Start with the trigger and actual processing
Complete a before processing sensitive personal information; using personal information for automated decision-making; entrusting processing; providing personal information to another processor; publicly disclosing it; providing it outside China; or carrying out another activity with a major effect on personal rights and interests.
Identify the system, business owner, processor role, people concerned, purpose, Article 13 basis, collection source, information categories, processing methods, recipients, locations, retention, deletion, rights handling, and security controls. The assessment should describe the intended operation, not only repeat a privacy notice or contract.
- Scope record: assessment identifier, Article 55 trigger, systems and versions, owner, participating teams, decision date, and processing start date.
- Data map: information fields and inferences, sensitive or child data, sources, people, volumes where relevant, recipients, entrusted parties, overseas locations, access paths, retention, and deletion.
- Rule analysis: Article 13 basis, notices, consent or separate-consent requirement, necessity, minimization, individual rights, and any export-route dependency.
- Change control: facts that require review, including a new purpose, method, information category, recipient, country, retention period, automated-decision use, or material risk.
Articles 55-56 identify every PIPIA trigger, the three required assessment topics, and the minimum three-year retention period.
Article 5 adds export-specific PIPIA topics for the standard-contract route, including scale, sensitivity, overseas-recipient safeguards, rights channels, and the recipient country's legal environment.
Articles 5-6 identify the separate data-export risk self-assessment and application materials when a CAC security assessment is required.