China Personal Information Protection Law (PIPL)
What is China Personal Information Protection Law (PIPL)?
China's comprehensive personal information protection statute (effective 1 November 2021), administered by the Cyberspace Administration of China. Establishes legal bases for handling personal information, sensitive-PI and minors' rules, cross-border transfer mechanisms, individual rights, handler obligations (PIPIA, DPO, breach notification, audits) and legal liability.. It comprises 52 controls organised across 8 domains, and applies in People's Republic of China.
How China Personal Information Protection Law (PIPL) maps to other frameworks
All 52 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 8 domains China Personal Information Protection Law (PIPL) groups its controls into
Frameworks that share controls with China Personal Information Protection Law (PIPL)
Each of these has at least one control mapped to a control in China Personal Information Protection Law (PIPL). The number is how many China Personal Information Protection Law (PIPL) controls are shared, counted from the mapping graph.
Where China Personal Information Protection Law (PIPL) overlaps with the standards you already hold
What China Personal Information Protection Law (PIPL) means in your sector
What China Personal Information Protection Law (PIPL) means for your job
Questions people ask about China Personal Information Protection Law (PIPL)
What is China Personal Information Protection Law?
How many controls does China Personal Information Protection Law have?
Where does China Personal Information Protection Law apply?
What frameworks does China Personal Information Protection Law map to?
How do I get started with China Personal Information Protection Law compliance?
Query China Personal Information Protection Law (PIPL) programmatically
China Personal Information Protection Law (PIPL), its 52 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
China Personal Information Protection Law (PIPL) API reference and MCP config →What China Personal Information Protection Law (PIPL) requires, control by control
Each page carries the requirement text for one China Personal Information Protection Law (PIPL) control and what an assessor expects to see as evidence.
- PIPL-ART13 Legal Bases for Handling
- PIPL-ART14 Consent Requirements
- PIPL-ART15 Right to Withdraw Consent
- PIPL-ART16 No Coerced Consent / No Service Refusal
- PIPL-ART17 Notice Content Before Handling
- PIPL-ART19 Retention Period Limitation
- PIPL-ART20 Joint Handlers
- PIPL-ART21 Entrusted Handling (Processors)
- PIPL-ART22 Transfer Due to Merger or Restructuring
- PIPL-ART23 Provision of PI to Third Parties
How ready are you for China Personal Information Protection Law (PIPL)?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.