PRC Personal Information Protection Law — Full English Translation (2021)

Adopted at the 30th Session of the Standing Committee of the Thirteenth National People’s Congress on August 20, 2021

Effective: November 1, 2021


Table of Contents


Chapter I — General Provisions

Article 1 — This Law is enacted in accordance with the Constitution for the purposes of protecting personal information rights and interests, regulating the processing of personal information, and promoting the reasonable use of personal information.

Article 2 — The personal information of natural persons shall be protected by law; no organization or individual may infringe upon the personal information rights and interests of natural persons.

Article 3 — This Law shall apply to the processing of personal information of natural persons within the territory of the People’s Republic of China. This Law shall also apply to the following activities conducted outside the territory of the People’s Republic of China that process the personal information of natural persons within the territory of the People’s Republic of China: (1) where the purpose is to provide products or services to natural persons within the territory; (2) where the purpose is to analyze or assess the conduct of natural persons within the territory; or (3) other circumstances provided for by laws or administrative regulations.

Article 4 — Personal information means any kind of information relating to an identified or identifiable natural person that is recorded electronically or by other means, but does not include information that has been anonymized. The processing of personal information includes the collection, storage, use, processing, transmission, provision, disclosure, and deletion of personal information.

Article 5 — The principles of legality, legitimacy, necessity, and good faith shall be observed in the processing of personal information. Personal information shall not be processed by misleading, fraudulent, coercive, or other improper means.

Article 6 — The processing of personal information shall have a clear and reasonable purpose and shall be directly related to the purpose of processing, and the method of processing shall be adopted in a manner that has the least impact on the rights and interests of individuals. The collection of personal information shall be limited to the minimum scope necessary for the realization of the purpose of processing, and personal information shall not be excessively collected.

Article 7 — The principles of openness and transparency shall be observed in the processing of personal information, the rules for processing personal information shall be disclosed, and the purpose, method, and scope of processing shall be expressly indicated.

Article 8 — The quality of personal information shall be ensured in the processing of personal information to avoid any adverse impact on individual rights and interests due to the inaccuracy or incompleteness of personal information.

Article 9 — Personal information processors shall assume responsibility for their personal information processing activities and shall adopt necessary measures to ensure the security of the personal information processed.

Article 10 — No organization or individual may illegally collect, use, process, or transmit the personal information of others, or illegally trade, provide, or disclose the personal information of others; nor may they engage in the processing of personal information that endangers national security or the public interest.

Article 11 — The state shall establish a sound personal information protection system, prevent and punish acts infringing upon personal information rights and interests, strengthen publicity and education on personal information protection, and promote the formation of a good environment in which the government, enterprises, relevant industry organizations, and the public jointly participate in the protection of personal information.

Article 12 — The state shall actively participate in the formulation of international rules for personal information protection, promote international exchanges and cooperation in personal information protection, and promote mutual recognition of personal information protection rules and standards with other countries, regions, and international organizations.

Chapter II — Rules for the Processing of Personal Information

Section 1 — General Rules

Article 13 — A personal information processor may process personal information only where the individual has given consent under any of the following circumstances: (1) consent has been obtained from the individual; (2) it is necessary for the conclusion or performance of a contract to which the individual is a party, or it is necessary for the implementation of human resources management in accordance with labor rules and regulations formulated in accordance with the law and a collective contract concluded in accordance with the law; (3) it is necessary for the performance of statutory functions and duties or statutory obligations; (4) it is necessary for responding to a public health emergency or for the protection of the life, health, and property safety of natural persons in an emergency; (5) the personal information is processed within a reasonable scope for the purposes of news reporting, supervision by public opinion, or other activities carried out in the public interest; (6) the personal information, which has already been disclosed by the individual or otherwise lawfully disclosed, is processed within a reasonable scope in accordance with the provisions of this Law; or (7) other circumstances provided for by laws or administrative regulations. Where the processing of personal information shall obtain the consent of the individual in accordance with the other provisions of this Law, the consent of the individual shall be obtained in addition to the circumstances provided for in items (2) through (7) of the preceding paragraph.

Article 14 — Where the processing of personal information is based on the consent of the individual, the consent shall be given by the individual voluntarily and expressly with full knowledge. Where laws or administrative regulations provide that the processing of personal information shall be subject to the separate consent or written consent of the individual, such provisions shall prevail. Where any change occurs in the purpose or method of processing personal information, or the type of personal information to be processed, the consent of the individual shall be obtained again.

Article 15 — Where the processing of personal information is based on the consent of the individual, the individual shall have the right to withdraw his or her consent. Personal information processors shall provide a convenient method for the withdrawal of consent. The withdrawal of consent by an individual shall not affect the validity of any processing of personal information that has been carried out on the basis of the individual’s consent before the withdrawal.

Article 16 — A personal information processor shall not refuse to provide products or services to an individual on the ground that the individual does not consent to the processing of his or her personal information or withdraws his or her consent, except where the processing of personal information is necessary for the provision of the products or services.

Article 17 — Before processing personal information, a personal information processor shall, in a conspicuous manner and in clear and understandable language, truthfully, accurately, and completely inform the individual of the following matters: (1) the name or designation and the contact information of the personal information processor; (2) the purpose and method of processing personal information, the type of personal information to be processed, and the retention period; (3) the method and procedure for the individual to exercise the rights provided for in this Law; and (4) other matters that shall be notified as provided for by laws or administrative regulations. Where a change occurs in any of the matters as provided for in the preceding paragraph, the individual shall be notified of the change. Where a personal information processor notifies the matters as provided for in the first paragraph by means of a personal information processing policy, the policy shall be made public and easily accessible.

Article 18 — Where a personal information processor processes personal information and falls under any of the circumstances where it is not required to inform the individual as provided for by laws or administrative regulations, the provisions of the first paragraph of the preceding Article shall not apply. Under urgent circumstances where it is impossible to inform the individual in a timely manner in order to protect the life, health, and property safety of a natural person, the personal information processor shall notify the individual in a timely manner after the urgent circumstances are eliminated.

Article 19 — The retention period of personal information shall be the shortest period necessary for the realization of the purpose of processing personal information, unless otherwise provided for by laws or administrative regulations. Where the purpose of processing personal information has been achieved, cannot be achieved, or is no longer necessary for the realization of the purpose of processing, the personal information processor shall promptly delete the personal information; where deletion is technically difficult to achieve, the personal information processor shall cease the processing of personal information, except for storage and the adoption of necessary security protection measures.

Article 20 — Where two or more personal information processors jointly decide on the purpose and method of processing personal information, they shall agree on their respective rights and obligations. However, such agreement shall not affect the right of an individual to claim against any of the personal information processors for the exercise of his or her rights provided for in this Law. Where a personal information processor jointly processing personal information causes damage as a result of the processing of personal information in violation of the provisions of this Law and infringes upon the rights and interests of an individual, the personal information processors shall bear joint and several liability in accordance with the law.

Article 21 — Where a personal information processor entrusts the processing of personal information, it shall enter into an agreement with the entrusted person on the purpose, time limit, method of processing, type of personal information, protective measures, and the rights and obligations of both parties, and shall supervise the personal information processing activities of the entrusted person. The entrusted person shall process personal information in accordance with the agreement and shall not process personal information beyond the agreed purpose and method of processing; where the entrustment contract is not effective, is void, is revoked, or is terminated, the entrusted person shall return the personal information to the personal information processor or delete it, and shall not retain the personal information. Without the consent of the personal information processor, the entrusted person shall not sub-entrust the processing of personal information to others.

Article 22 — Where a personal information processor needs to transfer personal information due to merger, division, dissolution, declaration of bankruptcy, or any other reason, it shall inform the individual of the name or designation and the contact information of the receiving party. The receiving party shall continue to fulfill the obligations of the personal information processor. Where the receiving party changes the original purpose or method of processing, it shall obtain the consent of the individual again in accordance with the provisions of this Law.

Article 23 — Where a personal information processor provides the personal information it processes to another personal information processor, it shall inform the individual of the name or designation and the contact information of the receiving party, the purpose and method of processing, and the type of personal information, and shall obtain the separate consent of the individual. The receiving party shall process the personal information within the scope of the purpose and method of processing and the type of personal information as stated in the consent. Where the receiving party changes the original purpose or method of processing, it shall obtain the consent of the individual again in accordance with the provisions of this Law.

Article 24 — Where a personal information processor uses personal information to conduct automated decision-making, the transparency of the decision-making and the fairness and impartiality of the result shall be ensured, and the practice of applying unreasonable differential treatment to individuals in terms of transaction prices or other transaction conditions shall be prohibited. Where information push or commercial marketing to individuals is conducted through automated decision-making, the option of not targeting the individual’s personal characteristics shall be provided simultaneously, or a convenient method for the individual to refuse shall be provided. Where an automated decision-making method is used to make a decision that has a significant impact on the rights and interests of an individual, the individual shall have the right to request the personal information processor to provide an explanation, and shall also have the right to refuse that the personal information processor makes a decision solely through the automated decision-making method.

Article 25 — A personal information processor shall not disclose the personal information it processes, except where it has obtained the separate consent of the individual.

Article 26 — The installation of image collection or personal identity recognition equipment in public places shall be necessary for the maintenance of public security, comply with the relevant provisions of the state, and be accompanied by a conspicuous indicating sign. The collected personal images and personal identity recognition information may only be used for the purpose of maintaining public security and shall not be used for any other purpose, except where the separate consent of the individual is obtained.

Article 27 — A personal information processor may, within a reasonable scope, process personal information that has already been disclosed by the individual or otherwise lawfully disclosed, unless the individual expressly refuses. Where a personal information processor processes the personal information that has already been disclosed and has a significant impact on the rights and interests of an individual, it shall obtain the consent of the individual in accordance with the provisions of this Law.

Section 2 — Special Provisions on the Processing of Sensitive Personal Information

Article 28 — Sensitive personal information means personal information that, if leaked or illegally used, may easily cause damage to the personal dignity of a natural person or endanger his or her personal or property safety, including biometric identification information, religious belief, special social status, medical and health information, financial accounts, whereabouts and tracks, and other such information, as well as the personal information of minors under the age of 14. A personal information processor may process sensitive personal information only where there is a specific purpose and sufficient necessity and strict protective measures are adopted. Where the processing of sensitive personal information is necessary, the consent of the individual shall be obtained in addition to the conditions set out in the first paragraph of Article 13 of this Law; where laws or administrative regulations provide that the processing of sensitive personal information shall be subject to the written consent of the individual, such provisions shall prevail.

Article 29 — Where sensitive personal information is processed, the consent of the individual shall be obtained separately; where laws or administrative regulations provide that the processing of sensitive personal information shall be subject to the written consent of the individual, such provisions shall prevail.

Article 30 — Where a personal information processor processes sensitive personal information, it shall, in addition to the matters provided for in the first paragraph of Article 17 of this Law, inform the individual of the necessity of processing the sensitive personal information and the impact on the rights and interests of the individual, except where this Law provides that it is not required to inform the individual.

Article 31 — Where a personal information processor processes the personal information of a minor under the age of 14, it shall obtain the consent of the minor’s parent or guardian. The personal information processor shall formulate special personal information processing rules for the processing of the personal information of minors under the age of 14.

Article 32 — Where laws or administrative regulations provide that the processing of sensitive personal information shall be subject to administrative licensing or have other restrictions, such provisions shall prevail.

Section 3 — Special Provisions on the Processing of Personal Information by State Organs

Article 33 — The processing of personal information by state organs shall be governed by the provisions of this Law; where there are special provisions in this Section, the provisions of this Section shall apply.

Article 34 — State organs shall process personal information within the scope of their statutory functions and duties in accordance with the authority and procedures provided for by laws and administrative regulations, and shall not process personal information beyond the scope and limits of their statutory functions and duties.

Article 35 — Where state organs process personal information for the performance of their statutory functions and duties, they shall fulfill the obligation of notification in accordance with the provisions of this Law, except under the circumstances provided for in Article 18 of this Law or where notification would obstruct the performance of statutory functions and duties by the state organs.

Article 36 — The personal information processed by state organs shall be stored within the territory of the People’s Republic of China; where it is necessary to provide it overseas, a security assessment shall be conducted. The security assessment may be supported by the relevant authorities.

Article 37 — The provisions of this Law on state organs shall apply to the processing of personal information by organizations authorized by laws or regulations to have the functions of administering public affairs in the performance of their statutory functions and duties.

Chapter III — Rules for the Cross-Border Transfer of Personal Information

Article 38 — Where a personal information processor really needs to provide personal information outside the territory of the People’s Republic of China for business or other needs, it shall meet one of the following conditions: (1) passing the security assessment organized by the national cyberspace administration authority in accordance with the provisions of Article 40 of this Law; (2) obtaining personal information protection certification from a specialized institution in accordance with the provisions of the national cyberspace administration authority; (3) entering into a contract with the overseas recipient in accordance with the standard contract formulated by the national cyberspace administration authority, specifying the rights and obligations of both parties; or (4) meeting other conditions provided for by laws, administrative regulations, or the national cyberspace administration authority. Where a treaty or an international agreement concluded or acceded to by the People’s Republic of China contains provisions on the conditions for providing personal information outside the territory of the People’s Republic of China, such provisions may be applied.

Article 39 — Where a personal information processor provides personal information outside the territory of the People’s Republic of China, it shall inform the individual of the name or designation and the contact information of the overseas recipient, the purpose and method of processing, the type of personal information, and the method and procedure for the individual to exercise the rights provided for in this Law against the overseas recipient, and shall obtain the separate consent of the individual.

Article 40 — Operators of critical information infrastructure and personal information processors that process personal information reaching the threshold prescribed by the national cyberspace administration authority in terms of quantity shall store the personal information collected and generated within the territory of the People’s Republic of China within the territory. Where it is necessary to provide it overseas, a security assessment organized by the national cyberspace administration authority shall be passed; where laws, administrative regulations, or the national cyberspace administration authority provide that security assessment may be exempted, such provisions shall prevail.

Article 41 — The competent authorities of the People’s Republic of China shall, in accordance with relevant laws and international treaties or agreements concluded or acceded to by the People’s Republic of China, or on the basis of the principle of equality and reciprocity, handle the requests of foreign judicial authorities or law enforcement authorities for the provision of personal information stored within the territory of the People’s Republic of China. Without the approval of the competent authorities of the People’s Republic of China, a personal information processor may not provide personal information stored within the territory of the People’s Republic of China to foreign judicial authorities or law enforcement authorities.

Article 42 — Where an overseas organization or individual engages in personal information processing activities that infringe upon the personal information rights and interests of citizens of the People’s Republic of China or endanger the national security or public interest of the People’s Republic of China, the national cyberspace administration authority may include it in a list of restricted or prohibited recipients of personal information, make an announcement, and adopt measures such as restricting or prohibiting the provision of personal information to it.

Article 43 — Where a country or region adopts discriminatory prohibitions, restrictions, or other similar measures against the People’s Republic of China in the area of personal information protection, the People’s Republic of China may, on the basis of the actual circumstances, adopt countermeasures against such country or region.

Chapter IV — Rights of Individuals in the Processing of Personal Information

Article 44 — An individual shall have the right to know and the right to decide on the processing of his or her personal information, and shall have the right to restrict or refuse the processing of his or her personal information by others, except as otherwise provided for by laws or administrative regulations.

Article 45 — An individual shall have the right to access and copy his or her personal information from the personal information processor, except under the circumstances provided for in Article 18 of this Law or Article 35 of this Law. Where an individual requests to access or copy his or her personal information, the personal information processor shall provide it in a timely manner. Where an individual requests to transfer his or her personal information to a personal information processor designated by him or her, and such transfer complies with the conditions prescribed by the national cyberspace administration authority, the personal information processor shall provide a method for the transfer.

Article 46 — Where an individual discovers that his or her personal information is inaccurate or incomplete, he or she shall have the right to request the personal information processor to correct or supplement it. Where an individual requests to correct or supplement his or her personal information, the personal information processor shall verify and correct or supplement it in a timely manner.

Article 47 — A personal information processor shall promptly delete personal information under any of the following circumstances: (1) the purpose of processing has been achieved, cannot be achieved, or is no longer necessary for the realization of the purpose of processing; (2) the personal information processor ceases to provide products or services, or the retention period has expired; (3) the individual withdraws his or her consent; (4) the personal information processor processes personal information in violation of laws, administrative regulations, or the agreement; or (5) other circumstances provided for by laws or administrative regulations. Where the retention period provided for by laws or administrative regulations has not expired, or it is technically difficult to delete personal information, the personal information processor shall cease the processing of personal information, except for storage and the adoption of necessary security protection measures.

Article 48 — An individual shall have the right to request the personal information processor to explain the rules for the processing of his or her personal information.

Article 49 — Where a natural person is deceased, his or her close relatives may, for their own lawful and legitimate interests, exercise the rights provided for in this Chapter to access, copy, correct, or delete the relevant personal information of the deceased, unless the deceased has made other arrangements before his or her death.

Article 50 — A personal information processor shall establish a convenient mechanism for accepting and handling applications for the exercise of the rights of individuals. Where an individual’s application to exercise his or her rights is refused, he or she shall be notified of the reason. Where a personal information processor refuses an individual’s application to exercise his or her rights, the individual may file a lawsuit with the people’s court in accordance with the law.

Chapter V — Obligations of Personal Information Processors

Article 51 — A personal information processor shall, on the basis of the purpose and method of processing personal information, the type of personal information, the impact on the rights and interests of individuals, the possible security risks, and other factors, adopt the following measures to ensure that the processing of personal information complies with the provisions of laws and administrative regulations and to prevent unauthorized access, leakage, tampering, or loss of personal information: (1) formulating internal management systems and operating procedures; (2) implementing classified management of personal information; (3) adopting corresponding security technical measures such as encryption and de-identification; (4) reasonably determining the authority for the operation of personal information and regularly conducting security education and training for employees; (5) formulating and organizing the implementation of emergency response plans for personal information security incidents; and (6) other measures provided for by laws or administrative regulations.

Article 52 — A personal information processor that processes personal information reaching the threshold prescribed by the national cyberspace administration authority in terms of quantity shall designate a person responsible for personal information protection, who shall be responsible for supervising the personal information processing activities and the protective measures adopted by the personal information processor. A personal information processor shall disclose the contact information of the person responsible for personal information protection, and shall report the name and contact information of the person responsible to the authority performing personal information protection functions and duties.

Article 53 — A personal information processor outside the territory of the People’s Republic of China as provided for in the second paragraph of Article 3 of this Law shall establish a dedicated institution or designate a representative within the territory of the People’s Republic of China to be responsible for matters relating to the personal information it processes, and shall report the name of the institution or the name and contact information of the representative to the authority performing personal information protection functions and duties.

Article 54 — A personal information processor shall regularly conduct audits of its compliance with laws and administrative regulations in its processing of personal information.

Article 55 — A personal information processor shall conduct a personal information protection impact assessment in advance under any of the following circumstances and keep a record of the processing: (1) processing sensitive personal information; (2) using personal information to conduct automated decision-making; (3) entrusting the processing of personal information, providing personal information to another personal information processor, or disclosing personal information; (4) providing personal information to an overseas recipient; or (5) other personal information processing activities that have a significant impact on the rights and interests of individuals. The content of the personal information protection impact assessment shall include: whether the purpose and method of processing personal information are lawful, legitimate, and necessary; the impact on the rights and interests of individuals and the degree of security risk; and whether the protective measures adopted are lawful, effective, and commensurate with the degree of risk. The personal information protection impact assessment report and the record of processing shall be kept for at least three years.

Article 56 — Where a personal information processor discovers that personal information has been or may have been leaked, tampered with, or lost, it shall immediately adopt remedial measures and notify the authority performing personal information protection functions and duties and the relevant individuals. The notification shall include the following: (1) the information on the type of personal information that has been or may have been leaked, tampered with, or lost, the cause, and the possible harm; (2) the remedial measures adopted by the personal information processor and the measures that the individual may adopt to mitigate the harm; and (3) the contact information of the personal information processor. Where the personal information processor adopts measures that can effectively avoid the harm caused by information leakage, tampering, or loss, the personal information processor is not required to notify the individuals; however, where the authority performing personal information protection functions and duties considers that the harm may occur, it may require the personal information processor to notify the individuals.

Article 57 — A personal information processor that provides important internet platform services, has a large number of users, and has a complex type of business shall fulfill the following obligations: (1) establishing an independent institution consisting mainly of external members to supervise the processing of personal information in accordance with the provisions of the state; (2) following the principles of openness, fairness, and impartiality, formulating platform rules, and specifying the norms for the processing of personal information by product or service providers on the platform and their obligations to protect personal information; (3) stopping the provision of services to product or service providers on the platform that process personal information in serious violation of laws or administrative regulations; and (4) regularly publishing a social responsibility report on personal information protection, and accepting public supervision.

Article 58 — Where a personal information processor processes personal information by means of automated decision-making, it shall conduct a personal information protection impact assessment in advance and shall not apply unreasonable differential treatment to individuals in terms of transaction prices or other transaction conditions. Where information push or commercial marketing to individuals is conducted through automated decision-making, the option of not targeting the individual’s personal characteristics shall be provided simultaneously, or a convenient method for the individual to refuse shall be provided.

Article 59 — An entrusted person processing personal information shall, in accordance with the provisions of this Law and relevant laws and administrative regulations, adopt necessary measures to ensure the security of the personal information processed and assist the personal information processor in fulfilling its obligations under this Law.

Chapter VI — Authorities Performing Personal Information Protection Functions and Duties

Article 60 — The national cyberspace administration authority shall be responsible for the overall planning and coordination of personal information protection and the related supervision and administration. The relevant authorities under the State Council shall, in accordance with the provisions of this Law and relevant laws and administrative regulations, be responsible for the protection of personal information, supervision, and administration within the scope of their respective functions and duties. The functions and duties of the relevant departments of the local people’s governments at or above the county level in the protection of personal information, supervision, and administration shall be determined in accordance with the relevant provisions of the state. The authorities as provided for in the two preceding paragraphs are collectively referred to as the “authorities performing personal information protection functions and duties.”

Article 61 — The authorities performing personal information protection functions and duties shall perform the following functions and duties: (1) carrying out publicity and education on personal information protection, and guiding and supervising personal information processors in carrying out personal information protection work; (2) accepting and handling complaints and reports relating to personal information protection; (3) organizing the assessment of the protection of personal information such as application programs, and publishing the assessment results; (4) investigating and punishing illegal personal information processing activities; and (5) other functions and duties provided for by laws or administrative regulations.

Article 62 — The national cyberspace administration authority shall coordinate with the relevant authorities in advancing the following personal information protection work: (1) formulating specific rules and standards for personal information protection; (2) formulating special rules for the processing of sensitive personal information and for personal information protection impact assessments for small personal information processors and the processing of personal information such as facial recognition and artificial intelligence; (3) supporting the research, development, and promotion of secure and convenient electronic identity authentication technologies, and promoting the construction of public services for electronic identity authentication; and (4) advancing the construction of socialized service systems for personal information protection, and supporting relevant institutions in carrying out personal information protection assessment and certification services.

Article 63 — When the authorities performing personal information protection functions and duties perform their personal information protection functions and duties, they may adopt the following measures: (1) interviewing the relevant parties and investigating the circumstances relating to the processing of personal information; (2) consulting and copying the relevant contracts, records, account books, and other materials of the parties; (3) conducting on-site inspections and investigating suspected illegal personal information processing activities; (4) inspecting the relevant equipment and articles relating to personal information processing activities; and (5) where there is evidence that the relevant equipment or articles are or may be used for illegal personal information processing activities, they may be sealed up or seized. Where the authorities performing personal information protection functions and duties perform their functions and duties in accordance with the law, the parties shall provide assistance and cooperation and shall not refuse or obstruct them.

Article 64 — Where the authorities performing personal information protection functions and duties, in the performance of their functions and duties, discover that there are relatively large risks in the processing of personal information or that a personal information security incident has occurred, they may, in accordance with the prescribed authority and procedures, conduct an interview with the legal representative or principal responsible person of the personal information processor, or require the personal information processor to entrust a specialized institution to conduct a compliance audit of its personal information processing activities. The personal information processor shall, in accordance with the requirements, adopt measures to make rectification and eliminate the hidden dangers. The authorities performing personal information protection functions and duties, in the performance of their functions and duties, shall keep confidential the personal information, trade secrets, confidential business information, and other information they come to know, and shall not disclose or illegally provide the same to others.

Article 65 — Every organization and individual shall have the right to lodge a complaint or report to the authorities performing personal information protection functions and duties regarding any illegal personal information processing activities. The authorities receiving the complaint or report shall handle it in a timely manner in accordance with the law and shall notify the complainant or reporter of the result of the handling. The authorities performing personal information protection functions and duties shall publish the contact information for accepting complaints and reports.

Article 66 — Where a personal information processor processes personal information in violation of the provisions of this Law or fails to fulfill its personal information protection obligations as provided for in this Law, the authority performing personal information protection functions and duties shall order it to make corrections, give it a warning, and confiscate its illegal gains; it shall also order the suspension or termination of the provision of services by the application program that illegally processes personal information; where it refuses to make corrections, a fine of not more than RMB 1,000,000 shall be imposed. Where the circumstances are serious, the authority performing personal information protection functions and duties at or above the provincial level shall order it to make corrections, confiscate its illegal gains, and impose a fine of not more than RMB 50,000,000 or not more than five percent of the annual turnover, and may order it to suspend the relevant business or suspend business for rectification, or notify the relevant competent authority to revoke the relevant business permit or business license; and a fine of not less than RMB 100,000 but not more than RMB 1,000,000 shall be imposed on the directly responsible person in charge and other directly responsible persons, and they may also be prohibited from holding the positions of director, supervisor, senior management personnel, and person responsible for personal information protection for a certain period.

Article 67 — Where a personal information processor commits an illegal act as provided for in this Law, it shall be recorded in its credit file in accordance with the provisions of relevant laws and administrative regulations and shall be made public.

Article 68 — Where a state organ fails to fulfill its personal information protection obligations as provided for in this Law, the authority at a higher level or the authority performing personal information protection functions and duties shall order it to make corrections; sanctions shall be imposed on the directly responsible person in charge and other directly responsible persons in accordance with the law. Where any staff member of an authority performing personal information protection functions and duties neglects his or her duties, engages in malpractice for personal gain, or abuses his or her power, and the violation does not constitute a crime, he or she shall be sanctioned in accordance with the law.

Article 69 — Where the processing of personal information infringes upon the rights and interests of an individual and causes damage, and the personal information processor cannot prove that it is not at fault, the personal information processor shall bear civil liability for damages such as compensation. The liability for damages as provided for in the preceding paragraph shall be determined on the basis of the losses suffered by the individual as a result of the damage or the benefits obtained by the personal information processor as a result of the damage; where it is difficult to determine the losses suffered by the individual and the benefits obtained by the personal information processor, the amount of compensation shall be determined on the basis of the actual circumstances.

Article 70 — Where a personal information processor processes personal information in violation of the provisions of this Law and infringes upon the rights and interests of a large number of individuals, the people’s procuratorate, the consumer organizations prescribed by law, and the organizations designated by the national cyberspace administration authority may file a lawsuit with the people’s court in accordance with the law.

Article 71 — Where any act violates the provisions of this Law and constitutes a violation of public security administration, public security administration penalties shall be imposed in accordance with the law; where a crime is constituted, criminal liability shall be pursued in accordance with the law.

Chapter VIII — Supplementary Provisions

Article 72 — For the purposes of this Law, the following terms have the following meanings: (1) “personal information processor” means an organization or individual that independently determines the purpose and method of processing personal information; (2) “automated decision-making” means the activity of using computer programs to automatically analyze or assess an individual’s behavior habits, hobbies and interests, or economic, health, credit status, and other such circumstances, and making decisions on the basis thereof; (3) “de-identification” means the process of processing personal information so that it cannot identify a specific natural person without the help of additional information; and (4) “anonymization” means the process of processing personal information so that it cannot identify a specific natural person and cannot be restored. The provisions of this Law shall not apply to the processing of personal information by natural persons for personal or family affairs. Where laws provide for the processing of personal information by the relevant people’s governments and their relevant authorities in the course of the organization and implementation of statistical and archival management activities, the provisions of such laws shall apply.

Article 73 — The processing of personal information in accordance with the law within the closed environment of a government affairs information system constructed by a state organ to carry out administrative management in accordance with the law shall not be subject to the provisions of Article 38 of this Law on the cross-border provision of personal information. The storage, processing, and administration of the personal information processed as provided for in the preceding paragraph shall be carried out in accordance with the relevant provisions of the state.

Article 74 — This Law shall come into force as of November 1, 2021.

Wechat

WhatsApp

WhatsApp

WhatsApp
[email protected]
+86 18565453956