Skip to content

AI law comparison · Data verified 2026-08-22

China PIPL vs India DPDP Act

China PIPL and India DPDP Act are two of the 169 AI and data regulations Aegis Firma tracks. They have different scopes, effective dates, and penalties — and many businesses fall under both. Here is the side-by-side, drawn directly from the regulatory registry.

Find which laws apply to my business

Side by side

Attribute
China PIPL
India DPDP Act
Region
CN
Asia Pacific
Effective date
2021-11-01
2023-08-11
Enforcement begins
2025-01-01
Who must comply
Extraterritorial reach: applies to processing of personal information of persons within China regardless of where the processing entity is located. Two bases for extraterritorial application: (1) providing products or se…
The DPDPA applies to the processing of digital personal data of Data Principals (individuals) who are in India, regardless of whether processing occurs within or outside India. Extraterritorial: a foreign SaaS company wi…
Maximum penalty
¥50,000,000 or 5% of annual revenue (whichever is higher); service suspension; individual liability for responsible persons up to ¥1,000,000
₹250 Crore (~$30M USD) maximum — but the Schedule sets DIFFERENT caps per violation type, which can stack: ₹250 Cr for failure to implement reasonable security safeguards (Sec. 8(5)); ₹200 Cr for failure to notify a breach to DPBI/Data Principals (Sec. 8(6)); ₹200 Cr for children's-data non-compliance (Sec. 9); ₹150 Cr for SDF-obligation failures (Sec. 10). The Data Protection Board must weigh mitigating/aggravating factors — penalties are not automatically set at the maximum. The previously stated "up to ₹500 Crore for repeat violations" figure could not be corroborated this cycle and has been removed.
Compliance requirements
5 tracked
5 tracked
Enforcement actions on record
1
None on record yet
Data last verified
2026-08-22
2026-08-22

Summary of publicly available regulatory text. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

The key difference

China PIPL takes effect first, so it is usually the more urgent of the two. China PIPL tracks 5 compliance requirements and India DPDP Act tracks 5. They are not interchangeable — meeting one does not discharge the other. The practical question is not which law is “stricter,” but which of them — or both — actually applies to your business.

CN

China Personal Information Protection Law (PIPL)

China's Personal Information Protection Law (PIPL, effective November 1, 2021) is China's primary personal data protection law, comparable in scope to GDPR but with distinct Chinese characteristics. PIPL directly affects AI systems by: requiring consent for AI profiling, mandating transparent disclosure of automated decision-making, prohibiting unreasonable differentiated treatment (pricing discrimination), and impos…

Full China PIPL requirements
Asia Pacific

India Digital Personal Data Protection Act 2023 (DPDPA)

India's Digital Personal Data Protection Act 2023 (DPDPA) is the most significant Indian data law since IT Act 2000. The implementing DPDP Rules were FINALIZED 2025-11-13 (CYCLE 4: previously described as still in draft) on a phased timeline — Data Protection Board of India (DPBI) establishment rules took force immediately, consent-manager rules apply from 2026-11-13, and the remaining Rules take full effect 2027-05-…

Full India DPDP Act requirements

Common questions

Could both China PIPL and India DPDP Act apply to my business?

Yes. China PIPL and India DPDP Act are separate regulations with separate scopes — a business can fall under both at once. China PIPL covers Extraterritorial reach: applies to processing of personal information of persons within China regardless of where the processing entity is located. India DPDP Act covers The DPDPA applies to the processing of digital personal data of Data Principals (individuals) who are in India, regardless of whether processing occurs within o… If your operations meet both scopes, you must comply with both. Aegis Firma's free scan checks all 169 tracked regulations against your business profile so you do not have to read each law to find out.

Which has the higher maximum penalty — China PIPL or India DPDP Act?

China PIPL: ¥50,000,000 or 5% of annual revenue (whichever is higher); service suspension; individual liability for responsible persons up to ¥1,000,000 India DPDP Act: ₹250 Crore (~$30M USD) maximum — but the Schedule sets DIFFERENT caps per violation type, which can stack: ₹250 Cr for failure to implement reasonable security safeguards (Sec. 8(5)); ₹200 Cr for failure to notify a breach to DPBI/Data Principals (Sec. 8(6)); ₹200 Cr for children's-data non-compliance (Sec. 9); ₹150 Cr for SDF-obligation failures (Sec. 10). The Data Protection Board must weigh mitigating/aggravating factors — penalties are not automatically set at the maximum. The previously stated "up to ₹500 Crore for repeat violations" figure could not be corroborated this cycle and has been removed. Penalty structures differ by regulator and violation type — read each law's full page for the cure periods and per-violation detail.

When does each law take effect?

China PIPL — effective 2021-11-01. India DPDP Act — effective 2023-08-11, enforcement from 2025-01-01. Dates last verified against official sources on 2026-08-22 and 2026-08-22 respectively.

Related comparisons

See all law comparisons

Stop guessing which laws apply

Answer a short questionnaire about your business and Aegis Firma tells you exactly which of 169 regulations apply — and what each one requires you to do.

Start free compliance scan