What PIPL says about fingerprinting
The Personal Information Protection Law of the People's Republic of China (PIPL) came into force on 1 November 2021. It does not mention 'fingerprinting' by name, but PIPL Article 4 defines personal information as 'any kind of information related to identified or identifiable natural persons recorded by electronic or other means, excluding anonymised information'. A browser or device fingerprint (the hash of a device's screen, fonts, rendering capabilities, audio stack, time zone and other stable characteristics) falls inside that definition the moment it can be linked to an individual, directly or in combination with other data.
The Cyberspace Administration of China (CAC), as the primary enforcement body, has applied similarly broad interpretive logic in its enforcement guidance and in the TC260 national standard GB/T 35273 on personal information security, which treats device identifiers and behavioural tracking signals as personal information covered by the standard. There is no 'low-risk' carve-out that excludes fingerprints from PIPL's scope on the basis that they are probabilistic rather than deterministic identifiers.
PIPL Article 13: the seven lawful bases
PIPL Article 13 sets out the only grounds on which personal information may be processed. These are: (1) obtaining the individual's consent; (2) necessity for conclusion or performance of a contract to which the individual is a party, or necessity for human resources management; (3) necessity for fulfilling a statutory duty or legal obligation; (4) necessity for responding to a public health emergency, or for protecting life, health or property in an emergency; (5) processing for public-interest journalism, supervision, or historical record; (6) processing already-disclosed personal information within a reasonable scope; and (7) other circumstances prescribed by law or administrative regulation.
For the vast majority of commercial fingerprinting use cases (analytics, personalisation, advertising, A/B testing, cross-device recognition, and most anti-fraud scenarios), none of the non-consent bases apply on a straightforward reading. Consent (ground 1) is the default, and the product team should start there.
The contract-necessity basis (ground 2) is occasionally argued for anti-fraud and account-security fingerprinting, on the theory that the service agreement contemplates keeping the account secure. Chinese regulators and the TC260 guidance have not endorsed a wide reading of this basis, and relying on it without a documented legal analysis creates enforcement risk.
PIPL Article 14: what valid consent requires
PIPL Article 14 defines consent as voluntary, fully informed, and explicit. The three requirements matter in practice. 'Voluntary' means consent obtained under conditions of coercion or as a bundled condition of using the service is not valid, a point the CAC has stressed in its mobile app enforcement campaign, where several apps were ordered to stop making core functionality contingent on consent to unnecessary data collection.
Article 14 also requires that where personal information processing involves multiple purposes, consent must be obtained separately for each purpose. This granularity requirement is close to the GDPR standard and has the same operational implication: a single 'I agree to the privacy policy' checkbox does not satisfy Article 14 when the privacy policy buries fingerprinting within a paragraph about analytics.
Article 14 further requires that when the purpose, processing method, or categories of information change materially, fresh consent must be re-obtained from individuals. A fingerprinting deployment that starts as fraud-only and is later repurposed for personalisation needs a new consent event; it cannot rely on the original acceptance.
Common fingerprinting use cases and PIPL lawful basis
| Use case | Likely lawful basis | Consent required? |
|---|---|---|
| Anti-fraud: blocking known bad device IDs at login or payment | Possibly contract necessity (Art. 13(2)) or statutory obligation (Art. 13(3)); document carefully | Probably not, if scoped and disclosed |
| Account takeover and credential-stuffing detection | Contract necessity or consent | Yes, unless contractual basis is documented |
| Product analytics and funnel tracking | Consent (Art. 13(1)) | Yes, explicit |
| Cross-device advertising and retargeting | Consent (Art. 13(1)) | Yes, explicit and granular |
| Personalisation and A/B testing | Consent (Art. 13(1)) | Yes, explicit |
| Third-party data sharing (ad networks, analytics vendors) | Separate consent under Art. 23 | Yes, separate consent event |
| Cross-border transfer of fingerprint data | Separate consent under Art. 39 | Yes, separate consent event |
Sensitive personal information: Articles 28 to 32
PIPL Article 28 defines sensitive personal information as personal information that, once leaked or illegally used, is liable to cause harm to the dignity of natural persons, or serious harm to personal or property safety. The article gives examples including biometric identification information, religious beliefs, specific identity, medical health, financial accounts, and whereabouts.
Fingerprints in the classic browser-fingerprinting sense (a hash of device characteristics) are not biometric identifiers of the kind PIPL Article 28 has in mind, which is aimed at fingerprints derived from physical biometrics (e.g. fingerprint scanners, facial recognition templates). However, the sensitive-information gate can be triggered in two scenarios relevant to product teams: first, if the fingerprinting pipeline includes actual biometric signals (face detection, fingerprint-reader signals on mobile devices); and second, if the device fingerprint is combined with precise geolocation data or financial account information in a way that creates a profile capable of causing serious harm.
When sensitive personal information is involved, Articles 29-32 impose additional requirements: processing must have a specific and sufficient purpose, must be necessary, and must have adopted strict protection measures. Individual notice must explain the necessity and the impact of processing, and explicit consent is required even when another lawful basis might otherwise apply. A Personal Information Protection Impact Assessment (PIPIA) under PIPL Articles 55-56 is also mandatory.
DPIA-equivalent obligations: Articles 53, 55, and 56
PIPL Articles 55 and 56 require personal information processors to conduct a Personal Information Protection Impact Assessment (PIPIA) before processing in any of the following circumstances: processing sensitive personal information, using personal information for automated decision-making, providing personal information to third parties, or processing in any other circumstance that has a significant impact on individuals.
For most fingerprinting deployments that go beyond narrow fraud detection, particularly any deployment that feeds advertising, personalisation, or cross-device tracking, a PIPIA is required. Article 56 specifies that the PIPIA must evaluate the lawfulness and necessity of the processing purpose and method, the impact on individuals and the security risks, and the adequacy of protective measures. Records of the assessment must be retained for at least three years.
PIPL Article 53 further requires that personal information processors establish an internal compliance regime and designate a responsible person for personal information protection, a role analogous to a DPO. For organisations processing personal information of more than one million individuals, or meeting other thresholds set by the CAC, a designated officer must be registered with the CAC.
Enforcement: the Didi Global precedent and CAC practice
The most consequential PIPL enforcement action to date is the CAC's decision against Didi Global (July 2022). The CAC found that Didi had illegally collected over 107 categories of personal information, processed data without a lawful basis, failed to obtain separate consent for sensitive data processing, and violated cross-border transfer rules. The fine was RMB 8.026 billion (approximately USD 1.1 billion at the time), the largest single penalty under PIPL since its entry into force.
Although the Didi case turned on the scale and breadth of unlawful collection rather than on fingerprinting specifically, three findings in the decision are directly relevant to fingerprinting products: the CAC treated device identifiers as personal information, found that bundled consent for multiple purposes violated Article 14's granularity requirement, and held that the absence of a separate consent event for cross-border data flows was a standalone violation under Article 39.
The CAC has also conducted rolling enforcement against mobile apps under its 'App Violations' programme. Several apps have been ordered to stop or remove functionality for collecting device identifiers, including advertising IDs and combinations of hardware signals, without adequate consent or disclosure. The programme has named more than 200 apps since 2021.
Key enforcement actions and guidance documents
- CAC v. Didi Global (July 2022): RMB 8.026 billion fine. The leading PIPL enforcement precedent; establishes that device identifiers are personal information and that bundled or absent consent is a standalone violation.
- CAC 'Measures for Standard Contracts for Cross-Border Transfers' (June 2023): The primary compliance route for organisations below the CIIO threshold transferring personal information overseas.
- Network Data Security Management Regulations (effective 1 January 2025): Supplement PIPL with network-layer obligations; clarify duties for 'network data processors' handling data from Chinese users.
- TC260 GB/T 35273 'Personal Information Security Specification': National standard providing implementation guidance; treats device identifiers and behavioural signals as personal information.
- CAC 'Provisions on the Administration of Algorithmic Recommendations' (March 2022): Covers behavioural tracking used to drive content or product recommendations; requires transparency and opt-out rights where fingerprinting feeds recommendation engines.
- CAC 'App Violations' enforcement programme (2021-ongoing): Rolling review of mobile applications; several removals and fines for collecting device identifiers without valid consent.
How Benny the Doorman fits into a PIPL-aware deployment
Benny is a fingerprinting SDK. Consent collection, purpose disclosure, and the Article 14 granularity requirements are obligations on the data controller (that is, the product team integrating Benny), not on Benny as a processor. The practical integration checklist for a PIPL-aware deployment has four steps.
First, present a granular consent notice before the fingerprint call is made. The notice must identify the purpose (e.g. fraud detection, analytics), the processing method, the categories of data collected, and, if the data will be transferred to a third party or outside China, the identity of the recipient and the basis for the transfer. A single 'I agree to the privacy policy' is not enough.
Second, if the fingerprint will be shared with third parties (including Benny as a sub-processor), obtain the separate consent required by PIPL Article 23. The same applies if the fingerprint data will be transferred outside mainland China: a separate consent event under Article 23 and Article 39 is required, and the standard contract route under the June 2023 CAC Measures must be in place.
Third, conduct and document a PIPIA under PIPL Articles 55-56 before go-live for any deployment beyond narrow fraud detection. Keep the record for at least three years. Fourth, appoint a responsible person for personal information protection under Article 53 and register with the CAC if you meet the volume thresholds.
Frequently asked questions
Is browser fingerprinting regulated under PIPL?
Yes. PIPL Article 4 defines personal information broadly as any information that identifies or can identify a natural person, recorded by electronic or other means. A browser or device fingerprint falls within this definition when it is used to recognise a user across sessions. There is no carve-out for probabilistic or indirect identifiers under PIPL or the TC260 national standards.
Do I need consent for fingerprinting under PIPL?
In most commercial contexts, yes. PIPL Article 13 sets consent as the default lawful basis, and the six non-consent bases are narrow. Personalisation, advertising, analytics, and cross-device recognition all require explicit consent under Article 14. Only narrow anti-fraud or security-of-service scenarios can plausibly rely on a non-consent basis, and even then a documented legal analysis and disclosure are necessary.
Does a standard privacy policy acceptance satisfy PIPL Article 14?
Generally no. Article 14 requires that where processing covers multiple purposes, consent must be obtained separately for each. A single checkbox or general privacy policy acceptance does not meet the granularity requirement when fingerprinting is one of several purposes buried in a lengthy document. The CAC's mobile-app enforcement has repeatedly cited exactly this pattern as non-compliant.
When does a fingerprint become sensitive personal information under PIPL?
Browser device fingerprints in the conventional sense are not ordinarily classified as sensitive personal information under PIPL Article 28, which targets biometric identifiers derived from physical traits. However, the sensitive-data rules can apply if the fingerprint incorporates actual biometric signals (such as facial detection or fingerprint-scanner data on a mobile device), or if the fingerprint is combined with precise geolocation or financial data in a way that could cause serious harm to the individual.
What does PIPL require for cross-border transfer of fingerprint data?
PIPL Article 39 requires a separate, specific consent event before any personal information is transferred outside mainland China. The individual must be told who the recipient is, what they will do with the data, and what rights the individual has in the destination country. Below the CIIO and CAC volume thresholds, the standard contract route under the CAC's June 2023 Measures is the primary compliance mechanism. Above the thresholds, a CAC security assessment and data localisation under Article 40 apply.
Is a PIPIA (data protection impact assessment) required for fingerprinting?
Yes, for most fingerprinting deployments beyond narrow fraud detection. PIPL Articles 55 and 56 require a Personal Information Protection Impact Assessment before processing sensitive personal information, sharing data with third parties, or using personal information for automated decision-making. Records must be retained for at least three years. A fingerprint pipeline that feeds analytics, personalisation, or advertising triggers the obligation.
What was the Didi Global fine and why is it relevant to fingerprinting?
The CAC fined Didi Global RMB 8.026 billion in July 2022 for widespread PIPL violations including unlawful collection of over 107 categories of personal information and failure to obtain granular or separate consent. The decision is the most cited PIPL enforcement precedent and is directly relevant to fingerprinting because it establishes that device identifiers are personal information, that bundled consent fails Article 14's granularity requirement, and that absent cross-border transfer consent is a standalone violation.
Does PIPL apply if our servers are outside China?
Yes. PIPL has extraterritorial reach where personal information of individuals within China is processed for the purpose of providing products or services to them, or for analysing or evaluating the behaviour of individuals within China. Fingerprinting Chinese users from overseas infrastructure is analysing or evaluating behaviour by definition. Organisations meeting the CAC's volume thresholds must also comply with data localisation requirements under Article 40 regardless of where they are incorporated.
Tooling
Benny the Doorman is built for this compliance posture.
Free, cookieless fingerprinting that defers to your consent management platform, runs on Indian infrastructure, and ships with a DPA addendum sized for the jurisdiction above.
Last reviewed 2026-06-06

