# PIPL (China Personal Information Protection Law 2021)

Source: https://onco.cc/terms/pipl/  
OnCo record `pipl` (Term). Data CC BY-NC 4.0, attribute "Data from OnCo (onco.cc)"; commercial use needs a licence.

## TL;DR

China's 2021 privacy law, in force since November 2021, treats medical and health data as sensitive information requiring separate consent, and together with the Data Security Law restricts sending patient data out of China, which shapes every international cancer trial run there.

## Summary

China, statute. The Personal Information Protection Law was adopted by the Standing Committee of the National People's Congress on 20 August 2021 and took effect on 1 November 2021, alongside the Data Security Law (effective 1 September 2021) and building on the Cybersecurity Law of 2017. Primary text: the National People's Congress publishes the Chinese text; the Wikipedia article summarises the provisions in English.

What it requires: a lawful basis and purpose limitation for processing personal information, with 'sensitive personal information', which explicitly includes medical health, biometric and genetic data and the data of minors under fourteen, requiring separate consent and a necessity justification; individual rights of access, correction and deletion; impact assessments; and, for cross-border transfers, a security assessment by the Cyberspace Administration of China, certification, or a standard contract, depending on volume and sensitivity, under measures issued in 2022 to 2024 that later eased the thresholds for lower-volume transfers. Critical information infrastructure operators and large processors must store data in China.

Why it matters for oncology and the arguments: multinational trials and genomic collaborations must now separate consent for research use, localise data and obtain approval before transferring identifiable patient data to sponsors abroad, on top of the separate Human Genetic Resources rules governing samples and genetic data. Foreign sponsors describe the layered approvals as a barrier that delays trial start-up and data cuts; Chinese regulators frame it as parity with the GDPR, on whose structure the law draws, though with far weaker limits on state access.

## Fields

- Kind: Term
- Last checked: 2026-09-17
- Also known as: PIPL; Personal Information Protection Law; Personal Information Protection Law of the People's Republic of China; sensitive personal information; China cross-border data transfer; Data Security Law
- Tags: law; cn

## Sources

- Wikipedia: https://en.wikipedia.org/wiki/Personal_Information_Protection_Law_of_the_People%27s_Republic_of_China
- Wikipedia: https://en.wikipedia.org/wiki/Personal_Information_Protection_Law_of_the_People%27s_Republic_of_China

## Connected records

- terms: [BIOSECURE Act](https://onco.cc/terms/biosecure-act/), [China Drug Administration Law (2019) and expedited pathways](https://onco.cc/terms/china-drug-administration-law/), [China Human Genetic Resources rules (2019, 2023)](https://onco.cc/terms/china-hgr-rules/), [Clinical Trials Regulation (EU) No 536/2014 and CTIS](https://onco.cc/terms/eu-clinical-trials-regulation/), [GDPR and health data (Regulation (EU) 2016/679)](https://onco.cc/terms/gdpr/), [HIPAA (Health Insurance Portability and Accountability Act)](https://onco.cc/terms/hipaa/), [UK Data Protection Act 2018 and health data law](https://onco.cc/terms/uk-data-protection-act/)
- institutions: [National Medical Products Administration / Center for Drug Evaluation](https://onco.cc/institutions/nmpa-cde/)
- bottlenecks: [Data silos](https://onco.cc/bottlenecks/b-data-silos/), [Regulatory divergence between regions](https://onco.cc/bottlenecks/b-regulatory-fragmentation/)

---
JSON: https://onco.cc/api/v1/entities/pipl.json