A Comparative Analysis of Customer Data Privacy Protection under the European Union’s General Data Protection Regulation and the People’s Republic of China’s Personal Information Protection Law — Oak Academic Publishing
Research ArticleOpen AccessGoogle Scholar indexed
A Comparative Analysis of Customer Data Privacy Protection under the European Union’s General Data Protection Regulation and the People’s Republic of China’s Personal Information Protection Law
Since its inception and full implementation in 2016 and 2018 respectively, the European Union’s (EU) General Data Protection Regulation (GDPR) has been widely regarded as the international community’s data protection—privacy protection “gold standard”. Many scholars attribute this GDPR status to influential global human rights instruments like the Universal Declaration on Human Rights 1948, European Convention on Human Rights 1950, and International Covenant on Economic, Social and Cultural Rights 1966. There is little doubt about when People’s Republic of China’s (PRC) data protection policymakers were determining how Chinese data laws should be reformed, as the GDPR provisions strongly influenced the eventual scope and effect of the PRC’s Personal Information Protection Law (PIPL). This comparative analysis considers the various GDPR—PIPL similarities and differences, with particular emphasis placed on the broad regulatory powers available to the Cyberspace Administration of China (CAC). The GDPR regulatory framework is tightly structured regarding how its chief oversight agencies are operated. The EU member states’ individual “Supervisory Authorities” are the regulators created within each member state, with the European Commission mechanisms providing the entire GDPR regulatory structure, the corresponding CAC powers are only generally defined. The relatively brief PIPL legislative history means that the CAC has not yet published enough rulings, or issued policy guidance that permits interested parties to ensure that their data processing and related activities fully conform to all PIPL requirements. Foreign companies with PRC interests must comply with all PIPL provisions, and absent clearer PIPL regulations regarding precisely how the CAC will deal with data protection—privacy issues, and uncertainty will prevail. The analysis confirms that it is very difficult to predict how the CAC will use its regulatory powers going forward—a reality that is likely the single biggest distinguishing feature when the PIPL and GDPR frameworks are compared. The analysis also considers the extent to which the CAC might be inclined to cooperate with PRC central government agencies regarding personal data being shared with the government for its purposes.
KeywordsGeneral Data Protection Regulation (GDPR)Personal Information Protection Law (PIPL)Cyberspace Administration of China (CAC)Data Privacy
(EU) 2016/679 on the Protection of Natural Persons with Regard to the Processing of Per-sonal Data and on the Free Movement of Such Data, and Repealing Directive 95/46/EC (General Data Protection Regulation). Official Journal of the European Union, 50, 119.
Agarwal, S., Ghosh, P., Ruan, T., & Zhang, Y. (2020). Privacy versus Convenience: Customer Response to Data Breaches of Their Information. SSRN Electronic Journal . https://doi.org/10.2139/ssrn.3729730
Article 29 Working Party (2017). Guidelines for Identifying a Controller or Processor ’ s Lead Supervisory Authority (WP 244 rev.01) . Article 29 Working Party.
Bo, H. (2023). Implications of the Ukraine War for China: Can China Survive Secondary Sanctions? Journal of Chinese Economic and Business Studies, 21, 311-322. https://doi.org/10.1080/14765284.2022.2136933
Bu, Q. X. (2025). The Didi Debacle: A Watershed of Financial Decoupling vis - À - vis Resilience Epitome of Global Data Governance. Capital Markets Law Journal, 20, kmae023. https://doi.org/10.1093/cmlj/kmae023
Chynoweth, P. (2013). Legal Research in the Built Environ ment: A Methodological Framework . CIB. https://www.irbnet.de/daten/iconda/CIB11548.pdf
Creemers, R. (2022). China’s Emerging Data Protection Framework. Journal of Cybersecurity, 8, tyac011. https://doi.org/10.1093/cybsec/tyac011
Creswell, J. W., & Creswell, J. D. (2018). Research Design : Qualitative, Quantitative , and Mixed Methods Approach es (5th ed.). Sage.
Cyberspace Administration of China (2022). Measures for Security Assessment of out Bound Data Transfers (in Chinese Only ) . https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm
da Silva, J. (2021). The EU and the Brussels Effect on Human Rights Protection in the New Era of Technology . Master’s Thesis, University of Nova.
Data Protection Commission (2020). Data Protection Commissioner v. Facebook Ireland Limited & Schrems . Data Protection Commission.
European Data Protection Board (2018). Guidelines 3/2018 on the Territorial Scope of the GDPR (Article 3) — Version for Public Consultation . European Data Protection Board.
European Data Protection Board (2019). Opinion 8/2019 on the Competence of a Supervisory Authority in Case of a Change in Circumstances Relating to the Main or Single Establishment . https://edpb.europa.eu/sites/edpb/files/files/file1/edpb_opinion_201908_changeofmainorsingleestablishme.pdf
Data Protection
Privacy Law
Cybersecurity
Comparative Law
Cross-Border Data Transfer
European Parliament & Council of the European Union (2016). Regulation .
European Union (2009). Charter of Fundamental Rights of the European Union . European Union.
European Union (2010). Treaty on the Functioning of the European Union . European Union.
Garg, M. (2025). India ’ s Data Protection Act: A Shield for Privacy or a Tool for State Surveillance ? Tech Policy Press. https://www.techpolicy.press/indias-data-protection-act-a-shield-for-privacy-or-a-tool-for-state-surveillance
Gilman, M. (2020). Five Privacy Principles (from the GDPR) the United States Should Adopt to Advance Economic Justice. Arizona State Law Journal, 52 , 368-444. https://ssrn.com/abstract=3667795
Goh, G., & Tang, G. (2025). China Data Protection and Cybersecurity: Annual Review of 2024 and Outlook for 2025 (I) . Bird & Bird. https://www.twobirds.com/en/insights/2025/china/china-data-protection-and-cybersecurity-annual-review-of-2024-and-outlook-for-2025-(i)
Golden Data (2023). What Is a “ Supervisory Auth ority ” (SA) under EU Data Protectio n Law ? The Media. https://medium.com/golden-data/what-is-a-supervisory-authority-under-eu-data-protection-law-5ea69d5b0ea2
Greenleaf, G. (2020). China Issues a Comprehensive Draft Data Privacy Law. Privacy Laws & Business International Report, 168, 6-10.
Greenleaf, G. (2023). Global Data Privacy Laws 2023: 162 National Laws and 20 Bills. Privacy Laws and Business International Report, 181, 2-4. https://doi.org/10.2139/ssrn.4426146
Greenleaf, G., & Livingston, S. (2017). China’s Personal Information Standard: The Long March to a Privacy Law. Privacy Laws & Business International Report, 150, 25-36.
Ivanova, Y. (2020). Data Controller, Processor or a Joint Controller: Towards Reaching GDPR Compliance in the Data and Technology Driven World. In M. Tzanou (Ed.), Personal Data Protection and Legal Developments in the Europea n Union (pp. 61-84). IGI Global. https://doi.org/10.2139/ssrn.3584207
Kennedy, G. (2022). China ’ s Security Assessment for Cross- Border Data Transfers, Effective September 2022 . Mayer Brown. https://www.mayerbrown.com/en/perspectives-events/publications/2022/07/china-s-security-assessments-for-cross-border-data-transfers-effective-september-2022
Kun, E. (2020). Questioning the Effectiveness of the Data Protection Impact Assessment Under the GDPR in Time of COVID-19 Crisis. In Koronavirüs Döneminde Güncel Hukuki Meseleler Sempozyumu Bildiri Tam Metin Kitabı (pp. 743-765). İbn Haldun Üniversitesi Yayınları. https://ssrn.com/abstract=4002566
Layton, R. (2017). How the GDPR Stacks up to Best Practices for Privacy, Accountability and Trust. SSRN Electronic Journal . https://doi.org/10.2139/ssrn.2944358
Lomas, N. (2022). Tik T ok Privacy Update in Europe Confirms China Staff Access to Data as GDPR Probe C ontinues . TechCrunch. https://techcrunch.com/2022/11/03/tiktok-privacy-policy-update-china/
Lum, N. (2022). The PRC Persona l Information Protection Law: Its Impact on Cross-Border Data Transfer and International Invest igations . Clyde & Co.
Makridis, C. A. (2021). Do Data Breaches Damage Reputation? Evidence from 45 Companies between 2002 and 2018. Journal of Cybersecurity, 7, 1-13. https://doi.org/10.1093/cybsec/tyab021
Malgieri, G. (2020). The Concept of Fairness in the GDPR. In Proceedings of the 2020 Conference on Fairness, Accountability, and Transparency (pp. 154-166). ACM. https://doi.org/10.1145/3351095.3372868
Mohsin, K. (2022). Data Privacy and Cybersecurity. SSRN Electronic Journal . https://doi.org/10.2139/ssrn.4299439
National People’s Congress of People’s Republic of China (2021). Personal Information Protection Law of the People ’ s Republic of China . National People’s Congress of People’s Republic of China. http://en.npc.gov.cn.cdurl.cn/2021-12/29/c_694559.htm
Nettesheim, M. (2023). Data Protection in Contractual Relationships (Art. 6 (1) (b) GDPR). SSRN Electronic Journal . https://doi.org/10.2139/ssrn.4427134
Oertel, J. (2020). US-China Confrontation and Repercussions for the EU . European Council on Foreign Relations. https://ecfr.eu/article/us-china-systemic-rivalry-repercussions-for-the-eu/
Office of Ethics, Risk & Compliance Services (2025). China Privacy Law . UC Berkeley. https://ethics.berkeley.edu/privacy/international-privacy-laws/china-privacy-law
Penta Security (2021). PIPL, How It Differs from GDPR and What It Means for Businesses ? https://www.pentasecurity.com/privacy-policy/
Pernot-Leplay, E. (2020). China’s Approach on Data Privacy Law: A Third Way between the US and the EU? Penn State Journal of Law & International Affairs, 8, 51-65.
Ross, L. (2022). China ’ s New Outbound Data Transfer Security Assessment Measures and Standard Contract Provisions . WilmerHale. https://www.wilmerhale.com/en/insights/client-alerts/20220725-china-new-outbound-data-transfer-security-assessment-measures
Shi, Z., & Wang, Y. (2023). China ’ s Risk Approach to Data Pri vacy: Analysing China ’ s New Personal Information Protection Law under a Comparative Per spective . SSRN.
Standardization Administration of China (2020). Information Security Technology— Personal Information Security Specific ation (GB/T 35273-2020) . Standardization Administration of China.
Svantesson, D. (2019). An Analysis of EDPB’s Opinion on the Competence of a Supervisory Authority in Case of a Change in Circumstances Relating to the Main or Single Establishment. SSRN Electronic Journal . https://doi.org/10.2139/ssrn.3437565
Svetlicinii, A. (2022). China’s Defense against Secondary Sanctions: Lessons from the EU Blocking Statute. Journal of International Trade Law and Policy, 21, 217-239. https://doi.org/10.1108/jitlp-09-2021-0048
Tsai, L. (2021). Interpretation of the Supreme People ’ s Court and the Supreme People ’ s Procuratorate on Several Issues Concerning the Application of Law in Handling Food Safety Criminal Cases . Lexology. https://www.leetsai.com/interpretation-of-the-supreme-peoples-court-and-the-supreme-peoples-procuratorate-on-several-issues-concerning-the-application-of-law-in-handling-food-safety-criminal-cases-2021
United Nations General Assembly (1948). Universal Declaration of Human Rights (217A(III)) . United Nations General Assembly.
Wang, C., & Shen, T. (2023). Implications of the Eu’s Position on Trade Distortion for Eu-China Trade Relations: From Selective Adaptation to Coordinated Compliance. Asian Journal of WTO & International Health Law and Policy, 17, 331-370.
Wang, S. (2023). China Data Compliance through Personal Data Protection Impact Assessments . Mondaq. https://www.mondaq.com/china/privacy-protection/1320876/china-data-compliance-through-personal-data-protection-impact-assessment
Xue, H. (2010). Privacy and Personal Data Protection in China: An Update for the Year End 2009. Computer Law & Security Review, 26, 284-289. https://doi.org/10.1016/j.clsr.2010.01.004
Yin, K., & Zhang, G. (2022). China’s Personal Information Protection Law and the Roadmap to Compliance . Fangda Partners. https://www.fangdalaw.com/wp-content/uploads/2021/08/China%E2%80%99s-Personal-Information-Protection-Law-and-the-roadmap-to-compliance.pdf
Zhu, J. (2022). The Personal Information Protection Law: China’s Version of the GDPR? Columbia Journal of Transnational Law: The Bulletin . https://www.jtl.columbia.edu/bulletin-blog/the-personal-information-protection-law-chinas-version-of-the-gdpr