China Personal Information Protection Law (PIPL)
Evidence request list. 52 controls, 52 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
PIPL: Cross-Border Provision (Ch III)
Cross-border provision of PI requires one of: a CAC security assessment; a professional-body personal-information protection certification; a standard contract with the overseas recipient on CAC terms; or other conditions in law/CAC rules.
- CAC security-assessment filing OR certification OR standard-contract records
- Transfer mechanism mapped per data flow
- Cross-border transfer without an Art.38 mechanism
- Standard contract not on CAC template
Before cross-border provision the individual must be informed of the overseas recipient identity/contact, purpose, method, categories and the means to exercise rights against the recipient, and separate consent must be obtained.
- Cross-border notice records
- Separate-consent capture for transfers
- Transfer without separate consent
- Recipient details not disclosed
Critical information infrastructure operators and handlers reaching the CAC-specified volume must store PI collected/generated in China domestically; any cross-border provision must pass a CAC security assessment unless exempted.
- Data-residency architecture for China-collected PI
- CAC security-assessment evidence for any export
- China PI stored abroad without assessment
- Volume threshold not monitored
Without approval of the competent Chinese authority, handlers may not provide PI stored in China to foreign judicial or law-enforcement bodies.
- Approval-request workflow for foreign legal demands
- Log of foreign requests and responses
- PI disclosed to foreign authority without approval
The CAC may list overseas recipients that harm Chinese citizens' rights or national security and restrict or prohibit provision of PI to them.
- Screening of overseas recipients against CAC blocklist
- No blocklist screening before transfer
China may take reciprocal measures against countries/regions that adopt discriminatory prohibitions or restrictions against China in personal-information protection.
- Monitoring of reciprocal-measure determinations affecting transfers
- Transfers continue despite countermeasure designation
PIPL: General Provisions (Ch I)
Applies to processing of personal information of natural persons within China, and to processing outside China that aims to provide products/services to individuals in China or to analyse/evaluate their conduct.
- Data-flow map showing in-scope processing
- Record of extraterritorial processing assessment
- Designated domestic representative records where required
- Overseas processing aimed at China not recognised as in-scope
- No assessment of analyse/evaluate trigger
Personal information is any information related to identified or identifiable natural persons recorded electronically or otherwise, excluding anonymised information; handling includes collection, storage, use, processing, transmission, provision, disclosure and deletion.
- Personal information inventory / RoPA
- Anonymisation methodology and validation
- Catalogue of handling activities
- Anonymisation claimed but data remains re-identifiable
- Inventory omits transmission/provision/disclosure activities
PI must be handled under principles of lawfulness, propriety, necessity and good faith; misleading, fraudulent or coercive methods are prohibited.
- Lawful-handling policy
- Necessity assessments per processing purpose
- Dark patterns / coercive consent flows
- No necessity analysis on record
Handling must have a clear and reasonable purpose, be directly related to that purpose, and use the method with the least impact on individual rights; collection limited to the minimum scope for the purpose.
- Documented purpose per data category
- Minimisation review evidence
- Data-collection forms mapped to purpose
- Over-collection beyond stated purpose
- Purpose drift without new basis
Handlers must observe principles of openness and transparency, disclosing handling rules and clearly indicating purpose, method and scope.
- Published privacy policy / handling rules
- Version history of rules
- Handling rules not published or outdated
PI handled must be accurate and kept up to date to avoid adverse effects on individual rights and interests from inaccurate or incomplete data.
- Accuracy / correction procedures
- Data-quality monitoring records
- No mechanism to keep PI current
Handlers are responsible for their handling activities and must adopt necessary measures to safeguard the security of the personal information handled.
- Security responsibility assignment
- Security measures inventory
- No accountable owner for PI security
PIPL: Handler Obligations (Ch V)
Handlers must adopt measures to ensure handling complies with law and to prevent unauthorised access, leakage, tampering or loss: internal management systems and procedures, classified management, technical security (encryption, de-identification), access controls and operational authorisation, training, and an incident response plan.
- Information-security management system docs
- Access-control and authorisation matrix
- Encryption/de-identification standards
- Security training records
- Incident response plan
- No classified management of PI
- Encryption/de-identification absent
- No incident response plan
Handlers reaching the CAC-specified processing volume must designate a person in charge of personal-information protection responsible for supervising handling and protection measures, and publish their contact details.
- DPO appointment record
- Published DPO contact details
- DPO oversight reports
- No DPO where volume threshold met
- DPO contact not published
Overseas handlers in scope of Art.3 must establish a dedicated entity or designate a representative in China to handle PI-protection matters and report their details to the authorities.
- Domestic-representative appointment
- Authority filing of representative details
- Extraterritorial handler with no domestic representative
Handlers must periodically audit their compliance of PI handling with laws and administrative regulations.
- Compliance audit schedule and reports
- Remediation tracking from audit findings
- No periodic compliance audit
A PIPIA must be conducted in advance, and records kept, before handling sensitive PI, automated decision-making, entrusting/providing/disclosing PI, or cross-border provision.
- PIPIA records for each trigger
- PIPIA methodology
- No PIPIA before high-risk processing
- PIPIA not retained
The PIPIA must assess the lawfulness/necessity of purpose and method, the impact and risk to individuals, and whether protection measures are lawful, effective and proportionate; reports and records must be kept for at least three years.
- PIPIA template covering Art.56 elements
- Three-year PIPIA retention evidence
- PIPIA missing proportionality analysis
- Records kept under three years
On a leak, tampering or loss (or risk thereof) handlers must immediately take remedial measures and notify the authorities and affected individuals, stating the categories/cause/harm, measures taken and mitigations available, and handler contact; notice to individuals may be withheld only if measures effectively avoid harm, subject to authority direction.
- Breach response procedure
- Authority and individual notification templates and logs
- Remediation evidence
- No breach notification to authority/individuals
- Notice withheld without effective-mitigation basis
Handlers of important internet platforms with large user numbers and complex business must establish an independent oversight body, formulate platform rules, suspend service to serious violators, and publish regular PI-protection social-responsibility reports.
- Independent oversight body charter
- Published platform rules
- Social-responsibility report
- No independent oversight body for large platform
PIPL: Individual Rights (Ch IV)
Individuals have the right to know and to decide about the handling of their PI, and to restrict or refuse handling by others, unless law provides otherwise.
- Rights request intake procedure
- Restriction/objection handling records
- No mechanism to restrict or refuse handling
Individuals may access and copy their PI from handlers (responded to promptly), and may request transfer of PI to a designated handler where conditions set by the CAC are met.
- DSAR fulfilment logs with timeliness
- Portability transfer mechanism
- Access requests not met promptly
- No portability route
Individuals may request correction or completion of inaccurate or incomplete PI; handlers must verify and correct in a timely manner.
- Correction request logs
- Verification and update evidence
- Corrections not actioned timely
Handlers must proactively delete PI where the purpose is achieved/impossible or no longer necessary, retention period expires, consent is withdrawn, handling violates law/agreement, or handling ceases; if deletion is technically hard, handling must stop except for storage and necessary security.
- Deletion triggers mapped to Art.47 grounds
- Deletion/cease-processing evidence
- No proactive deletion on purpose completion
- Withdrawal does not trigger deletion
Individuals have the right to request that handlers explain their personal-information handling rules.
- Procedure for explaining handling rules on request
- No process to explain handling rules
Close relatives of a deceased natural person may, for their own lawful and legitimate interests, exercise access, copy, correction and deletion rights over the deceased's PI unless the deceased arranged otherwise.
- Procedure for next-of-kin requests
- Records honoring deceased's prior arrangements
- No process for deceased-person data requests
Handlers must establish convenient mechanisms to accept and handle rights requests; refusals must state reasons, and individuals may sue if a request is rejected.
- Rights-request mechanism documentation
- Refusal-reason records
- Escalation/judicial-remedy notice
- Requests refused without stated reasons
- No accessible request channel
PIPL: Legal Liability (Ch VII)
Unlawful handling is subject to rectification orders, warnings, confiscation of gains and fines; for serious violations the CAC may fine up to RMB 50 million or 5% of prior-year turnover, suspend business and revoke licences, with personal fines for responsible individuals.
- Penalty exposure assessment
- Records of regulator orders and remediation
- No awareness of Art.66 penalty thresholds
Where handling infringes PI rights and causes harm, the handler is liable unless it proves it was not at fault; compensation is based on the individual's loss or the handler's gain.
- Evidence of fault-rebutting controls (logs, approvals)
- Liability/insurance assessment
- Inability to demonstrate fault-free handling
Where a handler's violation harms the rights of many individuals, the procuratorate, consumer organisations and CAC-designated bodies may bring litigation in the public interest.
- Awareness of collective-action exposure
- No tracking of mass-harm risk
Violations constituting public-security administration offences incur such penalties; conduct constituting a crime incurs criminal liability.
- Escalation procedure for conduct with criminal exposure
- No linkage between PI violations and criminal-liability awareness
PIPL: PI Handling Rules (Ch II)
Handling is permitted only on one of the legal bases: individual consent; necessity for a contract or HR management; statutory duties/obligations; public health or emergency; news reporting/public interest within reasonable scope; already-disclosed information within reasonable scope; other circumstances provided by law.
- Lawful-basis register mapping each purpose to an Art.13 ground
- Contracts evidencing contractual-necessity basis
- HR policies for employment basis
- Reliance on consent where another basis is required
- No documented basis for a processing purpose
Where consent is the basis it must be given voluntarily and explicitly by a fully informed individual; separate consent or written consent is required where laws/regulations so provide.
- Consent capture records (timestamp, scope, version)
- Separate-consent flows for designated processing
- Bundled or pre-ticked consent
- Separate consent not obtained where required
Individuals may withdraw consent; handlers must provide a convenient way to do so. Withdrawal does not affect prior lawful handling.
- Withdrawal mechanism
- Logs of withdrawal requests and downstream cessation
- No easy withdrawal path
- Processing continues after withdrawal
Handlers may not refuse to provide products or services because an individual declines consent or withdraws it, unless the handling is necessary for providing the product or service.
- Service-gating review
- Necessity justification where service is conditioned on processing
- Service refused for declining non-essential processing
Before handling, individuals must be truthfully, accurately and fully informed of the handler identity/contact, purpose and method, categories handled and retention period, and the methods/procedures to exercise their rights.
- Privacy notice mapped to Art.17 elements
- Just-in-time notices at collection points
- Notice missing retention period or rights-exercise method
- Notice not provided before handling
Retention period must be the minimum necessary to achieve the handling purpose unless laws/regulations provide otherwise.
- Retention schedule by data category
- Deletion/anonymisation evidence at end of period
- Indefinite retention
- No retention schedule
Where two or more handlers jointly decide purpose and method they must agree their respective rights and obligations; they bear joint and several liability for infringement of individual rights.
- Joint-handler agreements defining responsibilities
- Liability allocation records
- No agreement between joint handlers
When entrusting handling, the handler must agree purpose, period, method, categories and protection measures with, and supervise, the entrusted party; the entrusted party may not exceed the agreed scope and must return or delete PI when the entrustment ends; sub-entrustment requires consent.
- Data-processing agreements with entrusted parties
- Supervision/audit records
- Return-or-delete evidence at contract end
- No DPA with processors
- Sub-processing without consent
When PI is transferred due to merger, division, dissolution or bankruptcy, individuals must be notified of the recipient identity and contact; the recipient continues the original handler obligations and must obtain fresh consent to change purpose or method.
- M&A data-transfer notice records
- Recipient obligation continuity agreements
- No individual notification on corporate transfer
Providing PI to another handler requires informing individuals of the recipient identity/contact, purpose, method and categories, and obtaining separate consent; the recipient must handle within that scope.
- Separate-consent records for third-party provision
- Recipient list with purpose and categories
- Third-party sharing without separate consent
Automated decision-making must be transparent and fair; no unreasonable differential treatment in transaction terms; decisions with major effect entitle individuals to an explanation and to refuse decisions made solely by automated means; push/marketing must offer a non-targeted option or opt-out.
- Algorithm transparency documentation
- Opt-out mechanism for targeted push
- Records of explanations provided
- Price discrimination via profiling
- No opt-out of automated decisions with major effect
Handlers may not disclose the PI they handle unless they obtain separate consent.
- Separate-consent records for any public disclosure
- PI published without separate consent
Image-collection and personal-identity-recognition equipment in public places may be installed only as needed for public security, with prominent notice; collected images/identity data may be used only for public-security purposes unless separate consent is obtained.
- Signage/notice at collection points
- Purpose-restriction policy for CCTV/biometric capture
- Surveillance data reused for non-security purposes
Handlers may handle PI already lawfully disclosed within a reasonable scope unless the individual explicitly refuses; handling with major impact on rights requires consent.
- Assessment of reasonable-scope handling of public PI
- Opt-out honoring records
- Scraped public PI used beyond reasonable scope
PIPL: Sensitive PI (Ch II Sec 2)
Sensitive PI is information that, if leaked or unlawfully used, may endanger personal dignity or safety, including biometrics, religious belief, specific identity, medical/health, financial accounts, location tracking, and any PI of minors under 14; it may be handled only for a specific purpose and sufficient necessity with strict protection.
- Inventory flagging sensitive categories
- Specific-purpose and necessity justification
- Sensitive PI handled on general consent
- Minors' data not treated as sensitive
Handling sensitive PI on consent requires separate consent, and written consent where laws/regulations so provide.
- Separate-consent capture for sensitive categories
- Written-consent records where required
- Sensitive PI bundled into general consent
When handling sensitive PI, individuals must additionally be informed of the necessity and the impact on their rights and interests.
- Sensitive-PI notice including necessity and impact statement
- Standard notice reused without necessity/impact disclosure
Handling PI of minors under 14 requires the consent of a parent or guardian and a dedicated set of handling rules.
- Age-gating mechanism
- Guardian-consent records
- Dedicated children's handling rules
- No guardian consent for under-14 data
- No children-specific rules
Where laws or administrative regulations set out restrictions, approvals or other conditions on handling sensitive PI, those provisions must be followed.
- Sector-specific licence/approval records
- Sector restrictions not mapped or followed
PIPL: State Organs (Ch II Sec 3)
State organs handling PI to fulfil statutory duties must do so within the scope and limits necessary, and must inform individuals and obtain consent unless an exemption applies or it would impede the performance of those duties.
- Statutory-duty basis records
- Notice/exemption assessment
- State-organ handling without scope limits
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the China Personal Information Protection Law (PIPL) framework page.