China Privacy Law PIPL breach response and notification
PIPL incident workflow for immediate remediation, authority and individual notices, the narrow individual-notice exception, vendor coordination, and evidence.
When personal information has been or may have been leaked, altered, or lost, take remedial measures immediately and notify the responsible authority and individuals. PIPL sets no fixed hour-based deadline.
Trigger the Article 57 workflow when personal information has been or may have been leaked, altered, or lost. The must take remedial measures immediately and notify the department responsible for personal information protection and affected individuals. PIPL does not specify a 24-, 48-, or 72-hour deadline, so do not import a foreign deadline into the PIPL decision.
1
Section 1
Contain and establish the facts
Start remedial action before every fact is known. Stop continuing disclosure or alteration, preserve relevant logs and systems, secure affected accounts or interfaces, and determine whether the event involves personal information and one of Article 57's states: actual or possible leakage, alteration, or loss. The trigger is broader than a confirmed confidentiality breach because possible leakage, alteration, and loss are expressly included.
The remains responsible for the PIPL response. An entrusted processor must protect the information and assist the processor with PIPL duties, so the incident procedure and contract should state who escalates, preserves evidence, investigates, and supplies notice facts.
Incident lead: record discovery time, source, affected systems, status, containment steps, and decision owners.
Privacy lead: identify the information categories, affected people, sensitive-information or child-data status, processing purpose, jurisdictions, and possible harm.
Security lead: establish cause, access or disclosure path, duration, recipients, whether data was copied or changed, and whether containment is effective.
Vendor lead: obtain prompt facts and remedial evidence from entrusted processors and overseas recipients; preserve contractual and technical escalation records.
Legal owner: check other applicable Chinese sectoral, cybersecurity, data-security, contractual, and foreign notification rules separately. Article 57 is not necessarily the only incident rule.
Article 57 says the notice must describe the categories of information involved, the reason for the actual or possible leakage, alteration, or loss, the possible harm, the processor's remedial measures, steps individuals can take to reduce harm, and the processor's contact details. Use confirmed facts, identify uncertainty, and correct material information as the investigation develops.
The statute permits omission of notice to individuals only when the processor's measures can effectively prevent harm from the event. This exception does not remove notice to the responsible authority, and the authority may still require individual notice if it considers harm possible. A low-risk label by itself does not meet the statutory test; retain evidence showing how the measures effectively avoid harm.
Authority-notice record: recipient authority, submission route, submitted content, time, confirmation, follow-up requests, and updates.
Individual-notice record: audience, channel, languages, versions, send time, delivery status, support path, and measures individuals can take.
Exception record: the specific measures already operating, evidence that they effectively avoid harm, decision owner, time of decision, and continued monitoring.
Do not delay immediate remediation while debating notice wording. Do not state that PIPL itself supplies a fixed reporting clock or a numeric harm threshold.
Keep a decision log that links changing facts to containment, notification, individual support, and recovery. Preserve evidence needed to show what happened and why each action was taken without retaining exposed personal information longer than necessary.
After containment, verify that remedial measures work, address individual requests and complaints, update risk and vendor records, and correct the weakness that caused the event. Article 51 requires an incident plan; use the findings to update and test it.
Preserve the incident chronology, affected-data analysis, system and vendor evidence, decisions, approvals, notice versions, delivery records, regulator communications, and remediation tests.
Track later discoveries that change the affected population, data categories, cause, possible harm, or effectiveness of the individual-notice exception.
Record follow-up access, correction, deletion, explanation, and complaint requests through the normal PIPL rights process.
If the event involves an overseas transfer, also assess the transfer instrument, recipient duties, and any data-export incident reporting requirement that applies to the route.
Articles 44-51, 57, and 64 support rights handling, security remediation, incident records, and possible regulatory interviews or required compliance audits.
Article 11 requires remedial measures and timely reports to the provincial-level CAC and other relevant authorities for an actual or possible data-security incident involving exported data.