7/24 Service · Chinese / English

China Cybersecurity and PIPL Enforcement: A Defence Guide

The CSL, the Data Security Law and the PIPL now form a single enforcement machine. Here is how it is wielded, what the fines look like, and how a company under investigation should respond.

China's data regime is built on three statutes that arrived in quick succession and now operate as one system: the Cybersecurity Law (网络安全法, the "CSL"), effective 1 June 2017; the Data Security Law (数据安全法, the "DSL"), effective 1 September 2021; and the Personal Information Protection Law (个人信息保护法, the "PIPL"), effective 1 November 2021. For a foreign company in China, the practical question is not which law applies — it is usually all three — but how the Cyberspace Administration of China (CAC) and the other regulators enforce them, and what a company does the day an inspection or a penalty notice arrives.

The two-tier penalty in PIPL Article 66

The fine structure most companies ask about is PIPL Article 66, and it is worth understanding precisely because it is two-tiered. For an ordinary violation, the regulator orders correction, warns, confiscates unlawful gains and may suspend or terminate the app or service; if the processor refuses to correct, the fine is up to RMB 1,000,000, with responsible persons fined between RMB 10,000 and RMB 100,000. The serious tier is a different order of magnitude: where circumstances are serious (情节严重), the penalty is a fine of up to RMB 50,000,000 or up to 5% of the previous year's turnover — alternatives, not cumulative — together with possible suspension of business, rectification orders or a request that the business licence be revoked, and responsible persons face fines of RMB 100,000 to RMB 1,000,000 and possible disqualification from director, supervisor, senior-manager and data-protection-officer roles. The common shorthand that "responsible persons face up to RMB 1 million" is true only in the serious tier; in the ordinary tier the cap is RMB 100,000.

Cross-border data transfer: which route applies

The export of personal information out of China is channelled through three routes under PIPL Article 38: a CAC-organised security assessment, professional certification, or a standard contract. The operative thresholds were materially reset by the Provisions on Promoting and Regulating Cross-Border Data Flows, effective 22 March 2024, and refined by later CAC instruments:

  • Security assessment is mandatory for critical information infrastructure operators (CIIOs) exporting personal information, for the export of important data, and for non-CIIO processors that, since 1 January of the current year, have cumulatively exported the personal information of more than one million individuals, or the sensitive personal information of more than ten thousand individuals.
  • Standard contract or certification is available to non-CIIO processors exporting the personal information of between 100,000 and one million individuals (non-sensitive), or fewer than ten thousand individuals' sensitive personal information, where no important data is involved.

Because these thresholds have moved twice since 2022, they must be checked against the current CAC texts at the time of any transfer — do not rely on a remembered figure. Splitting a transfer into smaller batches to stay under a threshold is expressly treated as evasion.

Enforcement in practice

The landmark public case under the new regime remains the CAC's July 2022 penalty on DiDi of approximately RMB 8.026 billion for violations of the CSL, the DSL and the PIPL — the reference point for how the serious tier operates in the real world. Below that level, the CAC and its provincial branches regularly publish administrative penalties and app-removal notices for unlawful personal-information processing, and foreign-invested enterprises are not exempt. The realistic exposure for most companies is not a headline fine but a cumulative set of correction orders, confiscations, app takedowns and the reputational and commercial damage that follows a published penalty.

Defending a company under investigation

The defence starts before the penalty, not after it. A company that receives an inspection notice or a rectification demand should immediately: map which of the three statutes the alleged conduct engages, and which tier of Article 66 the regulator is invoking; secure the technical and documentary record of data processing — retention, consent, cross-border transfer mechanisms — because the written record, not oral explanation, is what the regulator and any later administrative litigation will be decided on; and treat a rectification order as a fork in the road, since correction within the required period is the single most effective way to stay out of the serious tier. Where a penalty is imposed, administrative reconsideration and administrative litigation are available, and the burden on the regulator to justify the tier — ordinary versus serious — is a genuine point of contest.

Compliance in this field is a programme, not a document, and it shares its logic with the broader compliance-programme defence we describe in our note on corporate criminal liability and compliance programs in China. If you are facing an inspection, penalty or app-removal proceeding, our first-steps guide sets out the immediate actions, and our team can advise on the specific defence. Because the data-export thresholds and the standard-contract filing measures are adjusted by CAC notice, always confirm the operative rules against the current official texts before acting.

This article is provided by Tianni Law Firm for general information only and does not create an attorney-client relationship. For legal advice on a specific matter, please contact a qualified attorney.

Facing a CAC inspection or data penalty?

We defend companies in data-protection investigations, administrative reconsideration and cross-border transfer compliance.

Get a Free Consultation