How long do I need to retain personal data under PIPL?

Date:

Share post:





How long do I need to retain personal data under PIPL?


How long do I need to retain personal data under PIPL?

The Personal Information Protection Law of the People’s Republic of China (PIPL) does not prescribe a fixed retention period for personal data. Instead, it establishes a principles-based framework: personal information must be retained only for the minimum period necessary to achieve the specified processing purpose. This approach gives enterprises flexibility but also creates ambiguity, as the appropriate retention period varies depending on the type of data, the processing purpose, and applicable industry-specific regulations. This article provides a detailed guide to understanding and implementing data retention periods under PIPL, with specific reference to common business scenarios for foreign enterprises in China.

The Core Principle: Minimum Necessary Period

Article 6 of PIPL establishes the principle that personal information processing shall be limited to the minimum scope necessary to achieve the purpose of processing, and personal information shall not be retained beyond the period necessary to achieve such purpose. This is known as the data minimization principle. PIPL does not provide a statutory default retention period, unlike the GDPR’s retention for as long as necessary standard, which is similarly principles-based. The key question for enterprises is how to determine the necessary period for each data category and processing activity.

The Personal Information Security Specification (GB/T 35273-2020), which serves as an implementation guide for PIPL, provides additional guidance on retention periods. It states that the retention period should be the minimum period required to fulfill the processing purpose, plus any additional period required by law or regulation. After the retention period expires, personal information must be deleted or anonymized in accordance with PIPL Article 47, which grants data subjects the right to request deletion of their personal information when the retention period has ended.

Retention Periods by Data Category and Purpose

The appropriate retention period depends on the purpose for which the data was collected and any legal requirements that mandate minimum retention periods. The following table provides indicative retention periods for common business scenarios, based on regulatory guidance and industry practices.

Data Category Typical Purpose Indicative Retention Period Legal Basis
Employee HR records Employment relationship, payroll, benefits Duration of employment + 2 to 5 years Labor Contract Law, Social Insurance Law, PIPL Article 6
Tax records Individual income tax filing and reporting 5 years from end of tax year Individual Income Tax Law, Tax Collection and Administration Law
Social insurance records Social insurance contributions and claims Duration of contribution + 5 years Social Insurance Law
Customer transaction data Order fulfillment, payment processing 3 years from transaction date Consumer protection regulations, E-Commerce Law
Customer service records Complaint handling, product support 2 to 3 years from date of resolution Industry best practices, PIPL Article 6
Contractual documents Performance of contracts, potential disputes 3 to 5 years from contract termination Civil Code, Statute of Limitations (3 years)
Website cookies and analytics Website optimization, user experience 6 months to 2 years PIPL Article 6, no specific extension
Marketing and promotional data Direct marketing, newsletters Until consent withdrawal or 1 year after last interaction PIPL Article 6, consent-based purpose
Biometric attendance records Employee time tracking 7 to 30 days after processing (delete raw data) Minimum necessity principle, sensitive PI
Health and medical data Employee health insurance claims Duration of insurance coverage + 3 years Industry regulations, PIPL sensitive PI provisions
Key Principle: Under PIPL Article 6, the retention period must be directly linked to the processing purpose. Once the purpose is fulfilled, data must be deleted or anonymized. Legal or regulatory requirements may extend retention beyond the business purpose, but the extension must be specifically mandated by law.

Legal and Regulatory Minimum Retention Periods

Several Chinese laws impose specific minimum retention periods for certain types of records that contain personal information. These requirements override the PIPL principle of minimum necessary retention because they serve legally recognized purposes such as tax administration, social insurance management, and commercial dispute resolution. Foreign enterprises must be aware of these overlapping obligations to set retention schedules that comply with both PIPL and the applicable sectoral laws.

Labor and Employment Records

The Labor Contract Law requires employers to maintain employment contracts and personnel records for at least two years after the termination of the employment relationship. The Social Insurance Law requires that social insurance contribution records be retained for at least five years. The Individual Income Tax Law requires withholding agents to retain employee income tax records for at least five years from the end of the relevant tax year. For foreign enterprises, these requirements mean that employee HR data, including salary records, tax withholding data, and social insurance contribution data, must be retained for at least two to five years after the employee’s departure, even if the business purpose for processing the data has concluded.

Financial and Transaction Records

The E-Commerce Law requires e-commerce platform operators to retain transaction records for at least three years from the date of the transaction. The Accounting Law requires financial records, including invoices and receipts that may contain personal information, to be retained for at least ten years in some cases. The Administrative Measures for Internet Information Services require internet service providers to retain user log records for at least 60 days. Foreign enterprises that operate e-commerce platforms, provide internet services, or maintain financial records in China must incorporate these statutory periods into their data retention schedules.

Industry-Specific Retention Requirements

Regulated industries have their own data retention requirements. Financial institutions are subject to regulatory requirements that may require retention of customer identity verification records for at least five years after the termination of the business relationship, under anti-money laundering regulations. Healthcare providers must retain medical records for at least fifteen years under the Regulations on the Administration of Medical Records. Telecommunications operators must retain user communication records for at least six months. Enterprises in these sectors must ensure that their PIPL compliance programs account for these industry-specific retention obligations.

Data Deletion and Anonymization Obligations

Article 47 of PIPL grants data subjects the right to request deletion of their personal information in the following circumstances: the processing purpose has been achieved, is impossible to achieve, or is no longer necessary; the personal information processor has ceased providing the relevant products or services; the retention period has expired; the data subject withdraws consent; the data subject objects to the processing and the objection is upheld; or the processing violates laws, administrative regulations, or the provisions of PIPL. When a data subject exercises this right, the enterprise must delete the relevant personal information within a reasonable period.

If the enterprise is legally required to retain the data beyond the deletion request (for example, due to tax or labor law requirements), it may refuse the deletion request but must inform the data subject of the legal basis for the continued retention. The enterprise must also document the lawful basis for refusing the deletion request and make this documentation available to regulatory authorities upon request.

Anonymization is an alternative to deletion. Under PIPL, properly anonymized data is no longer considered personal information and can be retained indefinitely without violating data subject rights. However, the anonymization standard is high: the process must be irreversible, meaning the data cannot be re-identified through any means reasonably available to the enterprise or third parties. Pseudonymization, which replaces identifiers with artificial labels, does not qualify as anonymization and therefore does not release the enterprise from the retention and deletion obligations under PIPL.

Practical Note: For data that is no longer needed for its original processing purpose but may have future business value, anonymization is the preferred approach. It eliminates the data retention compliance burden while preserving the data for analytics, research, and business intelligence purposes. Enterprises should invest in technical anonymization capabilities as part of their data compliance infrastructure.

Building a Data Retention Schedule

To comply with PIPL’s retention requirements, foreign enterprises should develop a formal data retention schedule that specifies, for each category of personal information, the following elements: the business purpose for which the data is processed, the legal basis for processing, the minimum retention period required to fulfill the business purpose, any statutory minimum retention period imposed by applicable laws, the maximum retention period (the longer of the business and statutory periods), the post-retention action (deletion or anonymization), and the responsible person or department for ensuring timely deletion or anonymization.

The retention schedule should be reviewed and updated at least annually and whenever there is a material change in the enterprise’s data processing activities or relevant regulations. The schedule should be approved by the enterprise’s data protection officer or the designated responsible person for personal information protection matters.

Implementation Steps

First, conduct a comprehensive data mapping exercise to identify all categories of personal information held by the enterprise, the systems in which they reside, and the purposes for which they are processed. Second, for each data category, determine the business purpose retention period based on the nature and duration of the processing activity. Third, identify any applicable statutory minimum retention periods under labor law, tax law, social insurance law, industry regulations, or other applicable legislation. Fourth, set the retention period at the longer of the business purpose period and the statutory minimum period. Fifth, implement technical controls to automatically delete or anonymize data when the retention period expires. Sixth, establish a process for handling data subject deletion requests, including the ability to identify and isolate data that must be retained under statutory obligations. Seventh, document all retention decisions and make the documentation available for regulatory inspection.

Consequences of Non-Compliance

Failing to comply with PIPL’s data retention and deletion obligations carries significant risks. Under PIPL Article 69, enterprises that unlawfully retain personal information beyond the necessary period may face an order to correct, a warning, confiscation of illegal gains, and fines of up to 50 million RMB or 5 percent of annual revenue. If the enterprise refuses to correct the violation, the penalties may be escalated. Additionally, data subjects whose deletion rights are not respected may file complaints with the cyberspace administration or initiate civil litigation for damages. Beyond regulatory penalties, non-compliance with data retention obligations increases the enterprise’s exposure to data breaches, as retained data that is no longer needed for business purposes represents an unnecessary security risk. Reducing data holdings to the minimum necessary scope, in alignment with PIPL Article 6, is both a compliance obligation and a security best practice.

Summary

PIPL requires personal information to be retained only for the minimum period necessary to achieve the processing purpose. There is no single statutory retention period that applies to all data categories. Rather, each enterprise must determine appropriate retention periods based on the purpose of processing, any statutory minimum periods imposed by applicable laws, and the nature of the data. Employee HR data typically requires retention of two to five years after employment ends, due to labor law and tax law requirements. Transaction data requires retention of three years or more. Biometric and sensitive personal information should be retained for the shortest practical period. Upon expiry of the retention period, personal information must be deleted or anonymized. A formal data retention schedule, supported by technical deletion controls and a process for handling data subject requests, is essential for PIPL compliance and the broader objective of minimizing data security risk.


Related articles

Onshore vs Offshore Wind in China: Better Investment for Foreigners?

Onshore vs Offshore Wind in China: Better Investment for Foreigners? China installed 52 GW of onshore wind and 24 GW of offshore wind capacity in 2025

Solar PV vs Wind: Better Clean Energy Bet for Foreign Firms in China?

Solar PV vs Wind: Better Clean Energy Bet for Foreign Firms in China? China added 216 GW of solar PV capacity and 76 GW of wind capacity in 2025 alone

WFOE vs JV: Which Clean Energy Entry Mode for China?

WFOE vs JV: Which Clean Energy Entry Mode for China? Over 65% of foreign clean energy firms entering China between 2020 and 2025 chose the Wholly Fore

Solar PV vs Wind: Better Clean Energy Bet for Foreign Firms in China?

Solar PV vs Wind: Better Clean Energy Bet for Foreign Firms in China? China added 216.9 GW of solar photovoltaic (太阳能光伏, tàiyángnéng guāngfú) capacity