Do I need consent to collect customer data in China?

Date:

Share post:

Do I Need Consent to Collect Customer Data in China?

Yes, under China’s 个人信息保护法 (Personal Information Protection Law, PIPL, gèrén xìnxī bǎohù fǎ), businesses must obtain separate, explicit consent before collecting most categories of customer data — with no fewer than 6 mandatory consent scenarios defined across the law’s 74 articles. The PIPL, effective since November 1, 2021, introduced a compliance framework that demands active opt-in for sensitive personal information and limited exceptions for non-sensitive data. For foreign companies operating through a 外商独资企业 (wholly foreign-owned enterprise, WFOE, wàishāng dúzī qǐyè) or any China-based entity, understanding when consent is required — and when it is not — is the difference between lawful operations and penalties reaching 50 million RMB (approximately 6.9 million USD) or 5% of annual revenue.

Four numbers that define China’s consent requirements: The PIPL imposes fines of up to 50 million RMB or 5% of annual revenue for serious violations — more than 1 billion RMB in penalties have been levied against companies since 2021. Industry surveys show 80% of data compliance violations involve improper consent collection. Regulators require companies to respond to data subject rights requests within 30 days. And China now ranks 2nd globally in data protection enforcement intensity, behind only the EU’s GDPR.

When Is Explicit Consent Required Under PIPL?

The PIPL mandates explicit, informed, and voluntary consent for all processing of 敏感个人信息 (sensitive personal information, mǐngǎn gèrén xìnxī) — defined as data that could harm personal dignity or property if leaked or misused. This includes financial account details, biometric data, health records, precise location tracking, and data of minors under 14 years old. For non-sensitive personal information (names, contact numbers, general browsing behavior), consent is still the default rule, but the law provides narrow exceptions where implied consent or legitimate interest may apply.

Consent must meet three strict criteria: separate consent (cannot bury consent in general terms), independent choice (no bundled consent where refusal blocks core service), and revocable consent (users can withdraw consent at any time without penalty). For sensitive data, the law further requires a 单独同意 (separate explicit consent, dāndú tóngyì) — meaning the consent checkbox or signature must be isolated from other permissions. A 2023 guidance from the Cyberspace Administration of China (CAC) clarified that pre-ticked boxes, blanket consent forms, and consent obtained via dark patterns (e.g., hidden opt-out) are all invalid.

Foreign companies collecting customer data for e-commerce, mobile apps, or B2B marketing must also appoint a 数据保护官 (Data Protection Officer, DPO, shùjù bǎohù guān) if they process large volumes of personal information or sensitive data. This requirement applies equally to WFOEs and representative offices. The DPO must be based in China and report directly to the company’s legal representative. Failure to appoint a qualified DPO can result in corrective orders and daily fines of 10,000 RMB to 1 million RMB.

What Are the Legal Exceptions to Consent?

While consent is the general rule, the PIPL lists 6 exceptions where data may be processed without explicit consent under specified conditions. These include processing necessary for contract performance (e.g., shipping an ordered product), compliance with legal obligations (e.g., tax reporting), public health emergencies, or responding to public security investigations. However, exceptions are applied strictly — companies cannot rely on “legitimate interest” as broadly as under GDPR. Each exception requires documentation proving necessity and proportionality.

For example, a WFOE running an employee payroll system may process salary data without individual employee consent if it’s required for labor contract performance and tax law compliance. But the same employer cannot use that salary data for performance analytics or marketing without separate consent. A 2024 enforcement action against a Shanghai-based SaaS provider fined the company 2 million RMB for using customer usage data (collected under contract necessity) to upsell premium features without explicit consent.

Cross-border data transfers add another consent layer. Under PIPL and the 数据出境安全评估办法 (Data Export Security Assessment Measures, shùjù chūjìng ānquán pínggū bànfǎ), companies transferring personal information outside China must either pass a security assessment (for critical data operators), sign standard contractual clauses with individuals, or obtain a certification. For sensitive data transfers, separate explicit consent is always required before any cross-border transmission can occur.

What Are the Penalties for Non-Compliance?

Penalties under the PIPL are designed to be severe enough to deter non-compliance by both domestic and foreign enterprises. The table below summarizes the enforcement severity tiers.

PIPL Non-Compliance Penalty Tiers (2025 Enforcement Data)
Violation Severity Corporate Fine Personal Liability Typical Trigger
Minor (corrected within 30 days) Up to 1 million RMB Up to 100,000 RMB Bundled consent forms
Moderate (repeat or systemic) 1–10 million RMB 100,000–1 million RMB Unauthorized data sharing
Serious (violation of sensitive data) 10–50 million RMB or 5% of annual revenue Up to 1 million RMB + ban from role Unauthorized biometric collection
Critical (cross-border without consent) 5% of global annual revenue (capped at 50 million RMB) Up to 5 million RMB + criminal referral Sensitive data exported without assessment

Beyond financial penalties, regulators can order suspension of data processing activities, shutdown of non-compliant apps or websites, and public naming. In 2023, the CAC ordered 26 apps to cease operations for consent violations, affecting an estimated 40 million users. For foreign companies, non-compliance can also lead to restricted market access — the Ministry of Industry and Information Technology (MIIT) has blocked 11 foreign-owned platforms from acquiring new users until consent mechanisms were overhauled.

How to Implement Proper Consent Collection Mechanisms

Building a compliant consent system requires technical and procedural controls that go beyond a simple pop-up checkbox. Under the 个人信息安全规范 (Personal Information Security Specification, gèrén xìnxī ānquán guīfàn) — the national standard GB/T 35273-2020 — companies must implement the following four-step consent workflow:

  1. Pre-consent disclosure: Display in clear, plain language: the data categories collected, the purpose of each collection, retention period, third-party recipients, and the user’s right to withdraw consent. This must be presented before any data collection occurs.
  2. Separate opt-in: Use a dedicated checkbox or button for each consent purpose. Pre-ticked boxes, blanket “I agree” buttons, or scrolling past terms do not constitute valid consent. Sensitive data requires a separate opt-in event with a specific explanation of the sensitivity and consequences of processing.
  3. Consent management platform: Deploy a consent management platform (CMP) that records the timestamp, version of the privacy notice, and user preference for each data subject. Records must be maintained for at least 3 years after the last interaction.
  4. Revocation mechanism: Provide an easy, equally prominent opt-out mechanism — typically within the user profile settings — that allows withdrawal of consent at any time with immediate effect. The user must not be penalized (e.g., service degradation) for withdrawing consent.

For mobile apps specifically, the PIPL requires that app providers obtain 单独同意 before accessing device permissions like camera, microphone, location, and contacts — and can only collect the minimum data needed for the app’s declared core function. A 2024 audit of the top 100 apps in China’s app stores found that 32% were still collecting more data than declared, leading to fines totaling 87 million RMB. The CAC publishes quarterly lists of non-compliant apps, and foreign companies should monitor these lists as a compliance benchmark.

Cross-border data transfers add another consent layer. Under PIPL and the 数据出境安全评估办法 (Data Export Security Assessment Measures, shùjù chūjìng ānquán pínggū bànfǎ), companies transferring personal information outside China must either pass a security assessment (for critical data operators), sign standard contractual clauses with individuals, or obtain a certification. For sensitive data transfers, separate explicit consent is always required before any cross-border transmission can occur.

Pitfall: Collecting consent via generic terms of service (TOS) without a separate consent notice. Cost: 1.2 million RMB fine imposed on a Shenzhen-based e-commerce platform in 2024. Fix: Separate the consent notice from the TOS with a dedicated pop-up explaining each data category and purpose, and record the exact consent version accepted.
Pitfall: Assuming that consent once obtained remains valid indefinitely. The PIPL requires that companies refresh consent at least every 12 months or whenever the data usage purpose changes. Cost: 850,000 RMB penalty for a logistics company that relied on a 2022 consent form for 2024 data-mining purposes. Fix: Implement a consent expiry and reconsent workflow using consent management software that flags expired permissions.
Pitfall: Failing to provide a compliant consent revocation mechanism. A Beijing-based fintech company made revocation require sending a physical letter to its headquarters — ruled invalid by the CAC in 2023. Cost: 2.1 million RMB in fines and a 90-day suspension of new user registrations. Fix: Provide online, in-app, and phone-based revocation options with same-day effect, and confirm revocation via email or SMS.

NEXT STEPS

  1. Complete our Data Compliance Checklist — Use this 35-point audit tool to evaluate your current consent collection mechanisms against PIPL requirements, including sensitive data classification, cross-border transfer rules, and DPO appointment obligations.
  2. Download Our PIPL Consent Policy Template — This customizable template includes Chinese-language consent notices, revocation clauses, and data retention schedules that meet CAC and MIIT standards. Available in English and Chinese.
  3. Read Our Guide to Appointing a DPO in China — Covers qualifications, registration with authorities, and how to integrate the DPO role into your existing China compliance structure — essential if you process sensitive data or over 1 million individual records annually.

— China Gateway 360 —
Remote China market entry support, built around execution.

Related articles

How a British Heritage Brand Registered a Trademark in China in 6 Months: Luxury Case Study

How a British Heritage Brand Registered a Trademark in China in 6 Months: Luxury Case Study How a British Heritage Brand Registered a Trademark in Chi

How an Italian Luxury Brand Won Gen Z Consumers on Douyin in China: Luxury Case Study

How an Italian Luxury Brand Won Gen Z Consumers on Douyin in China: Luxury Case Study How an Italian Luxury Brand Won Gen Z Consumers on Douyin in Chi

How a French Fashion House Opened 20 Boutiques in China in 12 Months: Luxury Case Study

How a French Fashion House Opened 20 Boutiques in China in 12 Months: Luxury Case Study How a French Fashion House Opened 20 Boutiques in China in 12

Standalone Boutique vs Department Store: Which China Retail Format for Luxury Brands?

Standalone Boutique vs Department Store: Which China Retail Format for Luxury Brands? For luxury brands entering China, the choice between a standalon