In an attempt to protect the rights of individuals in relation to their personal data, more than 130 countries have put data privacy laws in place to regulate the collection, processing, storage, and sharing of personal data by organizations and governments. Some of the most well-known privacy regulations include the European Union's General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA).
China is the latest to introduce this type of legislation in the form of the Personal Information Protection Law (PIPL). It is critical for any company doing business with Chinese nationals to be familiar and compliant with PIPL to avoid the heavy penalties and reputational damage that violations will incur.
So what do you need to know and do to be compliant?
PIPL is a comprehensive privacy regulation that came into effect in China in August 2021. It aims to protect personal information by regulating its collection, use, processing, storage, and transmission. PIPL applies to all domestic and foreign businesses and organizations that process the personal information of Chinese citizens.
While data protection legislation is now commonplace, PIPL is unique in several ways compared to other privacy regulations such as the GDPR and CCPA.
One of the most significant differences is that PIPL is tailored to the Chinese legal and cultural context in that it accounts for factors such as China's unique political and economic system, the cultural importance of personal privacy, and the importance of protecting state security and social order.
As a result, PIPL includes provisions not found in other privacy regulations, such as requirements for obtaining explicit consent from individuals for certain types of data processing and restrictions on the cross-border transfer of particular types of data.
Compliance with other privacy regulations does not mean you will automatically be in line with PIPL. Foreign companies operating in China must get relevant local legal and IT input to understand the unique requirements of PIPL.
While the temptation might be to hope that you are covered by compliance with your local legislation, PIPL compliance is crucial for businesses and organizations operating in China for several reasons.
The legal penalties for violating PIPL are onerous and can include hefty fines, the suspension of business activities, rectification orders, and criminal liability for both companies and individuals.
Non-compliance with PIPL can also damage your company's reputation. Authorities in China are permitted to publicize the names of companies that violate PIPL and stories about data breaches or privacy violations spread quickly on social media and other platforms and can be difficult to recover from.
Just as importantly, there are several benefits to businesses in becoming PIPL compliant including:
Becoming PIPL compliant can feel overwhelming, particularly given how complex and sensitive the Chinese business landscape is. There are a few basic steps that companies should take to ensure that they bring their business practices in-line with PIPL requirements. These steps include:
There are some basic best practices for data management and protection under PIPL. Understanding and implementing these will go a long way to ensuring compliance. These include:
Achieving compliance with PIPL can be a challenging task for businesses, especially those that operate in multiple regions with different privacy regulations. Some of the challenges that companies may face include:
Multinational companies with operations in China and other regions with different privacy regulations have some unique considerations and challenges. Some of these include:
While data privacy is nothing new and many companies have been working on compliance with different pieces of data protection legislation for several years, it is crucial for foreign companies operating in China to prioritize compliance with PIPL. PIPL has unique requirements and guidelines for collecting, processing, and storing personal data, and failure to comply can result in legal penalties and damage to reputation.
Given the complexity of both the Chinese legislative framework and the business landscape, it is critical that foreign companies operating in China partner with local teams to help access the relevant combination of IT and legal knowledge, skills, and expertise to implement PIPL requirements effectively.