- Use for PIPL scope, processing bases, notice and consent, individual rights, processor duties, PIPIA, cross-border transfer duties, penalties, and effective date.
China Privacy Law PIPL privacy notice and consent checklist
Practical notice, consent, separate consent, sensitive PI, and rights-handling checklist under PIPL.
China PIPL privacy notice and consent checklist is a practical China PIPL privacy compliance checklist. It explains what to check, what evidence to keep, and when the decision should be revisited before a China launch, procurement, product change, or operating change.
Structured answer sets in this page tree.
Cited legal and guidance references.
Practical notice, consent, separate consent, sensitive PI, and rights-handling checklist under PIPL.
What this guide helps you decide
China PIPL privacy notice and consent checklist explains how privacy, legal, product, app, vendor-management, and data-governance teams should apply China PIPL privacy compliance. It focuses on the decision to make, the evidence to keep, the owner to assign, and the trigger for revisiting the conclusion.
PIPL Article 13 lists processing bases; Article 29 requires separate consent for sensitive personal information where consent is used; Articles 38-40 frame outbound personal-information transfer routes; Article 55 requires impact assessment for higher-risk processing.
- Map what personal information is collected, why it is needed, who receives it, where it is stored, and whether it leaves China.
- Separate ordinary personal information, sensitive personal information, children-related data, entrusted processing, automated decision-making, and overseas transfers.
- Pick the lawful processing basis and consent pattern before launch, not after a complaint or audit.
- For exports, decide whether the 2022 security assessment route, the standard contract filing route, or a 2024 exemption/threshold applies.
- Attach the official source citation, owner, approval date, and change trigger to each decision.
Checklist steps that should produce evidence
Translate the official requirement into operational controls that product, legal, compliance, security, and supplier owners can actually maintain.
The practical point is this: China PIPL is not a single document exercise. It is a route decision plus evidence that survives product, supplier, app, data, or disposal changes.
- Separate ordinary personal information, sensitive personal information, children-related data, entrusted processing, automated decision-making, and overseas transfers.
- Pick the lawful processing basis and consent pattern before launch, not after a complaint or audit.
- For exports, decide whether the 2022 security assessment route, the standard contract filing route, or a 2024 exemption/threshold applies.
- Attach the official source citation, owner, approval date, and change trigger to each decision.
- Keep processing activity map.
- Keep privacy notice and lawful-basis record.
Evidence to keep before launch or change approval
Keep evidence that proves the China decision was made before the launch, transfer, filing, procurement, disposal, or product change went live.
Keep the record understandable to an external reviewer: decision owner, official source citation, product, app, data-flow, or vendor identifier, approval date, and the trigger for reopening the decision.
- Keep processing activity map.
- Keep privacy notice and lawful-basis record.
- Keep separate-consent evidence for sensitive PI or exports.
- Keep PIPIA report and approval.
- Keep entrusted-processing contract terms.
- Keep cross-border route decision, filing, or assessment package.
- Keep data-subject request and breach-response log.
Boundary with nearby China regimes
Keep network-security controls, MLPS mapping, cybersecurity review, and app filing in the China cybersecurity guide unless the question is specifically about personal information processing or personal-information export.
When one launch triggers several regimes, link the shared facts such as model number, app package, data flow, supplier, or release date, but keep the legal conclusions separate.
- Treating GDPR documentation as enough for PIPL without checking separate consent, sensitive PI, PIPIA, and China export routes.
- Using the standard contract route without checking whether a CAC security assessment trigger or newer 2024 rule changes the route.
- Letting product teams add app permissions or personalization logic without updating the processing map and user-facing notice.
Prepare the PIPL and data export evidence file
Sorena AI helps turn the China Privacy Law PIPL privacy notice and consent checklist decision into owners, controls, and reviewer-ready records.
Research Copilot connects the official citation, decision, owner, retained evidence, and change history.
Check the China Privacy Law scope decision and unresolved launch questions with Sorena.