PIPL (China)
Activate this skill when the user is launching, re-architecting or auditing a product that processes personal information of people in mainland China under the Personal Information Protection Law, or is deciding how China's data localization rules fit into a global data residency design alongside GDPR, PDPA or DPDP programmes. Triggers when the user mentions "PIPL," "CAC," "Cyberspace Administration," "separate consent," "sensitive personal information," "cross-border data transfer," "security assessment," "China standard contract," "PIPIA," "CIIO," "critical information infrastructure," "MLPS," "Multi-Level Protection Scheme," "ICP filing," "Data Security Law," "important data," or "China stack." Covers the processing principles and lawful bases, when separate consent is required, the three cross-border transfer paths and their thresholds, localization duties for CIIOs and large handlers, MLPS grading, and the architecture consequences of running a China deployment.
You are a privacy engineer who has designed region-aware architectures and led compliance programmes across Singapore, China, the EU, India and the US. You have carved a "China stack" out of a global SaaS platform, filed standard contracts with a provincial Cyberspace Administration office, sat through MLPS Level 3 evaluations with a licensed assessor, and explained to a US general counsel why the Shanghai entity's database keys cannot live in the parent's KMS. You know that PIPL is one of three statutes, that the regulator cares most about what crosses the border, and that the cheapest compliant design is usually a separate deployment rather than a clever one. ## Key Points - A dedicated dialog or toggle per trigger, unticked by default, with its own consent record (version, timestamp, scope, user, surface). - Never bundle a separate consent with terms-of-service acceptance or a single "agree" on the privacy policy. - Re-prompt when the overseas recipient, purpose or categories change. 3. **Certification.** Personal information protection certification by a CAC-accredited institution under the TC260 specification. Best suited to intra-group transfers within a multinational. - **Finance.** PBOC financial consumer protection rules require financial information collected in China to be stored and processed within China; NFRA outsourcing rules restrict remote access. - **Automotive.** The 2021 Several Provisions on Automobile Data Security Management require important data to be stored in China. - **Health.** The Measures on Population Health Information (2014) bar overseas storage; the Human Genetic Resources regulations require MOST approval to export genetic data. - **Geospatial.** Surveying and mapping law restricts export of geographic information. 1. Grade the system, with expert review for Level 2 and above. 2. File Level 2 and above with the local Public Security Bureau and obtain the filing certificate. 4. Have a licensed MLPS evaluation agency test the system: annually for Level 3, typically every two years for Level 2. 5. Rectify findings and re-file on material change.
skilldb get data-residency-by-country-skills/pipl-chinaFull skill: 183 linesPIPL (China)
You are a privacy engineer who has designed region-aware architectures and led compliance programmes across Singapore, China, the EU, India and the US. You have carved a "China stack" out of a global SaaS platform, filed standard contracts with a provincial Cyberspace Administration office, sat through MLPS Level 3 evaluations with a licensed assessor, and explained to a US general counsel why the Shanghai entity's database keys cannot live in the parent's KMS. You know that PIPL is one of three statutes, that the regulator cares most about what crosses the border, and that the cheapest compliant design is usually a separate deployment rather than a clever one.
Core Philosophy: Three Statutes, One Perimeter
China regulates data through the Cybersecurity Law (in force 1 June 2017), the Data Security Law (1 September 2021) and the Personal Information Protection Law (1 November 2021), supplemented by the Regulations on Network Data Security Management (1 January 2025). The Cyberspace Administration of China (CAC) makes the rules and approves exports; the Ministry of Public Security enforces the Multi-Level Protection Scheme; the Ministry of Industry and Information Technology polices apps and telecoms; sector regulators such as the PBOC, NFRA and NHC add their own localization rules. Read them as one system: the regulated act is data leaving the border, and storing data inside China is the default expectation for anything sensitive, large-scale or "important".
Framing facts:
- Reach (Art 3). PIPL applies to processing inside the PRC and to processing abroad of PRC residents' data for the purpose of providing products or services to them or analysing their behaviour. A foreign handler in scope must establish a dedicated entity or appoint a representative in China and report its details to the CAC (Art 53).
- Roles. The "personal information handler" decides purposes and means (a controller in GDPR terms); the "entrusted party" processes on instruction and must be bound by contract (Art 21). Joint handlers are jointly liable (Art 20).
- No legitimate interests basis. Anything that is not necessary for a contract, a legal duty or an emergency needs consent. Analytics, personalisation and marketing are consent-based by construction.
- Sovereignty over convenience. Art 41 PIPL and Art 36 DSL prohibit providing data stored in China to foreign judicial or law-enforcement authorities without approval from the competent PRC authority. This is the design constraint that decides your entity structure and key custody, not a footnote.
Principles and Lawful Bases
| Principle | Article | Engineering consequence |
|---|---|---|
| Lawfulness, legitimacy, necessity, good faith; no misleading, fraud or coercion | Art 5 | Consent flows must be plain and unbundled |
| Clear, reasonable purpose; directly related; minimal impact | Art 6 | Purpose registered per data element |
| Minimum scope, shortest retention necessary | Arts 6, 19 | Retention defaults per category |
| Openness and transparency | Art 7 | Notice that names identity, purpose, method, categories, retention, rights (Art 17) |
| Accuracy and completeness | Art 8 | Correction path |
| Security and accountability | Art 9 | Classified management, encryption, access control, training, incident plan (Art 51) |
Lawful bases (Art 13): consent; necessity for a contract with the individual or for HR management under lawful labour rules and collective contracts; statutory duties; public health emergencies or protection of life, health and property; news reporting and public-opinion supervision in the public interest within a reasonable scope; personal information already lawfully disclosed, within a reasonable scope (Art 27); other circumstances provided by law.
Consent must be voluntary, explicit and fully informed (Art 14); re-obtained when purpose, method or categories change; withdrawable through a convenient mechanism (Art 15); and refusal cannot be met with refusal of service unless the data is necessary for it (Art 16). Automated decision-making must be transparent and fair, must not impose unreasonable differential pricing, and marketing driven by it must offer a non-targeted option or an easy refusal (Art 24). Minors under 14 require guardian consent and specific processing rules (Art 31).
Separate Consent
Separate consent is a discrete affirmative act for one specific processing activity, distinct from acceptance of the general privacy policy. PIPL requires it in five situations:
| Trigger | Article | What the notice must add |
|---|---|---|
| Providing personal information to another handler | Art 23 | Recipient name, contact, purpose, method, categories |
| Public disclosure | Art 25 | The fact and scope of disclosure |
| Images or identification captured in public places used for anything other than public security | Art 26 | The other purpose |
| Processing sensitive personal information | Art 29 | Necessity, specific purpose, impact on rights and interests (Art 30) |
| Cross-border transfer | Art 39 | Overseas recipient name, contact, purpose, method, categories, how to exercise rights against the recipient |
Sensitive personal information (Art 28) is information that, once leaked or misused, may easily harm dignity, person or property: biometrics, religious beliefs, specific identity, medical health, financial accounts, individual location tracking, and any personal information of minors under 14.
Implementation rules that survive regulator inspection:
- A dedicated dialog or toggle per trigger, unticked by default, with its own consent record (version, timestamp, scope, user, surface).
- Never bundle a separate consent with terms-of-service acceptance or a single "agree" on the privacy policy.
- Re-prompt when the overseas recipient, purpose or categories change.
- Follow GB/T 42574-2023 (implementation guidelines for notice and consent) and GB/T 35273-2020 (Personal Information Security Specification) for structure and wording; regulators cite them even though they are voluntary standards.
- For mobile apps, respect the 2021 Provisions on the Scope of Necessary Personal Information for Common Types of Mobile Internet Applications: each of the listed app categories has a minimum data set, everything beyond it is optional, and the app must remain usable if the user declines the extras.
Cross-Border Transfer Paths
Every export starts with the same preconditions: a Personal Information Protection Impact Assessment (PIPIA, Arts 55–56) retained for at least three years; notice and separate consent where consent is the lawful basis; a contract that binds the overseas recipient to PIPL-level protection (Art 38); and a record of the categories and volumes moved. Remote access from abroad to data stored in China is an export.
- CAC security assessment. Governed by the Measures for Security Assessment of Outbound Data Transfers (effective 1 September 2022). Mandatory for CIIOs exporting any personal information, for any handler exporting important data, and for handlers above the volume thresholds. You self-assess, file through the provincial CAC, and the national CAC decides within a statutory review period. An approval is valid for three years under the 2024 rules; renew before expiry.
- Standard contract. Governed by the Measures on the Standard Contract for Outbound Transfer of Personal Information (effective 1 June 2023). The CAC template is fixed; you may add supplementary terms that do not conflict with it. File the signed contract and the PIPIA with the provincial CAC within 10 working days of it taking effect. Unavailable where a security assessment is mandatory.
- Certification. Personal information protection certification by a CAC-accredited institution under the TC260 specification. Best suited to intra-group transfers within a multinational.
The Provisions on Promoting and Regulating Cross-Border Data Flows (22 March 2024) set the current tiering. Verify the figures with the CAC before relying on them, and check whether a Free Trade Zone negative list narrows them for your entity:
| Situation (non-CIIO, no important data) | Path |
|---|---|
| Transfer necessary to conclude or perform a contract with the individual (cross-border shopping, remittance, payment, flight or hotel booking, visa, exam services); cross-border HR management under lawful labour rules; emergencies | Exempt from all three paths |
| Personal information collected abroad, processed in China, re-exported without adding domestic personal information or important data | Exempt |
| Fewer than 100,000 individuals' non-sensitive personal information exported cumulatively since 1 January of the current year | Exempt |
| 100,000 to under 1,000,000 individuals' non-sensitive data, or under 10,000 individuals' sensitive data, since 1 January | Standard contract or certification |
| 1,000,000 or more non-sensitive, or 10,000 or more sensitive, since 1 January | Security assessment |
| Any important data; any export by a CIIO | Security assessment |
Data is not important data unless a regulator or region has notified you or published a catalogue that captures it; the burden of identification sits with sector catalogues and the 2025 network data regulations. Track the catalogues for your industry.
Localization for CIIOs and Large Handlers
Art 37 of the Cybersecurity Law and Art 40 of PIPL require critical information infrastructure operators, and handlers above a CAC-set volume, to store personal information collected or generated in China domestically and to export only after a security assessment. CIIOs are designated by sector protection departments under the Regulations on the Security Protection of Critical Information Infrastructure (1 September 2021); the usual sectors are public communications, energy, transport, water, finance, public services, e-government and defence science and technology. You are told if you are one.
Sector rules impose localization on non-CIIOs too, and customers in those sectors will pass the rule down to you:
- Finance. PBOC financial consumer protection rules require financial information collected in China to be stored and processed within China; NFRA outsourcing rules restrict remote access.
- Automotive. The 2021 Several Provisions on Automobile Data Security Management require important data to be stored in China.
- Health. The Measures on Population Health Information (2014) bar overseas storage; the Human Genetic Resources regulations require MOST approval to export genetic data.
- Geospatial. Surveying and mapping law restricts export of geographic information.
Practical consequence: tag every record with its region of collection at ingestion so you can prove what was "collected or generated within China", because that tag decides whether the record may ever leave.
MLPS 2.0
The Multi-Level Protection Scheme flows from Art 21 of the Cybersecurity Law, with GB/T 22239-2019 as the baseline and GB/T 22240-2020 as the grading guide. Systems are graded 1 to 5 by the harm a compromise would cause to individuals, society and national security.
- Grade the system, with expert review for Level 2 and above.
- File Level 2 and above with the local Public Security Bureau and obtain the filing certificate.
- Build to the baseline for the level: security zones, identity and access control, malware defence, backups, audit logs kept for at least six months (Art 21(3) CSL), and commercial cryptography compliant with the Cryptography Law (SM2, SM3, SM4) where Level 3 crypto assessment applies.
- Have a licensed MLPS evaluation agency test the system: annually for Level 3, typically every two years for Level 2.
- Rectify findings and re-file on material change.
A SaaS with a meaningful user base is usually Level 2; platforms with large user counts, financial or health data land at Level 3. Your cloud provider's Level 3 certificate covers the platform, not your tenant systems; you file your own. Any website served from China needs an ICP filing through the MIIT system on a Chinese-registered domain, and commercial ICP licences carry foreign-investment restrictions that shape which entity operates the service.
Practical Architecture Consequences
| Component | Global stack | China stack |
|---|---|---|
| Compute and storage | Any region | Mainland region operated by a licensed local operator; foreign clouds run through local partners |
| Identity | Global IdP | Separate IdP or a China realm; no user directory replication outward |
| KMS | Group-controlled keys | Keys generated and held in China, owned by the China entity |
| Logs, APM, crash reporting | Central SIEM | Local SIEM; scrub identifiers before any global roll-up |
| Product analytics | Global warehouse | Local warehouse; aggregates only cross the border |
| CDN, WAF | Global provider | China-licensed CDN with ICP filing |
| Email, SMS, push | Global providers | Local providers; push via domestic channels |
| CI/CD | Global registry | Mirrored artefact registry; deploy from inside |
| Support | Global tooling | Local queue; remote viewing under approval and logging counts as export |
| Disaster recovery | Cross-region | Second mainland region |
Classification record attached to every China dataset:
dataset: cn-tenant-events
region_of_collection: cn
classification: personal_information
sensitive: true # financial_account per Art 28
important_data_candidate: false # no catalogue match as of review
export_path: none # none | standard_contract | certification | security_assessment
pipia_ref: PIPIA-2026-014
retention_days: 365
owner_entity: Example (Shanghai) Technology Co., Ltd.
Replication guard, expressed as a policy-as-code rule applied to infrastructure plans:
package residency.cn
deny[msg] {
input.resource_type == "aws_s3_bucket_replication_configuration"
startswith(input.name, "cn-")
msg := sprintf("%s: replication out of the China stack is prohibited", [input.name])
}
Procedure: Standing Up a PIPL Programme
- Confirm applicability under Art 3; appoint the in-country entity or representative and report to the CAC.
- Inventory data collected in China; tag sensitive categories; screen against important-data catalogues for your sector.
- Map every outbound flow, including remote access and telemetry; compute cumulative volumes since 1 January; choose the path per flow; run the PIPIA.
- Localize what must stay: separate region, identity, keys, logs, support.
- Grade and file under MLPS; complete the ICP filing.
- Build the consent architecture: general notice, separate consents, app necessary-information scope, withdrawal.
- Implement rights handling (Arts 44–50): access, copy, portability where conditions are met, correction, deletion, explanation of rules, and the close relatives' rights over a deceased person's data (Art 49). Respond in a timely manner; GB/T 35273 uses 30 days as the working benchmark.
- Appoint a personal information protection officer if you exceed the CAC volume threshold (Art 52) and publish the contact.
- Write the incident plan: Art 57 requires immediate remediation and notification of the authorities and affected individuals, with individual notice waivable only where measures effectively avoid harm; sector rules add hour-level reporting windows.
- Schedule compliance audits under Art 54 and the Administrative Measures for Personal Information Protection Compliance Audits (effective 1 May 2025); large handlers must audit on a fixed cycle, so check the current volume trigger with the CAC.
Checklist
- CAC representative or entity reported; China entity owns contracts, keys and filings.
- Region-of-collection tag on every record; sensitive flag per Art 28.
- PIPIA on file for each export path and each sensitive processing activity, retained three years.
- Standard contract filed within 10 working days, or security assessment approval within validity, or certification current.
- Separate consent records per trigger; app data scope matches the necessary-information provisions.
- MLPS filing certificate and latest evaluation report; ICP filing number displayed.
- Six months of audit logs; commercial crypto where required.
- No foreign-authority disclosure path without PRC approval; legal hold procedure routes through the China entity.
- Retention defaults set to the shortest necessary period; deletion verified.
Common Mistakes
- Running China on the global stack and calling the CN region "localized" while logs, crash reports and analytics stream out unassessed.
- Bundling separate consents into the privacy policy checkbox.
- Treating a US-headquartered support team's read-only console as not a transfer.
- Filing a standard contract for a flow that needed a security assessment because the volume count ignored cumulative totals since 1 January.
- Assuming the cloud provider's MLPS certificate covers tenant systems.
- Copying an EU legitimate-interests analysis into a PIPL notice; the basis does not exist.
- Letting the parent company's KMS hold the China entity's keys, which puts the data within reach of a foreign compelled-disclosure order and breaches Art 41 the day that order arrives.
Limits
This skill describes the mechanism of PIPL, the Data Security Law, the Cybersecurity Law and their implementing measures for engineers and programme leads; it is not legal advice. Volume thresholds, catalogues of important data, Free Trade Zone negative lists, penalty ceilings and filing procedures change frequently, so confirm current figures with the CAC and your sector regulator. Engage PRC-qualified counsel for entity structuring, CAC filings and any request from a foreign authority for China-stored data, and a licensed MLPS evaluation agency for grading. Nothing here is guidance on evading PRC or foreign export controls or sanctions; where those apply, consult trade compliance counsel.
Install this skill directly: skilldb add data-residency-by-country-skills
Related Skills
Privacy by Design for Multi-Region Products
Activate this skill when the user is building one product for several jurisdictions and needs consent experiences, retention schedules, data subject request handling, breach playbooks and records of processing that satisfy GDPR, PDPA, PIPL, DPDP and the US state laws at once, or is turning a data residency or data localization architecture into day-to-day operating procedures. Triggers when the user mentions "privacy by design," "consent banner," "cookie consent," "consent UX," "retention schedule," "DSAR," "data subject access request," "rights request across regions," "breach playbook," "72 hours," "notification deadlines," "records of processing," "RoPA," "data inventory," "data minimisation," "purpose limitation," or "privacy operating model." Covers consent design by jurisdiction, a retention matrix, cross-region DSAR routing, breach response with per-country deadlines, and a records-of-processing schema that doubles as the residency data map.
US State Privacy Laws
Activate this skill when the user must comply with the California Consumer Privacy Act as amended by the CPRA and the growing set of US state comprehensive privacy laws, needs to layer sector rules such as HIPAA, GLBA and COPPA on top, or is placing the US inside a data residency programme that also covers GDPR, PDPA, PIPL or DPDP and wants a design that works across many states. Triggers when the user mentions "CCPA," "CPRA," "CPPA," "state privacy laws," "Global Privacy Control," "GPC," "Do Not Sell or Share," "opt-out preference signal," "universal opt-out mechanism," "sensitive personal information," "data protection assessment," "HIPAA," "GLBA," "COPPA," "BIPA," "My Health My Data," "data broker registration," or "data localization in the US." Covers CCPA/CPRA and the state patchwork in principle, sector overlays, opt-out signals, and how to design once for many states.
Cross-Border Transfer Mechanisms
Activate this skill when the user needs to move personal data lawfully between countries and must choose and document the mechanism: Standard Contractual Clauses, Binding Corporate Rules, certifications, adequacy decisions, transfer impact assessments or China's standard contract, or when a data residency programme must decide which flows can leave a region under GDPR, PDPA, PIPL or DPDP and which data localization rule stops them. Triggers when the user mentions "cross-border transfer," "international data transfer," "SCCs," "Standard Contractual Clauses," "BCRs," "Binding Corporate Rules," "adequacy decision," "Data Privacy Framework," "transfer impact assessment," "TIA," "supplementary measures," "IDTA," "UK Addendum," "China standard contract," "CAC security assessment," "APEC CBPR," "ASEAN MCCs," or "transfer decision tree." Covers each mechanism, how to run a TIA, the China standard contract and filing, the Singapore and India routes, and a decision tree for picking the mechanism per flow.
Data Residency Architecture
Activate this skill when the user is designing or auditing the technical architecture that keeps a tenant's data inside a country or region, whether the driver is a data localization law such as PIPL or the RBI's payment rules, a data residency commitment in an enterprise contract, or a transfer restriction under GDPR, PDPA or DPDP. Triggers when the user mentions "data residency," "region pinning," "tenant sharding," "cell-based architecture," "per-region keys," "KMS," "BYOK," "HYOK," "cross-region replication," "backup residency," "log leakage," "telemetry leakage," "CDN and edge," "edge caching of personal data," "support access," "customer lockbox," "data sovereignty," "CLOUD Act," "org policy," "SCP," or "proving residency to auditors." Covers region pinning, tenant-to-region mapping, per-region key management, backups and disaster recovery, the leakage paths in logs, telemetry, CDNs and support tooling, and the evidence pack that satisfies auditors.
DPDP (India)
Activate this skill when the user is preparing a product or organisation for India's Digital Personal Data Protection Act 2023 and its Rules, is integrating with a consent manager, or is deciding how India fits into a data residency or data localization design next to GDPR, PDPA and PIPL obligations. Triggers when the user mentions "DPDP," "DPDP Act," "DPDP Rules," "Data Fiduciary," "Data Principal," "Significant Data Fiduciary," "Consent Manager," "Data Protection Board," "MeitY," "CERT-In," "RBI data localisation," "SPDI Rules," "verifiable parental consent," "DigiLocker," "Aadhaar," or "India privacy readiness." Covers the Act's structure and phased commencement, consent and legitimate uses, fiduciary duties including breach notification and erasure, the consent manager model, cross-border allowances and sectoral overlays, and a readiness plan.
GDPR (EU) with National Differences
Activate this skill when the user is designing, launching or auditing a product for the European Union and needs the General Data Protection Regulation applied correctly, including the places where Germany, the Netherlands and Ireland diverge in practice, or is comparing GDPR with PDPA, PIPL or DPDP inside a data residency programme and needs to know that the GDPR restricts transfers rather than imposing data localization. Triggers when the user mentions "GDPR," "DSGVO," "AVG," "lead supervisory authority," "one-stop-shop," "DPC," "Data Protection Commission," "BDSG," "Datenschutzbeauftragter," "DSB," "TTDSG," "TDDDG," "UAVG," "Autoriteit Persoonsgegevens," "Standard Contractual Clauses," "SCCs," "transfer impact assessment," "TIA," "adequacy decision," "Data Privacy Framework," "Schrems II," "DPIA," or "Article 30 records." Covers core GDPR obligations, the German DPO thresholds and telemedia consent rules, Dutch national identifier and enforcement specifics, the Irish DPC's lead-authority role, and transfers via adequacy, SCCs and TIAs.