Administrative penalty tiers under PIPL Article 66 — two-tier fine structure and jurisdictional thresholds
PIPL Article 66 establishes a two-tier administrative penalty framework that distinguishes between ordinary violations and violations where "the circumstances are serious" (情节严重). The statute assigns enforcement jurisdiction and maximum penalty authority based on severity, with provincial-level and higher authorities holding exclusive power to impose Tier 2 sanctions.
Tier 1: Ordinary violations under Article 66, paragraph 1
Where a personal information processor violates PIPL or fails to fulfill personal information protection obligations, the supervising authority shall order correction, issue a warning, confiscate illegal gains, and may order suspension or termination of the offending application or service. If the violator refuses to make corrections after being ordered to do so, the authority may impose:
- A fine of not more than RMB 1,000,000 on the entity; and
- A fine of RMB 10,000 to RMB 100,000 on each directly responsible manager and other directly responsible personnel.
Tier 1 penalties may be imposed by departments with personal information protection duties at any level—including county-level authorities for violations within their jurisdiction under Article 60. The "refusal to make corrections" language means that a violator who timely complies with a rectification order may avoid monetary penalties at this tier, though the warning, confiscation of illegal gains, and service-suspension orders remain available.
Tier 2: Violations where "the circumstances are serious" under Article 66, paragraph 2
Where the illegal acts described in Article 66(1) meet the "serious circumstances" threshold, departments with personal information protection duties at or above the provincial level shall apply elevated penalties. Only provincial-level and higher authorities may invoke Article 66(2). These authorities are empowered to:
- Order correction and confiscate illegal gains;
- Impose a fine of not more than RMB 50,000,000 OR not more than five percent of the previous year's turnover, applying whichever parameter the authority selects (the statute does not specify "whichever is higher" as GDPR Article 83 does, nor does it define whether "turnover" means PRC-only revenue or worldwide revenue);
- Order suspension of relevant business operations, suspension of all business operations for rectification, or notify competent authorities to revoke relevant business permits or business licenses;
- Impose a fine of RMB 100,000 to RMB 1,000,000 on each directly responsible manager and other directly responsible personnel; and
- Decide to prohibit the directly responsible persons from serving as directors, supervisors, senior managers, or the person in charge of personal information protection of any enterprise for a specified period of time.
"Serious circumstances" — undefined statutory trigger
PIPL does not define "serious circumstances" (情节严重) in Article 66(2) or elsewhere in the statute. The determination of whether a violation meets this threshold rests with the enforcing authority. No implementing regulation has published a categorical list of factors or bright-line thresholds (such as a minimum number of affected individuals, monetary harm, or recidivism requirement) that automatically trigger Tier 2 classification as of June 2026.
The absence of a statutory or regulatory definition means practitioners cannot predict with certainty whether a given violation will be treated as ordinary (Tier 1) or grave (Tier 2). Factors that enforcement authorities may consider—by analogy to "serious circumstances" language in other PRC administrative-penalty statutes—plausibly include the scale of personal information affected, whether the violation involved sensitive personal information under Article 28, whether the processor obstructed investigation under Article 63, prior violations and failure to correct after earlier warnings, and cross-border transfer violations. However, these factors are not codified and their weight is not publicly disclosed.
Credit records and public disclosure under Article 67
Article 67 of PIPL provides that any violation falling under Article 66 "shall be included in credit records and disclosed to the public in accordance with relevant provisions." The statute does not specify which credit-record system, the duration of the record, or the form of public disclosure. Article 67 cross-references "relevant provisions," which likely include the State Council's social credit system framework, but the operational consequence of a PIPL credit-record entry—such as restricted access to government procurement, restrictions on financing, or travel limitations—depends on implementing measures that are outside PIPL itself.
Relationship to criminal liability
Article 66 administrative penalties operate independently of criminal prosecution. Article 64 requires that supervisory authorities conducting investigations under Article 63 "timely transfer" cases with suspected criminal conduct to public security organs (police authorities). Article 71 provides that where a PIPL violation constitutes a crime, criminal liability shall be pursued in accordance with law, and where the violation also constitutes a violation of public security administration, a public security administrative penalty shall be imposed in accordance with law.
Criminal Law Article 253-A (unlawfully obtaining or providing citizens' personal information, as amended) and Article 286 (refusal to fulfill information network security management obligations) are the primary criminal offenses that may overlap with PIPL administrative violations. Article 253-A carries a maximum sentence of seven years' imprisonment where the circumstances are "especially serious," and Article 286 carries a maximum of three years' imprisonment. A PIPL violator may face administrative fines under Article 66, public security administrative detention or fines, and criminal prosecution simultaneously for the same underlying conduct.
Source: Personal Information Protection Law of the People's Republic of China, Art. 66 Source: Personal Information Protection Law of the People's Republic of China, Art. 67 Source: Personal Information Protection Law of the People's Republic of China, Art. 71 Source: Personal Information Protection Law of the People's Republic of China, Art. 60 Source: Personal Information Protection Law of the People's Republic of China, Art. 64
Private rights of action and civil remedies under PIPL Articles 69–70 — tort liability, reverse burden of proof, and public interest litigation
PIPL establishes a comprehensive private-enforcement mechanism for data subjects whose personal information rights have been infringed. Unlike the EU GDPR, which leaves tort liability primarily to member-state law, PIPL incorporates an explicit tort-liability rule with a reverse burden of proof and a parallel public-interest-litigation pathway that functions as a class-action equivalent for large-scale violations.
Individual private right of action — Article 69 and Article 50
Article 69 of PIPL provides that where the processing of personal information infringes personal information rights and interests and causes damage, the personal information processor shall bear tort liability unless the processor can prove it was not at fault. This is a fault-presumed regime: once the data subject demonstrates that (1) the processor handled personal information, (2) the handling infringed the data subject's personal information rights, and (3) damage resulted, the processor bears the burden of proving the absence of fault to avoid liability.
The statute does not define "damage" or specify whether intangible harm (such as privacy invasion absent pecuniary loss) suffices. Damages are calculated based on the actual losses suffered by the data subject or the gains obtained by the personal information processor as a result of the violation, applying whichever measure the plaintiff elects. Where it is difficult to determine actual damages or gains, Article 69 authorizes the people's court to award an appropriate amount "according to the circumstances."
Article 50 grants data subjects the right to file a lawsuit in a people's court when a personal information processor refuses the data subject's request to exercise any of the rights enumerated in PIPL Chapter 4 (including the rights to access, correct, delete, restrict processing, and data portability). The 2024 Guangzhou Internet Court decision in Zuo v. Company A (an unpublished ruling involving cross-border transfer of personal information to Austria) held that a data subject may file suit directly for infringement of the right to be informed and the right of decision-making under Article 44 without first exhausting a request-and-refusal procedure; the court awarded RMB 20,000 in damages and ordered deletion of the plaintiff's personal information held by the defendants and their overseas recipients.
Reverse burden of proof
The reverse burden of proof under Article 69 departs from the general tort rule in the Civil Code, which ordinarily requires the plaintiff to prove the defendant's fault. The personal information processor must affirmatively prove it was not at fault—such as by demonstrating that the processing complied with all applicable consent, purpose-limitation, and security requirements under PIPL, or that the damage was caused by the data subject's own conduct, a third party, or force majeure. This evidentiary shift materially increases litigation risk for processors, as proving negative fault (rather than the plaintiff proving positive fault) can be procedurally and documentarily burdensome.
Public interest litigation mechanism — Article 70
Article 70 extends standing to bring PIPL civil actions to three categories of third-party organizations when illegal processing of personal information harms the rights and interests of a large number of individuals:
- People's procuratorates (检察院, the state prosecutor general offices at provincial and lower levels);
- Consumer organizations prescribed by law (typically the China Consumers Association and its local affiliates); and
- Other organizations designated by the Cyberspace Administration of China (CAC) or relevant enforcement authorities.
Public interest litigation under Article 70 functions as China's analog to class-action litigation. It permits a qualified third party to sue on behalf of an affected group without requiring each data subject to individually assert a claim. One day after PIPL's adoption, the Supreme People's Procuratorate issued an official notice confirming that public interest actions for personal information protection would be a priority enforcement tool.
The earliest reported public interest PIPL decision was a 2020 case brought by the Procuratorate of Xiacheng District, Hangzhou, against an individual who purchased over 45,000 items of personal information (names, contact numbers, and email addresses) from the internet and resold them for profit via chat platforms. The People's Court ordered compensation of RMB 34,000 (representing the offender's gain) and a formal public apology broadcast through a provincial-level news agency. A March 2021 Gweiyang District (Hunan) case similarly involved public interest civil claims brought as ancillary actions to criminal prosecutions under Criminal Law Article 253-A (unlawful acquisition or provision of citizens' personal information).
No statutory cap on civil damages
PIPL does not impose a monetary cap on civil tort damages. Unlike the Article 66 administrative penalty tiers (which cap fines at RMB 50 million or 5 percent of annual revenue for grave violations), Article 69 tort liability is limited only by the actual-loss or processor-gain measure and the court's discretion when those measures are difficult to apply. This leaves civil exposure potentially unbounded for large-scale breaches affecting millions of data subjects or generating substantial processor revenue.
Relationship to administrative penalties and criminal liability
Civil liability under Article 69, administrative penalties under Article 66, and criminal prosecution under Article 71 operate independently and may be imposed simultaneously for the same underlying conduct. A personal information processor that suffers an administrative fine under Article 66 for a grave violation may also face civil tort claims under Article 69 from affected data subjects (individually or via public interest litigation) and, if the violation meets the thresholds in Criminal Law Article 253-A or Article 286, criminal liability for the entity and its directly responsible personnel. Article 64 requires supervisory authorities to timely transfer cases with suspected criminal elements to public security organs (police authorities), expanding the functional reach of initial administrative investigations.
Statute of limitations
Civil Code Article 188 establishes a general three-year statute of limitations for civil tort claims, running from the date the claimant knew or should have known of the infringement and the identity of the tortfeasor. However, for non-monetary remedies—including cessation of infringement, removal of obstacles, elimination of danger, elimination of adverse effects, rehabilitation of reputation, or apology—no statute of limitations applies under Article 188. A data subject seeking deletion of personal information or cessation of unlawful processing under Article 50 may therefore file suit at any time.
Source: Personal Information Protection Law of the People's Republic of China, Art. 69 Source: Personal Information Protection Law of the People's Republic of China, Art. 70 Source: Personal Information Protection Law of the People's Republic of China, Art. 50
Criminal liability under PIPL Article 71 — Article 253-A personal-information offenses and prison exposure up to seven years
PIPL Article 71 provides that where a violation of PIPL constitutes a crime, criminal liability shall be pursued "in accordance with law." This language cross-references two principal offenses in China's Criminal Law: Article 253-A (unlawfully obtaining or providing citizens' personal information) and Article 286 (refusal to fulfill information network security management obligations). Criminal prosecution operates independently of administrative penalties under Article 66 and civil tort liability under Article 69; the same conduct may trigger all three liabilities simultaneously for the same underlying violation.
Criminal Law Article 253-A — unlawfully obtaining or providing citizens' personal information
Article 253-A of the Criminal Law, as substantially revised by Amendment IX adopted in August 2015, criminalizes two categories of unlawful personal-information conduct. The first category targets insiders: any staff member of a state organ, or an institution of finance, telecommunication, transportation, education, or health care, who in violation of state regulations sells or illegally provides citizens' personal information obtained by the entity during the course of performing duties or providing services. The second category reaches any person who illegally obtains such information by theft or other means. Both categories require that "the circumstances are serious" as a threshold element for criminal liability to attach.
Sentencing tiers under Article 253-A:
- Serious circumstances: fixed-term imprisonment of not more than three years or criminal detention, and a concurrent fine or fine alone.
- Especially serious circumstances: fixed-term imprisonment of not less than three years but not more than seven years, and a concurrent fine.
The Criminal Law does not define "serious circumstances" or "especially serious circumstances" for Article 253-A. Judicial interpretations issued by the Supreme People's Court and the Supreme People's Procuratorate in May 2017 established quantitative thresholds tied to the volume of personal information unlawfully obtained or provided, the type of information (with stricter thresholds for sensitive categories such as health, biometric, and financial data), the monetary gain derived from the violation, and whether the violation caused actual harm. However, these judicial interpretations are not codified in primary legislation and are subject to revision. Practitioners should treat the statutory "serious circumstances" language as a fact-intensive determination reserved to the prosecutorial and judicial authorities.
Criminal Law Article 286 — refusal to fulfill information network security management obligations
Unable to confirm the full text and current sentencing tiers for Criminal Law Article 286 as of 2026-06-01.
PIPL Article 64 transfer mechanism — administrative investigation to criminal prosecution
PIPL Article 64 requires supervisory authorities conducting investigations under Article 63 to "timely transfer" cases with suspected criminal conduct to public security organs (police authorities). This provision functionally expands the reach of administrative enforcement: a case that begins as a PIPL compliance audit or administrative investigation under Article 63 may escalate to criminal prosecution under Article 253-A or Article 286 where the supervising authority discovers facts that satisfy the elements of either offense.
The transfer obligation under Article 64 is mandatory ("shall") and immediate ("timely"). The statute does not define "suspected criminal conduct," but the transfer standard is lower than the evidentiary threshold for conviction. Once transferred, the public security organ conducts its own investigation under the Criminal Procedure Law, and the supervising authority's administrative penalty proceeding under Article 66 may continue in parallel. A violator who receives an administrative fine under Article 66 while under criminal investigation may ultimately face both the administrative penalty and criminal prosecution for the same conduct.
Simultaneous liability — administrative, civil, and criminal exposure for the same PIPL violation
A personal information processor that commits a grave PIPL violation may face three independent and cumulative liability categories:
- Administrative fines under Article 66: up to RMB 50,000,000 or up to five percent of the previous year's turnover (whichever the provincial-level or higher authority selects), plus confiscation of illegal gains, suspension or revocation of business licenses, and personal fines of RMB 100,000 to RMB 1,000,000 on directly responsible managers and personnel, with potential prohibition from serving as directors, supervisors, or senior managers.
- Civil tort damages under Article 69: no statutory cap; measured by the actual losses suffered by the data subject or the gains obtained by the processor, with judicial discretion to award an appropriate amount where those measures are difficult to determine. Multiple data subjects may sue individually, or a people's procuratorate or qualified consumer organization may bring public interest litigation under Article 70 on behalf of a large number of affected individuals.
- Criminal prosecution under Article 253-A or Article 286: imprisonment of up to seven years for especially serious violations, criminal fines on both the entity and the directly responsible individuals, and potential public security administrative detention (up to 15 days) under the Law on Penalties for Administration of Public Security for conduct that does not meet the criminal "serious circumstances" threshold.
Article 71 does not bar simultaneous imposition of all three liability categories. The Civil Code (which superseded the earlier Tort Liability Law) confirms in principle that bearing administrative or criminal liability does not relieve tort liability, and where the offender's assets are insufficient to satisfy all liabilities, tort liability (compensation to victims) takes priority. A violator may therefore be subject to an administrative fine, a civil tort judgment, and a criminal sentence—including imprisonment—arising from the same underlying PIPL violation.
Entities versus natural persons — criminal liability of the processor and its personnel
Criminal Law Article 253-A imposes liability on natural persons. Where the unlawful conduct is committed by an employee or agent of a corporate processor, the individual who committed the act is subject to criminal prosecution. PIPL Article 66(2) separately authorizes administrative penalties against "the person in charge of personal information protection" and "directly responsible managers and other directly responsible personnel," and these individuals may also face criminal prosecution under Article 253-A if their conduct satisfies the statutory elements.
Chinese criminal law does not recognize corporate criminal liability for most offenses, including Article 253-A violations. The entity itself is not subject to imprisonment, but its directly responsible individuals are. The administrative penalty provisions in Article 66 fill this gap by imposing entity-level fines, business-license revocations, and prohibition orders on individuals that function similarly to the disqualification remedies familiar in other jurisdictions.
Relationship to public security administrative penalties
Article 2 of the Law on Penalties for Administration of Public Security provides that where an act is harmful to society but "not serious enough for criminal punishment" according to the Criminal Law, the public security organ shall impose an administrative penalty for public security (detention up to 15 days, fines up to specified amounts). This creates an intermediate sanction tier for personal-information violations that exceed the threshold for PIPL Article 66(1) administrative penalties but do not meet the "serious circumstances" threshold for criminal prosecution under Article 253-A.
A violator may therefore face layered administrative exposure: PIPL Article 66 administrative fines imposed by the CAC or another supervisory authority under Article 60, and public security administrative detention and fines imposed by the police under the public-security-penalties law, with both proceeding in parallel to (or as alternatives to) criminal prosecution under Article 253-A.
Source: Personal Information Protection Law of the People's Republic of China, Art. 71 Source: Personal Information Protection Law of the People's Republic of China, Art. 64 Source: Criminal Law of the People's Republic of China, Amendment VII (2009), Art. 253-A Source: Law of the People's Republic of China on Penalties for Administration of Public Security, Art. 2
Extraterritorial enforcement under PIPL Article 42 — CAC blacklist mechanism and restrictions on cross-border data provision to foreign entities
PIPL Article 42 creates an extraterritorial enforcement tool that extends China's personal information protection regime beyond its borders by authorizing the Cyberspace Administration of China (CAC) to designate foreign organizations and individuals for blacklisting. This mechanism operates independently of the Article 66 administrative penalty framework and does not require territorial presence or voluntary compliance — the CAC may blacklist a foreign entity based solely on the entity's offshore processing activities, and Chinese processors are then prohibited or restricted from transferring personal information to the blacklisted party.
Article 42 statutory text and trigger
Article 42 provides that where any overseas organization or individual engages in personal information processing activities that infringe upon the personal information rights and interests of citizens of the People's Republic of China, or that endanger the national security or public interest of the People's Republic of China, the State Cyberspace Administration (the CAC) may include the offending overseas organization or individual in a "list of restricted or prohibited provision of personal information," announce the list publicly, and take measures to restrict or prohibit the provision of personal information to such overseas organization or individual.
The statute does not define "infringe upon personal information rights and interests" or "endanger national security or public interest." No implementing regulation has published categorical thresholds, factors, or examples of conduct that automatically trigger blacklisting as of June 2026. The determination rests entirely with the CAC's discretion. Practitioners treating Article 42 as an analogue to blocking statutes in other jurisdictions should note that the CAC is not required to demonstrate a PRC territorial nexus for the underlying processing activity — the foreign entity need not have assets, personnel, or operations in China for the CAC to designate it under Article 42.
Substantive reach — offshore processing by foreign entities with no PRC presence
Article 42 applies to "overseas organizations or individuals." An entity incorporated, headquartered, and operating entirely outside China may be blacklisted if the CAC determines that the entity's personal information processing activities harm PRC citizens' personal information rights or harm national security or public interest. This extraterritorial assertion of jurisdiction operates through the secondary enforcement mechanism: once an entity is placed on the Article 42 blacklist, any personal information processor subject to PIPL — including processors operating within China or subject to PIPL's extraterritorial scope under Article 3 — is restricted or prohibited from providing personal information to the blacklisted entity.
Article 3 of PIPL establishes extraterritorial scope for the statute itself. PIPL applies to personal information processing activities outside the territory of the People's Republic of China where (1) the purpose is to provide products or services to natural persons located within China, or (2) the purpose is to analyze or assess the behavior of natural persons located within China. A foreign processor that falls within Article 3's extraterritorial scope and is later blacklisted under Article 42 faces both the direct compliance obligations of PIPL (including the Article 66 administrative penalty exposure for violations) and the secondary enforcement consequence that other processors cannot lawfully provide it with personal information.
The combined effect is that a foreign entity operating a website accessible to PRC users (triggering Article 3's extraterritorial scope), which then processes PRC citizens' personal information in a manner the CAC deems harmful to national security — such as by transferring the data to a government authority in the entity's home jurisdiction in response to a foreign law-enforcement request without obtaining CAC approval under Article 41 — may be blacklisted under Article 42. Once blacklisted, no processor in China or subject to PIPL may transfer personal information to that entity without violating PIPL, even if the original cross-border transfer was conducted under one of the lawful transfer mechanisms in Chapter V (security assessment, standard contracts, or certification).
Procedural mechanics — CAC designation and public announcement
Article 42 vests blacklisting authority exclusively in "the State Cyberspace Administration" (国家互联网信息办公室, also translated as the Cyberspace Administration of China or CAC). The CAC is the lead coordinator for personal information protection enforcement under Article 60 and holds primary responsibility for cross-border data transfer security assessments under Article 40. No other enforcement authority — including the Ministry of Public Security, provincial-level cyberspace administrations, or sectoral regulators such as MIIT or SAMR — may designate entities for the Article 42 blacklist, though these authorities may refer cases to the CAC for blacklisting consideration.
The statute requires the CAC to "announce" (公布) the blacklist. Article 42 does not specify the publication medium, update frequency, or whether the CAC must provide notice to the designated entity before or after publication. The statute's plain language permits the CAC to publish the blacklist unilaterally without prior notice to the affected foreign entity. Once published, the blacklist binds all processors subject to PIPL: they "shall be restricted or prohibited from providing personal information" to the designated entity. Whether a given blacklisted entity is subject to a "restriction" (partial prohibition, such as for specific categories of personal information or specific processing purposes) or an absolute "prohibition" is not specified in Article 42 and appears to be a case-by-case CAC determination reflected in the published blacklist entry.
Enforcement consequences — prohibition on data provision by Chinese processors
The primary enforcement consequence of Article 42 blacklisting is not a fine or penalty imposed on the blacklisted foreign entity (which may be beyond the CAC's territorial enforcement reach), but rather a prohibition imposed on processors within China or subject to PIPL. Article 42 states that the CAC "shall take measures to restrict or prohibit the provision of personal information" to the blacklisted entity. In practice, this means that any processor — whether a PRC-resident entity, a foreign processor with a PRC establishment under Article 53, or an offshore processor subject to PIPL's extraterritorial scope under Article 3 — commits a PIPL violation if it transfers personal information to a blacklisted entity.
A processor that provides personal information to a blacklisted entity after the CAC has published the blacklist may face administrative penalties under Article 66. If the violation meets the "serious circumstances" threshold under Article 66(2), the processor is subject to fines of up to RMB 50,000,000 or up to five percent of the previous year's turnover, confiscation of illegal gains, suspension or revocation of business licenses, and personal fines of RMB 100,000 to RMB 1,000,000 on directly responsible managers. The processor may also face civil tort liability under Article 69 if the transfer to the blacklisted entity results in harm to data subjects, and criminal prosecution under Article 71 and Criminal Law Article 253-A if the transfer constitutes unlawful provision of citizens' personal information.
Article 43 reciprocal countermeasures
Article 43 of PIPL complements the Article 42 blacklist by authorizing reciprocal countermeasures. Where any country or region adopts discriminatory prohibitive, restrictive, or similar measures against the People's Republic of China in respect of personal information protection, the People's Republic of China may, based on the actual circumstances, take corresponding measures against such country or region. Article 43 does not specify which PRC authority holds the power to impose reciprocal countermeasures (likely the State Council or the CAC, by analogy to export-control and unreliable-entity-list frameworks), nor does it define "discriminatory" or enumerate the forms that countermeasures may take.
Article 43 countermeasures are conceptually distinct from Article 42 blacklisting. Article 42 targets specific foreign organizations or individuals based on their personal information processing activities. Article 43 targets countries or regions based on their policies or laws. A practitioner advising a multinational client should assess both exposure pathways: the client's own processing may trigger Article 42 blacklisting, and the client's home jurisdiction's data-protection or national-security laws may trigger Article 43 countermeasures that apply categorically to all processors in that jurisdiction.
Interaction with cross-border transfer mechanisms under Chapter V
PIPL Chapter V establishes three lawful mechanisms for cross-border personal information transfers: (1) CAC security assessment under Article 40 for critical information infrastructure operators and processors meeting specified volume thresholds; (2) standard contracts under Article 38, filed with provincial-level CAC authorities; and (3) personal information protection certification under Article 38, obtained from accredited certification bodies. A processor that successfully completes one of these mechanisms — such as by obtaining CAC security assessment approval or filing standard contracts — does not receive immunity from Article 42 blacklisting.
Article 42 operates as a post-transfer enforcement tool. A foreign recipient that was lawfully receiving personal information from a PRC processor under an Article 38 standard contract may subsequently be blacklisted under Article 42 if the CAC determines that the recipient's processing activities harm PRC citizens' personal information rights or national security. Once blacklisted, the processor must cease transferring personal information to the recipient, even if the standard contract remains on file and the underlying cross-border transfer would otherwise satisfy PIPL's Chapter V requirements.
The CAC has not published guidance clarifying whether blacklisting under Article 42 automatically invalidates prior security assessments or standard contract filings, or whether the processor must affirmatively withdraw the filing. Until the CAC publishes implementing regulations or enforcement decisions addressing this interaction, practitioners should treat Article 42 blacklisting as a superseding prohibition that renders any prior cross-border transfer authorization inoperative for transfers to the blacklisted entity.
Absence of published blacklist and enforcement decisions as of June 2026
As of June 2026, the CAC has not published an Article 42 blacklist or announced any entity designated under Article 42. The mechanism remains dormant in the statute. The absence of enforcement precedent does not diminish the legal risk: Article 42 is fully operative, and the CAC retains the authority to designate entities and publish the blacklist at any time without advance notice to affected parties or prior implementing regulations. A foreign processor that handles PRC citizens' personal information and falls within PIPL's Article 3 extraterritorial scope should monitor CAC announcements for Article 42 blacklist publications and assess whether its processing activities — particularly cross-border transfers to foreign governments, foreign law-enforcement authorities, or third countries subject to Article 43 countermeasures — may trigger designation.
Practitioners advising multinational clients on PIPL compliance should incorporate Article 42 blacklisting into the cross-border transfer risk assessment. The risk is heightened for processors that (1) transfer PRC personal information to jurisdictions with mandatory data-access laws (such as foreign intelligence or national-security statutes requiring disclosure to government authorities), (2) operate in sectors the PRC government views as sensitive (telecommunications, social media platforms, location services, health data, genetic data, or biometric data), or (3) are headquartered in or controlled by entities in jurisdictions the PRC government has publicly criticized for discriminatory data-protection or national-security measures.
Relationship to the Data Security Law Article 2 and the Unreliable Entity List
PIPL Article 42 is part of a broader suite of PRC extraterritorial enforcement tools. The Data Security Law (DSL), which entered into force on September 1, 2021 (two months before PIPL), provides in Article 2 that where data processing activities outside the territory of the People's Republic of China harm the national security, public interests, or legitimate rights and interests of citizens or organizations of the People's Republic of China, legal liability shall be pursued in accordance with law. DSL Article 2 establishes territorial jurisdiction for data-harm claims but does not create an explicit blacklist mechanism analogous to PIPL Article 42.
The Ministry of Commerce's Provisions on the Unreliable Entity List (effective September 19, 2020) authorize the designation of foreign entities, organizations, or individuals that endanger China's national sovereignty, security, or development interests, or that violate normal market transaction principles and cut off supply to Chinese enterprises or discriminate against Chinese enterprises. The Unreliable Entity List is a separate designation framework administered by the Ministry of Commerce (not the CAC), with different triggers (supply-chain disruption and discrimination rather than personal information processing) and different consequences (export restrictions, import restrictions, prohibition on investment, and work-permit restrictions for responsible individuals).
PIPL Article 42 and the Unreliable Entity List may overlap for entities whose conduct satisfies both sets of triggers. A foreign technology company that processes PRC citizens' personal information in violation of PIPL and simultaneously cuts off supply of technology services to PRC customers under foreign sanctions may be designated on both the Article 42 blacklist (by the CAC) and the Unreliable Entity List (by the Ministry of Commerce). The designations are independent and cumulative; placement on one list does not require or preclude placement on the other.
Source: Personal Information Protection Law of the People's Republic of China, Art. 42 Source: Personal Information Protection Law of the People's Republic of China, Art. 43 Source: Personal Information Protection Law of the People's Republic of China, Art. 3 Source: Personal Information Protection Law of the People's Republic of China, Art. 41
Enforcement procedure under PIPL — investigation process, due process rights, and administrative appeal mechanisms (Articles 62–65)
The Personal Information Protection Law (PIPL) sets out core procedures for administrative enforcement in Articles 62 through 65, with important due process and appeal mechanisms supplemented by the Administrative Penalty Law of the People’s Republic of China (APL, 行政处罚法). For compliance teams and counsel facing a PIPL investigation, the statutory framework divides into four principal stages: (1) investigation initiation and notification, (2) investigatory powers and procedural protections, (3) hearing and defense, and (4) service of decision and rights of appeal.
1. Initiation and notification
Article 62 PIPL authorizes departments with personal information protection duties to investigate suspected violations, but the law is silent on specific triggers (complaints, referrals, etc.). According to APL Article 36, when an authority initiates an investigation, it must generally notify the investigated party—unless notification would interfere with the case, in which case notification may be delayed (APL Art. 37).
2. Investigatory powers and procedural rights
Article 63 PIPL permits the authority to question parties, inspect and duplicate materials, conduct on-site inspections, and seize or freeze equipment. The investigated party has the right to present statements and defenses (APL Art. 39–42), submit evidence, and request that trade secrets remain confidential (APL Art. 40). Restrictive measures must be lifted if the justification lapses (PIPL Art. 63(2)).
3. Hearing and defense process
Article 65 PIPL requires authorities to “fully hear the statements and defenses of the parties” prior to decision, and prohibits increasing penalties because a party presents a defense. For major or complex cases (including possible heavy fines, license revocation, or suspension), a formal administrative hearing (行政听证, xíngzhèng tīngzhèng) must be offered if requested by the party (APL Art. 45). Such hearings must be conducted with a written record.
4. Written penalty decision and appeal
Penalty decisions must be delivered in writing, specifying the facts, grounds, reasoning, and informing the party of their right to apply for administrative reconsideration or to file an administrative lawsuit in a people’s court (PIPL Art. 65; APL Art. 50, 71). The party has 60 days from receipt of the decision to apply for administrative reconsideration and six months to file suit (APL Art. 74). An application for reconsideration or court action generally suspends enforcement of business license revocations and certain major penalties until the appeal is resolved (APL Art. 57).
To date, no PIPL-specific implementing regulation details the procedural timeline, manner of notice, or form of hearings beyond these statutory basics. Practitioners must therefore cross-reference the APL, which applies to all administrative penalty cases in China by default except where overridden by sectoral law.
Source: Personal Information Protection Law of the People's Republic of China, Arts. 62–65 Source: Administrative Penalty Law of the People's Republic of China, selected articles
Credit record inclusion and public disclosure under PIPL Article 67 — statutory rule and limits
Article 67 of the Personal Information Protection Law (PIPL) introduces a requirement that any violation penalized under Article 66 must be "included in credit records and disclosed to the public in accordance with relevant provisions." This extends consequences for data protection violations beyond administrative fines by mandating reputational transparency and recordation in official government-managed credit records.
Credit record inclusion Article 67 directs the supervising authority to log PIPL-related administrative penalties in applicable "credit records" (信用记录), referencing government-managed systems that document compliance histories of organizations and individuals. The law does not specify the name or nature of these records, nor does it define their operational impact, duration, or process for removal. The only certainty is that these violations are reportable events that may appear in whatever credit or reputational systems are in force "in accordance with relevant provisions."
Public disclosure The same article requires the responsible authority to "disclose to the public" information about PIPL enforcement actions, again leaving implementation to unspecified "relevant provisions." The statute does not specify the channel (such as government websites, databases, or notices), the format, or the timeline. It also does not clarify what information—such as names of responsible persons or exact nature of the violation—must be disclosed. In practice, agencies may publish administrative penalty decisions on their official websites, but PIPL Article 67 itself is silent on process, scope, and duration.
Unsettled points as of June 2026 No PIPL-implementing regulation or judicial interpretation provides greater specificity on the credit record or public disclosure process as of June 2026. Article 67 does not define the effect of entry into a credit record, the rights of affected entities or persons to contest or remove entries, or any minimum or maximum timeframes for record retention. As a result, the operational and reputational effects of Article 67 reporting remain uncertain and highly dependent on future regulatory guidance.
Summary A processor or responsible individual penalized for a violation under Article 66 should expect at minimum: (1) entry of the penalty in official credit records, and (2) some form of public disclosure by the enforcing authority. No further procedural or substantive details are specified in the statute as of June 2026.
Source: Personal Information Protection Law of the People's Republic of China, Art. 67
Personal prohibitions under PIPL Article 66(2) — bans on directors and personal information protection officers
Article 66(2) of the Personal Information Protection Law (PIPL), effective November 1, 2021, authorizes a powerful individual-level penalty: in cases of grave violations, the competent provincial-level (or higher) authority may prohibit the “person in charge of personal information protection” (个人信息保护负责人), directors, supervisors, senior management, and other directly responsible individuals from holding such posts for a specified period. This ban targets persons found to bear direct responsibility for the violation—including, but not limited to, C-suite executives, legal representatives, and designated data protection officers under PIPL Chapter VI.
Scope of authority and procedural preconditions
Unlike administrative fines or warnings (which can be imposed by any authority at or above the county level), only departments with personal information protection duties at or above the provincial level may order this personal prohibition under Article 66(2). The statute applies when the underlying PIPL violation meets the undefined “serious circumstances” (情节严重) threshold—typically signaled by large-scale harm, recidivism, or willful obstruction of investigation (see section on penalty tiers for open points). The ban can be imposed in parallel with monetary fines and business-license suspension or revocation.
Positions subject to prohibition
Article 66(2) enumerates “the person in charge of personal information protection,” as well as “directly responsible managers” and “other directly responsible personnel.” While PIPL does not provide a formal definition of each role, regulatory guidance and CAC enforcement practice generally include legal representatives, CEOs, directors, compliance officers, operational managers with oversight of personal information processing, and others with active decision-making authority. If imposed, the prohibition extends across all enterprises in China—it is not limited to the original violating company.
Duration and scope of ban
PIPL leaves the maximum duration of the personal prohibition at the discretion of the enforcing authority; there is no statutorily-fixed timeframe or minimum. The order must specify the period of prohibition and the posts covered. Affected persons may seek administrative review or file a court action under PIPL Article 65 and the Administrative Penalty Law (see section on enforcement procedure for details).
Practical application: Didi case
In the July 2022 CAC penalty decision against Didi Global Inc., the company's chairman and president each received RMB 1 million personal fines as “directly responsible persons,” but public records as of June 2026 do not show use of the director/protection officer ban. No published CAC decision demonstrates the imposition of this ban under Article 66(2) as of the current date.
Unsettled points (as of June 2026)
- No implementing regulation or judicial interpretation provides substantive criteria or procedural detail for this prohibition.
- No public list of banned persons, maximum duration, or guidance on rehabilitation or appeal rights (beyond general administrative remedy provisions) has been published.
- Practitioners advising clients should flag the risk as real—but the details of enforcement remain undefined.
Source: Personal Information Protection Law of the People's Republic of China, Art. 66
Enforcement under the Data Security Law (DSL) — penalty tiers, sectoral overlays, and coordination with PIPL enforcement
China's Data Security Law (DSL), effective September 1, 2021, operates alongside the Personal Information Protection Law (PIPL) but covers a broader category of "data" beyond personal information—including business, industrial, and other forms of non-personal data. The DSL establishes its own enforcement and penalty regime, giving the Cyberspace Administration of China (CAC), the Ministry of Public Security (MPS), and other sectoral regulators explicit sanctioning powers. For multinational entities, understanding the DSL penalty structure is essential, as violations often arise from data classification or security incidents outside traditional privacy violations.
Penalty tiers and statutory maximums (DSL Chapter VI, Articles 45–48)
Article 45 of DSL provides that for ordinary data-security violations (excluding "important data" or "core data"), authorities may order correction, issue warnings, confiscate illegal gains, and impose fines up to RMB 1,000,000 on the entity and RMB 10,000–100,000 on directly responsible individuals. For refusal to correct, penalties may be doubled.
For violations involving "important data" (an undefined statutory category subject to separate CAC regulations), Article 46 provides for fines up to RMB 2,000,000 on entities and RMB 20,000–200,000 on individuals. More severe sanctions—suspension of business, revocation of business licenses—may be imposed for grave violations.
The harshest tier covers "core data" (国家核心数据), which relates to national security, lifeline infrastructure, or significant public interest per Article 21. Article 48 provides for fines up to RMB 10,000,000 on the entity and up to RMB 1,000,000 on individuals, with suspension or revocation of business licenses as possible additional measures. Where the violation constitutes a crime, criminal liability must be pursued in accordance with law—as in PIPL.
Sectoral overlays and cross-enforcement
Article 49 clarifies that where a data-security violation also infringes another law (such as PIPL), the more severe sanction applies. Sectoral regulators (such as the MIIT for telecoms or health authorities for medical data) may investigate and penalize based on their own regulatory remit. The CAC takes a coordinating role, but industry-specific overlays can substantially increase enforcement exposure.
2026 procedural developments — CAC Order No. 24 (Measures for Network Data Security Risk Assessment)
Effective August 20, 2026, the "Measures for Network Data Security Risk Assessment" (CAC Order No. 24) introduce binding risk assessment and reporting obligations for data processors, materially reinforcing enforcement of the DSL:
- Obligation: Processors of important data must conduct an annual network data security risk assessment; other processors are encouraged to assess every three years.
- Reporting: Assessment reports must be retained and, upon request, submitted to authorities within 20 working days.
- Escalation: Where significant risk is identified, CAC or other regulators may order third-party assessment or, in grave cases, order suspension or cessation of illegal data processing.
- Sectoral and multi-agency enforcement: The Measures formalize joint enforcement by CAC, MIIT, MPS, and relevant sector regulators, increasing procedural rigor and investigatory reach.
These Measures do not directly amend penalty tiers, but materially change enforcement by making risk assessment, reporting, and systematic regulatory scrutiny an operational requirement under the DSL framework as of August 2026. The escalation, reporting, and potential cease-processing powers make practical compliance and documentation newly central to risk management for organizations handling important or cross-sectoral data.
Coordination with PIPL enforcement
While DSL and PIPL enforcement frameworks are formally separate, the practical effect is cumulative: the same data-security breach can trigger administrative fines under both laws, as well as public disclosure, credit record inclusion, and—where national security or mass harm are implicated—criminal investigation under the Criminal Law. Article 48's referral mandate ensures that grave breaches (such as those affecting "core data") are transferred to police authorities for criminal investigation, just as PIPL Article 64 does for personal-information violations.
No published cases as of June 2026 definitively resolve the boundary between "data" subject only to DSL and "personal information" subject to PIPL, nor has the CAC published a categorical list of what constitutes "important data" or "core data." Entities processing large, sensitive, or cross-border data sets should treat both statutes as operative and track implementing regulations.
Source: Data Security Law of the People's Republic of China, Articles 45–49 Source: Measures for Network Data Security Risk Assessment (CAC Order No. 24, 2026, in Chinese)
Voluntary reporting, cooperation, and penalty reduction under PIPL and DSL — absence of statutory immunity, discretionary penalty mitigation, and unsettled enforcement practice
Neither the Personal Information Protection Law (PIPL, effective November 2021) nor the Data Security Law (DSL, effective September 2021) creates an explicit statutory immunity or mandatory penalty-reduction regime for entities or individuals who voluntarily disclose violations or cooperate with investigations. This stands in contrast to regimes such as the EU GDPR or US federal frameworks, where voluntary notification and cooperation may count as formal mitigating factors in the calculation of administrative penalties (see GDPR Art. 83(2)(f), US DOJ Corporate Enforcement Policy, etc.).
No explicit statutory immunity or safe harbor
PIPL and DSL are silent on safe harbor or immunity for self-reporting. PIPL Article 66 and DSL Articles 45–49 specify administrative penalties, corrective orders, and personal liability, but do not condition penalty calculation on voluntary disclosure or cooperation. Article 62 (PIPL) and Article 46 (DSL) empower the Cyberspace Administration of China (CAC) and other sectoral authorities to conduct investigations and impose sanctions but do not provide an affirmative defense or penalty waiver for proactive reporting. There is no statutory equivalent to US or EU leniency programs or whistleblower-protection statutes covering privacy or data-security law in China as of June 2026.
Discretionary penalty mitigation — administrative enforcement practices
While no immunity is articulated in statute, Chinese administrative law permits regulatory authorities to consider "circumstances of the violation" and the "handling attitude of the party" (处理态度) in deciding whether to reduce, remit, or suspend penalties. Article 27 of the Administrative Penalty Law of the People’s Republic of China (APL, 行政处罚法, as amended 2021) allows authorities to impose lighter or mitigated penalties where parties "take the initiative to eliminate or reduce the harmful consequences of the illegal act," or "voluntarily confess illegal acts" before being discovered. Article 32 further empowers authorities to "reduce or exempt administrative penalties" in certain circumstances, including voluntary correction, restitution, or significant assistance to enforcement. These general administrative-penalty mitigation provisions apply to PIPL and DSL enforcement by default, unless overridden by sectoral law. To date, the CAC and other personal information protection authorities have not published detailed guidance or enforcement precedents specifying the weight given to self-reporting or cooperation in privacy or data-security cases. Practitioners advising multinational companies or local processors should reference the APL mitigation language but should not rely on exemption from fines or director bans without agency confirmation.
Whistleblower protections — absence under PIPL/DSL
Neither PIPL nor DSL contains provisions directly protecting employees, contractors, or third parties who report violations internally or to authorities ("whistleblowers"). No statutory right against retaliation or guarantee of anonymity exists specific to data protection law in China as of June 2026. While certain sectoral anti-retaliation frameworks exist under labor law, these do not extend directly to privacy, security, or data law whistleblowing.
Summary
- No explicit immunity or safe harbor for voluntary self-reporting under PIPL or DSL.
- Administrative authorities have broad discretionary power under the Administrative Penalty Law to reduce or waive penalties for entities or individuals who admit violations, proactively correct harm, or assist with investigation.
- The effect of disclosure or cooperation is untested and not articulated in sectoral guidance. Caution is warranted until more practice emerges.
- No statutory whistleblower protection for PIPL/DSL-related reporting as of June 2026.
Source: Personal Information Protection Law of the People's Republic of China, Arts. 62, 66 Source: Data Security Law of the People's Republic of China, Arts. 46–49 Source: Administrative Penalty Law of the People's Republic of China, Arts. 27, 32
Publication of PIPL penalty decisions — legal disclosure requirements and government publication practice
Chinese supervisory authorities publish administrative penalty decisions following significant enforcement actions under the Personal Information Protection Law (PIPL). This practice draws from both a statutory requirement for public disclosure and established administrative procedures, but the scope and details of publication primarily depend on agency custom rather than fully harmonized rules.
Statutory requirements (PIPL Article 67, APL Article 49)
PIPL Article 67 states: "Where an administrative penalty is imposed for violation of this Law, the information shall be incorporated into credit records and disclosed to the public in accordance with relevant provisions." However, PIPL does not specify what details must be included in such disclosures or how they should be published.
The Administrative Penalty Law (APL) Article 49 requires: "Administrative organs shall promptly inform the party of any administrative penalty decision, and major administrative penalty decisions shall be disclosed to the public in accordance with law." Neither Article 67 nor Article 49 defines which specific information—such as names of individuals, full case details, or specific penalty amounts—must be published or redacted. The language "in accordance with law" signals that further detail is left to subsequent regulations or sectoral rules, which remain incomplete as of June 2026.
Practical publication and CAC enforcement practice
In practice, the Cyberspace Administration of China (CAC) and its provincial and municipal branches regularly publish the text of penalty decisions on official websites, most often listing:
- The penalized company’s full name
- Description of the violation and legal basis
- The penalties imposed (including fines and suspensions)
- Sometimes, the names and roles of responsible individuals
High-profile penalties (such as those in the Didi Global case) have included both the company and upper management by name. There is no statutory requirement for or against disclosing individual names, and redaction practices vary by case and authority. No national regulation clarifies retention periods, required depth of detail, or any mandatory redaction protocols for personal data of individuals named in penalty notices as of June 2026.
Penalty decisions are typically found on the CAC website (http://www.cac.gov.cn) under “Notices” (通知公告) or similarly labeled sections, and on regional cyberspace administration sites. These publications serve as official records, but the exact mechanics are shaped as much by custom as by law.
Unable to confirm as of 2026-06-16 whether new national regulations have standardized detail, retention, or redaction requirements for PIPL penalty publications beyond the general mandates in PIPL Article 67 and APL Article 49.
Source: Personal Information Protection Law of the People’s Republic of China, Art. 67 Source: Administrative Penalty Law of the People’s Republic of China, Art. 49 Source: Cyberspace Administration of China — Penalty Decision Publication Portal
Penalty calculation under PIPL and the Administrative Penalty Law — aggravating and mitigating factors, “handling attitude,” and enforcement discretion
Penalty calculation for violations of the Personal Information Protection Law (PIPL) is a hybrid of explicit statutory caps (PIPL Article 66) and discretionary adjustment under the Administrative Penalty Law (APL, 行政处罚法). PIPL sets the outer bounds, but the enforcement authority — most often the Cyberspace Administration of China (CAC) — uses the APL to calibrate the penalty by weighing the facts of each case, including both statutory and observed factors.
APL Articles 27 and 32 — statutory grounds for adjustment APL Article 27 authorizes regulatory authorities to "impose a lighter or mitigated administrative penalty" if the violator "voluntarily eliminates or mitigates harmful consequences" or "voluntarily confesses the illegal act before discovery by the authority." Article 32 permits authorities to reduce or exempt the penalty for prompt confession, voluntary correction, providing important leads, or assisting the investigation, so long as any statutory minimum is respected. These provisions apply to PIPL enforcement by default where PIPL is silent on penalty-calculation specifics. [APL Art. 27, 32]
How authorities weigh aggravating and mitigating factors PIPL Article 66 states maximum monetary penalties for ordinary violations (up to RMB 1 million) and for grave violations (up to RMB 50 million or 5% of turnover), but does not spell out factors for the precise penalty within these bands. In practice, CAC and other authorities have referenced the APL when explaining mitigated or aggravated outcomes. Based on published decisions and regulatory custom (not black-letter law), aggravating factors may include: large scale of affected individuals, processing of sensitive personal information (PIPL Art. 28), obstruction of investigation (PIPL Art. 63), recidivism, or intentional/profitable misconduct. Mitigating factors, as evidenced in penalty decisions, include voluntary admission, proactive cessation and correction, demonstrable lack of harm, restitution to affected data subjects, and full cooperation. [Observed in CAC penalty announcements and supported by APL discretionary language]
The "handling attitude" (处理态度) — an established term in Chinese administrative jurisprudence, reflecting how forthcoming and cooperative the company is during the process — often influences the penalty imposed, though no statute lists this expressly. This is a well-recognized factor in regulatory decision-writing, with authorities crediting positive attitudes by referencing Article 27 or 32 when explaining a reduced fine.
Summary
- Explicit in law: Voluntary confession, prompt correction, cooperation — grounds for lighter penalty (APL Art. 27, 32).
- Observed in practice: Scale and sensitivity of impact, recidivism, profit motive, obstruction, and "handling attitude" are considered in regulatory decisions, but not codified in PIPL.
- No CAC guidance: As of June 2026, there is no official sector-specific list of factors, and penalty calculation remains at the discretion of the enforcing authority, bounded by Article 66 caps and the APL’s mitigation framework.
Source: Administrative Penalty Law of the People’s Republic of China, Articles 27, 32 Source: Personal Information Protection Law of the People’s Republic of China, Article 66
Leniency and Defenses to Liability under PIPL and DSL — statutory defenses, force majeure, and impossibility
Neither the Personal Information Protection Law (PIPL, effective November 2021) nor the Data Security Law (DSL, effective September 2021) contains a dedicated provision establishing affirmative statutory defenses that exempt a personal information processor from administrative, civil, or criminal liability for violations. While both laws set out a penalty regime and mechanisms for the reduction or mitigation of penalties (see APL Article 27, 32), they do not articulate specific substantive defenses, such as force majeure (不可抗力) or impossibility, that would absolve the processor of liability altogether.
Absence of enumerated statutory defenses A close reading of PIPL reveals that the statute does not contain language parallel to force majeure, necessity, or impossibility exceptions familiar from civil or tort law traditions. Article 66 (administrative penalties), Article 69 (civil liability), and Article 71 (criminal liability) predicate liability on proof of violation, with no express carve-outs for scenarios such as loss of control due to technical impossibility, third-party sabotage, legal compulsion from a foreign jurisdiction, or other extenuating circumstances. Similarly, the DSL sets penalty tiers and links criminal liability to the gravity of a breach, without providing for statutory excuses based on force majeure or impossibility.
Mitigation and reduction: distinction from defenses Practitioners should distinguish between penalty mitigation (reduction or exemption of fines or sanctions, per APL Art. 27–32) and complete defenses to liability. While the Administrative Penalty Law (APL) empowers authorities to reduce or exempt penalties where the party confesses, eliminates consequences, or otherwise demonstrates good faith, such mitigation does not constitute a defense—the underlying violation remains confirmed. APL does allow consideration of “the circumstances of the violation” in the penalty determination, but only within the bounds of confirmed factual liability.
Civil law cross-reference: Civil Code force majeure Chinese Civil Code Article 180 defines force majeure as "an objective situation that is unforeseeable, unavoidable, and insurmountable," which may relieve liability for contract or tort obligations in civil disputes. Article 69 PIPL does not expressly incorporate the force majeure principle, but general civil liability doctrines may arguably apply to tort litigation initiated under PIPL where the violation and resulting damage are attributable to unforeseeable events—such as large-scale cyberattacks or catastrophic system failures outside the processor’s control. To date, no published court decision or authoritative administrative guidance confirms direct application of force majeure to PIPL or DSL violations as of June 2026.
Foreign legal conflicts, impossibility, and public interest exceptions PIPL is silent on legal conflicts arising from foreign court orders or mandatory foreign law that would make compliance with a CAC order impossible or unlawful for a multinational processor. While Article 36 GDPR (general legal bases) is commonly referenced by comparison, PIPL does not provide an analogous escape or conflict-of-law provision. Any such situation would likely be resolved on a case-by-case basis by the enforcing authority or, ultimately, by a PRC court.
Summary: Practitioner should not assume any enumerated statutory defense to liability under PIPL/DSL
- No explicit statutory defenses (force majeure, impossibility, foreign legal compulsion) in PIPL or DSL as of June 2026.
- Administrative authorities retain broad discretionary power to mitigate or exempt penalties on a case-by-case basis, but this is not a complete defense and does not erase liability.
- Civil Code force majeure may in theory apply in civil proceedings, but this is unconfirmed for data/privacy law claims as of this date.
- Practitioners must advise compliance based on strict-liability expectation, with only mitigation—rather than exoneration—likely available after violation.
Source: Personal Information Protection Law of the People's Republic of China, selected articles Source: Data Security Law of the People's Republic of China, selected articles Source: Civil Code of the People's Republic of China, Article 180
Sectoral enforcement overlays under PIPL — multi-regulator coordination and sector-specific penalty rules
China’s Personal Information Protection Law (PIPL) sets up a dual-layer enforcement architecture, establishing the Cyberspace Administration of China (CAC) as primary coordinator while mandating sectoral oversight and penalties through designated agencies for sector-specific risks. Article 60 explicitly requires "relevant departments of the State Council, as well as relevant departments of local governments" to perform personal information protection duties within their remit. As of mid-2026, key developments have materially expanded the scope and methods of sectoral overlays beyond what was previously in force.
Sectoral regulatory expansions in 2026
- Healthcare sector: On February 12, 2026, the National Health Commission, Ministry of Public Security, CAC, and other authorities jointly issued the "Measures for the Administration of Data Security and Personal Information Protection of Healthcare Institutions (Trial)" (effective immediately). These Measures translate PIPL, DSL, and related law into detailed requirements for hospitals and healthcare entities, including classification of personal health data, mandatory risk assessments, internal accountability requirements, and blacklists for high-risk processing. Enforcement is specifically coordinated: both health regulators and the CAC are authorized to initiate investigations and impose penalties, which may include warnings, orders to suspend or terminate data processing, and fines up to 5% of institution annual turnover for grave violations—mirroring PIPL Article 66(2) and supplementing it with sector-specific penalties such as clinical research bans and administrative designation of responsible individuals.
- AI/Interactive services sector: On April 10, 2026, CAC, the National Development and Reform Commission (NDRC), MIIT, MPS, and the State Administration for Market Regulation (SAMR) jointly promulgated the "Interim Measures for the Administration of Anthropomorphic Interactive Artificial Intelligence Services" (effective July 15, 2026). These Measures clarify that all providers of interactive AI in China must comply with PIPL and DSL, but add additional consent, transparency, and data management requirements. Multi-agency enforcement is the rule: regulatory investigations may be led by any named agency, and penalties for noncompliance (including processing, retention, or disclosure violations) include warnings, fines between CNY 10,000 and CNY 200,000 (or higher for serious violations), forced suspension or delisting, and bans on responsible personnel holding data-related roles. The Measures are enforceable directly by sectoral agencies or in joint commissions, and specify that the highest penalty from the applicable law (PIPL, DSL, or the Measures) applies.
General principle (unamended):
- Day-to-day privacy supervision and penalty imposition in sensitive sectors—healthcare, finance, AI, communications—often originate in the relevant sectoral regulator, with escalation to the CAC for cross-sectoral, large-scale, or national-security incidents. Article 74 PIPL continues to require that stricter sectoral rules generally override baseline PIPL rules, and penalty ceilings are set by whichever law or regulation imposes the stricter consequence for the same conduct.
- Entities facing regulatory investigations in 2026 must review both PIPL/DSL and sector-specific measures to assess total penalty and compliance risk, as sector rules may introduce not just higher fines but new administrative sanctions (e.g., blacklists, delisting from app stores, professional bans) not previously available under the PIPL framework.
No unified guidance or official compilation of cross-sector penalty cases exists as of June 2026. Practitioners must now track evolving sectoral measures and multi-agency penalty announcements for complete risk assessment.
Source: Personal Information Protection Law of the People’s Republic of China, Art. 60, Art. 74 Source: Measures for the Administration of Data Security and Personal Information Protection of Healthcare Institutions (Trial), NHC/CAC/MPS, Feb. 2026 Source: Interim Measures for the Administration of Anthropomorphic Interactive Artificial Intelligence Services, CAC et al., Apr. 2026
Appeal and Remedies After a PIPL/DSL Penalty Decision — Administrative Reconsideration, Judicial Review, and Suspension of Enforcement
China’s Personal Information Protection Law (PIPL) and Data Security Law (DSL) channel challenges to penalty decisions (such as fines, director bans, or business suspensions) through the general administrative review system, primarily structured by the Administrative Reconsideration Law (行政复议法, 2023 revision, effective Jan. 1, 2024) and the Administrative Procedure Law (行政诉讼法, as amended 2021). These statutes set out two main procedural paths: administrative reconsideration (复议) as the ordinary first step, followed by judicial review (诉讼) before a people's court.
1. Administrative reconsideration (行政复议) A party may, within 60 calendar days of receiving a penalty decision, apply for administrative reconsideration to the issuing department or its superior (Art. 32, 2023 Reconsideration Law). For CAC or sectoral agency enforcement, this is commonly the original agency or its next-higher authority. The act of filing a reconsideration application does NOT automatically suspend enforcement; authorities may order suspension only for defined reasons, such as to prevent irreparable harm (Art. 35). In practice, unless a suspension order is granted, entities must pay fines and comply with non-monetary penalties during review.
2. Administrative litigation (行政诉讼) A party not satisfied with the reconsideration result, or who receives no response within the statutory period (generally 60 days), may sue in a basic-level people’s court within 15 calendar days of receiving the decision (Art. 46, Reconsideration Law; Art. 46, Administrative Procedure Law). Courts may suspend penalty enforcement only if specific statutory conditions are met—such as risk of irreparable harm to lawful rights and interests, or where the penalty concerns property preservation or other urgent need (Administrative Procedure Law, Art. 50). Judicial review addresses the legality and appropriateness of the sanction and may uphold, amend, or annul the penalty. Notably, direct judicial review (bypassing reconsideration) is sometimes permitted for certain types of penalties or acts, but this is rare for ordinary PIPL/DSL enforcement (Administrative Procedure Law, Art. 49).
3. Timelines and practical points
- 60 calendar days to request reconsideration from service of penalty decision
- 15 calendar days to sue after a reconsideration result or expiry of agency period
- Neither appeal step automatically suspends enforcement; agency or court suspension requires specific application and statutory grounds
No PIPL/DSL-specific appellate divergence as of June 2026 There is no published evidence of supplemental or expedited appellate procedures unique to PIPL or DSL enforcement as of June 2026. Practitioners must rely on the general administrative framework. Where multiple authorities are involved (sector overlays), the lead agency’s channel governs reconsideration.
Note on sources: As of 2026-06-17, an official English translation of the 2023 revision of the Administrative Reconsideration Law was not available on the NPC or State Council English sites; links provided refer to the most recent official postings, but may not reflect the absolute latest text. Use the Chinese-language version for operational accuracy.
Source: Administrative Reconsideration Law of the People’s Republic of China (2023 revision, Chinese) Source: Administrative Procedure Law of the People’s Republic of China (Chinese)