Skip to content

Evidence request lists

China Personal Information Protection Law (PIPL)

Evidence request list. 52 controls, 52 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

PIPL: Cross-Border Provision (Ch III)

PIPL-Art38
Cross-Border Transfer Legal Mechanisms

Cross-border provision of PI requires one of: a CAC security assessment; a professional-body personal-information protection certification; a standard contract with the overseas recipient on CAC terms; or other conditions in law/CAC rules.

Artefacts an auditor will ask for
  • CAC security-assessment filing OR certification OR standard-contract records
  • Transfer mechanism mapped per data flow
Where this commonly fails
  • Cross-border transfer without an Art.38 mechanism
  • Standard contract not on CAC template
PIPL-Art39
Notice and Separate Consent for Cross-Border

Before cross-border provision the individual must be informed of the overseas recipient identity/contact, purpose, method, categories and the means to exercise rights against the recipient, and separate consent must be obtained.

Artefacts an auditor will ask for
  • Cross-border notice records
  • Separate-consent capture for transfers
Where this commonly fails
  • Transfer without separate consent
  • Recipient details not disclosed
PIPL-Art40
Data Localisation and Security Assessment for CIIOs

Critical information infrastructure operators and handlers reaching the CAC-specified volume must store PI collected/generated in China domestically; any cross-border provision must pass a CAC security assessment unless exempted.

Artefacts an auditor will ask for
  • Data-residency architecture for China-collected PI
  • CAC security-assessment evidence for any export
Where this commonly fails
  • China PI stored abroad without assessment
  • Volume threshold not monitored
PIPL-Art41
Foreign Authority Requests Require Approval

Without approval of the competent Chinese authority, handlers may not provide PI stored in China to foreign judicial or law-enforcement bodies.

Artefacts an auditor will ask for
  • Approval-request workflow for foreign legal demands
  • Log of foreign requests and responses
Where this commonly fails
  • PI disclosed to foreign authority without approval
PIPL-Art42
Blocklist of Overseas Recipients

The CAC may list overseas recipients that harm Chinese citizens' rights or national security and restrict or prohibit provision of PI to them.

Artefacts an auditor will ask for
  • Screening of overseas recipients against CAC blocklist
Where this commonly fails
  • No blocklist screening before transfer
PIPL-Art43
Reciprocal Countermeasures

China may take reciprocal measures against countries/regions that adopt discriminatory prohibitions or restrictions against China in personal-information protection.

Artefacts an auditor will ask for
  • Monitoring of reciprocal-measure determinations affecting transfers
Where this commonly fails
  • Transfers continue despite countermeasure designation

PIPL: General Provisions (Ch I)

PIPL-Art3
Scope and Extraterritorial Application

Applies to processing of personal information of natural persons within China, and to processing outside China that aims to provide products/services to individuals in China or to analyse/evaluate their conduct.

Artefacts an auditor will ask for
  • Data-flow map showing in-scope processing
  • Record of extraterritorial processing assessment
  • Designated domestic representative records where required
Where this commonly fails
  • Overseas processing aimed at China not recognised as in-scope
  • No assessment of analyse/evaluate trigger
PIPL-Art4
Definition of Personal Information and Handling

Personal information is any information related to identified or identifiable natural persons recorded electronically or otherwise, excluding anonymised information; handling includes collection, storage, use, processing, transmission, provision, disclosure and deletion.

Artefacts an auditor will ask for
  • Personal information inventory / RoPA
  • Anonymisation methodology and validation
  • Catalogue of handling activities
Where this commonly fails
  • Anonymisation claimed but data remains re-identifiable
  • Inventory omits transmission/provision/disclosure activities
PIPL-Art5
Lawfulness, Good Faith, Necessity

PI must be handled under principles of lawfulness, propriety, necessity and good faith; misleading, fraudulent or coercive methods are prohibited.

Artefacts an auditor will ask for
  • Lawful-handling policy
  • Necessity assessments per processing purpose
Where this commonly fails
  • Dark patterns / coercive consent flows
  • No necessity analysis on record
PIPL-Art6
Purpose Limitation and Minimisation

Handling must have a clear and reasonable purpose, be directly related to that purpose, and use the method with the least impact on individual rights; collection limited to the minimum scope for the purpose.

Artefacts an auditor will ask for
  • Documented purpose per data category
  • Minimisation review evidence
  • Data-collection forms mapped to purpose
Where this commonly fails
  • Over-collection beyond stated purpose
  • Purpose drift without new basis
PIPL-Art7
Openness and Transparency

Handlers must observe principles of openness and transparency, disclosing handling rules and clearly indicating purpose, method and scope.

Artefacts an auditor will ask for
  • Published privacy policy / handling rules
  • Version history of rules
Where this commonly fails
  • Handling rules not published or outdated
PIPL-Art8
Quality of Personal Information

PI handled must be accurate and kept up to date to avoid adverse effects on individual rights and interests from inaccurate or incomplete data.

Artefacts an auditor will ask for
  • Accuracy / correction procedures
  • Data-quality monitoring records
Where this commonly fails
  • No mechanism to keep PI current
PIPL-Art9
Security Responsibility of Handlers

Handlers are responsible for their handling activities and must adopt necessary measures to safeguard the security of the personal information handled.

Artefacts an auditor will ask for
  • Security responsibility assignment
  • Security measures inventory
Where this commonly fails
  • No accountable owner for PI security

PIPL: Handler Obligations (Ch V)

PIPL-Art51
Security Measures and Management System

Handlers must adopt measures to ensure handling complies with law and to prevent unauthorised access, leakage, tampering or loss: internal management systems and procedures, classified management, technical security (encryption, de-identification), access controls and operational authorisation, training, and an incident response plan.

Artefacts an auditor will ask for
  • Information-security management system docs
  • Access-control and authorisation matrix
  • Encryption/de-identification standards
  • Security training records
  • Incident response plan
Where this commonly fails
  • No classified management of PI
  • Encryption/de-identification absent
  • No incident response plan
PIPL-Art52
Designation of a DPO

Handlers reaching the CAC-specified processing volume must designate a person in charge of personal-information protection responsible for supervising handling and protection measures, and publish their contact details.

Artefacts an auditor will ask for
  • DPO appointment record
  • Published DPO contact details
  • DPO oversight reports
Where this commonly fails
  • No DPO where volume threshold met
  • DPO contact not published
PIPL-Art53
Domestic Representative for Overseas Handlers

Overseas handlers in scope of Art.3 must establish a dedicated entity or designate a representative in China to handle PI-protection matters and report their details to the authorities.

Artefacts an auditor will ask for
  • Domestic-representative appointment
  • Authority filing of representative details
Where this commonly fails
  • Extraterritorial handler with no domestic representative
PIPL-Art54
Regular Compliance Audits

Handlers must periodically audit their compliance of PI handling with laws and administrative regulations.

Artefacts an auditor will ask for
  • Compliance audit schedule and reports
  • Remediation tracking from audit findings
Where this commonly fails
  • No periodic compliance audit
PIPL-Art55
Personal Information Protection Impact Assessment

A PIPIA must be conducted in advance, and records kept, before handling sensitive PI, automated decision-making, entrusting/providing/disclosing PI, or cross-border provision.

Artefacts an auditor will ask for
  • PIPIA records for each trigger
  • PIPIA methodology
Where this commonly fails
  • No PIPIA before high-risk processing
  • PIPIA not retained
PIPL-Art56
PIPIA Content and Retention

The PIPIA must assess the lawfulness/necessity of purpose and method, the impact and risk to individuals, and whether protection measures are lawful, effective and proportionate; reports and records must be kept for at least three years.

Artefacts an auditor will ask for
  • PIPIA template covering Art.56 elements
  • Three-year PIPIA retention evidence
Where this commonly fails
  • PIPIA missing proportionality analysis
  • Records kept under three years
PIPL-Art57
Breach Remediation and Notification

On a leak, tampering or loss (or risk thereof) handlers must immediately take remedial measures and notify the authorities and affected individuals, stating the categories/cause/harm, measures taken and mitigations available, and handler contact; notice to individuals may be withheld only if measures effectively avoid harm, subject to authority direction.

Artefacts an auditor will ask for
  • Breach response procedure
  • Authority and individual notification templates and logs
  • Remediation evidence
Where this commonly fails
  • No breach notification to authority/individuals
  • Notice withheld without effective-mitigation basis
PIPL-Art58
Large Platform Obligations

Handlers of important internet platforms with large user numbers and complex business must establish an independent oversight body, formulate platform rules, suspend service to serious violators, and publish regular PI-protection social-responsibility reports.

Artefacts an auditor will ask for
  • Independent oversight body charter
  • Published platform rules
  • Social-responsibility report
Where this commonly fails
  • No independent oversight body for large platform

PIPL: Individual Rights (Ch IV)

PIPL-Art44
Right to Know and Decide

Individuals have the right to know and to decide about the handling of their PI, and to restrict or refuse handling by others, unless law provides otherwise.

Artefacts an auditor will ask for
  • Rights request intake procedure
  • Restriction/objection handling records
Where this commonly fails
  • No mechanism to restrict or refuse handling
PIPL-Art45
Right to Access, Copy and Portability

Individuals may access and copy their PI from handlers (responded to promptly), and may request transfer of PI to a designated handler where conditions set by the CAC are met.

Artefacts an auditor will ask for
  • DSAR fulfilment logs with timeliness
  • Portability transfer mechanism
Where this commonly fails
  • Access requests not met promptly
  • No portability route
PIPL-Art46
Right to Correction and Completion

Individuals may request correction or completion of inaccurate or incomplete PI; handlers must verify and correct in a timely manner.

Artefacts an auditor will ask for
  • Correction request logs
  • Verification and update evidence
Where this commonly fails
  • Corrections not actioned timely
PIPL-Art47
Right to Deletion

Handlers must proactively delete PI where the purpose is achieved/impossible or no longer necessary, retention period expires, consent is withdrawn, handling violates law/agreement, or handling ceases; if deletion is technically hard, handling must stop except for storage and necessary security.

Artefacts an auditor will ask for
  • Deletion triggers mapped to Art.47 grounds
  • Deletion/cease-processing evidence
Where this commonly fails
  • No proactive deletion on purpose completion
  • Withdrawal does not trigger deletion
PIPL-Art48
Right to Explanation of Handling Rules

Individuals have the right to request that handlers explain their personal-information handling rules.

Artefacts an auditor will ask for
  • Procedure for explaining handling rules on request
Where this commonly fails
  • No process to explain handling rules
PIPL-Art49
Rights of Deceased's Next of Kin

Close relatives of a deceased natural person may, for their own lawful and legitimate interests, exercise access, copy, correction and deletion rights over the deceased's PI unless the deceased arranged otherwise.

Artefacts an auditor will ask for
  • Procedure for next-of-kin requests
  • Records honoring deceased's prior arrangements
Where this commonly fails
  • No process for deceased-person data requests
PIPL-Art50
Request-Handling Mechanism and Remedy

Handlers must establish convenient mechanisms to accept and handle rights requests; refusals must state reasons, and individuals may sue if a request is rejected.

Artefacts an auditor will ask for
  • Rights-request mechanism documentation
  • Refusal-reason records
  • Escalation/judicial-remedy notice
Where this commonly fails
  • Requests refused without stated reasons
  • No accessible request channel

PIPL: Legal Liability (Ch VII)

PIPL-Art66
Administrative Penalties

Unlawful handling is subject to rectification orders, warnings, confiscation of gains and fines; for serious violations the CAC may fine up to RMB 50 million or 5% of prior-year turnover, suspend business and revoke licences, with personal fines for responsible individuals.

Artefacts an auditor will ask for
  • Penalty exposure assessment
  • Records of regulator orders and remediation
Where this commonly fails
  • No awareness of Art.66 penalty thresholds
PIPL-Art69
Civil Liability (Fault Presumed)

Where handling infringes PI rights and causes harm, the handler is liable unless it proves it was not at fault; compensation is based on the individual's loss or the handler's gain.

Artefacts an auditor will ask for
  • Evidence of fault-rebutting controls (logs, approvals)
  • Liability/insurance assessment
Where this commonly fails
  • Inability to demonstrate fault-free handling
PIPL-Art70
Public Interest Litigation

Where a handler's violation harms the rights of many individuals, the procuratorate, consumer organisations and CAC-designated bodies may bring litigation in the public interest.

Artefacts an auditor will ask for
  • Awareness of collective-action exposure
Where this commonly fails
  • No tracking of mass-harm risk
PIPL-Art71
Public Security and Criminal Liability

Violations constituting public-security administration offences incur such penalties; conduct constituting a crime incurs criminal liability.

Artefacts an auditor will ask for
  • Escalation procedure for conduct with criminal exposure
Where this commonly fails
  • No linkage between PI violations and criminal-liability awareness

PIPL: PI Handling Rules (Ch II)

PIPL-Art13
Legal Bases for Handling

Handling is permitted only on one of the legal bases: individual consent; necessity for a contract or HR management; statutory duties/obligations; public health or emergency; news reporting/public interest within reasonable scope; already-disclosed information within reasonable scope; other circumstances provided by law.

Artefacts an auditor will ask for
  • Lawful-basis register mapping each purpose to an Art.13 ground
  • Contracts evidencing contractual-necessity basis
  • HR policies for employment basis
Where this commonly fails
  • Reliance on consent where another basis is required
  • No documented basis for a processing purpose
PIPL-Art14
Consent Requirements

Where consent is the basis it must be given voluntarily and explicitly by a fully informed individual; separate consent or written consent is required where laws/regulations so provide.

Artefacts an auditor will ask for
  • Consent capture records (timestamp, scope, version)
  • Separate-consent flows for designated processing
Where this commonly fails
  • Bundled or pre-ticked consent
  • Separate consent not obtained where required
PIPL-Art15
Right to Withdraw Consent

Individuals may withdraw consent; handlers must provide a convenient way to do so. Withdrawal does not affect prior lawful handling.

Artefacts an auditor will ask for
  • Withdrawal mechanism
  • Logs of withdrawal requests and downstream cessation
Where this commonly fails
  • No easy withdrawal path
  • Processing continues after withdrawal
PIPL-Art16
No Coerced Consent / No Service Refusal

Handlers may not refuse to provide products or services because an individual declines consent or withdraws it, unless the handling is necessary for providing the product or service.

Artefacts an auditor will ask for
  • Service-gating review
  • Necessity justification where service is conditioned on processing
Where this commonly fails
  • Service refused for declining non-essential processing
PIPL-Art17
Notice Content Before Handling

Before handling, individuals must be truthfully, accurately and fully informed of the handler identity/contact, purpose and method, categories handled and retention period, and the methods/procedures to exercise their rights.

Artefacts an auditor will ask for
  • Privacy notice mapped to Art.17 elements
  • Just-in-time notices at collection points
Where this commonly fails
  • Notice missing retention period or rights-exercise method
  • Notice not provided before handling
PIPL-Art19
Retention Period Limitation

Retention period must be the minimum necessary to achieve the handling purpose unless laws/regulations provide otherwise.

Artefacts an auditor will ask for
  • Retention schedule by data category
  • Deletion/anonymisation evidence at end of period
Where this commonly fails
  • Indefinite retention
  • No retention schedule
PIPL-Art20
Joint Handlers

Where two or more handlers jointly decide purpose and method they must agree their respective rights and obligations; they bear joint and several liability for infringement of individual rights.

Artefacts an auditor will ask for
  • Joint-handler agreements defining responsibilities
  • Liability allocation records
Where this commonly fails
  • No agreement between joint handlers
PIPL-Art21
Entrusted Handling (Processors)

When entrusting handling, the handler must agree purpose, period, method, categories and protection measures with, and supervise, the entrusted party; the entrusted party may not exceed the agreed scope and must return or delete PI when the entrustment ends; sub-entrustment requires consent.

Artefacts an auditor will ask for
  • Data-processing agreements with entrusted parties
  • Supervision/audit records
  • Return-or-delete evidence at contract end
Where this commonly fails
  • No DPA with processors
  • Sub-processing without consent
PIPL-Art22
Transfer Due to Merger or Restructuring

When PI is transferred due to merger, division, dissolution or bankruptcy, individuals must be notified of the recipient identity and contact; the recipient continues the original handler obligations and must obtain fresh consent to change purpose or method.

Artefacts an auditor will ask for
  • M&A data-transfer notice records
  • Recipient obligation continuity agreements
Where this commonly fails
  • No individual notification on corporate transfer
PIPL-Art23
Provision of PI to Third Parties

Providing PI to another handler requires informing individuals of the recipient identity/contact, purpose, method and categories, and obtaining separate consent; the recipient must handle within that scope.

Artefacts an auditor will ask for
  • Separate-consent records for third-party provision
  • Recipient list with purpose and categories
Where this commonly fails
  • Third-party sharing without separate consent
PIPL-Art24
Automated Decision-Making

Automated decision-making must be transparent and fair; no unreasonable differential treatment in transaction terms; decisions with major effect entitle individuals to an explanation and to refuse decisions made solely by automated means; push/marketing must offer a non-targeted option or opt-out.

Artefacts an auditor will ask for
  • Algorithm transparency documentation
  • Opt-out mechanism for targeted push
  • Records of explanations provided
Where this commonly fails
  • Price discrimination via profiling
  • No opt-out of automated decisions with major effect
PIPL-Art25
Public Disclosure Prohibited Without Consent

Handlers may not disclose the PI they handle unless they obtain separate consent.

Artefacts an auditor will ask for
  • Separate-consent records for any public disclosure
Where this commonly fails
  • PI published without separate consent
PIPL-Art26
Image Collection in Public Places

Image-collection and personal-identity-recognition equipment in public places may be installed only as needed for public security, with prominent notice; collected images/identity data may be used only for public-security purposes unless separate consent is obtained.

Artefacts an auditor will ask for
  • Signage/notice at collection points
  • Purpose-restriction policy for CCTV/biometric capture
Where this commonly fails
  • Surveillance data reused for non-security purposes
PIPL-Art27
Handling Already-Disclosed PI

Handlers may handle PI already lawfully disclosed within a reasonable scope unless the individual explicitly refuses; handling with major impact on rights requires consent.

Artefacts an auditor will ask for
  • Assessment of reasonable-scope handling of public PI
  • Opt-out honoring records
Where this commonly fails
  • Scraped public PI used beyond reasonable scope

PIPL: Sensitive PI (Ch II Sec 2)

PIPL-Art28
Sensitive PI Definition and Threshold

Sensitive PI is information that, if leaked or unlawfully used, may endanger personal dignity or safety, including biometrics, religious belief, specific identity, medical/health, financial accounts, location tracking, and any PI of minors under 14; it may be handled only for a specific purpose and sufficient necessity with strict protection.

Artefacts an auditor will ask for
  • Inventory flagging sensitive categories
  • Specific-purpose and necessity justification
Where this commonly fails
  • Sensitive PI handled on general consent
  • Minors' data not treated as sensitive
PIPL-Art29
Separate Consent for Sensitive PI

Handling sensitive PI on consent requires separate consent, and written consent where laws/regulations so provide.

Artefacts an auditor will ask for
  • Separate-consent capture for sensitive categories
  • Written-consent records where required
Where this commonly fails
  • Sensitive PI bundled into general consent
PIPL-Art30
Enhanced Notice for Sensitive PI

When handling sensitive PI, individuals must additionally be informed of the necessity and the impact on their rights and interests.

Artefacts an auditor will ask for
  • Sensitive-PI notice including necessity and impact statement
Where this commonly fails
  • Standard notice reused without necessity/impact disclosure
PIPL-Art31
Minors Under 14

Handling PI of minors under 14 requires the consent of a parent or guardian and a dedicated set of handling rules.

Artefacts an auditor will ask for
  • Age-gating mechanism
  • Guardian-consent records
  • Dedicated children's handling rules
Where this commonly fails
  • No guardian consent for under-14 data
  • No children-specific rules
PIPL-Art32
Sectoral and Administrative Restrictions

Where laws or administrative regulations set out restrictions, approvals or other conditions on handling sensitive PI, those provisions must be followed.

Artefacts an auditor will ask for
  • Sector-specific licence/approval records
Where this commonly fails
  • Sector restrictions not mapped or followed

PIPL: State Organs (Ch II Sec 3)

PIPL-Art35
State Organs Handling for Statutory Duties

State organs handling PI to fulfil statutory duties must do so within the scope and limits necessary, and must inform individuals and obtain consent unless an exemption applies or it would impede the performance of those duties.

Artefacts an auditor will ask for
  • Statutory-duty basis records
  • Notice/exemption assessment
Where this commonly fails
  • State-organ handling without scope limits
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the China Personal Information Protection Law (PIPL) framework page.