China's PIPL combines recognizable privacy rights with a data-export regime that functions as a national security control. This hub covers export assessments, localization duties, and enforcement reaching foreign companies.

China (PIPL)

China's Network Data Regulations Put a Price on Scraping, Recommendation Switches and Important Data

September 21, 2026

The Regulations on Network Data Security Management are an administrative regulation of the State Council, made to implement three statutes at once rather than one. They define who a network data processor is, add concrete rules on privacy notices, portability and personalised recommendation, impose annual risk reporting on holders of important data, and set their own fine schedule.

Read more →
China (PIPL)

China's PIPL Audit Duty Waited Four Years for a Frequency, a Trigger List and an Annex of 27 Checks

September 21, 2026

Article 54 of China's Personal Information Protection Law has required regular compliance audits since November 2021, without saying how often, by whom or against what. The CAC's Measures for Personal Information Protection Compliance Audits, in force since 1 May 2025, supply those answers, and add a second route by which a regulator can order an outside audit at the processor's expense.

Read more →
China (PIPL)

China Decides Data Exports by Headcount, Not by Where the Data Is Going

August 24, 2026

Every other regime in this series asks whether the destination country protects data adequately. China's asks a different question: how many people's information is leaving, whether any of it is sensitive, and whether the exporter runs critical information infrastructure. This guide sets out the export thresholds in the 2024 CAC Provisions, and the PIPL machinery underneath them.

Read more →