China's data regime, mapped for outbound business.
China's data laws work as a stack: the Personal Information Protection Law (PIPL) governs personal information, the Data Security Law (DSL) classifies data, and the Cybersecurity Law (CSL) underpins security and localisation. Together they shape consent, classification and cross-border transfer.
How the stack fits together
PIPL
The Personal Information Protection Law, China's comprehensive personal information statute, close in ambition to the GDPR.
DSL
The Data Security Law classifies data by importance and imposes graded security and handling duties.
CSL
The Cybersecurity Law underpins network security, critical information infrastructure and localisation.
Consent, and separate consent
Handling generally requires consent that is voluntary, explicit and fully informed.
A distinct, specific consent is required for sensitive personal information, cross-border transfer, and disclosure to third parties.
Handling personal information of minors under 14 requires guardian consent and a dedicated set of rules.
Conduct a personal information protection impact assessment for sensitive handling, transfers and automated decision-making.