TITLE:
A Comparative Analysis of Customer Data Privacy Protection under the European Union’s General Data Protection Regulation and the People’s Republic of China’s Personal Information Protection Law
AUTHORS:
Oceanus Ming-Ting Kam
KEYWORDS:
General Data Protection Regulation (GDPR), Personal Information Protection Law (PIPL), Cyberspace Administration of China (CAC), Data Privacy, Data Protection, Privacy Law, Cybersecurity, Comparative Law, Cross-Border Data Transfer
JOURNAL NAME:
Beijing Law Review,
Vol.16 No.3,
September
3,
2025
ABSTRACT: Since its inception and full implementation in 2016 and 2018 respectively, the European Union’s (EU) General Data Protection Regulation (GDPR) has been widely regarded as the international community’s data protection—privacy protection “gold standard”. Many scholars attribute this GDPR status to influential global human rights instruments like the Universal Declaration on Human Rights 1948, European Convention on Human Rights 1950, and International Covenant on Economic, Social and Cultural Rights 1966. There is little doubt about when People’s Republic of China’s (PRC) data protection policymakers were determining how Chinese data laws should be reformed, as the GDPR provisions strongly influenced the eventual scope and effect of the PRC’s Personal Information Protection Law (PIPL). This comparative analysis considers the various GDPR—PIPL similarities and differences, with particular emphasis placed on the broad regulatory powers available to the Cyberspace Administration of China (CAC). The GDPR regulatory framework is tightly structured regarding how its chief oversight agencies are operated. The EU member states’ individual “Supervisory Authorities” are the regulators created within each member state, with the European Commission mechanisms providing the entire GDPR regulatory structure, the corresponding CAC powers are only generally defined. The relatively brief PIPL legislative history means that the CAC has not yet published enough rulings, or issued policy guidance that permits interested parties to ensure that their data processing and related activities fully conform to all PIPL requirements. Foreign companies with PRC interests must comply with all PIPL provisions, and absent clearer PIPL regulations regarding precisely how the CAC will deal with data protection—privacy issues, and uncertainty will prevail. The analysis confirms that it is very difficult to predict how the CAC will use its regulatory powers going forward—a reality that is likely the single biggest distinguishing feature when the PIPL and GDPR frameworks are compared. The analysis also considers the extent to which the CAC might be inclined to cooperate with PRC central government agencies regarding personal data being shared with the government for its purposes.