Decide whether China's Personal Information Protection Law (PIPL) applies, identify the personal information processor and entrusted parties, map processing and higher-risk activities, then choose the required controls and current cross-border transfer route.
Read the guides in decision order. The 22 March 2024 cross-border provisions control where they conflict with the older assessment and standard-contract measures.
PIPL is a binding national law adopted on 20 August 2021 and effective since 1 November 2021. It applies to processing in China and to specified overseas processing that offers products or services to people in China or analyzes or assesses their behavior. For each activity, document the Article 13 condition, notice, data minimization, retention, rights, security, higher-risk triggers, recipients, and any overseas provision.
Distinguish adoption, commencement, filing, validity, renewal, and reassessment dates under the binding PIPL, app rules, and export measures. For current route decisions, the binding 22 March 2024 cross-border provisions override inconsistent parts of the 2022 assessment and 2023 standard-contract measures; Sorena's reading order and evidence suggestions are explanatory, not additional legal requirements.
Start with territorial scope, role and processing basis. Then open the focused guide for consent, sensitive information, apps, vendors, PIPIA, incidents, exports, deadlines, enforcement or comparisons.
Decide whether PIPL applies, identify the personal information processor and other parties, and build the processing inventory and control plan.
Design notices and choices, protect sensitive information, govern vendors and automated decisions, and prepare breach response.
Map the app's real basic functions to the official 39-category necessary-information table, then overlay the full PIPL analysis.
Document higher-risk processing, apply 2024 exemptions and thresholds, and complete the selected assessment or standard-contract route.
Separate historical effective dates from event-driven filing, validity and record-retention periods, then understand the graduated enforcement exposure.
Keep China conclusions separate from GDPR, CCPA/CPRA and Singapore PDPA, or open a direct answer for a specific PIPL question.
Sorena AI turns China PIPL official requirements into scoped decisions, evidence records, owner assignments, and change-trigger reviews.
