TwinEthos homeRequest access

Law

China PIPL Art. 24 (automated decision-making)

Cyberspace Administration of China and departments performing personal-information protection duties · China (CN) · 2 provisions encoded · verified against the official source as of 2026-10-02.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

AI-adjacent law General privacy or biometric law, included only where AI data flows trigger it; reported apart from AI-specific law.

Official text: www.npc.gov.cn.

Trust and provenance 1 official source · last verified 3 Oct 2026 · not reviewed by a lawyer · 2 of 2 provisions audit-grade · release 2026.10.03.3

Where this instrument's data comes from, how current it is, and what has and has not been checked. Each provision below has its own panel.

Official sources
Lanes
Binding law — in force 2
Verification
Sources last verified 3 Oct 2026; each provision states how.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
None of the 2 provisions has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 1.
Audit standard
2 of 2 provisions audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
2 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
Changes
  • 2026.10.03.3 (3 Oct 2026): 2 provisions added

Each data release records which provisions changed; the full list is on Changes.

Binding law — in force AI-adjacent law

Automated push and marketing must offer an option not based on personal characteristics, or an easy way to refuse (China PIPL)

中华人民共和国个人信息保护法 第二十四条第二款 (Art. 24(2), non-personalised option or refusal for automated push and marketing) · official text · In force: applies since 1 Nov 2021 · China (CN)

Where a personal information handler pushes information or markets to individuals by automated decision-making, it must at the same time offer an option that is not targeted at the individual's personal characteristics, or give the individual a convenient way to refuse (Art. 24(2)). Automated decision-making means computer programs automatically analysing and assessing a person's behaviour, interests or economic, health or credit status and deciding (Art. 73(2)). Detect personalised feed, push or marketing calls with no non-personalised option or refusal.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 1 Nov 2021
Official source
中华人民共和国个人信息保护法 第二十四条第二款 (Art. 24(2), non-personalised option or refusal for automated push and marketing) · captured 2 Oct 2026 · anchor hash (SHA-256) b733e24e8f89… · 6 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Opt-out enforced by a feature-flag service
  • User-tag management UI
  • The toggle may be read in a controller that wraps the recommender; confirm the request path. Tag select/delete controls (Art. 17 para. 2) are checked by the artifact detector.

Who it applies to

  • Duty falls on: controller
  • Systems covered: automated decision
  • Personal information handlers that use personal information for automated decision-making (computer programs automatically analysing or assessing a person's behaviour, interests, or economic, health or credit status and making decisions, Art. 73(2)), in China and abroad where Art. 3(2) applies. In force 2021-11-01 (Art. 74). AI-adjacent (D-9, D-13).
  • Not covered:
    • Natural persons processing personal information for personal or family affairs (Art. 72(1))
    • Personal information processing in statistical and archival work organised by governments and their departments, where a law provides for it (Art. 72(2))

The guard to add

Give users a setting that turns off personalized recommendation (or picks a non-personalized feed) and controls to view and delete their targeting tags, enforced in the feed service.

A per-user personalization_enabled preference stored server-side and read by the feed or search service before it calls the personalized recommender (get_recommendations, recommend_for_user); when it is off, the service immediately serves a non-personalized feed (latest, popular, editorial) not keyed to user features, including on cached responses. The interest tags or labels that drive targeting are listed to the user with select and delete controls (GET and DELETE /me/tags/{id}), and the recommender excludes deleted tags on the next request. A notice in settings or next to the feed says that recommendations are algorithmic and why.

Where it goes: 1 application source code, 2 data models, 9 AI output handling, 14 user-facing text.

What this provision adds:

  • Offer, alongside personalised push and marketing, an option not targeted at personal characteristics, or a convenient refusal that the push and marketing service reads before calling the personalised model.

Example (FastAPI feed service), before:

@app.get('/feed')
def feed(user=Depends(current_user)):
    return get_recommendations(user_id=user.id, k=50)

After:

@app.get('/feed')
def feed(user=Depends(current_user)):
    if not prefs.get(user.id, 'personalization_enabled', default=True):
        return non_personalized_feed(k=50)       # latest/popular, no user features
    return get_recommendations(user_id=user.id, k=50, exclude_tags=tags.deleted(user.id))

@app.delete('/me/tags/{tag_id}')
def delete_tag(tag_id: str, user=Depends(current_user)):
    tags.delete(user.id, tag_id)
    feed_cache.invalidate(user.id)

Control: Algorithmic recommendation with no opt-out or non-personalized option. The same guard addresses 2 items with binding law in 1 jurisdiction. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

  • Meta says it will use people's interactions with Meta AI to personalize content and ads (2025-10; disclosed by the operator). On October 1, 2025 Meta announced that from December 16, 2025, in most regions, it would use people's interactions with AI at Meta to personalize the content and ads they see, with notifications to users starting October 7, 2025. Meta says that when people have conversations with Meta AI about topics such as their religious views, sexual orientation, political views, health, racial or ethnic origin, philosophical beliefs, or trade union membership, it does not use those topics to show them ads, and it points people to Ads Preferences and feed controls to adjust what they see. The entry records the operator's own description of its practice. Source: Meta Newsroom (2025-10-01) · evidence grade: primary · cited by Do not profile people from AI-inferred emotions or sensitive traits without notice and opt-in
  • Microsoft retires Azure Face emotion and identity-attribute inference (2022-06; disclosed by the operator). On June 21, 2022 Microsoft said it would retire Azure Face capabilities that infer emotional states and identity attributes such as gender, age, smile, facial hair, hair, and makeup: unavailable to new customers from that day, with existing customers given until June 30, 2023 to stop using them. Microsoft cited privacy, the lack of consensus on a definition of 'emotions', and the inability to generalize the link between facial expression and emotional state across use cases, regions, and demographics, and said that access to capabilities predicting sensitive attributes opens ways to misuse them, including stereotyping, discrimination, or unfair denial of services. It kept these capabilities for controlled accessibility scenarios such as Seeing AI. Source: Microsoft Azure Blog (2022-06-21) · evidence grade: primary · cited by Do not profile people from AI-inferred emotions or sensitive traits without notice and opt-in
  • Hungarian regulator fines a bank for AI analysis of callers' emotions without notice or a way to object (2017-05; confirmed). In decision NAIH-85-3/2022 of 8 February 2022, Hungary's data protection authority found that Budapest Bank's speech-analysis software, which the bank said it introduced on 26 May 2017, automatically analysed recorded customer-service calls for keywords and for the emotional state of the caller and the employee, and that the results were used to rank calls and to select dissatisfied customers to call back. The Authority found that callers were not told at the start of calls about the voice analysis, the automatic evaluation of their emotions, or the resulting possible callback, and could not object; it rejected the bank's statement that the software contained no artificial intelligence. It found infringements of GDPR Articles 5(1)(a)-(b), 6(1), 6(4), 12(1), 13, 21(1)-(2), 24(1) and 25(1), ordered the bank not to analyse emotions in the voice analysis, and imposed a fine of HUF 250 million. The decision also records, from the bank's own technical file, that the emotion was unrecognisable in 91.96% of cases. Source: Nemzeti Adatvédelmi és Információszabadság Hatóság (Hungarian data protection authority), decision NAIH-85-3/2022, English version · evidence grade: primary · cited by Do not profile people from AI-inferred emotions or sensitive traits without notice and opt-in

Rule id cn-pipl-adm.push-marketing-non-personalised-option · review status: primary source derived

Binding law — in force AI-adjacent law

Individuals may demand an explanation of automated decisions with significant effects and refuse decisions made solely by automation (China PIPL)

中华人民共和国个人信息保护法 第二十四条第三款 (Art. 24(3), explanation and refusal of solely automated significant decisions) · official text · In force: applies since 1 Nov 2021 · China (CN)

Where a decision that significantly affects an individual's rights and interests is made by automated decision-making, the individual may require the personal information handler to explain it and may refuse to have the handler make decisions solely by automated decision-making (Art. 24(3)). Detect model output that becomes a significant decision with no explanation request route and no way to have a person decide instead.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 1 Nov 2021
Official source
中华人民共和国个人信息保护法 第二十四条第三款 (Art. 24(3), explanation and refusal of solely automated significant decisions) · captured 2 Oct 2026 · anchor hash (SHA-256) 825cef977b1b… · 6 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Whether a decision has a significant impact on the individual's rights and interests is a human determination.

Who it applies to

  • Duty falls on: controller
  • Systems covered: automated decision
  • Personal information handlers that use personal information for automated decision-making (computer programs automatically analysing or assessing a person's behaviour, interests, or economic, health or credit status and making decisions, Art. 73(2)), in China and abroad where Art. 3(2) applies. In force 2021-11-01 (Art. 74). AI-adjacent (D-9, D-13).
  • Not covered:
    • Natural persons processing personal information for personal or family affairs (Art. 72(1))
    • Personal information processing in statistical and archival work organised by governments and their departments, where a law provides for it (Art. 72(2))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Route significant automated decisions through meaningful human review, or wire in an automated-decision notice, reasons, human intervention, a way to give a view, and contest.

At the point where model output becomes a significant decision about a person (approve, deny, underwrite, set_status), either queue the case for a reviewer who weighs the evidence and can change the outcome before it takes effect (review_queue.enqueue, requires_human_review), or, where the decision stays solely automated, record the permitted basis for that decision type and wire the safeguards in. Those safeguards are a notice in the decision message that it was made by automated processing, reasons the person can read, and request_human_review or contest routes where the person can give their view and have a human reconsider. A reviewer who approves every case without examining it does not make the decision non-automated, so the review records reviewer identity, the evidence viewed, and the outcome.

Where it goes: 1 application source code, 9 AI output handling, 15 agent action surface, 14 user-facing text.

What this provision adds:

  • Answer an explanation request about a significant automated decision, and route a person who refuses a solely automated decision to a decision with human involvement.

Example (Python + OpenAI SDK), before:

verdict = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
if verdict.strip() == 'deny':
    deny(applicant)
    send_decision_email(applicant, 'Your application was not approved.')

After:

out = client.chat.completions.create(model=MODEL, messages=msgs,
                                     response_format={'type': 'json_object'})
result = json.loads(out.choices[0].message.content)
if result['decision'] == 'deny':
    if requires_human_review('credit'):                 # a person decides
        review_queue.enqueue(applicant.id, proposal=result)
    else:                                               # solely automated, recorded basis
        deny(applicant, basis=DECISION_BASIS['credit'], reasons=result['reasons'])
        send_decision_email(applicant, render('adm_denial.txt', notice=ADM_NOTICE,
            reasons=result['reasons'], contest_url=f'{BASE}/decisions/{applicant.id}/contest'))

Control: Solely-automated significant decision without human-intervention safeguards. The same guard addresses 15 items with binding law in 15 jurisdictions. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

Rule id cn-pipl-adm.significant-decision-explanation-and-refusal · review status: primary source derived

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.