---
title: "China Privacy Law FAQ"
canonical_url: "https://www.sorena.io/artifacts/apac/china-privacy-law/faq"
source_url: "https://www.sorena.io/artifacts/apac/china-privacy-law/faq"
author: "Sorena AI"
description: "Practical answers on China's PIPL: scope, legal bases, sensitive information, separate consent, vendors, PIPIA records, app minimization, and export routes."
published_at: "2026-07-05"
updated_at: "2026-07-24"
keywords:
  - "China PIPL"
  - "Personal Information Protection Law"
  - "Data export"
  - "Standard contract"
  - "App privacy"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# China Privacy Law FAQ

Practical answers on China's PIPL: scope, legal bases, sensitive information, separate consent, vendors, PIPIA records, app minimization, and export routes.

*FAQ* *China*

## China Privacy Law FAQ

Use this FAQ to route common questions under China's Personal Information Protection Law, including sensitive information, separate consent, vendors, impact assessments, apps, and cross-border transfers.

Start with the scope and processing-basis decision, then apply the activity-specific rule and keep evidence that connects the facts to the conclusion.

PIPL applies to personal-information processing in China and to specified processing outside China involving people in China. For each activity, identify the responsible personal information processor, Article 13 basis, minimum necessary information, notice, consent or separate-consent requirement, retention, security, individual-rights process, PIPIA trigger, and any overseas-provision route.

## Definitions

### Personal Information Protection Law of the People's Republic of China

**Term:** PIPL

PIPL is China's national law governing the processing of personal information. It applies to processing in China and to specified processing outside China involving people in China, including offering them products or services or analyzing or assessing their behavior.

**Why it matters here:** A PIPL scope conclusion is the starting point, not the final compliance decision. A covered processor must still identify the Article 13 basis, notices, consent requirements, individual rights, security measures, PIPIA triggers, and any cross-border route.

Sources:

- [PRC Personal Information Protection Law, Articles 3-13](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io)

### Personal information protection impact assessment

**Term:** PIPIA

A PIPIA is the prior assessment required for sensitive-personal-information processing, automated decision-making, entrusted processing, provision to another processor, public disclosure, provision outside China, and other processing with a major effect on personal rights and interests.

**Why it matters here:** The assessment must address legality, legitimacy, necessity, effects on individuals, security risks, and whether the safeguards are lawful, effective, and proportionate. Keep the report and processing record for at least three years.

Sources:

- [PRC Personal Information Protection Law, Articles 55-56](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io)

## Browse sub-FAQ modules

### [How should vendor contracts handle entrusted processing under PIPL?](/artifacts/apac/china-privacy-law/faq/how-should-vendor-contracts-handle-entrusted-processing.md)

A PIPL entrusted-processing contract must define the purpose, duration, method, personal-information categories, safeguards, and both parties' duties. See the required terms and supporting records.

- 2 items

### [Is PIPL the same as GDPR?](/artifacts/apac/china-privacy-law/faq/is-pipl-the-same-as-gdpr.md)

No. China's PIPL and the EU GDPR overlap on core privacy controls, but differ in territorial scope, legal bases, roles, sensitive data, impact assessments, and transfer routes.

- 3 items

### [What counts as sensitive personal information in China?](/artifacts/apac/china-privacy-law/faq/what-counts-as-sensitive-personal-information-in-china.md)

PIPL uses a harm-based test for sensitive personal information and lists examples such as biometrics, health, financial accounts, location traces, and all personal information of children under 14.

- 2 items

### [What is separate consent under PIPL?](/artifacts/apac/china-privacy-law/faq/what-is-separate-consent-under-pipl.md)

Separate consent under China's PIPL is a distinct consent for a specified processing activity. See when it applies, what notice must come first, and what evidence to keep.

- 2 items

### [What records should we keep for a PIPL impact assessment?](/artifacts/apac/china-privacy-law/faq/what-records-should-we-keep-for-a-pipl-impact-assessment.md)

A PIPL impact-assessment file should preserve the Article 55 trigger, processing facts, Article 56 analysis, safeguards, decision, and processing record for at least three years.

- 2 items

### [What should an app collect as necessary personal information in China?](/artifacts/apac/china-privacy-law/faq/what-should-an-app-collect-as-necessary-personal-information.md)

Match the app's basic function to China's 2021 rules and collect no more than the listed necessary personal information. Users must retain the basic function if they decline non-necessary data.

- 2 items

### [When can a company use the China standard contract route?](/artifacts/apac/china-privacy-law/faq/when-can-a-company-use-the-china-standard-contract-route.md)

Use China's standard contract route only after applying the 2024 exemptions and confirming that no CAC security assessment is required. See current thresholds, filing steps, and change triggers.

- 2 items

### [When does a China PIPL security assessment apply?](/artifacts/apac/china-privacy-law/faq/when-does-a-china-pipl-security-assessment-apply.md)

A CAC data export security assessment applies to CIIO exports, important data, and specified high-volume personal-information exports after the 2024 exemptions are applied.

- 2 items

Browse all indexed questions: [/artifacts/apac/china-privacy-law/faq/items](/artifacts/apac/china-privacy-law/faq/items.md)

## Scope, basis, and higher-risk processing

PIPL is not the same as the GDPR. The laws share several privacy principles, but their territorial tests, role terminology, processing bases, sensitive-information rules, impact-assessment triggers, and transfer systems differ. Reuse factual inventories and controls where they fit, but make a separate legal conclusion under each law.

PIPL does not make consent the only processing basis. Article 13 also covers defined contract, human-resources, legal-duty, emergency, public-interest reporting or supervision, lawfully public information, and other statutory circumstances. Where processing relies on consent, it must be voluntary and explicit and based on sufficient knowledge; withdrawal must be convenient.

- Sensitive personal information uses a harm-based test. Statutory examples include biometric identification, religious belief, specific identity, medical and health, financial account, and location-tracking information.
- All personal information of children under 14 is sensitive. Obtain a parent or other guardian's consent and adopt dedicated processing rules.
- Sensitive processing requires a specific purpose, sufficient necessity, strict safeguards, an additional necessity-and-impact notice, separate consent, and a prior PIPIA.
- Separate consent also applies to provision to another processor, public disclosure, specified public-place image or identity uses, and overseas provision. PIPL does not prescribe a particular button or screen.

### Does PIPL apply to a company outside China?

Yes, when the company processes personal information outside China to offer products or services to people in China, to analyze or assess their behavior, or in another circumstance specified by law or administrative regulation. A covered overseas personal information processor must also establish a dedicated institution or appoint a representative in China and file the institution's or representative's details with the responsible authority. Mere access to a website from China is not itself one of the two express activity tests; document the intended market, affected people, and processing purpose.

### Is PIPL the same as GDPR?

No. PIPL and GDPR share privacy principles and many operational controls, but their territorial tests, legal roles, processing bases, sensitive-data categories, impact-assessment triggers, and international-transfer mechanisms differ. Run both scope tests and do not substitute a GDPR lawful basis, DPIA, or EU standard contractual clause for the corresponding PIPL analysis.

### What counts as sensitive personal information in China?

Use PIPL's harm test: information is sensitive when leakage or illegal use could readily harm a natural person's dignity or endanger personal or property safety. PIPL examples include biometric identification, religious belief, specific identity, medical and health, financial account, and location-tracking information. All personal information of a child under 14 is sensitive.

### What is separate consent under PIPL?

Separate consent is a distinct consent for a specified activity, obtained after the person receives the required information. PIPL requires it for provision to another personal information processor, public disclosure, specified uses of public-place images or identity information, sensitive-personal-information processing, and overseas provision. The law requires the result but does not prescribe a particular interface.

Related resources:

- [Compare PIPL with GDPR](/artifacts/apac/china-privacy-law/faq/is-pipl-the-same-as-gdpr.md): Compare scope, roles, legal bases, sensitive information, impact assessments, and transfer routes.
- [Classify sensitive personal information](/artifacts/apac/china-privacy-law/faq/what-counts-as-sensitive-personal-information-in-china.md): Apply PIPL's harm test and identify the additional duties for sensitive information and children under 14.
- [Implement separate consent](/artifacts/apac/china-privacy-law/faq/what-is-separate-consent-under-pipl.md): Identify each statutory trigger, required notice, consent evidence, withdrawal path, and renewal condition.

Sources for this answer:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Articles 3, 5-17, 23, 25-31, 39, and 55-56 support the scope, processing-basis, consent, separate-consent, sensitive-information, child, and PIPIA answers.

## Vendors, impact assessments, and app collection

For entrusted processing, Article 21 requires an agreement covering the purpose, duration, method, personal-information categories, protective measures, and both parties' rights and obligations. The personal information processor must supervise the entrusted party. The entrusted party must stay within the agreement, return or delete the information when the arrangement ends, obtain the personal information processor's consent before sub-entrustment, take necessary security measures, and assist with PIPL duties.

Complete a PIPIA before entrusted processing and every other Article 55 activity. The report must assess legality, legitimacy, necessity, effects on individuals, security risks, and whether safeguards are lawful, effective, and proportionate. Keep the report and processing record for at least three years; PIPL does not prescribe a single form or internal approval workflow.

For an app, match each basic function to the 2021 category table and collect no more than the listed necessary personal information. A user who refuses non-necessary information must retain the basic function. Apply PIPL's basis, notice, minimization, sensitive-information, child, security, rights, and PIPIA duties separately.

- Vendor file: role analysis, Article 21 terms, due diligence, sub-entrustment record, supervision, incident and rights support, exit evidence, and PIPIA.
- PIPIA file: trigger, actual data flow, basis, risks, effects, safeguards, outcome, processing record, and reassessment triggers.
- App file: category decision, function-to-field map, SDK and permission map, refusal tests, retention, PIPL overlay, and change record.

### How should vendor contracts handle entrusted processing?

State the purpose, duration, processing method, personal-information categories, protective measures, and both parties' rights and obligations. Limit the entrusted party to that scope, require return or deletion when the arrangement ends, prohibit sub-entrustment without consent, specify security and assistance duties, and preserve supervision evidence. Complete a PIPIA before entrustment.

### What records should we keep for a PIPL impact assessment?

Keep the Article 55 trigger, processing map, Article 13 basis, people and information involved, recipients and locations, necessity analysis, effects on individuals, security risks, safeguards, evidence of effectiveness, decision, conditions, processing record, and reassessment triggers. Keep the PIPIA report and processing record for at least three years.

### What should an app collect as necessary personal information?

Collect no more than the consumer-side information without which the app's stated basic function cannot operate, using the matching scope in the 2021 rules. Do not treat the list as a requirement to collect every field. Keep the basic function available when the user refuses information outside that scope, then apply all separate PIPL duties.

### What does PIPL require after a personal information incident?

When personal information has been or may have been leaked, altered, or lost, the personal information processor must take remedial measures immediately and notify the responsible department and affected individuals. The notice must cover the information categories, reason, possible harm, remedial measures, steps individuals can take, and processor contact details. Individual notice may be omitted only when the processor's measures can effectively prevent harm; authority notice still applies, and the authority may require individual notice. PIPL states no fixed 24-, 48-, or 72-hour deadline.

### What controls apply to automated decision-making under PIPL?

Every automated decision using personal information must be transparent and produce fair and impartial results, without unreasonable differential treatment in transaction terms such as price. Information pushes and commercial marketing must also provide either a non-personalized option or a convenient refusal method. If a solely automated decision has a major effect on a person's rights or interests, the person may request an explanation and refuse that solely automated decision. Complete a PIPIA before the processing starts.

Related resources:

- [Draft entrusted-processing terms](/artifacts/apac/china-privacy-law/faq/how-should-vendor-contracts-handle-entrusted-processing.md): Distinguish vendor roles and build the contract, oversight, exit, and PIPIA evidence.
- [Build a PIPIA evidence file](/artifacts/apac/china-privacy-law/faq/what-records-should-we-keep-for-a-pipl-impact-assessment.md): Map each Article 56 conclusion to processing facts, risks, safeguards, decisions, and retained records.
- [Limit app collection by basic function](/artifacts/apac/china-privacy-law/faq/what-should-an-app-collect-as-necessary-personal-information.md): Use the 2021 category rules and test that refusal of non-necessary information does not block the basic function.

Sources for this answer:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Articles 20-23, 55-56, and 59 support vendor classification, entrusted-processing terms and duties, prior PIPIA, and minimum retention.
- [Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Official source for covered apps, the consumer-side basic-function test, 39 category scopes, and the rule against denying the basic function for refusal of non-necessary information.

## Cross-border route decisions

Apply the 2024 Provisions on Promoting and Regulating Cross-border Data Flow before using the older route thresholds. They control where inconsistent with the 2022 security-assessment measures or 2023 standard-contract measures. Test the current exemptions first, then CIIO and important-data status, then the current-year counts for other and sensitive personal information.

A standard contract or certification applies to specified mid-range exports by a non-CIIO. A CAC security assessment applies to CIIO exports of personal information or important data and to non-CIIO exports of important data or personal information at the higher thresholds. Personal-information exports can still require notice, separate consent, a PIPIA, and safeguards even when exempt from all three transfer mechanisms.

- Standard contract or certification: at least 100,000 but fewer than 1 million individuals' personal information, excluding sensitive personal information, or fewer than 10,000 individuals' sensitive personal information, counted from January 1, after exemptions.
- Security assessment: CIIO exports of personal information or important data; non-CIIO exports of important data; at least 1 million individuals' personal information excluding sensitive personal information; or at least 10,000 individuals' sensitive personal information, after exemptions.
- Security-assessment result: valid for three years. If no reapplication trigger occurs, an exporter can seek a three-year extension through the provincial CAC within 60 working days before expiry.
- Standard-contract process: complete the export PIPIA, use the CAC form without conflicting additions, wait until it takes effect, and file the contract and PIPIA report with the provincial CAC within 10 working days.

### When can a company use the China standard contract route?

After applying the 2024 exemptions, a non-CIIO may use the standard contract for the regulated band that does not require a security assessment: personal information of at least 100,000 but fewer than 1 million individuals, excluding sensitive personal information, or sensitive personal information of fewer than 10,000 individuals, counted from January 1. Certification is an alternative in that band.

### When does a China data export security assessment apply?

After the 2024 exemptions, it applies to a CIIO exporting personal information or important data and to a non-CIIO exporting important data, personal information of at least 1 million individuals excluding sensitive personal information, or sensitive personal information of at least 10,000 individuals, counted from January 1 of the current year.

Related resources:

- [Decide whether the standard contract route applies](/artifacts/apac/china-privacy-law/faq/when-can-a-company-use-the-china-standard-contract-route.md): Apply exemptions and thresholds, then complete the contract, PIPIA, effective-date, filing, and change steps.
- [Decide whether a CAC security assessment applies](/artifacts/apac/china-privacy-law/faq/when-does-a-china-pipl-security-assessment-apply.md): Check CIIO and important-data status, current-year counts, exemptions, self-assessment, application, validity, and reapplication.

Sources for this answer:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Articles 38-40 and 55 establish the PIPL transfer mechanisms, overseas-recipient safeguards, notice, separate consent, localization and assessment conditions, and prior PIPIA.
- [Measures for the Standard Contract for Personal Information Export](https://www.cac.gov.cn/2023-02/24/c_1678884830036813.htm?ref=sorena.io) - Articles 5-8 govern the export PIPIA, prescribed contract, effective-before-export rule, 10-working-day filing, and change process.
- [Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Articles 5-14 govern the risk self-assessment, application materials, review process and timing, and reapplication triggers, subject to the 2024 provisions where inconsistent.
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Current source for exemptions, route thresholds, three-year assessment validity and extension, and priority over inconsistent older measures; effective 22 March 2024.

*Operationalize the requirement*

*Placement: Before primary sources*

## Prepare the PIPL and data export evidence file

Sorena AI helps turn the China Privacy Law FAQ decision into owners, controls, and reviewer-ready records.

- [Map official sources to evidence](/solutions/research-copilot.md): Research Copilot connects the official citation, decision, owner, retained evidence, and change history.
- [Review the China route](/contact.md): Check the China Privacy Law scope decision and unresolved launch questions with Sorena.

## Primary sources

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Binding source for PIPL scope, principles, processing bases, notice and consent, individual rights, processor and entrusted-party duties, sensitive information, PIPIA, and cross-border provision.
- [Measures for the Standard Contract for Personal Information Export](https://www.cac.gov.cn/2023-02/24/c_1678884830036813.htm?ref=sorena.io) - Binding source for the prescribed standard contract, export PIPIA, effective-before-export rule, provincial filing, and change process.
- [Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Binding source for the export risk self-assessment, application materials, assessment scope and timing, legal instrument, and reapplication triggers, subject to the 2024 provisions where inconsistent.
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Current binding source for cross-border exemptions, thresholds, three-year security-assessment validity and extension, and priority over inconsistent older measures; effective 22 March 2024.
- [Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Official source for covered app forms, the consumer-side basic-function test, the no-refusal rule, and 39 category-specific necessary-information scopes; effective 1 May 2021.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-privacy-law/faq.md
