---
title: "China Privacy Law FAQ"
canonical_url: "https://www.sorena.io/artifacts/apac/china-privacy-law/faq"
source_url: "https://www.sorena.io/artifacts/apac/china-privacy-law/faq/items"
author: "Sorena AI"
description: "Practical answers on China's PIPL: scope, legal bases, sensitive information, separate consent, vendors, PIPIA records, app minimization, and export routes."
published_at: "2026-07-05"
updated_at: "2026-07-24"
keywords:
  - "China PIPL"
  - "Personal Information Protection Law"
  - "Data export"
  - "Standard contract"
  - "App privacy"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# China Privacy Law FAQ

Practical answers on China's PIPL: scope, legal bases, sensitive information, separate consent, vendors, PIPIA records, app minimization, and export routes.

*FAQ* *China*

## China Privacy Law FAQ

Use this FAQ to route common questions under China's Personal Information Protection Law, including sensitive information, separate consent, vendors, impact assessments, apps, and cross-border transfers.

Start with the scope and processing-basis decision, then apply the activity-specific rule and keep evidence that connects the facts to the conclusion.

PIPL applies to personal-information processing in China and to specified processing outside China involving people in China. For each activity, identify the responsible personal information processor, Article 13 basis, minimum necessary information, notice, consent or separate-consent requirement, retention, security, individual-rights process, PIPIA trigger, and any overseas-provision route.

## Definitions

### Personal Information Protection Law of the People's Republic of China

**Term:** PIPL

PIPL is China's national law governing the processing of personal information. It applies to processing in China and to specified processing outside China involving people in China, including offering them products or services or analyzing or assessing their behavior.

**Why it matters here:** A PIPL scope conclusion is the starting point, not the final compliance decision. A covered processor must still identify the Article 13 basis, notices, consent requirements, individual rights, security measures, PIPIA triggers, and any cross-border route.

Sources:

- [PRC Personal Information Protection Law, Articles 3-13](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io)

### Personal information protection impact assessment

**Term:** PIPIA

A PIPIA is the prior assessment required for sensitive-personal-information processing, automated decision-making, entrusted processing, provision to another processor, public disclosure, provision outside China, and other processing with a major effect on personal rights and interests.

**Why it matters here:** The assessment must address legality, legitimacy, necessity, effects on individuals, security risks, and whether the safeguards are lawful, effective, and proportionate. Keep the report and processing record for at least three years.

Sources:

- [PRC Personal Information Protection Law, Articles 55-56](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io)

## Browse sub-FAQ modules

### [How should vendor contracts handle entrusted processing under PIPL?](/artifacts/apac/china-privacy-law/faq/how-should-vendor-contracts-handle-entrusted-processing.md)

A PIPL entrusted-processing contract must define the purpose, duration, method, personal-information categories, safeguards, and both parties' duties. See the required terms and supporting records.

- 2 items

### [Is PIPL the same as GDPR?](/artifacts/apac/china-privacy-law/faq/is-pipl-the-same-as-gdpr.md)

No. China's PIPL and the EU GDPR overlap on core privacy controls, but differ in territorial scope, legal bases, roles, sensitive data, impact assessments, and transfer routes.

- 3 items

### [What counts as sensitive personal information in China?](/artifacts/apac/china-privacy-law/faq/what-counts-as-sensitive-personal-information-in-china.md)

PIPL uses a harm-based test for sensitive personal information and lists examples such as biometrics, health, financial accounts, location traces, and all personal information of children under 14.

- 2 items

### [What is separate consent under PIPL?](/artifacts/apac/china-privacy-law/faq/what-is-separate-consent-under-pipl.md)

Separate consent under China's PIPL is a distinct consent for a specified processing activity. See when it applies, what notice must come first, and what evidence to keep.

- 2 items

### [What records should we keep for a PIPL impact assessment?](/artifacts/apac/china-privacy-law/faq/what-records-should-we-keep-for-a-pipl-impact-assessment.md)

A PIPL impact-assessment file should preserve the Article 55 trigger, processing facts, Article 56 analysis, safeguards, decision, and processing record for at least three years.

- 2 items

### [What should an app collect as necessary personal information in China?](/artifacts/apac/china-privacy-law/faq/what-should-an-app-collect-as-necessary-personal-information.md)

Match the app's basic function to China's 2021 rules and collect no more than the listed necessary personal information. Users must retain the basic function if they decline non-necessary data.

- 2 items

### [When can a company use the China standard contract route?](/artifacts/apac/china-privacy-law/faq/when-can-a-company-use-the-china-standard-contract-route.md)

Use China's standard contract route only after applying the 2024 exemptions and confirming that no CAC security assessment is required. See current thresholds, filing steps, and change triggers.

- 2 items

### [When does a China PIPL security assessment apply?](/artifacts/apac/china-privacy-law/faq/when-does-a-china-pipl-security-assessment-apply.md)

A CAC data export security assessment applies to CIIO exports, important data, and specified high-volume personal-information exports after the 2024 exemptions are applied.

- 2 items

Browse all indexed questions: [/artifacts/apac/china-privacy-law/faq/items](/artifacts/apac/china-privacy-law/faq/items.md)

## All FAQ items

*Page 1 of 1. Showing 17 of 17 items.*

### [Classify the relationship before drafting](/artifacts/apac/china-privacy-law/faq/how-should-vendor-contracts-handle-entrusted-processing.md#classify-the-relationship-before-drafting)

*Module: [How should vendor contracts handle entrusted processing under PIPL?](/artifacts/apac/china-privacy-law/faq/how-should-vendor-contracts-handle-entrusted-processing.md)*

Article 21 applies when the vendor processes personal information within the customer's agreed instructions and scope. If both parties decide the purpose and method, Article 20's joint-processing rule may apply. If the vendor receives the information and determines its own purpose or method, Article 23's provision-to-another-processor rule may apply, including recipient notice and separate consent.

- Entrusted party: process only within the agreed purpose, method, and other contractual limits.
- Personal information processor: supervise the entrusted party's processing rather than treating the signed contract as the end of oversight.
- Joint processors: agree their respective rights and obligations, while preserving the individual's ability to exercise PIPL rights against either processor.
- Another processor receiving personal information: give the Article 23 recipient notice and obtain separate consent before provision, unless a different legal rule controls.

Sources for this answer:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Articles 20-23 distinguish joint processing, entrusted processing, and provision to another personal information processor, with different agreement, supervision, notice, and consent consequences.

### [Required terms and useful operational clauses](/artifacts/apac/china-privacy-law/faq/how-should-vendor-contracts-handle-entrusted-processing.md#required-terms-and-useful-operational-clauses)

*Module: [How should vendor contracts handle entrusted processing under PIPL?](/artifacts/apac/china-privacy-law/faq/how-should-vendor-contracts-handle-entrusted-processing.md)*

Put every Article 21 item in the binding agreement: purpose, duration, method, personal-information categories, protective measures, and both parties' rights and obligations. State that the entrusted party may not exceed the agreed purpose or method, must return or delete the information without retaining it when the contract is ineffective, invalid, revoked, or terminated, and may not sub-entrust without the processor's consent.

- Scope schedule: systems, purposes, duration, methods, information categories, people concerned, access locations, retention, and approved recipients.
- Security and assistance: organizational and technical safeguards, incident escalation, rights-request support, compliance evidence, and named contacts.
- Sub-entrustment: prior-consent process, required flow-down terms, current sub-entrusted parties, and responsibility for monitoring the chain.
- Exit: return-or-deletion instructions, confirmation evidence, backup treatment, and the narrow legal basis for any retention that cannot end immediately.
- Oversight file: due diligence, contract approval, supervision results, remediation, and the prior Article 55 PIPIA. PIPL requires the PIPIA report and record of the assessed processing to be kept for at least three years.

Sources for this answer:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Articles 21 and 59 establish the mandatory entrusted-processing terms, supervision, return-or-deletion, sub-entrustment, security, and assistance duties. Articles 55-56 require a prior PIPIA for entrustment and at least three years' retention.

### [Scope, roles, and processing bases](/artifacts/apac/china-privacy-law/faq/is-pipl-the-same-as-gdpr.md#scope-roles-and-processing-bases)

*Module: [Is PIPL the same as GDPR?](/artifacts/apac/china-privacy-law/faq/is-pipl-the-same-as-gdpr.md)*

Run the territorial tests independently. PIPL applies to processing in China and also to specified processing outside China involving people in China, including offering them products or services or analyzing or assessing their behavior. GDPR applies to processing in the context of an EU establishment and, for certain organizations outside the EU, to offering goods or services to people in the EU or monitoring their behavior there.

- Outside-China PIPL processing can require a dedicated organization or representative in China under Article 53; GDPR Article 27 has its own representative rule and exceptions.
- PIPL consent must be voluntary and explicit and based on sufficient knowledge. PIPL also requires separate consent for specified activities; GDPR does not use the same general statutory concept.
- A GDPR legitimate-interests assessment does not create a PIPL basis. A PIPL Article 13 basis does not by itself establish a GDPR Article 6 basis.
- Keep shared facts once, then record the applicable role, basis, notice, consent, rights, retention, and responsible entity separately for each law.

Sources for this answer:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Articles 3, 13-17, 20-23, 53, and 73 support the PIPL territorial, role, processing-basis, consent, and representative comparison points.
- [EU General Data Protection Regulation](https://eur-lex.europa.eu/eli/reg/2016/679/oj?ref=sorena.io) - Articles 3, 4, 6-7, and 26-29 support the GDPR territorial, role, lawful-basis, consent, joint-controller, and processor comparison points.

### [Sensitive information, assessments, and transfers](/artifacts/apac/china-privacy-law/faq/is-pipl-the-same-as-gdpr.md#sensitive-information-assessments-and-transfers)

*Module: [Is PIPL the same as GDPR?](/artifacts/apac/china-privacy-law/faq/is-pipl-the-same-as-gdpr.md)*

PIPL and GDPR both impose added conditions on higher-risk processing, but the tests differ. PIPL permits sensitive personal information only for a specific purpose, with sufficient necessity and strict safeguards, and generally requires separate consent plus a prior PIPIA. GDPR Article 9 generally prohibits special-category processing unless an Article 9 exception applies; its categories and exceptions do not match PIPL's.

- Shared evidence: processing inventory, data flows, systems, vendors, recipients, countries, retention, security measures, and rights procedures.
- Separate conclusions: territorial scope, legal role, processing basis, sensitive or special-category classification, notice, consent, assessment trigger, and responsible entity.
- Separate transfer file: origin, destination, exporter and recipient, current threshold or exemption, transfer instrument, assessment, individual notice, and required filing or approval.
- Change control: reopen both analyses when a purpose, method, category, recipient, country, volume, automated-decision use, or applicable rule changes.

Sources for this answer:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Articles 28-31, 38-40, and 55-56 support the PIPL sensitive-information, export, separate-consent, and PIPIA comparison points.
- [EU General Data Protection Regulation](https://eur-lex.europa.eu/eli/reg/2016/679/oj?ref=sorena.io) - Articles 9, 35, and 44-49 support the GDPR special-category, DPIA, and international-transfer comparison points.

### [Rights, incidents, and enforcement also differ](/artifacts/apac/china-privacy-law/faq/is-pipl-the-same-as-gdpr.md#rights-incidents-and-enforcement-also-differ)

*Module: [Is PIPL the same as GDPR?](/artifacts/apac/china-privacy-law/faq/is-pipl-the-same-as-gdpr.md)*

Both laws provide access, correction, deletion, objection or refusal, and automated-decision protections, but their conditions and procedures are not identical. PIPL gives individuals rights to know and decide, restrict or refuse processing, access and copy, correct, and delete under stated conditions. GDPR provides its own access, rectification, erasure, restriction, portability, objection, and automated-decision rights, each with separate conditions and exceptions.

- Request workflow: identify the law, right, requester, identity check, applicable exception, response deadline, search scope, decision, and response evidence.
- Incident workflow: record awareness time, affected systems and people, data categories, likely consequences, remedial measures, risk conclusion, authority notice, individual notice, and the reason for any exception.
- Enforcement: PIPL and GDPR use different infringement tests, authorities, remedies, and turnover measures. Do not convert one law's maximum percentage into the other's penalty analysis.
- Reassessment: reopen both legal analyses when the role, purpose, processing method, information category, recipient, country, automated decision, or risk changes.

Sources for this answer:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Articles 44-50, 57, and 66 support the PIPL rights, incident-response, notification, and principal administrative-penalty distinctions.
- [EU General Data Protection Regulation](https://eur-lex.europa.eu/eli/reg/2016/679/oj?ref=sorena.io) - Articles 12-22, 33-34, 83, and 99 support the GDPR application date, rights, breach-notification clocks, and administrative-fine distinctions.

### [Apply the harm test, not only the examples](/artifacts/apac/china-privacy-law/faq/what-counts-as-sensitive-personal-information-in-china.md#apply-the-harm-test-not-only-the-examples)

*Module: [What counts as sensitive personal information in China?](/artifacts/apac/china-privacy-law/faq/what-counts-as-sensitive-personal-information-in-china.md)*

Article 28's examples are representative categories, not a complete field dictionary. Classify the actual information and processing context by asking whether leakage or illegal use could readily cause either kind of statutory harm. A field that looks ordinary in isolation may become sensitive when combined with other data or used to infer health, identity, movements, finances, or another protected condition.

- Biometric identification, religious belief, and specific identity are express statutory examples; record the exact information and how it is used.
- Medical and health information and financial account information are express statutory examples; apply the harm test to the fields, inferences, and processing context.
- Location-tracking information is an express statutory example; record what the information reveals, how long it is retained, and who can access it.
- Other information can qualify when it meets the statutory harm test even if it does not fit one of the named examples.

Sources for this answer:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Article 28 supplies the harm test, representative categories, and the rule for children under 14.

### [What changes when the information is sensitive](/artifacts/apac/china-privacy-law/faq/what-counts-as-sensitive-personal-information-in-china.md#what-changes-when-the-information-is-sensitive)

*Module: [What counts as sensitive personal information in China?](/artifacts/apac/china-privacy-law/faq/what-counts-as-sensitive-personal-information-in-china.md)*

A processor may handle sensitive personal information only for a specific purpose, with sufficient necessity and strict protective measures. Before processing, give the general Article 17 notice plus the necessity of the sensitive processing and its effect on the individual's rights and interests, unless a PIPL notice exception applies.

- Inventory: exact fields, inferred attributes, source, system, people concerned, recipients, access locations, and retention.
- Classification: statutory category where applicable, contextual harm analysis, child-age rule, decision owner, and unresolved borderline facts.
- Necessity and safeguards: specific purpose, why less intrusive information is insufficient, access restrictions, security measures, and shortest necessary retention.
- Individual-facing evidence: general and additional notice versions, separate-consent record, withdrawal path, and parent-or-guardian consent where the person is under 14.
- Assessment: Article 55 PIPIA, control implementation evidence, approval, and triggers for reassessment when the purpose, method, information, recipient, or risk changes.

Sources for this answer:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Articles 28-31 establish the purpose, necessity, safeguard, notice, consent, and child-specific duties. Articles 55-56 require a prior PIPIA and at least three years' retention.

### [When separate consent is required](/artifacts/apac/china-privacy-law/faq/what-is-separate-consent-under-pipl.md#when-separate-consent-is-required)

*Module: [What is separate consent under PIPL?](/artifacts/apac/china-privacy-law/faq/what-is-separate-consent-under-pipl.md)*

The provisions listed below call for separate consent when consent is required. It is different from a general acceptance of a privacy notice and must relate to the specified activity. Article 13 says consent is not required when one of its listed non-consent circumstances applies, so document the exact Article 13 conclusion before designing the consent flow. The processor must still satisfy the applicable notice, necessity, security, and impact-assessment duties.

- Providing personal information to another personal information processor: identify the recipient, contact details, purpose, method, and information categories before obtaining separate consent.
- Public disclosure: obtain separate consent unless a specific legal rule permits the disclosure.
- Public-place image or identity-recognition information: use it only to protect public security unless separate consent supports another purpose and the other legal conditions are met.
- Sensitive personal information: establish a specific purpose and sufficient necessity, use strict protective measures, give the additional necessity-and-impact notice, and obtain separate consent. A law or administrative regulation may also require written consent.
- Providing personal information outside China: identify the overseas recipient, its contact details, purpose, method, information categories, and the procedure for exercising PIPL rights before obtaining separate consent.

Sources for this answer:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Articles 14-17 govern informed consent, renewed consent, withdrawal, and general notice. Articles 23, 25, 26, 29, and 39 identify the activities that require separate consent and the additional information that must be given.

### [How to implement and document the choice](/artifacts/apac/china-privacy-law/faq/what-is-separate-consent-under-pipl.md#how-to-implement-and-document-the-choice)

*Module: [What is separate consent under PIPL?](/artifacts/apac/china-privacy-law/faq/what-is-separate-consent-under-pipl.md)*

PIPL does not mandate a checkbox, modal, signature, or other specific interface. Use a design that makes the specified activity clear and captures an affirmative choice separate from unrelated permissions. Do not describe a bundled acceptance of terms as separate consent merely because the notice mentions the activity.

- Decision record: statutory trigger, Article 13 basis, purpose, processing method, information categories, recipients, necessity analysis, and responsible owner.
- Notice evidence: the exact notice version, language, required recipient or overseas-transfer details, and when it appeared in the user flow.
- Choice evidence: account or device identifier where appropriate, affirmative action, timestamp, notice version, scope of consent, and later withdrawal or renewal.
- Related controls: the Article 55 PIPIA where triggered, retention rule, security measures, rights-request path, and a change trigger for a new purpose, method, category, or recipient.

Sources for this answer:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Articles 14 and 15 support the consent and withdrawal record; Articles 17, 23, 30, and 39 identify notice content; Article 55 identifies processing that requires a prior PIPIA.

### [Start with the trigger and actual processing](/artifacts/apac/china-privacy-law/faq/what-records-should-we-keep-for-a-pipl-impact-assessment.md#start-with-the-trigger-and-actual-processing)

*Module: [What records should we keep for a PIPL impact assessment?](/artifacts/apac/china-privacy-law/faq/what-records-should-we-keep-for-a-pipl-impact-assessment.md)*

Complete a PIPIA before processing sensitive personal information; using personal information for automated decision-making; entrusting processing; providing personal information to another processor; publicly disclosing it; providing it outside China; or carrying out another activity with a major effect on personal rights and interests.

- Scope record: assessment identifier, Article 55 trigger, systems and versions, owner, participating teams, decision date, and processing start date.
- Data map: information fields and inferences, sensitive or child data, sources, people, volumes where relevant, recipients, entrusted parties, overseas locations, access paths, retention, and deletion.
- Rule analysis: Article 13 basis, notices, consent or separate-consent requirement, necessity, minimization, individual rights, and any export-route dependency.
- Change control: facts that require review, including a new purpose, method, information category, recipient, country, retention period, automated-decision use, or material risk.

Sources for this answer:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Articles 55-56 identify every PIPIA trigger, the three required assessment topics, and the minimum three-year retention period.
- [Measures for the Standard Contract for Personal Information Export](https://www.cac.gov.cn/2023-02/24/c_1678884830036813.htm?ref=sorena.io) - Article 5 adds export-specific PIPIA topics for the standard-contract route, including scale, sensitivity, overseas-recipient safeguards, rights channels, and the recipient country's legal environment.
- [Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Articles 5-6 identify the separate data-export risk self-assessment and application materials when a CAC security assessment is required.

### [Record the Article 56 analysis and decision](/artifacts/apac/china-privacy-law/faq/what-records-should-we-keep-for-a-pipl-impact-assessment.md#record-the-article-56-analysis-and-decision)

*Module: [What records should we keep for a PIPL impact assessment?](/artifacts/apac/china-privacy-law/faq/what-records-should-we-keep-for-a-pipl-impact-assessment.md)*

Article 56 requires three conclusions: whether the purpose and method are lawful, legitimate, and necessary; the effect on personal rights and interests and the security risks; and whether the safeguards are lawful, effective, and proportionate to the risk. Show the facts, evidence, and reasoning behind each conclusion.

- Legality, legitimacy, and necessity: source provisions, purpose, basis, less intrusive alternatives, minimum information, and shortest necessary retention.
- Effects and risks: plausible misuse, leakage, unauthorized access, discrimination, loss of control, rights barriers, and severity and likelihood using the organization's defined method.
- Safeguards: contractual, organizational, and technical measures; responsible owner; implementation status; test or review evidence; and why the measures match the risk.
- Outcome: approved scope, conditions before launch, unresolved issues, risk acceptance under internal governance, reassessment triggers, and links to the processing record and implemented controls.
- Retention: preserve the PIPIA report and processing record for at least three years. Sorena recommends keeping material inputs, approvals, and control evidence with that file so a reviewer can reconstruct the decision; a longer period may follow from another applicable rule or the processing lifecycle.

Sources for this answer:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Article 56 supplies the mandatory assessment content and requires the assessment report and processing record to be kept for at least three years.
- [Measures for the Standard Contract for Personal Information Export](https://www.cac.gov.cn/2023-02/24/c_1678884830036813.htm?ref=sorena.io) - Articles 5, 7, and 8 support the additional export assessment content, filing of the report with the contract, and reassessment when specified facts change.
- [Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Use only when the export also triggers the CAC security-assessment route; its risk self-assessment is a separate, more detailed submission record.

### [Match the app to its basic function](/artifacts/apac/china-privacy-law/faq/what-should-an-app-collect-as-necessary-personal-information.md#match-the-app-to-its-basic-function)

*Module: [What should an app collect as necessary personal information in China?](/artifacts/apac/china-privacy-law/faq/what-should-an-app-collect-as-necessary-personal-information.md)*

Start with what the user is obtaining, not the app's marketing label. Match that basic function to the 2021 category and map each proposed field to the listed scope. If the app provides several distinct basic functions, document the category and necessary scope for each function rather than treating the broadest category as permission for the whole product.

- Map navigation: location, departure point, and destination are listed for the basic location-and-navigation function.
- Online shopping and food delivery: the listed scope includes a registered mobile number, recipient name, address and contact number, and payment time, amount, and channel.
- Instant messaging: the listed scope includes a registered mobile number plus the account and instant-messaging contact-account list.
- Functions requiring no personal information: the rules list news browsing, online audio or video playback, short-video search and playback, browsers, input methods, photography or beautification, and several other categories as needing none for the stated basic function. Requiring account registration or a device permission before those basic functions would conflict with that category result unless another controlling rule applies.
- Health, finance, transport, and other categories can include information that is sensitive under PIPL. The category table does not remove the separate sensitive-information duties.

Sources for this answer:

- [Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - Articles 2-5 define covered apps, consumer-side necessary personal information, the no-refusal rule, and the category-specific scopes and examples.
- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Articles 5-19 and 28-31 supply the separate purpose, minimization, basis, notice, consent, retention, sensitive-information, and child rules.

### [Build and test the collection map](/artifacts/apac/china-privacy-law/faq/what-should-an-app-collect-as-necessary-personal-information.md#build-and-test-the-collection-map)

*Module: [What should an app collect as necessary personal information in China?](/artifacts/apac/china-privacy-law/faq/what-should-an-app-collect-as-necessary-personal-information.md)*

For every field, device permission, SDK, and event, record the product function, collection timing, recipient, purpose, and whether the item is necessary for the basic function. If it is outside the category scope or the function works without it, keep it out of the mandatory flow and do not block the basic function when the user refuses.

- Category decision: basic-function description, selected 2021 category, any multi-function split, and product owner.
- Field map: field or event, collection source, user action, basic function, necessity rationale, recipient or SDK, retention, and deletion.
- Refusal test: evidence that declining each non-necessary field or permission leaves the relevant basic function available.
- PIPL overlay: basis, notice, consent, sensitive-information classification, child treatment, security controls, rights path, and PIPIA where triggered.
- Change trigger: reassess when a function, SDK, permission, field, use, recipient, or collection timing changes.

Sources for this answer:

- [Necessary Personal Information Scope for Common Types of Mobile Apps](https://www.cac.gov.cn/2021-03/22/c_1617990997054277.htm?ref=sorena.io) - The 2021 rules support the category decision, field map, and no-refusal test for information outside the necessary scope.
- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - PIPL supports the additional processing-basis, notice, minimization, retention, sensitive-information, child, security, rights, and PIPIA checks.

### [Apply the routing tests in order](/artifacts/apac/china-privacy-law/faq/when-can-a-company-use-the-china-standard-contract-route.md#apply-the-routing-tests-in-order)

*Module: [When can a company use the China standard contract route?](/artifacts/apac/china-privacy-law/faq/when-can-a-company-use-the-china-standard-contract-route.md)*

First decide whether the activity provides data outside China and whether that data contains personal information or important data. Then apply the 2024 exemptions. Next determine whether the exporter is a critical information infrastructure operator (CIIO), whether important data is involved, and how many individuals' non-sensitive and sensitive personal information has been exported since January 1.

- No personal information or important data: specified international-trade, cross-border transport, academic-cooperation, transnational-production, and marketing data can be exempt from all three CAC transfer mechanisms.
- Overseas-origin information: personal information collected outside China, processed in China, and sent out again is exempt if no personal information or important data collected or generated in China is introduced during processing.
- Necessary individual contract, qualifying cross-border HR management, or emergency: these exports can be exempt when every stated condition is met and no important data is included.
- Low-volume non-sensitive export: a non-CIIO exporting personal information of fewer than 100,000 individuals since January 1 is exempt only for the count excluding sensitive personal information. Sensitive information requires its own route analysis.
- Free-trade-zone rule: a qualifying exporter in a pilot free-trade zone may rely on the approved negative-list framework for data outside that list.

Sources for this answer:

- [Measures for the Standard Contract for Personal Information Export](https://www.cac.gov.cn/2023-02/24/c_1678884830036813.htm?ref=sorena.io) - Articles 5-8 govern the export PIPIA, prescribed contract, effective-before-export rule, filing deadline, and reassessment and re-filing triggers.
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Articles 3-8 provide the current exemptions and route thresholds. Article 13 makes these provisions control where they conflict with the older standard-contract measures.

### [Complete the contract, assessment, and filing](/artifacts/apac/china-privacy-law/faq/when-can-a-company-use-the-china-standard-contract-route.md#complete-the-contract-assessment-and-filing)

*Module: [When can a company use the China standard contract route?](/artifacts/apac/china-privacy-law/faq/when-can-a-company-use-the-china-standard-contract-route.md)*

Complete the export PIPIA before the transfer. It should examine the legality, legitimacy, and necessity of both parties' processing; the exported information's scale, scope, categories, and sensitivity; risks to individuals; the overseas recipient's commitments, measures, and capability; the availability of rights channels; and the effect of the recipient country's or region's law on performance.

- Route record: exporter and recipient, CIIO status, important-data conclusion, count period, non-sensitive count, sensitive count, exemption analysis, and selected route.
- PIPIA: source data, purposes, methods, locations, retention, onward transfers, rights channels, recipient controls, local-law analysis, risks, and safeguards.
- Contract file: prescribed contract, any non-conflicting additions, signatures, effective date, scope matching the PIPIA, and the date export began.
- Filing evidence: contract, PIPIA report, submission date, provincial CAC destination, receipt or other available evidence, and confirmation that the filed materials were accurate.
- Reassessment: repeat the PIPIA, supplement or replace the contract, and complete the corresponding filing when specified purposes, scope, categories, sensitivity, methods, storage location, overseas use, retention, foreign law, or another rights-affecting fact changes.

Sources for this answer:

- [Measures for the Standard Contract for Personal Information Export](https://www.cac.gov.cn/2023-02/24/c_1678884830036813.htm?ref=sorena.io) - Articles 5-8 support the required PIPIA topics, prescribed contract, timing, filing materials, truthfulness duty, and change process.
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Articles 7-8 confirm that a higher trigger requires security assessment and that eligible mid-range exports may use the standard contract or certification.

### [Determine whether a current trigger applies](/artifacts/apac/china-privacy-law/faq/when-does-a-china-pipl-security-assessment-apply.md#determine-whether-a-current-trigger-applies)

*Module: [When does a China PIPL security assessment apply?](/artifacts/apac/china-privacy-law/faq/when-does-a-china-pipl-security-assessment-apply.md)*

Start with the actual outbound flow, exporter, data, recipients, and count period. Determine CIIO status through the applicable designation process. For important data, check relevant sector or regional catalogues, published identification, and authority notices. The 2024 provisions say data need not be submitted as important data when a relevant department or region has neither notified the processor nor publicly identified it as important.

- CIIO: security assessment for any export of personal information or important data, subject to the controlling exemptions.
- Non-CIIO important data: security assessment regardless of the number of individuals, subject to the controlling exemptions.
- Non-CIIO personal information: security assessment at 1 million or more individuals, excluding sensitive personal information, from January 1.
- Non-CIIO sensitive personal information: security assessment at 10,000 or more individuals from January 1.
- Below the assessment thresholds: an exemption may apply, or the exporter may need the CAC standard contract or certification. A below-threshold export is not automatically free of PIPL notice, separate-consent, PIPIA, or security duties.

Sources for this answer:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - Articles 38-40 establish PIPL's overseas-provision conditions, individual notice and separate consent, and the security-assessment duty for specified processors.
- [Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Use for the assessment process, self-assessment, application materials, review scope, and change triggers, subject to the 2024 provisions where inconsistent.
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Articles 2-8 provide the current important-data treatment, exemptions, and assessment and alternative-route thresholds; Article 13 gives them priority over inconsistent older rules.

### [Apply exemptions, then prepare the application](/artifacts/apac/china-privacy-law/faq/when-does-a-china-pipl-security-assessment-apply.md#apply-exemptions-then-prepare-the-application)

*Module: [When does a China PIPL security assessment apply?](/artifacts/apac/china-privacy-law/faq/when-does-a-china-pipl-security-assessment-apply.md)*

Before applying, test the 2024 exemptions for data without personal information or important data in specified cross-border activities; qualifying overseas-origin personal information returned abroad without domestic personal information or important data added; necessary performance of an individual's contract; qualifying cross-border HR management; emergencies protecting life, health, or property; low-volume non-sensitive exports by a non-CIIO; and an applicable pilot free-trade-zone negative list. Each exemption has conditions, and the personal-information exemptions do not cover important data.

- Route evidence: export description, exporter and recipient, CIIO determination, important-data check, non-sensitive and sensitive counts, count period, exemption analysis, and conclusion.
- Self-assessment: purpose, scope, method, data scale and sensitivity, risks, recipient duties and capabilities, foreign legal environment, rights channels, legal instrument, and safeguards.
- Application: submitted form, self-assessment report, recipient legal instrument, requested supporting materials, completeness correspondence, and written outcome.
- Timing: the provincial CAC checks completeness within 5 working days; the national CAC decides whether to accept within 7 working days after receipt and ordinarily completes the assessment within 45 working days after written acceptance, with possible extension for complex or supplemented cases.
- Validity and change control: a successful result is valid for three years under the 2024 provisions. If no reapplication trigger occurs, the exporter may seek a three-year extension through the provincial CAC within 60 working days before expiry; changes affecting export security can require a new application earlier.

Sources for this answer:

- [PRC Personal Information Protection Law](https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm?ref=sorena.io) - PIPL supports the continuing notice, separate-consent, safeguards, overseas-recipient protection, and PIPIA duties for personal-information exports.
- [Measures for Security Assessment of Data Export](https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm?ref=sorena.io) - Articles 5-14 support the self-assessment content, application materials, completeness and acceptance steps, review period, reconsideration, and change triggers. Its former two-year validity rule is superseded by the 2024 provisions.
- [Provisions on Promoting and Regulating Cross-border Data Flow](https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm?ref=sorena.io) - Articles 3-9 support the exemptions, current thresholds, three-year validity, extension request, and calculation from January 1.

*Operationalize the requirement*

*Placement: Before primary sources*

## Prepare the PIPL and data export evidence file

Sorena AI helps turn the China Privacy Law FAQ decision into owners, controls, and reviewer-ready records.

- [Map official sources to evidence](/solutions/research-copilot.md): Research Copilot connects the official citation, decision, owner, retained evidence, and change history.
- [Review the China route](/contact.md): Check the China Privacy Law scope decision and unresolved launch questions with Sorena.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/apac/china-privacy-law/faq/items.md
