Personal Information Protection Law of the People’s Republic of China — Full English Translation (2021)

Adopted August 20, 2021; Effective November 1, 2021

Effective: November 1, 2021


Table of Contents


Chapter I — General Provisions

Article 1. This Law is enacted for the purposes of protecting the rights and interests of personal information subjects, regulating personal information processing activities, promoting the reasonable use of personal information, and safeguarding the lawful rights and interests of individuals.

Article 2. The personal information of natural persons shall be protected by law; no organization or individual may infringe upon the personal information rights and interests of natural persons.

Article 3. This Law applies to personal information processing activities conducted within the territory of the People’s Republic of China. This Law also applies to personal information processing activities conducted outside China where: (1) the purpose is to provide products or services to natural persons within China; (2) the purpose is to analyze or assess the conduct of natural persons within China; or (3) other circumstances provided by laws or administrative regulations.

Article 4. “Personal information” means any kind of information relating to an identified or identifiable natural person, recorded electronically or by other means, excluding anonymized information. “Processing of personal information” includes the collection, storage, use, processing, transmission, provision, disclosure, and deletion of personal information.

Article 5. The principles of legality, legitimacy, necessity, and good faith shall be observed in the processing of personal information. Personal information shall not be processed by misleading, fraudulent, coercive, or other improper means.

Article 6. The processing of personal information shall have a clear and reasonable purpose and shall be directly related to the processing purpose. The collection of personal information shall be limited to the minimum scope necessary for achieving the processing purpose and shall not be excessive.

Article 7. Personal information shall be processed in accordance with the principles of openness and transparency, disclosing the rules for processing personal information and clearly indicating the purpose, method, and scope of processing.

Article 8. The quality of personal information shall be ensured when processing to avoid any adverse effect on the rights and interests of individuals caused by inaccurate or incomplete personal information.

Article 9. Personal information processors shall bear responsibility for their personal information processing activities and shall adopt necessary measures to safeguard the security of the personal information processed.

Article 10. No organization or individual may illegally collect, use, process, or transmit the personal information of others, or illegally trade, provide, or disclose the personal information of others, or engage in personal information processing activities that endanger national security or the public interest.

Article 11. The State shall establish a sound personal information protection system, prevent and punish infringements upon personal information rights and interests, strengthen publicity and education on personal information protection, and promote the formation of a favorable environment in which governments, enterprises, relevant social organizations, and the public jointly participate in personal information protection.

Article 12. The State shall actively participate in the formulation of international rules on personal information protection, promote international exchanges and cooperation in the field of personal information protection, and facilitate mutual recognition of personal information protection rules and standards with other countries, regions, and international organizations.

Chapter II — Rules for Processing Personal Information

Article 13. A personal information processor may process personal information only where: (1) consent has been obtained from the individual; (2) it is necessary for the conclusion or performance of a contract to which the individual is a party; (3) it is necessary for the performance of statutory duties or statutory obligations; (4) it is necessary for responding to public health emergencies or for protecting the life, health, and property safety of natural persons in emergencies; (5) it is for news reporting and public opinion supervision conducted in the public interest; (6) the personal information has been disclosed by the individual or has otherwise been lawfully disclosed; or (7) other circumstances provided by laws or administrative regulations.

Article 14. Where consent is the basis for processing personal information, such consent shall be given voluntarily and explicitly by the individual with full knowledge of the relevant facts. Where laws or administrative regulations provide that separate consent shall be obtained, such separate consent shall be obtained.

Article 15. Where the purpose, method, or categories of personal information processed change, consent shall be obtained anew from the individual.

Article 16. An individual shall have the right to withdraw consent. The personal information processor shall provide a convenient method for withdrawal of consent. Withdrawal of consent shall not affect the lawfulness of processing based on consent prior to withdrawal.

Article 17. Before processing personal information, the personal information processor shall inform the individual of the following in a conspicuous and clear manner using plain language: (1) the identity and contact information of the personal information processor; (2) the purpose and method of processing, and the categories and retention period of personal information to be processed; (3) the method and procedure for the individual to exercise rights under this Law; and (4) other matters to be notified under laws or administrative regulations.

Article 18. A personal information processor shall store personal information for the shortest period necessary for achieving the processing purpose. Where laws or administrative regulations provide otherwise, such provisions shall prevail.

Article 19. Where multiple personal information processors jointly determine the purpose and method of processing personal information, they shall agree on their respective rights and obligations. However, such agreement shall not affect the right of an individual to claim against any of the processors.

Article 20. Where a personal information processor entrusts the processing of personal information to another party, it shall enter into an agreement with the entrusted party specifying the purpose, time limit, method, categories of personal information, and protection measures. The entrusted party shall process personal information in accordance with the agreement and shall not process beyond the agreed scope. Upon termination of the entrustment, the entrusted party shall return or delete the personal information.

Article 21. A personal information processor shall not provide personal information processed by it to another personal information processor without the individual’s separate consent, except where laws or administrative regulations provide otherwise.

Article 22. Where personal information processors use personal information for automated decision-making, they shall ensure the transparency of the decision-making process and the fairness and reasonableness of the results. Where automated decision-making is used to push information or make commercial marketing to individuals, the option not targeting personal characteristics shall be provided, or a convenient method of refusal shall be offered.

Article 23. The processing of sensitive personal information requires a specific purpose and sufficient necessity, and strict protective measures shall be adopted. Sensitive personal information means personal information that, if leaked or illegally used, could easily cause harm to the personal dignity or endanger the personal or property safety of a natural person, including biometric information, religious beliefs, specific identity, medical and health information, financial accounts, whereabouts and trajectory, and personal information of minors under 14 years of age.

Article 24. The processing of sensitive personal information shall obtain the individual’s separate consent. Where laws or administrative regulations provide that written consent shall be obtained, such provisions shall be followed.

Chapter III — Rules for Cross-Border Provision of Personal Information

Article 25. A personal information processor that needs to provide personal information abroad shall meet one of the following conditions: (1) passing a security assessment organized by the national cyberspace administration authority; (2) obtaining personal information protection certification from a specialized institution; (3) entering into a contract with the overseas recipient based on standard contracts formulated by the national cyberspace administration authority; or (4) meeting other conditions prescribed by laws, administrative regulations, or the national cyberspace administration authority.

Article 26. Where personal information is provided abroad, the personal information processor shall inform the individual of the name and contact information of the overseas recipient, the purpose and method of processing, the categories of personal information, and the method and procedure for the individual to exercise rights against the overseas recipient, and shall obtain the individual’s separate consent.

Article 27. Personal information processors shall take necessary measures to ensure that overseas recipients’ processing of personal information meets the standards of protection provided by this Law.

Article 28. Where any country or region adopts discriminatory prohibitions, restrictions, or other similar measures against the People’s Republic of China in respect of personal information protection, the People’s Republic of China may adopt proportionate countermeasures against that country or region.

Chapter IV — Rights of Individuals in Personal Information Processing Activities

Article 29. An individual shall have the right to know and the right to decide on the processing of his or her personal information, and shall have the right to restrict or refuse the processing of personal information by others, unless otherwise provided by laws or administrative regulations.

Article 30. An individual shall have the right to access and copy his or her personal information from the personal information processor. Where the individual requests access or copying, the personal information processor shall provide it in a timely manner.

Article 31. Where an individual discovers that his or her personal information is inaccurate or incomplete, he or she shall have the right to request the personal information processor to correct or supplement it.

Article 32. An individual shall have the right to request the personal information processor to delete his or her personal information where: (1) the processing purpose has been achieved, cannot be achieved, or the personal information is no longer necessary for achieving the processing purpose; (2) the personal information processor ceases providing products or services, or the retention period has expired; (3) the individual withdraws consent; (4) the personal information processor processes personal information in violation of laws or administrative regulations or the agreement; or (5) other circumstances provided by laws or administrative regulations.

Article 33. An individual shall have the right to request the personal information processor to explain the rules for processing his or her personal information.

Article 34. Where an individual who is deceased has no prior arrangement, his or her close relatives may, for their own lawful and legitimate interests, exercise the rights of access, copying, correction, deletion, and other rights over the relevant personal information of the deceased, unless the deceased has arranged otherwise prior to death.

Article 35. Where a personal information processor refuses an individual’s request to exercise rights, it shall explain the reason. An individual may file a lawsuit with a people’s court in accordance with law.

Chapter V — Obligations of Personal Information Processors

Article 36. Personal information processors shall adopt the following measures to ensure that personal information processing activities comply with laws and administrative regulations and to prevent unauthorized access, leakage, tampering, or loss of personal information: (1) formulating internal management systems and operating procedures; (2) implementing categorized and graded management of personal information; (3) adopting encryption, de-identification, and other appropriate security technical measures; (4) reasonably determining the operational authority for personal information processing and conducting regular security education and training for employees; and (5) formulating and organizing the implementation of emergency response plans for personal information security incidents.

Article 37. Personal information processors that process personal information reaching a volume specified by the national cyberspace administration authority shall appoint a person in charge of personal information protection, who shall be responsible for supervising personal information processing activities and protection measures.

Article 38. Personal information processors processing personal information abroad that fall under Article 3(2) of this Law shall establish a specialized agency or appoint a representative within the territory of the People’s Republic of China to be responsible for matters relating to the personal information they process, and shall report the name and contact information of the agency or representative to the departments fulfilling personal information protection duties.

Article 39. Personal information processors shall conduct personal information protection impact assessments prior to: (1) processing sensitive personal information; (2) using personal information for automated decision-making; (3) entrusting processing, providing personal information to other processors, or disclosing personal information; (4) providing personal information abroad; or (5) other processing activities that have a significant impact on individuals’ rights and interests.

Article 40. Where a personal information security incident occurs or is likely to occur, the personal information processor shall immediately take remedial measures and notify the departments fulfilling personal information protection duties and the affected individuals.

Chapter VI — Departments Fulfilling Personal Information Protection Duties

Article 41. The national cyberspace administration authority shall be responsible for the overall planning and coordination of personal information protection work and related supervision and administration. Relevant departments under the State Council shall be responsible for personal information protection work and related supervision and administration within their respective scopes of duties.

Article 42. Departments fulfilling personal information protection duties may take the following measures when performing their duties: (1) conducting interviews and questioning of relevant parties; (2) inspecting and reviewing relevant documentation and records; (3) conducting on-site inspections; (4) inspecting and testing equipment and articles; and (5) conducting forensic examination and evidence collection.

Article 43. Where personal information is processed in violation of this Law, the departments fulfilling personal information protection duties shall order correction, issue a warning, and confiscate illegal gains. Where correction is refused, a fine of not more than CNY 1 million may be imposed on the processor, and a fine of not less than CNY 10,000 and not more than CNY 100,000 may be imposed on the directly responsible person in charge.

Article 44. Where the violation is serious, the departments fulfilling personal information protection duties shall order correction, confiscate illegal gains, and impose a fine of not more than CNY 50 million or not more than 5% of the annual revenue of the preceding year; and may order suspension of relevant business activities, cessation of business for rectification, or report to the relevant competent authority for revocation of business permits or business licenses. A fine of not less than CNY 100,000 and not more than CNY 1 million shall be imposed on the directly responsible person in charge.

Article 45. Where an infringement upon personal information rights and interests causes damage and the personal information processor cannot prove that it is not at fault, it shall bear tort liability such as compensation for damages.

Article 46. Where personal information processors violate the provisions of this Law, the relevant records of the violation shall be entered into the credit file and published in accordance with law.

Chapter VIII — Supplementary Provisions

Article 47. This Law shall take effect as of November 1, 2021.

Wechat

WhatsApp

WhatsApp

WhatsApp
[email protected]
+86 18565453956