Solutions / By Regulation

China PIPL compliance for global enterprises.

Manage separate consent, cross-border transfer mechanisms, and PIPIA assessments required by China's Personal Information Protection Law — without slowing down your business in the region.

PIPL at a glance
¥50M
or 5% of prior year turnover for serious violations
2021
PIPL effective November 1
3
approved cross-border transfer mechanisms
Local rep.
required for offshore controllers

What is China PIPL?

Overview

China's Personal Information Protection Law (PIPL), effective November 1, 2021, is China's comprehensive data protection law. It governs the processing of personal information of natural persons within China and applies extraterritorially. PIPL emphasizes informed and 'separate' consent, strict cross-border transfer rules, and integrates with the Cybersecurity Law (CSL) and Data Security Law (DSL).

Who must comply

Typical applicability thresholds

  • Any organization processing PI of individuals in China
  • Extraterritorial: foreign entities offering products/services to or analyzing behavior of PRC individuals
  • Critical Information Infrastructure Operators' face additional obligations
  • Foreign processors must designate a PRC representative or establishment

Key requirements

What PIPL expects from your organization.

Lawful basis & separate consent

Identify a lawful basis (consent, contract, legal duty, etc.) and obtain explicit 'separate consent' for sensitive PI, cross-border transfers, public disclosure, and sharing with other handlers.

Cross-border transfer mechanism

Use one of: CAC security assessment (high volume / sensitive / CIIO), CAC-issued Standard Contract, or PI Protection Certification — and conduct a transfer impact assessment.

Personal Information Protection Impact Assessments (PIPIA)

Conduct PIPIAs before sensitive PI processing, automated decision-making, sharing/entrusting, public disclosure, and cross-border transfers; retain records for 3+ years.

Individual rights

Provide rights to know, decide, restrict, refuse, access, copy, port (where conditions met), correct, and delete personal information; respond to requests in a timely manner.

Local representative & DPO

Foreign handlers must designate a PRC-based representative; large-scale handlers must appoint a Personal Information Protection Officer.

Security & breach notification

Implement technical and organizational measures and notify regulators and affected individuals in the event of a breach (with limited exceptions).

Penalties & enforcement

What's at stake

For serious violations, the Cyberspace Administration of China (CAC) and other regulators may impose fines up to ¥50 million or 5% of the prior year's annual turnover, suspend business, revoke licenses, and personally fine responsible individuals up to ¥1 million. Violations also feed China's social credit system.

How Clarip helps

Operationalize PIPL on one platform.

Clarip unifies consent, data discovery, subject rights, and regulatory reporting — with workflows pre-configured for PIPL.

Separate consent

  • Granular consent flows for sensitive PI
  • Cross-border transfer consent
  • Audit log of consent versions

Cross-border transfer

  • Standard Contract workflow
  • Security assessment workpapers
  • Certification readiness checks

PIPIA workflows

  • Templated assessments
  • Risk scoring & mitigations
  • 3-year evidence retention

Individual rights

  • China-localized rights portal
  • Translated request templates
  • SLA tracking & escalation

Data mapping

  • Identify PI processed in China
  • Cross-border data flow registry
  • CIIO-aware risk classification

Governance

  • PIPO appointment tracking
  • Local representative records
  • Multi-jurisdiction policy harmonization
FAQ

PIPL compliance, answered.

Quick answers to the questions privacy, legal, and engineering teams most often ask about PIPL.

Yes. PIPL applies extraterritorially to processing outside China that aims to provide products or services to individuals in China, analyzes/evaluates the behavior of individuals in China, or otherwise as prescribed by law. Such handlers must establish a dedicated office or designate a representative in China.

PIPL requires distinct, specific consent — separate from general consent — for certain activities, including processing sensitive personal information, providing personal information to other handlers, public disclosure, and cross-border transfers. It cannot be bundled into a generic privacy policy acceptance.

Three primary mechanisms: (1) a security assessment by the Cyberspace Administration of China (mandatory for CIIOs, large volumes, or sensitive PI), (2) the CAC Standard Contract for cross-border transfer, or (3) personal information protection certification by an accredited body. A PIPIA must accompany the transfer.

A Personal Information Protection Impact Assessment is required before processing sensitive PI, using PI for automated decision-making, sharing or entrusting PI, public disclosure, cross-border transfers, and other activities significantly affecting individuals. Records must be retained for at least 3 years.

For serious violations, fines up to ¥50 million or 5% of the prior year's annual turnover, suspension or termination of business, revocation of licenses, personal fines on responsible persons up to ¥1 million, and adverse social credit consequences.

Clarip provides PIPL-aligned separate consent flows, cross-border transfer workflows for Standard Contracts and security assessments, templated PIPIAs with 3-year evidence retention, and a China-localized individual rights portal — coordinated with your global privacy program.

Get PIPL-ready with Clarip.

Book a 30-minute walkthrough and a custom gap assessment against PIPLrequirements — mapped to the systems and vendors you already use.