Skip to content
Coverage

Data rights

China — Personal Information Protection Law (PIPL)

NationalCNDerived or secondary source

People's Republic of China

Rule id
data.cn-pipl
Version
1.0.0
In force from
November 1, 2021
Last read against its sources
August 5, 2026
Countries bound
China

In plain language

What this regime says.

China — Personal Information Protection Law (PIPL) gives individuals rights over the personal data organisations hold about them, and sets a deadline for answering.

Who is covered

Individuals whose personal data is processed by an organisation within the reach of People's Republic of China.

What you get

A copy of your data, correction, deletion or an opt-out — depending on the right you exercise. Money is rare: see the enforcement section.

Where claims go wrong

  • Sending the request to a support chatbot rather than to the privacy or data-protection contact, so the clock never starts.
  • Not keeping proof of the date you sent it — the whole deadline analysis rests on that date.
  • Assuming a missed deadline means money. In almost every jurisdiction it does not; it means a regulator complaint.

Authority

Every citation,
with its pinpoint.

A claim that cites “EU law” gets filed. A claim that cites Article 7(1)(c) gets answered. These are the exact coordinates this entry rests on.
  1. 中华人民共和国个人信息保护法 (Personal Information Protection Law), Arts. 44–50, 69Personal Information Protection Law of the People's Republic of ChinaURL verified 2026-08-05Art. 45 (access and copy), Art. 46 (correction), Art. 47 (deletion), Art. 50 (the handler's duty to establish a request mechanism and the right to sue on refusal), Art. 69 (reversed burden of proof on damages)

Sources

Where a figure is indexed, converted or published by a regulator rather than fixed in the instrument, the provenance is recorded separately. Anything marked as a modelled estimate is exactly that — a model, not a statutory number.

What it imposes

Clocks, defences and the ladder.

A rule module builds these while it evaluates, because a limitation period depends on which forum is open to you. What follows is the structure this regime produces — deliberately with no dates and no figures, because those belong to your facts rather than to the law.

The clocks it starts

  • China — Personal Information Protection Law (PIPL): deadline for the controller to respondThe PIPL requires a handler to establish a mechanism to accept and process requests and to respond in a timely manner, but it fixes no numerical deadline. Thirty days follows the national standard GB/T 35273 and is what regulators and platforms work to in practice. It is NOT a statutory deadline — say "promptly, and in any event within the period contemplated by the national standard" rather than asserting a legal thirty-day right.中华人民共和国个人信息保护法 (Personal Information Protection Law), Arts. 44–50, 69 — Art. 45 (access and copy), Art. 46 (correction), Art. 47 (deletion), Art. 50 (the handler's duty to establish a request mechanism and the right to sue on refusal), Art. 69 (reversed burden of proof on damages)Response due

What it entitles you to, beyond money

  • Compliance with your access requestThe right to consult and copy your personal information held by a handler. Art. 45 also gives a right to have your personal information TRANSFERRED to a handler you designate, where the conditions set by the Cyberspace Administration are met — China legislated portability at the same time as access.Art. 45

What the other side will say

Each of these is a refusal this regime lets a counterparty attempt, paired with the answer to it. Reading them before you write is worth more than any amount of polish on the letter itself.

Endless identity verification

high likelihood

We cannot action your request until you verify your identity. Please send a copy of your passport, a utility bill, and a selfie holding your ID.

What answers it

A controller may use reasonable measures to verify identity, but it may only ask for information it actually needs and already holds a basis to check. Demanding a passport scan from someone whose account you identify by email address is disproportionate and is itself a data-minimisation problem. Offer to verify through the same channel you already use to log in, state that you consider the demand excessive, and note that the response clock is running.

"We hold no personal data about you"

high likelihood

A search of our systems returned no personal data relating to you.

What answers it

Ask for that in writing, signed, together with a description of the systems searched and the search terms used. A nil return is a substantive answer that the controller must stand behind, and it is frequently wrong: it usually means one production database was searched and backups, CRM, marketing, support tickets, call recordings, and third-party processors were not. Name the systems you believe hold your data, including any you have interacted with.

Blanket confidentiality or trade-secret refusal

medium likelihood

The information you have requested is commercially confidential / contains our trade secrets / is proprietary.

What answers it

Confidentiality and intellectual-property carve-outs are narrow and must be applied item by item, not as a blanket. The correct response is redaction of the protected element and disclosure of the rest, with a schedule explaining what was withheld and why. Ask for that schedule.

Refusal because the data mentions someone else

medium likelihood

We cannot disclose these records because they contain the personal data of other individuals.

What answers it

The presence of third-party data is a reason to redact, not to refuse. The controller must consider whether it can disclose with the third party removed, whether the third party has consented, and whether it is reasonable to disclose without consent. A blanket refusal on this ground is not a lawful answer.

"Your request is manifestly excessive"

medium likelihood

Your request is manifestly unfounded or excessive, so we are refusing it / charging a fee.

What answers it

The burden of showing that a request is manifestly unfounded or excessive is on the controller, and it is a high bar — the regulator guidance treats it as exceptional, not as a routine response to a broad request. Ask the controller to state, in writing, the specific grounds and the evidence for them. If you have made only one request, say so. A single, first, ordinary request is not excessive.

Where to take it next

  1. Written request to Sample ControllerSend it to the named data-protection contact or privacy team, in writing, and keep proof of the date. If the organisation has a designated Data Protection Officer, address it to them by title. Use the word "request" and name the right you are exercising.Claim directtypically 30 days
  2. Internal appeal / complaint to the controllerUse the handler's own request channel first — Art. 50 obliges it to have one — and keep the refusal, because Art. 50 requires reasons and the refusal is what unlocks the lawsuit.Internal appealtypically 45 days
  3. Complain to the Cyberspace Administration of China and the sectoral regulatorsthe Cyberspace Administration of China and the sectoral regulators takes complaints from individuals about a specific organisation's handling of a specific request. It is free. Attach your original request, proof of the date you sent it, and anything the organisation sent back.Regulatortypically 60 daysofficial page

Documents

What this regime can produce.

Every one of these is a document you send yourself, in your own name. Duesday never writes to anybody on your behalf and is never anyone’s agent.

The same claim type elsewhere

Other rights in the same countries

China — rental deposit (中华人民共和国民法典 (Civil Code of the PRC), Book Three, Chapter 14 (lease contracts), together with the municipal housing rental regulations of the city where the property is)CNNationalChina中华人民共和国民法典 (Civil Code of the PRC), Book Three, Chapter 14 (lease contracts), together with the municipal housing rental regulations of the city where the property isConfidence: lowChina — 航班正常管理规定 (Flight Normality Management Provisions, CCAR-271)CNNationalChina航班正常管理规定(交通运输部令2016年第56号),第十七条Confidence: mediumChina — E-Commerce Law and the 2024 Consumer Rights Protection Law Implementing RegulationsCNNationalChina中华人民共和国消费者权益保护法实施条例 (Regulations for the Implementation of the Law on the Protection of Consumer Rights and Interests), State Council Decree No. 778Confidence: mediumChina — payment services supervision and UnionPay card dispute rulesCNNationalChina非银行支付机构监督管理条例 (Regulations on the Supervision and Administration of Non-bank Payment Institutions), State Council Decree No. 768Confidence: lowPeople's Republic of China — China PostCNNationalChina中华人民共和国邮政法 (Postal Law of the People's Republic of China)Confidence: lowPeople's Republic of China — China Railway refund and change rules (铁路旅客运输规程)CNNationalChina铁路旅客运输规程 (Regulations on Railway Passenger Transport) and the Railway Law of the PRCConfidence: low

Does this one reach your facts?

The engine runs every regime that could apply at once and reconciles them, rather than making you guess which page to read.

Not a law firm. Not legal advice. You send it yourself. This page describes a law; it is not advice about your situation and no outcome is promised.