Personal Information Protection Law of the PRC — Full English Translation (2021)

Table of Contents


Chapter I — General Provisions

Article 1 — This Law is enacted in accordance with the Constitution for the purposes of protecting the rights and interests of personal information, regulating the processing of personal information, promoting the reasonable use of personal information, and safeguarding the lawful rights and interests of individuals.

Article 2 — The personal information of natural persons shall be protected by law. No organization or individual shall infringe upon the rights and interests of personal information of natural persons.

Article 3 — This Law shall apply to the processing of personal information of natural persons within the territory of the People’s Republic of China. This Law shall also apply to the processing outside the territory of the People’s Republic of China of personal information of natural persons within the territory of the People’s Republic of China under any of the following circumstances: (1) where the purpose is to provide products or services to natural persons within the territory; (2) where the purpose is to analyze or evaluate the conduct of natural persons within the territory; or (3) under other circumstances provided by laws or administrative regulations.

Article 4 — “Personal information” means all kinds of information relating to identified or identifiable natural persons recorded by electronic or other means, excluding anonymized information. “Processing of personal information” includes the collection, storage, use, processing, transmission, provision, disclosure, and deletion of personal information.

Article 5 — The principles of legality, legitimacy, necessity, good faith and transparency shall be observed in the processing of personal information. Personal information shall not be processed in any misleading, fraudulent or coercive manner.

Article 6 — The processing of personal information shall have a clear and reasonable purpose, and shall be directly related to the purpose of processing. The collection of personal information shall be limited to the minimum scope necessary for achieving the purpose of processing, and excessive collection of personal information shall be prohibited.

Article 7 — The principles of openness and transparency shall be observed in the processing of personal information. The rules for processing personal information shall be disclosed, and the purpose, method and scope of processing shall be clearly indicated.

Article 8 — The quality of personal information shall be ensured in the processing of personal information, so as to avoid any adverse impact on the rights and interests of individuals due to inaccuracy or incompleteness of personal information.

Article 9 — Personal information processors shall be responsible for their personal information processing activities and shall take necessary measures to ensure the security of the personal information processed.

Article 10 — No organization or individual shall illegally collect, use, process or transmit the personal information of others, or illegally sell, provide or disclose the personal information of others, or engage in any other personal information processing activities that endanger national security or the public interest.

Article 11 — The state shall establish a sound personal information protection system, prevent and punish acts infringing upon the rights and interests of personal information, strengthen publicity and education on personal information protection, and promote the formation of a favorable environment in which the government, enterprises, relevant industry organizations and the public participate together in the protection of personal information.

Article 12 — The state shall actively participate in the formulation of international rules for personal information protection, promote international exchanges and cooperation in the field of personal information protection, and promote mutual recognition of rules and standards for personal information protection with other countries, regions and international organizations.

Chapter II — Rules for the Processing of Personal Information

Section 1: General Rules

Article 13 — Personal information may be processed only under any of the following circumstances: (1) where the consent of the individual has been obtained; (2) where it is necessary for the conclusion or performance of a contract to which the individual is a party, or for conducting human resources management in accordance with labor rules and regulations formulated in accordance with the law and collective contracts concluded in accordance with the law; (3) where it is necessary for the performance of statutory duties or obligations; (4) where it is necessary for responding to public health emergencies, or for protecting the life, health or property safety of natural persons in emergency situations; (5) where the personal information is processed within a reasonable scope for news reporting, supervision by public opinion, or other public interest activities in accordance with the law; (6) where the personal information has been disclosed by the individual or has otherwise been lawfully disclosed and is processed within a reasonable scope in accordance with this Law; or (7) under other circumstances provided by laws or administrative regulations. Processing of personal information shall be based on the consent of the individual, except as otherwise provided by laws or administrative regulations for the processing of personal information under the circumstances specified in items (2) through (7) of the preceding paragraph.

Article 14 — Where consent is the basis for the processing of personal information, such consent shall be given by the individual voluntarily and explicitly with full knowledge. Where laws or administrative regulations provide that the processing of personal information shall require the separate consent or written consent of the individual, such provisions shall prevail. Where the purpose, method or type of personal information processed is changed, the consent of the individual shall be obtained anew.

Article 15 — An individual shall have the right to withdraw his or her consent. Personal information processors shall provide a convenient means for withdrawing consent. The withdrawal of consent by an individual shall not affect the validity of the processing of personal information that has been carried out on the basis of consent prior to the withdrawal.

Article 16 — A personal information processor shall not refuse to provide products or services on the grounds that an individual does not consent to the processing of his or her personal information or withdraws his or her consent, except where the processing of personal information is necessary for the provision of products or services.

Article 17 — Before processing personal information, a personal information processor shall truthfully, accurately and completely inform the individual of the following matters in a conspicuous manner and in clear and understandable language: (1) the name and contact information of the personal information processor; (2) the purpose and method of processing personal information, the types of personal information processed, and the retention period; (3) the method and procedure for the individual to exercise the rights provided in this Law; and (4) other matters required by laws or administrative regulations to be notified. Where any of the matters specified in the preceding paragraph is changed, the individual shall be notified of such change. Where a personal information processor notifies the matters specified in the first paragraph by means of a personal information processing policy, the processing policy shall be made public and easy to access and keep. The processing policy shall be the sole basis for the exercise of the rights of the individual.

Article 18 — Where a personal information processor processes personal information under circumstances where laws or administrative regulations provide that confidentiality shall be maintained or notification is not required, the processor may not be required to notify the individual of the matters specified in the first paragraph of Article 17. When an emergency situation arises for protecting the life, health or property safety of natural persons, and it is impossible to notify the individual in a timely manner, the personal information processor shall notify the individual of the situation after the emergency is resolved.

Article 19 — The retention period for personal information shall be the minimum period necessary for achieving the purpose of processing, except as otherwise provided by laws or administrative regulations.

Article 20 — Where two or more personal information processors jointly determine the purpose and method of processing personal information, they shall agree on their respective rights and obligations. Provided, however, that such agreement shall not affect the right of an individual to request any one of the personal information processors to perform obligations, and the personal information processors shall bear joint and several liability where damage is caused to the rights and interests of personal information as a result of the processing of personal information.

Article 21 — Where a personal information processor entrusts another party with the processing of personal information, the processor shall enter into an agreement with the entrusted party on the purpose, time limit, method of processing, types of personal information, protective measures, and the rights and obligations of both parties, and shall supervise the personal information processing activities of the entrusted party. The entrusted party shall process personal information in accordance with the agreement and shall not process personal information beyond the agreed purpose and method of processing. Where the entrustment contract does not take effect, is void, is revoked or is terminated, the entrusted party shall return the personal information to the personal information processor or delete it, and shall not retain such personal information. Without the consent of the personal information processor, the entrusted party shall not sub-entrust another party with the processing of personal information.

Article 22 — Where a personal information processor needs to transfer personal information due to merger, division, dissolution, declaration of bankruptcy or other reasons, the processor shall notify the individual of the name and contact information of the receiving party. The receiving party shall continue to perform the obligations of the personal information processor. Where the receiving party changes the original purpose or method of processing, it shall obtain the consent of the individual anew in accordance with this Law.

Article 23 — Where a personal information processor provides personal information to another personal information processor, the processor shall notify the individual of the name and contact information of the receiving party, the purpose and method of processing, and the types of personal information, and shall obtain the separate consent of the individual. The receiving party shall process personal information within the scope of the above-mentioned purpose, method and types of personal information. Where the receiving party changes the original purpose or method of processing, it shall obtain the consent of the individual anew in accordance with this Law.

Article 24 — Where a personal information processor uses personal information to make automated decisions, it shall ensure the transparency of the decision-making and the fairness and impartiality of the results, and shall not engage in differential treatment that is unreasonably discriminatory in terms of transaction prices or other transaction conditions. Where information push or commercial marketing is conducted to individuals through automated decision-making methods, options that are not specific to their personal characteristics shall be provided simultaneously, or easy and convenient means for the individual to refuse shall be provided. Where an automated decision has a material impact on the rights and interests of an individual, the individual shall have the right to request the personal information processor to provide an explanation and may refuse to be subject to decisions made solely by automated decision-making methods.

Article 25 — A personal information processor shall not disclose the personal information it processes, unless it has obtained the separate consent of the individual, except as otherwise provided by laws or administrative regulations.

Article 26 — Where image capture and personal identification equipment is installed in public places, it shall be necessary for maintaining public safety, the relevant national standards shall be observed, and conspicuous notice signs shall be set up. The personal information collected may only be used for the purpose of maintaining public safety and shall not be used for other purposes, unless the separate consent of the individual is obtained.

Article 27 — A personal information processor may process, within a reasonable scope, personal information that has been disclosed by the individual or otherwise lawfully disclosed, unless the individual expressly refuses. Where the processing of such disclosed personal information has a material impact on the rights and interests of the individual, the consent of the individual shall be obtained in accordance with this Law.

Section 2: Rules for Processing Sensitive Personal Information

Article 28 — “Sensitive personal information” means personal information that, once leaked or illegally used, is likely to cause infringement of the personal dignity of a natural person or endangerment of personal safety or property safety, including biometric identification information, religious belief information, specific identity information, medical and health information, financial account information, whereabouts and location information, and personal information of minors under the age of 14. A personal information processor may process sensitive personal information only when there is a specific purpose and sufficient necessity and under circumstances where strict protective measures have been taken.

Article 29 — The processing of sensitive personal information shall require the separate consent of the individual. Where laws or administrative regulations provide that the processing of sensitive personal information shall require written consent, such provisions shall prevail.

Article 30 — Where a personal information processor processes sensitive personal information, it shall, in addition to the matters specified in the first paragraph of Article 17 of this Law, notify the individual of the necessity of processing the sensitive personal information and the impact on the rights and interests of the individual, unless this Law otherwise provides that notification is not required.

Article 31 — Where a personal information processor processes the personal information of a minor under the age of 14, the processor shall obtain the consent of the minor’s parent or other guardian. Where a personal information processor processes the personal information of a minor under the age of 14, the processor shall formulate special rules for the processing of such personal information.

Article 32 — Where laws or administrative regulations provide that relevant administrative licensing or other restrictions shall apply to the processing of sensitive personal information, such provisions shall prevail.

Section 3: Special Provisions on Processing of Personal Information by State Authorities

Article 33 — This Law shall apply to the processing of personal information by state authorities. Where there are special provisions in this Section, such provisions shall prevail.

Article 34 — State authorities shall process personal information for the purpose of performing their statutory duties, and shall process personal information in accordance with the powers and procedures prescribed by laws and administrative regulations. They shall not process personal information beyond the scope and extent necessary for the performance of their statutory duties.

Article 35 — State authorities shall, in accordance with this Law, fulfill their obligation to notify individuals of the processing of personal information, unless this Law otherwise provides that notification is not required, or where notification would impede the performance of statutory duties by state authorities.

Article 36 — Personal information processed by state authorities shall be stored within the territory of the People’s Republic of China. Where it is necessary to provide such information abroad, a security assessment shall be conducted in accordance with the law. The relevant authorities may support and assist the security assessment.

Article 37 — The processing of personal information by organizations authorized by laws and regulations with the function of administering public affairs shall be governed by the provisions of this Section applicable to state authorities.

Chapter III — Rules on Cross-Border Provision of Personal Information

Article 38 — Where a personal information processor needs to provide personal information outside the territory of the People’s Republic of China for business or other purposes, the processor shall meet one of the following conditions: (1) passing a security assessment organized by the State Cyberspace Administration in accordance with Article 40 of this Law; (2) obtaining personal information protection certification from a specialized institution in accordance with the provisions of the State Cyberspace Administration; (3) entering into a contract with the overseas recipient in accordance with the standard contract formulated by the State Cyberspace Administration, agreeing on the rights and obligations of both parties; or (4) meeting other conditions prescribed by laws, administrative regulations or the State Cyberspace Administration. Where a treaty or international agreement to which the People’s Republic of China is a party contains provisions on the provision of personal information outside the territory of the People’s Republic of China, such provisions may be applied, provided that the provisions are fulfilled.

Article 39 — Where a personal information processor provides personal information outside the territory of the People’s Republic of China, the processor shall notify the individual of the name and contact information of the overseas recipient, the purpose, method and types of personal information processed, and the method and procedure for the individual to exercise the rights provided in this Law against the overseas recipient, and shall obtain the separate consent of the individual.

Article 40 — A personal information processor that is a critical information infrastructure operator or that processes personal information reaching the threshold amount prescribed by the State Cyberspace Administration shall store the personal information collected and generated within the territory of the People’s Republic of China domestically. Where it is necessary to provide such information abroad, a security assessment shall be organized by the State Cyberspace Administration, unless laws, administrative regulations or the State Cyberspace Administration otherwise provide that such security assessment is not required.

Article 41 — The competent authorities of the People’s Republic of China shall, in accordance with relevant laws and international treaties or agreements concluded or acceded to by the People’s Republic of China, or on the principle of equality and reciprocity, handle requests from foreign judicial or law enforcement authorities for the provision of personal information stored within the territory. Without the approval of the competent authorities of the People’s Republic of China, a personal information processor shall not provide personal information stored within the territory of the People’s Republic of China to foreign judicial or law enforcement authorities.

Article 42 — The State Cyberspace Administration may include an overseas organization or individual in the list of restricted or prohibited recipients of personal information where the overseas organization or individual engages in personal information processing activities that infringe upon the rights and interests of personal information of citizens of the People’s Republic of China or endanger the national security or public interest of the People’s Republic of China, and shall make an announcement and take measures such as restricting or prohibiting the provision of personal information to such organization or individual.

Article 43 — Where any country or region adopts discriminatory or restrictive measures against the People’s Republic of China in respect of personal information protection, the People’s Republic of China may, based on actual circumstances, adopt reciprocal measures against such country or region.

Chapter IV — Rights of Individuals in the Processing of Personal Information

Article 44 — An individual shall have the right to know and the right to decide on the processing of his or her personal information, and shall have the right to restrict or refuse the processing of his or her personal information by others, except as otherwise provided by laws or administrative regulations.

Article 45 — An individual shall have the right to access and copy his or her personal information from the personal information processor, except as otherwise provided in Article 18 and Article 35 of this Law. Where an individual requests access to or copying of his or her personal information, the personal information processor shall provide such information in a timely manner. Where an individual requests the transfer of his or her personal information to a personal information processor designated by the individual, and the request meets the conditions prescribed by the State Cyberspace Administration, the personal information processor shall provide a means of transfer.

Article 46 — Where an individual discovers that his or her personal information is inaccurate or incomplete, the individual shall have the right to request the personal information processor to correct or supplement the information. Where an individual requests the correction or supplementation of his or her personal information, the personal information processor shall verify the personal information and make the correction or supplementation in a timely manner.

Article 47 — Under any of the following circumstances, a personal information processor shall voluntarily delete personal information. Where the personal information processor fails to delete, the individual shall have the right to request deletion: (1) the purpose of processing has been achieved, cannot be achieved, or is no longer necessary to achieve; (2) the personal information processor ceases to provide products or services, or the retention period has expired; (3) the individual withdraws consent; (4) the personal information processor processes personal information in violation of laws, administrative regulations or the agreement; or (5) under other circumstances provided by laws or administrative regulations. Where the retention period prescribed by laws or administrative regulations has not expired, or it is technically difficult to delete the personal information, the personal information processor shall cease processing other than storing and taking necessary security protective measures.

Article 48 — An individual shall have the right to request a personal information processor to explain the rules for processing personal information.

Article 49 — Where a natural person dies, his or her close relatives may, for the sake of their own lawful and legitimate interests, exercise the right to access, copy, correct or delete such personal information of the deceased, except where the deceased has arranged otherwise before his or her death.

Article 50 — A personal information processor shall establish a convenient mechanism for accepting and processing applications from individuals to exercise their rights. Where the processor refuses an individual’s request to exercise his or her rights, the processor shall provide the reason for such refusal. Where an individual refuses a request made by a personal information processor to exercise his or her rights, the individual may file a lawsuit with a people’s court in accordance with the law.

Chapter V — Obligations of Personal Information Processors

Article 51 — A personal information processor shall, based on the purpose, method and scope of processing personal information, the impact on the rights and interests of the individual, and the potential security risks, take the following measures to ensure that the processing of personal information complies with laws and administrative regulations and to prevent unauthorized access, leakage, tampering or loss of personal information: (1) formulating internal management systems and operating procedures; (2) implementing classified management of personal information; (3) adopting appropriate technical security measures such as encryption and de-identification; (4) reasonably determining the operational authority for the processing of personal information and regularly providing education and training on security to employees; (5) formulating and organizing the implementation of contingency plans for personal information security incidents; and (6) taking other measures provided by laws or administrative regulations.

Article 52 — A personal information processor that processes personal information reaching the threshold amount prescribed by the State Cyberspace Administration shall designate a person in charge of personal information protection, who shall be responsible for supervising the personal information processing activities and the protective measures taken, and other matters. The personal information processor shall disclose the contact information of the person in charge of personal information protection and report the name and contact information of such person to the department performing personal information protection duties.

Article 53 — A personal information processor outside the territory of the People’s Republic of China as specified in the second paragraph of Article 3 of this Law shall establish a specialized agency or designate a representative within the territory of the People’s Republic of China to be responsible for matters relating to the personal information it processes, and shall report the name and contact information of such agency or representative to the department performing personal information protection duties.

Article 54 — A personal information processor shall regularly conduct compliance audits of its personal information processing activities to verify compliance with laws and administrative regulations.

Article 55 — Under any of the following circumstances, a personal information processor shall conduct a personal information protection impact assessment in advance and keep a record of the processing: (1) processing sensitive personal information; (2) using personal information to make automated decisions; (3) entrusting another party with the processing of personal information, providing personal information to another personal information processor, or disclosing personal information; (4) providing personal information abroad; or (5) other processing of personal information that has a material impact on the rights and interests of individuals. The content of the personal information protection impact assessment shall include: (a) whether the purpose and method of processing personal information are lawful, legitimate and necessary; (b) the impact on the rights and interests of individuals and the degree of risk; and (c) whether the security protective measures taken are lawful, effective and appropriate to the degree of risk. The personal information protection impact assessment report and the record of processing shall be kept for at least three years.

Article 56 — Where a personal information processor discovers a leakage, tampering or loss of personal information, the processor shall immediately take remedial measures and notify the department performing personal information protection duties and the individual. The notification shall include the following items: (1) the types of personal information that have been leaked, tampered with or lost, the cause and possible harm caused; (2) the remedial measures taken by the personal information processor and the measures that the individual may take to mitigate the harm; and (3) the contact information of the personal information processor. Where the personal information processor takes measures that can effectively prevent harm caused by information leakage, the processor may not be required to notify the individual; provided, however, that the department performing personal information protection duties may still require the processor to notify the individual when it considers that the harm may have been caused.

Article 57 — A personal information processor that provides important internet platform services, has a large number of users, and has a complex type of business shall perform the following obligations: (1) establishing and improving its personal information protection compliance system and system architecture in accordance with the provisions of the state, and establishing an independent body mainly composed of external members to supervise personal information protection; (2) following the principles of openness, fairness and impartiality, formulating platform rules, and clarifying the standards for the processing of personal information by product or service providers on the platform and the obligations of such providers to protect personal information; (3) stopping providing services to product or service providers on the platform that process personal information in serious violation of laws or administrative regulations; and (4) regularly publishing social responsibility reports on personal information protection and accepting public supervision.

Article 58 — A personal information processor processing personal information by means of automated decision-making shall conduct a prior personal information protection impact assessment, and shall not conduct differential treatment that is unreasonably discriminatory in terms of transaction prices or other transaction conditions. Where information push or commercial marketing is conducted to individuals through automated decision-making methods, options that are not specific to their personal characteristics shall be provided simultaneously, or easy and convenient means for the individual to refuse shall be provided.

Article 59 — A party that processes personal information upon entrustment shall take necessary measures to ensure the security of the personal information processed and shall assist the personal information processor in fulfilling the obligations provided in this Law.

Chapter VI — Departments Performing Personal Information Protection Duties

Article 60 — The State Cyberspace Administration shall be responsible for the overall planning and coordination of personal information protection and related supervision and administration. The relevant departments of the State Council shall, in accordance with this Law and the provisions of relevant laws and administrative regulations, be responsible for the protection, supervision and administration of personal information within their respective functions and duties. The relevant departments of the local people’s governments at or above the county level shall, in accordance with this Law and the provisions of relevant laws and administrative regulations, perform their duties of protecting, supervising and administering personal information. The functions and duties of the departments specified in the preceding two paragraphs shall be determined in accordance with the provisions of the relevant laws and administrative regulations.

Article 61 — The departments performing personal information protection duties shall perform the following personal information protection duties: (1) conducting publicity and education on personal information protection, and guiding and supervising personal information processors in the protection of personal information; (2) accepting and handling complaints and reports relating to personal information protection; (3) organizing investigations, testing and assessment of the security of applications and other personal information protection activities, and publishing the results; (4) investigating and punishing illegal personal information processing activities; and (5) other duties provided by laws or administrative regulations.

Article 62 — The State Cyberspace Administration shall coordinate the relevant departments in promoting the following personal information protection work in accordance with this Law: (1) formulating specific rules and standards for personal information protection; (2) formulating special rules and standards for the protection of personal information of minors in accordance with this Law; (3) formulating rules for personal information protection certification; (4) formulating model contracts for the cross-border provision of personal information; and (5) organizing the formulation of rules for personal information protection for small-scale personal information processors that process personal information of a small number of individuals.

Article 63 — Departments performing personal information protection duties may take the following measures in the performance of their duties: (1) interviewing the relevant parties and investigating the situation relating to personal information processing activities; (2) accessing and copying contracts, records, account books and other relevant materials relating to personal information processing activities of the parties; (3) conducting on-site inspections and investigating personal information processing activities suspected of being illegal; (4) inspecting equipment and goods relating to personal information processing activities; and (5) sealing or seizing items that are proven evidence of illegal personal information processing activities upon written approval of the responsible person of the department. Where the departments performing personal information protection duties perform their duties in accordance with the law, the parties shall provide assistance and cooperation and shall not refuse or obstruct them.

Article 64 — Where a department performing personal information protection duties discovers in the performance of its duties that there are relatively large risks in the processing of personal information or that there is a personal information security incident, the department may interview the legal representative or the principal responsible person of the personal information processor in accordance with the prescribed authority and procedures, or require the personal information processor to entrust a specialized institution to conduct a compliance audit of its personal information processing activities. The personal information processor shall take measures to rectify and eliminate the risks as required. The relevant departments performing personal information protection duties shall, in accordance with their functions and duties, order rectification or suspend the provision of services to illegal applications.

Article 65 — Any organization or individual shall have the right to report illegal personal information processing activities to the departments performing personal information protection duties. The departments receiving the report shall handle it in a timely manner in accordance with the law and inform the reporter of the outcome of the handling. The departments performing personal information protection duties shall publish the contact information for receiving complaints and reports.

Article 66 — Where personal information is processed in violation of the provisions of this Law or personal information is processed without fulfilling the protection obligations provided in this Law, the department performing personal information protection duties shall order rectification, give a warning, and confiscate illegal gains, and may impose a provisional suspension or termination of the provision of services by the illegal application. Where rectification is refused, a fine of not more than one million yuan shall be imposed on the personal information processor and a fine of not less than 10,000 yuan but not more than 100,000 yuan on the person directly in charge and other directly responsible persons. Where the circumstances specified in the preceding paragraph are serious, the department performing personal information protection duties at or above the provincial level shall order rectification, confiscate illegal gains, and impose a fine of not more than 50 million yuan or not more than five percent of the turnover of the previous year on the personal information processor, and may also order a suspension of the relevant business activities or cessation of business for rectification, and notify the relevant competent authority to revoke the relevant business license or business permit. A fine of not less than 100,000 yuan but not more than one million yuan shall be imposed on the person directly in charge and other directly responsible persons, and such persons may be prohibited from serving as directors, supervisors, senior management personnel or persons in charge of personal information protection of relevant enterprises within a certain period.

Article 67 — Where there are illegal acts as provided in this Law, they shall be recorded in the credit files in accordance with the provisions of relevant laws and administrative regulations and shall be publicized.

Article 68 — Where a state authority fails to fulfill its personal information protection obligations as provided in this Law, its superior organ or the department performing personal information protection duties shall order rectification. The person directly in charge and other directly responsible persons shall be subject to disciplinary action in accordance with the law.

Article 69 — Where the processing of personal information infringes upon the rights and interests of personal information and causes damage, and the personal information processor cannot prove that it is not at fault, the personal information processor shall be liable for damages and other infringement liabilities. The damages specified in the preceding paragraph shall be determined based on the loss suffered by the individual or the benefits obtained by the personal information processor as a result of the infringement. Where it is difficult to determine the loss suffered by the individual and the benefits obtained by the personal information processor, the damages shall be determined by the people’s court based on the actual circumstances.

Article 70 — Where a personal information processor processes personal information in violation of the provisions of this Law, infringing upon the rights and interests of a large number of individuals, the people’s procuratorate, the consumer organizations prescribed by law and the organizations designated by the State Cyberspace Administration may file a lawsuit with a people’s court in accordance with the law.

Article 71 — Violations of the provisions of this Law that constitute a violation of public security administration shall be subject to public security administration penalties in accordance with the law. Where a crime is constituted, criminal liability shall be pursued in accordance with the law.

Chapter VIII — Supplementary Provisions

Article 72 — This Law shall not apply to the processing of personal information by a natural person for personal or family affairs. Where laws provide for the processing of personal information by relevant state authorities in the course of statistical or archival administration activities, the provisions of such laws shall apply.

Article 73 — For the purposes of this Law, the following terms shall have the following meanings: (1) “personal information processor” means an organization or individual that independently determines the purpose and method of processing personal information in personal information processing activities; (2) “automated decision-making” means the activity of analyzing and assessing the behavior, habits, interests and hobbies, financial, health, credit and other status of an individual through computer programs and making decisions based on such analysis and assessment; (3) “de-identification” means the process of processing personal information so that the information cannot identify a specific natural person without the aid of additional information; and (4) “anonymization” means the process of processing personal information so that the information cannot identify a specific natural person and cannot be restored. The protection of personal information in the processing of personal information by legal persons or unincorporated organizations shall be governed by this Law by reference.

Article 74 — This Law shall come into force as of November 1, 2021.

Wechat

WhatsApp

WhatsApp

WhatsApp
[email protected]
+86 18565453956