← All enforcement actions
China PIPLData Security LawCybersecurity LawMobility

Didi Global¥8.026B (~$1.2B) GDPR fine (2022)

Largest data-protection fine in Asia — 16 violations across PIPL, DSL, CSL

Penalty
¥8.026B (~$1.2B)
Regulator
Cyberspace Administration of China (CAC)
Jurisdiction
China

What happened

CAC fined Didi ¥8.026B (~$1.2B) for 16 violations of China's Personal Information Protection Law, Data Security Law, and Cybersecurity Law — including illegal collection of facial recognition data, clipboard data, ID information, and family-relationship data. The CEO and President were personally fined ¥1M each.

Root cause

What every team should do

  1. Apply data-minimization principle (PIPL Art. 6, GDPR Art. 5(1)(c)) before launch
  2. Classify all collected data; document retention + deletion procedures
  3. Any China cross-border data export needs a CAC Security Assessment or SCC filing
Source: CAC announcement (Jul 21, 2022).
Would your controls have stopped this?

ComplianceIQ audits your existing policies in 60 seconds and shows you exactly which GDPR controls you are missing — mapped to enforcement patterns like this one.

Run my GDPR audit Generate missing policies

Related enforcement actions

Uber
$148M
Paid hackers $100K to hide a 57M-record breach for over a year