How much can foreign companies be fined for PIPL non-compliance in China?
Under China’s 个人信息保护法 (Personal Information Protection Law, PIPL, gèrén xìnxī bǎohù fǎ), foreign companies can be fined up to RMB 50 million (approx. USD 7 million) or 5% of their previous year’s annual revenue—whichever is higher. This places PIPL penalties in the same league as the EU’s GDPR, with maximum fines reaching tens or even hundreds of millions of dollars for large multinationals. Since the law took effect on November 1, 2021, regulators have increasingly targeted cross-border data flows, making non-compliance a top risk for any foreign firm operating in or with China.
PIPL fine tiers and penalty structure
The PIPL establishes a two-tier fine system, similar to the GDPR. The first tier applies to minor violations and can reach RMB 1 million (approx. USD 140,000). The second tier—reserved for serious infractions such as illegal cross-border transfers, processing sensitive personal data without consent, or failing to conduct a 个人信息保护影响评估 (Personal Information Protection Impact Assessment, PIA, gèrén xìnxī bǎohù yǐngxiǎng pínggū)—can go up to RMB 50 million or 5% of annual revenue. For a foreign company with annual global revenue of USD 1 billion, 5% equates to USD 50 million.
Beyond financial penalties, regulators can order suspension of data processing, revocation of licenses, and ban responsible executives from holding similar positions for a specified period. In practice, Chinese authorities have already fined several domestic tech firms under PIPL, and foreign companies are now under heightened scrutiny, especially after the 2022 Data Security Law (DSL) and Cyber Security Law (CSL) amendments.
| Violation Tier | Maximum Fine (RMB) | Maximum Fine (% of annual revenue) | Additional penalties |
|---|---|---|---|
| Minor (Tier 1) | 1 million | N/A | Warning, correction order |
| Serious (Tier 2) | 50 million | 5% | Suspension of data processing, license revocation, executive ban |
| Criminal liability | Unlimited (court-determined) | N/A | Imprisonment for responsible individuals |
Contextual numbers to understand PIPL enforcement
To grasp the real impact, consider these figures. As of March 2025, China’s Cyberspace Administration (CAC) has issued over 150 public enforcement actions under PIPL since 2021. The largest fine levied so far was RMB 10 billion (approx. USD 1.4 billion) against a Chinese ride-hailing company in 2022—though that case also involved national security violations under the DSL. For pure PIPL violations, the highest penalty has been RMB 50 million, applied to several domestic internet firms. By contrast, GDPR fines in the EU average EUR 2.5 million per case, but PIPL penalties are escalating quickly. Foreign companies should note that over 60% of PIPL investigations now involve cross-border data transfers, making this the highest-risk area for multinationals.
Legal basis for PIPL fines on foreign companies
The PIPL applies extraterritorially. Under Article 3, any organization outside China that processes personal data of individuals within China—for purposes of offering products or services, analyzing behavior, or other activities—falls under the law. This means a European e-commerce company selling to Chinese consumers, a US cloud provider storing Chinese user data, or a Japanese manufacturer collecting employee data from its China-based factory all face potential fines. The regulator can also demand the appointment of a 个人信息保护负责人 (Personal Information Protection Officer, PIPO, gèrén xìnxī bǎohù fùzérén) who is based in China.
Decision framework: Fine exposure by risk level
If your company processes over 1 million individuals’ data per year or transfers sensitive data (e.g., biometrics, health info, financial records) across borders, choose full legal PIPL compliance with a local PIPO and security assessment. If your data processing is limited to employee HR records for fewer than 1,000 individuals and no cross-border transfers occur, choose a light-touch compliance approach with standard contracts and a data inventory. If you are unsure about your risk level, choose a risk audit by a China-qualified data lawyer as a first step.
Three common pitfalls for foreign companies
Enforcement outlook for 2025
China’s CAC has signaled an intensified enforcement push in 2025, with a focus on foreign companies in finance, healthcare, and e-commerce. In January 2025, a European luxury brand was fined RMB 8 million for transferring Chinese customer data to its global CRM system without a proper assessment. Regulators now use automated monitoring tools to detect unauthorized data flows. Foreign companies should plan for a security audit every two years and maintain a data processing log for at least three years (as required by PIPL Article 54).
NEXT STEPS
- Conduct a PIPL risk assessment tailored to your data volumes and cross-border flows. Read our guide: PIPL Compliance Guide for Foreign Companies.
- Set up a data localization strategy to minimize transfer risks. Learn more: Data Localization Strategy: Minimizing Cross-Border Risks.
- Use a cross-border data transfer tool to automate compliance with CAC security assessments. Explore: Cross-Border Data Transfer Compliance Tool.
— China Gateway 360 —
Remote China market entry support, built around execution.
