ComparisonChina

China PIPL vs CCPA/CPRA

Use this comparison to separate China and California scope, roles, consumer choices, assessments, transfers, breach response, and enforcement.

PIPL requires a valid processing circumstance and adds separate consent for specified activities. CCPA/CPRA applies to qualifying businesses and centers notice, consumer requests, and opt-outs from sale or sharing.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 24, 2026
Sections
1

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 24, 2026
Overview

PIPL and CCPA/CPRA require separate analyses. PIPL can apply to processing in China and specified processing outside China involving people in China. CCPA/CPRA applies to a qualifying for-profit business doing business in California, including one with more than $26,625,000 in prior-year gross revenue under the adjustment effective 1 January 2025, one that annually buys, sells, or shares the personal information of at least 100,000 consumers or households, or one that earns at least half its annual revenue from selling or sharing personal information. Test both laws before reusing notices, contracts, request workflows, or transfer controls.

Comparison

China PIPL vs CCPA/CPRA

Compare coverage, roles, processing and choice rules, sensitive data, rights, assessments, breaches, China exports, and enforcement. Apply each law independently.

Review all sources
First framework
China PIPL

Use the official PIPL text and current China transfer rules for the China conclusion.

Second framework
California CCPA/CPRA

Use the current California Civil Code and CPPA regulations for the California conclusion.

Comparison row 1

Scope trigger

China PIPL

PIPL applies to processing personal information in China. It also reaches overseas processing intended to provide products or services to people in China, analyze or assess their behavior, or meet another condition set by law or regulation.

California CCPA/CPRA

A for-profit entity doing business in California is a business if it controls collection and purpose or means and meets a threshold: more than $26,625,000 in prior-year gross revenue under the adjustment effective 1 January 2025; at least 100,000 consumers' or households' personal information bought, sold, or shared annually; or at least 50% of annual revenue from selling or sharing personal information. Controlled entities with common branding and shared personal information, specified joint ventures, and voluntary certifiers can also qualify.

Operational implication

Record the PIPL territorial ground and the exact CCPA business threshold or relationship. Coverage under one law says nothing about coverage under the other.

Comparison row 2

Actors

China PIPL

A personal information processor decides the purpose and method. An entrusted processor handles information under an agreement that states the purpose, duration, method, categories, protection measures, and parties' rights and duties; the processor must supervise it.

California CCPA/CPRA

A business determines purpose and means. Service-provider and contractor status depends on a qualifying written contract and use restrictions; a recipient that does not meet those terms may be a third party. The label in a vendor agreement does not control the statutory result.

Operational implication

Classify the actual data flow under both laws, then use the contract clauses required for each role.

Comparison row 3

Collection and choice

China PIPL

Article 13 permits processing under consent or listed non-consent circumstances, including necessity to conclude or perform a contract with the individual, human-resources necessity under lawfully formulated employment rules or a lawfully concluded collective contract, legal duties, emergencies, specified news and public-interest activities, and reasonable processing of lawfully public information. Separate consent applies to specified disclosures, sensitive personal information, and overseas provision.

California CCPA/CPRA

A business must give notice at or before collection, limit collection, use, retention, and sharing to what is reasonably necessary and proportionate, and honor applicable opt-outs from sale or sharing. Consent is required for some later incompatible uses and opt-in situations, but the CCPA is not organized around a general lawful-basis list.

Operational implication

Map every purpose to PIPL Article 13 and separately identify the California notice, opt-out, limit, or consent requirement.

Comparison row 4

Sensitive information

China PIPL

Sensitive personal information is information that, if leaked or illegally used, can readily harm dignity or personal or property safety. PIPL lists biometrics, religious belief, specific identity, medical health, financial accounts, location tracking, and information of children under 14. Processing requires a specific purpose, sufficient necessity, strict safeguards, additional notice, separate consent, and a PIPIA.

California CCPA/CPRA

Sensitive personal information is a defined list that includes specified identifiers and credentials, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, certain communications, genetic data, and neural data, as well as some account, health, sex-life, sexual-orientation, biometric, and child data. The right to limit applies only to uses or disclosures outside listed permitted purposes and statutory exceptions.

Operational implication

Maintain two classification fields and record whether the California limit right applies; do not assume that either list contains the other.

Comparison row 5

Individual rights

China PIPL

Individuals have rights to know and decide, restrict or refuse processing, access and copy, correct, and delete, subject to statutory conditions. For a decision with a major effect made solely through automated decision-making, an individual may request an explanation and refuse a decision made only that way. Processors must provide a convenient request mechanism and may reject a request only with reasons; the individual may sue.

California CCPA/CPRA

Consumers have rights to know or access, delete, correct, opt out of sale or sharing, limit specified sensitive-information use or disclosure, and receive equal treatment. A business generally has 45 days to answer a verifiable request to know, delete, or correct, with one additional 45-day extension when reasonably necessary and timely notice is given. Opt-out and limit requests follow separate rules and generally may not require verification.

Operational implication

Use one intake channel only if it preserves the correct identity standard, exception, deadline, appeal or explanation, and response record for each law.

Comparison row 6

Assessments and governance

China PIPL

Article 55 requires a PIPIA before processing sensitive personal information, using personal information in automated decision-making, entrusting processing, providing information to another processor, publicly disclosing it, exporting it, or carrying out other processing with a major effect on individuals. The assessment must address legality, necessity, effects, risks, and safeguards; the report and record must be kept for at least three years. Article 54 separately requires regular compliance audits.

California CCPA/CPRA

California regulations effective January 1, 2026 require risk assessments for specified processing presenting significant risk, annual cybersecurity audits for businesses meeting the regulatory tests, and notices and rights for specified automated decisionmaking technology uses. The triggers and phased dates differ by duty; processing begun before 2026 and continuing afterward has a December 31, 2027 risk-assessment deadline.

Operational implication

Reuse system descriptions and risk evidence, but keep separate legal triggers, required content, approval, retention, submission, and deadline records.

Comparison row 7

Security incidents and private claims

China PIPL

If personal information is or may be leaked, altered, or lost, the processor must immediately take remedial measures and notify the authorities and individuals with the information listed in Article 57. Individual notice may be omitted if the processor can effectively avoid harm, but an authority may still require it.

California CCPA/CPRA

The CCPA does not create a general regulator-notification deadline equivalent to PIPL Article 57. Its limited private right of action covers specified nonencrypted and nonredacted personal information exposed through a failure to maintain reasonable security, with statutory damages of $107-$799 per consumer per incident under the adjustment effective 1 January 2025, or actual damages, whichever is greater, subject to the statute's conditions. Other California breach-notification laws may apply separately.

Operational implication

Use the incident record to run PIPL notification, California security-breach liability, and any separate California breach-notice analysis; do not infer one result from another.

Comparison row 8

Cross-border transfer

China PIPL

Before overseas provision, PIPL generally requires recipient notice, separate consent, a PIPIA, and one Article 38 route unless a current exemption applies. Under the 2024 provisions, non-critical-information-infrastructure operators generally use a standard contract or certification when they export personal information of at least 100,000 but fewer than 1 million individuals, excluding sensitive personal information, or sensitive personal information of fewer than 10,000 individuals, counted from 1 January of the current year. A CAC assessment is required for critical information infrastructure operators, important data, personal information of at least 1 million individuals excluding sensitive personal information, or sensitive personal information of at least 10,000 individuals, subject to stated exemptions.

California CCPA/CPRA

CCPA/CPRA has no national data-export mechanism equivalent to China's CAC routes. A disclosure can still be a sale or sharing, or be governed by service-provider or contractor terms, regardless of whether the recipient is in California, another state, or another country.

Operational implication

Classify the California disclosure and separately select and document the China export route. A CCPA service-provider contract is not the CAC standard contract.

Comparison row 9

Enforcement and maximum penalties

China PIPL

For a serious PIPL violation, the responsible authority may order correction, confiscate unlawful gains, and impose up to RMB 50 million or 5% of the prior year's turnover. It may also suspend business, revoke permits or a business license, and fine or disqualify responsible individuals. Lesser violations have a different penalty tier.

California CCPA/CPRA

The CPPA may seek an administrative fine of up to $2,663 per violation or $7,988 per intentional violation or violation involving personal information of a consumer the respondent actually knows is under 16 under the adjustment effective 1 January 2025. The Attorney General may seek civil penalties at the same adjusted per-violation amounts under the statute. The limited private action for specified security breaches is separate.

Operational implication

Do not compare headline figures as equivalent exposure; the unit of violation, turnover base, facts, enforcement route, and available orders differ.

Section 1

How to use this comparison

Start with scope, then assign the legal role for each data flow. Under PIPL, the organization that decides the purpose and method is the personal information processor. California instead distinguishes a business, service provider, contractor, and third party. Similar vendor relationships can produce different roles and contract terms.

Next, document the processing rule and consumer control. PIPL Article 13 lists consent and non-consent circumstances, while separate consent applies to specified disclosures, sensitive personal information, and overseas provision. California requires notice at or before collection and, where applicable, opt-outs from sale or sharing and limits on certain uses or disclosures of sensitive personal information.

Run the assessment, incident, and transfer tests separately. A PIPL personal information protection impact assessment (PIPIA) is required before listed high-risk activities. California's regulations effective January 1, 2026 add risk-assessment, cybersecurity-audit, and automated decisionmaking technology duties for covered activities and businesses, with phased compliance dates. China also has a separate export-route analysis; a California service-provider contract does not satisfy it.

  • Record why each entity is or is not covered, including the California threshold used.
  • Map each data flow to a PIPL processing circumstance and the applicable California notice or choice.
  • Keep separate request deadlines, exceptions, identity checks, and response records.
  • For China exports, count volumes from January 1 of the current year and check important-data and critical-information-infrastructure status before selecting an exemption, standard contract or certification, or CAC security assessment.
Primary sources

References and citations

cppa.ca.gov
Referenced sections
  • California's 2026 regulations set distinct triggers and phased compliance provisions.
cac.gov.cn
Referenced sections
  • Use for assessment self-assessment, filing materials, review procedure and reapplication triggers; use the 2024 provisions for current exemptions, thresholds and validity.
Related guides

Explore more topics

App minimum necessary personal information by category
App category mapping page for common mobile app necessary personal information scope, using only categories supported by the official source.
China app personal information minimization
How to map app category, basic functions, and necessary personal information under China mobile app personal-information rules.
China data export security assessment workflow
Workflow for screening data export security assessment triggers, materials, owners, and evidence records.
China personal information cross-border transfer routes
Compare China's current data-export exemptions, CAC security assessment, standard contract, and personal information protection certification routes.
China personal information standard contract filing workflow
Workflow for the PIPL standard contract route, assessment, filing package, and cited evidence.
China PIPL compliance checklist
China PIPL compliance checklist covering scope, processing bases, notices, sensitive information, rights, vendors, impact assessments, incidents, and exports.
China PIPL deadlines and compliance calendar
Calendar China PIPL effective dates, recurring audits, privacy-officer reporting, impact-assessment retention, and data export filing and renewal deadlines.
China PIPL penalties and enforcement exposure
Understand PIPL corrective orders, serious-violation fines, responsible-person exposure, civil claims, public-interest actions, and data export enforcement.
China PIPL privacy notice and consent checklist
China PIPL checklist for privacy notices, valid consent, separate consent, sensitive information, children under 14, withdrawal, and rights requests.
China PIPL requirements
China PIPL requirements from scope and processing basis through notices, rights, security, impact assessments, incidents, vendors, and data exports.
China PIPL vs EU GDPR: Requirements Compared
Compare PIPL and GDPR scope, roles, legal bases, rights, impact assessments, breach deadlines, international transfers, and penalties.
China PIPL vs Singapore PDPA: Requirements Compared
Compare PIPL and Singapore PDPA scope, roles, consent alternatives, rights, breach duties, overseas transfers, and penalties.
China Privacy Law FAQ
Practical answers on China's PIPL: scope, legal bases, sensitive information, separate consent, vendors, PIPIA records, app minimization, and export routes.
How should vendor contracts handle entrusted processing under PIPL?
A PIPL entrusted-processing contract must define the purpose, duration, method, personal-information categories, safeguards, and both parties' duties. See the required terms and supporting records.
Is PIPL the same as GDPR?
No. China's PIPL and the EU GDPR overlap on core privacy controls, but differ in territorial scope, legal bases, roles, sensitive data, impact assessments, and transfer routes.
PIPL automated decision-making and personalized recommendations
PIPL checks for automated decisions, personalized recommendations, marketing, differential treatment, explanations, refusal rights, and impact assessments.
PIPL breach response and notification
PIPL incident workflow for immediate remediation, authority and individual notices, the narrow individual-notice exception, vendor coordination, and evidence.
PIPL cross-border transfer route selector
Step-by-step selector for China's data-export exemptions, CAC security assessment, standard contract, and personal information protection certification.
PIPL entrusted processing and vendor contracts
How to document entrusted processing, vendor responsibilities, contract controls, and evidence under PIPL.
PIPL impact assessment template
Template fields for a China personal information protection impact assessment and export/entrusted-processing evidence.
Sensitive personal information and separate consent under PIPL
How to identify sensitive PI triggers, separate consent, minors, additional safeguards, and evidence records.
What counts as sensitive personal information in China?
PIPL uses a harm-based test for sensitive personal information and lists examples such as biometrics, health, financial accounts, location traces, and all personal information of children under 14.
What is separate consent under PIPL?
Separate consent under China's PIPL is a distinct consent for a specified processing activity. See when it applies, what notice must come first, and what evidence to keep.
What records should we keep for a PIPL impact assessment?
A PIPL impact-assessment file should preserve the Article 55 trigger, processing facts, Article 56 analysis, safeguards, decision, and processing record for at least three years.
What should an app collect as necessary personal information in China?
Match the app's basic function to China's 2021 rules and collect no more than the listed necessary personal information. Users must retain the basic function if they decline non-necessary data.
When can a company use the China standard contract route?
Use China's standard contract route only after applying the 2024 exemptions and confirming that no CAC security assessment is required. See current thresholds, filing steps, and change triggers.
When does a China PIPL security assessment apply?
A CAC data export security assessment applies to CIIO exports, important data, and specified high-volume personal-information exports after the 2024 exemptions are applied.