---
title: "China PIPL vs CCPA/CPRA: Requirements Compared"
canonical_url: "https://www.sorena.io/artifacts/apac/china-privacy-law/china-pipl-vs-ccpa-cpra"
source_url: "https://www.sorena.io/artifacts/apac/china-privacy-law/china-pipl-vs-ccpa-cpra"
author: "Sorena AI"
description: "Compare PIPL and CCPA/CPRA scope, consent and opt-out rules, rights, assessments, data exports, breach duties, and penalties."
published_at: "2026-07-05"
updated_at: "2026-07-24"
keywords:
  - "China PIPL"
  - "Personal Information Protection Law"
  - "Data export"
  - "Standard contract"
  - "App privacy"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# China PIPL vs CCPA/CPRA: Requirements Compared

Compare PIPL and CCPA/CPRA scope, consent and opt-out rules, rights, assessments, data exports, breach duties, and penalties.

*Comparison* *China*

## China PIPL vs CCPA/CPRA

Use this comparison to separate China and California scope, roles, consumer choices, assessments, transfers, breach response, and enforcement.

PIPL requires a valid processing circumstance and adds separate consent for specified activities. CCPA/CPRA applies to qualifying businesses and centers notice, consumer requests, and opt-outs from sale or sharing.

PIPL and CCPA/CPRA require separate analyses. PIPL can apply to processing in China and specified processing outside China involving people in China. CCPA/CPRA applies to a qualifying for-profit business doing business in California, including one with more than $26,625,000 in prior-year gross revenue under the adjustment effective 1 January 2025, one that annually buys, sells, or shares the personal information of at least 100,000 consumers or households, or one that earns at least half its annual revenue from selling or sharing personal information. Test both laws before reusing notices, contracts, request workflows, or transfer controls.

## China PIPL vs CCPA/CPRA

Compare coverage, roles, processing and choice rules, sensitive data, rights, assessments, breaches, China exports, and enforcement. Apply each law independently.

- **China PIPL**: Use the official PIPL text and current China transfer rules for the China conclusion.
- **California CCPA/CPRA**: Use the current California Civil Code and CPPA regulations for the California conclusion.

| Dimension | China PIPL | California CCPA/CPRA | Operational implication | Sources |
| --- | --- | --- | --- | --- |
| Scope trigger | PIPL applies to processing personal information in China. It also reaches overseas processing intended to provide products or services to people in China, analyze or assess their behavior, or meet another condition set by law or regulation. | A for-profit entity doing business in California is a business if it controls collection and purpose or means and meets a threshold: more than $26,625,000 in prior-year gross revenue under the adjustment effective 1 January 2025; at least 100,000 consumers' or households' personal information bought, sold, or shared annually; or at least 50% of annual revenue from selling or sharing personal information. Controlled entities with common branding and shared personal information, specified joint ventures, and voluntary certifiers can also qualify. | Record the PIPL territorial ground and the exact CCPA business threshold or relationship. Coverage under one law says nothing about coverage under the other. | [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - PIPL Article 3 and CCPA section 1798.140(d) require separate territorial and entity analyses.<br>[California Civil Code, Title 1.81.5 (CCPA)](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) - Section 1798.140(d) supplies the California entity and threshold test that must be applied independently of PIPL Article 3.<br>[CPPA Updated Monetary Thresholds in CCPA](https://cppa.ca.gov/regulations/cpi_adjustment.html?ref=sorena.io) - Sets the adjusted annual-gross-revenue threshold at $26,625,000 effective 1 January 2025. |
| Actors | A personal information processor decides the purpose and method. An entrusted processor handles information under an agreement that states the purpose, duration, method, categories, protection measures, and parties' rights and duties; the processor must supervise it. | A business determines purpose and means. Service-provider and contractor status depends on a qualifying written contract and use restrictions; a recipient that does not meet those terms may be a third party. The label in a vendor agreement does not control the statutory result. | Classify the actual data flow under both laws, then use the contract clauses required for each role. | [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - PIPL Articles 20-21 use role and contract rules distinct from California's statutory categories.<br>[California Civil Code, Title 1.81.5 (CCPA)](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) - California role and contract requirements do not replace PIPL Articles 20-23. |
| Collection and choice | Article 13 permits processing under consent or listed non-consent circumstances, including necessity to conclude or perform a contract with the individual, human-resources necessity under lawfully formulated employment rules or a lawfully concluded collective contract, legal duties, emergencies, specified news and public-interest activities, and reasonable processing of lawfully public information. Separate consent applies to specified disclosures, sensitive personal information, and overseas provision. | A business must give notice at or before collection, limit collection, use, retention, and sharing to what is reasonably necessary and proportionate, and honor applicable opt-outs from sale or sharing. Consent is required for some later incompatible uses and opt-in situations, but the CCPA is not organized around a general lawful-basis list. | Map every purpose to PIPL Article 13 and separately identify the California notice, opt-out, limit, or consent requirement. | [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - PIPL Articles 13-18 require their own processing-circumstance, consent, and notice analysis.<br>[California Civil Code, Title 1.81.5 (CCPA)](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) - California notice and choice rules do not satisfy a PIPL separate-consent requirement. |
| Sensitive information | Sensitive personal information is information that, if leaked or illegally used, can readily harm dignity or personal or property safety. PIPL lists biometrics, religious belief, specific identity, medical health, financial accounts, location tracking, and information of children under 14. Processing requires a specific purpose, sufficient necessity, strict safeguards, additional notice, separate consent, and a PIPIA. | Sensitive personal information is a defined list that includes specified identifiers and credentials, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, certain communications, genetic data, and neural data, as well as some account, health, sex-life, sexual-orientation, biometric, and child data. The right to limit applies only to uses or disclosures outside listed permitted purposes and statutory exceptions. | Maintain two classification fields and record whether the California limit right applies; do not assume that either list contains the other. | [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - PIPL Articles 28-32 and 55 create a category and duties distinct from California sections 1798.121 and 1798.140.<br>[California Civil Code, Title 1.81.5 (CCPA)](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) - The California category and limit right differ from PIPL Articles 28-30. |
| Individual rights | Individuals have rights to know and decide, restrict or refuse processing, access and copy, correct, and delete, subject to statutory conditions. For a decision with a major effect made solely through automated decision-making, an individual may request an explanation and refuse a decision made only that way. Processors must provide a convenient request mechanism and may reject a request only with reasons; the individual may sue. | Consumers have rights to know or access, delete, correct, opt out of sale or sharing, limit specified sensitive-information use or disclosure, and receive equal treatment. A business generally has 45 days to answer a verifiable request to know, delete, or correct, with one additional 45-day extension when reasonably necessary and timely notice is given. Opt-out and limit requests follow separate rules and generally may not require verification. | Use one intake channel only if it preserves the correct identity standard, exception, deadline, appeal or explanation, and response record for each law. | [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - PIPL Articles 24 and 44-50 require a separate rights and response analysis.<br>[California Civil Code, Title 1.81.5 (CCPA)](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) - California request scope and timing must be applied separately from PIPL Articles 44-50. |
| Assessments and governance | Article 55 requires a PIPIA before processing sensitive personal information, using personal information in automated decision-making, entrusting processing, providing information to another processor, publicly disclosing it, exporting it, or carrying out other processing with a major effect on individuals. The assessment must address legality, necessity, effects, risks, and safeguards; the report and record must be kept for at least three years. Article 54 separately requires regular compliance audits. | California regulations effective January 1, 2026 require risk assessments for specified processing presenting significant risk, annual cybersecurity audits for businesses meeting the regulatory tests, and notices and rights for specified automated decisionmaking technology uses. The triggers and phased dates differ by duty; processing begun before 2026 and continuing afterward has a December 31, 2027 risk-assessment deadline. | Reuse system descriptions and risk evidence, but keep separate legal triggers, required content, approval, retention, submission, and deadline records. | [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - PIPL Articles 54-56 control the China assessment and audit record.<br>[CPPA 2026 CCPA regulations](https://cppa.ca.gov/regulations/ccpa_updates.html?ref=sorena.io) - California's 2026 regulations set distinct triggers and phased compliance provisions. |
| Security incidents and private claims | If personal information is or may be leaked, altered, or lost, the processor must immediately take remedial measures and notify the authorities and individuals with the information listed in Article 57. Individual notice may be omitted if the processor can effectively avoid harm, but an authority may still require it. | The CCPA does not create a general regulator-notification deadline equivalent to PIPL Article 57. Its limited private right of action covers specified nonencrypted and nonredacted personal information exposed through a failure to maintain reasonable security, with statutory damages of $107-$799 per consumer per incident under the adjustment effective 1 January 2025, or actual damages, whichever is greater, subject to the statute's conditions. Other California breach-notification laws may apply separately. | Use the incident record to run PIPL notification, California security-breach liability, and any separate California breach-notice analysis; do not infer one result from another. | [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Article 57 supplies the PIPL incident-notification test.<br>[California Civil Code, Title 1.81.5 (CCPA)](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) - Section 1798.150 supplies the narrower CCPA private-action test.<br>[CPPA Updated Monetary Thresholds in CCPA](https://cppa.ca.gov/regulations/cpi_adjustment.html?ref=sorena.io) - Sets the adjusted statutory-damages range at $107-$799 per consumer per incident effective 1 January 2025. |
| Cross-border transfer | Before overseas provision, PIPL generally requires recipient notice, separate consent, a PIPIA, and one Article 38 route unless a current exemption applies. Under the 2024 provisions, non-critical-information-infrastructure operators generally use a standard contract or certification when they export personal information of at least 100,000 but fewer than 1 million individuals, excluding sensitive personal information, or sensitive personal information of fewer than 10,000 individuals, counted from 1 January of the current year. A CAC assessment is required for critical information infrastructure operators, important data, personal information of at least 1 million individuals excluding sensitive personal information, or sensitive personal information of at least 10,000 individuals, subject to stated exemptions. | CCPA/CPRA has no national data-export mechanism equivalent to China's CAC routes. A disclosure can still be a sale or sharing, or be governed by service-provider or contractor terms, regardless of whether the recipient is in California, another state, or another country. | Classify the California disclosure and separately select and document the China export route. A CCPA service-provider contract is not the CAC standard contract. | [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - PIPL Articles 38-40 and the 2024 provisions control the China export analysis.<br>[Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Use for current export exemptions, thresholds, three-year assessment validity and precedence over inconsistent older measures.<br>[California Civil Code, Title 1.81.5 (CCPA)](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) - California contract status does not satisfy PIPL Articles 38-40 or the 2024 CAC provisions. |
| Enforcement and maximum penalties | For a serious PIPL violation, the responsible authority may order correction, confiscate unlawful gains, and impose up to RMB 50 million or 5% of the prior year's turnover. It may also suspend business, revoke permits or a business license, and fine or disqualify responsible individuals. Lesser violations have a different penalty tier. | The CPPA may seek an administrative fine of up to $2,663 per violation or $7,988 per intentional violation or violation involving personal information of a consumer the respondent actually knows is under 16 under the adjustment effective 1 January 2025. The Attorney General may seek civil penalties at the same adjusted per-violation amounts under the statute. The limited private action for specified security breaches is separate. | Do not compare headline figures as equivalent exposure; the unit of violation, turnover base, facts, enforcement route, and available orders differ. | [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Article 66 uses China-specific penalty tiers and remedies.<br>[California Civil Code, Title 1.81.5 (CCPA)](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) - California uses per-violation administrative and civil penalty provisions and a limited private action.<br>[CPPA Updated Monetary Thresholds in CCPA](https://cppa.ca.gov/regulations/cpi_adjustment.html?ref=sorena.io) - Sets the adjusted administrative and civil penalty ceilings at $2,663 and $7,988 per violation effective 1 January 2025. |

Sources for Scope trigger - China PIPL:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Article 3 establishes in-China scope and the overseas product-or-service, behavior-analysis, and further-law grounds.

Sources for Scope trigger - California CCPA/CPRA:

- [California Civil Code, Title 1.81.5 (CCPA)](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) - Section 1798.140(d) defines a business and its revenue, 100,000-consumer-or-household, and 50%-of-revenue thresholds, plus covered relationships.
- [CPPA Updated Monetary Thresholds in CCPA](https://cppa.ca.gov/regulations/cpi_adjustment.html?ref=sorena.io) - Sets the adjusted annual-gross-revenue threshold at $26,625,000 effective 1 January 2025.

Sources for Scope trigger - operational implication:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - PIPL Article 3 and CCPA section 1798.140(d) require separate territorial and entity analyses.
- [California Civil Code, Title 1.81.5 (CCPA)](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) - Section 1798.140(d) supplies the California entity and threshold test that must be applied independently of PIPL Article 3.

Sources for Actors - China PIPL:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Articles 20-21 govern joint decision-makers, entrusted processing terms, sub-entrustment, supervision, and return or deletion.

Sources for Actors - California CCPA/CPRA:

- [California Civil Code, Title 1.81.5 (CCPA)](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) - Sections 1798.100(d) and 1798.140 define business, service provider, contractor, and third party and prescribe contract and use restrictions.

Sources for Actors - operational implication:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - PIPL Articles 20-21 use role and contract rules distinct from California's statutory categories.
- [California Civil Code, Title 1.81.5 (CCPA)](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) - California role and contract requirements do not replace PIPL Articles 20-23.

Sources for Collection and choice - China PIPL:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Articles 13-18 establish processing circumstances, consent and withdrawal, separate-consent overlays, and notice duties.

Sources for Collection and choice - California CCPA/CPRA:

- [California Civil Code, Title 1.81.5 (CCPA)](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) - Sections 1798.100, 1798.120-1798.121, and 1798.135 establish notice, proportionality, sale or sharing opt-out, and sensitive-information controls.

Sources for Collection and choice - operational implication:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - PIPL Articles 13-18 require their own processing-circumstance, consent, and notice analysis.
- [California Civil Code, Title 1.81.5 (CCPA)](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) - California notice and choice rules do not satisfy a PIPL separate-consent requirement.

Sources for Sensitive information - China PIPL:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Articles 28-32 define sensitive personal information, list examples including data of children under 14, and set purpose, necessity, notice, consent, and safeguard duties; Article 55 requires a PIPIA.

Sources for Sensitive information - California CCPA/CPRA:

- [California Civil Code, Title 1.81.5 (CCPA)](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) - Sections 1798.121 and 1798.140 define sensitive personal information and limit the right to specified uses and disclosures.

Sources for Sensitive information - operational implication:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - PIPL Articles 28-32 and 55 create a category and duties distinct from California sections 1798.121 and 1798.140.
- [California Civil Code, Title 1.81.5 (CCPA)](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) - The California category and limit right differ from PIPL Articles 28-30.

Sources for Individual rights - China PIPL:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Articles 24 and 44-50 establish individual rights, automated-decision protections, request mechanisms, rejection reasons, and judicial recourse.

Sources for Individual rights - California CCPA/CPRA:

- [California Civil Code, Title 1.81.5 (CCPA)](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) - Sections 1798.105-1798.135 establish consumer rights; section 1798.130(a)(2) sets the 45-day response period and possible 45-day extension.

Sources for Individual rights - operational implication:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - PIPL Articles 24 and 44-50 require a separate rights and response analysis.
- [California Civil Code, Title 1.81.5 (CCPA)](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) - California request scope and timing must be applied separately from PIPL Articles 44-50.

Sources for Assessments and governance - China PIPL:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Articles 54-56 require regular compliance audits, list pre-processing PIPIA triggers and content, and set a minimum three-year retention period.

Sources for Assessments and governance - California CCPA/CPRA:

- [CPPA 2026 CCPA regulations](https://cppa.ca.gov/regulations/ccpa_updates.html?ref=sorena.io) - The completed rulemaking took effect January 1, 2026 and implements risk-assessment, cybersecurity-audit, and automated decisionmaking technology requirements.

Sources for Assessments and governance - operational implication:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - PIPL Articles 54-56 control the China assessment and audit record.
- [CPPA 2026 CCPA regulations](https://cppa.ca.gov/regulations/ccpa_updates.html?ref=sorena.io) - California's 2026 regulations set distinct triggers and phased compliance provisions.

Sources for Security incidents and private claims - China PIPL:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Article 57 sets remedial action and authority and individual notification duties for actual or possible leaks, alteration, or loss.

Sources for Security incidents and private claims - California CCPA/CPRA:

- [California Civil Code, Title 1.81.5 (CCPA)](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) - Section 1798.150 limits the CCPA private action to specified security breaches and sets statutory or actual damages and pre-suit conditions.
- [CPPA Updated Monetary Thresholds in CCPA](https://cppa.ca.gov/regulations/cpi_adjustment.html?ref=sorena.io) - Sets the adjusted statutory-damages range at $107-$799 per consumer per incident effective 1 January 2025.

Sources for Security incidents and private claims - operational implication:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Article 57 supplies the PIPL incident-notification test.
- [California Civil Code, Title 1.81.5 (CCPA)](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) - Section 1798.150 supplies the narrower CCPA private-action test.

Sources for Cross-border transfer - China PIPL:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Articles 38-40 establish China export routes, overseas-recipient notice and separate consent, and security-assessment duties.
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Use for current export exemptions, thresholds, three-year assessment validity and precedence over inconsistent older measures.

Sources for Cross-border transfer - California CCPA/CPRA:

- [California Civil Code, Title 1.81.5 (CCPA)](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) - Sections 1798.100, 1798.120, and 1798.140 classify disclosures and define sale, sharing, service providers, contractors, and third parties without a PIPL-style export route.

Sources for Cross-border transfer - operational implication:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - PIPL Articles 38-40 and the 2024 provisions control the China export analysis.
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Use for current export exemptions, thresholds, three-year assessment validity and precedence over inconsistent older measures.
- [California Civil Code, Title 1.81.5 (CCPA)](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) - California contract status does not satisfy PIPL Articles 38-40 or the 2024 CAC provisions.

Sources for Enforcement and maximum penalties - China PIPL:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Article 66 establishes corrective orders and the ordinary and serious-violation penalty tiers, including the RMB 50 million or 5% ceiling.

Sources for Enforcement and maximum penalties - California CCPA/CPRA:

- [California Civil Code, Title 1.81.5 (CCPA)](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) - Sections 1798.150, 1798.155, and 1798.199.90 set the private-action, administrative-fine, and Attorney General civil-enforcement routes.
- [CPPA Updated Monetary Thresholds in CCPA](https://cppa.ca.gov/regulations/cpi_adjustment.html?ref=sorena.io) - Sets the adjusted administrative and civil penalty ceilings at $2,663 and $7,988 per violation effective 1 January 2025.

Sources for Enforcement and maximum penalties - operational implication:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Article 66 uses China-specific penalty tiers and remedies.
- [California Civil Code, Title 1.81.5 (CCPA)](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) - California uses per-violation administrative and civil penalty provisions and a limited private action.

## How to use this comparison

Start with scope, then assign the legal role for each data flow. Under PIPL, the organization that decides the purpose and method is the personal information processor. California instead distinguishes a business, service provider, contractor, and third party. Similar vendor relationships can produce different roles and contract terms.

Next, document the processing rule and consumer control. PIPL Article 13 lists consent and non-consent circumstances, while separate consent applies to specified disclosures, sensitive personal information, and overseas provision. California requires notice at or before collection and, where applicable, opt-outs from sale or sharing and limits on certain uses or disclosures of sensitive personal information.

Run the assessment, incident, and transfer tests separately. A PIPL personal information protection impact assessment (PIPIA) is required before listed high-risk activities. California's regulations effective January 1, 2026 add risk-assessment, cybersecurity-audit, and automated decisionmaking technology duties for covered activities and businesses, with phased compliance dates. China also has a separate export-route analysis; a California service-provider contract does not satisfy it.

- Record why each entity is or is not covered, including the California threshold used.
- Map each data flow to a PIPL processing circumstance and the applicable California notice or choice.
- Keep separate request deadlines, exceptions, identity checks, and response records.
- For China exports, count volumes from January 1 of the current year and check important-data and critical-information-infrastructure status before selecting an exemption, standard contract or certification, or CAC security assessment.

Sources for this answer:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Use for PIPL scope, processing bases, notice and consent, individual rights, processor duties, PIPIA, cross-border transfer duties, penalties, and effective date.
- [California Civil Code, Title 1.81.5 (CCPA)](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) - Sections 1798.100-1798.199.100 establish business scope, notices, consumer rights, role and contract rules, response timing, enforcement, and penalties.
- [CPPA 2026 CCPA regulations](https://cppa.ca.gov/regulations/ccpa_updates.html?ref=sorena.io) - The completed rulemaking took effect January 1, 2026 and covers risk assessments, cybersecurity audits, and automated decisionmaking technology.
- [CPPA Updated Monetary Thresholds in CCPA](https://cppa.ca.gov/regulations/cpi_adjustment.html?ref=sorena.io) - Sets the adjusted business revenue threshold, statutory-damages range, and administrative and civil penalty amounts effective 1 January 2025.

*Operationalize the requirement*

*Placement: Before primary sources*

## Prepare the PIPL and data export evidence file

Sorena AI links the China PIPL vs CCPA/CPRA decision to owners, controls, and reviewer-ready records.

- [Map official sources to evidence](/solutions/research-copilot.md): Research Copilot connects the official citation, decision, owner, retained evidence, and change history.
- [Review the China route](/contact.md): Check the China Privacy Law scope decision and unresolved launch questions with Sorena.

## Primary sources

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Article 66 uses China-specific penalty tiers and remedies.
- [Measures for the Standard Contract for Personal Information Export](https://www.cac.gov.cn/2023-02/24/c_1678884830036813.htm?ref=sorena.io) - Use for the CAC standard-contract form, pre-export PIPIA, contract effectiveness, filing and re-filing procedure; use the 2024 provisions for current exemptions and volume bands.
- [Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Use for assessment self-assessment, filing materials, review procedure and reapplication triggers; use the 2024 provisions for current exemptions, thresholds and validity.
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Use for current export exemptions, thresholds, three-year assessment validity and precedence over inconsistent older measures.
- [California Civil Code, Title 1.81.5 (CCPA)](https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5.&part=4.&ref=sorena.io) - California uses per-violation administrative and civil penalty provisions and a limited private action.
- [CPPA 2026 CCPA regulations](https://cppa.ca.gov/regulations/ccpa_updates.html?ref=sorena.io) - California's 2026 regulations set distinct triggers and phased compliance provisions.
- [CPPA Updated Monetary Thresholds in CCPA](https://cppa.ca.gov/regulations/cpi_adjustment.html?ref=sorena.io) - Sets the adjusted administrative and civil penalty ceilings at $2,663 and $7,988 per violation effective 1 January 2025.

## Related Topic Guides

- [App minimum necessary personal information by category](/artifacts/apac/china-privacy-law/app-minimum-necessary-personal-information-by-category.md): App category mapping page for common mobile app necessary personal information scope, using only categories supported by the official source.
- [China app personal information minimization](/artifacts/apac/china-privacy-law/app-personal-information-minimization.md): How to map app category, basic functions, and necessary personal information under China mobile app personal-information rules.
- [China data export security assessment workflow](/artifacts/apac/china-privacy-law/data-export-security-assessment-workflow.md): Workflow for screening data export security assessment triggers, materials, owners, and evidence records.
- [China personal information cross-border transfer routes](/artifacts/apac/china-privacy-law/cross-border-transfer-routes.md): Compare China's current data-export exemptions, CAC security assessment, standard contract, and personal information protection certification routes.
- [China personal information standard contract filing workflow](/artifacts/apac/china-privacy-law/standard-contract-filing-workflow.md): Workflow for the PIPL standard contract route, assessment, filing package, and cited evidence.
- [China PIPL compliance checklist](/artifacts/apac/china-privacy-law/checklist.md): China PIPL compliance checklist covering scope, processing bases, notices, sensitive information, rights, vendors, impact assessments, incidents, and exports.
- [China PIPL deadlines and compliance calendar](/artifacts/apac/china-privacy-law/deadlines-and-compliance-calendar.md): Calendar China PIPL effective dates, recurring audits, privacy-officer reporting, impact-assessment retention, and data export filing and renewal deadlines.
- [China PIPL penalties and enforcement exposure](/artifacts/apac/china-privacy-law/penalties-and-fines.md): Understand PIPL corrective orders, serious-violation fines, responsible-person exposure, civil claims, public-interest actions, and data export enforcement.
- [China PIPL privacy notice and consent checklist](/artifacts/apac/china-privacy-law/privacy-policy-and-consent-checklist.md): China PIPL checklist for privacy notices, valid consent, separate consent, sensitive information, children under 14, withdrawal, and rights requests.
- [China PIPL requirements](/artifacts/apac/china-privacy-law/requirements.md): China PIPL requirements from scope and processing basis through notices, rights, security, impact assessments, incidents, vendors, and data exports.
- [China PIPL vs EU GDPR: Requirements Compared](/artifacts/apac/china-privacy-law/china-privacy-law-vs-gdpr.md): Compare PIPL and GDPR scope, roles, legal bases, rights, impact assessments, breach deadlines, international transfers, and penalties.
- [China PIPL vs Singapore PDPA: Requirements Compared](/artifacts/apac/china-privacy-law/china-privacy-law-vs-singapore-pdpa.md): Compare PIPL and Singapore PDPA scope, roles, consent alternatives, rights, breach duties, overseas transfers, and penalties.
- [China Privacy Law FAQ](/artifacts/apac/china-privacy-law/faq.md): Practical answers on China's PIPL: scope, legal bases, sensitive information, separate consent, vendors, PIPIA records, app minimization, and export routes.
- [How should vendor contracts handle entrusted processing under PIPL?](/artifacts/apac/china-privacy-law/faq/how-should-vendor-contracts-handle-entrusted-processing.md): A PIPL entrusted-processing contract must define the purpose, duration, method, personal-information categories, safeguards, and both parties' duties. See the required terms and supporting records.
- [Is PIPL the same as GDPR?](/artifacts/apac/china-privacy-law/faq/is-pipl-the-same-as-gdpr.md): No. China's PIPL and the EU GDPR overlap on core privacy controls, but differ in territorial scope, legal bases, roles, sensitive data, impact assessments, and transfer routes.
- [PIPL automated decision-making and personalized recommendations](/artifacts/apac/china-privacy-law/automated-decision-making-and-personalized-recommendations.md): PIPL checks for automated decisions, personalized recommendations, marketing, differential treatment, explanations, refusal rights, and impact assessments.
- [PIPL breach response and notification](/artifacts/apac/china-privacy-law/breach-response-and-notification.md): PIPL incident workflow for immediate remediation, authority and individual notices, the narrow individual-notice exception, vendor coordination, and evidence.
- [PIPL cross-border transfer route selector](/artifacts/apac/china-privacy-law/pipl-cross-border-transfer-route-selector.md): Step-by-step selector for China's data-export exemptions, CAC security assessment, standard contract, and personal information protection certification.
- [PIPL entrusted processing and vendor contracts](/artifacts/apac/china-privacy-law/entrusted-processing-and-vendor-contracts.md): How to document entrusted processing, vendor responsibilities, contract controls, and evidence under PIPL.
- [PIPL impact assessment template](/artifacts/apac/china-privacy-law/personal-information-protection-impact-assessment-template.md): Template fields for a China personal information protection impact assessment and export/entrusted-processing evidence.
- [Sensitive personal information and separate consent under PIPL](/artifacts/apac/china-privacy-law/sensitive-personal-information-and-separate-consent.md): How to identify sensitive PI triggers, separate consent, minors, additional safeguards, and evidence records.
- [What counts as sensitive personal information in China?](/artifacts/apac/china-privacy-law/faq/what-counts-as-sensitive-personal-information-in-china.md): PIPL uses a harm-based test for sensitive personal information and lists examples such as biometrics, health, financial accounts, location traces, and all personal information of children under 14.
- [What is separate consent under PIPL?](/artifacts/apac/china-privacy-law/faq/what-is-separate-consent-under-pipl.md): Separate consent under China's PIPL is a distinct consent for a specified processing activity. See when it applies, what notice must come first, and what evidence to keep.
- [What records should we keep for a PIPL impact assessment?](/artifacts/apac/china-privacy-law/faq/what-records-should-we-keep-for-a-pipl-impact-assessment.md): A PIPL impact-assessment file should preserve the Article 55 trigger, processing facts, Article 56 analysis, safeguards, decision, and processing record for at least three years.
- [What should an app collect as necessary personal information in China?](/artifacts/apac/china-privacy-law/faq/what-should-an-app-collect-as-necessary-personal-information.md): Match the app's basic function to China's 2021 rules and collect no more than the listed necessary personal information. Users must retain the basic function if they decline non-necessary data.
- [When can a company use the China standard contract route?](/artifacts/apac/china-privacy-law/faq/when-can-a-company-use-the-china-standard-contract-route.md): Use China's standard contract route only after applying the 2024 exemptions and confirming that no CAC security assessment is required. See current thresholds, filing steps, and change triggers.
- [When does a China PIPL security assessment apply?](/artifacts/apac/china-privacy-law/faq/when-does-a-china-pipl-security-assessment-apply.md): A CAC data export security assessment applies to CIIO exports, important data, and specified high-volume personal-information exports after the 2024 exemptions are applied.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-privacy-law/china-pipl-vs-ccpa-cpra.md
