Law / China

Personal Information Protection Law, Supervision and Legal Liability

PIPL Arts. 60-71

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 1 November 2021.

An enforcement supervision rule binding public and private bodies.

As of 2 September 2026.

What it requires

  • Comply with lawful CAC and sectoral-regulator investigation, including document production and on-site inspection.
  • Bear the burden of proving the absence of fault once an individual establishes harm from unlawful personal information processing, or pay compensation.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

PIPL Article 71 provides that a violation constituting a public security administrative offence draws punishment under the Public Security Administration Punishments Law, and a violation constituting a crime draws criminal liability according to law. The criminal offence most commonly charged for personal-information violations is Criminal Law Article 253-1 (infringing citizens' personal information), which secondary legal commentary describes as carrying imprisonment of up to three years (or short-term detention) plus or in lieu of a fine for serious circumstances, rising to three to seven years' imprisonment plus a fine for especially serious circumstances. The imprisonment terms rest on well corroborated secondary commentary rather than on the amended primary text of Article 253-1; PIPL Article 71 itself, quoted in attribute_sources, is primary text.

Penalty structure

PIPL Article 66 sets a two-tier structure. The ordinary tier, triggered when a processor refuses to correct a violation, caps the organizational fine at RMB 1,000,000 and the fine on the directly responsible manager or other directly responsible individual at RMB 10,000 to 100,000. Where the circumstances are serious, a provincial-or-above personal information protection department may instead impose a fine of not more than RMB 50,000,000 or not more than 5 percent of the preceding year's turnover, may order suspension of the relevant business or a shutdown for rectification, and may have the relevant business permit or business licence revoked; the responsible individual's fine rises to RMB 100,000 to 1,000,000, with a possible bar from serving as a director, supervisor, senior manager, or personal information protection officer for a period. The statute's own text joins the RMB 50,000,000 figure and the 5 percent turnover figure with 'or' (或者) rather than an explicit 'whichever is higher' comparative. This record treats the serious-violation tier as its operative ceiling on the higher_of model, consistent with how a large reported fine (the RMB 8.026 billion 2022 fine against Didi Global, reported as roughly 4.7 percent of its prior year's China revenue) applied the percentage figure in practice, but that reading is an interpretive judgement about how the two caps are actually applied, not the statute's own explicit comparative language, and is flagged as such.

Rule
Higher of
As of
2 September 2026
Currency
CNY
Fixed cap
50,000,000
Turnover percentage cap
5

Who enforces it

Enforcement body

Cyberspace Administration of China (CAC), which under PIPL Article 60 coordinates and leads personal information protection and related supervisory work nationally. Relevant departments of the State Council carry out personal information protection and supervision within their own areas of responsibility under the same article, and county-level-or-above local government departments hold personal information protection and supervisory duties as determined by state regulations; the statute refers to this group collectively as the departments performing personal information protection duties.

What it reaches

Obligation class

Governance

Who checks it

Audit expectation

on_request

Who audits it

Independent third party

Where the report goes

Filed with regulator

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The Cyberspace Administration of China leads coordination, with sectoral State Council departments and their local counterparts supervising within their own scope; investigative powers include interviews, record examination, on-site inspection, and, with approval, seizure of equipment.

Ordinary violations draw a warning, confiscation of gains, and service suspension, escalating on non-correction to fines up to RMB 1,000,000 for the entity and RMB 10,000 to 100,000 for the responsible individual; grave violations draw fines up to RMB 50,000,000 or 5 percent of the prior year's revenue, possible business suspension or license revocation, individual fines of RMB 100,000 to 1,000,000, and a bar on serving as a director, supervisor, senior manager, or protection officer of a related enterprise.

A handler that cannot prove itself free of fault bears civil compensation liability, and procuratorates and designated organizations may bring public-interest suits over mass violations.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics

Read the law

official CAC-published full Chinese statutory text

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app