FAQChina

China Privacy Law FAQ

Use this FAQ to route common questions under China's Personal Information Protection Law, including sensitive information, separate consent, vendors, impact assessments, apps, and cross-border transfers.

Start with the scope and processing-basis decision, then apply the activity-specific rule and keep evidence that connects the facts to the conclusion.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 24, 2026
FAQ modules
8

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 24, 2026
Overview

applies to personal-information processing in China and to specified processing outside China involving people in China. For each activity, identify the responsible personal information processor, Article 13 basis, minimum necessary information, notice, consent or separate-consent requirement, retention, security, individual-rights process, trigger, and any overseas-provision route.

Browse sub-FAQs

Choose the question set you need

These focused FAQ modules break this artifact into narrower answer sets so teams can move straight to the right source-backed guidance.

Browse all FAQ items17
Focused FAQ modules
8
Showing 8 of 8
FAQ module

How should vendor contracts handle entrusted processing under PIPL?

A PIPL entrusted-processing contract must define the purpose, duration, method, personal-information categories, safeguards, and both parties' duties. See the required terms and supporting records.

2 items
FAQ module

Is PIPL the same as GDPR?

No. China's PIPL and the EU GDPR overlap on core privacy controls, but differ in territorial scope, legal bases, roles, sensitive data, impact assessments, and transfer routes.

3 items
FAQ module

What counts as sensitive personal information in China?

PIPL uses a harm-based test for sensitive personal information and lists examples such as biometrics, health, financial accounts, location traces, and all personal information of children under 14.

2 items
FAQ module

What is separate consent under PIPL?

Separate consent under China's PIPL is a distinct consent for a specified processing activity. See when it applies, what notice must come first, and what evidence to keep.

2 items
FAQ module

What records should we keep for a PIPL impact assessment?

A PIPL impact-assessment file should preserve the Article 55 trigger, processing facts, Article 56 analysis, safeguards, decision, and processing record for at least three years.

2 items
FAQ module

What should an app collect as necessary personal information in China?

Match the app's basic function to China's 2021 rules and collect no more than the listed necessary personal information. Users must retain the basic function if they decline non-necessary data.

2 items
FAQ module

When can a company use the China standard contract route?

Use China's standard contract route only after applying the 2024 exemptions and confirming that no CAC security assessment is required. See current thresholds, filing steps, and change triggers.

2 items
FAQ module

When does a China PIPL security assessment apply?

A CAC data export security assessment applies to CIIO exports, important data, and specified high-volume personal-information exports after the 2024 exemptions are applied.

2 items
Question 1

Scope, basis, and higher-risk processing

is not the same as the GDPR. The laws share several privacy principles, but their territorial tests, role terminology, processing bases, sensitive-information rules, impact-assessment triggers, and transfer systems differ. Reuse factual inventories and controls where they fit, but make a separate legal conclusion under each law.

does not make consent the only processing basis. Article 13 also covers defined contract, human-resources, legal-duty, emergency, public-interest reporting or supervision, lawfully public information, and other statutory circumstances. Where processing relies on consent, it must be voluntary and explicit and based on sufficient knowledge; withdrawal must be convenient.

Does apply to a company outside China?

Yes, when the company processes personal information outside China to offer products or services to people in China, to analyze or assess their behavior, or in another circumstance specified by law or administrative regulation. A covered overseas personal information processor must also establish a dedicated institution or appoint a representative in China and file the institution's or representative's details with the responsible authority. Mere access to a website from China is not itself one of the two express activity tests; document the intended market, affected people, and processing purpose.

Is the same as GDPR?

No. and GDPR share privacy principles and many operational controls, but their territorial tests, legal roles, processing bases, sensitive-data categories, impact-assessment triggers, and international-transfer mechanisms differ. Run both scope tests and do not substitute a GDPR lawful basis, DPIA, or EU standard contractual clause for the corresponding PIPL analysis.

What counts as sensitive personal information in China?

Use 's harm test: information is sensitive when leakage or illegal use could readily harm a natural person's dignity or endanger personal or property safety. PIPL examples include biometric identification, religious belief, specific identity, medical and health, financial account, and location-tracking information. All personal information of a child under 14 is sensitive.

What is separate consent under ?

Separate consent is a distinct consent for a specified activity, obtained after the person receives the required information. requires it for provision to another personal information processor, public disclosure, specified uses of public-place images or identity information, sensitive-personal-information processing, and overseas provision. The law requires the result but does not prescribe a particular interface.

  • Sensitive personal information uses a harm-based test. Statutory examples include biometric identification, religious belief, specific identity, medical and health, financial account, and location-tracking information.
  • All personal information of children under 14 is sensitive. Obtain a parent or other guardian's consent and adopt dedicated processing rules.
  • Sensitive processing requires a specific purpose, sufficient necessity, strict safeguards, an additional necessity-and-impact notice, separate consent, and a prior .
  • Separate consent also applies to provision to another processor, public disclosure, specified public-place image or identity uses, and overseas provision. does not prescribe a particular button or screen.
Question 2

Vendors, impact assessments, and app collection

For entrusted processing, Article 21 requires an agreement covering the purpose, duration, method, personal-information categories, protective measures, and both parties' rights and obligations. The personal information processor must supervise the entrusted party. The entrusted party must stay within the agreement, return or delete the information when the arrangement ends, obtain the personal information processor's consent before sub-entrustment, take necessary security measures, and assist with duties.

Complete a before entrusted processing and every other Article 55 activity. The report must assess legality, legitimacy, necessity, effects on individuals, security risks, and whether safeguards are lawful, effective, and proportionate. Keep the report and processing record for at least three years; does not prescribe a single form or internal approval workflow.

For an app, match each basic function to the 2021 category table and collect no more than the listed necessary personal information. A user who refuses non-necessary information must retain the basic function. Apply 's basis, notice, minimization, sensitive-information, child, security, rights, and duties separately.

How should vendor contracts handle entrusted processing?

State the purpose, duration, processing method, personal-information categories, protective measures, and both parties' rights and obligations. Limit the entrusted party to that scope, require return or deletion when the arrangement ends, prohibit sub-entrustment without consent, specify security and assistance duties, and preserve supervision evidence. Complete a before entrustment.

What records should we keep for a impact assessment?

Keep the Article 55 trigger, processing map, Article 13 basis, people and information involved, recipients and locations, necessity analysis, effects on individuals, security risks, safeguards, evidence of effectiveness, decision, conditions, processing record, and reassessment triggers. Keep the report and processing record for at least three years.

What should an app collect as necessary personal information?

Collect no more than the consumer-side information without which the app's stated basic function cannot operate, using the matching scope in the 2021 rules. Do not treat the list as a requirement to collect every field. Keep the basic function available when the user refuses information outside that scope, then apply all separate duties.

What does require after a personal information incident?

When personal information has been or may have been leaked, altered, or lost, the personal information processor must take remedial measures immediately and notify the responsible department and affected individuals. The notice must cover the information categories, reason, possible harm, remedial measures, steps individuals can take, and processor contact details. Individual notice may be omitted only when the processor's measures can effectively prevent harm; authority notice still applies, and the authority may require individual notice. states no fixed 24-, 48-, or 72-hour deadline.

What controls apply to automated decision-making under ?

Every automated decision using personal information must be transparent and produce fair and impartial results, without unreasonable differential treatment in transaction terms such as price. Information pushes and commercial marketing must also provide either a non-personalized option or a convenient refusal method. If a solely automated decision has a major effect on a person's rights or interests, the person may request an explanation and refuse that solely automated decision. Complete a before the processing starts.

  • Vendor file: role analysis, Article 21 terms, due diligence, sub-entrustment record, supervision, incident and rights support, exit evidence, and .
  • file: trigger, actual data flow, basis, risks, effects, safeguards, outcome, processing record, and reassessment triggers.
  • App file: category decision, function-to-field map, SDK and permission map, refusal tests, retention, overlay, and change record.
Question 3

Cross-border route decisions

Apply the 2024 Provisions on Promoting and Regulating Cross-border Data Flow before using the older route thresholds. They control where inconsistent with the 2022 security-assessment measures or 2023 standard-contract measures. Test the current exemptions first, then CIIO and important-data status, then the current-year counts for other and sensitive personal information.

A standard contract or certification applies to specified mid-range exports by a non-CIIO. A CAC security assessment applies to CIIO exports of personal information or important data and to non-CIIO exports of important data or personal information at the higher thresholds. Personal-information exports can still require notice, separate consent, a , and safeguards even when exempt from all three transfer mechanisms.

When can a company use the China standard contract route?

After applying the 2024 exemptions, a non-CIIO may use the standard contract for the regulated band that does not require a security assessment: personal information of at least 100,000 but fewer than 1 million individuals, excluding sensitive personal information, or sensitive personal information of fewer than 10,000 individuals, counted from January 1. Certification is an alternative in that band.

When does a China data export security assessment apply?

After the 2024 exemptions, it applies to a CIIO exporting personal information or important data and to a non-CIIO exporting important data, personal information of at least 1 million individuals excluding sensitive personal information, or sensitive personal information of at least 10,000 individuals, counted from January 1 of the current year.

  • Standard contract or certification: at least 100,000 but fewer than 1 million individuals' personal information, excluding sensitive personal information, or fewer than 10,000 individuals' sensitive personal information, counted from January 1, after exemptions.
  • Security assessment: CIIO exports of personal information or important data; non-CIIO exports of important data; at least 1 million individuals' personal information excluding sensitive personal information; or at least 10,000 individuals' sensitive personal information, after exemptions.
  • Security-assessment result: valid for three years. If no reapplication trigger occurs, an exporter can seek a three-year extension through the provincial CAC within 60 working days before expiry.
  • Standard-contract process: complete the export , use the CAC form without conflicting additions, wait until it takes effect, and file the contract and PIPIA report with the provincial CAC within 10 working days.
Primary sources

References and citations

cac.gov.cn
Referenced sections
  • Articles 5-14 govern the risk self-assessment, application materials, review process and timing, and reapplication triggers, subject to the 2024 provisions where inconsistent.
cac.gov.cn
Referenced sections
  • Articles 38-40 and 55 establish the PIPL transfer mechanisms, overseas-recipient safeguards, notice, separate consent, localization and assessment conditions, and prior PIPIA.
Related guides

Explore more topics

App minimum necessary personal information by category
App category mapping page for common mobile app necessary personal information scope, using only categories supported by the official source.
China app personal information minimization
How to map app category, basic functions, and necessary personal information under China mobile app personal-information rules.
China data export security assessment workflow
Workflow for screening data export security assessment triggers, materials, owners, and evidence records.
China personal information cross-border transfer routes
Compare China's current data-export exemptions, CAC security assessment, standard contract, and personal information protection certification routes.
China personal information standard contract filing workflow
Workflow for the PIPL standard contract route, assessment, filing package, and cited evidence.
China PIPL compliance checklist
China PIPL compliance checklist covering scope, processing bases, notices, sensitive information, rights, vendors, impact assessments, incidents, and exports.
China PIPL deadlines and compliance calendar
Calendar China PIPL effective dates, recurring audits, privacy-officer reporting, impact-assessment retention, and data export filing and renewal deadlines.
China PIPL penalties and enforcement exposure
Understand PIPL corrective orders, serious-violation fines, responsible-person exposure, civil claims, public-interest actions, and data export enforcement.
China PIPL privacy notice and consent checklist
China PIPL checklist for privacy notices, valid consent, separate consent, sensitive information, children under 14, withdrawal, and rights requests.
China PIPL requirements
China PIPL requirements from scope and processing basis through notices, rights, security, impact assessments, incidents, vendors, and data exports.
China PIPL vs CCPA/CPRA: Requirements Compared
Compare PIPL and CCPA/CPRA scope, consent and opt-out rules, rights, assessments, data exports, breach duties, and penalties.
China PIPL vs EU GDPR: Requirements Compared
Compare PIPL and GDPR scope, roles, legal bases, rights, impact assessments, breach deadlines, international transfers, and penalties.
China PIPL vs Singapore PDPA: Requirements Compared
Compare PIPL and Singapore PDPA scope, roles, consent alternatives, rights, breach duties, overseas transfers, and penalties.
PIPL automated decision-making and personalized recommendations
PIPL checks for automated decisions, personalized recommendations, marketing, differential treatment, explanations, refusal rights, and impact assessments.
PIPL breach response and notification
PIPL incident workflow for immediate remediation, authority and individual notices, the narrow individual-notice exception, vendor coordination, and evidence.
PIPL cross-border transfer route selector
Step-by-step selector for China's data-export exemptions, CAC security assessment, standard contract, and personal information protection certification.
PIPL entrusted processing and vendor contracts
How to document entrusted processing, vendor responsibilities, contract controls, and evidence under PIPL.
PIPL impact assessment template
Template fields for a China personal information protection impact assessment and export/entrusted-processing evidence.
Sensitive personal information and separate consent under PIPL
How to identify sensitive PI triggers, separate consent, minors, additional safeguards, and evidence records.