November 8, 2023
The Personal Information Protection Law of the People’s Republic of China is a particular law enacted for the purposes of protecting the rights and interests on personal information, regulating personal information processing activities, and promoting reasonable use of personal information (Art.1).
The PIPL entered into force as of the 1st of November 2021, nearly 3 months after being adopted at the 30th Meeting of the Standing Committee of the Thirteenth National People’s Congress on August 20, 2021.
No, the PIPL is the first national-level law of the People’s Republic of China (the PRC) to address personal information processes in order to protect legal rights and interests of the data subjects.
According to Art.3, the PIPL generally applies to all personal information processes within the territory of the PRC. Besides, the PIPL also has extra-territorial effect, regulating the process of within the PRC natural persons’ data, however, conducted outside the territory of the PRC, under some circumstances, such as for the purpose of providing products or services for natural persons inside the PRC.
According to Art.2, the personal information of natural persons shall be the main entity of protection by the law. Therefore, the PIPL applies to all organizations or individuals in both the public and private sectors having relevance to personal information processes within the preceding-mentioned territorial scope.
Generally, the PIPL has 8 chapters and 73 articles, regulating on:
(i) Process of normal and sensitive personal information within and across border of the PRC;
(ii) State organs data use;
(iii) Individuals’ rights in personal information processing activities;
(iv) Obligations of personal information processors;
(v) Legal liabilities;
(vi) Miscellaneous supplementary provisions.
According to Art.4, “personal information” is considered as any sort of information recorded by electronic means or others, which is related to an identified or identifiable natural person within the PRC but does not include anonymized information.
According to Art.4, personal information processing consists of personal information collection, storage, use, processing, transmission, provision, disclosure, deletion and so on.
According to Art.5 and Art.6, personal information processing shall be mainly based on the following principles:
(i) According to law, with justified reasons, in good faith, and the processing may not involve misguidance, fraud, coercion, and the like.
(ii) Resulting from explicit and reasonable purposes and directly related to those purposes, and shall exert the minimum impacts on the rights and interests of individuals.
(iii) Limiting the scope of data collection to the minimum required by the purpose of processing, and personal information may not be collected excessively.
According to Art.13, there are seven legal bases for processing personal information:
(i) Obtaining the data subject’s consent;
(ii) Where necessary for the conclusion or performance of a contract in which the individual is a party, or for personnel management;
(iii) Where necessary for the performance of statutory duties or obligations;
(iv) Where necessary for public health emergencies’ response, or for protecting the life, health, and property safety of natural persons in emergencies;
(v) Information utilization for news reporting, media supervision, and other activities for the purpose of the public interest;
(vi) Information which has been already disclosed personal information by the individual himself or other legal disclosure;
(vii) In other circumstances permitted by laws or administrative regulations.
Furthermore, individual consent shall be required if any other relevant regulations so provide, except for the preceding specified cases.
The PIPL entitles the data subjects (individuals) some rights in order to support their PI self-protection:
(i) Be informed and allowed to decide on the processing of their personal information (Art.44).
(ii) Be entitled to access and make a copy of their personal information (Art.45).
(iii) Be entitled to transfer their personal information from one processor to another (Art.45).
(iv) Be entitled to request to correct and/or supplement their personal information if incorrect or incomplete (Art.46).
(v) Be entitled to request the processor to delete their personal information in regulated cases (Art.47).
(vi) Be entitled to request an interpretation for the processor’s personal information processing regulations (Art.48).
(vii) The deceased’s close relatives shall be entitled to exercise the rights to handle their personal information (Art.49).
According to Art.60, the national cyberspace department and the relevant departments of the State Council, the Ministry of Science and Technology, the Ministry of Public Security, for instance, are entitled to enforce the PIPL.
The former shall take the responsibility for the overall planning and coordination of personal information protection and related supervision and administration.
Meanwhile, the latter shall be responsible for personal information protection and related supervision and administration within the scope of their respective duties.
PrivacyCompliance
Territorial Scope of GDPR In the modern world, data is flowing across borders at an unprecedented rate. This creates risks for the data since most laws are only effective within their respective borders and cannot guarantee adequate protection when the data is transferred abroad. It is for this reason that the General Data Protection Regulation […]
Learn more
Independent Supervisory Authorities Under GDPR The EU’s General Data Protection Regulation (“GDPR”) is an incredibly useful framework to protect personal data. However, all rules are only as good as our ability to enforce them, a legal framework alone cannot protect personal data. As such, independent enforcement agencies are required to put the regulations into practice. […]
Learn more
E-Privacy Directive The Directive 2002/58/EC or e-Privacy Directive (ePD) – also known as the Privacy and Electronic Communications Directive, is a regulatory framework established by the European Union (EU) to protect the privacy of individuals. With similar functions to the General Data Protection Regulation (GDPR), the ePD remains in effect alongside the GDPR with the […]
Learn more