China’s Draft Privacy Law Both Builds On and Complicates Its Data Governance

The Chinese government in October released the long-awaited draft of its comprehensive privacy law, the Personal Information Protection Law (PIPL). DigiChina’s full English translation is here. As a whole, the draft PIPL largely follows mainstream global approaches to personal data protection, adopting many elements common to other privacy laws, such as notice-and-consent, individual rights, and a comprehensive set of data governance duties for personal information handlers. Notably, it also briefly addresses some still emerging topics in privacy law, such as algorithmic transparency and facial recognition. And it restricts processing of personal information that has already been made public, limiting further use of such data to the scope of use for which the data was originally made public. The draft PIPL is a crucial piece for China’s data governance legal regime, and although it is still subject to revision, it provides insight into the evolving process and potential future directions of Chinese regulation.
The draft PIPL’s legislative history can be traced back to as early as 2003, when the State Council assigned the job of brainstorming a Chinese privacy law to the Institute of Law at the Chinese Academy of Social Sciences. After a thorough study of privacy laws from the European Union and many countries, including the United States, Japan, South Korea, and Canada, the Chinese scholars, led by Zhou Hanhua, prepared an earlier draft PIPL in 2005, seeking to establish a framework built upon the experiences of other countries but tailor-made for China’s political and social realities. Unfortunately, for various reasons, that effort didn’t make it to the National People’s Congress (NPC) for an official legislative process. Fifteen years later, the latest draft PIPL released for comment by the NPC’s legislative team has emerged in a different technological environment and amidst an already burgeoning domestic data governance regime.
Currently, China’s Cybersecurity Law is the most common reference point in Chinese privacy law. This milestone law, which came into force in June 2017, was in its own words enacted to “ensure cybersecurity; safeguard cyberspace sovereignty and national security, and social and public interests; protect the lawful rights and interests of citizens, legal persons, and other organizations; and promote the healthy development of the informatization of the economy and society” (Article 1). With its emphasis on cybersecurity, national security, and national interests, the Cybersecurity Law is one of three recent pillars framing China’s national security legal regime, together with the National Security Law and the Anti-Terrorism Law. Still, it is also a significant piece of China’s data governance regime.
As this DigiChina timeline shows, prior to the Cybersecurity Law, China already had quite a few sectoral laws addressing personal information protection, with differing levels of detail and stringency, in the areas such as finance, credit reporting, telecommunications, internet, healthcare, e-commerce, and postal services. China also criminalizes certain privacy-relevant behaviors, including the illegal sale or provision of personal information, or refusal by a network service provider to fulfill its administrative duties to maintain information network security under circumstances specified in the Criminal Law.
Since enactment of the Cybersecurity Law, China has accelerated the establishment of a broader data governance regime, issuing or proposing numerous supporting or related regulations, as well as national standards, to help implement the Cybersecurity Law. Among these are a special regulation on children’s personal data, a draft regulation on security assessment for the cross-border transfer of personal data, and the Personal Information Security Specification (a national standard that, while technically nonbinding, exerts great influence on companies doing business in China).


