China Privacy Law Compliance Guide
Decide whether China's Personal Information Protection Law () applies, identify the and entrusted parties, map processing and higher-risk activities, then choose the required controls and current cross-border transfer route.
Read the guides in decision order. The 22 March 2024 cross-border provisions control where they conflict with the older assessment and standard-contract measures.
is a binding national law adopted on 20 August 2021 and effective since 1 November 2021. It applies to processing in China and to specified overseas processing that offers products or services to people in China or analyzes or assesses their behavior. For each activity, document the Article 13 condition, notice, data minimization, retention, rights, security, higher-risk triggers, recipients, and any overseas provision.
Key dates for China Privacy Law
Distinguish adoption, commencement, filing, validity, renewal, and reassessment dates under the binding , app rules, and export measures. For current route decisions, the binding 22 March 2024 cross-border provisions override inconsistent parts of the 2022 assessment and 2023 standard-contract measures; Sorena's reading order and evidence suggestions are explanatory, not additional legal requirements.
Choose the next PIPL decision
Start with territorial scope, role and processing basis. Then open the focused guide for consent, sensitive information, apps, vendors, , incidents, exports, deadlines, enforcement or comparisons.
Start here: scope, roles and baseline duties
Decide whether PIPL applies, identify the personal information processor and other parties, and build the processing inventory and control plan.
Processing choices and operating controls
Design notices and choices, protect sensitive information, govern vendors and automated decisions, and prepare breach response.
App minimization
Map the app's real basic functions to the official 39-category necessary-information table, then overlay the full PIPL analysis.
PIPIA and cross-border transfers
Document higher-risk processing, apply 2024 exemptions and thresholds, and complete the selected assessment or standard-contract route.
Deadlines and enforcement
Separate historical effective dates from event-driven filing, validity and record-retention periods, then understand the graduated enforcement exposure.
Comparisons and focused questions
Keep China conclusions separate from GDPR, CCPA/CPRA and Singapore PDPA, or open a direct answer for a specific PIPL question.
Prepare the PIPL and data export evidence file
Sorena AI turns China official requirements into scoped decisions, evidence records, owner assignments, and change-trigger reviews.
- Start with territorial scope, the role, the processing purpose and basis, the affected people, and the complete data flow.
- Research Copilot keeps the official citation, decision owner, evidence record, and approval history connected.
- SSOT preserves notices, consent states, PIPIAs, vendor terms, rights records, incident decisions, transfer routes and their change history.
