| Scope trigger | PIPL applies to processing personal information in China. It also reaches overseas processing intended to provide products or services to people in China, analyze or assess their behavior, or meet another condition set by law or regulation. | A for-profit entity doing business in California is a business if it controls collection and purpose or means and meets a threshold: more than $26,625,000 in prior-year gross revenue under the adjustment effective 1 January 2025; at least 100,000 consumers' or households' personal information bought, sold, or shared annually; or at least 50% of annual revenue from selling or sharing personal information. Controlled entities with common branding and shared personal information, specified joint ventures, and voluntary certifiers can also qualify. | Record the PIPL territorial ground and the exact CCPA business threshold or relationship. Coverage under one law says nothing about coverage under the other. |
|---|
| Actors | A personal information processor decides the purpose and method. An entrusted processor handles information under an agreement that states the purpose, duration, method, categories, protection measures, and parties' rights and duties; the processor must supervise it. | A business determines purpose and means. Service-provider and contractor status depends on a qualifying written contract and use restrictions; a recipient that does not meet those terms may be a third party. The label in a vendor agreement does not control the statutory result. | Classify the actual data flow under both laws, then use the contract clauses required for each role. |
|---|
| Collection and choice | Article 13 permits processing under consent or listed non-consent circumstances, including necessity to conclude or perform a contract with the individual, human-resources necessity under lawfully formulated employment rules or a lawfully concluded collective contract, legal duties, emergencies, specified news and public-interest activities, and reasonable processing of lawfully public information. Separate consent applies to specified disclosures, sensitive personal information, and overseas provision. | A business must give notice at or before collection, limit collection, use, retention, and sharing to what is reasonably necessary and proportionate, and honor applicable opt-outs from sale or sharing. Consent is required for some later incompatible uses and opt-in situations, but the CCPA is not organized around a general lawful-basis list. | Map every purpose to PIPL Article 13 and separately identify the California notice, opt-out, limit, or consent requirement. |
|---|
| Sensitive information | Sensitive personal information is information that, if leaked or illegally used, can readily harm dignity or personal or property safety. PIPL lists biometrics, religious belief, specific identity, medical health, financial accounts, location tracking, and information of children under 14. Processing requires a specific purpose, sufficient necessity, strict safeguards, additional notice, separate consent, and a PIPIA. | Sensitive personal information is a defined list that includes specified identifiers and credentials, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, certain communications, genetic data, and neural data, as well as some account, health, sex-life, sexual-orientation, biometric, and child data. The right to limit applies only to uses or disclosures outside listed permitted purposes and statutory exceptions. | Maintain two classification fields and record whether the California limit right applies; do not assume that either list contains the other. |
|---|
| Individual rights | Individuals have rights to know and decide, restrict or refuse processing, access and copy, correct, and delete, subject to statutory conditions. For a decision with a major effect made solely through automated decision-making, an individual may request an explanation and refuse a decision made only that way. Processors must provide a convenient request mechanism and may reject a request only with reasons; the individual may sue. | Consumers have rights to know or access, delete, correct, opt out of sale or sharing, limit specified sensitive-information use or disclosure, and receive equal treatment. A business generally has 45 days to answer a verifiable request to know, delete, or correct, with one additional 45-day extension when reasonably necessary and timely notice is given. Opt-out and limit requests follow separate rules and generally may not require verification. | Use one intake channel only if it preserves the correct identity standard, exception, deadline, appeal or explanation, and response record for each law. |
|---|
| Assessments and governance | Article 55 requires a PIPIA before processing sensitive personal information, using personal information in automated decision-making, entrusting processing, providing information to another processor, publicly disclosing it, exporting it, or carrying out other processing with a major effect on individuals. The assessment must address legality, necessity, effects, risks, and safeguards; the report and record must be kept for at least three years. Article 54 separately requires regular compliance audits. | California regulations effective January 1, 2026 require risk assessments for specified processing presenting significant risk, annual cybersecurity audits for businesses meeting the regulatory tests, and notices and rights for specified automated decisionmaking technology uses. The triggers and phased dates differ by duty; processing begun before 2026 and continuing afterward has a December 31, 2027 risk-assessment deadline. | Reuse system descriptions and risk evidence, but keep separate legal triggers, required content, approval, retention, submission, and deadline records. |
|---|
| Security incidents and private claims | If personal information is or may be leaked, altered, or lost, the processor must immediately take remedial measures and notify the authorities and individuals with the information listed in Article 57. Individual notice may be omitted if the processor can effectively avoid harm, but an authority may still require it. | The CCPA does not create a general regulator-notification deadline equivalent to PIPL Article 57. Its limited private right of action covers specified nonencrypted and nonredacted personal information exposed through a failure to maintain reasonable security, with statutory damages of $107-$799 per consumer per incident under the adjustment effective 1 January 2025, or actual damages, whichever is greater, subject to the statute's conditions. Other California breach-notification laws may apply separately. | Use the incident record to run PIPL notification, California security-breach liability, and any separate California breach-notice analysis; do not infer one result from another. |
|---|
| Cross-border transfer | Before overseas provision, PIPL generally requires recipient notice, separate consent, a PIPIA, and one Article 38 route unless a current exemption applies. Under the 2024 provisions, non-critical-information-infrastructure operators generally use a standard contract or certification when they export personal information of at least 100,000 but fewer than 1 million individuals, excluding sensitive personal information, or sensitive personal information of fewer than 10,000 individuals, counted from 1 January of the current year. A CAC assessment is required for critical information infrastructure operators, important data, personal information of at least 1 million individuals excluding sensitive personal information, or sensitive personal information of at least 10,000 individuals, subject to stated exemptions. | CCPA/CPRA has no national data-export mechanism equivalent to China's CAC routes. A disclosure can still be a sale or sharing, or be governed by service-provider or contractor terms, regardless of whether the recipient is in California, another state, or another country. | Classify the California disclosure and separately select and document the China export route. A CCPA service-provider contract is not the CAC standard contract. |
|---|
| Enforcement and maximum penalties | For a serious PIPL violation, the responsible authority may order correction, confiscate unlawful gains, and impose up to RMB 50 million or 5% of the prior year's turnover. It may also suspend business, revoke permits or a business license, and fine or disqualify responsible individuals. Lesser violations have a different penalty tier. | The CPPA may seek an administrative fine of up to $2,663 per violation or $7,988 per intentional violation or violation involving personal information of a consumer the respondent actually knows is under 16 under the adjustment effective 1 January 2025. The Attorney General may seek civil penalties at the same adjusted per-violation amounts under the statute. The limited private action for specified security breaches is separate. | Do not compare headline figures as equivalent exposure; the unit of violation, turnover base, facts, enforcement route, and available orders differ. |
|---|