PIPL Article 57 — Immediate notification duty and required content
The Personal Information Protection Law of the People's Republic of China (PIPL, effective November 1, 2021) imposes a dual notification duty on personal information processors when a breach occurs or may occur. Article 57 requires processors to immediately take remedial measures and notify both (1) the departments with personal information protection duties and (2) the relevant individuals.
## Triggering events
A notifiable breach under Article 57 encompasses three scenarios: leakage, tampering, or loss of personal information. The statute covers both actual incidents and potential incidents—the duty arises when such events "occur or may occur," establishing a precautionary threshold that captures risks before confirmation of actual harm.
## Notification to supervisory authorities
Article 57 requires notification to "the departments with personal information protection duties" but does not name a specific regulator or prescribe a reporting mechanism. The Cyberspace Administration of China (CAC) is designated elsewhere in PIPL as the national-level authority responsible for overall personal information protection, though Article 57 itself is silent on which office receives breach reports, what form the report must take, and whether sectoral regulators (telecommunications, finance, health) share concurrent jurisdiction.
## Timing
PIPL requires that processors act "immediately" (立即) upon discovering a breach or potential breach. Article 57 sets no explicit hour- or day-based deadline, in contrast to regimes that impose fixed clocks (such as the GDPR's 72-hour supervisory-authority notification rule under Article 33 or various U.S. state laws). The statute does not define "immediately," leaving the standard to enforcement practice and implementing regulations.
## Notification to individuals
Processors must notify affected individuals of the breach, but Article 57 is silent on the timing, method, and language of such notification. The statute does not specify whether notification must be direct (email, SMS, postal mail) or may be made by substitute means (website posting, media notice), nor does it address translation requirements for cross-border processors.
Notification to individuals may be waived if the processor's remedial measures "can effectively prevent the information leakage, unauthorized alteration or loss from causing harm." This is an outcome-based exemption tied to the processor's ability to eliminate risk. However, even when individual notification is waived, notification to the supervisory authority remains mandatory. Article 57 further provides that the authority may order the processor to notify individuals if the authority determines that harm may result, overriding the processor's assessment.
## Required content — notification to individuals
When notifying individuals, Article 57 mandates disclosure of:
- The categories of personal information that were or may be leaked, tampered with, or lost, and the causes and possible harm of the incident;
- Remedial measures taken by the personal information processor and measures individuals can take to mitigate harm; and
- Contact information of the personal information processor.
Article 57 does not specify the required content for notifications to supervisory authorities, nor does it address recordkeeping obligations or the consequence of late, incomplete, or omitted notifications.
## What Article 57 does not address
The statute is silent on: deadlines for notification (other than "immediately"); the format, channel, or language of notifications; whether processors must maintain logs of breaches or notifications; the interplay with China's Cybersecurity Law (CSL) and Data Security Law (DSL) breach-reporting requirements; enforcement penalties for non-compliance; and whether affected individuals possess a statutory cause of action for failure to notify. PIPL contains separate enforcement and civil-liability provisions in Articles 66–70, but Article 57 itself does not specify sanctions.
Source: Personal Information Protection Law of the People's Republic of China, Art. 57
Enforcement penalties — PIPL Article 66 administrative fines and civil liability for notification failures
The Personal Information Protection Law establishes a two-tier administrative penalty structure for violations of its breach-notification obligations (Article 57), including late notification, incomplete notification, or complete failure to notify. Article 66 governs the administrative enforcement regime; Article 69 governs civil liability. Criminal exposure for severe breaches exists under separate statutes (discussed below), though PIPL itself does not define the threshold for prosecution.
## Two-tier administrative penalties under Article 66
PIPL Article 66 divides violations into minor and serious categories, with separate penalty caps for each. Breach-notification failures under Article 57 fall under this framework. The statute does not define "serious" (严重情形, yánzhòng qíngxíng), leaving the determination to the enforcing authority—typically the Cyberspace Administration of China (CAC) at the national level, or provincial-level CAC branches and sector-specific regulators (telecommunications, finance, health) within their respective domains.
Minor violations — Article 66, first paragraph
For violations that do not rise to the level of "serious circumstances," the departments with personal information protection duties may:
- Order correction, give a warning, and confiscate illegal gains;
- Order suspension or termination of applications that illegally process personal information;
- If the violator refuses to make corrections, impose a fine of not more than RMB 1 million on the entity; and
- Impose fines of RMB 10,000 to RMB 100,000 on each of the directly liable persons in charge and other directly liable personnel.
The "refuses to make corrections" language means that penalties escalate if the processor ignores the initial correction order. A processor that promptly remediates after the order may avoid the fine, though the statute does not specify a grace period.
Serious violations — Article 66, second paragraph
When "the circumstances are serious," the departments with personal information protection duties at or above the provincial level may:
- Order correction, confiscate illegal gains, and impose a fine of not more than RMB 50 million or not more than 5 percent of the previous year's turnover, whichever is higher;
- Order suspension of relevant businesses, or suspension of all business operations for an overhaul;
- Notify the competent authorities to revoke relevant business permits or licenses;
- Impose fines of not less than RMB 100,000 but not more than RMB 1 million on each of the directly liable persons in charge and other directly liable personnel; and
- Prohibit the abovementioned persons from serving as directors, supervisors, senior managers, or the persons in charge of relevant companies within a specific period of time.
The 5 percent turnover calculation is based on the previous year's turnover (上一年度营业额, shàng yī niándù yíngyè'é), not global revenue, though PIPL does not clarify whether "turnover" means China operations only or worldwide. CAC guidance and implementing regulations have not resolved this ambiguity as of May 2026.
What constitutes "serious circumstances"
PIPL does not define the threshold. The Didi Global enforcement decision (July 2022) provides the only major public precedent: CAC fined Didi RMB 8.026 billion (approximately USD 1.2 billion, or 4 percent of its 2020 China revenue) and fined the CEO and president RMB 1 million each for multiple PIPL violations, including failures to conduct proper data-security assessments and illegal cross-border transfers. The decision cited "serious violations" but did not publish a detailed threshold analysis. CAC has not issued regulations defining "serious" for breach-notification failures specifically, though large-scale breaches (affecting millions of records), refusal to cooperate with authorities, cross-border data exfiltration, and breaches involving sensitive personal information (Article 28 categories: biometrics, health, finance, precise location, minors' data) are widely understood to elevate severity.
## Civil liability — Article 69 and the burden-shifting rule
Article 69 creates a private cause of action with a reversed burden of proof: "Where the right and interests of personal information are infringed upon due to personal information processing and cause damages, and the personal information processor cannot prove that it is not at fault, it shall bear the tort liability for damages."
This means that once a data subject demonstrates harm from a breach (identity theft, financial loss, emotional distress), the processor must prove it exercised due care in meeting Article 57 notification duties and implementing Article 51 security measures. Failure to notify, late notification, or incomplete notification under Article 57 is powerful evidence of fault. Courts may award:
- Actual losses suffered by the individual (out-of-pocket costs, lost wages, credit-monitoring fees);
- Alternatively, the processor's illegal gains from the data processing that led to the breach; or
- If neither is ascertainable, damages at the court's discretion.
There is no statutory cap on civil damages under PIPL. Class actions are not recognized under PRC civil procedure, but public-interest litigation is authorized: Article 70 permits people's procuratorates (state prosecutors), statutorily designated consumer organizations, and organizations designated by CAC to bring representative actions on behalf of individuals whose rights have been infringed.
## Criminal liability under separate statutes
PIPL does not itself criminalize conduct, but Article 71 cross-references the Criminal Law of the People's Republic of China. The Ninth Amendment to the Criminal Law (effective November 1, 2015) added Article 253-1, which criminalizes:
- Selling or providing personal information to others in violation of state regulations, where the circumstances are serious, punishable by fixed-term imprisonment of up to three years or criminal detention, plus a fine or forfeiture; and
- Theft or other illegal acquisition of personal information, with the same penalties.
"Serious circumstances" under Article 253-1 has been interpreted by the Supreme People's Court and Supreme People's Procuratorate in a 2017 judicial interpretation to include (among other thresholds): illegal acquisition or sale of 50 or more records of sensitive personal information (financial accounts, communications, health, biometrics), or 500 or more records of general personal information. Breach-notification failures themselves are not criminalized, but a processor that covers up a breach to avoid regulatory scrutiny or that misappropriates breach data may face prosecution under Article 253-1 or other fraud / computer-crime provisions.
## Supervisory authority structure
PIPL Article 60 designates the Cyberspace Administration of China (CAC) as the national coordinator for personal information protection. Enforcement authority is shared with:
- Relevant departments under the State Council (Ministry of Public Security, State Administration for Market Regulation, Ministry of Industry and Information Technology) within their respective sectors;
- Relevant departments under local people's governments at county level and above, as determined by law and regulation.
In practice, breach reports under Article 57 are submitted to the CAC's municipal- or provincial-level office with jurisdiction over the processor's registered address, or to sector-specific regulators (e.g., China Banking and Insurance Regulatory Commission for financial institutions). Public security organs (police) handle investigations involving criminal suspicion, including ransomware and extortion-related breaches.
## Other enforcement consequences
Beyond fines and liability, PIPL violations are recorded in the processor's credit file (社会信用体系, shèhuì xìnyòng tǐxì), China's social-credit system for enterprises. Negative credit records can result in:
- Disqualification from government procurement and public tenders;
- Denial of business licenses for new ventures;
- Increased scrutiny in cross-border data-transfer security assessments (Articles 38–40); and
- Blacklisting for foreign processors under Article 42, which authorizes countermeasures against overseas entities that harm the rights of Chinese data subjects or endanger China's national security.
Article 42 countermeasures may include a ban on processing personal information of individuals in China, effectively barring the processor from the Chinese market.
Source: Personal Information Protection Law of the People's Republic of China, Arts. 66, 69, 70, 71
Recordkeeping and retention requirements — PIPL three-year rule for impact assessments and processing records
The Personal Information Protection Law (PIPL) imposes a mandatory three-year retention requirement for certain compliance documentation related to high-risk personal information processing activities, but does not expressly require processors to maintain a log or register of breach incidents or breach notifications. This creates a gap: processors must document and retain records of specified processing activities, yet PIPL Article 57's breach-notification duty carries no explicit recordkeeping obligation.
## Three-year retention — PIPL Articles 55 and 56
PIPL Article 55 requires personal information processors to conduct an impact assessment in advance and make a record of the course of the processing in five enumerated circumstances:
- Processing sensitive personal information (Article 28 categories: biometric identifiers, religious beliefs, specific identity, medical and health, financial accounts, individual location tracking, and personal information of minors under 14);
- Using personal information to conduct automated decision-making;
- Entrusting personal information processing to another party, providing personal information to another personal information processor, or publicly disclosing personal information;
- Providing personal information to parties outside the territory of the People's Republic of China (cross-border transfers); or
- Conducting other personal information processing activities which may have significant impacts on individuals.
Article 56 specifies the required content of the impact assessment — whether the purposes and means of processing are legitimate, justified, and necessary; the impact on personal information rights and interests and the level of risk; and whether protective measures are lawful, effective, and commensurate with the risk — and then mandates retention:
> "The report of the impact assessment on personal information protection and the processing record shall be retained for at least three years."
The three-year retention period runs from the date the PIPIA is completed and the processing activity is recorded, not from the date processing ceases. PIPL does not specify when the retention clock stops, nor does it require processors to delete the records after three years. Retention beyond three years is permissible and prudent for litigation-defense and audit purposes.
## What must be retained under Article 56?
Article 56 identifies two categories of documentation subject to the three-year rule:
- The impact assessment report itself — a written analysis covering the three mandatory elements in Article 56 (legitimacy, necessity, and proportionality of purposes and means; impact on individuals and degree of risk; and adequacy of security measures); and
- The processing record — documentation of "the course of the processing" for the high-risk activity triggering the Article 55 PIPIA requirement.
PIPL does not define "processing record" (处理情况记录, chǔlǐ qíngkuàng jìlù). The statute is silent on the format, medium (electronic vs. paper), level of detail, and specific data points that must be documented. Industry practice typically interprets "processing record" to include:
- The lawful basis for processing under Article 13 (consent, contract, legal obligation, vital interests, public task, legitimate interests, or publicly disclosed information);
- Categories of personal information processed;
- Identity of recipients (third-party processors, cross-border recipients, or the public in the case of disclosure);
- Security measures implemented;
- Retention periods; and
- Evidence of individual notification under Article 17 and, where required, consent under Articles 14–15.
However, because PIPL does not prescribe a mandatory format, processors have discretion to determine what documentation suffices to demonstrate compliance during a regulatory inspection under Article 64.
## Does the three-year rule apply to breach incidents?
No — at least not directly. PIPL Article 57 requires processors to "immediately take remedial measures and notify the departments with personal information protection duties and the relevant individuals" when "breach, tampering, or loss of personal information occurs or may occur," but Article 57 does not mandate that processors maintain a breach log or retain copies of breach notifications. The three-year retention obligation in Article 56 applies only to PIPIA reports and processing records for the five categories of high-risk activities enumerated in Article 55.
That said, a breach may trigger a new Article 55 PIPIA requirement if the processor's post-breach response involves one of the listed activities. For example:
- If the processor shares breach data with a forensic vendor or outside counsel, that constitutes "providing personal information to another personal information processor" under Article 55(3), triggering a PIPIA duty. The PIPIA for that data-sharing arrangement — and the processing record documenting the sharing — must be retained for three years.
- If the processor subsequently transfers breach-related data to an overseas forensic firm or parent company, that is a cross-border transfer under Article 55(4), requiring a separate PIPIA and three-year retention.
- If the processor publicly discloses the breach (for example, by issuing a press release naming affected individuals or categories of individuals), that constitutes "publicly disclosing personal information" under Article 55(3), again triggering the PIPIA and retention requirements.
In each case, the three-year clock runs from the date of the post-breach PIPIA, not the date of the original breach. Processors that conduct multiple post-breach processing activities (sharing with forensic vendors, transferring to overseas counsel, and publicly disclosing the incident) must complete a separate PIPIA for each activity and retain each PIPIA and processing record for three years.
## Inspection authority and practical implications
PIPL Article 64 grants the "departments with personal information protection duties" — the Cyberspace Administration of China (CAC) at the national level, provincial-level CAC offices, and sector-specific regulators (banking, telecommunications, health) — the authority to:
- Question relevant parties and investigate circumstances related to personal information processing activities;
- Consult and duplicate the parties' contracts, records, account books and other relevant materials related to personal information processing activities;
- Conduct on-site inspections; and
- Inspect, seal, or seize equipment and articles related to illegal processing activities.
A processor that cannot produce a required PIPIA report or processing record during an Article 64 inspection — because the documents were never created, were not retained for three years, or were destroyed — faces enforcement action under Article 66. Article 66 authorizes CAC to order correction, issue a warning, confiscate illegal gains, and, if the processor refuses to correct, impose fines of up to RMB 1 million on the entity and RMB 10,000 to RMB 100,000 on directly responsible individuals. For serious violations, the penalty escalates to RMB 50 million or 5 percent of the previous year's turnover (whichever is higher), plus fines of RMB 100,000 to RMB 1 million on responsible individuals, suspension of business operations, revocation of licenses, and potential disqualification from serving as directors or senior managers.
Although PIPL does not expressly state that failure to retain records for three years constitutes a "serious violation," CAC enforcement practice and analogous enforcement decisions under the Cybersecurity Law and Data Security Law suggest that systematic recordkeeping failures — particularly when they impede CAC's inspection authority or are coupled with substantive processing violations (unlawful cross-border transfers, inadequate security, failure to obtain consent) — elevate the violation to the serious tier.
## What PIPL does not address
PIPL is silent on:
- Whether processors must maintain a centralized breach register or incident log documenting all Article 57 breach notifications (as distinct from processing records for high-risk activities);
- The retention period for breach notifications sent to CAC or affected individuals under Article 57;
- The format or medium for retained PIPIA reports and processing records (electronic, paper, or both);
- Whether records must be stored in China (though Article 40 data-localization requirements for critical information infrastructure operators and large-volume processors imply that compliance records should be accessible to CAC within the territory);
- Whether processors may delete PIPIA reports and processing records after three years, or whether longer retention is required or recommended; and
- The consequences of partial compliance (for example, retaining the PIPIA report but not the processing record, or retaining records for two years instead of three).
Interaction with other recordkeeping obligations
PIPL's three-year retention rule for PIPIA reports and processing records is separate from and in addition to:
- Article 54's requirement that processors "regularly conduct compliance audits of their personal information processing activities with laws and administrative regulations" (PIPL does not specify whether audit reports must be retained or for how long);
- Recordkeeping obligations under the Cybersecurity Law (CSL), which requires network operators to monitor and record network operation status and cybersecurity incidents and retain network logs for specified periods (CSL Article 21 — the statute does not appear in the PIPL source cited here, and processors should consult CSL separately);
- Recordkeeping obligations under the Data Security Law (DSL), which requires data processors to establish data-security management systems and emergency response plans (DSL does not specify retention periods); and
- Sector-specific recordkeeping requirements imposed by the People's Bank of China (financial institutions), the China Banking and Insurance Regulatory Commission, the Ministry of Industry and Information Technology (telecommunications), and the National Health Commission.
Processors subject to multiple regimes should maintain a comprehensive records-retention schedule that identifies the longest applicable retention period for each category of documentation. In practice, most processors retain PIPIA reports, processing records, breach logs, and incident-response documentation for at least three years to satisfy PIPL Article 56, even when the underlying activity (such as a breach notification or forensic investigation) is not expressly listed in Article 55.
Source: Personal Information Protection Law of the People's Republic of China, Arts. 55–56, 64, 66
Harm-prevention exemption — when processors may skip individual notification under Article 57
PIPL Article 57 creates a narrow exemption from the duty to notify affected individuals when a breach occurs, conditioned on the processor's ability to demonstrate that remedial measures "can effectively avoid the harm" caused by the leakage, tampering, or loss of personal information. Even when this exemption applies, notification to the supervisory authority remains mandatory—the exemption relieves only the individual-notification leg of the dual notification duty.
The exemption is outcome-based: the processor must prove that its remedial measures eliminate the risk of harm, not merely reduce it. PIPL does not define "effectively avoid harm" (有效避免危害, yǒuxiào bìmiǎn wéihài), nor does it specify what remedial measures suffice, leaving the threshold to enforcement practice and to the supervisory authority's override judgment.
## Statutory language and structure
Article 57, second paragraph, provides:
> "Where the measures taken by the personal information processor can effectively prevent the information leakage, tampering or loss from causing harm, personal information processors need not notify individuals; where the departments with personal information protection duties consider that harm may be caused, they shall have the authority to require the personal information processor to notify individuals."
The exemption thus operates in three steps:
- The processor assesses whether its remedial measures can effectively prevent harm.
- If the processor concludes that harm is avoided, it may skip individual notification (but must still notify the authority under Article 57, first paragraph).
- The supervisory authority—typically the Cyberspace Administration of China (CAC) at the provincial level, or a sector-specific regulator (banking, telecommunications, health)—independently evaluates whether harm may result and may order the processor to notify individuals if it disagrees with the processor's assessment.
The authority's override power is discretionary and unbounded by PIPL's text. The statute does not require the authority to provide reasons, to adhere to a specific timeline, or to apply consistent criteria. A processor that invokes the exemption and later receives an order to notify individuals must comply; refusal exposes the processor to administrative penalties under Article 66 for failure to meet the Article 57 notification duty.
## What does "effectively avoid harm" mean?
PIPL provides no definition of harm thresholds, no list of acceptable remedial measures, and no safe harbor for specific technologies (encryption, pseudonymization, deletion). The statutory language is categorical—"can effectively avoid harm," not "reduce the likelihood of harm" or "mitigate harm to an acceptable level"—suggesting a total-elimination standard rather than a risk-balancing test.
In practice, the exemption is understood to apply when the processor can demonstrate that:
- The personal information was encrypted with keys that were not compromised, rendering the breached data unintelligible and unusable to an attacker;
- The personal information was pseudonymized or tokenized, such that the breached records cannot be linked back to identifiable individuals without access to a separate key or mapping table that was not breached;
- The breach involved test data, dummy records, or fully anonymized information that does not relate to identifiable natural persons (though such data may not qualify as "personal information" under PIPL Article 4 in the first place);
- The processor retrieved and destroyed all exfiltrated copies before the data could be accessed, disclosed, or used by any third party (a scenario limited to insider breaches or accidental transfers quickly detected and reversed); or
- The breach was a logical access control misconfiguration that exposed records to unauthorized internal users who are bound by confidentiality obligations, but no external disclosure or exfiltration occurred, and the misconfiguration was corrected immediately.
Conversely, the exemption is unlikely to apply when:
- The breach involved sensitive personal information (Article 28 categories: biometric identifiers, health, financial accounts, precise location, minors' data), where even encrypted data poses identity-theft, discrimination, or financial-fraud risk if decryption is possible;
- The breached data was in plaintext or weakly encrypted form;
- The processor cannot confirm whether data was exfiltrated (for example, a ransomware attack or server intrusion where logs are incomplete or have been deleted by the attacker);
- The processor's remedial measures are prospective only (patching the vulnerability, rotating credentials, segmenting the network) without addressing the already-exfiltrated or already-disclosed data;
- The breach involved cross-border exfiltration to a jurisdiction where Chinese data subjects have limited legal recourse; or
- The processor is a critical information infrastructure operator (CIIO) or processes personal information of one million or more individuals, thresholds that trigger heightened security obligations under PIPL Articles 51–54 and suggest that any breach creates systemic risk.
The burden of proof rests on the processor. Under PIPL Article 69's tort-liability regime, a data subject who suffers harm from a breach can sue the processor, and the processor must prove it was not at fault. A processor that invoked the Article 57 exemption and skipped individual notification—yet later faces a lawsuit from an affected individual—must demonstrate that its remedial measures did, in fact, eliminate the risk of harm. Failure to notify is itself evidence of fault unless the processor can prove the exemption applied.
## Supervisory authority override — timing and enforcement
Article 57 gives the departments with personal information protection duties the power to "require the personal information processor to notify individuals" when the authority "consider[s] that harm may be caused." The statute does not specify:
- When the authority must issue such an order (immediately upon receiving the processor's breach report, or after an investigation);
- How the authority notifies the processor (written order, email, oral instruction during an on-site inspection);
- What standard of proof the authority applies (must it affirmatively find that harm will occur, or is "may occur" sufficient?); or
- Whether the processor may appeal the order or seek administrative reconsideration under the Administrative Reconsideration Law.
In practice, processors should assume that the authority's override order is immediately enforceable. A processor that delays compliance while seeking reconsideration risks compounding liability: the original breach plus obstruction of a supervisory directive. Article 66, second paragraph, authorizes CAC to impose fines of up to RMB 50 million or 5 percent of the previous year's turnover (whichever is higher) for serious violations, to order suspension of business operations, to revoke licenses, and to ban responsible individuals from serving as directors or senior managers. Refusal to comply with a CAC order to notify individuals elevates the violation from a minor breach-notification lapse to defiance of regulatory authority, a factor CAC has cited in high-profile enforcement actions (including the Didi Global decision in July 2022, where refusal to cooperate with the security review was cited as an aggravating factor in the RMB 8.026 billion fine).
The authority may also publicly disclose that it ordered the processor to notify individuals, undermining any reputational benefit the processor hoped to achieve by invoking the exemption. PIPL Article 64 grants CAC the power to publicize violations and enforcement decisions.
## Interaction with the notification-to-authority duty
Even when a processor invokes the harm-prevention exemption and skips individual notification, Article 57's notification to the supervisory authority is non-waivable. The processor must still report the breach "immediately" to "the departments with personal information protection duties." The authority-notification must include:
- The categories of personal information that were or may have been leaked, tampered with, or lost;
- The causes and possible harm of the incident;
- Remedial measures taken by the processor and measures individuals can take to mitigate harm; and
- The processor's contact information.
(These are the same content requirements specified for individual notification, suggesting that the processor must prepare a full breach report even if it ultimately decides not to send it to individuals.)
The processor's breach report to CAC should affirmatively state that the processor is invoking the Article 57 exemption and should include evidence that remedial measures effectively prevent harm—technical documentation of encryption, logs showing retrieval and deletion of exfiltrated data, third-party forensic assessments, or expert opinions. A processor that files a bare-bones report claiming the exemption without supporting evidence invites immediate scrutiny and a high likelihood of an override order.
## No statutory deadline for the processor's exemption determination
PIPL does not specify when the processor must decide whether to invoke the exemption. Article 57 requires the processor to act "immediately" upon discovering the breach, but "immediately" modifies the duty to take remedial measures and notify, not the exemption determination itself. In theory, a processor could delay individual notification for hours or days while conducting a forensic investigation to assess whether remedial measures effectively prevent harm.
However, delaying the determination carries risk. If the processor ultimately concludes that the exemption does not apply and sends individual notifications 72 hours or a week after the breach, affected individuals may argue that the delay prevented them from taking timely protective action (freezing credit, changing passwords, monitoring accounts). Under Article 69's reversed-burden tort liability, the processor must then prove that the delay did not contribute to the harm—a difficult evidentiary showing.
Best practice: processors should make the exemption determination within the same "immediately" window that governs the notification duties—typically interpreted as within hours of breach discovery, not days. If the forensic investigation is ongoing and the processor cannot yet confirm that harm is avoided, the processor should notify individuals as a precaution rather than invoke the exemption prematurely.
## Comparison to other regimes
The Article 57 harm-prevention exemption is narrower than GDPR Article 34(3)(a), which allows controllers to skip individual notification when the breached data was subject to "appropriate technical and organizational protection measures … such as encryption" that render the data "unintelligible to any person who is not authorized to access it." GDPR's exemption is measure-based (if you encrypted, you may skip notification, subject to supervisory-authority discretion), whereas PIPL's exemption is outcome-based (you must prove that harm is avoided, regardless of the specific measure).
PIPL's structure is also distinct from U.S. state breach-notification laws that use a "risk of harm" trigger for the notification duty itself (California, Colorado, Connecticut, and others require notification only when the breach creates a "reasonable likelihood of harm"). PIPL presumes notification is required for any breach (Article 57 applies when leakage, tampering, or loss "occurs or may occur," a precautionary threshold), and the harm-prevention exemption operates as an affirmative defense the processor must prove, rather than a threshold the data subject must demonstrate.
The exemption most closely resembles Canada PIPEDA's "real risk of significant harm" (RROSH) test, though PIPEDA makes RROSH the trigger for notification (no notification required if no RROSH), whereas PIPL makes harm-avoidance an exemption after the duty is already triggered.
## What Article 57 does not address
The statute is silent on:
- What documentation the processor must retain to prove it invoked the exemption lawfully (PIPL Article 56 requires three-year retention of impact assessments and processing records for high-risk activities, but does not expressly require breach-exemption justification logs);
- Whether the processor must obtain an affirmative approval from CAC before invoking the exemption, or whether the processor may self-assess and CAC intervenes only if it disagrees (the statutory text suggests the latter—self-assessment subject to override—but some provincial CAC offices have issued guidance requiring advance consultation for large-scale breaches);
- Whether the exemption applies differently for sensitive personal information (Article 28) or for breaches affecting minors under 14 (all of whose data is deemed sensitive under Article 28);
- Whether the processor may invoke the exemption for part of the affected population (for example, notifying individuals whose plaintext data was breached, but not notifying individuals whose encrypted data was breached in the same incident); and
- Whether a processor that invokes the exemption must later notify individuals if new facts emerge (for example, the attacker subsequently decrypts the data or posts it for sale on a dark-web forum).
Industry practice is to treat the exemption as all-or-nothing for a given breach incident: either remedial measures prevent harm for all affected individuals, or they do not. Partial reliance on the exemption risks inconsistent messaging and regulatory confusion.
Source: Personal Information Protection Law of the People's Republic of China, Art. 57
What constitutes a notifiable breach — the three triggering events under PIPL Article 57
PIPL Article 57 creates a notification duty when "the breach, tampering, or loss of personal information occurs or may occur." These three triggering events—leakage (泄露, xièlòu), tampering (篡改, cuàngǎi), and loss (丢失, diūshī)—establish the threshold for mandatory reporting to the supervisory authority and, subject to the harm-prevention exemption, to affected individuals. The statute does not define any of the three terms, leaving processors to determine whether a given incident crosses the notification threshold based on the plain meaning of the statutory language, enforcement precedent, and analogous provisions in the Cybersecurity Law (CSL) and Data Security Law (DSL).
The duty is precautionary: notification is required when a breach "occurs or may occur" (发生或者可能发生, fāshēng huòzhě kěnéng fāshēng). This language captures both confirmed incidents (personal information was exfiltrated, modified, or destroyed) and potential incidents where the processor has reasonable grounds to suspect that such events have taken place but cannot yet confirm the scope or impact. The "may occur" trigger means that processors facing uncertainty—incomplete forensic findings, inconclusive logs, or evidence of intrusion without proof of data exfiltration—must err on the side of notification rather than wait for definitive confirmation.
## Leakage (泄露) — unauthorized disclosure or access
"Leakage" is understood in enforcement practice to encompass any unauthorized disclosure of personal information to a third party or unauthorized access by a person lacking lawful authority to view the data. The term covers:
- External exfiltration by an attacker (hacking, malware, ransomware, SQL injection, credential stuffing, or any other means by which personal information is copied, downloaded, or transmitted outside the processor's control);
- Accidental public disclosure, such as misconfigured cloud storage buckets, publicly accessible databases, inadvertent email attachments sent to wrong recipients, or documents posted to public websites;
- Insider theft or misuse, including employees, contractors, or service providers who access personal information beyond the scope of their authorization and copy, sell, or disclose it to third parties; and
- Unauthorized access by authorized users, for example, an employee who is authorized to process certain categories of personal information but accesses different categories (customer financial records vs. employee HR files) without legitimate business need.
The critical element is that the personal information left the processor's zone of control (either physically or through access by an unauthorized party), whether through deliberate action, negligence, or technical misconfiguration. A processor that discovers that personal information was accessible to the public internet for any period—even if server logs show no downloads—faces a difficult determination: the data "may" have been accessed, triggering the Article 57 notification duty unless the processor can affirmatively prove no access occurred (a high evidentiary bar when logs are incomplete or attackers erase traces).
Leakage does not require that the disclosed information be used, monetized, or published. The notification duty arises upon unauthorized disclosure or access, not upon subsequent harm. A processor that suffers a breach in which encrypted customer records are exfiltrated but never decrypted or sold still experienced "leakage" under Article 57, though it may invoke the harm-prevention exemption if encryption renders the data unintelligible (see /guides/china/breach-notification#harm-prevention-exemption-individual-notification).
## Tampering (篡改) — unauthorized alteration or modification
"Tampering" means unauthorized modification, alteration, or corruption of personal information, whether by an external attacker or an insider. This includes:
- Malicious modification of personal information to change names, contact details, financial account numbers, health records, or other data points (for example, an attacker changing the bank account number in a customer profile to redirect payments);
- Ransomware encryption that renders personal information inaccessible to the processor and affected individuals (the data is "altered" by encryption, even if the underlying plaintext is theoretically recoverable);
- Data corruption due to malware, software bugs, hardware failures, or operator error that changes personal information from its original, accurate state; and
- Integrity violations in which personal information is modified without authorization, even if the modification does not cause immediate harm (for example, changing a customer's email address to a different valid address, or altering timestamps in an audit log).
The notification duty under Article 57 does not turn on whether the modification was detected by the processor or the individuals. If a processor discovers through forensic analysis that personal information was altered six months ago, the "tampering … occurred," triggering the immediate notification duty upon discovery even if the modification went unnoticed by data subjects.
Tampering is conceptually distinct from leakage, but the two often co-occur. An attacker who exfiltrates a database (leakage) and then modifies records to cover tracks (tampering) triggers both prongs of Article 57. A processor must report both events and describe both in the notification to CAC and affected individuals.
## Loss (丢失) — destruction, deletion, or inability to access
"Loss" encompasses destruction, deletion, or any situation in which the processor can no longer access or retrieve personal information that it was processing. This includes:
- Permanent deletion by an attacker, insider, or through accidental operator action (DROP TABLE commands, mass file deletion, shredding of paper records);
- Hardware destruction or failure (server crashes, disk failures, fire, flood, or other disaster) that results in the irretrievable loss of personal information not backed up elsewhere;
- Ransomware attacks in which data is encrypted and the processor cannot decrypt it (loss of access, even if the data technically still exists in encrypted form);
- Theft of physical media (laptops, USB drives, backup tapes, paper files) containing personal information, where the processor no longer possesses the information and cannot confirm whether it was accessed or destroyed; and
- Loss of control over third-party-held data, for example, a cloud service provider that notifies the processor that backup storage was deleted or that the processor's account was terminated and data purged.
The statutory term "loss" (丢失) connotes irretrievability from the processor's perspective. If the processor maintains a backup copy of the personal information and can restore it, the incident may still constitute "leakage" (if unauthorized parties obtained access during the attack) or "tampering" (if the attacker modified the primary copy before it was lost), but not necessarily "loss" in the strict sense. However, restoration does not cure the notification duty: once leakage, tampering, or loss has occurred, the processor must notify, even if the processor subsequently recovers or reconstitutes the data.
## "Occurs or may occur" — the precautionary threshold
Article 57's use of the disjunctive "occurs or may occur" establishes a risk-based, precautionary trigger rather than a certainty standard. A processor must notify when:
- A breach has occurred and the processor has confirmed leakage, tampering, or loss through forensic investigation, logs, third-party reports, or other evidence; or
- A breach may have occurred—the processor has reasonable grounds to suspect leakage, tampering, or loss based on indicators of compromise (unusual network traffic, unauthorized login attempts, alerts from intrusion-detection systems, reports from security researchers, evidence of vulnerability exploitation) but cannot yet confirm the scope, the categories of personal information affected, or whether data was actually exfiltrated.
The "may occur" trigger is lower than a balance-of-probabilities threshold. If a processor detects an intrusion into a database containing personal information and cannot rule out exfiltration, the processor must treat the incident as a potential breach and notify immediately, rather than delaying notification until forensic analysis is complete. This is consistent with the statute's use of the term "immediately" (立即) to modify the remediation and notification duties—processors must act on incomplete information if the risk exists.
In practice, the "may occur" trigger captures:
- Vulnerability disclosures where a security researcher or third party reports that the processor's systems were exposed or compromised, but the processor has not yet confirmed whether personal information was accessed;
- Suspicious access patterns (mass downloads, unusual queries, login from unfamiliar IP addresses) that suggest unauthorized access but are not yet conclusive;
- Ransomware or malware detection before the processor has determined which systems and datasets were affected; and
- Notification from a third-party processor or service provider that it suffered a breach involving personal information the processor had entrusted to it (triggering both the third party's notification duty under Article 57 and the processor's duty to report the breach to CAC and affected individuals as the controller).
## What Article 57 does not explicitly cover
PIPL Article 57 does not define the following, leaving processors to interpret the scope of the notification duty in light of enforcement practice, analogous statutes (CSL, DSL), and supervisory authority guidance:
- Unauthorized access without exfiltration. If an attacker gains access to a system containing personal information but forensic analysis shows no data was copied, viewed, or modified, has "leakage" occurred? Industry practice treats access as presumptive leakage unless the processor can affirmatively demonstrate (through logs, access-control records, or other technical evidence) that the intruder did not view or copy the data. The burden is on the processor to prove no leakage, not on the authority to prove leakage occurred.
- Near-miss incidents. If a processor detects and blocks an intrusion attempt before the attacker accesses personal information, is notification required? The statutory language "may occur" arguably captures scenarios in which a breach was imminent but prevented, though enforcement practice has not clarified whether "may occur" means "could occur in the future if not remediated" (a forward-looking risk assessment) or "may have occurred in the past but cannot be confirmed" (a backward-looking uncertainty about whether the breach already happened). Processors typically do not notify for blocked intrusion attempts where no evidence suggests personal information was accessed, but this is a grey area.
- Metadata and derived data. If an attacker exfiltrates server logs, access records, IP addresses, or other metadata that can be linked to identifiable individuals but did not exfiltrate the personal information itself (names, contact details, account credentials), does that constitute "leakage of personal information"? The answer turns on whether the metadata qualifies as "personal information" under PIPL Article 4's definition ("information relating to an identified or identifiable natural person, recorded by electronic or other means, excluding information after anonymization"). Metadata that identifies individuals or can be combined with other information to identify individuals is personal information, and its leakage triggers Article 57.
- Breach of anonymized or pseudonymized data. If the breached data was anonymized under PIPL Article 4's standard (cannot be re-identified without disproportionate effort), it is not "personal information" and Article 57 does not apply. If the data was pseudonymized (identifiers replaced with tokens, but re-identification is possible with access to a key or mapping table), it remains personal information, and its leakage triggers the notification duty. Processors must assess whether the pseudonymization key or mapping table was also breached; if so, the data is readily re-identifiable and the breach is clearly notifiable. If the key was not breached and is stored separately with strong access controls, the processor may argue that the pseudonymized data alone does not constitute a breach of personal information, though this is contested.
- Cross-border breach origination. If a processor's overseas parent company or overseas service provider suffers a breach that affects personal information originally collected in China and subsequently transferred abroad under PIPL's cross-border transfer mechanisms (security assessment, standard contractual clauses, or personal information protection certification), the Chinese entity must still report the breach to CAC under Article 57. The statute applies to "personal information processors" (Article 4(5)), which includes entities processing personal information of individuals in China, and the breach of that data—wherever it is stored—triggers the notification duty. Recent enforcement cases (including the May 2025 breach involving a European luxury brand's Shanghai subsidiary, investigated by Shanghai police and publicized by China's National Network and Information Security Report Center) confirm that overseas breaches affecting China-origin personal information are notifiable under PIPL.
## Interaction with the Cybersecurity Law (CSL) and Data Security Law (DSL)
PIPL Article 57's breach-notification duty operates in parallel with, not in substitution of, analogous obligations under the Cybersecurity Law and Data Security Law. Processors subject to multiple regimes must comply with all applicable notification requirements.
CSL Article 21 requires network operators to adopt technical measures to monitor and record network operation status and cybersecurity incidents, and CSL Article 25 requires network operators to "formulate contingency plans for network security incidents" and report incidents to relevant authorities. The Cybersecurity Administration of China issued the National Cybersecurity Incident Reporting Management Measures (effective November 1, 2025), which establish a four-tier incident classification system and prescribe reporting timelines (one hour for Tier 1–3 incidents, which include breaches affecting large volumes of personal information or sensitive personal information). Processors experiencing a PIPL Article 57 breach must determine whether the incident also qualifies as a reportable cybersecurity incident under the 2025 Measures and, if so, must comply with the stricter (one-hour) reporting deadline.
DSL Article 29 requires data processors to establish a data-security incident emergency response plan and, "in the event of a data security incident," to immediately take disposal measures, notify users, and report to relevant authorities. DSL uses the term "data security incident" (数据安全事件, shùjù ānquán shìjiàn), which is broader than PIPL's personal-information-specific trigger but overlaps in cases where personal information is leaked, tampered with, or lost.
Processors should assume that a PIPL Article 57 breach involving personal information triggers parallel reporting duties under CSL and DSL, and that CAC (or the relevant provincial office) will expect a single integrated breach report covering all three statutes, rather than three separate filings. The National Cybersecurity Incident Reporting Management Measures (2025) establish a unified reporting platform (the 12387 hotline, website, and WeChat mini-program) that accepts reports for cybersecurity incidents, data security incidents, and personal information breaches.
## No quantitative threshold in PIPL Article 57
Unlike some breach-notification regimes that exempt small-scale incidents (for example, U.S. state laws that require notification only if a certain number of residents are affected), PIPL Article 57 contains no de minimis exception or volume threshold. The notification duty arises whenever leakage, tampering, or loss of personal information "occurs or may occur," regardless of the number of affected individuals. A processor that suffers a breach affecting one individual must notify CAC and that individual, subject only to the harm-prevention exemption.
In practice, the National Cybersecurity Incident Reporting Management Measures (2025) impose quantitative thresholds for tiered classification of cybersecurity incidents, which indirectly affect the urgency and escalation level of PIPL breach notifications:
- Tier 1 (Extremely Severe) incidents include breaches involving more than 10 million individuals' personal information;
- Tier 2 (Severe) incidents include breaches involving more than 1 million but fewer than 10 million individuals' personal information;
- Tier 3 (Significant) incidents include breaches involving more than 100,000 but fewer than 1 million individuals' personal information; and
- Tier 4 (General) incidents include breaches involving fewer than 100,000 individuals' personal information or breaches that do not meet Tier 1–3 thresholds.
These thresholds determine the reporting authority (national-level CAC for Tier 1–2, provincial-level CAC for Tier 3–4) and may influence penalty severity under PIPL Article 66, but they do not exempt small breaches from the Article 57 notification duty. A processor experiencing a 10-record breach must still notify CAC and the affected individuals immediately, though the incident will be classified as Tier 4 and handled at the municipal or provincial level rather than escalated to the national CAC.
## Practical implications: when to notify
A processor should notify under Article 57 immediately upon discovering any of the following:
- Confirmed exfiltration of personal information (logs show unauthorized access, download, or transmission; third-party security researcher reports that the processor's data is circulating on dark-web forums or paste sites);
- Unauthorized access to systems or databases containing personal information, even if exfiltration cannot be confirmed (intrusion-detection alerts, unusual login patterns, privilege escalation by unauthorized users);
- Ransomware or malware infection affecting systems that store or process personal information, even if the scope of encrypted or exfiltrated data is not yet known;
- Misconfiguration or exposure that made personal information accessible to the public internet, third parties, or unauthorized internal users for any period, even briefly;
- Theft or loss of physical media (laptops, phones, USB drives, backup tapes, paper files) containing personal information;
- Notification from a third-party processor (cloud provider, SaaS vendor, outsourced call center, marketing agency) that it suffered a breach involving personal information the processor had entrusted to it;
- Data modification or corruption detected through audit, reconciliation, or user complaints, where the cause is unknown or suspected to be malicious; or
- Inability to access or recover personal information due to system failure, deletion, destruction, or encryption.
When in doubt, notify. The penalties under PIPL Article 66 for failure to notify (up to RMB 50 million or 5 percent of the previous year's turnover for serious violations, plus personal fines and potential license revocation) far exceed the reputational and operational costs of over-notification. CAC has discretion to determine that a reported incident did not require notification, but a processor that fails to report an incident later deemed notifiable faces compounding liability: the underlying breach plus obstruction or non-cooperation.
Source: Personal Information Protection Law of the People's Republic of China, Art. 57
Interplay of PIPL, Cybersecurity Law, and Data Security Law in Breach Notification — Parallel and Cumulative Duties (2026)
China’s breach notification regime is governed by three overlapping statutes: the Personal Information Protection Law (PIPL, effective Nov. 2021), the Cybersecurity Law (CSL, effective June 2017), and the Data Security Law (DSL, effective Sept. 2021). For nearly all significant incidents, a processor must reconcile and comply with all three sets of requirements, which—while parallel—differ in scope and sometimes in threshold and timeline.
PIPL Article 57 (see /guides/china/breach-notification#pipl-article-57-notification-duty) imposes immediate notification duties for any leakage, tampering, or loss of personal information occurring or possibly occurring. CSL Article 21 directs network operators (a defined, broad category) to monitor, log, and report network security incidents and maintain emergency response plans; CSL Article 25 requires incident reporting to authorities and stipulates disclosure obligations. DSL Article 29 requires data processors to adopt emergency incident plans and, upon a “data security incident,” to notify users and report to regulators; “data security incident” here includes but is not restricted to personal information.
Until 2025, these duties ran on different, vaguely defined clocks (CSL: “immediately,” DSL: upon incident, PIPL: “immediately”). As of November 2025, the Administrative Measures for the Reporting of National Cybersecurity Incidents (CAC Measures) create a harmonized, national regime for all “network operators”—including those subject to PIPL, CSL, and DSL. Under the Measures, most processors must report any major-or-higher incident (including personal information breaches meeting specified volume/harm criteria) to the appropriate authorities through the 12387 online/telephone platform within four hours of discovery (CAC Measures Articles 3–4; see /guides/china/breach-notification#notification-to-authority-procedure-channels). “Critical information infrastructure operators” (CIIOs) and government-affiliated entities face stricter one- or two-hour deadlines. These fixed, tiered timelines override the “immediately” language of the prior statutes solely for authority notification.
Unified intake, cumulative duties: The 12387 system is the official unified portal for submitting all cybersecurity (CSL), data security (DSL), and personal information breach (PIPL) notifications. CAC and provincial offices expect—explicitly in Measures, Art. 9 and Q&A 28-5—that processors submit one integrated, preliminary report (with supplemental filings as facts develop, Measures Art. 8) meeting the combined requirements of all relevant statutes and regulations. Sectoral authorities (e.g., financial, telecom, healthcare) may have parallel requirements and expect mirrored reporting, but all are channeled through or coordinated with CAC.
No “lowest common denominator” safe harbor: If timelines, triggers, or required content diverge among PIPL, CSL, DSL, or sectoral regulation, the processor is expected to comply with the strictest (fastest, most comprehensive) standard. The Measures do not create a defense for compliance with only one statute when two or more apply.
Uncertainties and open issues: The statutes do not resolve every potential conflict. For events not reaching “major” severity for CAC Measures but subject to PIPL Art. 57 (e.g., a small but sensitive breach), processors should document internal analysis, make voluntary filings where appropriate, and expect local CAC/provincial practice to shape requirements. Processors without a registered PRC legal entity must ensure their China representative (PIPL Art. 53) can file via the 12387 system.
In practice, breach notification in China for any significant incident is always multi-regime. Treat the 12387 platform as authoritative, but ensure your internal incident workflow maps the event facts against all three statutes’ (PIPL, CSL, DSL) triggers and requirements. Failure to report under any regime risks major penalties under PIPL Article 66.
Source: Personal Information Protection Law of the People's Republic of China, Article 57 Source: Cybersecurity Law of the People's Republic of China, Articles 21, 25 Source: Data Security Law of the People's Republic of China, Article 29 Source: Administrative Measures for the Reporting of National Cybersecurity Incidents (国家网络安全事件报告管理办法), Arts. 3–9, Q&A 28-5
Severity classification thresholds for cybersecurity and personal information breaches — CAC Measures, 2025 Annex (major, severe, extremely severe)
The Administrative Measures for the Reporting of National Cybersecurity Incidents (CAC Measures, effective November 1, 2025) set out a mandatory four-tier system for classifying cybersecurity and personal information breach incidents. These thresholds are critical: incidents classified as “major” (较大), “severe” (重大), or “extremely severe” (特别重大) must be reported to the Cyberspace Administration of China (CAC) under strict deadlines via the 12387 hotline or portal (Measures Art. 4; Annex). Practitioners should anchor their breach response policies on these quantitative and contextual triggers — a threshold breach changes your regulatory clock.
Article 4 and the Annex: numeric and contextual thresholds
The operative rules (direct translation and paraphrase from Article 4 and the Incident Classification Guidelines “Annex”):
- Extremely severe (特别重大):
- Affects over 10 million individuals’ personal information; _or_
- Involves state secrets, CIIO-wide systemic paralysis, or well-substantiated coordinated campaigns with international/public order implications. (Annex I.1)
- Severe (重大):
- Affects more than 1 million, but not exceeding 10 million, individuals; _or_
- Involves sensitive personal information for this cohort; _or_
- Major disruption of multiple regional critical networks or direct threat to public order. (Annex I.2)
- Major (较大):
- Affects more than 100,000, but not exceeding 1 million individuals; _or_
- Involves cross-border exfiltration of more than 100,000 records; _or_
- Serious sectoral incident (e.g., banking, healthcare, energy) with high public profile or operational consequence. (Annex I.3)
- General (一般):
- Involves fewer than 100,000 individuals or does not meet any of the escalation conditions. (Annex I.4)
Only “major and above” incidents (Art. 4(1)) trigger a mandatory report through the unified 12387 reporting system. The text states: “网络运营者应当在4小时内向省级网信部门报告较大及以上等级的网络安全事件。” (“Network operators shall report major and higher-level cybersecurity incidents to the provincial-level cybersecurity authority within four hours.”)
Contextual aggravators — sensitivity, sector, cross-border factor
The Annex mandates numeric thresholds as the primary test, but also outlines aggravating circumstances (serious impact to critical information infrastructure, involvement of sensitive data categories, incidents drawing significant media or public attention, or evidence of cross-border coordination or exfiltration) that can elevate an incident’s tier regardless of strict volume.
Precaution for unclear incidents
Where the number of affected individuals cannot be promptly determined — such as with certain malware or ransomware attacks, or composite incidents involving both leakage and tampering — processors are advised (Annex II) to classify conservatively and report within the shortest feasible time. This precautionary approach is grounded in the “in case of doubt, escalate” language of the guidelines, not a formal provision of the Measures.
Sectoral overlay
While the CAC Measures provide national baseline thresholds, sectoral regulators (e.g., finance, health, telecom) may require notification or escalation at lower volumes or based on additional criteria. These sectoral requirements must be tracked in parallel (Art. 3).
Caveats and control
The current thresholds and conditions originate from the CAC’s officially published Measures and Annex (September 15, 2025). As of June 2026, no public amendments have materially changed these numbers, but subsequent CAC notices or provincial-level variations can apply.
Breach notification duties for financial institutions — CBIRC 2021 Interim Measures
Financial institutions in China—including banks, insurers, and trust companies—are subject to China Banking and Insurance Regulatory Commission (CBIRC) requirements that build on the baseline duties established by the Personal Information Protection Law (PIPL). The CBIRC’s 2021 Interim Measures for the Reporting and Handling of Major Emergencies by Banking and Insurance Institutions (银保监发〔2021〕31号) impose tighter, parallel breach notification obligations distinct from the CAC 12387 regime and general PIPL rules.
Definition of major emergency: The Interim Measures define a notifiable "major emergency" to include incidents where there is unauthorized disclosure or large-scale unauthorized access to customer personal information, or where an incident causes adverse social impact or infringes on customer rights and interests (Arts. 2, 4).
Reporting deadline: Article 13 requires the financial institution to report a major emergency to the CBIRC branch having jurisdiction over its principal office within 1 hour of becoming aware. This is a stricter timeline than the four-hour window under CAC’s Measures for most non-critical entities. The reporting channel includes fax, email, or other written method specified by the CBIRC office. The report content must include:
- The type and scope of the incident
- Immediate remedial measures taken
- An assessment of potential impact
- Contact information for the responsible person
Relationship to PIPL/CAC: The Interim Measures operate in parallel with PIPL Article 57’s requirement for immediate notification to authorities (and, where relevant, individuals), but do not modify or override the CAC’s system. If both frameworks apply, institutions should comply with the strictest clock.
Recordkeeping: The Measures require regulated entities to maintain incident records, including notifications made under these rules, for possible regulatory review (Art. 17). However, there is no explicit statutory requirement for annual inspection of breach logs.
Enforcement: Failure to comply with CBIRC’s 1-hour reporting window may expose the institution to administrative penalties as provided under banking and insurance sector regulation, independently from PIPL or CAC enforcement mechanisms. The Interim Measures themselves do not specify penalty tiers, referring instead to the general CBIRC sanction framework.
Notification to affected individuals — required content, notification method, and special-category scenarios under PIPL Article 57
PIPL Article 57 creates a direct obligation for personal information processors to notify individuals affected by a breach (leakage, tampering, or loss of personal information), unless the outcome-based exemption applies (see /guides/china/breach-notification#harm-prevention-exemption-individual-notification). Unlike the authority-notification procedure, which has been elaborated in recent CAC Measures, the requirements for notifying individuals rely exclusively on PIPL’s text and general enforcement practice—leaving nontrivial gaps around language, delivery method, thresholds for special categories, and edge cases such as minors or cross-border data subjects.
## Required content (Article 57, first paragraph) PIPL Article 57, read in context with Articles 8 (principles) and 17 (transparency), requires that individual notification specify:
- The categories of personal information involved (including whether it is sensitive, Art. 28, or relates to minors as defined in Art. 28(2));
- The cause of the incident and potential or actual harm;
- Measures taken by the processor and actions individuals can take for mitigation;
- Contact information of the processor.
No further content specification appears in the statute. Unlike some regimes (e.g., GDPR Art. 34), PIPL does not explicitly require free credit monitoring or additional remedial actions, nor does it prescribe a model notice template. Processors must judge what details enable the individual to effectively protect their lawful interests.
## Method of notification: individualized and language PIPL is silent on the required method for notifying individuals (electronic, SMS, email, postal mail, phone call), and does not address scenarios involving uncontactable data subjects or language accessibility. In practice, the CAC expects processors to use the channel best calculated to reach the individual, mirroring GDPR expectations for "direct" notice. Substitute methods (posting on a website, public announcement) should be used only as a last resort when direct means fail. For cross-border breaches, or where the data subject's native language is not Chinese, the law is silent; prudence and industry practice recommend notification in the individual’s primary language when contact details so indicate, or at minimum in both Chinese and English for global organizations.
## Special categories: minors and sensitive data Article 28 of the PIPL confers heightened protection on sensitive personal information (biometrics, health records, financial accounts, minors under 14). Where a breach involves such categories, notification must explicitly describe the nature and scope of the affected sensitive data, and the content must be tailored to enable guardians of affected minors (legal representatives) to take mitigation steps. Article 15 requires parental or guardian consent for processing minors’ data; by analogy, breach notices to children must be directed to their legal guardians. PIPL does not define a process for identifying or contacting guardians post-breach, leaving this to practitioner judgment.
## Timeliness and subsequent updates Notification must be made "immediately" (立即), with no hour/day specification. Where initial notification lacks material facts (e.g., scope unknown), follow-up updates must be made as facts become available, mirroring CAC Measures requirements for authority notification (see /guides/china/breach-notification#notification-to-authority-procedure-channels).
## Open issues (2026) PIPL has not been supplemented with standardized model notice templates, explicit language requirements, or detailed guidance on notification for digital-only service providers or cross-border data subjects. No primary-law guidance specifies what constitutes "immediate" notification for overseas subjects or what constitutes sufficient effort to reach uncontactable individuals.
Source: Personal Information Protection Law of the People’s Republic of China, Art. 57
Breach notification requirements for overseas (foreign) processors — PIPL Article 53 and cross-border breach reporting mechanics
China’s Personal Information Protection Law (PIPL) creates direct breach-notification duties for foreign (overseas) personal information processors, not only entities with a corporate presence in the People’s Republic of China (PRC). Practitioners outside China need to know the statutory basis, mechanics, and risk points when their business handles personal information subject to PIPL, especially in a cross-border incident.
## Article 53 — China representative and local contact point Article 53 of PIPL requires any personal information processor based outside China—but subject to extraterritorial reach under Article 3 (offering goods/services to individuals in China, or analyzing their activities)—to "establish a special agency or designate a representative within the territory of the PRC" for personal information protection affairs. This China-based representative becomes the effective contact for all PIPL matters, including breach notification. The processor must report the representative’s name and contact details to the "departments with personal information protection duties" (Article 53, para. 2).
## Breach reporting duty — mechanics for overseas entities If a foreign processor suffers a breach that triggers Article 57 (leakage, tampering, or loss of personal information "occurs or may occur"), it must notify:
- The supervisory authority (typically the provincial-level Cyberspace Administration of China [CAC] with jurisdiction over the representative’s registered address, via the 12387 platform—see
/guides/china/breach-notification#notification-to-authority-procedure-channels), and - All affected individuals in China, unless the outcome-based exemption applies.
The foreign entity’s designated China representative is responsible for submitting the breach report on its behalf. This report must:
- Be submitted through the official 12387 system (hotline, portal, WeChat mini-program, email, or fax);
- Include both the overseas processor’s information and the China representative’s contact details;
- Disclose whether the breach involved any cross-border transfer of the affected personal information;
- Follow the reporting timelines and content requirements set by the CAC Measures (2025) and PIPL Article 57 (typically, within four hours of discovery for "major and above" incidents; see
/guides/china/breach-notification#notification-to-authority-procedure-channels).
## Special issues for overseas/cross-border breaches
- Processors without a registered China representative: Failure to designate and disclose a local representative is a separate violation (Article 66), which can compound fines for any breach notification failure.
- Cross-border data flows: Where breached data originated in China and was transferred overseas (under a valid mechanism such as security assessment/SCC/certification), any incident affecting that data, wherever located, is notifiable to the CAC. China-origin personal information remains in PIPL scope.
- Language: Reports must be submitted in Chinese; there is no official template, but authorities require clear, structured content per the CAC Measures.
- Practical enforcement: The designated representative may be summoned or investigated for breach follow-up. Erroneous, delayed, or incomplete reporting may trigger sanctions against both the foreign entity and the local representative.
## Open issues (2026) PIPL and CAC guidance are silent on the precise procedure where a foreign group has multiple local representatives (e.g., by subsidiary or business line), and on conflict-of-law between PIPL notification timing/content and that of the foreign processor’s home regime.
Source: Personal Information Protection Law of the People’s Republic of China, Art. 53 Source: Administrative Measures for the Reporting of National Cybersecurity Incidents (国家网络安全事件报告管理办法), Art. 9, Q&A 28-5
Sensitive personal information: PIPL Article 28 — definition, breach notification triggers, and escalated risk (2026)
Sensitive personal information (SPI), as defined in Article 28 of China’s Personal Information Protection Law (PIPL, effective Nov. 1, 2021), includes any personal data that, once leaked or illegally used, may easily lead to infringement of personal dignity or endangerment of personal or property safety. Article 28 provides an enumerated non-exhaustive list: biometrics, religious beliefs, specific identities, medical/health information, financial accounts, individual location tracking, and personal information of minors under 14 years old automatically constitute SPI. Processors are allowed to designate additional categories in internal policies or sectoral codes.
## SPI and Breach Notification
PIPL Article 57 does not create a higher notification threshold for SPI—the duty to notify the regulator and affected individuals arises for any leakage, tampering, or loss of SPI "occurring or possibly occurring," just as with ordinary personal information. However, SPI is integral to several enforcement and operational aspects of breach notification:
1. Heightened risk and content requirements. In a breach involving SPI, notification (to individuals per Article 57, and to authorities per the CAC’s 2025 Measures) must:
- Explicitly identify which SPI categories were involved,
- Assess the possibility of significant harm tied to SPI leakage (identity theft, discrimination, financial loss, etc.), and
- Where minors are affected, address notice to legal guardians (per Article 15, 28; see
/guides/china/breach-notification#notification-to-individuals-content-method-special-categories).
2. Harm-prevention exemption harder to invoke. The outcome-based exemption (allowing processors not to notify individuals if harm is "effectively avoided") is much more difficult to justify with SPI, given its inherent risk. CAC practice and enforcement commentary treat SPI as rarely, if ever, eligible for exemption unless the processor has incontrovertible evidence (e.g., proven-strong encryption with uncompromised keys).
3. Escalated penalty and classification risk. Under the CAC’s 2025 Administrative Measures, a breach involving SPI can escalate the incident’s severity classification (Annex, Art. I.2) or raise the penalty tier under Article 66:
- Breaches involving SPI, especially in large volumes or cross-border exfiltration, are automatically classified as at least "major" or "severe," tightening reporting deadlines (4h/1h) and prompting higher scrutiny.
- In enforcement (see Didi case, July 2022), CAC cited mishandling of sensitive health, location, and minors' information as aggravating factors resulting in a top-tier penalty.
4. Sectoral overlays. Processors subject to sectoral regulation (healthcare, finance, minors’ services) must comply with SPI-specific notice standards, alongside baseline PIPL duties. Overlapping CAC, health, or education authority requirements are common.
Summary. A practitioner handling SPI breaches should:
- Catalog and flag all SPI in incident assessment and in notifications;
- Assume regulatory and individual notice are both mandatory unless immediate, incontrovertible avoidance of harm is proven;
- Escalate authority notification speed and depth of factual detail;
- Apply sector overlays for SPI from minors/health/finance contexts.
Source: Personal Information Protection Law of the People's Republic of China, Art. 28 Source: Administrative Measures for the Reporting of National Cybersecurity Incidents (国家网络安全事件报告管理办法), Annex I.2
Step-by-step breach response workflow under PIPL and CAC Measures: discovery, containment, notification, and follow-up (2026)
A compliant breach response in China involves tightly sequenced steps across PIPL (Personal Information Protection Law, eff. Nov. 2021), the Administrative Measures for Reporting National Cybersecurity Incidents (CAC Measures, eff. Nov. 2025), and—when applicable—sector regulations (e.g., CBIRC for finance). Proper order, division of roles, and real-time reporting are critical; CAC enforcement has cited failure to parallel-track notification and investigation as grounds for escalated penalties under Article 66. Below is a one-page workflow practitioners can apply for personal information (PI) breaches:
1. Immediate discovery and containment On indication of leakage, tampering, or loss (PIPL Art. 57), the response team must (a) isolate affected systems, (b) secure logs, (c) prevent further leakage/tampering, and (d) begin initial scope assessment. Do not wait for complete understanding to begin notification analysis—the notification clock starts at discovery, not full confirmation.
2. Internal triage and parallel notification decision Simultaneously, legal/compliance and IT should:
- Assess likely volume and whether sensitive PI (Art. 28) or minors’ data is implicated (triggers escalated response per CAC Annex, PIPL Art. 28).
- Classify severity per CAC Measures Annex: "major or above" triggers 12387 notification within four hours of discovery (one hour for CIIOs; sector overlays for finance/health).
- Determine if the outcome-based individual-notification exemption (PIPL Art. 57, para. 2) plausibly applies; in doubt, prepare to notify both authority and individuals.
3. Authority notification through 12387 system File the initial CAC breach report via hotline/portal/WeChat/email/fax to the correct provincial CAC (per registered address or local representative for overseas processors, PIPL Art. 53; CAC Measures Art. 9). Include all facts then known (see /guides/china/breach-notification#notification-to-authority-procedure-channels). If severity is undetermined, escalate as if "major;" supplemental report is required as new facts arise (CAC Measures Art. 8). For regulated sectors (banking, telecom, health), make parallel filings per sector regulator's protocol (CBIRC, MIIT, NHC).
4. Notification to affected individuals Draft the individual breach notice per PIPL Art. 57(1) and /guides/china/breach-notification#notification-to-individuals-content-method-special-categories. If exemption is claimed (PIPL Art. 57, para. 2), document evidence that remedial measures "effectively avoid harm"; be prepared for CAC override. Notification must be "immediate," best practice is contemporaneous with authority notification but never delayed more than 24–48 hours post-discovery.
5. Investigation, supplemental reporting, and resolution Continue forensic investigation. File supplemental reports via 12387 as soon as new facts (affected scope, root cause, attacker identity) are confirmed (CAC Measures Art. 8). After incident close, submit a final summary report (see /guides/china/breach-notification#notification-to-authority-procedure-channels). Update affected individuals if new risks or mitigation steps emerge.
6. Retention and internal review Retain breach, investigation, and notification records for at least three years (see /guides/china/breach-notification#recordkeeping-retention-requirements). Conduct internal audit to review response gaps and update incident protocols accordingly—as required by PIPL Art. 54–56.
Authority and source: This workflow is synthesized from official requirements in PIPL Arts. 54–57, CAC Measures Arts. 3–9, and sector regulatory practice. CAC’s own guidance (CAC Measures Q&A 2025, section II) emphasizes parallel notification and not waiting for post-mortem to file. Enforcement in major 2022–2025 cases (publicized via cac.gov.cn) shows penalty escalation for delayed reporting, missed sectoral filings, and lack of investigation follow-up.
Source: Personal Information Protection Law of the People’s Republic of China, Arts. 54–57 Source: Administrative Measures for the Reporting of National Cybersecurity Incidents (国家网络安全事件报告管理办法), Arts. 3–9, Q&A 28-5
Breach notification duties for healthcare institutions — National Health Commission sectoral rules (2026)
China’s healthcare sector faces parallel breach notification requirements: not only does the Personal Information Protection Law (PIPL, Article 57, effective Nov. 2021) and the Cyberspace Administration of China (CAC) 2025 Measures apply, but hospitals, clinics, and medical data processors must also comply with sector-specific mandates issued by the National Health Commission (NHC).
Dual notification duty — NHC and CAC Healthcare providers must notify both:
- The relevant local/provincial Health Commission (under NHC sectoral data security rules), and
- The provincial CAC office (through the 12387 reporting system), per the Administrative Measures for the Reporting of National Cybersecurity Incidents (CAC Measures 2025, Article 4).
NHC’s breach notification rules The National Health Commission’s 2018 Regulation on the Management of Medical Big Data Security (试行) sets a 24-hour window: "medical institutions shall report security incidents related to the disclosure, tampering, or loss of medical big data to the local health administrative department within 24 hours of discovery" (Article 18). This includes patient information and medical records. Notification content must specify the time, location, cause, scope, and containment measures, as well as responsible contacts (NHC, Art. 18). Telephone notice is required "in case of major or urgent incidents." Written reports follow prescribed templates issued by local health departments.
Interaction with PIPL and CAC rules The NHC’s 24-hour maximum is distinct from (and may be longer than) the 1–4 hour CAC window for "major and above" cybersecurity or personal information breach incidents, per CAC Measures 2025, Article 4 and its Annex (see /guides/china/breach-notification#notification-to-authority-procedure-channels). Processors must comply with both and err on the stricter deadline. Under PIPL Article 28, medical record information—including health, biometrics, and minors’ data—meets the definition of sensitive personal information, often requiring escalated regulatory attention and increasing the likelihood of reports being classified as "major" or "severe" under CAC tiers.
Enforcement and penalties Failure to report to the Health Commission as required by NHC regulations can result in administrative sanctions under the Regulation on the Administration of Medical Institutions; the regulation allows for corrective orders, public criticism, or other statutory penalties (see NHC Regulation, Article 32). Penalties under PIPL Article 66 for general notification failures also apply. Joint Health Commission–CAC enforcement is authorized but the precise form is determined case by case—license suspension is a possible but not an automatic outcome and is reserved for egregious or repeat violations as specifically described in administrative penalty provisions.
Key takeaways Medical and health-sector practitioners in China must maintain incident-response protocols that meet both CAC’s (1–4 hour) and NHC’s (24-hour) notification standards. When any breach involves patient or medical data, immediately notify both the CAC (via 12387) and the local Health Commission, and document all submissions, following the local Health Commission’s reporting format. Reference PIPL Article 28 for which data types will be treated as sensitive and presumed to trigger heightened incident classification.
Source: National Health Commission Regulation on the Management of Medical Big Data Security (2018, 试行), Art. 18, 32 Source: Administrative Measures for the Reporting of National Cybersecurity Incidents (国家网络安全事件报告管理办法), Arts. 3–9, Annex Source: Personal Information Protection Law of the People's Republic of China, Arts. 28, 57, 66
Breach notification for personal information involved in cross-border transfers — PIPL Articles 38–40 and CAC cross-border assessment triggers (2026)
Personal Information Protection Law (PIPL) Articles 38–40 set the compliance framework for cross-border transfers of personal information from China, originally requiring a security assessment, standard contract (SCC), or personal information protection certification, with the Cyberspace Administration of China (CAC) retaining final approval. A material change occurred effective January 1, 2026: the CAC and State Administration for Market Regulation (SAMR) jointly issued the "Measures for Certification of Cross-Border Personal Information Transfer," which operationalized the Certification pathway and added further texture to China’s breach-notification and cross-border compliance regime.
## Updated pathways for cross-border transfer (as of 2026)
- Security assessment: For large-scale data transfers (typically processors handling over 1 million individuals or exporting sensitive/important data), a CAC security assessment remains mandatory. Breaches involving such data must be reported to both the provincial-level CAC (via 12387) and the original CAC assessment office.
- Standard contract (SCC): For qualifying transfers, parties may use the SCC route, stipulating breach-notification and remediation responsibilities per CAC’s February 2023 contract template. Breaches must be disclosed to CAC and affected individuals, and may trigger reevaluation or suspension of transfer approval.
- Certification route (effective Jan 2026): The new "Measures for Certification of Cross-Border Personal Information Transfer" introduce a certification pathway for non-CIIO personal information processors handling between 100,000 and 1 million individuals (or fewer than 10,000 sensitive individuals), so long as "important data" is not involved. Key features:
- Separate individual consent is required for the transfer.
- A Personal Information Protection Impact Assessment (PIPIA) must be conducted and retained.
- Certification is valid for 3 years, renewable subject to re-assessment.
- Certification authorities (designated by CAC/SAMR) review compliance audits, ongoing obligations, and incident response protocols.
- Material breaches or non-compliance can trigger re-examination, suspension, or revocation of certification.
## Breach notification triggers and obligations (cross-border context)
A breach of personal information that has been transferred overseas still triggers Article 57’s dual duty: immediate notification both to CAC and to affected individuals (unless the harm-prevention exemption applies). The entity responsible for the cross-border transfer, and the overseas recipient (if designated as a processor), must coordinate responses and disclosures.
- For Security Assessment transfers, any overseas breach must be reported to both the provincial CAC and the original approval office per Measures, Art. 9(3).
- For SCC or Certification routes, the responsible party must notify the CAC per SCC Article 8 and the Certification Measures (Art. 22–23), and update all relevant filings.
- Each pathway authorizes the CAC to suspend or revoke the right to transfer the implicated dataset during investigation of the breach.
## Enforcement and consequences Breach of cross-border personal information—especially if not reported on time, or if it reveals systemic control failures—may result in:
- Revocation or suspension of security assessment, SCC filing, or certification,
- Penalties up to 5% of turnover or RMB 50 million,
- Blacklisting of overseas entities under Art. 42,
- Possible requirements for additional remedial measures or new contractual guarantees.
## Key change (2026): Certification pathway The Certification pathway is now fully in force alongside security assessment and SCC routes, expanding options particularly for processors below the CIIO or "important data" thresholds. Entities using the certification mechanism must promptly report breaches per the new Measures’ requirements; certifications may be suspended or revoked after material overseas incidents even if other compliance steps were followed.
Source: Personal Information Protection Law of the People’s Republic of China, Arts. 38–40, 57 Source: Measures for Security Assessment of Cross-Border Data Transfer, Arts. 9, 15–16 Source: Standard Contract for Cross-Border Transfer of Personal Information, Art. 8 Source: Measures for Certification of Cross-Border Personal Information Transfer, Arts. 3, 5, 22–23 (2026)