China - Federal
Summary
Law: Personal Information Protection Law (PIPL) (Enforcement date of 1 November 2021)
Regulator: The Cyberspace Administration of China (the CAC).
Summary: On August 20, 2021, China approved the Personal Information Protection Law (PIPL), the first comprehensive data protection legislation in the region. The PIPL entered into effect on November 1, 2021, and established personal information processing rules, data subject rights, and obligations for personal information processors, among other things. The Cyberspace Administration of China (CAC) is responsible for the enforcement of the PIPL alongside issuing supplementary measures and guidance clarifying the provisions of the PIPL. Notably, the CAC has clarified provisions relating to cross-border data transfers under the PIPL, including the Standard Contract for Personal Information Exit (only available in Chinese), the Measures on Standard Contract for Personal Information Exit (only available in Chinese here), and the Outbound Data Transfer Security Assessment Measures (only available in Chinese here).
In addition to the PIPL, the National People's Congress (NPC) approved, on June 10, 2021, the Data Security Law (DSL), which entered into effect on September 1, 2021. The DSL regulates data processing activities associated with personal and non-personal data. There are also provisions related to personal data protection in several other pieces of legislation; most notably the Cybersecurity Law 2016 (official Chinese version here; unofficial English available here) which provides certain general requirements, and the regulations for the protection of children's personal information (only available in Chinese here) which contains obligations relating to the processing of children's personal data stipulated.
In addition, there are numerous non-binding guidelines and standards, which provide best practice recommendations for the handling of personal data. The most notable of these is Standard GB/T 35273-2020 on Information Security Technology - Personal Information Security Specification.