An Overview of the Chinese “personal Information Protection Law”

Jun Yang
DOI: https://doi.org/10.3917/pinc.010.0008
2022-01-01
Abstract:The note below is intended to provide the readers with an introductory review of the scope of the application of PIPL, the fundamental rules (both general and specific) governing processing, the outbound data transfer, the rights of data subjects as well as the obligation and liabilities of the processor under the PRC PIPL. The long-awaited “PRC Personal Information Protection Law” (“PIPL”) was finally unveiled on August 20, 2021, and took effect on November 1, 2021. As the last piece of the Chinese legislative trilogy in data protection area (after “Cyber Security Law” [‘CSL”] in 2016 and “Data Security Law” [« DSL”] in June, 2021), this legislative milestone will have immediate and lasting impact on the data protection in China. PIPL which was released amid Beijing’s continued regulatory crackdown on Chinese tech giants would not only help the Chinese regulator to end the wild practices in the local market in the short term but also achieve a rebalance between commercial exploitation of personal information and protection of data subjects. PIPL will profoundly change our daily life and the way how the corporate citizens operate in China (and in overseas jurisdictions) in various fronts ranging from the design of their products/services, defining (redefining) their operating rules to internal decision-making process. This article is intended to offer you an overview of some key aspects of this new law.
What problem does this paper attempt to address?