FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
17of17items
Across 8 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 24, 2026
How should vendor contracts handle entrusted processing under PIPL?

Classify the relationship before drafting

Article 21 applies when the vendor processes personal information within the customer's agreed instructions and scope. If both parties decide the purpose and method, Article 20's joint-processing rule may apply. If the vendor receives the information and determines its own purpose or method, Article 23's provision-to-another-processor rule may apply, including recipient notice and separate consent.

The contract label does not decide the legal role. Record who decides the purpose, method, categories, retention, recipients, and onward use for each processing activity.

  • Entrusted party: process only within the agreed purpose, method, and other contractual limits.
  • Personal information processor: supervise the entrusted party's processing rather than treating the signed contract as the end of oversight.
  • Joint processors: agree their respective rights and obligations, while preserving the individual's ability to exercise PIPL rights against either processor.
  • Another processor receiving personal information: give the Article 23 recipient notice and obtain separate consent before provision, unless a different legal rule controls.
Citations
PRC Personal Information Protection Law

Articles 20-23 distinguish joint processing, entrusted processing, and provision to another personal information processor, with different agreement, supervision, notice, and consent consequences.

How should vendor contracts handle entrusted processing under PIPL?

Required terms and useful operational clauses

Put every Article 21 item in the binding agreement: purpose, duration, method, personal-information categories, protective measures, and both parties' rights and obligations. State that the entrusted party may not exceed the agreed purpose or method, must return or delete the information without retaining it when the contract is ineffective, invalid, revoked, or terminated, and may not sub-entrust without the processor's consent.

Article 59 separately requires the entrusted party to take necessary security measures and assist the personal information processor with its PIPL duties. Translate that obligation into activity-specific clauses. Incident notice timing, rights-request support, access controls, audit evidence, deletion verification, and overseas-access restrictions should match the service and risk; PIPL does not prescribe one universal clause set for every vendor.

  • Scope schedule: systems, purposes, duration, methods, information categories, people concerned, access locations, retention, and approved recipients.
  • Security and assistance: organizational and technical safeguards, incident escalation, rights-request support, compliance evidence, and named contacts.
  • Sub-entrustment: prior-consent process, required flow-down terms, current sub-entrusted parties, and responsibility for monitoring the chain.
  • Exit: return-or-deletion instructions, confirmation evidence, backup treatment, and the narrow legal basis for any retention that cannot end immediately.
  • Oversight file: due diligence, contract approval, supervision results, remediation, and the prior Article 55 PIPIA. PIPL requires the PIPIA report and record of the assessed processing to be kept for at least three years.
Citations
PRC Personal Information Protection Law

Articles 21 and 59 establish the mandatory entrusted-processing terms, supervision, return-or-deletion, sub-entrustment, security, and assistance duties. Articles 55-56 require a prior PIPIA for entrustment and at least three years' retention.

Is PIPL the same as GDPR?

Scope, roles, and processing bases

Run the territorial tests independently. PIPL applies to processing in China and also to specified processing outside China involving people in China, including offering them products or services or analyzing or assessing their behavior. GDPR applies to processing in the context of an EU establishment and, for certain organizations outside the EU, to offering goods or services to people in the EU or monitoring their behavior there.

Map roles from the facts. PIPL defines a personal information processor by independent control over purpose and method and separately regulates joint processing, entrusted processing, and provision to another processor. GDPR uses controller, joint controller, and processor concepts. The labels often align operationally, but they are not interchangeable legal conclusions.

Both laws allow processing without consent in defined circumstances, but the lists and conditions differ. PIPL Article 13 includes consent, contract necessity, qualifying human-resources management, legal duties, emergencies, public-interest reporting or supervision, lawfully public information, and other statutory grounds. GDPR Article 6 uses consent, contract, legal obligation, vital interests, public task, and legitimate interests, subject to its conditions.

  • Outside-China PIPL processing can require a dedicated organization or representative in China under Article 53; GDPR Article 27 has its own representative rule and exceptions.
  • PIPL consent must be voluntary and explicit and based on sufficient knowledge. PIPL also requires separate consent for specified activities; GDPR does not use the same general statutory concept.
  • A GDPR legitimate-interests assessment does not create a PIPL basis. A PIPL Article 13 basis does not by itself establish a GDPR Article 6 basis.
  • Keep shared facts once, then record the applicable role, basis, notice, consent, rights, retention, and responsible entity separately for each law.
Citations
Is PIPL the same as GDPR?

Sensitive information, assessments, and transfers

PIPL and GDPR both impose added conditions on higher-risk processing, but the tests differ. PIPL permits sensitive personal information only for a specific purpose, with sufficient necessity and strict safeguards, and generally requires separate consent plus a prior PIPIA. GDPR Article 9 generally prohibits special-category processing unless an Article 9 exception applies; its categories and exceptions do not match PIPL's.

The assessment triggers also differ. PIPL Article 55 expressly includes sensitive personal information, automated decision-making, entrusted processing, provision to another processor, public disclosure, overseas provision, and other processing with a major effect on rights and interests. GDPR Article 35 requires a DPIA where processing is likely to result in a high risk and gives specific examples. Reuse the system and risk facts, but test both thresholds and required content.

Do not interchange transfer tools. PIPL Article 38 uses a CAC security assessment, certification, the CAC standard contract, or another recognized condition, with additional notice, separate-consent, and PIPIA duties for personal-information exports. GDPR Chapter V uses its own adequacy decisions, appropriate safeguards such as EU standard contractual clauses, and limited derogations.

  • Shared evidence: processing inventory, data flows, systems, vendors, recipients, countries, retention, security measures, and rights procedures.
  • Separate conclusions: territorial scope, legal role, processing basis, sensitive or special-category classification, notice, consent, assessment trigger, and responsible entity.
  • Separate transfer file: origin, destination, exporter and recipient, current threshold or exemption, transfer instrument, assessment, individual notice, and required filing or approval.
  • Change control: reopen both analyses when a purpose, method, category, recipient, country, volume, automated-decision use, or applicable rule changes.
Citations
Is PIPL the same as GDPR?

Rights, incidents, and enforcement also differ

Both laws provide access, correction, deletion, objection or refusal, and automated-decision protections, but their conditions and procedures are not identical. PIPL gives individuals rights to know and decide, restrict or refuse processing, access and copy, correct, and delete under stated conditions. GDPR provides its own access, rectification, erasure, restriction, portability, objection, and automated-decision rights, each with separate conditions and exceptions.

Incident rules also require separate clocks. Under PIPL Article 57, a processor must immediately take remedial measures and notify the responsible authorities and individuals when personal information is or may be leaked, altered, or lost; individual notice can be omitted if effective measures avoid harm, although an authority may still require it. Under GDPR Articles 33-34, a controller generally notifies the supervisory authority within 72 hours after becoming aware of a breach unless it is unlikely to risk people's rights and freedoms, and notifies affected people without undue delay when the breach is likely to create a high risk.

  • Request workflow: identify the law, right, requester, identity check, applicable exception, response deadline, search scope, decision, and response evidence.
  • Incident workflow: record awareness time, affected systems and people, data categories, likely consequences, remedial measures, risk conclusion, authority notice, individual notice, and the reason for any exception.
  • Enforcement: PIPL and GDPR use different infringement tests, authorities, remedies, and turnover measures. Do not convert one law's maximum percentage into the other's penalty analysis.
  • Reassessment: reopen both legal analyses when the role, purpose, processing method, information category, recipient, country, automated decision, or risk changes.
Citations
What counts as sensitive personal information in China?

Apply the harm test, not only the examples

Article 28's examples are representative categories, not a complete field dictionary. Classify the actual information and processing context by asking whether leakage or illegal use could readily cause either kind of statutory harm. A field that looks ordinary in isolation may become sensitive when combined with other data or used to infer health, identity, movements, finances, or another protected condition.

The category includes all personal information of a child under 14, even if the same field would not be sensitive for an adult. For example, a child's basic account identifier falls within the child-specific rule because of the person's age.

  • Biometric identification, religious belief, and specific identity are express statutory examples; record the exact information and how it is used.
  • Medical and health information and financial account information are express statutory examples; apply the harm test to the fields, inferences, and processing context.
  • Location-tracking information is an express statutory example; record what the information reveals, how long it is retained, and who can access it.
  • Other information can qualify when it meets the statutory harm test even if it does not fit one of the named examples.
Citations
What counts as sensitive personal information in China?

What changes when the information is sensitive

A processor may handle sensitive personal information only for a specific purpose, with sufficient necessity and strict protective measures. Before processing, give the general Article 17 notice plus the necessity of the sensitive processing and its effect on the individual's rights and interests, unless a PIPL notice exception applies.

Where consent is required, obtain separate consent. Article 13 says consent is not required when one of its listed non-consent circumstances applies, so record that conclusion instead of collecting consent by default. If a law or administrative regulation requires written consent for the particular processing, follow that rule. For a child under 14, obtain consent from a parent or other guardian and adopt dedicated personal-information processing rules. Complete a PIPIA before the processing and retain its report and processing record for at least three years.

  • Inventory: exact fields, inferred attributes, source, system, people concerned, recipients, access locations, and retention.
  • Classification: statutory category where applicable, contextual harm analysis, child-age rule, decision owner, and unresolved borderline facts.
  • Necessity and safeguards: specific purpose, why less intrusive information is insufficient, access restrictions, security measures, and shortest necessary retention.
  • Individual-facing evidence: general and additional notice versions, separate-consent record, withdrawal path, and parent-or-guardian consent where the person is under 14.
  • Assessment: Article 55 PIPIA, control implementation evidence, approval, and triggers for reassessment when the purpose, method, information, recipient, or risk changes.
Citations
PRC Personal Information Protection Law

Articles 28-31 establish the purpose, necessity, safeguard, notice, consent, and child-specific duties. Articles 55-56 require a prior PIPIA and at least three years' retention.

What is separate consent under PIPL?

When separate consent is required

The provisions listed below call for separate consent when consent is required. It is different from a general acceptance of a privacy notice and must relate to the specified activity. Article 13 says consent is not required when one of its listed non-consent circumstances applies, so document the exact Article 13 conclusion before designing the consent flow. The processor must still satisfy the applicable notice, necessity, security, and impact-assessment duties.

Where processing relies on consent, Article 14 requires a voluntary and explicit choice made with sufficient knowledge. If the purpose, processing method, or categories of personal information change, obtain consent again. Article 15 also requires a convenient way to withdraw consent. A contract necessity or other Article 13 circumstance should be assessed on its own conditions; it is not created by a separate-consent screen.

  • Providing personal information to another personal information processor: identify the recipient, contact details, purpose, method, and information categories before obtaining separate consent.
  • Public disclosure: obtain separate consent unless a specific legal rule permits the disclosure.
  • Public-place image or identity-recognition information: use it only to protect public security unless separate consent supports another purpose and the other legal conditions are met.
  • Sensitive personal information: establish a specific purpose and sufficient necessity, use strict protective measures, give the additional necessity-and-impact notice, and obtain separate consent. A law or administrative regulation may also require written consent.
  • Providing personal information outside China: identify the overseas recipient, its contact details, purpose, method, information categories, and the procedure for exercising PIPL rights before obtaining separate consent.
Citations
PRC Personal Information Protection Law

Articles 14-17 govern informed consent, renewed consent, withdrawal, and general notice. Articles 23, 25, 26, 29, and 39 identify the activities that require separate consent and the additional information that must be given.

What is separate consent under PIPL?

How to implement and document the choice

PIPL does not mandate a checkbox, modal, signature, or other specific interface. Use a design that makes the specified activity clear and captures an affirmative choice separate from unrelated permissions. Do not describe a bundled acceptance of terms as separate consent merely because the notice mentions the activity.

Keep enough evidence to reconstruct what the person saw and did. This is an operational record, not an official form prescribed by PIPL.

  • Decision record: statutory trigger, Article 13 basis, purpose, processing method, information categories, recipients, necessity analysis, and responsible owner.
  • Notice evidence: the exact notice version, language, required recipient or overseas-transfer details, and when it appeared in the user flow.
  • Choice evidence: account or device identifier where appropriate, affirmative action, timestamp, notice version, scope of consent, and later withdrawal or renewal.
  • Related controls: the Article 55 PIPIA where triggered, retention rule, security measures, rights-request path, and a change trigger for a new purpose, method, category, or recipient.
Citations
PRC Personal Information Protection Law

Articles 14 and 15 support the consent and withdrawal record; Articles 17, 23, 30, and 39 identify notice content; Article 55 identifies processing that requires a prior PIPIA.

What records should we keep for a PIPL impact assessment?

Start with the trigger and actual processing

Complete a PIPIA before processing sensitive personal information; using personal information for automated decision-making; entrusting processing; providing personal information to another processor; publicly disclosing it; providing it outside China; or carrying out another activity with a major effect on personal rights and interests.

Identify the system, business owner, processor role, people concerned, purpose, Article 13 basis, collection source, information categories, processing methods, recipients, locations, retention, deletion, rights handling, and security controls. The assessment should describe the intended operation, not only repeat a privacy notice or contract.

  • Scope record: assessment identifier, Article 55 trigger, systems and versions, owner, participating teams, decision date, and processing start date.
  • Data map: information fields and inferences, sensitive or child data, sources, people, volumes where relevant, recipients, entrusted parties, overseas locations, access paths, retention, and deletion.
  • Rule analysis: Article 13 basis, notices, consent or separate-consent requirement, necessity, minimization, individual rights, and any export-route dependency.
  • Change control: facts that require review, including a new purpose, method, information category, recipient, country, retention period, automated-decision use, or material risk.
Citations
What records should we keep for a PIPL impact assessment?

Record the Article 56 analysis and decision

Article 56 requires three conclusions: whether the purpose and method are lawful, legitimate, and necessary; the effect on personal rights and interests and the security risks; and whether the safeguards are lawful, effective, and proportionate to the risk. Show the facts, evidence, and reasoning behind each conclusion.

PIPL requires retention of the assessment report and processing record. It does not prescribe a universal template, risk matrix, named approver, mandatory report length, or retention rule for every supporting input. Use the organization's governance process, but label internal scoring, evidence attachments, sign-off fields, and any longer retention period as organizational controls rather than Article 56 requirements.

  • Legality, legitimacy, and necessity: source provisions, purpose, basis, less intrusive alternatives, minimum information, and shortest necessary retention.
  • Effects and risks: plausible misuse, leakage, unauthorized access, discrimination, loss of control, rights barriers, and severity and likelihood using the organization's defined method.
  • Safeguards: contractual, organizational, and technical measures; responsible owner; implementation status; test or review evidence; and why the measures match the risk.
  • Outcome: approved scope, conditions before launch, unresolved issues, risk acceptance under internal governance, reassessment triggers, and links to the processing record and implemented controls.
  • Retention: preserve the PIPIA report and processing record for at least three years. Sorena recommends keeping material inputs, approvals, and control evidence with that file so a reviewer can reconstruct the decision; a longer period may follow from another applicable rule or the processing lifecycle.
Citations
What should an app collect as necessary personal information in China?

Match the app to its basic function

Start with what the user is obtaining, not the app's marketing label. Match that basic function to the 2021 category and map each proposed field to the listed scope. If the app provides several distinct basic functions, document the category and necessary scope for each function rather than treating the broadest category as permission for the whole product.

The list sets the outer scope of information treated as necessary for each stated basic function. It does not require collection of every listed item when the app can deliver the function without it. It also does not make optional analytics, advertising, personalization, contacts, background permissions, or SDK events necessary merely because they support the business.

  • Map navigation: location, departure point, and destination are listed for the basic location-and-navigation function.
  • Online shopping and food delivery: the listed scope includes a registered mobile number, recipient name, address and contact number, and payment time, amount, and channel.
  • Instant messaging: the listed scope includes a registered mobile number plus the account and instant-messaging contact-account list.
  • Functions requiring no personal information: the rules list news browsing, online audio or video playback, short-video search and playback, browsers, input methods, photography or beautification, and several other categories as needing none for the stated basic function. Requiring account registration or a device permission before those basic functions would conflict with that category result unless another controlling rule applies.
  • Health, finance, transport, and other categories can include information that is sensitive under PIPL. The category table does not remove the separate sensitive-information duties.
Citations
What should an app collect as necessary personal information in China?

Build and test the collection map

For every field, device permission, SDK, and event, record the product function, collection timing, recipient, purpose, and whether the item is necessary for the basic function. If it is outside the category scope or the function works without it, keep it out of the mandatory flow and do not block the basic function when the user refuses.

Then apply PIPL. Identify the processing basis, give the required notice, keep collection within the minimum necessary range, use the shortest necessary retention, and address sensitive personal information, children under 14, security, individual rights, and PIPIA triggers.

  • Category decision: basic-function description, selected 2021 category, any multi-function split, and product owner.
  • Field map: field or event, collection source, user action, basic function, necessity rationale, recipient or SDK, retention, and deletion.
  • Refusal test: evidence that declining each non-necessary field or permission leaves the relevant basic function available.
  • PIPL overlay: basis, notice, consent, sensitive-information classification, child treatment, security controls, rights path, and PIPIA where triggered.
  • Change trigger: reassess when a function, SDK, permission, field, use, recipient, or collection timing changes.
Citations
When can a company use the China standard contract route?

Apply the routing tests in order

First decide whether the activity provides data outside China and whether that data contains personal information or important data. Then apply the 2024 exemptions. Next determine whether the exporter is a critical information infrastructure operator (CIIO), whether important data is involved, and how many individuals' non-sensitive and sensitive personal information has been exported since January 1.

A CIIO exporting personal information or important data must use the security-assessment route. A non-CIIO must also use that route for important data, personal information of at least 1 million individuals excluding sensitive personal information, or sensitive personal information of at least 10,000 individuals. For a non-CIIO, Article 8 places exports from 100,000 to under 1 million individuals excluding sensitive personal information, and exports involving any sensitive personal information below 10,000 individuals, in the standard-contract-or-certification band unless an exemption controls.

  • No personal information or important data: specified international-trade, cross-border transport, academic-cooperation, transnational-production, and marketing data can be exempt from all three CAC transfer mechanisms.
  • Overseas-origin information: personal information collected outside China, processed in China, and sent out again is exempt if no personal information or important data collected or generated in China is introduced during processing.
  • Necessary individual contract, qualifying cross-border HR management, or emergency: these exports can be exempt when every stated condition is met and no important data is included.
  • Low-volume non-sensitive export: a non-CIIO exporting personal information of fewer than 100,000 individuals since January 1 is exempt only for the count excluding sensitive personal information. Sensitive information requires its own route analysis.
  • Free-trade-zone rule: a qualifying exporter in a pilot free-trade zone may rely on the approved negative-list framework for data outside that list.
Citations
When can a company use the China standard contract route?

Complete the contract, assessment, and filing

Complete the export PIPIA before the transfer. It should examine the legality, legitimacy, and necessity of both parties' processing; the exported information's scale, scope, categories, and sensitivity; risks to individuals; the overseas recipient's commitments, measures, and capability; the availability of rights channels; and the effect of the recipient country's or region's law on performance.

Use the CAC contract in the form attached to the measures. Additional terms are allowed only if they do not conflict with it. The contract must take effect before the export begins. File the effective contract and PIPIA report with the provincial CAC within 10 working days after effectiveness; filing is not described as an approval of the export.

  • Route record: exporter and recipient, CIIO status, important-data conclusion, count period, non-sensitive count, sensitive count, exemption analysis, and selected route.
  • PIPIA: source data, purposes, methods, locations, retention, onward transfers, rights channels, recipient controls, local-law analysis, risks, and safeguards.
  • Contract file: prescribed contract, any non-conflicting additions, signatures, effective date, scope matching the PIPIA, and the date export began.
  • Filing evidence: contract, PIPIA report, submission date, provincial CAC destination, receipt or other available evidence, and confirmation that the filed materials were accurate.
  • Reassessment: repeat the PIPIA, supplement or replace the contract, and complete the corresponding filing when specified purposes, scope, categories, sensitivity, methods, storage location, overseas use, retention, foreign law, or another rights-affecting fact changes.
Citations
When does a China PIPL security assessment apply?

Determine whether a current trigger applies

Start with the actual outbound flow, exporter, data, recipients, and count period. Determine CIIO status through the applicable designation process. For important data, check relevant sector or regional catalogues, published identification, and authority notices. The 2024 provisions say data need not be submitted as important data when a relevant department or region has neither notified the processor nor publicly identified it as important.

Count personal information exported from January 1 of the current year. Count personal information excluding sensitive personal information against the 1 million threshold and count sensitive personal information separately against the 10,000 threshold.

  • CIIO: security assessment for any export of personal information or important data, subject to the controlling exemptions.
  • Non-CIIO important data: security assessment regardless of the number of individuals, subject to the controlling exemptions.
  • Non-CIIO personal information: security assessment at 1 million or more individuals, excluding sensitive personal information, from January 1.
  • Non-CIIO sensitive personal information: security assessment at 10,000 or more individuals from January 1.
  • Below the assessment thresholds: an exemption may apply, or the exporter may need the CAC standard contract or certification. A below-threshold export is not automatically free of PIPL notice, separate-consent, PIPIA, or security duties.
Citations
When does a China PIPL security assessment apply?

Apply exemptions, then prepare the application

Before applying, test the 2024 exemptions for data without personal information or important data in specified cross-border activities; qualifying overseas-origin personal information returned abroad without domestic personal information or important data added; necessary performance of an individual's contract; qualifying cross-border HR management; emergencies protecting life, health, or property; low-volume non-sensitive exports by a non-CIIO; and an applicable pilot free-trade-zone negative list. Each exemption has conditions, and the personal-information exemptions do not cover important data.

When an assessment is triggered, complete the export risk self-assessment and apply through the provincial CAC. The application materials include the application, self-assessment report, the legal document with the overseas recipient, and other materials required for the assessment.

  • Route evidence: export description, exporter and recipient, CIIO determination, important-data check, non-sensitive and sensitive counts, count period, exemption analysis, and conclusion.
  • Self-assessment: purpose, scope, method, data scale and sensitivity, risks, recipient duties and capabilities, foreign legal environment, rights channels, legal instrument, and safeguards.
  • Application: submitted form, self-assessment report, recipient legal instrument, requested supporting materials, completeness correspondence, and written outcome.
  • Timing: the provincial CAC checks completeness within 5 working days; the national CAC decides whether to accept within 7 working days after receipt and ordinarily completes the assessment within 45 working days after written acceptance, with possible extension for complex or supplemented cases.
  • Validity and change control: a successful result is valid for three years under the 2024 provisions. If no reapplication trigger occurs, the exporter may seek a three-year extension through the provincial CAC within 60 working days before expiry; changes affecting export security can require a new application earlier.
Citations
Measures for Security Assessment of Data Export

Articles 5-14 support the self-assessment content, application materials, completeness and acceptance steps, review period, reconsideration, and change triggers. Its former two-year validity rule is superseded by the 2024 provisions.

Page 1 of 1
Previous1Next