Data compliance and cybersecurity in China runs on three overlapping laws at once: the PIPL (Personal Information Protection Law), the Cybersecurity Law, and the Data Security Law.

Together they create a framework fundamentally different from GDPR — with data-localization rules, mandatory security assessments before certain data can leave the country, and multiple regulators sharing jurisdiction. For foreign companies, the consequences of China data-compliance violations are concrete: fines that can reach 5% of annual revenue, outright bans on cross-border data transfers, and suspension of operations. China’s data regime is not a localized version of the rules a company already follows elsewhere — it is a separate system that has to be complied with on its own terms.

Why Data Compliance in China Is Different

The revised Cybersecurity Law (CSL), which came into force on 1 January 2026, addresses the rapid development of digital technologies and new cybersecurity challenges, strengthens the cyber governance system, and safeguards the digital economy and cyberspace. The Data Security Law (DSL), effective in 2021, classifies and categorizes data according to its sensitivity and introduces national security vetting and cross-border rules. The Personal Information Protection Law (PIPL), also effective in 2021, is China’s comprehensive personal-data statute. The three overlap: a single processing activity can trigger obligations under all three at once, which is the first thing that surprises companies arriving from a single-regulation environment.

PIPL compliance in China shares concepts with the General Data Protection Regulation — lawful bases, data-subject rights, breach notification — but diverges in ways that matter. PIPL’s consent requirements are stricter in places, requiring ‘separate consent’ for sensitive data, cross-border transfers, and other specific scenarios. It asserts extraterritorial reach over the processing of PRC residents’ data from abroad. And it pairs with data-localization obligations and pre-transfer security assessments that have no direct GDPR equivalent. Treating PIPL as ‘GDPR for China’ is one of the most common and costly mistakes.

Data protection enforcement in China is shared among several regulators with overlapping jurisdiction — the Cyberspace Administration of China (CAC) as the lead, alongside the MIIT and the Ministry of Public Security — and sector regulators add their own rules for financial services, healthcare, and operators of critical information infrastructure. Enforcement has real teeth: the landmark DiDi case ended in a penalty exceeding RMB 8 billion, with personal fines on senior executives. For a foreign company, this means compliance is not a single filing, but an ongoing posture maintained across multiple authorities.

Cybersecurity Law & Data Security Law in China

The Chinese Cybersecurity Law (CSL) applies to virtually every company that operates a network in China — which, in practice, means almost all of them. It imposes baseline network-security obligations, the multi-level protection scheme (MLPS) grading of IT systems, and far stricter requirements on operators of critical information infrastructure, whose procurement can trigger a national-security review.

The Data Security Law (DSL) sits alongside it, establishing a data-classification system — general, important, and core data — with escalating obligations at each level, plus a national-security review for data activities that affect national security. Cybersecurity and data protection compliance in China cannot be separate workstreams: a single system can owe MLPS obligations under the CSL, classification and handling duties under the DSL, and personal-information rules under the PIPL simultaneously. For foreign-invested enterprises, the practical consequence is that IT infrastructure, data handling, and privacy practices all have to be designed against this combined data protection law framework from the outset — retrofitting compliance after a system is built is far more expensive.

PIPL Compliance: Key Obligations

PIPL compliance requirements turn on a set of obligations that look familiar to anyone who knows GDPR but differ in the operational detail that determines whether a company is actually compliant.

  • Unlike GDPR, the PIPL does not treat ‘legitimate interest’ as a general lawful basis — most processing by private companies rests on consent, which raises the stakes on getting consent right. Consent must also be informed: before collecting personal information, a company has to give a clear notice covering who is processing the data, for what purpose, by what method, how long it is kept, and how individuals exercise their rights. For sensitive personal information, cross-border transfers, and several other scenarios, the PIPL requires ‘separate consent’ — a distinct, specific, affirmative opt-in, not a bundled acceptance of a general privacy policy. This separate-consent requirement is stricter than GDPR in practice and is a frequent compliance gap.
  • Sensitive personal information under PIPL — biometrics, financial accounts, health, religious beliefs, location data, and any data on minors under 14 — carries additional obligations, including a documented necessity justification and, in many cases, a data protection assessment (the personal information protection impact assessment the PIPL requires for higher-risk processing). Data subjects have rights to access, correct, delete, and port their data, and to withdraw consent, which a company must be operationally able to honor.
  • PIPL Personal Information Protection Officer (PIPO) requirements apply to processors handling large volumes — a designated, accountable role with no direct GDPR equivalent. Meeting these regulatory requirements is not a one-time documentation exercise; it means building consent flows, assessment processes, and a response capability for data-subject requests into how the business actually operates in China.

Cross-Border Data Transfer in China

Cross-border data transfer compliance is the single most operationally complex part of data compliance in China. Moving personal information out of the country requires one of three legal mechanisms under the PIPL: a CAC security assessment, a filing of the China Standard Contract (the SCC), or a personal-information protection certification. Which one applies depends mainly on volume and data type.

China cross-border data transfer mechanisms (effective March 2024) set clear thresholds CAC security assessment — the most demanding route — is mandatory for transferring ‘important data,’ for any critical-information-infrastructure operator, or for transferring the non-sensitive personal information of more than one million people or the sensitive personal information of more than 10,000 people in a year. Below those levels, the Standard Contract or certification route generally applies, and transfers of non-sensitive personal information below 100,000 people — along with specific scenarios such as cross-border HR management and contract performance — are exempt from all three mechanisms.

In practice, the security assessment is the hard case: it requires detailed data mapping, can take months, and is far from guaranteed to succeed. For EU-China data flows, the two regimes stack — a transfer can require both a GDPR transfer mechanism on the outbound EU side and a PIPL mechanism on the China side. The certification route, finalized in measures effective in 2026, is increasingly attractive for intra-group transfers within multinationals. Getting this wrong is not theoretical: unauthorized cross-border transfers are an active enforcement priority, and the cost of an unapproved data export can be an operational shutdown of the data flow the business depends on.

Data Localization & Security Requirements

Data localization and MLPS 2.0 requirements in China catch foreign companies off guard: data localization and the multi-level protection scheme.

Data localization applies most directly to critical information infrastructure operators (CIIOs), which must store the personal information and important data they collect and generate in China on servers physically located in the mainland; moving that data abroad requires passing a security assessment. The multi-level protection scheme (MLPS 2.0) is a mandatory cybersecurity-grading framework under the Cybersecurity Law: network systems are graded by their importance and potential impact (commonly levels 2 to 4 for most business systems), and each grade carries defined technical and management requirements, including filing with the public-security authorities. Foreign companies frequently overlook MLPS when standing up systems in China, only to discover the obligation during an audit or a transaction. Underneath both sits the DSL’s data-classification scheme — general, important, and core data — which determines how strictly any given dataset must be handled. Designing infrastructure and data handling against these requirements from the start is far cheaper than remediating later.

Enforcement & Regulatory Response in China

Data enforcement in China is shared among several regulators with overlapping jurisdiction. The Cyberspace Administration of China (CAC) is the lead data and cybersecurity regulator; the Ministry of Industry and Information Technology (MIIT) oversees telecoms and many app-related obligations; and the Ministry of Public Security (MPS) handles cybersecurity policing and the MLPS system. Sector regulators add further layers.

Enforcement has intensified, and penalties are substantial — the DiDi case, with a fine exceeding RMB 8 billion and personal fines on senior executives, set the tone. China data breach notification and incident response is time-sensitive and procedural: the PIPL and the CSL impose breach-notification obligations on regulators and, in defined cases, on affected individuals, and a dedicated cybersecurity-incident reporting regime sets timelines that depend on the severity of the incident. How a company handles the notification, the regulator interaction, and the remediation in the first days often determines whether an incident becomes a manageable matter or a much larger liability. Having local counsel who can manage the regulator relationship directly is the difference between a controlled response and an escalating one.

Our Role as a Cybersecurity and Data Compliance Law Firm in China

As a China cybersecurity and data-compliance law firm with a permanent presence in China, we provide data compliance services to foreign enterprises that must comply with the PIPL, the CSL, and the DSL simultaneously. Our practicing lawyers in China handle the relevant work locally, responding to corporate enquiries regarding data security and personal information protection, conducting MLPS and data classification analyses, drafting privacy notices and policies, and assisting with the preparation and filing of cross-border data transfer mechanisms.

A data protection lawyer on our China team also manages the regulator-facing side — responding to CAC and other inquiries, handling breach notifications, and representing the client in investigations — while our European and broader Asian network keeps the China program aligned with the company’s GDPR and other obligations, so EU-China data flows are handled coherently on both sides.

Because data compliance rarely stands alone, the same team draws on our corporate, employment, and contracts practices — the data clauses in a supply agreement, the employee-data side of HR, the diligence in a transaction — so a company gets one coordinated program rather than separate advice from separate firms.

Contact us for a
first consultation

CONTACT US FOR A FREE CONSULTATION

This field is for validation purposes and should be left unchanged.