The processor must use safeguards suited to the purpose, method, categories, effect on rights, and security risk. Article 51 lists internal rules, classification, appropriate encryption or de-identification, access controls, staff training, and an incident plan. Conduct periodic compliance audits. PIPL does not state one audit interval, so set and retain a risk-based schedule while checking any later or sector-specific rules that apply.
Complete a PIPIA before processing sensitive information, automated decision-making, entrusted processing, providing information to another processor, public disclosure, overseas provision, or other processing with a major effect on individual rights. Assess legality, necessity, effect, risk, and the adequacy of safeguards, and keep the assessment and processing record for at least three years.