before processing personal information — individual consent, contract necessity, legal obligation, public health emergency, public interest, or information already made public by the individual.

2

Separate Consent for Sensitive Data

Obtain specific, informed separate consent before processing sensitive personal information including biometrics, religious beliefs, medical health data, financial accounts, location tracking, and data of minors under 14.

3

Cross-Border Data Transfer Compliance

For transferring personal information outside of China, complete a CAC security assessment (for CII operators or large-scale data), enter into standard contracts, or obtain personal information protection certification.

4

Personal Information Protection Impact Assessment

Conduct impact assessments before processing sensitive data, using personal information for automated decision-making, transferring data cross-border, or any processing that may significantly affect individuals' rights.

5

Incident Notification

Immediately take remedial measures upon discovering a personal information security incident. Notify the relevant regulatory authority and affected individuals, including the types of information involved, causes, and remediation measures.

Penalties & Enforcement

warning

For serious violations: fines up to RMB 50 million (approximately USD 7 million) or 5% of the prior year's annual revenue, suspension or termination of business, and revocation of business licenses. Responsible individuals face fines of RMB 100,000 to RMB 1 million and may be banned from holding senior management or DPO positions.

官方文档

查看全部

实施时间线

edit_document
2020年10月
PIPL draft published for public comment
gavel
2021年8月
PIPL adopted by the Standing Committee of the National People's Congress
check_circle
2021年11月
PIPL entered into force
description
2023年2月
Standard Contract Measures for cross-border personal information transfer took effect
update
2024年3月
Regulations on Promoting and Regulating Cross-Border Data Flows issued, relaxing some transfer requirements

相关分类