Language

A Chinese Data Privacy Law with Strong Influences from the EU


A Chinese Data Privacy Law with Strong Influences from the EU-China Releases the Draft on Its First Uniform Personal Information Protection Law


Authored by Yingying Zhu


The world has witnessed a torrent of lawmaking, regulatory design and enforcement activities regarding data privacy following the enactment of the General Data Protection Regulation (“GDPR”) [1] of the European Union in May 2018. At present, 132 out of 194 countries had put in place legislation to secure the protection of data and privacy. [2]

 

The inadequacy of personal information protection in China has raised widespread public concerns in this big data land with 904 million netizens,[3] vulnerable to data breaches and cyber frauds. In 2016, a professor at the prestigious Tsinghua University wired more than CNY17 million to a fraud, after she received a scam call from the fraud who knew every detail about the deal of a recent sale of her real property.[4] Incidents like this have led to nationwide discussions and provoked reflection among thinkers, legal experts and law makers. 

 

At present, data protection laws, regulations and specifications in China were scattered in sectional laws, regulations and non-binding guidelines, such as the Criminal Law and its Amendment VII, the Consumer Protection Law, the Cybersecurity Law, the Personal Information Security Specification, the Civil Code, etc.

 

On October 13, 2020, after years of brewing, China releases the long-awaited and much-welcomed draft on its first dedicated personal information protection law. The draft has been submitted to the standing committee of the China's top legislature-the National People’s Congress (“NPC”) for the first review and then posted for public comments on NPC’s official website. The comment period lasts until November 19, 2020.

 

Being the first comprehensive law that emulates the GDPR, the draft Personal Information Protection Law (“draft PIPL”) has shown strong GDPR influences as well as its unique Chinese characteristics.

Definition of “Personal Information” and “Sensitive Personal Information”

The types of information considered personal under the draft PIPL include various information recorded electronically or in other forms that is relating to an identified or identifiable natural person (“data subject”), excluding the anonymized information. The processing of personal information includes activities such as the collection, storage, use, handling, transmission, provision, and disclosure of personal information.

Here, “personal information” under the draft PIPL is similar in terms of definition to “personal data” used in the GDPR as well as in its predecessor, the EU Data Protection Directive,[5] because it includes data that relate both to an “identified” or “identifiable” individual. “Identifiable” means that an individual might not currently be identified but could be identified by combining various pieces of data.[6] For example, the name of a person (in particular, a none-celebrity), is often not identified to an individual, but sometimes can easily be linked to an individual with bits of other information, such as an address, a telephone number or a place of work.

 

On a risk-based approach, the draft PIPL defines sensitive personal information (“SPI”) as personal information that once leaked or illegally used may lead to discriminatory treatment or could seriously endanger the safety of persons or property, including information such as one’s race, ethnicity, religious beliefs, personal biological characteristics, medical health, financial accounts, personal whereabouts and so forth.[7] Only personal information processors with a specific purpose and sufficient necessity may process SPI. The draft also requires that the individuals' “independent consent” shall be obtained where processing SPI is to be based on individuals' consent and individuals shall also be informed of the necessity of processing SPI and the impact on them.

 

The draft PIPL, for the first time in China’s privacy protection legislation, specifically defines SPI. As improper disclosures of SPI can cause greater harm and damage to the image, reputation or security of an individual, it is of significant importance to ensure that SPI could be specifically defined and appropriately protected.

 

One problem with the draft PIPL’s definition of SPI, however, is that it seems to ignore a certain type of SPI -a person’s private or secret life that in many defamation cases has been the subject of public online shaming. If an individual’s personal private life (usually unpleasant, eccentric or immoral) was posted on some popular online platforms due to mishandling of that individual’s personal information, and the news goes viral, the victim in many cases would suffer spiritually from attacks of cyber-mobs and internet violence. The suffering can be nothing financial but only emotional. Here, the risk-based definition of SPI in the draft PIPL only covers risks in the form of “discriminatory treatment” or “endangering safety of persons or property”, but leaving out the harm caused to personal reputation and psychological health, which, in many cases, could be the only resulted harm in violation of SPI. The draft PIPL obviously did not give enough consideration to such type of possible harm in its current definition of SPI.

 

Under the GDPR, processing of personal data of a sensitive nature shall be prohibited, unless some stricter preconditions could be met. Such data are classified under the label of SPI[8] and sensitive data are clearly listed by its definition.

 

Though differ in defining, the draft PIPL converges with the GDPR in that both recognize SPI is belonging to a specific category of information that must be treated with extra safeguarding.

Rights of Individuals

Under the draft PIPL, individuals enjoy the right to know and make decisions about the processing of their personal information, and have the right to limit or refuse the processing of their personal information by others, except otherwise provided by laws and administrative regulations

Specifically, individuals enjoy the following rights:

1)    Right to access:[9] the data subject may consult or reproduce his personal information from the information processor;

2)    Right to rectification: upon discovery of any error in the information, the data subject has the right to raise an objection and to request to have a timely correction;

3)    Right to be forgotten: if the handling of personal information is in violation of law, or any prior agreement, or the purposes of processing have been realized, or an individual has withdrawn the consent, the data subject has the right to request a timely erasure. If, however, the retention period prescribed by law has not been completed, or deletion of personal information is technically difficult to achieve, the personal information processor shall stop the processing;

4)    Right to be informed: individuals have the right to be informed about rules concerning the processing of their personal information;

5)    Right to refuse automated decision-making: where an individual believes that automated decision-making has a significant impact on one’s rights and interests, one has the right to request an explanation from the personal information processor and has the right to refuse automated individual decision-making.

Under the draft PIPL, individuals have a broader scope of rights than previous laws in the same sector and it brings China’s protection on privacy even closer to the GDPR standards.[10] It is however interesting to note the “right to data portability”[11] under the GDPR has not been transplanted to its Chinese counterpart. As the right to data portability does not apply to genuinely anonymous data but only to pseudonymous data that can clearly be linked back to a data subject, maybe the notions of cyber- sovereignty and network security with a distinguishable Chinese feature could account for the missing of such right in the Chinese context..

Principles and Conditions for Data Processing

Under the draft PIPL, the general principles for data collection are: data shall be collected lawfully and justifiably, openly and transparently, accurately and kept up-to-date and data collection shall have clear and reasonable purposes and be limited to the minimum scope to achieve such purposes of processing. The data processing activities shall meet the following conditions:

(1) With the consent of the individual;

 

(2) It is necessary for entering into or performing a contract to which the individual is a party;

 

(3) It is necessary for performing of legally-binding duties or obligations;

 

(4) It is necessary to respond to public health incidents or to protect natural persons' security in their lives, health, and property under an emergency;

 

(5) It is within a reasonable range in order to carry out acts such as news reporting and public opinion overseeing in the public interest; or

 

Other circumstances warranted by laws or administrative regulations.

 

The GDPR provides six legal bases for processing personal data, namely: consent; contract; legal obligation; vital interests; public task; or legitimate interests pursued by the controller or by a third party.[12] The draft PIPL sets out the above five specific legal bases for processing personal data, which are comparable to the first five legal bases of the GDPR while chipping away the last one concerning “legitimate interests pursued by the controller or by a third party”, on the possible account that it would have the potential of giving too much discretion to the information processor and therefore dilute the value of all the other legal bases.

 

Under the draft PIPL, consent, albeit the most well-known one, is just one of the legal bases a business can rely on to justify the proceeding of individuals’ personal data. Furthermore, for consent to be valid, it must be freely-given, unambiguous and explicit, informed and withdrawable. Consent is not freely-given if individuals have no other meaningful options but to give out their consent. This means businesses shall not create an opt-in-or-leave-it situation when seeking people’s consent. Individuals need to maintain the ability to decline and shall be free from discrimination when they opt out. The draft PIPL also specifies that if there are changes to the purposes or methods for processing information, or to the type of personal information to be processed, the individual's consent shall be re-obtained.

 

Extraterritorial Applicability

 

The GDPR has an extraterritorial scope, because it may apply to businesses established outside the European Union when they offer goods or services to data subjects in the European Union or monitor their behavior when it takes place in the European Union.[13]

 

Modeling on the GDPR’s approach towards extraterritorial application, Article 3 of the draft PIPL expands the law’s territorial scope to data processing activities outside China. Any data processing activities that process personal data within P.R. China, if meeting any of the following conditions, will fall under the territorial scope of the Chinese data protection law:

 

(1) for the purpose of providing products or services to natural persons within the territory;

 

(2) to analyze and evaluate the conduct of natural persons in the territory; or

 

(3) other circumstances provided for by laws and administrative regulations.

 

If this clause remains intact in the final legal text, it means that the Chinese privacy rules now can also apply to data processing activities outside China. The consequence of this expansion is that non-Chinese data controllers and processors must comply with the Chinese data protection obligations when processing data on individuals in China for the above-listed purposes.

Obligations of Personal Information Processor

Under the draft PIPL, the personal information processor, the one who collects, stores, uses, handles, transmits, provides, and discloses personal information, shall have the following obligations:

(1) take necessary measures to ensure the legal compliance of personal information processing activities and prevent unauthorized access, disclosure or theft, tampering, and deletion of personal information;

(2) while processing personal information at certain volume, shall designate a person in charge to be responsible for overseeing personal information processing activities and any protection measures taken;

(3) if processing Chinese individuals’ personal information outside China as provided in Article 3 of the Law shall establish a point of contact within China;

(4) shall conduct periodic audits and risk assessments in advance for certain categories of personal information processing activities;

(5) where there is incident of personal information leakage, shall immediately take remedial measures and notify the supervisory authorities.

Once a data breach occurs, the GDPR requires data controllers to notify supervisory authorities of a security breach within 72 hours after it has been aware of it.[14] Furthermore, when the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.[15]

In comparison, the draft PIPL is not specific about the timeframe for notification to the supervisory authorities and where personal information processors take measures that can effectively avoid the harm caused by the information leakage, the personal information processors are allowed to not notify the individuals.

Liabilities and Penalties

Violations of the draft PIPL may be subject to a fine of up to CNY1 million (about EUR 0.128 million); the directly responsible management and other directly responsible person may be subject to a fine of between CNY10,000 (about EUR1,283) to CNY100,000 (about EUR12,831). Serious violations of the draft PIPL can be fined up to CNY 50 million (about EUR 6.4 million) or up to 5% of the preceding year's turnover. Where there is an illegal act of data processing activities, it is to be recorded in the business’ credit files with a public announcement posted.

In comparison, under GDPR, the less severe infringements could result in a fine of up to EUR10 million, or 2% of the business’ global annual revenue in the preceding financial year, whichever is higher. For more severe infringements, GDPR sets a maximum fine of EUR 20 million or 4% of annual turnover, whichever is higher.[16]

In an age of constant, complex and sometimes intrusive technological innovation, the high penalties on noncompliance aim to have a deterrent effect on rule-breakers who are mishandling people’s data or using people’s data without adequate measures in place to safeguard them.

Conclusion

The draft PIPL, being the first dedicated law to data privacy protection in China, thus forming a unified force of enforcement, marks a milestone in the country data privacy legislation. The law shows a broader scope of application than the previous sectional laws and regulations and levels up the country’s protection on data privacy closer to the GDPR standards, a.k.a., the global standards, given the large number of countries around the world that have adopted the GDPR model. While highly converging with the EU rules, the draft PIPL demonstrates a unique Chinese characteristics thus showing a strong Chinese voice with a subtle EU accent.

The laws and regulations on data privacy are constantly evolving in China with changes still in the pipeline. We are here to help if you have any problems, issues, concerns regarding data privacy protection inside or outside China.

 



[1] The General Data Protection Regulation (EU) 2016/679.

[2] See https://unctad.org/page/data-protection-and-privacy-legislation-worldwide.

[3]See https://www.thehindu.com/news/international/chinas-netizen-population-hits-record-904-million-report/article31451143.ece.

[4] See http://www.techweb.com.cn/tele/2017-02-20/2489197.shtml.

[5] The Data Protection Directive, officially Directive 95/46/EC on the protection of individuals with regard to the processing of personal data and on the free movement of such data.

[6] Paul M. Schwartz & Daniel J. Solove, Reconciling Personal Information in the U.S. and EU, 102 Cal. L. Rev. 886 (2014).

[7] While an official translation is not yet available, the author has referenced the source at https://www.chinalawtranslate.com/en/personal-information-protection-draft for the translation of the texts of the draft PIPL.

[8] Definition of “sensitive personal information” under the GDPR: data consisting of racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data, data concerning health or data concerning a natural person's sex life or sexual orientation.

[9] The subtitles are used in this article for convenience only; they are not part of the draft PIPL.

[10] Rights for individuals under the GDPR, see https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/individual-rights.

[11] The right to data portability allows individuals to obtain and reuse their personal data for their own purposes across different services. It allows them to move, copy or transfer personal data easily from one IT environment to another in a safe and secure way, without affecting its usability. See https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-data-portability/.

[12] GDPR, Article 6(1).

[13] GDPR, Article 3(2).

[14] GDPR, Article 33(1).

[15] GDPR, Article 34(1).

[16] See https://www.itgovernance.co.uk/dpa-and-gdpr-penalties.

  • 相关资讯 More
  • 点击次数: 2
    2026 - 09 - 09
    伴随新业态经济的快速持续发展,依托互联网平台的新就业形态从业规模不断扩大,劳动者与平台企业之间的法律关系日趋复杂,有的不良平台企业以“承揽合同”“自由职业者合作协议”等民事协议之名行直接用工之实,有的通过关联企业混同用工规避法律责任,有的公然要求劳动者自带车辆完成配送等等,给传统劳动关系的认定带来了很大冲击和挑战。这种形势下,劳动者权益如何保障?企业发展活力如何兼顾?这是司法必须回应的时代之问。【基本案情】2024年初,平台企业某驴公司发布广告称,在某市区公开招聘配送司机,要求应聘司机自带车内空间七方以上的面包车型车辆;在配送时间方面,要求配送司机半夜23时前到达仓库,配送在上午8-9时结束;月薪12000至18000元。作业内容对配送区域、配送食材以及司机的年龄、驾龄要求进行了具体描述;同时,要求配送司机熟悉基本手机软件操作,能够独立使用APP软件进行送货、签到、打卡等等。失业已有三月的袁先生,得知此消息兴奋不已,自己各方面条件都符合招聘要求,面对如此高薪,怎能在家“坐吃山空”,赶紧挣钱养家才是男人第一大要务。袁先生的应聘非常顺利,很快被录用。在办理入职过程中,某驴公司先是要求其在公司运营的APP软件注册,随后引导其与公司签订了承揽合同,并将其拉入工作微信群。一切都很顺利,一切又似乎让人迷茫。接下来的两年里,老实巴交的袁先生总是在夜间提前到达仓库,提前在APP里签到打卡,然后根据仓库领导在微信群里的工作安排,对配送的货物进行分拣、装车,再送往各个餐饮店,通常在次日上午10点配送结束后回到家里。几次因途中堵车延误时间,遭到客户投诉及某驴公司罚款。时不时接受某驴公司对全体配送司机的培训教育。老家有红白喜事,必须先在微信群向领导请假,获批后方可离开。两年来,袁先生虽有委屈,虽然辛苦,但每月看到某驴公司转给自己的一万多元的“收入”,心理还是有些许安慰的。然而,天有不测风云。202...
  • 点击次数: 7
    2026 - 08 - 17
    引言:创造性判断中,申请人常以“现有技术给出了反向教导”为由主张技术方案非显而易见。那么,什么情况下才能成立反向教导?最高人民法院在(2023)最高法知行终413号案中给出了明确裁判思路。为进一步理解这一标准,我们结合具体案件分析及相关案例一并探讨。一、基本案情德国某公司申请的发明专利“导线连接接触元件”(申请号20181015****.3)被国家知识产权局以不具备创造性为由驳回。复审及一审均维持驳回决定。申请人上诉至最高人民法院,核心理由之一是:对比文件1公开的结构给出了针对区别技术特征的反向教导,本领域技术人员不会作出本申请的改进。最高人民法院于2024年12月24日作出(2023)最高法知行终413号行政判决,驳回上诉,维持原判。二、裁判要旨最高人民法院明确指出:所谓的反向教导属于创造性评价中判断技术启示时可能涉及的问题。判断现有技术是否存在反向教导,应当以发明实际解决的技术问题为基础,如果现有技术公开的内容不构成本领域技术人员解决发明实际解决的技术问题的障碍,则通常不认为其构成反向教导。简言之,反向教导的认定必须锚定在发明实际解决的技术问题上,而非孤立地看待对比文件中的某个结构或功能。三、具体案例分析本案中,本申请权利要求1相对于对比文件1的区别技术特征主要在于提供了一种不同结构的SMD焊接接触件。该接触件并未保留对比文件1中的“摆动抑制作用”,也未实现其他新功能,其核心作用仍是提供支撑面。申请人主张对比文件1因强调摆动抑制功能而构成反向教导。法院对此不予支持,理由如下:以实际解决的技术问题为判断基准 本申请实际解决的技术问题并非“如何实现摆动抑制”,而是提供一种具有支撑功能的SMD焊接接触件结构。对比文件1公开的摆动抑制部位置和结构,并不妨碍本领域技术人员在此基础上进行简化或调整。放弃原有功能不必然构成反向教导 本领域技术人员完全可以从对比文件1公开的结构出发,放...
  • 点击次数: 7
    2026 - 08 - 07
    在侵权赔偿纠纷中,受害人自身疾病或特殊体质与侵权行为结合给受害人造成同一损害或导致损害扩大时,侵权人往往以此为由主张免除或减轻赔偿责任。对此,司法机关是如何考量的呢?本文即以案释法,对此进行分析探讨。一、典型案例(一)案例1:参见(2020)京01民终6829号民事判决书1.基本案情2018年3月21日,孙某到提供游泳服务的某公司处游泳,由于某公司工作人员在游泳池内尚有人在游泳时,将游泳池外围地面处铺设的防滑网垫移开,并用水冲洗游泳池外地面淤泥及桌椅,导致孙某从游泳池内出来后,在游泳池外围的地面滑倒后摔伤。当日,孙某即被送往医院紧急就诊,后住院治疗。住院病历诊断:1.颈椎外伤,无骨折脱位型颈脊髓损伤;2.冠状动脉粥样硬化性心脏病,陈旧性心梗,支架植入术后,心功能II级;3.高血压病3级,极高危;4.陈旧脑梗塞;5.高血脂症;6.II型糖尿病。手术志摘要:颈后正中纵切口12cm,充分暴露C3-7棘突及椎板,逐层缝合关闭切口。后孙某起诉至法院。案件审理过程中,某公司申请对孙某的医疗费合理性进行鉴定,鉴定中心表示,孙某自身患有先天性颈椎狭窄的疾病,这次摔伤加重了孙某的病情,且鉴定意见第2项中有控制高血压、血糖等用药,建议住院后产生的医疗费用外伤的原因力的诱发因素不超过50%。孙某向一审法院起诉请求:判令某公司支付孙某医疗费102991.85元、住院伙食补助费1600元、营养费4500元、护理费6700元、误工费10687元、交通费200元、精神损失费5000元,以上共计131678.85元。2.法院裁判要旨及判决结果(1)裁判要旨一审法院认为,我国侵权责任法规定,宾馆、商场、银行、车站、娱乐场所等公共场所的管理人或者群众性活动的组织者,未尽到安全保障义务,造成他人损害的,应当承担侵权责任。侵害他人造成人身损害的,应当赔偿医疗费、护理费、交通费等为治疗和康复支出的合理费用,以及因误...
  • 点击次数: 21
    2026 - 07 - 17
    导语股权收购、资产并购、业务分拆整合、新设合营企业,是企业扩大市场份额、完善产业链布局的主流商业手段。经营者集中事前申报,是《中华人民共和国反垄断法》设定的强制性前置合规程序,也是投融资交易中法务、合规团队首要核查的法律节点。  实务中,不同赛道的并购交易,监管审查范围、配套申报义务、材料披露尺度存在明显区分。本文结合现行有效法律法规、国家市场监督管理总局、国家发改委发布的官方实操文件,分别梳理大众快消行业并购、外资收购高科技企业两类高频交易场景下经营者集中申报实操要点。    一、快消品类经营者集中 日化、生活用纸、非处方健康消费品、包装食品等民生快消行业的境内、跨境并购,仅需完成经营者集中单一申报流程,不存在外商投资安全审查叠加义务,全部合规工作围绕市场公平竞争维度开展。  1. 申报触发判定标准依据《中华人民共和国反垄断法》(2022 修正)第二十六条、《国务院关于经营者集中申报标准的规定》(2024 修订)第三条,交易参与方上一会计年度的合并营业额达到下述任一标准,必须在股权交割、业务整合前向国家市场监督管理总局提交申报,未取得审查决定不得实施集中:一是参与集中的所有经营者全球合计年营业额超过 120 亿元,且至少两家经营者在中国境内年营业额均超过8 亿元以上;二是全部经营者境内合计年营业额超 40 亿元,且至少两家境内营业额均超过 8 亿元。金佰利公司拟收购科赴(Kenvue)公司股权是当前快消领域典型横向收购案例,交易覆盖纸巾、个人护理、家用护理等重合赛道,交易双方全球及中国区域营收规模均足额触发申报门槛。金佰利提交申报材料后,市场监管总局已要求金佰利就其计划以490亿美元收购Kenvue的交易提供补充信息,是快消行业经营者集中申报的典型参考实例。   ...
× 扫一扫,关注微信公众号
铭盾MiNGDUN   www.mdlaw.cn                                               犀牛云提供企业云服务 
Copyright© 2008 - 2026 铭盾京ICP备14029762号-1                                                                                                                                隐私政策   免责声明       
X
1

QQ设置

3

SKYPE 设置

4

阿里旺旺设置

5

电话号码管理

6

二维码管理

展开