Pandectes GDPR Compliance - 3,000+ Verified ⭐⭐⭐⭐⭐ 5/5 Reviews Worldwide - #1 on Shopify 🏅

China Personal Information Protection Law (PIPL) Compliance

Pandectes GDPR Compliance helps Shopify stores meet PIPL requirements by collecting consent before non-essential cookies, scanning and classifying cookies, and keeping consent records.

Start Free
PIPL China

The #1 cookie consent app for Shopify, trusted by 185k stores

  • Nike Strength
  • Reebok
  • Ted Baker
  • Juicy Couture
  • Aje
  • Casely
  • Oracle Red Bull Racing
  • KFC
  • Flying Tiger Copenhagen
  • Sennheiser
  • Susanne Kaufmann
  • Aldo
  • Victoria Beckham
  • Scalpers
  • UGREEN

What is PIPL?

The Personal Information Protection Law of the People’s Republic of China (PIPL) is China’s comprehensive law on personal information. It sets the rules for how organizations, which the law calls “personal information processors”, collect, store, use, share and delete information about identified or identifiable people. Many of its ideas will be familiar from the GDPR, but some of its consent rules are stricter.

Key principles of the PIPL include:

  • Processing needs a legal basis, and for most marketing and tracking that basis is the individual’s consent, which must be voluntary, explicit and fully informed.
  • Individuals must be told, before processing, who is processing their information, for what purposes, how, for how long, and how to exercise their rights.
  • Separate consent is required for processing sensitive personal information, sharing information with another processor, making it public, and transferring it outside China.
  • Information about children under 14 counts as sensitive, and needs consent from a parent or guardian.
  • Individuals can withdraw consent at any time, and must be given a convenient way to do so.
  • Individuals have rights to access, copy, correct and delete their information.

Who does the PIPL apply to?

The PIPL applies to the processing of personal information inside China. It also applies to processing outside China when the purpose is to provide products or services to people in China, or to analyze or evaluate their behavior. An online store abroad that sells to customers in China can therefore be covered, and such processors must appoint a representative or set up an office in China.

What happens if I don’t comply with the PIPL?

The PIPL is enforced by the Cyberspace Administration of China (CAC), which coordinates enforcement, together with other government departments within their own areas. Possible consequences include:

  • Corrective orders and warnings: Orders to fix the violation, confiscation of illegal gains, and suspension of apps or services that process information unlawfully.
  • Fines: Up to RMB 1 million for refusing to correct a violation. For serious violations, up to RMB 50 million or 5% of the previous year’s turnover.
  • Personal liability: Responsible managers can be fined between RMB 100,000 and RMB 1 million and barred from senior roles for a period.
  • Business restrictions: Suspension of business operations and revocation of business licenses in serious cases.
  • Credit records: Violations are entered in credit records and can be made public.

Individuals can also bring civil claims for damages caused by unlawful processing.

When did the PIPL go into effect?

The PIPL was adopted on August 20, 2021 and came into force on November 1, 2021. The CAC has since issued further rules, including rules in 2024 that ease some requirements for cross-border transfers.

Complying with the PIPL

For a Shopify store selling to customers in China, the most visible part of the PIPL is consent. Analytics, advertising and other tracking tools that collect personal information should not run until the visitor has explicitly agreed, and a visitor who declines must still be able to use the store unless the information is truly needed to provide the service. Your privacy notice should describe your processing in clear language, and visitors need a convenient way to withdraw consent later.

Cross-border transfer needs particular attention, because most stores send customer information outside China to their platform, payment and marketing providers. The PIPL requires a transfer mechanism, such as the CAC standard contract, unless an exemption applies. The CAC’s 2024 rules exempt some transfers, for example those necessary to fulfil a contract with the customer such as a cross-border purchase, but individuals must still be informed about the overseas recipient and give separate consent. You should also be ready to answer requests from individuals to access, correct or delete their information.

A Consent Management Platform (CMP) like Pandectes GDPR Compliance helps with the parts of this that happen on your storefront. It shows a cookie banner and blocks non-essential cookies until the visitor consents, automatically scans and classifies the cookies on your store, and generates a cookie declaration for your policy. It keeps consent logs as proof of consent, helps you handle data subject requests, and lets you configure banner settings by region using geolocation, so visitors from China can see a banner suited to the PIPL.

Transfer mechanisms, representatives in China and sector rules go beyond what a consent tool can cover, so review your setup with legal counsel where appropriate.

Make your Shopify Store's use of cookies and online tracking compliant today

Try for free