PrivacyChina

China Privacy Law PIPL privacy notice and consent checklist

Practical notice, consent, separate consent, sensitive PI, and rights-handling checklist under PIPL.

China PIPL privacy notice and consent checklist is a practical China PIPL privacy compliance checklist. It explains what to check, what evidence to keep, and when the decision should be revisited before a China launch, procurement, product change, or operating change.

Author
Sorena AI
Published
Jul 5, 2026
Updated
Jul 5, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
1

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jul 5, 2026
Updated Jul 5, 2026
Overview

Practical notice, consent, separate consent, sensitive PI, and rights-handling checklist under PIPL.

Section 1

What this guide helps you decide

China PIPL privacy notice and consent checklist explains how privacy, legal, product, app, vendor-management, and data-governance teams should apply China PIPL privacy compliance. It focuses on the decision to make, the evidence to keep, the owner to assign, and the trigger for revisiting the conclusion.

PIPL Article 13 lists processing bases; Article 29 requires separate consent for sensitive personal information where consent is used; Articles 38-40 frame outbound personal-information transfer routes; Article 55 requires impact assessment for higher-risk processing.

  • Map what personal information is collected, why it is needed, who receives it, where it is stored, and whether it leaves China.
  • Separate ordinary personal information, sensitive personal information, children-related data, entrusted processing, automated decision-making, and overseas transfers.
  • Pick the lawful processing basis and consent pattern before launch, not after a complaint or audit.
  • For exports, decide whether the 2022 security assessment route, the standard contract filing route, or a 2024 exemption/threshold applies.
  • Attach the official source citation, owner, approval date, and change trigger to each decision.
Section 2

Checklist steps that should produce evidence

Translate the official requirement into operational controls that product, legal, compliance, security, and supplier owners can actually maintain.

The practical point is this: China PIPL is not a single document exercise. It is a route decision plus evidence that survives product, supplier, app, data, or disposal changes.

  • Separate ordinary personal information, sensitive personal information, children-related data, entrusted processing, automated decision-making, and overseas transfers.
  • Pick the lawful processing basis and consent pattern before launch, not after a complaint or audit.
  • For exports, decide whether the 2022 security assessment route, the standard contract filing route, or a 2024 exemption/threshold applies.
  • Attach the official source citation, owner, approval date, and change trigger to each decision.
  • Keep processing activity map.
  • Keep privacy notice and lawful-basis record.
Section 3

Evidence to keep before launch or change approval

Keep evidence that proves the China decision was made before the launch, transfer, filing, procurement, disposal, or product change went live.

Keep the record understandable to an external reviewer: decision owner, official source citation, product, app, data-flow, or vendor identifier, approval date, and the trigger for reopening the decision.

  • Keep processing activity map.
  • Keep privacy notice and lawful-basis record.
  • Keep separate-consent evidence for sensitive PI or exports.
  • Keep PIPIA report and approval.
  • Keep entrusted-processing contract terms.
  • Keep cross-border route decision, filing, or assessment package.
  • Keep data-subject request and breach-response log.
Section 4

Boundary with nearby China regimes

Keep network-security controls, MLPS mapping, cybersecurity review, and app filing in the China cybersecurity guide unless the question is specifically about personal information processing or personal-information export.

When one launch triggers several regimes, link the shared facts such as model number, app package, data flow, supplier, or release date, but keep the legal conclusions separate.

  • Treating GDPR documentation as enough for PIPL without checking separate consent, sensitive PI, PIPIA, and China export routes.
  • Using the standard contract route without checking whether a CAC security assessment trigger or newer 2024 rule changes the route.
  • Letting product teams add app permissions or personalization logic without updating the processing map and user-facing notice.
Operationalize the requirement

Prepare the PIPL and data export evidence file

Sorena AI helps turn the China Privacy Law PIPL privacy notice and consent checklist decision into owners, controls, and reviewer-ready records.

Primary sources

References and citations

cac.gov.cn
Referenced sections
  • Use for PIPL scope, processing bases, notice and consent, individual rights, processor duties, PIPIA, cross-border transfer duties, penalties, and effective date.
Related guides

Explore more topics

App minimum necessary personal information by category
App category mapping page for common mobile app necessary personal information scope, using only categories supported by the official source.
China app personal information minimization
How to map app category, basic functions, and necessary personal information under China mobile app personal-information rules.
China data export security assessment workflow
Workflow for screening data export security assessment triggers, materials, owners, and evidence records.
China personal information cross-border transfer routes
How to route China personal information exports across security assessment, standard contract, and newer cross-border data flow provisions.
China personal information standard contract filing workflow
Workflow for the PIPL standard contract route, assessment, filing package, and cited evidence.
China PIPL compliance checklist
Checklist for PIPL processing activity maps, notices, consent, separate consent, sensitive PI, entrusted processing, export route, and app minimization evidence.
China PIPL deadlines and compliance calendar
Official privacy, app minimization, SCC, data export assessment, and cross-border data flow dates.
China PIPL penalties and enforcement exposure
China privacy penalties and operational exposure under PIPL and data export rules.
China PIPL requirements
China Personal Information Protection Law requirements by processing lifecycle, including consent, sensitive PI, rights, exports, breach response, and evidence.
China PIPL vs CCPA/CPRA
Comparison of China PIPL and California CCPA/CPRA for global privacy teams.
China PIPL vs EU GDPR
Comparison of China PIPL and EU GDPR for privacy teams handling global data processing and transfer programs.
China PIPL vs Singapore PDPA
Comparison of China PIPL and Singapore PDPA for APAC privacy programs.
China Privacy Law FAQ
Answers to practical China Privacy Law questions for scope, official source triggers, evidence records, and related China scope decisions.
How should vendor contracts handle entrusted processing under PIPL?
Vendor contracts should show entrusted-processing scope, processing purpose, data categories, security duties, assistance with rights/incidents, onward transfer limits, deletion/return, audit evidence, and source references.
Is PIPL the same as GDPR?
No. PIPL and GDPR can support a shared privacy program, but they use different legal concepts, transfer routes, regulatory sources, and evidence requirements. Compare article-by-article before reusing notices, consent flows, or transfer assessments.
PIPL automated decision-making and personalized recommendations
Practical checks for automated decision-making transparency, fairness, choice, and evidence under PIPL.
PIPL breach response and notification
How to document breach response, mitigation, notification analysis, and evidence under China personal information rules.
PIPL cross-border transfer route selector
Route selector for China personal information exports across security assessment, standard contract, and lower-risk/exemption analysis.
PIPL entrusted processing and vendor contracts
How to document entrusted processing, vendor responsibilities, contract controls, and evidence under PIPL.
PIPL impact assessment template
Template fields for a China personal information protection impact assessment and export/entrusted-processing evidence.
Sensitive personal information and separate consent under PIPL
How to identify sensitive PI triggers, separate consent, minors, additional safeguards, and evidence records.
What counts as sensitive personal information in China?
Sensitive personal information should be identified from the PIPL source and recorded with purpose, necessity, separate consent analysis, safeguards, retention, and access limits before processing.
What is separate consent under PIPL?
Separate consent is a PIPL-specific consent requirement for certain higher-risk processing situations. The evidence file should identify the trigger, user-facing text, affirmative action, withdrawal path, and source article.
What records should we keep for a PIPL impact assessment?
Keep purpose, processing basis, personal information categories, sensitive PI/minors, entrusted processors, export route, risks, safeguards, retention, rights handling, incident plan, reviewer, and source references.
What should an app collect as necessary personal information in China?
Use the app necessary personal information source by app category. If a data field is not necessary for the basic function, keep a product decision explaining why collection is optional or remove it from the basic flow.
When can a company use the China standard contract route?
The standard contract route is a specific personal-information export route with filing and impact-assessment evidence. It should be selected only after screening whether a security assessment or newer cross-border data flow rule changes the route.
When does a China PIPL security assessment apply?
A security assessment check is needed before certain outbound data or personal information transfers. The record should screen PIPL export duties, the Data Export Security Assessment Measures, and newer cross-border data flow provisions before choosing a route.