Scope, roles, and processing bases
Run the territorial tests independently. PIPL applies to processing in China and also to specified processing outside China involving people in China, including offering them products or services or analyzing or assessing their behavior. GDPR applies to processing in the context of an EU establishment and, for certain organizations outside the EU, to offering goods or services to people in the EU or monitoring their behavior there.
Map roles from the facts. PIPL defines a by independent control over purpose and method and separately regulates joint processing, entrusted processing, and provision to another processor. GDPR uses controller, joint controller, and processor concepts. The labels often align operationally, but they are not interchangeable legal conclusions.
Both laws allow processing without consent in defined circumstances, but the lists and conditions differ. PIPL Article 13 includes consent, contract necessity, qualifying human-resources management, legal duties, emergencies, public-interest reporting or supervision, lawfully public information, and other statutory grounds. GDPR Article 6 uses consent, contract, legal obligation, vital interests, public task, and legitimate interests, subject to its conditions.
- Outside-China PIPL processing can require a dedicated organization or representative in China under Article 53; GDPR Article 27 has its own representative rule and exceptions.
- PIPL consent must be voluntary and explicit and based on sufficient knowledge. PIPL also requires separate consent for specified activities; GDPR does not use the same general statutory concept.
- A GDPR legitimate-interests assessment does not create a PIPL basis. A PIPL Article 13 basis does not by itself establish a GDPR Article 6 basis.
- Keep shared facts once, then record the applicable role, basis, notice, consent, rights, retention, and responsible entity separately for each law.
Articles 3, 13-17, 20-23, 53, and 73 support the PIPL territorial, role, processing-basis, consent, and representative comparison points.
Articles 3, 4, 6-7, and 26-29 support the GDPR territorial, role, lawful-basis, consent, joint-controller, and processor comparison points.