Ctrip Fined RMB 10 Million for Illegally Exporting Personal Data – Lessons for Foreign Companies
Shanghai cybersecurity regulators have fined Ctrip a record RMB 10 million under China’s PIPL for failing to conduct required security assessments before exporting personal information abroad. The Ctrip PIPL fine is the latest high-profile incident of a PIPL violation and signals intensifying enforcement of China’s cross-border data transfer rules, underscoring the compliance risks facing multinationals operating in the country.
The Shanghai Cyberspace Administration has revealed it fined the Shanghai branch of Ctrip, the Chinese mainland business of the Singapore-based multinational travel company Trip.com Group, RMB 10 million (US$1.4 million) for failing to implement data export security assessment requirements and illegally exporting personal information, in violation of the Personal Information Protection Law (PIPL).
The RMB 10 million fine is the highest fine imposed for a violation of China’s cross-border data transfer regulations and highlights how authorities are stepping up enforcement almost five years since the implementation of the landmark law.
For companies operating in China, the case is a reminder that personal information export compliance remains firmly in regulators’ sights. With regulators stepping up enforcement of the PIPL, businesses should ensure they have completed the required transfer mechanisms, security assessments, and internal compliance reviews before transmitting personal data overseas.
How did Ctrip violate the PIPL?
The Shanghai Cyberspace Administration did not specify exactly how Ctrip violated the PIPL. The announcement simply stated that the company had “failed to implement data export security assessment requirements and illegally exported personal information” in violation of the PIPL.
Under the PIPL and its implementing regulations, companies that export certain volumes of personal information are required to undergo a security assessment by the Cyberspace Administration of China (CAC). These thresholds are:
- Since January 1 of the current year, the company has cumulatively exported the personal information of 1 million or more individuals (excluding sensitive personal information); or
- Since January 1 of the current year, the company has cumulatively exported the sensitive personal information of 10,000 or more individuals.
Given the size and nature of Ctrip’s operations, the company is almost certain to exceed the personal information export threshold for undergoing a security assessment every year. Moreover, as a consumer-facing travel company, Ctrip will also handle large volumes of sensitive personal data, including financial account information, addresses, whereabouts, and the personal information of minors under 14.
It is therefore reasonable to presume that Ctrip either failed to complete the security assessment as required, submitted it incompletely or incorrectly, or chose a different compliance procedure that applies only to companies exporting smaller volumes of personal information, such as signing a standard contract or undergoing third-party certification.
It is also important to note that, under regulations released in March 2024 to facilitate cross-border data transfers, an exception to the security assessment rules was provided for situations in which a company had a genuine necessity to export personal information to enter into or fulfill the contract with the individual, such as for cross-border shopping, delivery, remittance, payment, account opening, and flight and hotel booking. This suggests that Ctrip’s personal information export activity was also non-essential for the performance of contracts with customers, in addition to exceeding the total export volume thresholds.
Why did Ctrip get a RMB 10 million fine?
The size of the fine also suggests that the violation was relatively serious. The PIPL does not immediately impose a fine for violations; instead, the company will be issued a warning, ordered to make corrections, and have any illegal gains confiscated. A fine of up to RMB 1 million (US$147,639) is given only where the company refuses to comply with these orders.
However, fines of up to RMB 50 million (US$7.38 million) or up to 5 percent of the previous year’s turnover are given for violations where the “circumstances are serious”.
The notice also mentioned that Ctrip actively cooperated after being penalized and fully implemented the corrections it was ordered to make, which may have helped to lessen the fine.
What does this mean for companies?
The Ctrip case is a strong indication that China’s cybersecurity regulators are taking violations of the PIPL more seriously.
The PIPL and its implementing regulations are written in such a way as to give authorities considerable flexibility in issuing legal orders and meting out penalties, meaning it is difficult for companies to accurately assess how a given compliance gap will be treated until a regulatory investigation.
The announcement from the Shanghai Cyberspace Administration noted that recent data protection cases show that consumer-focused internet companies are still engaging in illegal and irregular personal information export, despite these requirements being in place since 2021. The regulator is therefore intensifying efforts to crack down on activities that could endanger cyber- and data security and infringe upon the rights of individuals.
The size of the fine underscores this approach. Previous PIPL violation cases, such as the ruling against Dior for violations of personal information protection obligations in 2025, resulted only in a warning and order for rectification.
This means companies must take extra precautions to ensure compliance and be vigilant against areas of the business which could inadvertently breach personal information export rules, whether it is data collection and consent policies, data storage infrastructure, protection protocols, or data export procedures.
Companies also need to carefully assess whether activity does indeed fall under the compliance exemption scenarios, and that all activity is strictly necessary for the fulfilment of duties under a contract with the individual concerned, rather than assuming an exemption applies simply because the data relates to a customer transaction.
How can companies stay compliant and avoid fines?
China’s PIPL, cybersecurity, and data laws are now some of the top compliance considerations for foreign companies and multinationals operating in China. This means companies must have personnel (either internal or external) who are adequately trained and familiar with all of the data and personal information protection requirements relevant to their business, including how to correctly classify personal and sensitive personal information, when a security assessment, standard contract, or certification is required, and how to document that a cross-border transfer is genuinely necessary for the performance of a contract.
While China’s personal information export rules have a higher impact on large multinationals that routinely exceed the security assessment thresholds, smaller companies also need to be vigilant and ensure they are correctly tracking their cumulative export volumes throughout the year, since crossing a threshold partway through the year can trigger the same security assessment obligations as those faced by much larger firms.
How Dezan Shira & Associates can help
Given the complexity and fast-changing nature of these requirements, many companies find it useful to work with an experienced advisory partner to review their data handling practices, close compliance gaps, and prepare for potential regulatory scrutiny before it happens.
Dezan Shira & Associates provides cybersecurity and compliance advisory tailored for China’s regulatory landscape, including IT infrastructure audits, Zero Trust implementation, security training, and multi-jurisdictional data privacy compliance covering China’s Cybersecurity Law, Data Security Law, and PIPL alongside global frameworks such as GDPR. To arrange a consultation, please contact our local team.
Asia’s data protection environment is rapidly evolving, with businesses facing rising pressure to maintain secure IT systems while complying with national regulations like China’s CSL, DSL, and PIPL, alongside global frameworks such as GDPR. Dezan Shira & Associates provides cybersecurity and compliance advisory tailored for Asia’s regulatory landscape. Our services include IT infrastructure audits, Zero Trust implementation, security training, and multi-jurisdictional data privacy compliance.
About Us
China Briefing is one of five regional Asia Briefing publications. It is supported by Dezan Shira & Associates, a pan-Asia, multi-disciplinary professional services firm that assists foreign investors throughout Asia, including through offices in Beijing, Tianjin, Dalian, Qingdao, Shanghai, Hangzhou, Ningbo, Suzhou, Guangzhou, Haikou, Zhongshan, Shenzhen, and Hong Kong in China. Dezan Shira & Associates also maintains offices or has alliance partners assisting foreign investors in Vietnam, Indonesia, Singapore, India, Malaysia, Mongolia, Dubai (UAE), Japan, South Korea, Nepal, The Philippines, Sri Lanka, Thailand, Italy, Germany, Bangladesh, Australia, United States, and United Kingdom and Ireland.
For a complimentary subscription to China Briefing’s content products, please click here. For support with establishing a business in China or for assistance in analyzing and entering markets, please contact the firm at china@dezshira.com or visit our website at www.dezshira.com.
- Previous Article EU Forced Labour Regulation: What FIEs in China Need to Know
- Next Article




