China — data protection and AI governance

Personal Information Protection Law (PIPL), in force since 2021-11-01. Supervisory authority: CAC.

CNPriority jurisdiction — re-verified every cycleVerified on Lire en français

Data protection

Instrument
Personal Information Protection Law (PIPL)
In force since
2021-11-01
Authority
CAC
Penalties
50M RMB ou 5% CA
Key obligations
  • Consentement
  • Localisation
  • Évaluation transferts
  • DPO grande échelle

What the engine decides here

These three attributes are what an agent decision depends on in this jurisdiction. They are modelled, sourced and dated.

Transfer regime
Restricted

Moving data out is restricted: it requires a recognised destination, or an explicit mechanism when the destination is not one.

Localisation mandate
Yes
Automated decision rights
Yes
Verified on
2026-08-14

Three decisions, computed just now

Same actions, this jurisdiction's context. These answers come out of the engine as the page renders — the same function the API calls.

  • Read an internal contract

    Low-risk operation

    ALLOW
  • Send a customer record to US_FED

    The transfer requires a mechanism

    APPROVE
  • Decide on a job application

    Decision reserved for a human

    DENY

Advisory decisions. StructureClerk decides; your infrastructure enforces.

AI governance

Framework
Interim Measures GenAI + Algorithm Rules
Status
enacted
Date
2023-08-15
Key points
  • Enregistrement
  • Filtrage contenu
  • Évaluation sécurité

Cybersecurity

Framework
CSL + DSL + MLPS 2.0
Key points
  • Classification
  • Localisation données importantes
  • CII protection

Do your agents operate in China?

The authority API makes these attributes executable: an ALLOW, APPROVE, DENY or ESCALATE decision before the agent acts, with signed evidence any third party can verify.

Other jurisdictions — Asia-Pacific