Skip to content
Is there an AI for this?

Jurisdiction

China (mainland)

Source
Editorial review of primary sources — not yet re-anchored
Verified
Evidence not verified
Confidence
Low

Structured issue-spotting to support your own review — not legal advice. Verify against the cited primary sources and your counsel.

01Framework

Mainland China regulates through three statutes — the Personal Information Protection Law, the Data Security Law and the Cybersecurity Law, the last amended with effect from 1 January 2026 — plus a dense layer of CAC departmental rules. There is no enacted AI law; comprehensive AI legislation sits in the State Council’s 2026 legislative work plan. AI-specific obligations come from the 2023 generative AI interim measures, the 2025 content-labelling measures and, since July 2026, measures on anthropomorphic interaction services. Outbound personal information now has three routes: security assessment, standard contract, and certification.

Region
North Asia
ISO code
CN
Privacy framework
Personal Information Protection Law (PIPL), in force since 1 November 2021. Requires a lawful basis, notice, and separate consent for defined activities including providing personal information to a third party, publicising it, processing sensitive personal information and sending it abroad. Sensitive personal information needs a specific purpose, sufficient necessity and strict protective measures. A personal information protection impact assessment is required before high-risk processing, including any outbound transfer. Article 38 sets the outbound routes. Entrusted processing must be governed by a contract that fixes purpose, period, method and protective measures.
AI-specific rules
No AI statute. The Interim Measures for the Management of Generative AI Services apply to generative services offered to the public inside China, with security assessment and filing obligations for services having public-opinion attributes or social mobilisation capability. The Measures for Labeling AI-Generated Synthetic Content, in force since 1 September 2025, require both explicit and implicit labels on generated content. Since 15 July 2026 there are separate interim measures for anthropomorphic interaction services, expressly excluding intelligent customer service, knowledge question answering, work assistants, learning and education, and research where there is no sustained emotional interaction. The amended Cybersecurity Law now states support for AI research and for AI ethics and risk monitoring.
Last reviewed
20 Aug 2026
Status
published

Cross-border transfer

PIPL Article 38 sets three routes for sending personal information out of China: a CAC-organised security assessment, certification by an accredited body, or the CAC standard contract filed with the provincial cyberspace administration. The certification route was completed by measures in force since 1 January 2026, so an analysis listing only two routes is out of date. The 2024 cross-border provisions relaxed the thresholds and extended the validity of a passed assessment result to three years, although the 2022 measures still state two years in their own text. Separately, Data Security Law Article 36 prohibits providing data stored in China to a foreign judicial or law-enforcement authority without approval — a clause that bites on discovery, subpoenas and vendor-side legal process, not only on ordinary transfers.

Primary sources

  1. Legislation中华人民共和国个人信息保护法 — 中国人大网
  2. Legislation中华人民共和国数据安全法 — 中国人大网
  3. Legislation全国人大常委会关于修改《中华人民共和国网络安全法》的决定 (2025-10-28)
  4. Legislation中华人民共和国网络安全法(2025年修正)— 国家互联网信息办公室
  5. Legislation生成式人工智能服务管理暂行办法 — 国家互联网信息办公室
  6. Legislation人工智能生成合成内容标识办法 — 国家互联网信息办公室
  7. Legislation促进和规范数据跨境流动规定 — 国家互联网信息办公室
  8. Legislation个人信息出境标准合同办法 — 国家互联网信息办公室
  9. Legislation数据出境安全评估办法 — 国家互联网信息办公室
  10. Legislation个人信息出境认证办法 — 国家互联网信息办公室
  11. Legislation人工智能拟人化互动服务管理暂行办法 — 国家互联网信息办公室
  12. Legislation小型个人信息处理者个人信息保护简化措施规定 — 国家互联网信息办公室
  13. Official faqPersonal Information Protection Law — NPC English text (the NPC labels its English texts "Translation for Reference Only")
  14. Official faqData Security Law — NPC English text (the NPC labels its English texts "Translation for Reference Only")

02Regulations and guidance

11 instruments
InstrumentStatus
PI Standard Contract MeasuresOne of the three routes under PIPL Article 38. The handler concludes the CAC standard contract with the overseas recipient and files it with the provincial cyberspace administration within ten working days of the contract taking effect, together with a personal information protection impact assessment.In force
PI Outbound Certification MeasuresCompletes the certification route under PIPL Article 38 by setting the procedure for certifying an outbound transfer of personal information through an accredited body. Earlier inconsistent certification rules give way to these measures. A cross-border analysis that lists only the security assessment and the standard contract is now incomplete.In force
PIPLChina’s personal information law. Requires a lawful basis and separate consent for defined activities, imposes heightened rules on sensitive personal information, requires a personal information protection impact assessment for high-risk processing, and sets the outbound transfer routes in Article 38. It applies to processing inside China and, in defined cases, to processing abroad.In force
DSLEstablishes a data classification and grading protection system, with heavier duties for important data. Article 36 prohibits organisations and individuals in China from providing data stored in China to a foreign judicial or law-enforcement authority without approval from the competent Chinese authority.In force
CSLChina’s network security statute, republished after the 28 October 2025 amending Decision. The amendment added support for artificial intelligence research and for AI ethics and risk monitoring, cross-referenced the PIPL, raised penalty ceilings, and renumbered the articles from 79 to 81.In force
AI Anthropomorphic Interaction MeasuresApplies to services offered to the public in China that simulate a natural person’s personality, thinking and communication style in sustained emotional interaction. The text expressly excludes intelligent customer service, knowledge question answering, work assistants, learning and education, and scientific research where no sustained emotional interaction is involved.In force
AI Labelling MeasuresRequires AI-generated synthetic content to carry labels. Labelling is both explicit — visible to the user — and implicit, added into the content file data by technical means and not readily perceptible. Distribution platforms carry verification duties, and a mandatory national standard sits underneath the measures.In force
Cross-border Data Flow ProvisionsRelaxes and restates the outbound transfer thresholds. Sets volume-based exemptions for non-CII handlers, and extends the validity of a passed outbound data security assessment result to three years from the date it is issued. Read together with the 2022 assessment measures, whose original text on the regulator’s site still states two years.In force
Small Handler Simplified MeasuresCreates a lighter PIPL compliance tier for a small personal information handler, defined as one processing the personal information of fewer than 100,000 individuals. Published on 24 July 2026 and applicable from 1 September 2026, so it was adopted but not yet applicable when this page was reviewed.Adopted, not yet applicable
Outbound Assessment MeasuresThe CAC-organised security assessment route for sending important data or personal information collected in China abroad. Not repealed, but its trigger thresholds and the validity period of an assessment result are displaced by the 2024 cross-border provisions; the original two-year validity still appears in the text on the regulator’s site.In force
Generative AI Interim MeasuresApplies to the use of generative AI technology to provide text, image, audio or video generation services to the public inside China. Services with public-opinion attributes or social mobilisation capability must undergo a security assessment and complete algorithm filing under the applicable rules. In-house tools that are not offered to the public fall outside the stated scope.In force

03Common enterprise issues

5
  • Consent

    Separate consent is a distinct act

    PIPL treats providing personal information to a third party, processing sensitive personal information and sending data abroad as needing separate consent, not a line in a general privacy notice. An AI feature bolted onto an existing product usually needs its own consent flow.

  • Cross-border transfers

    Choosing among three outbound routes

    Assessment, certification and standard contract have different thresholds, timelines and filing duties. The choice depends on volumes, whether the operator is critical information infrastructure, and whether sensitive personal information is involved.

  • Vendor jurisdiction

    Foreign model providers may not be procurable at all

    Before designing around an overseas model API, establish whether the provider offers the service in mainland China and on what contract. This is a question for the vendor and its published availability page, not an assumption.

  • High-risk AI

    Whether the generative AI measures reach an internal tool

    The interim measures are drafted around services provided to the public inside China. An internal assistant is usually outside that scope, but the scope question has to be settled and recorded rather than assumed.

  • Security

    Data classification and grading is a prerequisite

    The Data Security Law builds on a classification and grading system. Until documents are classified, you cannot tell whether important data is in the corpus, and every downstream decision about where it may be processed rests on that.


04Vendor restrictions

4

Restrictions we have written down and the page each one must be checked against. A restriction becomes a verified claim only once the sync job has fetched that page and found the phrase it declares; until then it is an editorial note with a link, and says so.

  • OpenAIclaim pending review

    Mainland China was not found in OpenAI’s supported countries and territories list when it was fetched on 2026-08-20. Procuring the service through an intermediary does not cure a restriction in the vendor’s own terms — read the terms as well as the list.

    Page to verify against

  • Anthropicclaim pending review

    Mainland China was not found in either of Anthropic’s supported-country lists when they were fetched on 2026-08-20.

    Page to verify against

  • Googleclaim pending review

    Mainland China was not found in the Gemini API and Google AI Studio availability list when it was fetched on 2026-08-20.

    Page to verify against

  • Microsoftclaim pending review

    Azure in mainland China is a separate cloud operated by 21Vianet and is not covered by the global Foundry Models region availability page. Treat model availability there as a separate question with separate contracts.

    Page to verify against


05Stacks with notes for this jurisdiction

0

No published stack carries a compliance note for this jurisdiction yet.


06Evidence

0 records · 0 of 11 instruments

Every instrument above that we have fetched and anchored carries a footnote. The rest link to their primary source but have not been fetched and hashed yet, and are marked ASSESSMENT rather than FACT.

No sources were recorded for this answer. Nothing on this page should be treated as verified.

Improve this page

Sign in to contribute

From the field

0 deployments · 0 questions

Nobody has reported deploying this here yet, and no question has been opened against this page. Both appear once a reviewer accepts them.