PrivacyChina

China Privacy Law PIPL penalties and enforcement exposure

PIPL Article 66 has a corrective tier and a serious-circumstances tier. The maximum fine is not automatic for every violation.

Exposure can also include confiscation of unlawful gains, service or business restrictions, licence consequences, fines and role restrictions for responsible personnel, civil damages, public-interest litigation, credit-record publication, and public-security or criminal liability.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
9

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 24, 2026
Overview

A that violates PIPL does not automatically receive the RMB 50 million or 5% maximum. Article 66 first allows correction, a warning, confiscation of unlawful gains, and suspension or termination of an unlawfully processing App. Refusal to correct can lead to lower-tier fines. allow the higher organizational fine and additional business and individual sanctions. The text of Article 66 does not define serious circumstances or the geographic and accounting base for prior-year turnover, so this page does not calculate a case-specific maximum.

Section 1

Who and what PIPL can reach

PIPL applies to personal-information processing in China. It can also apply to processing outside China when the activity is for providing products or services to people in China, analyzes or assesses their behavior, or falls within another condition set by law or administrative regulation. An overseas within that extraterritorial scope must establish a dedicated organization or appoint a representative in China and report the organization or representative to the protection authority.

Identify the actor and violated duty before estimating exposure. Article 66 covers processing that violates PIPL and failures to perform PIPL personal-information protection obligations. State organs have a separate responsibility rule in Article 68. Other statutes and sector rules may apply to the same conduct, so Article 66 is not a universal ceiling for every privacy, cybersecurity, data-security, consumer, employment, or criminal consequence.

  • Identify whether the organization is the , an entrusted processor, a joint processor, an overseas recipient, an App provider, or another regulated actor for the processing at issue.
  • Map the alleged conduct to the actual duty: legal basis and consent, notice, sensitive information, individual rights, automated decisions, security controls, impact assessment, breach response, cross-border transfer, audit, or another provision.
  • Separate PIPL exposure from penalties available under other applicable laws. Do not add unrelated maximums together without a legal basis and case-specific analysis.
Section 2

Article 66 administrative penalty tiers

Article 66 separates the available measures by posture and seriousness. It does not say that every initial violation receives a fine, and it does not make the upper limit the expected amount. The competent authority determines the applicable measures in the enforcement case.

Is every PIPL violation fined RMB 50 million or 5% of turnover?

No. Those are alternative upper limits available for the serious-circumstances tier under Article 66. The same article provides corrective measures for violations and lower fines when an organization refuses to correct. It does not make the maximum automatic, define a standard fine for every violation, or state the turnover calculation base. Determine the violated duty, enforcement posture, facts, applicable tier, entity, and authority interpretation before estimating exposure.

Can managers or privacy officers be fined personally?

Yes, when they are directly responsible managers or other directly responsible personnel. For refusal to correct, Article 66 sets a range of RMB 10,000 to RMB 100,000. In , it sets a range of RMB 100,000 to RMB 1 million and allows a temporary bar from specified director, supervisor, senior-management, or personal information protection officer roles. A title alone does not establish direct responsibility; that depends on the person's role and the case facts.

  • Initial corrective measures: an authority may order correction, issue a warning, confiscate unlawful gains, and order an App that unlawfully processes personal information to suspend or terminate service.
  • Refusal to correct: the organization may also be fined up to RMB 1 million. Directly responsible managers and other directly responsible personnel may be fined from RMB 10,000 to RMB 100,000.
  • : a provincial-level or higher protection authority may order correction, confiscate unlawful gains, and fine the organization up to RMB 50 million or up to 5% of its prior-year turnover.
  • Additional serious-case measures: the authority may order suspension of related business or suspension for rectification and may notify another competent authority to revoke a relevant business permit or business licence.
  • Responsible personnel in a serious case: directly responsible managers and other directly responsible personnel may be fined from RMB 100,000 to RMB 1 million. The authority may also bar them for a period from serving as a director, supervisor, senior manager, or personal information protection officer of a relevant enterprise.
  • Turnover caveat: Article 66 states 'prior-year turnover' but does not specify in its text whether the base is worldwide, China-only, group, or entity turnover, or how it must be calculated. A case-specific maximum requires the controlling authority's interpretation and the relevant entity and accounting facts.
Section 3

Other PIPL consequences

Administrative fines are only one part of PIPL exposure. Articles 63-71 address investigative powers, risk remediation, credit records, state-organ responsibility, civil liability, public-interest litigation, and public-security or criminal liability.

Can individuals claim damages under PIPL?

Yes, if personal-information processing infringes their rights and causes harm. Under Article 69, the bears tort liability if it cannot prove it was not at fault. Damages are determined from the individual's loss or the processor's resulting gain; when both are difficult to determine, the court sets the amount according to the circumstances. The claimant still needs a case within Article 69, and this page cannot determine causation, harm, fault, or damages for a specific dispute.

Does PIPL allow public-interest litigation?

Yes. Article 70 allows a people's procuratorate, a consumer organization designated by law, or an organization designated by the national cyberspace authority to sue when unlawful processing infringes the rights of many individuals. This is separate from an individual's Article 69 damages claim and from an authority's administrative enforcement.

  • Investigation and controls: protection authorities may question parties, inspect and copy contracts and records, conduct on-site inspections, and, with the required approval, seal or seize equipment or items supported by evidence of unlawful processing. Parties must assist and may not refuse or obstruct.
  • Risk remediation and audit: where processing presents a relatively high risk or a personal-information security incident occurs, an authority may interview the legal representative or principal responsible person or require an audit by a professional institution. The processor must rectify and eliminate the risk as required.
  • Credit record: Article 67, not Article 66, provides that a PIPL violation is entered into a credit record and publicized in accordance with applicable laws and administrative regulations.
  • Civil damages: when processing infringes personal-information rights and causes harm, a processor that cannot prove it was not at fault bears tort liability. Damages are based on the individual's loss or the processor's gain; if both are difficult to determine, the amount is set according to the circumstances.
  • Public-interest actions: where unlawful processing infringes the rights of many individuals, a people's procuratorate, a legally designated consumer organization, or an organization designated by the national cyberspace authority may bring an action.
  • Public-security and criminal exposure: conduct constituting a public-security violation is handled under the applicable public-security rules; conduct constituting a crime is subject to criminal liability.
Section 4

Data export and App enforcement

The data export measures do not create one self-contained fine table. Their liability provisions direct violations to PIPL and other applicable cybersecurity, data-security, certification, or criminal rules. The governing instrument and actor must therefore be identified before stating a penalty.

For Apps, PIPL Article 66 expressly allows suspension or termination of service for an App that unlawfully processes personal information. The 2022 App provisions separately state that App providers and distribution platforms that violate those provisions are handled by cyberspace and other competent authorities within their responsibilities under relevant laws and regulations.

  • Standard-contract route: the provincial or higher cyberspace authority may interview a processor when an export presents a relatively high risk or a personal-information security incident occurs; the processor must rectify and eliminate the risk. Violations are handled under PIPL and other applicable laws, and crimes are prosecuted.
  • Security-assessment route: the national cyberspace authority may order termination of an approved export that no longer meets data export security requirements. To continue, the processor must rectify and reapply. Violations are handled under the Cybersecurity Law, Data Security Law, PIPL, and other applicable laws.
  • 2024 cross-border provisions: local cyberspace authorities may require rectification when they find a relatively high risk or data-security incident. Refusal to correct or serious consequences can lead to legal responsibility under applicable law.
  • Certification route: violations of the Personal Information Export Certification Measures are handled under PIPL, the Network Data Security Management Regulations, the Certification and Accreditation Regulations, and other applicable rules; criminal conduct is prosecuted.
  • Do not assume that a contract filing receipt, assessment result, or certification proves general PIPL compliance. Each mechanism addresses a transfer route and does not remove the underlying notice, consent where required, impact-assessment, security, individual-rights, and recipient-protection duties.
Section 5

Evidence to preserve during an investigation or remediation

Preserve the record before changing systems or documents. It should show what happened, which duty applied, who decided, what the organization knew, how it responded, and whether the corrective action is complete. Do not alter or recreate evidence to make the record look cleaner.

  • Scope and role: data map, processing purpose and method, affected people and data categories, sensitive-information and minors analysis, actor roles, system and App versions, jurisdictions, and cross-border recipients.
  • Legal and control record: notices, consent or other processing basis, individual-rights workflow, contracts, impact assessments, audit records, security measures, access logs, retention rules, export-route decision, filings, assessment results, and certifications.
  • Event record: detection time, known facts, affected systems and data, preservation steps, containment, remediation, notifications, complaints, regulator communications, instructions, owners, decisions, and completion evidence.
  • Responsibility record: governance documents, delegated authority, escalation paths, meeting decisions, training, prior findings, remediation commitments, and evidence showing who controlled or approved the relevant processing.
  • Exposure analysis: assess the Article 66 tier, individual responsibility, civil claims, public-interest litigation, credit consequences, and any separate law. Keep uncertainty explicit and update the analysis when the authority or facts change.
Primary sources

References and citations

cac.gov.cn
Referenced sections
  • Articles 17-18 support termination, rectification, reapplication, and enforcement under the Cybersecurity Law, Data Security Law, PIPL, and other applicable laws.
cac.gov.cn
Referenced sections
  • Articles 51, 55-57, 63-66 and 69 support security controls, impact-assessment and incident records, authority inspection powers, remediation, administrative exposure, and civil liability.
cac.gov.cn
Referenced sections
  • Binding source for corrective orders, warnings, confiscation, App service restrictions, refusal-to-correct fines, serious-circumstances fines and business measures, responsible-person fines, and temporary role restrictions.
cac.gov.cn
Referenced sections
  • Binding source for authority powers, interviews and compliance audits, credit-record publication, state-organ responsibility, fault-based civil liability with a reversed proof burden, damages, public-interest actions, and public-security or criminal liability.
Related guides

Explore more topics

App minimum necessary personal information by category
App category mapping page for common mobile app necessary personal information scope, using only categories supported by the official source.
China app personal information minimization
How to map app category, basic functions, and necessary personal information under China mobile app personal-information rules.
China data export security assessment workflow
Workflow for screening data export security assessment triggers, materials, owners, and evidence records.
China personal information cross-border transfer routes
Compare China's current data-export exemptions, CAC security assessment, standard contract, and personal information protection certification routes.
China personal information standard contract filing workflow
Workflow for the PIPL standard contract route, assessment, filing package, and cited evidence.
China PIPL compliance checklist
China PIPL compliance checklist covering scope, processing bases, notices, sensitive information, rights, vendors, impact assessments, incidents, and exports.
China PIPL deadlines and compliance calendar
Calendar China PIPL effective dates, recurring audits, privacy-officer reporting, impact-assessment retention, and data export filing and renewal deadlines.
China PIPL privacy notice and consent checklist
China PIPL checklist for privacy notices, valid consent, separate consent, sensitive information, children under 14, withdrawal, and rights requests.
China PIPL requirements
China PIPL requirements from scope and processing basis through notices, rights, security, impact assessments, incidents, vendors, and data exports.
China PIPL vs CCPA/CPRA: Requirements Compared
Compare PIPL and CCPA/CPRA scope, consent and opt-out rules, rights, assessments, data exports, breach duties, and penalties.
China PIPL vs EU GDPR: Requirements Compared
Compare PIPL and GDPR scope, roles, legal bases, rights, impact assessments, breach deadlines, international transfers, and penalties.
China PIPL vs Singapore PDPA: Requirements Compared
Compare PIPL and Singapore PDPA scope, roles, consent alternatives, rights, breach duties, overseas transfers, and penalties.
China Privacy Law FAQ
Practical answers on China's PIPL: scope, legal bases, sensitive information, separate consent, vendors, PIPIA records, app minimization, and export routes.
How should vendor contracts handle entrusted processing under PIPL?
A PIPL entrusted-processing contract must define the purpose, duration, method, personal-information categories, safeguards, and both parties' duties. See the required terms and supporting records.
Is PIPL the same as GDPR?
No. China's PIPL and the EU GDPR overlap on core privacy controls, but differ in territorial scope, legal bases, roles, sensitive data, impact assessments, and transfer routes.
PIPL automated decision-making and personalized recommendations
PIPL checks for automated decisions, personalized recommendations, marketing, differential treatment, explanations, refusal rights, and impact assessments.
PIPL breach response and notification
PIPL incident workflow for immediate remediation, authority and individual notices, the narrow individual-notice exception, vendor coordination, and evidence.
PIPL cross-border transfer route selector
Step-by-step selector for China's data-export exemptions, CAC security assessment, standard contract, and personal information protection certification.
PIPL entrusted processing and vendor contracts
How to document entrusted processing, vendor responsibilities, contract controls, and evidence under PIPL.
PIPL impact assessment template
Template fields for a China personal information protection impact assessment and export/entrusted-processing evidence.
Sensitive personal information and separate consent under PIPL
How to identify sensitive PI triggers, separate consent, minors, additional safeguards, and evidence records.
What counts as sensitive personal information in China?
PIPL uses a harm-based test for sensitive personal information and lists examples such as biometrics, health, financial accounts, location traces, and all personal information of children under 14.
What is separate consent under PIPL?
Separate consent under China's PIPL is a distinct consent for a specified processing activity. See when it applies, what notice must come first, and what evidence to keep.
What records should we keep for a PIPL impact assessment?
A PIPL impact-assessment file should preserve the Article 55 trigger, processing facts, Article 56 analysis, safeguards, decision, and processing record for at least three years.
What should an app collect as necessary personal information in China?
Match the app's basic function to China's 2021 rules and collect no more than the listed necessary personal information. Users must retain the basic function if they decline non-necessary data.
When can a company use the China standard contract route?
Use China's standard contract route only after applying the 2024 exemptions and confirming that no CAC security assessment is required. See current thresholds, filing steps, and change triggers.
When does a China PIPL security assessment apply?
A CAC data export security assessment applies to CIIO exports, important data, and specified high-volume personal-information exports after the 2024 exemptions are applied.