The Personal Information Protection Law is China’s comprehensive privacy statute. For most companies the practical question is narrower than the law: which cross-border transfer route applies to you, what it requires, and who has to be appointed in China.
The short answer: PIPL gives you three routes for moving personal information out of China, and volume and sensitivity decide which one you are on. Below 100,000 non-sensitive records a year most transfers are exempt, the middle band takes the standard contract or a certification, and the top band takes a government security assessment. Separately, a company with no entity in China that PIPL reaches has to appoint a representative there.
Engage Compliance advises technology companies on PIPL scope, transfer route selection, the personal information protection impact assessment behind each route, and the filings that follow. We work alongside PRC-qualified counsel where the engagement needs a local filing agent.
Key takeaways
- PIPL reaches companies with no Chinese entity where they offer products or services to people in China or analyze their behavior.
- Three cross-border routes exist under Article 38: CAC security assessment, certification, and the CAC standard contract.
- The March 2024 Provisions set the thresholds that decide which route applies, and they relaxed the position considerably from the 2022 regime.
- A personal information protection impact assessment sits behind every route, and the standard contract route has to be filed with the provincial CAC.
- Article 53 requires an entity or designated representative in China for extraterritorial processors, which is the PIPL counterpart to the GDPR Article 27 representative.
- Engage Compliance scopes PIPL work per engagement: which Article 38 transfer route applies, the impact assessment behind it, and the Article 53 representative in China where one is needed.
What PIPL is
The Personal Information Protection Law took effect on 1 November 2021. It sits alongside the Cybersecurity Law and the Data Security Law, and the three together are usually what people mean when they talk about Chinese data regulation.
Structurally PIPL will look familiar to anyone who works with GDPR. It has a lawful-basis architecture, data subject rights, a processor concept, breach notification, impact assessments, and an accountability model. The differences that matter in practice are not structural:
- Consent does far more work. PIPL has no legitimate interests basis. Separate consent is required for sensitive personal information, for transfers abroad, for automated decision-making that affects individuals, and for disclosure to third parties, which means consent flows have to be granular rather than bundled.
- Data localization is real for critical information infrastructure operators and for handlers above the specified volume, who must store personal information collected in China inside China.
- Cross-border transfer is a permissioned act, not a contractual one. Even the lightest route involves a filing.
- The state has standing in a way it does not under GDPR, including provisions on data requests from foreign judicial and law enforcement authorities, which cannot be complied with without approval from the competent Chinese authority.
The comparison against GDPR clause by clause is set out in GDPR and China PIPL. This page is about the operational work.
Who needs it
Companies with a Chinese entity processing personal information there, which is the ordinary case.
Companies with no Chinese entity where Article 3 reaches them: processing the personal information of people inside China for the purpose of offering them products or services, or to analyze and evaluate their behavior. A SaaS product with paying users in China is inside this. So is an analytics-heavy consumer product with Chinese traffic it monetizes.
Companies receiving data out of China, including group companies taking employee or customer data from a Chinese subsidiary into a global system. This is the single most common trigger we see and the one most often missed, because internal transfers do not feel like exports.
What we do
Route selection
The first deliverable is a written answer to which of the three routes applies, based on counted volumes rather than estimates.
- Exempt. Under 100,000 non-sensitive records cumulatively in a calendar year, plus the specific exemptions in the March 2024 Provisions: data with no personal information arising from international trade or academic cooperation, personal information collected abroad and merely processed in China before being sent back, transfers necessary to perform a contract the individual is party to such as cross-border shopping, payments, ticketing or visa processing, transfers necessary for human resources management under lawful labor policies, and emergency transfers to protect life, health, or property.
- Standard contract or certification. From 100,000 to under 1,000,000 non-sensitive records, or under 10,000 sensitive records, in a calendar year.
- CAC security assessment. At or above 1,000,000 non-sensitive records or 10,000 sensitive records, any transfer of important data, and any transfer of personal information by a critical information infrastructure operator.
Counting is cumulative from 1 January, which means a company can move up a band mid-year. Route selection is therefore a standing check rather than a one-off.
The impact assessment
Every route requires a personal information protection impact assessment under Article 55. It covers the legality and necessity of the purpose and scope, the impact on individuals and the risk level, the protective measures and whether they are proportionate, and for transfers, the data protection standards in the destination country and the terms binding the overseas recipient.
This is closer to a GDPR transfer impact assessment than to a DPIA, and companies that have already done the Schrems II work have most of the raw material. Our DPIA services cover the GDPR side of the same estate so the two assessments stay consistent rather than contradicting each other.
Filings and appointments
- Standard contract filing with the provincial CAC, with the executed contract and the impact assessment, and management of the review correspondence.
- Security assessment submission where the top band applies, including the self-assessment that has to accompany it.
- Article 53 representative or entity, where the company has no presence in China, and the report of that name and contact to the authority.
- Article 52 person in charge of personal information protection, where the volume threshold is met, with the contact details published.
Ongoing
Volume monitoring against the band boundaries, re-assessment when the processing changes, renewal of an assessment result before its three-year validity expires, and coordination with the rest of the privacy program so a Chinese filing does not describe processing that the record of processing contradicts.
How it works
Scoping. What data leaves China, in what volume, to whom, and on what basis. Most engagements start with the discovery that nobody has counted.
Route determination. A written route decision with the counted volumes behind it, and the trigger points at which the route would change.
Assessment and documentation. The impact assessment, the contract or the submission pack, and the internal record.
Filing. Submission, review correspondence, and the outcome recorded.
Standing review. Quarterly volume checks and an annual re-read against current CAC practice, which moves more than the statute does.
What it costs
PIPL work is scoped per engagement rather than sold as a monthly tier, because a standard contract filing and a security assessment are different orders of work. Where PIPL sits inside a wider outsourced privacy program, it is scoped as an addition to the DPO tiers, which start From €1,000 per month for DPO Foundation and run to From €4,500 per month for DPO Complete. Multi-jurisdiction programs are usually the right frame here; global privacy compliance covers how that is put together.
Why Engage Compliance
Experience across 100+ startups and enterprises including Amazon, Coinbase, and Robinhood. The same senior privacy expert stays on the account, which matters on a filing that takes months and comes back with questions.
We are honest about the boundary. PIPL filings are made in China, in Chinese, and some steps need a local filing agent or PRC-qualified counsel. We do the scoping, the volume analysis, the impact assessment, the documentation, and the coordination, and we bring in local counsel for the parts that need them rather than pretending the whole thing sits in one place. Every engagement carries professional indemnity and cyber insurance.
Sources and references
- Personal Information Protection Law of the People’s Republic of China, adopted 20 August 2021, in force 1 November 2021. English text published by the National People’s Congress.
- Provisions on Promoting and Regulating Cross-Border Data Flows, Cyberspace Administration of China, March 2024