🇨🇳 China · Privacy & Data Protection

Data-protection regime (GDPR/CCPA/PIPL and local laws), registration duties, and the official supervisory authority.

China's data regime centres on the Personal Information Protection Law (PIPL), alongside the Data Security Law and Cybersecurity Law, with the Cyberspace Administration of China (CAC) as the lead regulator. Organisations generally need a legal basis (often consent) to process personal information, must protect it, and must satisfy strict cross-border transfer rules (CAC security assessment, standard contract, or certification).

  • The PIPL (with the Data Security Law and Cybersecurity Law) governs personal information; CAC is the lead regulator.
  • You generally need a legal basis (often consent) and must protect personal information.
  • Cross-border transfers must meet strict rules (CAC security assessment, standard contract, or certification).

Official authorities

Official-information aggregation, not legal advice. Always verify on the authority's own site.

Government portals

This topic in other countries

← Back to China