01
Compliance starts with the data card
The company describes data categories, subjects, purposes, systems, server locations, recipients, retention periods and international flows. Only then can the PIPL, critical data, industry regulations and data export route be determined.
- Subjects
- Clients, employees, candidates, counterparty representatives and visitors
- Systems
- CRM, HRIS, ERP, email, cloud, CCTV, website and mobile app
- Recipients
- Chinese vendors, parent company and global providers
- Streams
- Collection → use → provision → export → delete
02
Consent is not the only basis, but it cannot be implied
PIPL provides for several grounds: consent, the need to conclude or execute an agreement with an individual, HR-management according to legally established rules, fulfillment of a legal obligation, protection of life and health, certain public scenarios and other legal grounds.
- Goal
- Specific, clear and reasonable
- Minimization
- Only the volume necessary for the stated purpose
- Deadline
- No longer than necessary unless storage is required by law
- Changing the goal
- Re-evaluation of notice, consent and contracts
03
Notice must precede processing
Before processing, the subject is informed of the identity of the processor, contact, purposes, methods, categories, retention period and procedure for exercising rights. Consent must be informed, voluntary and demonstrable; separate consent is required for legally required scenarios.
Website, contract, CRM, call recording, marketing and international transfer require a consistent system of notices and reasons, and not one general phrase.
04
Sensitive PI requires a specific need
Biometrics, religious beliefs, special identifiers, medical and financial information, precise location and data of minors under 14 years of age are at increased risk. A specific purpose, strict protection, separate consent and special notice of the impact on rights are needed.
05
Separate entrusted processing and independent sharing
If the contractor processes data on behalf, the contract specifies the purpose, duration, method, categories, protections, rights and controls. When provided independently to another processor, separate information and, as a rule, separate consent are required.
- Due diligence
- Location, subcontractors, security and data export
- DPA
- Roles, instructions, confidentiality, incidents and deletion
- Audit
- Right of inspection and evidence of compliance
- Exit
- Return or deletion of data and confirmation
06
Remote access from abroad - also data export
Export can be not only the physical sending of a file, but also access by a foreign parent company or cloud support to data stored in China. Before the transfer, a PI protection impact assessment, notice, separate consent if necessary, an agreement with the recipient and the selection of the CAC procedure are performed.
For critical data, CII and flows are above the set thresholds.
SCC with a foreign recipient plus impact assessment and filing.
Approved PI Security Certification Procedure.
Only if the stream clearly falls within the 2024 rule exception.
07
The threshold is calculated based on data for the period, and not on one transmission
The 2024 CAC rules take into account the status of critical information infrastructure operator, the presence of important data and the total volume of PI provided abroad since January 1 of the corresponding year. For a regular handler, exemptions and different procedures are applied depending on the volume and sensitive PI.
Associated systems and recipients are included in the calculation, and important data is analyzed separately. The threshold test is documented and revised as the business grows.
08
Organizational measures are as important as IT
- Governance
- Responsible person, policies, register and regular checks
- Access
- Least privilege, MFA, logging and periodic review
- Protection
- Encryption, segmentation, backup and vulnerability management
- Incident
- Detection, containment, harm assessment, notifications and evidence
- Deletion
- Time limits, legal hold and verified destruction
09
HR data does not become “internal” outside of PIPL
HR management may have a special basis, but the employer still respects notice, minimization, safety and employee rights. Transfer of global HRIS, payroll, background check or performance data abroad is analyzed as a separate stream.
10
Compliance roadmap
- 01
Data inventory and map of Chinese and cross-border flows.
- 02
Classification of PI, sensitive PI, important data and industry data.
- 03
Reasons, notices, consent records and retention schedule.
- 04
Vendor due diligence, DPA and sub-processing rules.
- 05
PIPIA and the choice of security assessment, SCC, certification or exemption.
- 06
Security controls, incident plan and employee training.
+7 (495) 221 31 46