• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

The Pentagon said Iran War costs $29 billion, but the real cost is closer to $200 billion—and counting

2

After forcing workers back to the office, Goldman Sachs and JPMorgan Chase are now letting their staff work remotely—but only for the World Cup

3

Now worth $200 million, Sarah Jessica Parker credits being ‘one of eight kids that struggled financially’ for her hunger, ambition, and work ethic

1

The Pentagon said Iran War costs $29 billion, but the real cost is closer to $200 billion—and counting

2

After forcing workers back to the office, Goldman Sachs and JPMorgan Chase are now letting their staff work remotely—but only for the World Cup

3

Now worth $200 million, Sarah Jessica Parker credits being ‘one of eight kids that struggled financially’ for her hunger, ambition, and work ethic
CommentaryChina

What China’s new data privacy rules mean for foreign companies and the future of regulation

By
Nader Henein
Nader Henein
Down Arrow Button Icon
By
Nader Henein
Nader Henein
Down Arrow Button Icon
November 22, 2021, 11:30 AM ET
In theory, the new rules give Chinese users a right to transparency and control over their data.
In theory, the new rules give Chinese users a right to transparency and control over their data.Getty Images
Add Fortune on Google for similar content.

China’s answer to the EU data privacy rules, the Personal Information Protection Law (PIPL), went into effect earlier this month after an expedited process. Proponents hailed it as a significant step towards global standardization in consumer privacy rights. Opponents viewed it as a state tool to curb data dissemination.

Both interpretations may be valid, but only time will tell, as any new set of laws needs sufficient time to “soak in.” In time, outside observers will be able to assess how these laws are enforced and discern between the letter of the law and the spirit in which it is applied.

Consumer privacy rights

The fact is that the PIPL will provide 1.4 billion individuals with transparency and control over their personal data. This almost doubles the global total of consumers that have access to these rights today, bringing it to over three billion. By 2023, this number is projected to jump to five billion people, representing 70% of global GDP.

For organizations handling personal information collected in China, this law will require an additional layer of data governance. Operationally, this new layer is intended to deliver consumer privacy rights and crucially realign corporate strategies regarding where to store, where to process, and with whom they can share customer data.

Very similar to the EU’s General Data Protection Regulation (GDPR), the PIPL outlines a set of consumer privacy rights that fall into three categories: informative, corrective, and restrictive. These rights allow individuals to get a copy of their data, correct it where there are errors, delete it where possible or control how their data is used. This includes objecting to data being used in AI-driven decision making. For example, a bank would have to demonstrate it can reach the same result through a manual process rather than just running the request through an AI decision engine.

Data residency and localization

The PIPL’s data residency rules govern if and when personal information collected in China can be transferred to other countries. The PIPL creates different levels of required diligence depending on the sensitivity and volume of data, but generally, the two principal conditions for cross-border transfers are maintaining a certain level of control over the data and securing the consent of the consumer.

Control of cross-border transfers is workable and should be familiar to many organizations doing business in China, as they likely already follow a similar certification process as required by the Multi-level Protection Scheme (MLPS) which China established in late 2019.

However, consent makes cross-border transfers impractical, because even if a minority of individuals object to the transfer of their data, it would require the establishment of local store-and-compute capabilities.

The PIPL does allow for some exceptions, but they are limited to specific use cases such as HR and where there is an unavoidable necessity.

The good news is that the PIPL is similar to the GDPR in many ways. It’s not as comprehensive, and it will likely be heavily supported with ongoing guidance from the regulatory bodies. But for organizations that have taken the last few years to put in place a modern privacy program, satisfying these new consumer privacy rights should not represent a challenge.

The not-so-good news is that the PIPL is not the GDPR. Processing data as part of a contractual or legal obligation is covered, but critically, the concept of “legitimate interest” continues to be absent, which means that many use cases that involve the processing of personal information will have to rely on informed consent.

Since cross-border transfers will also rely largely on individual consent, centralized storage and processing of personal data outside of China will remain challenging.

Where should organizations focus?

Two critical areas should be at the top of an organization’s priority list in China: Privacy user experience (UX) and data residency.

Crafting a well-developed privacy UX will be critical for organizations handling personal information in China, both to satisfy regulatory requirements and improve consumer sentiment, boosting consent rates. Critical aspects of privacy UX include providing transparency to individuals when collecting their data and providing individuals with a privacy portal where they can exercise their consumer rights and manage consent.

Data residency requirements are such that organizations should budget for localized governance and technology in China as part of market entry or market expansion. The transfer of identifiable data from China to other countries will be difficult, but anonymized or aggregate data will afford organizations much more flexibility for centralized processing.

China’s latest rules come amid a general crackdown on the tech sector. Unlike the EU, which has independent courts, their outcomes will largely depend on what the country’s leaders decide to do next. For now, foreign companies should tread carefully and onshore user data when possible.

Nader Henein is privacy research VP at Gartner.

More must-read commentary published by Fortune:

  • The U.S. urgently needs an A.I. Bill of Rights
  • Meet the unsung heroes of climate change
  • I know how lobbyists make sure Americans don’t get dental care–I was one of them
  • Millennials and Gen Z are a growing force in investing. The market needs to catch up
  • Don’t let them tell you inflation is good for the poor. It’s not

Subscribe to Fortune Daily to get essential business stories straight to your inbox each morning.

About the Author
By Nader Henein
See full bioRight Arrow Button Icon
Add Fortune on Google for similar content.

Latest in Commentary

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Commentary

Asia’s defense boom is rewiring the global arms supply chain
Commentaryarms, weapons, and defense
Asia’s defense boom is rewiring the global arms supply chain
By Chris OberoiJune 24, 2026
9 hours ago
steve
Commentary250 Years of Innovation
Steve Case: America was built by entrepreneurs. Here’s how we keep that edge for the next 250 years
By Steve CaseJune 24, 2026
17 hours ago
t
CommentaryWhite House
Trump mistakes the bully pulpit for bullying leadership — history’s villains were never heroes
By Jeffrey Sonnenfeld and Steven TianJune 24, 2026
18 hours ago
mg
CommentaryHealth
The ‘tech neck’ time bomb: why 43 million young Americans could cripple U.S. health care within a generation
By Michael GerlingJune 24, 2026
18 hours ago
sb
Commentaryclimate change
The climate policy triangle: why leaders can no longer choose between growth, security and sustainability
By Sebastian BuckupJune 23, 2026
1 day ago
brett
CommentaryManagement
Middle managers aren’t going extinct—they’re evolving into something more powerful
By Brett HurtJune 23, 2026
2 days ago

Most Popular

The Pentagon said Iran War costs $29 billion, but the real cost is closer to $200 billion—and counting
Economy
The Pentagon said Iran War costs $29 billion, but the real cost is closer to $200 billion—and counting
By Jacqueline MunisJune 24, 2026
23 hours ago
After forcing workers back to the office, Goldman Sachs and JPMorgan Chase are now letting their staff work remotely—but only for the World Cup
Success
After forcing workers back to the office, Goldman Sachs and JPMorgan Chase are now letting their staff work remotely—but only for the World Cup
By Orianna Rosa RoyleJune 23, 2026
2 days ago
Now worth $200 million, Sarah Jessica Parker credits being ‘one of eight kids that struggled financially’ for her hunger, ambition, and work ethic
Success
Now worth $200 million, Sarah Jessica Parker credits being ‘one of eight kids that struggled financially’ for her hunger, ambition, and work ethic
By Orianna Rosa RoyleJune 24, 2026
23 hours ago
Amazon's record Prime Day masks a darker truth: Americans are spending more and getting less
Retail
Amazon's record Prime Day masks a darker truth: Americans are spending more and getting less
By Nick LichtenbergJune 24, 2026
15 hours ago
Ray Dalio just finished a 10-day trip to China. He says global leaders know America ‘doesn’t have what it takes to fight to maintain its empire’
Asia
Ray Dalio just finished a 10-day trip to China. He says global leaders know America ‘doesn’t have what it takes to fight to maintain its empire’
By Nick LichtenbergJune 24, 2026
16 hours ago
Current price of gold as of June 23, 2026
Personal Finance
Current price of gold as of June 23, 2026
By Danny BakstJune 23, 2026
2 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.