Language

A Chinese Data Privacy Law with Strong Influences from the EU


A Chinese Data Privacy Law with Strong Influences from the EU-China Releases the Draft on Its First Uniform Personal Information Protection Law


Authored by Yingying Zhu


The world has witnessed a torrent of lawmaking, regulatory design and enforcement activities regarding data privacy following the enactment of the General Data Protection Regulation (“GDPR”) [1] of the European Union in May 2018. At present, 132 out of 194 countries had put in place legislation to secure the protection of data and privacy. [2]

 

The inadequacy of personal information protection in China has raised widespread public concerns in this big data land with 904 million netizens,[3] vulnerable to data breaches and cyber frauds. In 2016, a professor at the prestigious Tsinghua University wired more than CNY17 million to a fraud, after she received a scam call from the fraud who knew every detail about the deal of a recent sale of her real property.[4] Incidents like this have led to nationwide discussions and provoked reflection among thinkers, legal experts and law makers. 

 

At present, data protection laws, regulations and specifications in China were scattered in sectional laws, regulations and non-binding guidelines, such as the Criminal Law and its Amendment VII, the Consumer Protection Law, the Cybersecurity Law, the Personal Information Security Specification, the Civil Code, etc.

 

On October 13, 2020, after years of brewing, China releases the long-awaited and much-welcomed draft on its first dedicated personal information protection law. The draft has been submitted to the standing committee of the China's top legislature-the National People’s Congress (“NPC”) for the first review and then posted for public comments on NPC’s official website. The comment period lasts until November 19, 2020.

 

Being the first comprehensive law that emulates the GDPR, the draft Personal Information Protection Law (“draft PIPL”) has shown strong GDPR influences as well as its unique Chinese characteristics.

Definition of “Personal Information” and “Sensitive Personal Information”

The types of information considered personal under the draft PIPL include various information recorded electronically or in other forms that is relating to an identified or identifiable natural person (“data subject”), excluding the anonymized information. The processing of personal information includes activities such as the collection, storage, use, handling, transmission, provision, and disclosure of personal information.

Here, “personal information” under the draft PIPL is similar in terms of definition to “personal data” used in the GDPR as well as in its predecessor, the EU Data Protection Directive,[5] because it includes data that relate both to an “identified” or “identifiable” individual. “Identifiable” means that an individual might not currently be identified but could be identified by combining various pieces of data.[6] For example, the name of a person (in particular, a none-celebrity), is often not identified to an individual, but sometimes can easily be linked to an individual with bits of other information, such as an address, a telephone number or a place of work.

 

On a risk-based approach, the draft PIPL defines sensitive personal information (“SPI”) as personal information that once leaked or illegally used may lead to discriminatory treatment or could seriously endanger the safety of persons or property, including information such as one’s race, ethnicity, religious beliefs, personal biological characteristics, medical health, financial accounts, personal whereabouts and so forth.[7] Only personal information processors with a specific purpose and sufficient necessity may process SPI. The draft also requires that the individuals' “independent consent” shall be obtained where processing SPI is to be based on individuals' consent and individuals shall also be informed of the necessity of processing SPI and the impact on them.

 

The draft PIPL, for the first time in China’s privacy protection legislation, specifically defines SPI. As improper disclosures of SPI can cause greater harm and damage to the image, reputation or security of an individual, it is of significant importance to ensure that SPI could be specifically defined and appropriately protected.

 

One problem with the draft PIPL’s definition of SPI, however, is that it seems to ignore a certain type of SPI -a person’s private or secret life that in many defamation cases has been the subject of public online shaming. If an individual’s personal private life (usually unpleasant, eccentric or immoral) was posted on some popular online platforms due to mishandling of that individual’s personal information, and the news goes viral, the victim in many cases would suffer spiritually from attacks of cyber-mobs and internet violence. The suffering can be nothing financial but only emotional. Here, the risk-based definition of SPI in the draft PIPL only covers risks in the form of “discriminatory treatment” or “endangering safety of persons or property”, but leaving out the harm caused to personal reputation and psychological health, which, in many cases, could be the only resulted harm in violation of SPI. The draft PIPL obviously did not give enough consideration to such type of possible harm in its current definition of SPI.

 

Under the GDPR, processing of personal data of a sensitive nature shall be prohibited, unless some stricter preconditions could be met. Such data are classified under the label of SPI[8] and sensitive data are clearly listed by its definition.

 

Though differ in defining, the draft PIPL converges with the GDPR in that both recognize SPI is belonging to a specific category of information that must be treated with extra safeguarding.

Rights of Individuals

Under the draft PIPL, individuals enjoy the right to know and make decisions about the processing of their personal information, and have the right to limit or refuse the processing of their personal information by others, except otherwise provided by laws and administrative regulations

Specifically, individuals enjoy the following rights:

1)    Right to access:[9] the data subject may consult or reproduce his personal information from the information processor;

2)    Right to rectification: upon discovery of any error in the information, the data subject has the right to raise an objection and to request to have a timely correction;

3)    Right to be forgotten: if the handling of personal information is in violation of law, or any prior agreement, or the purposes of processing have been realized, or an individual has withdrawn the consent, the data subject has the right to request a timely erasure. If, however, the retention period prescribed by law has not been completed, or deletion of personal information is technically difficult to achieve, the personal information processor shall stop the processing;

4)    Right to be informed: individuals have the right to be informed about rules concerning the processing of their personal information;

5)    Right to refuse automated decision-making: where an individual believes that automated decision-making has a significant impact on one’s rights and interests, one has the right to request an explanation from the personal information processor and has the right to refuse automated individual decision-making.

Under the draft PIPL, individuals have a broader scope of rights than previous laws in the same sector and it brings China’s protection on privacy even closer to the GDPR standards.[10] It is however interesting to note the “right to data portability”[11] under the GDPR has not been transplanted to its Chinese counterpart. As the right to data portability does not apply to genuinely anonymous data but only to pseudonymous data that can clearly be linked back to a data subject, maybe the notions of cyber- sovereignty and network security with a distinguishable Chinese feature could account for the missing of such right in the Chinese context..

Principles and Conditions for Data Processing

Under the draft PIPL, the general principles for data collection are: data shall be collected lawfully and justifiably, openly and transparently, accurately and kept up-to-date and data collection shall have clear and reasonable purposes and be limited to the minimum scope to achieve such purposes of processing. The data processing activities shall meet the following conditions:

(1) With the consent of the individual;

 

(2) It is necessary for entering into or performing a contract to which the individual is a party;

 

(3) It is necessary for performing of legally-binding duties or obligations;

 

(4) It is necessary to respond to public health incidents or to protect natural persons' security in their lives, health, and property under an emergency;

 

(5) It is within a reasonable range in order to carry out acts such as news reporting and public opinion overseeing in the public interest; or

 

Other circumstances warranted by laws or administrative regulations.

 

The GDPR provides six legal bases for processing personal data, namely: consent; contract; legal obligation; vital interests; public task; or legitimate interests pursued by the controller or by a third party.[12] The draft PIPL sets out the above five specific legal bases for processing personal data, which are comparable to the first five legal bases of the GDPR while chipping away the last one concerning “legitimate interests pursued by the controller or by a third party”, on the possible account that it would have the potential of giving too much discretion to the information processor and therefore dilute the value of all the other legal bases.

 

Under the draft PIPL, consent, albeit the most well-known one, is just one of the legal bases a business can rely on to justify the proceeding of individuals’ personal data. Furthermore, for consent to be valid, it must be freely-given, unambiguous and explicit, informed and withdrawable. Consent is not freely-given if individuals have no other meaningful options but to give out their consent. This means businesses shall not create an opt-in-or-leave-it situation when seeking people’s consent. Individuals need to maintain the ability to decline and shall be free from discrimination when they opt out. The draft PIPL also specifies that if there are changes to the purposes or methods for processing information, or to the type of personal information to be processed, the individual's consent shall be re-obtained.

 

Extraterritorial Applicability

 

The GDPR has an extraterritorial scope, because it may apply to businesses established outside the European Union when they offer goods or services to data subjects in the European Union or monitor their behavior when it takes place in the European Union.[13]

 

Modeling on the GDPR’s approach towards extraterritorial application, Article 3 of the draft PIPL expands the law’s territorial scope to data processing activities outside China. Any data processing activities that process personal data within P.R. China, if meeting any of the following conditions, will fall under the territorial scope of the Chinese data protection law:

 

(1) for the purpose of providing products or services to natural persons within the territory;

 

(2) to analyze and evaluate the conduct of natural persons in the territory; or

 

(3) other circumstances provided for by laws and administrative regulations.

 

If this clause remains intact in the final legal text, it means that the Chinese privacy rules now can also apply to data processing activities outside China. The consequence of this expansion is that non-Chinese data controllers and processors must comply with the Chinese data protection obligations when processing data on individuals in China for the above-listed purposes.

Obligations of Personal Information Processor

Under the draft PIPL, the personal information processor, the one who collects, stores, uses, handles, transmits, provides, and discloses personal information, shall have the following obligations:

(1) take necessary measures to ensure the legal compliance of personal information processing activities and prevent unauthorized access, disclosure or theft, tampering, and deletion of personal information;

(2) while processing personal information at certain volume, shall designate a person in charge to be responsible for overseeing personal information processing activities and any protection measures taken;

(3) if processing Chinese individuals’ personal information outside China as provided in Article 3 of the Law shall establish a point of contact within China;

(4) shall conduct periodic audits and risk assessments in advance for certain categories of personal information processing activities;

(5) where there is incident of personal information leakage, shall immediately take remedial measures and notify the supervisory authorities.

Once a data breach occurs, the GDPR requires data controllers to notify supervisory authorities of a security breach within 72 hours after it has been aware of it.[14] Furthermore, when the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.[15]

In comparison, the draft PIPL is not specific about the timeframe for notification to the supervisory authorities and where personal information processors take measures that can effectively avoid the harm caused by the information leakage, the personal information processors are allowed to not notify the individuals.

Liabilities and Penalties

Violations of the draft PIPL may be subject to a fine of up to CNY1 million (about EUR 0.128 million); the directly responsible management and other directly responsible person may be subject to a fine of between CNY10,000 (about EUR1,283) to CNY100,000 (about EUR12,831). Serious violations of the draft PIPL can be fined up to CNY 50 million (about EUR 6.4 million) or up to 5% of the preceding year's turnover. Where there is an illegal act of data processing activities, it is to be recorded in the business’ credit files with a public announcement posted.

In comparison, under GDPR, the less severe infringements could result in a fine of up to EUR10 million, or 2% of the business’ global annual revenue in the preceding financial year, whichever is higher. For more severe infringements, GDPR sets a maximum fine of EUR 20 million or 4% of annual turnover, whichever is higher.[16]

In an age of constant, complex and sometimes intrusive technological innovation, the high penalties on noncompliance aim to have a deterrent effect on rule-breakers who are mishandling people’s data or using people’s data without adequate measures in place to safeguard them.

Conclusion

The draft PIPL, being the first dedicated law to data privacy protection in China, thus forming a unified force of enforcement, marks a milestone in the country data privacy legislation. The law shows a broader scope of application than the previous sectional laws and regulations and levels up the country’s protection on data privacy closer to the GDPR standards, a.k.a., the global standards, given the large number of countries around the world that have adopted the GDPR model. While highly converging with the EU rules, the draft PIPL demonstrates a unique Chinese characteristics thus showing a strong Chinese voice with a subtle EU accent.

The laws and regulations on data privacy are constantly evolving in China with changes still in the pipeline. We are here to help if you have any problems, issues, concerns regarding data privacy protection inside or outside China.

 



[1] The General Data Protection Regulation (EU) 2016/679.

[2] See https://unctad.org/page/data-protection-and-privacy-legislation-worldwide.

[3]See https://www.thehindu.com/news/international/chinas-netizen-population-hits-record-904-million-report/article31451143.ece.

[4] See http://www.techweb.com.cn/tele/2017-02-20/2489197.shtml.

[5] The Data Protection Directive, officially Directive 95/46/EC on the protection of individuals with regard to the processing of personal data and on the free movement of such data.

[6] Paul M. Schwartz & Daniel J. Solove, Reconciling Personal Information in the U.S. and EU, 102 Cal. L. Rev. 886 (2014).

[7] While an official translation is not yet available, the author has referenced the source at https://www.chinalawtranslate.com/en/personal-information-protection-draft for the translation of the texts of the draft PIPL.

[8] Definition of “sensitive personal information” under the GDPR: data consisting of racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data, data concerning health or data concerning a natural person's sex life or sexual orientation.

[9] The subtitles are used in this article for convenience only; they are not part of the draft PIPL.

[10] Rights for individuals under the GDPR, see https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/individual-rights.

[11] The right to data portability allows individuals to obtain and reuse their personal data for their own purposes across different services. It allows them to move, copy or transfer personal data easily from one IT environment to another in a safe and secure way, without affecting its usability. See https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-data-portability/.

[12] GDPR, Article 6(1).

[13] GDPR, Article 3(2).

[14] GDPR, Article 33(1).

[15] GDPR, Article 34(1).

[16] See https://www.itgovernance.co.uk/dpa-and-gdpr-penalties.

  • 相关资讯 More
  • 点击次数: 1000002
    2026 - 04 - 10
    作者:金涟伊一、官网的定义与功能定位“官网”是“官方网站”的简称,在中国法律语境下,通常指由特定组织、企业或政府机构正式设立和运营的网站,使用经合法注册的域名(如.cn、.com.cn等)。官网应当完成ICP备案(非经营性)或取得ICP许可证(经营性),代表该主体的正式立场,具有公示和公信力。在实践中,政府官网使用.gov.cn域名,需经严格审批,且仅限政府机构注册。企业自称“官网”则主要受《反不正当竞争法》《广告法》约束,不得进行虚假宣传。本文主要聚焦于企业官网,即由企业自行或委托他人创建、注册和运营,代表企业意志、面向社会公众、展示企业信息的网站。企业官网通常包含首页、关于我们、产品(服务)中心、技术服务、新闻中心、联系我们等板块。它作为数字时代的核心商业基础设施,承载着多维度的功能。有些官网构成运营场所,用于展示产品/服务信息、技术参数、应用场景,发布促销活动、案例故事,有些官网还具有交易功能,如在线支付、订单管理。对于中小企业而言,官网更重要的功能是输出统一的视觉识别系统、品牌故事、企业价值观,进而为企业获得消费者信任。二、官网展示行为的法律定性如前所述,官网承载着对外展示企业形象、品牌美誉的功能,因此大部分官网都会展示企业相关产品。那么,企业在官网上发布自家产品及品牌的行为是否构成广告宣传,是否构成商标法意义上的使用?从广告法的角度来说,根据《广告法》第二条,商品经营者或者服务提供者通过一定媒介和形式直接或者间接地介绍自己所推销的商品或者服务的商业广告活动,适用本法。企业作为产品的生产者或者销售者,在自己所能控制的互联网空间中向不特定的人群介绍自己的产品或服务,符合广告法的定义,属于应当被广告法所规制的行为,即广告宣传行为。如果未介绍产品或服务,仅是单纯发布自身名称(姓名)、简称、商标、标识、经营范围、成立时间、发展历程、企业简介等信息,且未直接或者间接推销商品或...
  • 点击次数: 1000004
    2026 - 04 - 03
    作者:张嘉畅3月29日,歌手李荣浩在社交媒体上公开指出歌手单依纯在其演唱会“纯妹妹2.0”上演唱了《李白》一作,侵犯了自己的著作权。3月30日凌晨,单依纯长文回复致歉,并承诺不再演唱《李白》。此争议引发了大众的广泛讨论,大部分网友支持原创者维权,也有小部分网友支持新版本翻唱,也有一些过往的类似案件被再度提及。在本文中,笔者将对不同的观点从法律角度进行解读。 一、争议观点 著作权,又称版权,是作品的作者依法享有的权利。根据《著作权法》第十条,著作权包括“发表权”、“署名权”、“修改权”、“保护作品完整权”……等13项权利。在本次争议当中,网友提出了以下几种观点: (1)该行为侵犯了修改权 修改权,即修改,或者授权他人修改作品的权利。修改权属于人身权,只有作者本人或受到授权的人可以对作品进行修改。网络上有部分观点认为对歌曲进行再加工侵犯了作者的修改权。然而在本案中,因为《李白》一作已经发表,且翻唱并未对《李白》作品本身进行修改,不影响原作的呈现方式,所以笔者认为本案不涉及到侵犯修改权。 (2)改编作品具有独立著作权 其实,单依纯并非首次演唱《李白》。早在去年的《歌手2025》节目上,单依纯团队就已对《李白》一歌进行了改编和翻唱。有小部分网友依据《著作权法》第十三条提出观点,认为单依纯团队对改编后的《李白》享有著作权,因此其演唱行为并无不当。但这一说法在法律上并非没有争议。首先,对于公众而言,目前并不清楚《歌手 2025》节目录制时,双方就《李白》一歌的改编权具体是如何约定的,权利基础尚不明确。其次,从司法实践来看,法院在类似案件中已形成较为一致的裁判观点:改编后的作品能否产生独立的著作权,核心取决于改编过程中新增的创作部分是否具备独创性。具体到本案,新增的念白与编曲是否达到独创性标准、能否构成新的作品,仍需要结合行业标...
  • 点击次数: 10000002
    2026 - 03 - 13
    作者:杨秀芸2021年,《刑法修正案(十一)》将“服务商标”作为假冒注册商标罪的对象之一,赋予了其和“商品商标”同等的受保护地位。这一立法完善,为规制新型服务领域商标侵权行为提供了明确法律依据。本文评析的黃某等人假冒注册商标罪案,正是这一立法背景下,司法实践打击“傍名牌”式服务侵权的典型案例。 一、基本案情 1、案件背景与事实2020至2023年3月,被告人黄某先后经营多家公司,雇佣被告人王某,未经注册商标所有人许可,在上海、沈阳、武汉等地开展带有“DIOR”注册商标的儿童时装表演活动,以此收取报名费用。 2、涉案金额与权利基础经审计查明:1、被告人黄某:共组织7场带有“DIOR”注册商标的时装表演活动,违法所得共计人民币80余万元;2、被告人王某:参与组织其中4场时装表演活动,个人违法所得50余万元。3、权利基础:“DIOR”商标在我国被核定使用的服务类别包括第41类“组织和安排文化、艺术、教育和体育讨论会、报告会或代表大会、时装表演”等,注册号为G1102827,注册有效期经续展至2031年11月18日。 3、裁判结果一审判决(上海市浦东新区人民法院,案号:(2025)沪0115刑初857号):被告人黄某犯假冒注册商标罪,判处有期徒刑三年六个月,并处罚金人民币160万元;被告人王某犯假冒注册商标罪,判处有期徒刑一年,缓刑一年,并处罚金人民币5万元。宣判后,被告人黄某提出上诉。 二审裁定(上海市第三中级人民法院,案号:(2025)沪03刑终52号):驳回上诉,维持原判。 二、争议焦点与法律分析本案审理过程中,法院重点厘清了服务商标侵权的刑法适用边界、量刑标准及共同犯罪责任划分三个核心问题。 (一)服务商标侵权的刑法适用被告人黄某辩称,其使用“DIOR”标识,系为了指示服务中使用的“DIOR”服装,属合理...
  • 点击次数: 1000016
    2026 - 01 - 23
    作者:张琳公司在出现生产经营严重困难、不可抗力等情况时可能会选择停工停产一段时间。根据我国相关法律法规,非因劳动者原因造成单位停工、停产在一个工资支付周期内的,用人单位应按劳动合同规定的标准支付劳动者工资。超过一个工资支付周期的,若劳动者提供了正常劳动,则支付给劳动者的劳动报酬不得低于当地的最低工资标准;若劳动者没有提供正常劳动,应按国家有关规定办理。北京市还规定:用人单位停工停产超过一个工资支付周期,用人单位没有安排劳动者工作的,应当按照不低于北京市最低工资标准的70%支付劳动者基本生活费。这些规定对于公司在停工停产期间如何发放员工工资问题给出了明确的指导和要求。但是,在实际用工过程中,有些公司却随意以停工停产为由安排员工待岗,以期达到给员工少发工资、逼迫员工主动辞职、不支付或少支付经济补偿金、赔偿金的目的。公司的这种做法有可能损害员工的利益;如果得不到法律的支持,还可能最终损害公司自身的利益。因此,本文将通过二个案例就公司以停工停产为由安排员工待岗、给员工少发工资是否合法、能否得到法律支持的问题展开分析探讨。一、案例简介案例一:汤某与某商业公司劳动争议案件(参见北京市丰台区人民法院(2024)京0106民初30351号民事判决书、北京市第二中级人民法院(2025)京02民终4138号民事判决书)  汤某于2004年入职某商业公司,双方签订了无固定期限劳动合同。某商业公司于2023年6月28日向汤某发放《待岗通知书》,内容为由于公司业务量急剧下降,公司从2023年6月30日起安排汤某停工待岗直至公司通知返岗之日,第一个工资支付周期公司将按劳动合同规定的标准支付工资,超出第一个工资支付周期的,公司将按当地最低工资的70%支付待岗工资。汤某回函表示不接受待岗安排,并坚持到岗打卡上班。后汤某提起劳动仲裁,要求某商业公司支付2023年7月1日至2023年10月...
× 扫一扫,关注微信公众号
铭盾MiNGDUN   www.mdlaw.cn                                               犀牛云提供企业云服务 
Copyright© 2008 - 2026 铭盾京ICP备14029762号-1                                                                                                                                隐私政策   免责声明       
X
1

QQ设置

3

SKYPE 设置

4

阿里旺旺设置

5

电话号码管理

6

二维码管理

展开