• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Jeff Bezos wants the bottom half of earners to pay zero income tax—he says nurses making just $75K should save $12K a year

2

Despite a $500 million net worth, Shaq just finished his fourth degree. He warns graduates: 'Your character will take you further than your resume'

3

Bolt CEO says he let go of his entire HR team for creating problems that didn’t exist: ‘Those problems disappeared when I let them go’ 

1

Jeff Bezos wants the bottom half of earners to pay zero income tax—he says nurses making just $75K should save $12K a year

2

Despite a $500 million net worth, Shaq just finished his fourth degree. He warns graduates: 'Your character will take you further than your resume'

3

Bolt CEO says he let go of his entire HR team for creating problems that didn’t exist: ‘Those problems disappeared when I let them go’ 
CommentaryChina

What China’s new data privacy rules mean for foreign companies and the future of regulation

By
Nader Henein
Nader Henein
Down Arrow Button Icon
By
Nader Henein
Nader Henein
Down Arrow Button Icon
November 22, 2021, 11:30 AM ET
In theory, the new rules give Chinese users a right to transparency and control over their data.
In theory, the new rules give Chinese users a right to transparency and control over their data.Getty Images

China’s answer to the EU data privacy rules, the Personal Information Protection Law (PIPL), went into effect earlier this month after an expedited process. Proponents hailed it as a significant step towards global standardization in consumer privacy rights. Opponents viewed it as a state tool to curb data dissemination.

Both interpretations may be valid, but only time will tell, as any new set of laws needs sufficient time to “soak in.” In time, outside observers will be able to assess how these laws are enforced and discern between the letter of the law and the spirit in which it is applied.

Consumer privacy rights

The fact is that the PIPL will provide 1.4 billion individuals with transparency and control over their personal data. This almost doubles the global total of consumers that have access to these rights today, bringing it to over three billion. By 2023, this number is projected to jump to five billion people, representing 70% of global GDP.

For organizations handling personal information collected in China, this law will require an additional layer of data governance. Operationally, this new layer is intended to deliver consumer privacy rights and crucially realign corporate strategies regarding where to store, where to process, and with whom they can share customer data.

Very similar to the EU’s General Data Protection Regulation (GDPR), the PIPL outlines a set of consumer privacy rights that fall into three categories: informative, corrective, and restrictive. These rights allow individuals to get a copy of their data, correct it where there are errors, delete it where possible or control how their data is used. This includes objecting to data being used in AI-driven decision making. For example, a bank would have to demonstrate it can reach the same result through a manual process rather than just running the request through an AI decision engine.

Data residency and localization

The PIPL’s data residency rules govern if and when personal information collected in China can be transferred to other countries. The PIPL creates different levels of required diligence depending on the sensitivity and volume of data, but generally, the two principal conditions for cross-border transfers are maintaining a certain level of control over the data and securing the consent of the consumer.

Control of cross-border transfers is workable and should be familiar to many organizations doing business in China, as they likely already follow a similar certification process as required by the Multi-level Protection Scheme (MLPS) which China established in late 2019.

However, consent makes cross-border transfers impractical, because even if a minority of individuals object to the transfer of their data, it would require the establishment of local store-and-compute capabilities.

The PIPL does allow for some exceptions, but they are limited to specific use cases such as HR and where there is an unavoidable necessity.

The good news is that the PIPL is similar to the GDPR in many ways. It’s not as comprehensive, and it will likely be heavily supported with ongoing guidance from the regulatory bodies. But for organizations that have taken the last few years to put in place a modern privacy program, satisfying these new consumer privacy rights should not represent a challenge.

The not-so-good news is that the PIPL is not the GDPR. Processing data as part of a contractual or legal obligation is covered, but critically, the concept of “legitimate interest” continues to be absent, which means that many use cases that involve the processing of personal information will have to rely on informed consent.

Since cross-border transfers will also rely largely on individual consent, centralized storage and processing of personal data outside of China will remain challenging.

Where should organizations focus?

Two critical areas should be at the top of an organization’s priority list in China: Privacy user experience (UX) and data residency.

Crafting a well-developed privacy UX will be critical for organizations handling personal information in China, both to satisfy regulatory requirements and improve consumer sentiment, boosting consent rates. Critical aspects of privacy UX include providing transparency to individuals when collecting their data and providing individuals with a privacy portal where they can exercise their consumer rights and manage consent.

Data residency requirements are such that organizations should budget for localized governance and technology in China as part of market entry or market expansion. The transfer of identifiable data from China to other countries will be difficult, but anonymized or aggregate data will afford organizations much more flexibility for centralized processing.

China’s latest rules come amid a general crackdown on the tech sector. Unlike the EU, which has independent courts, their outcomes will largely depend on what the country’s leaders decide to do next. For now, foreign companies should tread carefully and onshore user data when possible.

Nader Henein is privacy research VP at Gartner.

More must-read commentary published by Fortune:

  • The U.S. urgently needs an A.I. Bill of Rights
  • Meet the unsung heroes of climate change
  • I know how lobbyists make sure Americans don’t get dental care–I was one of them
  • Millennials and Gen Z are a growing force in investing. The market needs to catch up
  • Don’t let them tell you inflation is good for the poor. It’s not

Subscribe to Fortune Daily to get essential business stories straight to your inbox each morning.

About the Author
By Nader Henein
See full bioRight Arrow Button Icon

Latest in Commentary

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Commentary

brotman
CommentaryVenture Capital
I’ve spent 25 years in venture capital. Here’s how it quietly shut ordinary Americans out of the AI wealth boom—and what could fix it
By Steve BrotmanMay 22, 2026
16 hours ago
cox
CommentarySuccession
McKinsey studied 200 family business successions. The biggest problem wasn’t the heir — it was the outgoing CEO
By Acha Leke and Chaitali MukherjeeMay 22, 2026
17 hours ago
himanshu
CommentaryLayoffs
I’ve led companies through every major tech disruption. AI washing is the same mistake, every time
By Himanshu PalsuleMay 22, 2026
20 hours ago
trump
CommentaryWhite House
Trump Accounts have a bigger problem than billionaire stock donations
By Jin Huang and Stephen RollMay 21, 2026
2 days ago
brigham
CommentaryRailroads
The U.S. freight network is broken by design. One merger could start fixing it
By Brigham A. McCownMay 21, 2026
2 days ago
Elon Musk sits with his fists together, looking up.
Commentaryspace
SpaceX will be worth trillions, but the space station that made it possible is worth even more — if we don’t squander it
By Tejpaul BhatiaMay 20, 2026
2 days ago

Most Popular

Jeff Bezos wants the bottom half of earners to pay zero income tax—he says nurses making just $75K should save $12K a year
Success
Jeff Bezos wants the bottom half of earners to pay zero income tax—he says nurses making just $75K should save $12K a year
By Preston ForeMay 21, 2026
2 days ago
Despite a $500 million net worth, Shaq just finished his fourth degree. He warns graduates: 'Your character will take you further than your resume'
Success
Despite a $500 million net worth, Shaq just finished his fourth degree. He warns graduates: 'Your character will take you further than your resume'
By Preston ForeMay 20, 2026
3 days ago
Bolt CEO says he let go of his entire HR team for creating problems that didn’t exist: ‘Those problems disappeared when I let them go’ 
Workplace Culture
Bolt CEO says he let go of his entire HR team for creating problems that didn’t exist: ‘Those problems disappeared when I let them go’ 
By Preston ForeMay 19, 2026
3 days ago
Pay transparency is exposing a bigger problem: Most companies can't explain why they pay what they pay
Workplace Culture
Pay transparency is exposing a bigger problem: Most companies can't explain why they pay what they pay
By Sydney LakeMay 20, 2026
2 days ago
Indeed chief economist says we’re entering an era of ‘great mismatch’ thanks to a generational imbalance of workers
Success
Indeed chief economist says we’re entering an era of ‘great mismatch’ thanks to a generational imbalance of workers
By Emma BurleighMay 22, 2026
13 hours ago
Microsoft reports are exposing AI's real cost problem: Using the tech is more expensive than paying human employees
AI
Microsoft reports are exposing AI's real cost problem: Using the tech is more expensive than paying human employees
By Jake AngeloMay 22, 2026
12 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.