PrivacyChina

China Privacy Law Compliance Guide

Decide whether China's Personal Information Protection Law (PIPL) applies, identify the personal information processor and entrusted parties, map processing and higher-risk activities, then choose the required controls and current cross-border transfer route.

By Sorena AIOfficial citationsPractical launch evidence
Quick scan
Privacy
1. Scope, data and role
Confirm China or overseas territorial scope and the personal-or-family-affairs exclusion. Distinguish personal information, sensitive personal information, de-identified information, and genuinely anonymized information. Identify the personal information processor, joint processors, entrusted processors, and independent recipients.
2. Processing controls
Assign an Article 13 processing condition and implement purpose limitation, minimum scope, shortest necessary retention, notice, valid consent where used, separate consent where required, individual rights, vendor controls, automated-decision rules, security, and incident response.
3. PIPIA and export route
Complete PIPIAs before every Article 55 activity and keep the report and processing record for at least three years. For overseas flows, apply important-data and CIIO checks, then the 2024 exemptions and thresholds before selecting security assessment, standard contract, or certification.

Read the guides in decision order. The 22 March 2024 cross-border provisions control where they conflict with the older assessment and standard-contract measures.

Key dates
1 Nov 2021
PIPL effective
1 Jun 2023
SCC measures effective
1 Sep 2022
export assessment effective
22 Mar 2024
cross-border provisions
Use this decision order
1. Scope, data and role
Confirm China or overseas territorial scope and the personal-or-family-affairs exclusion. Distinguish personal information, sensitive personal information, de-identified information, and genuinely anonymized information. Identify the personal information processor, joint processors, entrusted processors, and independent recipients.
2. Processing controls
Assign an Article 13 processing condition and implement purpose limitation, minimum scope, shortest necessary retention, notice, valid consent where used, separate consent where required, individual rights, vendor controls, automated-decision rules, security, and incident response.
3. PIPIA and export route
Complete PIPIAs before every Article 55 activity and keep the report and processing record for at least three years. For overseas flows, apply important-data and CIIO checks, then the 2024 exemptions and thresholds before selecting security assessment, standard contract, or certification.
Scope and processor role
Processing basis and separate consent
PIPIA and current export route
Publication details
Editorial metadata for this artifact
Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 16, 2026

PIPL is a binding national law adopted on 20 August 2021 and effective since 1 November 2021. It applies to processing in China and to specified overseas processing that offers products or services to people in China or analyzes or assesses their behavior. For each activity, document the Article 13 condition, notice, data minimization, retention, rights, security, higher-risk triggers, recipients, and any overseas provision.

China Timeline

Key dates for China Privacy Law

Distinguish adoption, commencement, filing, validity, renewal, and reassessment dates under the binding PIPL, app rules, and export measures. For current route decisions, the binding 22 March 2024 cross-border provisions override inconsistent parts of the 2022 assessment and 2023 standard-contract measures; Sorena's reading order and evidence suggestions are explanatory, not additional legal requirements.

Loading timeline...
Recommended reading path

Choose the next PIPL decision

Start with territorial scope, role and processing basis. Then open the focused guide for consent, sensitive information, apps, vendors, PIPIA, incidents, exports, deadlines, enforcement or comparisons.

2

Processing choices and operating controls

Design notices and choices, protect sensitive information, govern vendors and automated decisions, and prepare breach response.

4

PIPIA and cross-border transfers

Document higher-risk processing, apply 2024 exemptions and thresholds, and complete the selected assessment or standard-contract route.

6

Comparisons and focused questions

Keep China conclusions separate from GDPR, CCPA/CPRA and Singapore PDPA, or open a direct answer for a specific PIPL question.

Next step

Prepare the PIPL and data export evidence file

Sorena AI turns China PIPL official requirements into scoped decisions, evidence records, owner assignments, and change-trigger reviews.

What this unlocks
  • Start with territorial scope, the personal information processor role, the processing purpose and basis, the affected people, and the complete data flow.
  • Research Copilot keeps the official citation, decision owner, evidence record, and approval history connected.
  • SSOT preserves notices, consent states, PIPIAs, vendor terms, rights records, incident decisions, transfer routes and their change history.
China Privacy Law artifact preview
Share it internally
Download the timeline export to align legal, product, engineering, and commercial teams on milestones and deadlines.