Skip to content
Esta e uma traducao de conveniencia. A versao em ingles e a versao oficial e legalmente vinculativa. Ver versao em ingles
CNDEEP coverage1 enforcement action

China Personal Information Protection Law (PIPL): AI Compliance Requirements

China's Personal Information Protection Law (PIPL, effective November 1, 2021) is China's primary personal data protection law, comparable in scope to GDPR but with distinct Chinese characteristics. PIPL directly affects AI systems by: requiring consent for AI profiling, mandating transparent disclosure of automated decision-making, prohibiting unreasonable differentiated treatment (pricing discrimination), and imposing strict cross-border data transfer restrictions. Non-compliance can result in fines up to ¥50M (≈$7M USD) or 5% of annual revenue, and service suspension.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

November 1, 2021

Maximum Penalty

¥50,000,000 or 5% of annual revenue (whichever is higher); service suspension; individual liability for responsible persons up to ¥1,000,000

What Your Business Must Do

5 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Automated Decision-Making Transparency (Art. 24)

Critical

When using personal information for automated decision-making (AI-driven personalization, behavioral profiling, price differentiation), provide individuals with a clear and transparent explanation of the logic and rules used. Individuals must be able to request human review of decisions that significantly affect their interests.

Deadline: November 1, 2021

PIPL Art. 24

No AI-Driven Price Discrimination

Critical

Prohibited under PIPL Art. 24: using AI to offer different prices, service terms, or conditions to individuals based on their personal information profiles, in ways that constitute unreasonable differentiated treatment. This specifically targets dynamic pricing algorithms that discriminate against returning customers or based on behavioral profiling.

Deadline: November 1, 2021

PIPL Art. 24(3)

Consent for AI Behavioral Profiling

Critical

Obtain explicit informed consent before processing personal information for AI behavioral profiling, targeted advertising, or personalized recommendation services. Consent must be separate from general terms of service, voluntary, and withdrawable. Users must be able to opt out of profiling without losing access to basic service.

Deadline: November 1, 2021

PIPL Art. 13, 15

Cross-Border Data Transfer Compliance

Critical

Transfer of Chinese personal information outside China (including uploading to non-Chinese AI APIs/servers) requires: (1) CAC security assessment (for important data or large volumes); (2) PIPL-compliant standard contract; or (3) certification by approved institution. Cannot transfer Chinese personal information to overseas AI processing without one of these mechanisms.

Deadline: June 1, 2023

PIPL Art. 38-40

Personal Information Protection Officer (Large Processors)

High Priority

Organizations processing personal information of 1 million+ individuals must appoint a Personal Information Protection Officer (PIPO). PIPO oversees PIPL compliance including AI data processing. Contact information must be published. Name and contact must be submitted to relevant authorities.

Deadline: November 1, 2021

PIPL Art. 52

Who Does This Apply To?

Extraterritorial reach: applies to processing of personal information of persons within China regardless of where the processing entity is located. Two bases for extraterritorial application: (1) providing products or services to persons in China; (2) analyzing the behavior of persons in China. AI-specific: PIPL Art. 24 specifically addresses automated decision-making — businesses using AI for personalized recommendations, targeted advertising, or behavioral profiling of Chinese users must comply.

Recent Enforcement Actions

Cyberspace Administration of China (CAC)2022-07-21¥8,026,000,000 (≈$1.2B USD); additionally ¥1,000,000 personal fines each on Chairman/CEO Cheng Wei and President Liu Qing.Source verified· as of 2026-08-22

Against: DiDi Global Inc.

CAC announced (21 July 2022) an ¥8.026B fine against DiDi for PIPL/Cybersecurity Law/Data Security Law violations spanning as early as June 2015 through 2022, including excessive collection of user personal information (beyond what was necessary for ridesharing), inadequate consent for behavioral/location data processing, and cross-border data-handling failures. China's largest data-protection fine on record, establishing the extraterritorial reach and severity of PIPL enforcement.

Source

Recent Regulatory Guidance

rulemaking2023-06-01

CAC Standard Contract for Cross-Border Personal Information Transfer

CAC promulgated the final Measures for the Standard Contract for Cross-Border Transfer of Personal Information on 2023-02-22, effective 2023-06-01 (with a grace period to 2023-11-30 for existing transfers). Organizations transferring Chinese individuals' personal information overseas below the mandatory-security-assessment thresholds — including calling Western AI services (OpenAI, Anthropic, Azure AI) from Chinese operations — may use this "Standard Contract" mechanism (filed with the provincial CAC, plus a Personal Information Protection Impact Assessment) as an alternative to CAC security assessment or third-party certification.

Source

Key Case Law & Precedent

SAMR v. Alibaba Group (Anti-Monopoly "pick one of two")

State Administration for Market Regulation (SAMR) administrative penalty · 2021

An Anti-Monopoly Law abuse-of-dominance action (the "二选一 / pick one of two" exclusive-dealing practice), often cited alongside PIPL Art. 24 (which restricts automated decision-making used for unreasonable differential treatment on transaction terms) to illustrate China's dual competition-plus-data-protection exposure for platform pricing. Note honestly: the SAMR fine itself was an antitrust penalty, NOT a PIPL or AI-specific action, and there is no SAMR/PIPL "AI price discrimination" enforcement against a named party on public record.

Outcome: IMPOSED: ¥18.228 billion (~US$2.8B) administrative penalty (10 Apr 2021), ~4% of Alibaba's 2019 China sales — a record antitrust fine at the time; Alibaba was ordered to cease the exclusive-dealing conduct and file self-rectification reports.

Case reference

Quarterly Enforcement Digest

PIPL enforcement at full strength. The DiDi ¥8.026B fine (announced 2022-07-21) remains the benchmark for AI-adjacent data-violation severity — China's largest data-protection fine on record. No SAMR/PIPL "AI price discrimination" enforcement against a named party is on public record (see caseCitations' honest note); the real, related precedent is SAMR's 2021 antitrust fine against Alibaba for the unrelated "pick one of two" exclusive-dealing practice, not a PIPL Art. 24 automated-decision-making case. Cross-border data transfer via CAC's Standard Contract mechanism (effective 2023-06-01) is now standard for companies operating both in China and overseas using shared AI infrastructure. Key practical risk: calling Western AI APIs (OpenAI, Anthropic, Azure AI) from China-based servers with Chinese personal data requires a PIPL cross-border transfer mechanism (Standard Contract, CAC security assessment, or certification) — many Western providers do not offer PIPL-compliant contractual terms, forcing companies to use China-domestic AI models instead.

Digest covers enforcement actions, guidance, and regulatory developments. Last verified: 2026-08-22.

Industry Playbooks covering China Personal Information Protection Law (PIPL)

These industry playbooks include jurisdiction-specific checklist items and guidance for China Personal Information Protection Law (PIPL).

Frequently Asked Questions

Does China Personal Information Protection Law (PIPL) apply to my business?

China's Personal Information Protection Law (PIPL, effective November 1, 2021) is China's primary personal data protection law, comparable in scope to GDPR but with distinct Chinese characteristics. PIPL directly affects AI systems by: requiring… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under China Personal Information Protection Law (PIPL) is: ¥50,000,000 or 5% of annual revenue (whichever is higher); service suspension; individual liability for responsible persons up to ¥1,000,000. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with China Personal Information Protection Law (PIPL)?

The 5 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://www.chinalawtranslate.com/en/pipl/

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan