
The design
China's Personal Information Protection Law (PIPL) was adopted by the Standing Committee of the National People's Congress on 20 August 2021 and took effect on 1 November 2021, according to the official NPC translation. It is the framework statute governing how any company handling personal data inside China, including Xiaoice's operator, must collect and process it. A parallel scholarly rendering by Stanford's DigiChina project, published 20 August 2021, is widely cited for its article-by-article English translation.
What the evidence says
Both translations agree on the operative text. Article 13 requires that handling personal information rest on one of several bases, ordinarily an individual's consent; Article 14 requires that consent be given “under the precondition of full knowledge, and in a voluntary and explicit statement.” Articles 28 and 29 require “separate consent” before handling “sensitive personal information.” Articles 38 and 39 require either a security assessment, a certification, or a standard contract before personal information is sent outside China's borders, plus separate consent and notice to the individual about the receiving party. Neither translation is itself a ruling on any company's compliance.
What it asks of people
PIPL asks a company processing data inside China to obtain consent that is specific and informed rather than bundled into a single blanket agreement, and to treat data revealing things like health or biometric identity as requiring extra, separate consent under Article 29. For a companion product's users, this framework is what determines, in principle, whether their conversation data can be sent to servers outside China at all, and on what terms they must be told about it beforehand.
Privacy and safeguards
The law creates state mechanisms rather than product-level ones: Article 12 commits China to participating in international personal-information rules, and later provisions direct regulators to write sector-specific rules, including “new technologies and new applications for handling sensitive personal information, facial recognition, artificial intelligence.” This entry describes the statute's own text as background for a China-based companion product; it does not describe, and no source here establishes, how Xiaoice's operator has applied these articles in practice.
- What separate-consent mechanism, if any, does a given companion app show before collecting sensitive personal information?
- Where are a companion app's servers, and does that determine whether Articles 38-39 on cross-border transfer apply?
- Has any Chinese regulator issued a public finding about a specific companion app under this law?
PIPL is the legal backdrop against which any China-based companion app, Xiaoice included, has operated since November 2021; treating it as background context rather than a verdict on any single company keeps the statute's own text from being over-read as proof of what one product actually does.
Sources & reading trail
Scholarly English translation of the full statute, including the consent, sensitive-information, and cross-border-transfer articles, with a note on the law's effective date.
Source published: 20 August 2021 · Retrieved: 16 September 2026
The National People's Congress's own English translation, confirming the law's adoption date of 20 August 2021 and effective date of 1 November 2021, and the numbered articles on consent and cross-border transfer.
Source published: 29 December 2021 · Retrieved: 16 September 2026
Product documents, regulator records and studies establish the entry; the design reading is AI Companions editorial analysis. This retrospective draft does not imply the site published on the event date.