---
title: "China Personal Information Protection and Data Export Compliance Guide"
canonical_url: "https://www.sorena.io/artifacts/apac/china-privacy-law"
source_url: "https://www.sorena.io/artifacts/apac/china-privacy-law"
author: "Sorena AI"
description: "Plain-language China PIPL guide covering territorial scope, processor and vendor roles, consent and sensitive information, PIPIA, app minimization, incidents, and current cross-border transfer routes."
published_at: "2026-07-05"
updated_at: "2026-07-16"
keywords:
  - "China PIPL"
  - "Personal Information Protection Law"
  - "Data export"
  - "Standard contract"
  - "App privacy"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# China Personal Information Protection and Data Export Compliance Guide

Plain-language China PIPL guide covering territorial scope, processor and vendor roles, consent and sensitive information, PIPIA, app minimization, incidents, and current cross-border transfer routes.

![China Privacy Law artifact preview](https://cdn.sorena.io/cdn-cgi/image/format=auto/cheatsheets/prod/sorena-ai-china-privacy-law-timeline-small.jpg?v=cheatsheets%2Fprod)

*Privacy* *China*

## China Privacy Law Compliance Guide

Decide whether China's Personal Information Protection Law (PIPL) applies, identify the personal information processor and entrusted parties, map processing and higher-risk activities, then choose the required controls and current cross-border transfer route.

PIPL is a binding national law adopted on 20 August 2021 and effective since 1 November 2021. It applies to processing in China and to specified overseas processing that offers products or services to people in China or analyzes or assesses their behavior. For each activity, document the Article 13 condition, notice, data minimization, retention, rights, security, higher-risk triggers, recipients, and any overseas provision.

[Prepare the PIPL and data export evidence file](/contact.md)

## Use this decision order

- **1. Scope, data and role**: Confirm China or overseas territorial scope and the personal-or-family-affairs exclusion. Distinguish personal information, sensitive personal information, de-identified information, and genuinely anonymized information. Identify the personal information processor, joint processors, entrusted processors, and independent recipients.
- **2. Processing controls**: Assign an Article 13 processing condition and implement purpose limitation, minimum scope, shortest necessary retention, notice, valid consent where used, separate consent where required, individual rights, vendor controls, automated-decision rules, security, and incident response.
- **3. PIPIA and export route**: Complete PIPIAs before every Article 55 activity and keep the report and processing record for at least three years. For overseas flows, apply important-data and CIIO checks, then the 2024 exemptions and thresholds before selecting security assessment, standard contract, or certification.

By Sorena AI | Official citations | Practical launch evidence

### Quick scan

*Privacy*

- **1. Scope, data and role**: Confirm China or overseas territorial scope and the personal-or-family-affairs exclusion. Distinguish personal information, sensitive personal information, de-identified information, and genuinely anonymized information. Identify the personal information processor, joint processors, entrusted processors, and independent recipients.
- **2. Processing controls**: Assign an Article 13 processing condition and implement purpose limitation, minimum scope, shortest necessary retention, notice, valid consent where used, separate consent where required, individual rights, vendor controls, automated-decision rules, security, and incident response.
- **3. PIPIA and export route**: Complete PIPIAs before every Article 55 activity and keep the report and processing record for at least three years. For overseas flows, apply important-data and CIIO checks, then the 2024 exemptions and thresholds before selecting security assessment, standard contract, or certification.

Read the guides in decision order. The 22 March 2024 cross-border provisions control where they conflict with the older assessment and standard-contract measures.

| Value | Metric |
| --- | --- |
| 1 Nov 2021 | PIPL effective |
| 1 Jun 2023 | SCC measures effective |
| 1 Sep 2022 | export assessment effective |
| 22 Mar 2024 | cross-border provisions |

**Key highlights:** Scope and processor role | Processing basis and separate consent | PIPIA and current export route

## Primary sources

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Binding source for territorial scope, definitions, processing conditions, notice and consent, sensitive information, automated decisions, individual rights, processor and vendor duties, PIPIA, incidents, overseas transfers, penalties, and the 1 November 2021 effective date.
- [Measures for the Standard Contract for Personal Information Export](https://www.cac.gov.cn/2023-02/24/c_1678884830036813.htm?ref=sorena.io) - Binding measure for the CAC standard-contract form, pre-export PIPIA, contract effectiveness, filing within 10 working days, and refiling triggers, subject to the controlling 2024 provisions.
- [Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Binding measure for assessment preparation, filing materials, review steps, legal-instrument content, and reapplication triggers; the 2024 provisions replace its older two-year validity rule with three years.
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Controlling current source for important-data treatment, export exemptions, CIIO and current-year volume thresholds, standard-contract or certification bands, three-year assessment validity, continuing PIPL duties, and precedence over inconsistent earlier measures.
- [Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Use for app category, basic-function, minimum necessary personal information, no-refusal rule, and 1 May 2021 effective date.
- [Mobile Internet Application Information Service Management Provisions](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io) - Use for app provider and app distribution platform governance, content/security/data duties, platform filing and verification, and 1 August 2022 effective date.

*Recommended reading path*

## Choose the next PIPL decision

Start with territorial scope, role and processing basis. Then open the focused guide for consent, sensitive information, apps, vendors, PIPIA, incidents, exports, deadlines, enforcement or comparisons.

### 1. Start here: scope, roles and baseline duties

Decide whether PIPL applies, identify the personal information processor and other parties, and build the processing inventory and control plan.

1. [China PIPL requirements](/artifacts/apac/china-privacy-law/requirements.md): China PIPL requirements from scope and processing basis through notices, rights, security, impact assessments, incidents, vendors, and data exports.
2. [China PIPL compliance checklist](/artifacts/apac/china-privacy-law/checklist.md): China PIPL compliance checklist covering scope, processing bases, notices, sensitive information, rights, vendors, impact assessments, incidents, and exports.

### 2. Processing choices and operating controls

Design notices and choices, protect sensitive information, govern vendors and automated decisions, and prepare breach response.

3. [China PIPL privacy notice and consent checklist](/artifacts/apac/china-privacy-law/privacy-policy-and-consent-checklist.md): China PIPL checklist for privacy notices, valid consent, separate consent, sensitive information, children under 14, withdrawal, and rights requests.
4. [Sensitive personal information and separate consent under PIPL](/artifacts/apac/china-privacy-law/sensitive-personal-information-and-separate-consent.md): How to identify sensitive PI triggers, separate consent, minors, additional safeguards, and evidence records.
5. [PIPL entrusted processing and vendor contracts](/artifacts/apac/china-privacy-law/entrusted-processing-and-vendor-contracts.md): How to document entrusted processing, vendor responsibilities, contract controls, and evidence under PIPL.
6. [PIPL automated decision-making and personalized recommendations](/artifacts/apac/china-privacy-law/automated-decision-making-and-personalized-recommendations.md): PIPL checks for automated decisions, personalized recommendations, marketing, differential treatment, explanations, refusal rights, and impact assessments.
7. [PIPL breach response and notification](/artifacts/apac/china-privacy-law/breach-response-and-notification.md): PIPL incident workflow for immediate remediation, authority and individual notices, the narrow individual-notice exception, vendor coordination, and evidence.

### 3. App minimization

Map the app's real basic functions to the official 39-category necessary-information table, then overlay the full PIPL analysis.

8. [China app personal information minimization](/artifacts/apac/china-privacy-law/app-personal-information-minimization.md): How to map app category, basic functions, and necessary personal information under China mobile app personal-information rules.
9. [App minimum necessary personal information by category](/artifacts/apac/china-privacy-law/app-minimum-necessary-personal-information-by-category.md): App category mapping page for common mobile app necessary personal information scope, using only categories supported by the official source.

### 4. PIPIA and cross-border transfers

Document higher-risk processing, apply 2024 exemptions and thresholds, and complete the selected assessment or standard-contract route.

10. [PIPL impact assessment template](/artifacts/apac/china-privacy-law/personal-information-protection-impact-assessment-template.md): Template fields for a China personal information protection impact assessment and export/entrusted-processing evidence.
11. [China personal information cross-border transfer routes](/artifacts/apac/china-privacy-law/cross-border-transfer-routes.md): Compare China's current data-export exemptions, CAC security assessment, standard contract, and personal information protection certification routes.
12. [PIPL cross-border transfer route selector](/artifacts/apac/china-privacy-law/pipl-cross-border-transfer-route-selector.md): Step-by-step selector for China's data-export exemptions, CAC security assessment, standard contract, and personal information protection certification.
13. [China data export security assessment workflow](/artifacts/apac/china-privacy-law/data-export-security-assessment-workflow.md): Workflow for screening data export security assessment triggers, materials, owners, and evidence records.
14. [China personal information standard contract filing workflow](/artifacts/apac/china-privacy-law/standard-contract-filing-workflow.md): Workflow for the PIPL standard contract route, assessment, filing package, and cited evidence.

### 5. Deadlines and enforcement

Separate historical effective dates from event-driven filing, validity and record-retention periods, then understand the graduated enforcement exposure.

15. [China PIPL deadlines and compliance calendar](/artifacts/apac/china-privacy-law/deadlines-and-compliance-calendar.md): Calendar China PIPL effective dates, recurring audits, privacy-officer reporting, impact-assessment retention, and data export filing and renewal deadlines.
16. [China PIPL penalties and enforcement exposure](/artifacts/apac/china-privacy-law/penalties-and-fines.md): Understand PIPL corrective orders, serious-violation fines, responsible-person exposure, civil claims, public-interest actions, and data export enforcement.

### 6. Comparisons and focused questions

Keep China conclusions separate from GDPR, CCPA/CPRA and Singapore PDPA, or open a direct answer for a specific PIPL question.

17. [China PIPL vs EU GDPR: Requirements Compared](/artifacts/apac/china-privacy-law/china-privacy-law-vs-gdpr.md): Compare PIPL and GDPR scope, roles, legal bases, rights, impact assessments, breach deadlines, international transfers, and penalties.
18. [China PIPL vs CCPA/CPRA: Requirements Compared](/artifacts/apac/china-privacy-law/china-pipl-vs-ccpa-cpra.md): Compare PIPL and CCPA/CPRA scope, consent and opt-out rules, rights, assessments, data exports, breach duties, and penalties.
19. [China PIPL vs Singapore PDPA: Requirements Compared](/artifacts/apac/china-privacy-law/china-privacy-law-vs-singapore-pdpa.md): Compare PIPL and Singapore PDPA scope, roles, consent alternatives, rights, breach duties, overseas transfers, and penalties.
20. [China Privacy Law FAQ](/artifacts/apac/china-privacy-law/faq.md): Practical answers on China's PIPL: scope, legal bases, sensitive information, separate consent, vendors, PIPIA records, app minimization, and export routes.

### 7. More guides

Additional guidance related to this artifact.

21. [How should vendor contracts handle entrusted processing under PIPL?](/artifacts/apac/china-privacy-law/faq/how-should-vendor-contracts-handle-entrusted-processing.md): A PIPL entrusted-processing contract must define the purpose, duration, method, personal-information categories, safeguards, and both parties' duties. See the required terms and supporting records.
22. [Is PIPL the same as GDPR?](/artifacts/apac/china-privacy-law/faq/is-pipl-the-same-as-gdpr.md): No. China's PIPL and the EU GDPR overlap on core privacy controls, but differ in territorial scope, legal bases, roles, sensitive data, impact assessments, and transfer routes.
23. [What counts as sensitive personal information in China?](/artifacts/apac/china-privacy-law/faq/what-counts-as-sensitive-personal-information-in-china.md): PIPL uses a harm-based test for sensitive personal information and lists examples such as biometrics, health, financial accounts, location traces, and all personal information of children under 14.
24. [What is separate consent under PIPL?](/artifacts/apac/china-privacy-law/faq/what-is-separate-consent-under-pipl.md): Separate consent under China's PIPL is a distinct consent for a specified processing activity. See when it applies, what notice must come first, and what evidence to keep.
25. [What records should we keep for a PIPL impact assessment?](/artifacts/apac/china-privacy-law/faq/what-records-should-we-keep-for-a-pipl-impact-assessment.md): A PIPL impact-assessment file should preserve the Article 55 trigger, processing facts, Article 56 analysis, safeguards, decision, and processing record for at least three years.
26. [What should an app collect as necessary personal information in China?](/artifacts/apac/china-privacy-law/faq/what-should-an-app-collect-as-necessary-personal-information.md): Match the app's basic function to China's 2021 rules and collect no more than the listed necessary personal information. Users must retain the basic function if they decline non-necessary data.
27. [When can a company use the China standard contract route?](/artifacts/apac/china-privacy-law/faq/when-can-a-company-use-the-china-standard-contract-route.md): Use China's standard contract route only after applying the 2024 exemptions and confirming that no CAC security assessment is required. See current thresholds, filing steps, and change triggers.
28. [When does a China PIPL security assessment apply?](/artifacts/apac/china-privacy-law/faq/when-does-a-china-pipl-security-assessment-apply.md): A CAC data export security assessment applies to CIIO exports, important data, and specified high-volume personal-information exports after the 2024 exemptions are applied.

## Key dates for China Privacy Law

*China Timeline*

Distinguish adoption, commencement, filing, validity, renewal, and reassessment dates under the binding PIPL, app rules, and export measures. For current route decisions, the binding 22 March 2024 cross-border provisions override inconsistent parts of the 2022 assessment and 2023 standard-contract measures; Sorena's reading order and evidence suggestions are explanatory, not additional legal requirements.

*Next step*

## Prepare the PIPL and data export evidence file

Sorena AI turns China PIPL official requirements into scoped decisions, evidence records, owner assignments, and change-trigger reviews.

- Start with territorial scope, the personal information processor role, the processing purpose and basis, the affected people, and the complete data flow.
- Research Copilot keeps the official citation, decision owner, evidence record, and approval history connected.
- SSOT preserves notices, consent states, PIPIAs, vendor terms, rights records, incident decisions, transfer routes and their change history.

- [Open Research Copilot](/solutions/research-copilot.md): Map processing maps, separate consent, sensitive PI, entrusted processing, PIPIA, SCC filings, security assessment, and rights records to official citations, owners, and review checkpoints.
- [Open SSOT](/solutions/ssot.md): Keep official citations, decisions, approvals, and evidence records connected to governed product and compliance files.
- [Review unresolved triggers](/contact.md): Check unresolved scope, role, sensitive-information, PIPIA, app-minimization, incident or overseas-transfer questions before processing begins.

## Compliance Timeline

| Date | Event | Category | Reference |
| --- | --- | --- | --- |
| 2021-03-12 | App necessary personal information provisions issued | App privacy | [Source](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) |
| 2021-05-01 | App necessary personal information provisions take effect | App privacy | [Source](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) |
| 2021-08-20 | PIPL adopted | Law | [Source](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) |
| 2021-11-01 | PIPL takes effect | Law | [Source](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) |
| 2022-05-19 | Data export security assessment measures approved | Data export | [Source](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) |
| 2022-06-14 | Revised mobile app information-service provisions published | App privacy | [Source](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io) |
| 2022-08-01 | Revised mobile app information-service provisions take effect | App privacy | [Source](https://www.cac.gov.cn/2022-06/14/c_1656821626455324.htm?ref=sorena.io) |
| 2022-09-01 | Data export security assessment measures take effect | Data export | [Source](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) |
| 2023-02-03 | Personal information export standard contract measures approved | Standard contract | [Source](https://www.cac.gov.cn/2023-02/24/c_1678884830036813.htm?ref=sorena.io) |
| 2023-06-01 | Personal information export standard contract measures take effect | Standard contract | [Source](https://www.cac.gov.cn/2023-02/24/c_1678884830036813.htm?ref=sorena.io) |
| 2023-11-28 | Cross-border data flow provisions approved | Data export | [Source](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) |
| 2024-03-22 | Current cross-border data flow provisions take effect | Data export | [Source](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) |

**Event details:**

- **2021-03-12 - App necessary personal information provisions issued**: The notice issuing the common mobile app necessary personal information provisions was signed on 12 March 2021.
- **2021-05-01 - App necessary personal information provisions take effect**: The provisions on necessary personal information scope for common mobile apps took effect on 1 May 2021.
- **2021-08-20 - PIPL adopted**: The PRC Personal Information Protection Law was adopted on 20 August 2021.
- **2021-11-01 - PIPL takes effect**: The PRC Personal Information Protection Law took effect on 1 November 2021.
- **2022-05-19 - Data export security assessment measures approved**: The Measures for Security Assessment of Data Export were approved on 19 May 2022 before taking effect on 1 September 2022.
- **2022-06-14 - Revised mobile app information-service provisions published**: The revised Mobile Internet Application Information Service Management Provisions were published on 14 June 2022, replacing the 2016 provisions when they later took effect.
- **2022-08-01 - Revised mobile app information-service provisions take effect**: The revised provisions took effect on 1 August 2022 and simultaneously repealed the mobile app information-service provisions published on 28 June 2016.
- **2022-09-01 - Data export security assessment measures take effect**: The 2022 assessment measures took effect. Use their filing and review procedure together with the 2024 provisions, which now control exemptions, thresholds and the three-year validity period.
- **2023-02-03 - Personal information export standard contract measures approved**: The standard contract measures for personal information export were approved on 3 February 2023 before taking effect on 1 June 2023.
- **2023-06-01 - Personal information export standard contract measures take effect**: The standard-contract measures took effect. Use their contract, PIPIA and filing procedure together with the 2024 provisions, which now control exemptions and volume bands.
- **2023-11-28 - Cross-border data flow provisions approved**: The cross-border data flow provisions were approved on 28 November 2023 and later published/effective on 22 March 2024.
- **2024-03-22 - Current cross-border data flow provisions take effect**: The provisions took effect on publication. They add exemptions and current thresholds, extend assessment validity to three years, and control where they conflict with the 2022 assessment or 2023 standard-contract measures.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-privacy-law.md
