| Territorial reach | PIPL applies to processing personal information in China. It also reaches overseas processing intended to provide products or services to people in China, analyze or assess their behavior, or meet another condition set by law or regulation. An overseas processor within that rule must establish an institution or appoint a representative in China. | GDPR applies to processing in the context of an EU establishment regardless of where processing occurs. It also reaches a non-EU controller or processor offering goods or services to, or monitoring behavior of, people in the EU when the behavior occurs there. Article 27 generally requires a written EU representative for Article 3(2) processing, subject to its exceptions. | Record the establishment, targeting, or monitoring facts under GDPR and the in-China or overseas ground under PIPL; neither territorial result determines the other. |
|---|
| Core roles | A personal information processor decides the purpose and method. An entrusted processor handles information under an agreement stating the purpose, duration, method, categories, protection measures, and parties' rights and duties; the processor must supervise it. Joint decision-makers agree their duties and can face joint liability. | A controller determines purposes and means. A processor acts on documented instructions under an Article 28 contract and has specified direct duties. Joint controllers must transparently allocate responsibilities under Article 26 without removing data-subject rights against either controller. | Classify the actual decision-making under both laws and keep the Article 21 PIPL terms separate from the GDPR Article 28 clauses. |
|---|
| Processing basis and consent | Article 13 permits processing under consent or listed non-consent circumstances, including necessity to conclude or perform a contract with the individual, human-resources necessity under lawfully formulated employment rules or a lawfully concluded collective contract, legal duties, emergencies, specified news and public-interest activities, and reasonable processing of lawfully public information. Separate consent applies to specified disclosures, sensitive personal information, and overseas provision. | Article 6 provides six lawful bases: consent, contract, legal obligation, vital interests, public task, and legitimate interests, with limits on the last basis for public authorities. Consent must satisfy Articles 4(11) and 7. Special-category data also needs an Article 9(2) exception; Article 6 alone is insufficient. | Document the PIPL circumstance, any separate-consent trigger, the GDPR Article 6 basis, and any Article 9 condition as distinct conclusions. |
|---|
| Sensitive data and assessments | Sensitive personal information is information that, if leaked or illegally used, can readily harm dignity or personal or property safety. It includes biometrics, religious belief, specific identity, medical health, financial accounts, location tracking, and information of children under 14. Processing requires a specific purpose, sufficient necessity, strict safeguards, additional notice, separate consent, and a pre-processing PIPIA. | Article 9 special categories are racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic and biometric data used for unique identification, health data, and sex-life or sexual-orientation data. Processing is prohibited unless an Article 9(2) condition applies. Criminal-conviction data is governed separately by Article 10. | Maintain separate classification fields. Data may fall within one protected category but not the other, and each category changes a different legal test. |
|---|
| Individual rights | Individuals have rights to know and decide, restrict or refuse processing, access and copy, correct, and delete, subject to statutory conditions. For a decision with a major effect made solely through automated decision-making, an individual may request an explanation and refuse a decision made only that way. A rejected rights request must be explained, and the individual may sue. | Data subjects have rights to information, access, rectification, erasure, restriction, portability, objection, and safeguards for decisions based solely on automated processing. The controller generally must respond without undue delay and within one month, extendable by two further months for complexity or volume if the person is told within the first month. | One intake channel can work only if it applies the correct right, exception, identity check, deadline, fee rule, and response explanation. |
|---|
| Impact assessments and records | Article 55 requires a PIPIA before sensitive-information processing, automated decision-making, entrusted processing, provision to another processor, public disclosure, overseas provision, and other processing with a major effect on individuals. The report and processing record must be kept for at least three years. Article 54 separately requires regular compliance audits. | Article 35 requires a DPIA before processing likely to result in high risk, especially specified systematic evaluations with significant effects, large-scale special-category or criminal-conviction processing, and large-scale systematic monitoring of public areas. Supervisory-authority lists can add or clarify triggers. Article 30 separately requires records of processing, subject to a limited exception for some organizations under 250 employees. | Reuse factual system and risk evidence, but keep separate trigger, content, consultation, approval, retention, and record-of-processing analyses. |
|---|
| Personal-data breaches | If personal information is or may be leaked, altered, or lost, the processor must immediately take remedial measures and notify the authorities and individuals with the information listed in Article 57. Individual notice may be omitted if the processor can effectively avoid harm, but an authority may still require it. PIPL does not state a fixed 72-hour period. | A controller must notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after awareness unless the breach is unlikely to risk people's rights and freedoms. It must communicate a high-risk breach to affected people without undue delay unless an Article 34 exception applies. Processors notify controllers without undue delay. | Start both assessments when the incident is discovered, but record the trigger, recipient, deadline, exception, content, and decision under each law. |
|---|
| International transfers | Before overseas provision, PIPL generally requires recipient notice, separate consent, a PIPIA, and one Article 38 route unless a current exemption applies. Under the 2024 provisions, non-critical-information-infrastructure operators generally use a standard contract or certification when they export personal information of at least 100,000 but fewer than 1 million individuals, excluding sensitive personal information, or sensitive personal information of fewer than 10,000 individuals, counted from 1 January of the current year. A CAC assessment is required for critical information infrastructure operators, important data, personal information of at least 1 million individuals excluding sensitive personal information, or sensitive personal information of at least 10,000 individuals, subject to stated exemptions. | Chapter V permits transfer on an adequacy decision, appropriate safeguards such as the EU standard contractual clauses or binding corporate rules, or a limited Article 49 derogation. All Chapter V conditions must preserve GDPR protection, including for onward transfers. The chosen mechanism does not remove the rest of the GDPR duties. | For a China-EU flow, complete both analyses. The CAC standard contract and EU standard contractual clauses are different instruments with different legal tests. |
|---|
| Enforcement and maximum fines | For a serious PIPL violation, the responsible authority may order correction, confiscate unlawful gains, and impose up to RMB 50 million or 5% of the prior year's turnover. It may also suspend business, revoke permits or a business license, and fine or disqualify responsible individuals. Lesser violations have a different penalty tier. | For infringements in GDPR Article 83(5), including core principles, data-subject rights, and international-transfer rules, a supervisory authority may impose up to EUR 20 million or 4% of the undertaking's total worldwide annual turnover from the preceding financial year, whichever is higher. Article 83 requires a case-specific assessment, and other infringement tiers and corrective powers also apply. | Do not treat 5% and 4% as directly comparable. The turnover base, infringement tier, authority powers, calculation, and affected entity can differ. |
|---|