Personal Information Protection Law China
Definition
Personal Information Protection Law China
Personal Information Protection Law China is the country’s privacy statute, in force since 2021 and binding on handlers inside and outside the mainland. Entrusted processing requires a written agreement, and the handler answers for everything that its processor does.
The law arrived alongside the Data Security Law and the Cybersecurity Law, and the three operate together as one regime.
Its structure will look familiar to anyone who has read European privacy law — the vocabulary differs, but the logic of purpose, consent and accountability is recognisable.
What is not familiar is the transfer regime. Moving personal information out of the mainland requires a specific mechanism, chosen in advance and documented.
Key takeaways
- The law uses personal information handler and entrusted party rather than controller and processor.
- An entrusted party may not exceed the agreed scope or delegate further without consent.
- Cross-border transfers need one of three defined mechanisms before data moves.
- Penalties reach 5 percent of annual revenue at the top of the range.
How it works
The statute puts the handler in charge and treats the outsourced party as an extension of it. A handler that entrusts processing must agree the purpose, time limit, method, data categories, protection measures and both parties’ rights and duties.
The entrusted party is then boxed in. It may not exceed the agreed scope, and it cannot further delegate to others without the handler’s consent, which makes undisclosed subcontracting a breach rather than a commercial detail.
Extraterritorial reach catches offshore providers. The law applies to processing outside the mainland carried out for the purposes of providing products or services to PRC residents, or for analysing their behaviour.
| Requirement | What it means for an outsourcing contract |
|---|---|
| Entrustment agreement | Purpose, duration, method, data categories and protection measures in writing |
| Scope limit | The provider may not process beyond what was agreed |
| No onward delegation | Sub-processing needs the handler’s consent |
| Deletion or return | Data goes back or is destroyed when the entrustment ends |
| Transfer mechanism | Security assessment, standard contract filing or certification |
Cross-border movement has three routes — a regulator security assessment, standard contractual clauses filed with the authorities, or certification, with narrow exemptions for some human resources and contractual scenarios.
Separate consent is also required for transfers — the individual must be told the recipient’s name, contact details, purpose, methods and the categories of information involved.
Examples
Foreign companies underestimate how often their arrangements touch this law, and the reach is wider than any org chart suggests. The cases below were settled by lawyers rather than by anybody in operations.
A European retailer runs customer service for its China storefront from Kuala Lumpur. The processing sits offshore but serves people in China, so the law reaches the arrangement anyway.
A manufacturer consolidates payroll for its Chinese subsidiary into a shared service centre in Manila. Employee data leaving the mainland requires a transfer mechanism, and intra-group status does not create an exemption.
A software company’s Chinese entity uses a domestic vendor for data labelling. The vendor quietly used a smaller firm for overflow work, which breached the no-delegation rule long before anyone noticed.
A logistics platform stores order data with a mainland cloud provider and mirrors it abroad for analytics. The mirror is a cross-border transfer, and calling it a backup does not change the analysis.
Related terms
Chinese privacy vocabulary maps imperfectly onto the European terms that buyers usually arrive holding. Each of these sits beside this regime, and none of them is a synonym.
- GDPR outsourcing: the European processor regime this law resembles without copying.
- PDPA outsourcing: the Singapore regime, lighter on transfer mechanics.
- ISO 27018: the cloud privacy code providers cite when handling personal data.
- ISO 27701: the privacy management certification buyers ask for during diligence.
- Business process outsourcing (BPO): the delivery model that most often creates entrusted processing.
- Compliance outsourcing: contracting the compliance function rather than the data handling.
- Risk outsourcing: moving risk work to a provider without moving the exposure.
FAQ
Does the law apply to a company with no China entity?
It can. Processing carried out abroad falls in scope where it serves the offering of products or services to people in China, or the analysis of their behaviour.
Is an entrusted party liable directly?
The handler carries the principal duty. The entrusted party is bound by the agreement and by its own obligations, including the ban on exceeding scope.
Can we move data out of China?
Yes, through a security assessment, filed standard contractual clauses or certification. Some human resources and contract-performance scenarios are exempt.
Does consent cover everything?
No. Transfers abroad require separate consent and a specific disclosure about the recipient, which is a distinct step from general processing consent.
What are the maximum penalties?
Serious violations can draw fines of up to 50 million yuan or 5 percent of annual revenue, alongside suspension orders and individual liability.
How does this compare to European law?
The concepts rhyme. The transfer regime is stricter and the consent architecture is more granular, so a European programme needs adaptation rather than translation.
Browse Outsource Accelerator and narrow the field to firms that survive a supervisory question.







Independent




