Personal Information Protection Law of the PRC — Full English Translation (2021)

Adopted at the 30th Session of the Standing Committee of the 13th National People’s Congress on August 20, 2021

Effective: November 1, 2021


Table of Contents


Chapter I — General Provisions

Article 1 — This Law is enacted for the purposes of protecting personal information rights and interests, regulating personal information processing activities, and promoting the reasonable use of personal information.

Article 2 — The personal information of natural persons shall be protected by law, and no organization or individual shall infringe upon the personal information rights and interests of natural persons.

Article 3 — This Law shall apply to the processing of personal information of natural persons within the territory of the People’s Republic of China. Where any of the following circumstances exists in the processing of personal information of natural persons within the territory of China outside the territory of China, this Law shall also apply: (1) where the purpose is to provide products or services to natural persons within the territory of China; (2) where the purpose is to analyze or evaluate the conduct of natural persons within the territory of China; or (3) other circumstances provided by laws or administrative regulations.

Article 4 — “Personal information” means all kinds of information relating to identified or identifiable natural persons recorded by electronic or other means, excluding information that has been anonymized. The “processing of personal information” includes the collection, storage, use, processing, transmission, provision, disclosure and deletion of personal information.

Article 5 — Personal information shall be processed in accordance with the principles of legality, legitimacy, necessity and good faith, and shall not be processed by means of misleading, fraud or coercion.

Article 6 — The processing of personal information shall have a clear and reasonable purpose and shall be directly related to the purpose of processing. The method of processing personal information shall be adopted in a manner that has the least impact on the rights and interests of individuals. The collection of personal information shall be limited to the minimum scope necessary to achieve the purpose of processing and shall not be excessive.

Article 7 — Personal information shall be processed in accordance with the principles of openness and transparency, the rules for the processing of personal information shall be disclosed, and the purpose, method and scope of processing shall be clearly stated.

Article 8 — Quality shall be ensured when processing personal information to avoid adverse effects on individual rights and interests due to inaccurate or incomplete personal information.

Article 9 — Personal information processors shall bear responsibility for their personal information processing activities and shall adopt necessary measures to ensure the security of the personal information they process.

Article 10 — No organization or individual shall illegally collect, use, process or transmit personal information of others, or illegally trade, provide or disclose personal information of others; nor shall they engage in personal information processing activities that endanger national security or public interests.

Article 11 — The State shall establish a sound personal information protection system, prevent and punish acts infringing upon personal information rights and interests, strengthen publicity and education on the protection of personal information, and promote the formation of a sound environment in which the government, enterprises, relevant industry associations, and the public all participate in the protection of personal information.

Article 12 — The State shall actively participate in the formulation of international rules for the protection of personal information and promote international exchanges and cooperation in the field of personal information protection.

Chapter II — Rules for Processing Personal Information

Section 1 — General Rules

Article 13 — A personal information processor may process personal information only where the individual’s consent has been obtained, except under any of the following circumstances: (1) where it is necessary for the conclusion or performance of a contract to which the individual is a party, or for the implementation of human resources management under a labor rules and regulations formulated in accordance with the law and a collective contract lawfully concluded; (2) where it is necessary for the performance of statutory duties or obligations; (3) where it is necessary for responding to a public health emergency or for protecting the life, health or property safety of natural persons in an emergency; (4) where personal information is processed within a reasonable scope for purposes such as news reporting and supervision by public opinion for the public interest; (5) where personal information that has already been disclosed by the individual or otherwise lawfully disclosed is processed within a reasonable scope in accordance with the provisions of this Law; or (6) other circumstances provided by laws or administrative regulations.

Article 14 — Where consent is the basis for processing personal information, such consent shall be given by the individual voluntarily and explicitly on the premise of being fully informed. Where laws or administrative regulations provide that separate consent or written consent shall be obtained for the processing of personal information, such provisions shall prevail. Where the purpose of processing personal information, the method of processing and the types of personal information are changed, the individual’s consent shall be obtained anew.

Article 15 — Where the processing of personal information is based on the individual’s consent, the individual shall have the right to withdraw his or her consent. Personal information processors shall provide a convenient way to withdraw consent. The withdrawal of consent by an individual shall not affect the validity of the processing of personal information that has been carried out on the basis of the individual’s consent prior to such withdrawal.

Article 16 — Personal information processors shall not refuse to provide products or services on the grounds that an individual does not consent to the processing of his or her personal information, or withdraws his or her consent, unless the processing of personal information is necessary for the provision of such products or services.

Article 17 — Before processing personal information, personal information processors shall truthfully, accurately and completely inform individuals of the following matters in a conspicuous manner and in clear and easily understandable language: (1) the name and contact information of the personal information processor; (2) the purpose of processing personal information and the method of processing, and the types and storage period of the personal information to be processed; (3) the method and procedure for individuals to exercise their rights provided in this Law; and (4) other matters required to be notified by laws or administrative regulations. Where any of the matters provided in the preceding paragraph is changed, the individual shall be notified of such change. Where personal information processors inform individuals of the matters provided in the first paragraph by means of formulating personal information processing rules, such rules shall be made public and easily accessible and readable.

Article 18 — Where personal information processors process personal information under any circumstances where laws or administrative regulations provide that notification shall not be required, the individual may not be notified of the matters provided in the first paragraph of Article 17 of this Law. Where it is impossible to inform the individual in a timely manner in order to protect the life, health or property safety of a natural person in an emergency, the personal information processor shall inform the individual in a timely manner after the emergency is eliminated.

Article 19 — Unless otherwise provided by laws or administrative regulations, the storage period of personal information shall be the shortest period necessary to achieve the purpose of processing.

Article 20 — Where two or more personal information processors jointly determine the purpose and method of processing personal information, they shall agree on their respective rights and obligations. However, such agreement shall not affect an individual’s right to request any personal information processor to perform the obligations provided in this Law. Where a jointly processing personal information processor infringes upon personal information rights and interests and causes damage, it shall bear joint and several liability in accordance with the law.

Article 21 — Where a personal information processor entrusts the processing of personal information to another party, it shall agree with the entrusted party on the purpose, time limit, method of processing, types of personal information, protection measures, and the rights and obligations of both parties, and shall supervise the personal information processing activities of the entrusted party. The entrusted party shall process personal information in accordance with the agreement and shall not process personal information beyond the agreed purpose and method of processing; where the entrustment contract is not effective, not yet effective, is invalid, revoked or terminated, the entrusted party shall return the personal information to the personal information processor or delete it, and shall not retain it. Without the consent of the personal information processor, the entrusted party shall not sub-entrust the processing of personal information to others.

Article 22 — Where a personal information processor needs to transfer personal information due to merger, division, dissolution, bankruptcy, or other reasons, it shall inform the individual of the name and contact information of the receiving party. The receiving party shall continue to perform the obligations of the personal information processor. Where the receiving party changes the original purpose or method of processing, it shall re-obtain the individual’s consent in accordance with the provisions of this Law.

Article 23 — Where a personal information processor provides personal information it processes to another personal information processor, it shall inform the individual of the name and contact information of the receiving party, the purpose and method of processing, and the types of personal information, and obtain the individual’s separate consent. The receiving party shall process personal information within the scope of the processing purpose, processing method and types of personal information stated above. Where the receiving party changes the original purpose or method of processing, it shall re-obtain the individual’s consent in accordance with the provisions of this Law.

Article 24 — Where a personal information processor uses personal information to make automated decisions, it shall ensure the transparency of the decision-making and the fairness and impartiality of the outcome, and shall not apply unreasonable differential treatment to individuals in transaction pricing and other transaction conditions. Where commercial marketing or information push to individuals is carried out through automated decision-making methods, options that are not specific to the individual’s characteristics shall be provided at the same time, or the individual shall be provided with a convenient method to refuse. Where a decision made through automated decision-making methods has a significant impact on the individual’s rights and interests, the individual shall have the right to request an explanation from the personal information processor and shall have the right to refuse that the personal information processor makes decisions solely through automated decision-making methods.

Article 25 — Personal information processors shall not disclose personal information they process, unless they have obtained the individual’s separate consent.

Article 26 — Image capture and personal identification equipment installed in public places shall be necessary for the maintenance of public security, shall comply with the relevant provisions of the State, and shall be accompanied by conspicuous signs. Personal images and personal identification feature information collected may be used only for the purpose of maintaining public security and shall not be used for other purposes, unless the individual’s separate consent is obtained.

Article 27 — Personal information processors may, within a reasonable scope, process personal information that has already been disclosed by the individual or otherwise lawfully disclosed, unless the individual expressly refuses. Where personal information processors process disclosed personal information that has a significant impact on the individual’s rights and interests, they shall obtain the individual’s consent in accordance with the provisions of this Law.

Chapter III — Rules for Cross-Border Provision of Personal Information

Article 38 — Where a personal information processor truly needs to provide personal information outside the territory of the People’s Republic of China for business needs or other needs, it shall meet one of the following conditions: (1) passing the security assessment organized by the national cyberspace administration authority in accordance with Article 40 of this Law; (2) obtaining personal information protection certification from a professional institution in accordance with the provisions of the national cyberspace administration authority; (3) concluding a contract with the overseas recipient in accordance with the standard contract formulated by the national cyberspace administration authority, agreeing on the rights and obligations of both parties; or (4) meeting other conditions provided by laws, administrative regulations or the national cyberspace administration authority. Where an international treaty or agreement concluded or acceded to by the People’s Republic of China provides for conditions for the provision of personal information outside the territory of China, such conditions may be implemented in accordance with the provisions of such treaty or agreement. Personal information processors shall take necessary measures to ensure that the overseas recipient’s personal information processing activities meet the standards of personal information protection provided in this Law.

Article 39 — Where a personal information processor provides personal information outside the territory of the People’s Republic of China, it shall inform the individual of the name, contact information, purpose and method of processing, and types of personal information of the overseas recipient, and the method and procedure for the individual to exercise the rights provided in this Law against the overseas recipient, and shall obtain the individual’s separate consent.

Article 40 — Critical information infrastructure operators and personal information processors whose processing of personal information reaches the threshold prescribed by the national cyberspace administration authority shall store personal information collected and generated within the territory of the People’s Republic of China within the territory of China. Where it is truly necessary to provide such personal information outside the territory of China, a security assessment organized by the national cyberspace administration authority shall be passed; where laws, administrative regulations and the national cyberspace administration authority provide that security assessment is not required, such provisions shall prevail.

Article 41 — Competent authorities of the People’s Republic of China shall, in accordance with relevant laws and international treaties and agreements concluded or acceded to by the People’s Republic of China, or on the principle of equality and reciprocity, handle the request of a judicial or law enforcement authority of a foreign country for the provision of personal information stored within the territory of China. Without the approval of the competent authorities of the People’s Republic of China, personal information processors shall not provide personal information stored within the territory of the People’s Republic of China to any judicial or law enforcement authority of a foreign country.

Article 42 — Where an overseas organization or individual engages in personal information processing activities that infringe upon the personal information rights and interests of citizens of the People’s Republic of China, or endanger the national security or public interest of the People’s Republic of China, the national cyberspace administration authority may include it in a restricted or prohibited list of personal information provision, announce it, and take measures such as restricting or prohibiting the provision of personal information to it.

Article 43 — Where any country or region adopts any discriminatory prohibitions, restrictions or other similar measures against the People’s Republic of China in respect of personal information protection, the People’s Republic of China may, in light of the actual circumstances, adopt corresponding measures against such country or region.

Chapter IV — Rights of Individuals in the Processing of Personal Information

Article 44 — Individuals shall have the right to know and the right to decide on the processing of their personal information, and shall have the right to restrict or refuse the processing of their personal information by others, unless otherwise provided by laws or administrative regulations.

Article 45 — Individuals shall have the right to access and copy their personal information from personal information processors, except where laws or administrative regulations provide that such access shall not be granted or copying shall not be allowed. Where an individual requests access to or copying of his or her personal information, the personal information processor shall provide it in a timely manner. Where an individual requests the transfer of his or her personal information to a personal information processor designated by him or her, and the conditions prescribed by the national cyberspace administration authority are met, the personal information processor shall provide a means of transfer.

Article 46 — Where an individual discovers that his or her personal information is inaccurate or incomplete, he or she shall have the right to request the personal information processor to correct or supplement. Where an individual requests the correction or supplementation of his or her personal information, the personal information processor shall verify the personal information and correct or supplement it in a timely manner.

Article 47 — Under any of the following circumstances, a personal information processor shall voluntarily delete personal information; where the personal information processor fails to delete, the individual shall have the right to request deletion: (1) the purpose of processing has been achieved, cannot be achieved, or it is no longer necessary to achieve the purpose of processing; (2) the personal information processor ceases to provide products or services, or the storage period has expired; (3) the individual withdraws consent; (4) the personal information processor processes personal information in violation of laws, administrative regulations or the agreement; or (5) other circumstances provided by laws or administrative regulations. Where laws or administrative regulations provide that the storage period has not expired, or it is technically difficult to delete personal information, the personal information processor shall cease the processing of personal information except for storage and taking necessary security protection measures.

Article 48 — Individuals shall have the right to request personal information processors to explain the rules for the processing of their personal information.

Article 49 — Where a natural person dies, his or her close relatives may, for their own lawful and legitimate interests, exercise the rights provided in this Chapter, such as the right to access, copy, correct or delete the personal information of the deceased, unless otherwise arranged by the deceased prior to his or her death.

Article 50 — Personal information processors shall establish a convenient mechanism for accepting and handling applications from individuals to exercise their rights. Where an application from an individual to exercise his or her rights is refused, the reason shall be stated. Where an application from an individual to exercise his or her rights in accordance with the law is refused, the individual may bring a lawsuit in the people’s court in accordance with the law.

Chapter V — Obligations of Personal Information Processors

Article 51 — Personal information processors shall, based on the purpose and method of processing personal information, the types of personal information, the impact on individual rights and interests, and possible security risks, take the following measures to ensure that personal information processing activities comply with the provisions of laws and administrative regulations and prevent unauthorized access, divulgence, tampering or loss of personal information: (1) formulating internal management systems and operating procedures; (2) implementing classified management of personal information; (3) adopting corresponding security technical measures such as encryption and de-identification; (4) reasonably determining the operation authority for the processing of personal information and regularly providing education and training on security to employees; (5) formulating and organizing the implementation of personal information security incident emergency response plans; and (6) other measures provided by laws or administrative regulations.

Article 52 — Personal information processors whose volume of personal information processing reaches the threshold prescribed by the national cyberspace administration authority shall designate a person in charge of personal information protection, who shall be responsible for supervising personal information processing activities and the protection measures adopted, and other matters. Personal information processors shall disclose the contact information of the person in charge of personal information protection and submit the name of the person in charge, contact information and other information to the department performing personal information protection duties.

Article 53 — Personal information processors outside the territory of the People’s Republic of China as provided in the second paragraph of Article 3 of this Law shall establish a dedicated institution or designate a representative within the territory of the People’s Republic of China to be responsible for matters relating to the personal information they process, and submit the name of the relevant institution or the name and contact information of the representative to the department performing personal information protection duties.

Article 54 — Personal information processors shall regularly conduct compliance audits of their personal information processing activities and compliance with laws and administrative regulations.

Article 55 — Under any of the following circumstances, a personal information processor shall conduct a personal information protection impact assessment in advance and keep a record of the processing: (1) processing sensitive personal information; (2) using personal information in automated decision-making; (3) entrusting the processing of personal information, providing personal information to another personal information processor, or disclosing personal information; (4) providing personal information outside the territory of China; or (5) other personal information processing activities that have a significant impact on individual rights and interests. The content of the personal information protection impact assessment shall include: (1) whether the purpose and method of processing personal information are legal, legitimate and necessary; (2) the impact on individual rights and interests and the degree of security risk; and (3) whether the protection measures adopted are legal, effective and suitable for the degree of risk. The personal information protection impact assessment report and the record of processing shall be kept for at least three years.

Article 56 — Personal information processors shall take necessary measures to ensure the security of the personal information they process; where a personal information security incident such as divulgence, tampering or loss of personal information occurs, the personal information processor shall immediately take remedial measures and notify the department performing personal information protection duties and the individuals affected. The notification shall include the following matters: (1) the categories of personal information and the cause of and possible harm caused by the incident such as divulgence, tampering or loss of personal information; (2) the remedial measures taken by the personal information processor and the measures that individuals may take to mitigate harm; and (3) the contact information of the person in charge of personal information protection of the personal information processor. Where a personal information processor has taken measures that can effectively prevent the harm caused by the information security incident, the personal information processor may not notify the individuals; however, where the department performing personal information protection duties considers that harm may be caused, it may require the personal information processor to notify the individuals.

Article 57 — Personal information processors providing important internet platform services with a large number of users and complex business types shall perform the following obligations: (1) establishing an independent organization mainly composed of external members in accordance with the provisions of the State to supervise personal information protection; (2) following the principles of openness, fairness and justice, formulating platform rules, and clarifying the standards for personal information processing by product or service providers on the platform, and the obligations of platform product or service providers to protect personal information; (3) stopping providing services to product or service providers on the platform that seriously violate laws or administrative regulations in processing personal information; and (4) regularly publishing personal information protection social responsibility reports, and accepting social supervision.

Article 58 — Where a personal information processor that accepts an entrustment to process personal information performs its obligations under this Chapter, it shall take necessary measures to ensure the security of the personal information it processes, and assist the entrusting personal information processor in performing its obligations under this Law.

Chapter VI — Departments Performing Personal Information Protection Duties

Article 60 — The national cyberspace administration authority shall be responsible for overall planning and coordination of personal information protection and related supervision and administration work. The relevant departments under the State Council shall, in accordance with the provisions of this Law and relevant laws and administrative regulations, be responsible for personal information protection and supervision and administration work within their respective scope of duties. The relevant departments of the local people’s governments at or above the county level shall perform their personal information protection and supervision and administration duties in accordance with the relevant provisions of the State. The specific scope of duties of the departments provided in the two preceding paragraphs shall be determined in accordance with the relevant provisions of the State.

Article 61 — The departments performing personal information protection duties shall perform the following personal information protection duties: (1) carrying out publicity and education on personal information protection and guiding and supervising personal information processors in carrying out personal information protection work; (2) accepting and handling complaints and reports relating to personal information protection; (3) organizing the assessment of the protection of personal information such as application programs and investigating and publishing the results; (4) investigating and dealing with illegal personal information processing activities; and (5) other duties provided by laws or administrative regulations.

Article 62 — The national cyberspace administration authority shall coordinate and coordinate the relevant departments to promote the following personal information protection work: (1) formulating specific rules and standards for personal information protection; (2) formulating specialized rules and standards for the protection of personal information such as small and micro personal information processors and personal information processing for the processing of sensitive personal information and face recognition or artificial intelligence; (3) supporting the research and development and promotion of secure and convenient electronic identity authentication technology and promoting the construction of public services for online identity authentication; and (4) promoting the construction of a socialized service system for personal information protection and supporting relevant institutions in carrying out personal information protection assessment and certification services.

Article 63 — When performing their personal information protection duties, the departments performing personal information protection duties may adopt the following measures: (1) interviewing relevant parties and investigating matters relating to personal information processing activities; (2) consulting and copying contracts, account books, records and other materials relating to personal information processing activities; (3) conducting on-site inspections and investigating suspected illegal personal information processing activities; (4) inspecting equipment and articles relating to personal information processing activities; and (5) sealing up or seizing equipment and articles with evidence to prove that they are used for illegal personal information processing activities. When the departments performing personal information protection duties perform their duties in accordance with the law, the parties shall provide assistance and cooperation, and shall not refuse or obstruct them.

Article 64 — Where the departments performing personal information protection duties discover any relatively large risk in personal information processing activities or any personal information security incident in the course of performing their duties, they may, in accordance with the prescribed competence and procedures, interview the legal representative or the person in charge of the relevant personal information processor, or require the personal information processor to entrust a professional institution to conduct a compliance audit of its personal information processing activities. The personal information processor shall take measures in accordance with the requirements to rectify the matter and eliminate the hidden danger. Where the departments performing personal information protection duties discover illegal personal information processing activities suspected of constituting a crime in the course of performing their duties, they shall transfer the case to the public security organ for handling in accordance with the law.

Article 65 — Any organization or individual shall have the right to complain about or report illegal personal information processing activities to the departments performing personal information protection duties. The departments receiving the complaints or reports shall handle them in accordance with the law and inform the complainants or whistleblowers of the handling results in a timely manner. The departments performing personal information protection duties shall publish their contact information for receiving complaints and reports.

Chapter VII — Legal Liability

Article 66 — Where personal information is processed in violation of the provisions of this Law or personal information is processed without performing the personal information protection obligations provided in this Law, the department performing personal information protection duties shall order the rectification, give a warning, and confiscate the illegal gains; where an application program that illegally processes personal information is involved, it shall order the suspension or termination of the provision of services; where rectification is refused, a fine of not more than RMB 1,000,000 shall be imposed on the personal information processor; a fine of not less than RMB 10,000 and not more than RMB 100,000 shall be imposed on the directly responsible person in charge and other directly responsible personnel. Where the illegal acts specified in the preceding paragraph are serious, the department performing personal information protection duties at or above the provincial level shall order the rectification, confiscate the illegal gains, and impose a fine of not more than RMB 50,000,000 or 5% of the turnover of the previous year, whichever is higher, and may also order the suspension of relevant business, cessation of business operations for rectification, or report to the relevant competent department for the revocation of the relevant business permit or business license. A fine of not less than RMB 100,000 and not more than RMB 1,000,000 shall be imposed on the directly responsible person in charge and other directly responsible personnel, and they may also be prohibited from holding the positions of director, supervisor, senior manager or person in charge of personal information protection of the relevant enterprise for a certain period.

Article 67 — Where an illegal act specified in this Law exists, it shall be recorded in the credit file in accordance with the provisions of relevant laws and administrative regulations, and shall be published to the public.

Article 68 — Where a state organ fails to perform its personal information protection obligations as provided in this Law, the organ at a higher level or the department performing personal information protection duties shall order rectification; the directly responsible person in charge and other directly responsible personnel shall be subject to sanctions in accordance with the law.

Article 69 — Where the processing of personal information infringes upon personal information rights and interests and causes damage, and the personal information processor cannot prove that it is not at fault, it shall bear tort liability such as compensation for damages. The liability for damages provided in the preceding paragraph shall be determined based on the loss suffered by the individual or the benefits obtained by the personal information processor as a result of the infringement; where it is difficult to determine the loss suffered by the individual or the benefits obtained by the personal information processor, the compensation amount shall be determined based on the actual circumstances. Where the personal information processor has violated the provisions of this Law with respect to the processing of personal information and has caused damage to the rights and interests of a large number of individuals, the people’s procuratorate, the consumer organization specified by the law, and the organization designated by the national cyberspace administration authority may bring a public interest lawsuit in the people’s court in accordance with the law.

Article 71 — Where a violation of the provisions of this Law constitutes a violation of public security administration, public security administration penalties shall be imposed in accordance with the law; where a crime is constituted, criminal liability shall be pursued in accordance with the law.

Chapter VIII — Supplementary Provisions

Article 72 — This Law shall not apply to the processing of personal information by a natural person for personal or family affairs. Where laws provide for the processing of personal information by the people’s governments at all levels and their relevant departments in organizing and implementing statistical or archives management activities, such provisions shall apply.

Article 73 — For the purposes of this Law, the following terms shall have the following meanings: (1) “personal information processor” means an organization or individual that independently determines the purpose and method of processing personal information in personal information processing activities; (2) “automated decision-making” means the activity of using computer programs to automatically analyze or evaluate the conduct habits, hobbies or economic, health or credit status of individuals and make decisions; (3) “de-identification” means the process whereby personal information is processed so that a specific natural person cannot be identified without the aid of additional information; and (4) “anonymization” means the process whereby personal information is processed so that a specific natural person cannot be identified and the personal information after processing cannot be restored. The protection of personal information in the form of natural person’s health and medical records shall be governed by the provisions of relevant laws and administrative regulations in addition to the provisions of this Law.

Article 74 — This Law shall come into force on November 1, 2021.

Wechat

WhatsApp

WhatsApp

WhatsApp
[email protected]
+86 18565453956