People's Republic of China (with extraterritorial reach under Article 3(2))

China Personal Information Protection Law (PIPL)

98 controls. 7 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

98 controls 7 frameworks share controls with it People's Republic of China (with extraterritorial reach under Article 3(2)) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

China PIPL Personal Information Protection Law Evidence & Implementation Kit

98 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
PIPL-Art13Legal Bases for Handling2
PIPL-Art14Consent Requirements1
PIPL-Art15Right to Withdraw Consent1
PIPL-Art16No Coerced Consent / No Service Refusal1
PIPL-Art17Notice Content Before Handling1
PIPL-Art19Retention Period Limitation2
PIPL-Art20Joint Handlers1
PIPL-Art21Entrusted Handling (Processors)1
PIPL-Art22Transfer Due to Merger or Restructuring1
PIPL-Art23Provision of PI to Third Parties1
PIPL-Art24Automated Decision-Making2
PIPL-Art25Public Disclosure Prohibited Without Consent1
PIPL-Art26Image Collection in Public Places1
PIPL-Art27Handling Already-Disclosed PI1
PIPL-Art28Sensitive PI Definition and Threshold1
PIPL-Art29Separate Consent for Sensitive PI1
PIPL-Art3Scope and Extraterritorial Application1
PIPL-Art30Enhanced Notice for Sensitive PI1
PIPL-Art31Minors Under 141
PIPL-Art32Sectoral and Administrative Restrictions1
PIPL-Art35State Organs Handling for Statutory Duties1
PIPL-Art38Cross-Border Transfer Legal Mechanisms3
PIPL-Art39Notice and Separate Consent for Cross-Border1
PIPL-Art4Definition of Personal Information and Handling1
PIPL-Art40Data Localisation and Security Assessment for CIIOs2
PIPL-Art41Foreign Authority Requests Require Approval1
PIPL-Art42Blocklist of Overseas Recipients0
PIPL-Art43Reciprocal Countermeasures0
PIPL-Art44Right to Know and Decide2
PIPL-Art45Right to Access, Copy and Portability2
PIPL-Art46Right to Correction and Completion2
PIPL-Art47Right to Deletion2
PIPL-Art48Right to Explanation of Handling Rules1
PIPL-Art49Rights of Deceased's Next of Kin0
PIPL-Art5Lawfulness, Good Faith, Necessity1
PIPL-Art50Request-Handling Mechanism and Remedy1
PIPL-Art51Security Measures and Management System2
PIPL-Art52Designation of a DPO1
PIPL-Art53Domestic Representative for Overseas Handlers1
PIPL-Art54Regular Compliance Audits0
PIPL-Art55Personal Information Protection Impact Assessment2
PIPL-Art56PIPIA Content and Retention1
PIPL-Art57Breach Remediation and Notification3
PIPL-Art58Large Platform Obligations0
PIPL-Art6Purpose Limitation and Minimisation2
PIPL-Art66Administrative Penalties0
PIPL-Art69Civil Liability (Fault Presumed)0
PIPL-Art7Openness and Transparency1
PIPL-Art70Public Interest Litigation0
PIPL-Art71Public Security and Criminal Liability0
PIPL-Art8Quality of Personal Information1
PIPL-Art9Security Responsibility of Handlers2
13Art. 13 Process only on one of the seven lawful circumstances0
14-16Art. 14-16 Consent voluntary, explicit and fully informed; new consent on change; withdrawal made convenient; no refusal of service for withholding consent0
17-18Art. 17-18 Pre-processing notice: processor identity, purposes, means, categories, retention, rights procedures; changes notified; public processing rules; the exceptions0
19Art. 19 Retention limited to the minimum period necessary0
20Art. 20 Joint processors agree their rights and obligations and bear joint and several liability0
21Art. 21 Entrusted processing: written agreement, supervision, no processing beyond the agreement, return or deletion, no sub-entrustment without consent0
22Art. 22 Transfers on merger, division, dissolution or bankruptcy: inform individuals, recipient bound, new purpose needs consent0
23Art. 23 Provision to another processor: inform of the recipient, purposes, means and categories and obtain separate consent; recipient bound to that scope0
24Art. 24 Automated decision-making: transparency, fairness, no unreasonable price discrimination, opt-out from targeted push, explanation and refusal of solely automated significant0
25-27Art. 25-27 No disclosure without separate consent; public-place image and identification equipment; limits on using publicly available information0
28-29Art. 28-29 Sensitive personal information only for a specific purpose with sufficient necessity and strict protection, on separate (or written) consent0
30Art. 30 Sensitive processing notice: the necessity and the impact on rights and interests0
31-32Art. 31-32 Minors under fourteen: guardian consent and special processing rules; administrative permits where required0
34-36Art. 34-36 State organs: within statutory authority and scope, with notice, storing within China and security assessment before any provision abroad0
38Art. 38 Cross-border provision only through one of the four mechanisms, with the overseas recipient held to the Law's standard0
39Art. 39 Cross-border notice and separate consent0
40Art. 40 Domestic storage for critical information infrastructure operators and processors above the CAC threshold; security assessment before provision abroad0
41Art. 41 No provision of data stored in China to foreign judicial or law enforcement authorities without competent-authority approval0
44-45Art. 44-45 Right to know, decide, restrict and refuse; access, copy and portability provided in a timely manner0
46Art. 46 Rectification and supplementation after verification0
47Art. 47 Proactive deletion on five triggers, and deletion on request; where deletion is barred, stop all processing but storage and protection0
48-50Art. 48-50 Explain the processing rules on request, honour close relatives' rights over the deceased, run a request mechanism and give reasons for refusals0
5Art. 5 Lawful, necessary, justified and good-faith processing; no misleading, fraud or coercion0
51Art. 51 Security and compliance measures: internal systems, classified management, encryption and de-identification, access authority and training, incident plans0
52Art. 52 Person in charge of personal information protection above the CAC threshold, contact details published and reported0
53Art. 53 Overseas processors within Article 3(2) establish a specialised agency or representative in China and report it0
54Art. 54 Regular compliance audits0
55-56Art. 55-56 Personal information protection impact assessment before sensitive, automated, shared, published or cross-border processing, with records kept three years0
57Art. 57 Breach: immediate remediation and notification to the departments and the individuals with the prescribed content0
58Art. 58 Large internet platforms: compliance system with an independent external supervisory body, platform rules, expulsion of violators, public responsibility reports0
59Art. 59 Entrusted parties secure the information and assist the processor0
6Art. 6 Explicit, reasonable and directly related purposes with minimum impact; collection limited to the minimum scope0
63-64Art. 63-64 Cooperate with inspections, act on interviews and ordered audits, and rectify risks0
7Art. 7 Openness and transparency: processing rules disclosed, purposes, means and scope explicit0
8Art. 8 Quality: accuracy and completeness guaranteed to avoid adverse impact0
9-10Art. 9-10 Responsibility for processing and security; prohibited conduct0
CH1Chapter I: General provisions and principles (Articles 5 to 10)0
CH2Chapter II Section 1: General processing rules (Articles 13 to 27)0
CH2SChapter II Sections 2 and 3: Sensitive personal information, minors and state organs (Articles 28 to 36)0
CH3Chapter III: Cross-border provision (Articles 38 to 41)0
CH4Chapter IV: Individuals' rights and the processor's duties to honour them (Articles 44 to 50)0
CH5Chapter V: Obligations of personal information processors (Articles 51 to 59)0
CH6Chapter VI: Cooperation with the departments with protection duties (Articles 63 and 64)0
GOVThe state's role, the regulators and the individual's remedies (Articles 1, 2, 11, 12, 42, 43, 60 to 62, 65, 70)0
LAWThe Personal Information Protection Law: what it is, what is held, and its implementing instruments0
PENLegal liability (Articles 66 to 69, 71)0

Tell me when China Personal Information Protection Law (PIPL) files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Records retention schedule
  • Retention schedule
  • Retention schedule and disposal records
  • Records inventory
  • Document management platform export
  • Evidence repository index
  • Retention schedule with the section 14(1) ground per record class
  • Destruction and de-identification records showing irreversibility
  • Restriction procedure and log with pre-lifting notices
  • Purpose specification

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for China Personal Information Protection Law (PIPL), drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition