Skip to main content

PIPL (Personal Information Protection Law)

China's national data protection law, effective November 2021, whose Article 28 defines sensitive personal information as data that, if leaked or misused, could easily harm a natural person's dignity, safety, or property, explicitly naming biometric information, religious belief, medical health, and location tracking among others; Article 29 requires separate consent for its processing.

Defined in 2 GAGE programs, which carry 5 distinct definitions of it. The wording above is taught in AI Data Governance: The Data Chair.

How each discipline defines it

The same term does different work depending on who is using it. These are the definitions as each program teaches them, unedited.

AI Data Governance: The Data Chair

China's national data protection law, effective November 2021, whose Article 28 defines sensitive personal information as data that, if leaked or misused, could easily harm a natural person's dignity, safety, or property, explicitly naming biometric information, religious belief, medical health, and location tracking among others; Article 29 requires separate consent for its processing.

Certified China AI Regulatory Professional (CCARP)

China's comprehensive personal-information-protection statute (2021, unamended as of Jul 2026), applying to any AI deployment that processes personal information, including extraterritorially under Article 3 where Chinese individuals are targeted.

AI Data Governance: The Data Chair

China's comprehensive data protection law, in force since 2021, using a permission-first structure with consent as the default expectation and a shorter list of named alternative grounds, layered with a separately stricter cross-border transfer assessment obligation.

Certified China AI Regulatory Professional (CCARP)

China's comprehensive personal data protection statute, in force since November 2021 and unamended as of July 2026, whose extraterritorial scope (Article 3) is a primary source of Channel 2 reach for organizations with no China presence.

Certified China AI Regulatory Professional (CCARP)

China's 2021 data-protection statute; its Article 3 extraterritorial-reach provision is the primary basis for Section 3E and Section 3M's step-zero jurisdictional question for foreign-facing deployments. (see Topic 1.2)

Where it is taught

The exact lessons this term appears in. The first 7 topics of every program are free with a free account.

Terms it appears with

Not an alphabetical neighbourhood: these are the terms taught in the same lessons, ranked by how often they appear together.