Personal Information Protection Law of China
China comprehensive data protection law with strict requirements for processing personal information of individuals in China, including data localization requirements.
What PIPL draws on
This framework pulls on all three pillars — which is why running them as three separate tools means reconciling three sets of evidence at audit time.
Compliance
- Sensitive Data DiscoveryFinds and classifies the regulated data, so everything downstream knows what is in scope.
- Policy & ComplianceTurns the captured activity into the report shape the framework asks for.
- Compliance Advisory ServicesOrganises the gap register, the remediation roadmap, and the auditor-ready pack.
Security
What your auditor cites,
and what produces the evidence
The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.
Security Measures
Personal information handlers MUST adopt necessary measures to ensure processing activities comply with laws and prevent unauthorized access.
Continuous scanning checks each engine and version against known CVEs, missing patches, end-of-life versions, and hardening benchmarks, and extends to the network: exposed listeners, unexpected reachability, weak TLS, and drift from the documented baseline. Findings rank by exploitability and by the classification of the data at risk, so the same CVE sits differently in the queue on classified data than on a development copy — and the scan history is the evidence that the control operated continuously rather than quarterly.
Impact Assessment
REQUIRES personal information protection impact assessment before processing sensitive personal information.
An assessment is only defensible if the findings in it are observed rather than asserted. Discovery supplies what regulated data exists and where, scanning supplies the configuration and exposure posture, and the audit trail supplies who has actually been reaching it — so the assessment describes the estate as measured. Our advisory engagements then map each finding to the specific mandate it touches and sequence the remediation.
Incident Response
In case of data breach, handlers MUST immediately take remedial measures and notify authorities and individuals.
Notification clocks start when you become aware, so detection latency is the whole exposure. Behavioural baselines score each deviation as it happens and flag it in under a second, rather than surfacing it in a weekly review. Severity is decided at the collector and routed immediately, so the window between the access and someone knowing about it is measured in seconds — and the audit trail behind it already holds what was reached, by whom, and when.
Cross-Border Transfer
Cross-border data transfers REQUIRE security assessment, certification, or standard contracts.
This mandate asks for documented policy and procedure rather than telemetry, so the platform is the evidence layer beneath it rather than the control itself. Our advisory engagements organise that documentation — a gap register mapping each requirement to its current state and a named owner, a sequenced remediation roadmap, and quarterly auditor-ready packs — and we answer the database-controls questions during the audit window. Drafting and owning the policy stays with you; assembling the evidence that it operates does not have to.
What PIPL covers
Art. 4; sensitive personal information at Art. 28
Information recorded electronically or otherwise relating to identified or identifiable natural persons within China.
In scope
- Any recorded information relating to an identifiable natural person
Sensitive personal information (Art. 28)
The instrument's own term, kept as it writes it — these labels differ between frameworks on purpose.
- Biometric characteristics
- Religious beliefs
- Specially designated status
- Medical health
- Financial accounts
- Individual location tracking
- Any personal information of a minor under 14
What falls outside
Anonymised information, which Art. 4 places outside the definition.
The under-14 rule is a class boundary rather than a factor: a minor’s ordinary personal information is sensitive personal information by definition, which is stricter than the equivalent EU treatment.
PIPL, Art. 28 · as at 2026-08
How PIPL is enforced
Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by The Cyberspace Administration of China and provincial-level authorities.
| Published maximum | Charged | As at |
|---|---|---|
| CNY 50 million | for serious violations | 2026-08 |
| 5% of the previous year turnover | the percentage limb for serious violations | 2026-08 |
| CNY 1 million | for an ordinary breach, alongside an order to rectify | 2026-08 |
Article 66 sets a two-step scheme: an order to rectify and a fine of up to CNY 1 million for ordinary breaches, escalating to the CNY 50 million or 5% ceiling where the circumstances are serious. The same article reaches the people who ran the processing, not only the company.
Separate criminal liability for infringing personal information exists under PRC Criminal Law and is prosecuted independently of Art. 66; it is not claimed here.
Who is personally on the hook
- Who can be charged
- The directly liable person in charge, and other directly liable staff
- For what
- directing or permitting personal information handling that breaches the Law
- Maximum
- A personal fine of CNY 100,000 to CNY 1 million, and a bar on serving as a director, supervisor, senior manager, or person in charge of a relevant company for a set period
- Brought by
- The Cyberspace Administration of China and provincial authorities
- Provision
- PIPL Art. 66
Uncapped exposure that sits outside this instrument
These come from company law rather than from PIPL, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.
Duty of oversight
Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.
Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.
Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.
This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.
In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).
Enforcement data reviewed August 2026. Several figures are indexed annually and move.
Built for PIPL,
not configured for it afterwards
China Data Processing Monitor
Track all processing of Chinese resident personal information
PIPL Impact Assessment
Document processing activities for impact assessment requirements
Chinese PII Patterns
Detect Chinese ID numbers, phone formats, and sensitive categories
Cross-Border Transfer Detection
Alert when data matching Chinese residents is accessed from outside China
Other Data Privacy frameworks
Walk into the PIPL audit knowing the answer
228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.