China Data & Privacy

Data in China:
first the map, then the cloud

How to identify personal and sensitive data, choose the basis of processing, manage suppliers and legally transfer information to the parent company abroad.

PIPLpersonal information
DSLdata classification
CACcross-border procedures
3 waysassessment · SCC · certification

01

Compliance starts with the data card

The company describes data categories, subjects, purposes, systems, server locations, recipients, retention periods and international flows. Only then can the PIPL, critical data, industry regulations and data export route be determined.

Subjects
Clients, employees, candidates, counterparty representatives and visitors
Systems
CRM, HRIS, ERP, email, cloud, CCTV, website and mobile app
Recipients
Chinese vendors, parent company and global providers
Streams
Collection → use → provision → export → delete

02

Consent is not the only basis, but it cannot be implied

PIPL provides for several grounds: consent, the need to conclude or execute an agreement with an individual, HR-management according to legally established rules, fulfillment of a legal obligation, protection of life and health, certain public scenarios and other legal grounds.

Goal
Specific, clear and reasonable
Minimization
Only the volume necessary for the stated purpose
Deadline
No longer than necessary unless storage is required by law
Changing the goal
Re-evaluation of notice, consent and contracts

03

Notice must precede processing

Before processing, the subject is informed of the identity of the processor, contact, purposes, methods, categories, retention period and procedure for exercising rights. Consent must be informed, voluntary and demonstrable; separate consent is required for legally required scenarios.

Cookie banner doesn't solve everything

Website, contract, CRM, call recording, marketing and international transfer require a consistent system of notices and reasons, and not one general phrase.

04

Sensitive PI requires a specific need

Biometrics, religious beliefs, special identifiers, medical and financial information, precise location and data of minors under 14 years of age are at increased risk. A specific purpose, strict protection, separate consent and special notice of the impact on rights are needed.

05

Separate entrusted processing and independent sharing

If the contractor processes data on behalf, the contract specifies the purpose, duration, method, categories, protections, rights and controls. When provided independently to another processor, separate information and, as a rule, separate consent are required.

Due diligence
Location, subcontractors, security and data export
DPA
Roles, instructions, confidentiality, incidents and deletion
Audit
Right of inspection and evidence of compliance
Exit
Return or deletion of data and confirmation

06

Remote access from abroad - also data export

Export can be not only the physical sending of a file, but also access by a foreign parent company or cloud support to data stored in China. Before the transfer, a PI protection impact assessment, notice, separate consent if necessary, an agreement with the recipient and the selection of the CAC procedure are performed.

Security assessment

For critical data, CII and flows are above the set thresholds.

Standard contract

SCC with a foreign recipient plus impact assessment and filing.

Certification

Approved PI Security Certification Procedure.

Exemption

Only if the stream clearly falls within the 2024 rule exception.

07

The threshold is calculated based on data for the period, and not on one transmission

The 2024 CAC rules take into account the status of critical information infrastructure operator, the presence of important data and the total volume of PI provided abroad since January 1 of the corresponding year. For a regular handler, exemptions and different procedures are applied depending on the volume and sensitive PI.

You cannot count only the current upload

Associated systems and recipients are included in the calculation, and important data is analyzed separately. The threshold test is documented and revised as the business grows.

08

Organizational measures are as important as IT

Governance
Responsible person, policies, register and regular checks
Access
Least privilege, MFA, logging and periodic review
Protection
Encryption, segmentation, backup and vulnerability management
Incident
Detection, containment, harm assessment, notifications and evidence
Deletion
Time limits, legal hold and verified destruction

09

HR data does not become “internal” outside of PIPL

HR management may have a special basis, but the employer still respects notice, minimization, safety and employee rights. Transfer of global HRIS, payroll, background check or performance data abroad is analyzed as a separate stream.

10

Compliance roadmap

  1. 01

    Data inventory and map of Chinese and cross-border flows.

  2. 02

    Classification of PI, sensitive PI, important data and industry data.

  3. 03

    Reasons, notices, consent records and retention schedule.

  4. 04

    Vendor due diligence, DPA and sub-processing rules.

  5. 05

    PIPIA and the choice of security assessment, SCC, certification or exemption.

  6. 06

    Security controls, incident plan and employee training.

Primary sources

The flow is confirmed by documents

The data map and impact assessment connect legal findings to real-world systems.

01

Personal Information Protection Law - official NPC translation

Basic principles, grounds for processing, rights of subjects, sensitive PI and cross-border transfer.

Open official source
02

CAC Provisions on Promoting and Regulating Cross-Border Data Flows

Rules of March 22, 2024 on exceptions, thresholds and procedures for data export.

Open official source
03

CAC Measures for Standard Contract for Cross-border Transfer of PI

Conditions for using SCC, impact assessment and filing.

Open official source

China data audit

We will find international flows before the regulator checks

We will compile a data map, PIPIA, notices, vendor terms and a package for legal cross-border transfer.

Request data audit
WAWhatsAppTGTelegram