🇨🇳 China · Privacy & Data Protection
Data-protection regime (GDPR/CCPA/PIPL and local laws), registration duties, and the official supervisory authority.
China's data regime centres on the Personal Information Protection Law (PIPL), alongside the Data Security Law and Cybersecurity Law, with the Cyberspace Administration of China (CAC) as the lead regulator. Organisations generally need a legal basis (often consent) to process personal information, must protect it, and must satisfy strict cross-border transfer rules (CAC security assessment, standard contract, or certification).
- The PIPL (with the Data Security Law and Cybersecurity Law) governs personal information; CAC is the lead regulator.
- You generally need a legal basis (often consent) and must protect personal information.
- Cross-border transfers must meet strict rules (CAC security assessment, standard contract, or certification).
Official authorities
- Cyberspace Administration of China (CAC)
Lead regulator for personal information and data.
Official-information aggregation, not legal advice. Always verify on the authority's own site.
Government portals
- China Government Portal — State Council official portal — policy releases, public services, and government documents
- Ministry of Foreign Affairs — China's foreign policy and consular services — passport, visa, and consular protection info
- National Immigration Administration — Visas, permanent residency, and border control for foreigners entering China
- State Taxation Administration — Personal income tax filing, business tax registration, and VAT invoice verification