---
title: "China PIPL penalties and enforcement exposure"
canonical_url: "https://www.sorena.io/artifacts/apac/china-privacy-law/penalties-and-fines"
source_url: "https://www.sorena.io/artifacts/apac/china-privacy-law/penalties-and-fines"
author: "Sorena AI"
description: "Understand PIPL corrective orders, serious-violation fines, responsible-person exposure, civil claims, public-interest actions, and data export enforcement."
published_at: "2026-07-05"
updated_at: "2026-07-24"
keywords:
  - "China PIPL penalties"
  - "PIPL fines"
  - "Article 66"
  - "personal information enforcement"
  - "data export penalties"
  - "China PIPL"
  - "Personal Information Protection Law"
  - "Data export"
  - "Standard contract"
  - "App privacy"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# China PIPL penalties and enforcement exposure

Understand PIPL corrective orders, serious-violation fines, responsible-person exposure, civil claims, public-interest actions, and data export enforcement.

*Privacy* *China*

## China Privacy Law PIPL penalties and enforcement exposure

PIPL Article 66 has a corrective tier and a serious-circumstances tier. The maximum fine is not automatic for every violation.

Exposure can also include confiscation of unlawful gains, service or business restrictions, licence consequences, fines and role restrictions for responsible personnel, civil damages, public-interest litigation, credit-record publication, and public-security or criminal liability.

A personal information processor that violates PIPL does not automatically receive the RMB 50 million or 5% maximum. Article 66 first allows correction, a warning, confiscation of unlawful gains, and suspension or termination of an unlawfully processing App. Refusal to correct can lead to lower-tier fines. Serious circumstances allow the higher organizational fine and additional business and individual sanctions. The text of Article 66 does not define serious circumstances or the geographic and accounting base for prior-year turnover, so this page does not calculate a case-specific maximum.

## Definitions

### Personal information processor

An organization or individual that independently decides the purposes and methods of personal information processing. The role is determined by decision-making control, not by a contract label alone.

**Why it matters here:** Article 66 applies to unlawful processing and failures to perform PIPL duties. A service provider acting only on instructions may instead be an entrusted processor for that activity, although its own independent decisions can make it a personal information processor for separate processing.

Sources:

- [PRC Personal Information Protection Law, Articles 21 and 73](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io)

### Serious circumstances under PIPL Article 66

**Term:** serious circumstances

The condition that activates Article 66's higher administrative-penalty tier. Article 66 states the available consequences but does not provide a closed definition or scoring formula for deciding when circumstances are serious.

**Why it matters here:** Do not present the higher fine, business suspension, licence consequences, or higher individual fine as the default outcome. Preserve the facts that may affect an authority's case-specific assessment, including the conduct, scale, data involved, effects on individuals, duration, remediation, cooperation, prior notice, and repeated behavior, without assuming that any one fact decides the tier.

Sources:

- [PRC Personal Information Protection Law, Article 66](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io)

## Who and what PIPL can reach

PIPL applies to personal-information processing in China. It can also apply to processing outside China when the activity is for providing products or services to people in China, analyzes or assesses their behavior, or falls within another condition set by law or administrative regulation. An overseas personal information processor within that extraterritorial scope must establish a dedicated organization or appoint a representative in China and report the organization or representative to the protection authority.

Identify the actor and violated duty before estimating exposure. Article 66 covers processing that violates PIPL and failures to perform PIPL personal-information protection obligations. State organs have a separate responsibility rule in Article 68. Other statutes and sector rules may apply to the same conduct, so Article 66 is not a universal ceiling for every privacy, cybersecurity, data-security, consumer, employment, or criminal consequence.

- Identify whether the organization is the personal information processor, an entrusted processor, a joint processor, an overseas recipient, an App provider, or another regulated actor for the processing at issue.
- Map the alleged conduct to the actual duty: legal basis and consent, notice, sensitive information, individual rights, automated decisions, security controls, impact assessment, breach response, cross-border transfer, audit, or another provision.
- Separate PIPL exposure from penalties available under other applicable laws. Do not add unrelated maximums together without a legal basis and case-specific analysis.

Sources for this answer:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Articles 3 and 53 establish territorial and specified extraterritorial scope and the local organization or representative duty; Articles 21 and 73 distinguish entrusted processing and define a personal information processor; Articles 66 and 68 separate general violations from state-organ responsibility.

## Article 66 administrative penalty tiers

Article 66 separates the available measures by posture and seriousness. It does not say that every initial violation receives a fine, and it does not make the upper limit the expected amount. The competent authority determines the applicable measures in the enforcement case.

- Initial corrective measures: an authority may order correction, issue a warning, confiscate unlawful gains, and order an App that unlawfully processes personal information to suspend or terminate service.
- Refusal to correct: the organization may also be fined up to RMB 1 million. Directly responsible managers and other directly responsible personnel may be fined from RMB 10,000 to RMB 100,000.
- Serious circumstances: a provincial-level or higher protection authority may order correction, confiscate unlawful gains, and fine the organization up to RMB 50 million or up to 5% of its prior-year turnover.
- Additional serious-case measures: the authority may order suspension of related business or suspension for rectification and may notify another competent authority to revoke a relevant business permit or business licence.
- Responsible personnel in a serious case: directly responsible managers and other directly responsible personnel may be fined from RMB 100,000 to RMB 1 million. The authority may also bar them for a period from serving as a director, supervisor, senior manager, or personal information protection officer of a relevant enterprise.
- Turnover caveat: Article 66 states 'prior-year turnover' but does not specify in its text whether the base is worldwide, China-only, group, or entity turnover, or how it must be calculated. A case-specific maximum requires the controlling authority's interpretation and the relevant entity and accounting facts.

### Is every PIPL violation fined RMB 50 million or 5% of turnover?

No. Those are alternative upper limits available for the serious-circumstances tier under Article 66. The same article provides corrective measures for violations and lower fines when an organization refuses to correct. It does not make the maximum automatic, define a standard fine for every violation, or state the turnover calculation base. Determine the violated duty, enforcement posture, facts, applicable tier, entity, and authority interpretation before estimating exposure.

### Can managers or privacy officers be fined personally?

Yes, when they are directly responsible managers or other directly responsible personnel. For refusal to correct, Article 66 sets a range of RMB 10,000 to RMB 100,000. In serious circumstances, it sets a range of RMB 100,000 to RMB 1 million and allows a temporary bar from specified director, supervisor, senior-management, or personal information protection officer roles. A title alone does not establish direct responsibility; that depends on the person's role and the case facts.

Sources for this answer:

- [PRC Personal Information Protection Law, Article 66](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Binding source for corrective orders, warnings, confiscation, App service restrictions, refusal-to-correct fines, serious-circumstances fines and business measures, responsible-person fines, and temporary role restrictions.

## Other PIPL consequences

Administrative fines are only one part of PIPL exposure. Articles 63-71 address investigative powers, risk remediation, credit records, state-organ responsibility, civil liability, public-interest litigation, and public-security or criminal liability.

- Investigation and controls: protection authorities may question parties, inspect and copy contracts and records, conduct on-site inspections, and, with the required approval, seal or seize equipment or items supported by evidence of unlawful processing. Parties must assist and may not refuse or obstruct.
- Risk remediation and audit: where processing presents a relatively high risk or a personal-information security incident occurs, an authority may interview the legal representative or principal responsible person or require an audit by a professional institution. The processor must rectify and eliminate the risk as required.
- Credit record: Article 67, not Article 66, provides that a PIPL violation is entered into a credit record and publicized in accordance with applicable laws and administrative regulations.
- Civil damages: when processing infringes personal-information rights and causes harm, a processor that cannot prove it was not at fault bears tort liability. Damages are based on the individual's loss or the processor's gain; if both are difficult to determine, the amount is set according to the circumstances.
- Public-interest actions: where unlawful processing infringes the rights of many individuals, a people's procuratorate, a legally designated consumer organization, or an organization designated by the national cyberspace authority may bring an action.
- Public-security and criminal exposure: conduct constituting a public-security violation is handled under the applicable public-security rules; conduct constituting a crime is subject to criminal liability.

### Can individuals claim damages under PIPL?

Yes, if personal-information processing infringes their rights and causes harm. Under Article 69, the personal information processor bears tort liability if it cannot prove it was not at fault. Damages are determined from the individual's loss or the processor's resulting gain; when both are difficult to determine, the court sets the amount according to the circumstances. The claimant still needs a case within Article 69, and this page cannot determine causation, harm, fault, or damages for a specific dispute.

### Does PIPL allow public-interest litigation?

Yes. Article 70 allows a people's procuratorate, a consumer organization designated by law, or an organization designated by the national cyberspace authority to sue when unlawful processing infringes the rights of many individuals. This is separate from an individual's Article 69 damages claim and from an authority's administrative enforcement.

Sources for this answer:

- [PRC Personal Information Protection Law, Articles 63-71](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Binding source for authority powers, interviews and compliance audits, credit-record publication, state-organ responsibility, fault-based civil liability with a reversed proof burden, damages, public-interest actions, and public-security or criminal liability.

## Data export and App enforcement

The data export measures do not create one self-contained fine table. Their liability provisions direct violations to PIPL and other applicable cybersecurity, data-security, certification, or criminal rules. The governing instrument and actor must therefore be identified before stating a penalty.

For Apps, PIPL Article 66 expressly allows suspension or termination of service for an App that unlawfully processes personal information. The 2022 App provisions separately state that App providers and distribution platforms that violate those provisions are handled by cyberspace and other competent authorities within their responsibilities under relevant laws and regulations.

- Standard-contract route: the provincial or higher cyberspace authority may interview a processor when an export presents a relatively high risk or a personal-information security incident occurs; the processor must rectify and eliminate the risk. Violations are handled under PIPL and other applicable laws, and crimes are prosecuted.
- Security-assessment route: the national cyberspace authority may order termination of an approved export that no longer meets data export security requirements. To continue, the processor must rectify and reapply. Violations are handled under the Cybersecurity Law, Data Security Law, PIPL, and other applicable laws.
- 2024 cross-border provisions: local cyberspace authorities may require rectification when they find a relatively high risk or data-security incident. Refusal to correct or serious consequences can lead to legal responsibility under applicable law.
- Certification route: violations of the Personal Information Export Certification Measures are handled under PIPL, the Network Data Security Management Regulations, the Certification and Accreditation Regulations, and other applicable rules; criminal conduct is prosecuted.
- Do not assume that a contract filing receipt, assessment result, or certification proves general PIPL compliance. Each mechanism addresses a transfer route and does not remove the underlying notice, consent where required, impact-assessment, security, individual-rights, and recipient-protection duties.

Related resources:

- [China PIPL cross-border transfer route selector](/artifacts/apac/china-privacy-law/pipl-cross-border-transfer-route-selector.md): Identify the exemption, standard-contract, certification, or security-assessment route before evaluating a transfer failure.
- [China App personal-information minimization guide](/artifacts/apac/china-privacy-law/app-personal-information-minimization.md): Check App collection, basic-function access, non-necessary information, and platform review controls.

Sources for this answer:

- [Measures for the Standard Contract for Personal Information Export](https://www.cac.gov.cn/2023-02/24/c_1678884830036813.htm?ref=sorena.io) - Articles 11-12 establish interview and rectification powers and refer violations to PIPL and other applicable laws, including criminal liability.
- [Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Articles 17-18 support termination, rectification, reapplication, and enforcement under the Cybersecurity Law, Data Security Law, PIPL, and other applicable laws.
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Articles 10-12 preserve underlying PIPL duties, require security measures and incident reporting, and provide for rectification and legal responsibility.
- [Personal Information Export Certification Measures](https://www.cac.gov.cn/2025-10/17/c_1762449728720008.htm?ref=sorena.io) - Article 17 identifies the legal frameworks used to handle certification-measure violations and preserves criminal liability.
- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io) - Articles 12, 20-21 and 25 support App personal-information duties, platform review and service measures, and enforcement under relevant laws and regulations.

## Evidence to preserve during an investigation or remediation

Preserve the record before changing systems or documents. It should show what happened, which duty applied, who decided, what the organization knew, how it responded, and whether the corrective action is complete. Do not alter or recreate evidence to make the record look cleaner.

- Scope and role: data map, processing purpose and method, affected people and data categories, sensitive-information and minors analysis, actor roles, system and App versions, jurisdictions, and cross-border recipients.
- Legal and control record: notices, consent or other processing basis, individual-rights workflow, contracts, impact assessments, audit records, security measures, access logs, retention rules, export-route decision, filings, assessment results, and certifications.
- Event record: detection time, known facts, affected systems and data, preservation steps, containment, remediation, notifications, complaints, regulator communications, instructions, owners, decisions, and completion evidence.
- Responsibility record: governance documents, delegated authority, escalation paths, meeting decisions, training, prior findings, remediation commitments, and evidence showing who controlled or approved the relevant processing.
- Exposure analysis: assess the Article 66 tier, individual responsibility, civil claims, public-interest litigation, credit consequences, and any separate law. Keep uncertainty explicit and update the analysis when the authority or facts change.

Related resources:

- [China PIPL compliance checklist](/artifacts/apac/china-privacy-law/checklist.md): Map the processing activity to notices, legal basis, rights, security, assessment, audit, and transfer evidence.
- [China privacy breach response and notification](/artifacts/apac/china-privacy-law/breach-response-and-notification.md): Structure containment, authority and individual notification analysis, evidence preservation, and remediation.

Sources for this answer:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Articles 51, 55-57, 63-66 and 69 support security controls, impact-assessment and incident records, authority inspection powers, remediation, administrative exposure, and civil liability.
- [Personal Information Protection Compliance Audit Measures](https://www.cac.gov.cn/2025-02/14/c_1741233507681519.htm?ref=sorena.io) - Articles 5-11 and the audit guidelines support authority-directed audits, reports, remediation, and review of personal-information governance and processing controls.

*Operationalize the requirement*

*Placement: Before primary sources*

## Document the PIPL exposure and response

Connect the alleged conduct, applicable duty, actor, evidence, corrective action, authority direction, and unresolved legal questions.

- [Map official sources to evidence](/solutions/research-copilot.md): Research Copilot connects each legal provision and exposure conclusion to the relevant facts, owner, and retained record.
- [Review the China exposure](/contact.md): Review the actor, alleged violation, remediation record, and unresolved case-specific questions with Sorena.

## Primary sources

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Binding source for territorial scope, actor definitions, authority powers, Article 66 penalty tiers, credit records, state-organ responsibility, civil liability, public-interest actions, and public-security or criminal liability.
- [Measures for the Standard Contract for Personal Information Export](https://www.cac.gov.cn/2023-02/24/c_1678884830036813.htm?ref=sorena.io) - Interview, rectification, and liability provisions for the standard-contract route.
- [Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Termination, rectification, reapplication, and cross-reference to applicable cybersecurity, data-security, personal-information, and criminal law.
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Underlying PIPL duties, export security, incident response, regulator-directed rectification, and responsibility for refusal or serious consequences.
- [Personal Information Export Certification Measures](https://www.cac.gov.cn/2025-10/17/c_1762449728720008.htm?ref=sorena.io) - Current certification-route liability provision, effective 1 January 2026.
- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io) - App-provider and distribution-platform personal-information duties, platform controls, and enforcement under relevant laws and regulations.
- [Personal Information Protection Compliance Audit Measures](https://www.cac.gov.cn/2025-02/14/c_1741233507681519.htm?ref=sorena.io) - Current authority-directed audit, reporting, remediation, and audit-guideline requirements.

## Related Topic Guides

- [App minimum necessary personal information by category](/artifacts/apac/china-privacy-law/app-minimum-necessary-personal-information-by-category.md): App category mapping page for common mobile app necessary personal information scope, using only categories supported by the official source.
- [China app personal information minimization](/artifacts/apac/china-privacy-law/app-personal-information-minimization.md): How to map app category, basic functions, and necessary personal information under China mobile app personal-information rules.
- [China data export security assessment workflow](/artifacts/apac/china-privacy-law/data-export-security-assessment-workflow.md): Workflow for screening data export security assessment triggers, materials, owners, and evidence records.
- [China personal information cross-border transfer routes](/artifacts/apac/china-privacy-law/cross-border-transfer-routes.md): Compare China's current data-export exemptions, CAC security assessment, standard contract, and personal information protection certification routes.
- [China personal information standard contract filing workflow](/artifacts/apac/china-privacy-law/standard-contract-filing-workflow.md): Workflow for the PIPL standard contract route, assessment, filing package, and cited evidence.
- [China PIPL compliance checklist](/artifacts/apac/china-privacy-law/checklist.md): China PIPL compliance checklist covering scope, processing bases, notices, sensitive information, rights, vendors, impact assessments, incidents, and exports.
- [China PIPL deadlines and compliance calendar](/artifacts/apac/china-privacy-law/deadlines-and-compliance-calendar.md): Calendar China PIPL effective dates, recurring audits, privacy-officer reporting, impact-assessment retention, and data export filing and renewal deadlines.
- [China PIPL privacy notice and consent checklist](/artifacts/apac/china-privacy-law/privacy-policy-and-consent-checklist.md): China PIPL checklist for privacy notices, valid consent, separate consent, sensitive information, children under 14, withdrawal, and rights requests.
- [China PIPL requirements](/artifacts/apac/china-privacy-law/requirements.md): China PIPL requirements from scope and processing basis through notices, rights, security, impact assessments, incidents, vendors, and data exports.
- [China PIPL vs CCPA/CPRA: Requirements Compared](/artifacts/apac/china-privacy-law/china-pipl-vs-ccpa-cpra.md): Compare PIPL and CCPA/CPRA scope, consent and opt-out rules, rights, assessments, data exports, breach duties, and penalties.
- [China PIPL vs EU GDPR: Requirements Compared](/artifacts/apac/china-privacy-law/china-privacy-law-vs-gdpr.md): Compare PIPL and GDPR scope, roles, legal bases, rights, impact assessments, breach deadlines, international transfers, and penalties.
- [China PIPL vs Singapore PDPA: Requirements Compared](/artifacts/apac/china-privacy-law/china-privacy-law-vs-singapore-pdpa.md): Compare PIPL and Singapore PDPA scope, roles, consent alternatives, rights, breach duties, overseas transfers, and penalties.
- [China Privacy Law FAQ](/artifacts/apac/china-privacy-law/faq.md): Practical answers on China's PIPL: scope, legal bases, sensitive information, separate consent, vendors, PIPIA records, app minimization, and export routes.
- [How should vendor contracts handle entrusted processing under PIPL?](/artifacts/apac/china-privacy-law/faq/how-should-vendor-contracts-handle-entrusted-processing.md): A PIPL entrusted-processing contract must define the purpose, duration, method, personal-information categories, safeguards, and both parties' duties. See the required terms and supporting records.
- [Is PIPL the same as GDPR?](/artifacts/apac/china-privacy-law/faq/is-pipl-the-same-as-gdpr.md): No. China's PIPL and the EU GDPR overlap on core privacy controls, but differ in territorial scope, legal bases, roles, sensitive data, impact assessments, and transfer routes.
- [PIPL automated decision-making and personalized recommendations](/artifacts/apac/china-privacy-law/automated-decision-making-and-personalized-recommendations.md): PIPL checks for automated decisions, personalized recommendations, marketing, differential treatment, explanations, refusal rights, and impact assessments.
- [PIPL breach response and notification](/artifacts/apac/china-privacy-law/breach-response-and-notification.md): PIPL incident workflow for immediate remediation, authority and individual notices, the narrow individual-notice exception, vendor coordination, and evidence.
- [PIPL cross-border transfer route selector](/artifacts/apac/china-privacy-law/pipl-cross-border-transfer-route-selector.md): Step-by-step selector for China's data-export exemptions, CAC security assessment, standard contract, and personal information protection certification.
- [PIPL entrusted processing and vendor contracts](/artifacts/apac/china-privacy-law/entrusted-processing-and-vendor-contracts.md): How to document entrusted processing, vendor responsibilities, contract controls, and evidence under PIPL.
- [PIPL impact assessment template](/artifacts/apac/china-privacy-law/personal-information-protection-impact-assessment-template.md): Template fields for a China personal information protection impact assessment and export/entrusted-processing evidence.
- [Sensitive personal information and separate consent under PIPL](/artifacts/apac/china-privacy-law/sensitive-personal-information-and-separate-consent.md): How to identify sensitive PI triggers, separate consent, minors, additional safeguards, and evidence records.
- [What counts as sensitive personal information in China?](/artifacts/apac/china-privacy-law/faq/what-counts-as-sensitive-personal-information-in-china.md): PIPL uses a harm-based test for sensitive personal information and lists examples such as biometrics, health, financial accounts, location traces, and all personal information of children under 14.
- [What is separate consent under PIPL?](/artifacts/apac/china-privacy-law/faq/what-is-separate-consent-under-pipl.md): Separate consent under China's PIPL is a distinct consent for a specified processing activity. See when it applies, what notice must come first, and what evidence to keep.
- [What records should we keep for a PIPL impact assessment?](/artifacts/apac/china-privacy-law/faq/what-records-should-we-keep-for-a-pipl-impact-assessment.md): A PIPL impact-assessment file should preserve the Article 55 trigger, processing facts, Article 56 analysis, safeguards, decision, and processing record for at least three years.
- [What should an app collect as necessary personal information in China?](/artifacts/apac/china-privacy-law/faq/what-should-an-app-collect-as-necessary-personal-information.md): Match the app's basic function to China's 2021 rules and collect no more than the listed necessary personal information. Users must retain the basic function if they decline non-necessary data.
- [When can a company use the China standard contract route?](/artifacts/apac/china-privacy-law/faq/when-can-a-company-use-the-china-standard-contract-route.md): Use China's standard contract route only after applying the 2024 exemptions and confirming that no CAC security assessment is required. See current thresholds, filing steps, and change triggers.
- [When does a China PIPL security assessment apply?](/artifacts/apac/china-privacy-law/faq/when-does-a-china-pipl-security-assessment-apply.md): A CAC data export security assessment applies to CIIO exports, important data, and specified high-volume personal-information exports after the 2024 exemptions are applied.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-privacy-law/penalties-and-fines.md
