International Privacy Law

PIPL (+ DSL, CSL)

China's personal information law (Nov 2021). Separate consent for sharing and sensitive data; app SDKs are the CAC's main enforcement target.

PIPL (+ DSL, CSL) requirements

China's PIPL has applied since November 1, 2021 and reaches any organization that processes personal information of people in China, including from abroad when offering goods or services to them. It requires a lawful basis, most often consent, and demands separate consent for sharing personal information with other handlers, for processing sensitive information, and for cross-border transfers. Advertising and analytics SDKs embedded in apps have been the Cyberspace Administration of China's most frequent enforcement target, with regular public lists of apps ordered to fix excessive collection. The Data Security Law and Cybersecurity Law add data classification, localization, and security review obligations. Fines reach RMB 50 million or 5 percent of the prior year's revenue. For a mobile app distributed in China, the SDK inventory and what each SDK transmits is the compliance record.

See what your sites and apps actually send

Get a free site analysis: every tracker, mapped to the laws that apply to it.