If you live or work in China, your personal information is protected by law. Since November 2021, China‘s Personal Information Protection Law (PIPL) has established a comprehensive framework for how organizations collect, use, and transfer personal data.
1.Who Does the Law Protect?
The PIPL applies to anyone in China, regardless of nationality. It also applies to overseas organizations that process the personal information of individuals in China for purposes such as providing products or services, or analyzing behavior.
2.What Is Personal Information?
Personal information means any information related to an identified or identifiable individual. This includes your name, phone number, address, email, and even location data. Special protection applies to “sensitive personal information,” such as biometric data (fingerprints, facial recognition), financial accounts, medical records, religious beliefs, and information about children under 14.
3.Your Key Rights Under the PIPL
-Right to know and decide: You have the right to know how your information is being processed and to decide whether to allow it.
-Right to access and copy: You can request a copy of the personal information an organization holds about you.
-Right to correct and delete: If your information is inaccurate or no longer needed, you can ask for it to be corrected or deleted.
-Right to withdraw consent: You can withdraw your consent at any time, and the organization must provide an easy way to do so.
4.What About Facial Recognition?
The PIPL imposes strict rules on biometric information. In public places, devices that collect facial or other biometric data may only be installed when necessary for public security, and they must display clear signage. Such data cannot be used for other purposes unless you provide separate consent. Under rules effective June 2025, if an alternative non-facial recognition method exists for the same purpose, facial recognition cannot be the only verification option — and if you refuse facial verification, a reasonable alternative must be provided.
5.Cross-Border Data Transfers
If a company wants to send your personal information outside China, it must follow one of three legal pathways: security assessment, standard contract filing, or certification. The certification mechanism, effective January 2026, applies to non-critical infrastructure operators that transfer fewer than 1 million individuals’ general personal information or fewer than 10,000 individuals’ sensitive personal information annually.
6.Penalties for Violations
Violations of the PIPL can result in serious consequences. Fines can reach up to RMB 50 million or 5% of the previous year‘s revenue. Separately, the amended Cybersecurity Law, effective January 2026, raised the maximum fine for failing to fulfill network security obligations to RMB 10 million — a tenfold increase.
7.What Should You Do?
– Read privacy policies before clicking “agree.”
– Be cautious when granting permissions to apps, especially for camera, microphone, and location.
– If you believe your rights have been violated, you can file a complaint with the cyberspace administration authorities or seek legal assistance.
The PIPL is designed to give individuals control over their personal information. Understanding your rights is the first step to protecting them.
