Personal Information Protection Law, Supervision and Legal Liability
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 November 2021.
An enforcement supervision rule binding public and private bodies.
As of 2 September 2026.
What it requires
- Comply with lawful CAC and sectoral-regulator investigation, including document production and on-site inspection.
- Bear the burden of proving the absence of fault once an individual establishes harm from unlawful personal information processing, or pay compensation.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
PIPL Article 71 provides that a violation constituting a public security administrative offence draws punishment under the Public Security Administration Punishments Law, and a violation constituting a crime draws criminal liability according to law. The criminal offence most commonly charged for personal-information violations is Criminal Law Article 253-1 (infringing citizens' personal information), which secondary legal commentary describes as carrying imprisonment of up to three years (or short-term detention) plus or in lieu of a fine for serious circumstances, rising to three to seven years' imprisonment plus a fine for especially serious circumstances. The imprisonment terms rest on well corroborated secondary commentary rather than on the amended primary text of Article 253-1; PIPL Article 71 itself, quoted in attribute_sources, is primary text.
Penalty structure
PIPL Article 66 sets a two-tier structure. The ordinary tier, triggered when a processor refuses to correct a violation, caps the organizational fine at RMB 1,000,000 and the fine on the directly responsible manager or other directly responsible individual at RMB 10,000 to 100,000. Where the circumstances are serious, a provincial-or-above personal information protection department may instead impose a fine of not more than RMB 50,000,000 or not more than 5 percent of the preceding year's turnover, may order suspension of the relevant business or a shutdown for rectification, and may have the relevant business permit or business licence revoked; the responsible individual's fine rises to RMB 100,000 to 1,000,000, with a possible bar from serving as a director, supervisor, senior manager, or personal information protection officer for a period. The statute's own text joins the RMB 50,000,000 figure and the 5 percent turnover figure with 'or' (或者) rather than an explicit 'whichever is higher' comparative. This record treats the serious-violation tier as its operative ceiling on the higher_of model, consistent with how a large reported fine (the RMB 8.026 billion 2022 fine against Didi Global, reported as roughly 4.7 percent of its prior year's China revenue) applied the percentage figure in practice, but that reading is an interpretive judgement about how the two caps are actually applied, not the statute's own explicit comparative language, and is flagged as such.
- Rule
- Higher of
- As of
- 2 September 2026
- Currency
- CNY
- Fixed cap
- 50,000,000
- Turnover percentage cap
- 5
Who enforces it
Enforcement body
Cyberspace Administration of China (CAC), which under PIPL Article 60 coordinates and leads personal information protection and related supervisory work nationally. Relevant departments of the State Council carry out personal information protection and supervision within their own areas of responsibility under the same article, and county-level-or-above local government departments hold personal information protection and supervisory duties as determined by state regulations; the statute refers to this group collectively as the departments performing personal information protection duties.
What it reaches
Obligation class
Governance
Who checks it
Audit expectation
on_request
Who audits it
Independent third party
Where the report goes
Filed with regulator
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Cyberspace Administration of China leads coordination, with sectoral State Council departments and their local counterparts supervising within their own scope; investigative powers include interviews, record examination, on-site inspection, and, with approval, seizure of equipment.
Ordinary violations draw a warning, confiscation of gains, and service suspension, escalating on non-correction to fines up to RMB 1,000,000 for the entity and RMB 10,000 to 100,000 for the responsible individual; grave violations draw fines up to RMB 50,000,000 or 5 percent of the prior year's revenue, possible business suspension or license revocation, individual fines of RMB 100,000 to 1,000,000, and a bar on serving as a director, supervisor, senior manager, or protection officer of a related enterprise.
A handler that cannot prove itself free of fault bears civil compensation liability, and procuratorates and designated organizations may bring public-interest suits over mass violations.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
Read the law
official CAC-published full Chinese statutory text
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.