Use this FAQ to route common questions under China's Personal Information Protection Law, including sensitive information, separate consent, vendors, impact assessments, apps, and cross-border transfers.
Start with the scope and processing-basis decision, then apply the activity-specific rule and keep evidence that connects the facts to the conclusion.
applies to personal-information processing in China and to specified processing outside China involving people in China. For each activity, identify the responsible personal information processor, Article 13 basis, minimum necessary information, notice, consent or separate-consent requirement, retention, security, individual-rights process, trigger, and any overseas-provision route.
Browse sub-FAQs
Choose the question set you need
These focused FAQ modules break this artifact into narrower answer sets so teams can move straight to the right source-backed guidance.
is not the same as the GDPR. The laws share several privacy principles, but their territorial tests, role terminology, processing bases, sensitive-information rules, impact-assessment triggers, and transfer systems differ. Reuse factual inventories and controls where they fit, but make a separate legal conclusion under each law.
does not make consent the only processing basis. Article 13 also covers defined contract, human-resources, legal-duty, emergency, public-interest reporting or supervision, lawfully public information, and other statutory circumstances. Where processing relies on consent, it must be voluntary and explicit and based on sufficient knowledge; withdrawal must be convenient.
Does apply to a company outside China?
Yes, when the company processes personal information outside China to offer products or services to people in China, to analyze or assess their behavior, or in another circumstance specified by law or administrative regulation. A covered overseas personal information processor must also establish a dedicated institution or appoint a representative in China and file the institution's or representative's details with the responsible authority. Mere access to a website from China is not itself one of the two express activity tests; document the intended market, affected people, and processing purpose.
Is the same as GDPR?
No. and GDPR share privacy principles and many operational controls, but their territorial tests, legal roles, processing bases, sensitive-data categories, impact-assessment triggers, and international-transfer mechanisms differ. Run both scope tests and do not substitute a GDPR lawful basis, DPIA, or EU standard contractual clause for the corresponding PIPL analysis.
What counts as sensitive personal information in China?
Use 's harm test: information is sensitive when leakage or illegal use could readily harm a natural person's dignity or endanger personal or property safety. PIPL examples include biometric identification, religious belief, specific identity, medical and health, financial account, and location-tracking information. All personal information of a child under 14 is sensitive.
What is separate consent under ?
Separate consent is a distinct consent for a specified activity, obtained after the person receives the required information. requires it for provision to another personal information processor, public disclosure, specified uses of public-place images or identity information, sensitive-personal-information processing, and overseas provision. The law requires the result but does not prescribe a particular interface.
Sensitive personal information uses a harm-based test. Statutory examples include biometric identification, religious belief, specific identity, medical and health, financial account, and location-tracking information.
All personal information of children under 14 is sensitive. Obtain a parent or other guardian's consent and adopt dedicated processing rules.
Sensitive processing requires a specific purpose, sufficient necessity, strict safeguards, an additional necessity-and-impact notice, separate consent, and a prior .
Separate consent also applies to provision to another processor, public disclosure, specified public-place image or identity uses, and overseas provision. does not prescribe a particular button or screen.
For entrusted processing, Article 21 requires an agreement covering the purpose, duration, method, personal-information categories, protective measures, and both parties' rights and obligations. The personal information processor must supervise the entrusted party. The entrusted party must stay within the agreement, return or delete the information when the arrangement ends, obtain the personal information processor's consent before sub-entrustment, take necessary security measures, and assist with duties.
Complete a before entrusted processing and every other Article 55 activity. The report must assess legality, legitimacy, necessity, effects on individuals, security risks, and whether safeguards are lawful, effective, and proportionate. Keep the report and processing record for at least three years; does not prescribe a single form or internal approval workflow.
For an app, match each basic function to the 2021 category table and collect no more than the listed necessary personal information. A user who refuses non-necessary information must retain the basic function. Apply 's basis, notice, minimization, sensitive-information, child, security, rights, and duties separately.
How should vendor contracts handle entrusted processing?
State the purpose, duration, processing method, personal-information categories, protective measures, and both parties' rights and obligations. Limit the entrusted party to that scope, require return or deletion when the arrangement ends, prohibit sub-entrustment without consent, specify security and assistance duties, and preserve supervision evidence. Complete a before entrustment.
What records should we keep for a impact assessment?
Keep the Article 55 trigger, processing map, Article 13 basis, people and information involved, recipients and locations, necessity analysis, effects on individuals, security risks, safeguards, evidence of effectiveness, decision, conditions, processing record, and reassessment triggers. Keep the report and processing record for at least three years.
What should an app collect as necessary personal information?
Collect no more than the consumer-side information without which the app's stated basic function cannot operate, using the matching scope in the 2021 rules. Do not treat the list as a requirement to collect every field. Keep the basic function available when the user refuses information outside that scope, then apply all separate duties.
What does require after a personal information incident?
When personal information has been or may have been leaked, altered, or lost, the personal information processor must take remedial measures immediately and notify the responsible department and affected individuals. The notice must cover the information categories, reason, possible harm, remedial measures, steps individuals can take, and processor contact details. Individual notice may be omitted only when the processor's measures can effectively prevent harm; authority notice still applies, and the authority may require individual notice. states no fixed 24-, 48-, or 72-hour deadline.
What controls apply to automated decision-making under ?
Every automated decision using personal information must be transparent and produce fair and impartial results, without unreasonable differential treatment in transaction terms such as price. Information pushes and commercial marketing must also provide either a non-personalized option or a convenient refusal method. If a solely automated decision has a major effect on a person's rights or interests, the person may request an explanation and refuse that solely automated decision. Complete a before the processing starts.
Vendor file: role analysis, Article 21 terms, due diligence, sub-entrustment record, supervision, incident and rights support, exit evidence, and .
file: trigger, actual data flow, basis, risks, effects, safeguards, outcome, processing record, and reassessment triggers.
App file: category decision, function-to-field map, SDK and permission map, refusal tests, retention, overlay, and change record.
Apply the 2024 Provisions on Promoting and Regulating Cross-border Data Flow before using the older route thresholds. They control where inconsistent with the 2022 security-assessment measures or 2023 standard-contract measures. Test the current exemptions first, then CIIO and important-data status, then the current-year counts for other and sensitive personal information.
A standard contract or certification applies to specified mid-range exports by a non-CIIO. A CAC security assessment applies to CIIO exports of personal information or important data and to non-CIIO exports of important data or personal information at the higher thresholds. Personal-information exports can still require notice, separate consent, a , and safeguards even when exempt from all three transfer mechanisms.
When can a company use the China standard contract route?
After applying the 2024 exemptions, a non-CIIO may use the standard contract for the regulated band that does not require a security assessment: personal information of at least 100,000 but fewer than 1 million individuals, excluding sensitive personal information, or sensitive personal information of fewer than 10,000 individuals, counted from January 1. Certification is an alternative in that band.
When does a China data export security assessment apply?
After the 2024 exemptions, it applies to a CIIO exporting personal information or important data and to a non-CIIO exporting important data, personal information of at least 1 million individuals excluding sensitive personal information, or sensitive personal information of at least 10,000 individuals, counted from January 1 of the current year.
Standard contract or certification: at least 100,000 but fewer than 1 million individuals' personal information, excluding sensitive personal information, or fewer than 10,000 individuals' sensitive personal information, counted from January 1, after exemptions.
Security assessment: CIIO exports of personal information or important data; non-CIIO exports of important data; at least 1 million individuals' personal information excluding sensitive personal information; or at least 10,000 individuals' sensitive personal information, after exemptions.
Security-assessment result: valid for three years. If no reapplication trigger occurs, an exporter can seek a three-year extension through the provincial CAC within 60 working days before expiry.
Standard-contract process: complete the export , use the CAC form without conflicting additions, wait until it takes effect, and file the contract and PIPIA report with the provincial CAC within 10 working days.
Articles 5-14 govern the risk self-assessment, application materials, review process and timing, and reapplication triggers, subject to the 2024 provisions where inconsistent.
Official source for covered apps, the consumer-side basic-function test, 39 category scopes, and the rule against denying the basic function for refusal of non-necessary information.
Articles 38-40 and 55 establish the PIPL transfer mechanisms, overseas-recipient safeguards, notice, separate consent, localization and assessment conditions, and prior PIPIA.
Current source for exemptions, route thresholds, three-year assessment validity and extension, and priority over inconsistent older measures; effective 22 March 2024.