China — Personal Information Protection Law (个人信息保护法)
China's omnibus privacy law (2021). Extraterritorial: it reaches processing outside China that targets people in China (art. 3(2)). Direct contracting confirmed 2026-09-06 — we carry the compliance burden ourselves.
Statute text is Chinese (the authentic language); this README is curation.
Applicability to EdTech
- Minors under 14 are doubly protected: their personal information is 敏感个人信息 by definition (第二十八条), and processing requires parent/guardian consent plus dedicated processing rules (专门的个人信息处理规则, 第三十一条) — a documented, minors-specific privacy policy is a hard requirement.
- Lawful bases (第十三条): consent, contract/HR necessity, legal duties, emergencies, limited news/public-interest grounds, lawfully disclosed data — no general legitimate-interest ground: school deployments run on consent or contract necessity.
- Cross-border transfers are the hard constraint (第三十八条): a CAC security assessment, certification, or CAC standard contract is needed to move Chinese personal information abroad, plus separate consent; state organs and CIIOs must localise (第四十条) — architecture question: keep Chinese school data in-country or run a transfer mechanism.
Contents
| Document | Covers |
|---|---|
| ERTONG-YU-KUAJING.md | 第十三条 (处理根据), 第二十八条 (敏感个人信息), 第三十一条 (不满14周岁), 第三十八条/第四十条 (跨境) |
Enforcement
国家互联网信息办公室 (CAC) and sector regulators; fines up to ¥50m or 5% of prior-year turnover (第六十六条, not extracted).
Related
- CN 网络安全法 — MLPS + CII localisation
- CN 未成年人网络保护条例 — the minors' operational layer
- EU GDPR — the closest structural sibling
Sources
Meta
Statute text in ERTONG-YU-KUAJING.md is reproduced verbatim in Chinese from the CAC official full-text page by tools/cac-cn/build_cn.py. CAC pages are immutable promulgation snapshots, so verify detects silent edits; a future amendment must be found via the NPC 国家法律法规数据库 (unamended as of last_checked).