QuestionChina

What is separate consent under PIPL? Direct answer

Separate consent is a PIPL requirement for higher-risk processing situations, including sensitive personal information, certain sharing/provision scenarios, public disclosure, and cross-border transfer routes where the law calls for it. Keep proof that the consent request was distinct from general notice acceptance.

What is separate consent under PIPL? is a practical China PIPL privacy compliance question. The answer explains the trigger, the decision to make, and the evidence visitors should keep for review.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 5, 2026
Questions
2

Structured answer sets in this page tree.

Primary sources
1

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 5, 2026
Overview

Separate consent is a PIPL requirement for higher-risk processing situations, including sensitive personal information, certain sharing/provision scenarios, public disclosure, and cross-border transfer routes where the law calls for it. Keep proof that the consent request was distinct from general notice acceptance.

Search this module

Find a question or answer quickly

2 of 2 questions
Question 1

Short answer

This answer explains what is separate consent under pipl? in practical terms: the trigger to check, the evidence to keep, and the follow-up decision that should be owned before launch or change approval.

The record should show the exact user-facing text, action taken, timestamp or consent state, withdrawal path, and processing purpose covered.

Citations
Question 2

What to keep as evidence

A reviewer should be able to reconstruct the decision without asking the launch team what happened.

  • Keep processing activity map.
  • Keep privacy notice and lawful-basis record.
  • Keep separate-consent evidence for sensitive PI or exports.
  • Keep PIPIA report and approval.
  • Keep entrusted-processing contract terms.
Citations
Primary sources

References and citations

Related guides

Explore more topics

App minimum necessary personal information by category
App category mapping page for common mobile app necessary personal information scope, using only categories supported by the official source.
China app personal information minimization
How to map app category, basic functions, and necessary personal information under China mobile app personal-information rules.
China data export security assessment workflow
Workflow for screening data export security assessment triggers, materials, owners, and evidence records.
China personal information cross-border transfer routes
How to route China personal information exports across security assessment, standard contract, and newer cross-border data flow provisions.
China personal information standard contract filing workflow
Workflow for the PIPL standard contract route, assessment, filing package, and cited evidence.
China PIPL compliance checklist
Checklist for PIPL processing activity maps, notices, consent, separate consent, sensitive PI, entrusted processing, export route, and app minimization evidence.
China PIPL deadlines and compliance calendar
Official privacy, app minimization, SCC, data export assessment, and cross-border data flow dates.
China PIPL penalties and enforcement exposure
China privacy penalties and operational exposure under PIPL and data export rules.
China PIPL privacy notice and consent checklist
Practical notice, consent, separate consent, sensitive PI, and rights-handling checklist under PIPL.
China PIPL requirements
China Personal Information Protection Law requirements by processing lifecycle, including consent, sensitive PI, rights, exports, breach response, and evidence.
China PIPL vs CCPA/CPRA
Comparison of China PIPL and California CCPA/CPRA for global privacy teams.
China PIPL vs EU GDPR
Comparison of China PIPL and EU GDPR for privacy teams handling global data processing and transfer programs.
China PIPL vs Singapore PDPA
Comparison of China PIPL and Singapore PDPA for APAC privacy programs.
China Privacy Law FAQ
Answers to practical China Privacy Law questions for scope, official source triggers, evidence records, and related China scope decisions.
How should vendor contracts handle entrusted processing under PIPL?
Vendor contracts should show entrusted-processing scope, processing purpose, data categories, security duties, assistance with rights/incidents, onward transfer limits, deletion/return, audit evidence, and source references.
Is PIPL the same as GDPR?
No. PIPL and GDPR can support a shared privacy program, but they use different legal concepts, transfer routes, regulatory sources, and evidence requirements. Compare article-by-article before reusing notices, consent flows, or transfer assessments.
PIPL automated decision-making and personalized recommendations
Practical checks for automated decision-making transparency, fairness, choice, and evidence under PIPL.
PIPL breach response and notification
How to document breach response, mitigation, notification analysis, and evidence under China personal information rules.
PIPL cross-border transfer route selector
Route selector for China personal information exports across security assessment, standard contract, and lower-risk/exemption analysis.
PIPL entrusted processing and vendor contracts
How to document entrusted processing, vendor responsibilities, contract controls, and evidence under PIPL.
PIPL impact assessment template
Template fields for a China personal information protection impact assessment and export/entrusted-processing evidence.
Sensitive personal information and separate consent under PIPL
How to identify sensitive PI triggers, separate consent, minors, additional safeguards, and evidence records.
What counts as sensitive personal information in China?
Sensitive personal information should be identified from the PIPL source and recorded with purpose, necessity, separate consent analysis, safeguards, retention, and access limits before processing.
What records should we keep for a PIPL impact assessment?
Keep purpose, processing basis, personal information categories, sensitive PI/minors, entrusted processors, export route, risks, safeguards, retention, rights handling, incident plan, reviewer, and source references.
What should an app collect as necessary personal information in China?
Use the app necessary personal information source by app category. If a data field is not necessary for the basic function, keep a product decision explaining why collection is optional or remove it from the basic flow.
When can a company use the China standard contract route?
The standard contract route is a specific personal-information export route with filing and impact-assessment evidence. It should be selected only after screening whether a security assessment or newer cross-border data flow rule changes the route.
When does a China PIPL security assessment apply?
A security assessment check is needed before certain outbound data or personal information transfers. The record should screen PIPL export duties, the Data Export Security Assessment Measures, and newer cross-border data flow provisions before choosing a route.