PIPL-Art13 | Legal Bases for Handling | 2 |
PIPL-Art14 | Consent Requirements | 1 |
PIPL-Art15 | Right to Withdraw Consent | 1 |
PIPL-Art16 | No Coerced Consent / No Service Refusal | 1 |
PIPL-Art17 | Notice Content Before Handling | 1 |
PIPL-Art19 | Retention Period Limitation | 2 |
PIPL-Art20 | Joint Handlers | 1 |
PIPL-Art21 | Entrusted Handling (Processors) | 1 |
PIPL-Art22 | Transfer Due to Merger or Restructuring | 1 |
PIPL-Art23 | Provision of PI to Third Parties | 1 |
PIPL-Art24 | Automated Decision-Making | 2 |
PIPL-Art25 | Public Disclosure Prohibited Without Consent | 1 |
PIPL-Art26 | Image Collection in Public Places | 1 |
PIPL-Art27 | Handling Already-Disclosed PI | 1 |
PIPL-Art28 | Sensitive PI Definition and Threshold | 1 |
PIPL-Art29 | Separate Consent for Sensitive PI | 1 |
PIPL-Art3 | Scope and Extraterritorial Application | 1 |
PIPL-Art30 | Enhanced Notice for Sensitive PI | 1 |
PIPL-Art31 | Minors Under 14 | 1 |
PIPL-Art32 | Sectoral and Administrative Restrictions | 1 |
PIPL-Art35 | State Organs Handling for Statutory Duties | 1 |
PIPL-Art38 | Cross-Border Transfer Legal Mechanisms | 3 |
PIPL-Art39 | Notice and Separate Consent for Cross-Border | 1 |
PIPL-Art4 | Definition of Personal Information and Handling | 1 |
PIPL-Art40 | Data Localisation and Security Assessment for CIIOs | 2 |
PIPL-Art41 | Foreign Authority Requests Require Approval | 1 |
PIPL-Art42 | Blocklist of Overseas Recipients | 0 |
PIPL-Art43 | Reciprocal Countermeasures | 0 |
PIPL-Art44 | Right to Know and Decide | 2 |
PIPL-Art45 | Right to Access, Copy and Portability | 2 |
PIPL-Art46 | Right to Correction and Completion | 2 |
PIPL-Art47 | Right to Deletion | 2 |
PIPL-Art48 | Right to Explanation of Handling Rules | 1 |
PIPL-Art49 | Rights of Deceased's Next of Kin | 0 |
PIPL-Art5 | Lawfulness, Good Faith, Necessity | 1 |
PIPL-Art50 | Request-Handling Mechanism and Remedy | 1 |
PIPL-Art51 | Security Measures and Management System | 2 |
PIPL-Art52 | Designation of a DPO | 1 |
PIPL-Art53 | Domestic Representative for Overseas Handlers | 1 |
PIPL-Art54 | Regular Compliance Audits | 0 |
PIPL-Art55 | Personal Information Protection Impact Assessment | 2 |
PIPL-Art56 | PIPIA Content and Retention | 1 |
PIPL-Art57 | Breach Remediation and Notification | 3 |
PIPL-Art58 | Large Platform Obligations | 0 |
PIPL-Art6 | Purpose Limitation and Minimisation | 2 |
PIPL-Art66 | Administrative Penalties | 0 |
PIPL-Art69 | Civil Liability (Fault Presumed) | 0 |
PIPL-Art7 | Openness and Transparency | 1 |
PIPL-Art70 | Public Interest Litigation | 0 |
PIPL-Art71 | Public Security and Criminal Liability | 0 |
PIPL-Art8 | Quality of Personal Information | 1 |
PIPL-Art9 | Security Responsibility of Handlers | 2 |
13 | Art. 13 Process only on one of the seven lawful circumstances | 0 |
14-16 | Art. 14-16 Consent voluntary, explicit and fully informed; new consent on change; withdrawal made convenient; no refusal of service for withholding consent | 0 |
17-18 | Art. 17-18 Pre-processing notice: processor identity, purposes, means, categories, retention, rights procedures; changes notified; public processing rules; the exceptions | 0 |
19 | Art. 19 Retention limited to the minimum period necessary | 0 |
20 | Art. 20 Joint processors agree their rights and obligations and bear joint and several liability | 0 |
21 | Art. 21 Entrusted processing: written agreement, supervision, no processing beyond the agreement, return or deletion, no sub-entrustment without consent | 0 |
22 | Art. 22 Transfers on merger, division, dissolution or bankruptcy: inform individuals, recipient bound, new purpose needs consent | 0 |
23 | Art. 23 Provision to another processor: inform of the recipient, purposes, means and categories and obtain separate consent; recipient bound to that scope | 0 |
24 | Art. 24 Automated decision-making: transparency, fairness, no unreasonable price discrimination, opt-out from targeted push, explanation and refusal of solely automated significant | 0 |
25-27 | Art. 25-27 No disclosure without separate consent; public-place image and identification equipment; limits on using publicly available information | 0 |
28-29 | Art. 28-29 Sensitive personal information only for a specific purpose with sufficient necessity and strict protection, on separate (or written) consent | 0 |
30 | Art. 30 Sensitive processing notice: the necessity and the impact on rights and interests | 0 |
31-32 | Art. 31-32 Minors under fourteen: guardian consent and special processing rules; administrative permits where required | 0 |
34-36 | Art. 34-36 State organs: within statutory authority and scope, with notice, storing within China and security assessment before any provision abroad | 0 |
38 | Art. 38 Cross-border provision only through one of the four mechanisms, with the overseas recipient held to the Law's standard | 0 |
39 | Art. 39 Cross-border notice and separate consent | 0 |
40 | Art. 40 Domestic storage for critical information infrastructure operators and processors above the CAC threshold; security assessment before provision abroad | 0 |
41 | Art. 41 No provision of data stored in China to foreign judicial or law enforcement authorities without competent-authority approval | 0 |
44-45 | Art. 44-45 Right to know, decide, restrict and refuse; access, copy and portability provided in a timely manner | 0 |
46 | Art. 46 Rectification and supplementation after verification | 0 |
47 | Art. 47 Proactive deletion on five triggers, and deletion on request; where deletion is barred, stop all processing but storage and protection | 0 |
48-50 | Art. 48-50 Explain the processing rules on request, honour close relatives' rights over the deceased, run a request mechanism and give reasons for refusals | 0 |
5 | Art. 5 Lawful, necessary, justified and good-faith processing; no misleading, fraud or coercion | 0 |
51 | Art. 51 Security and compliance measures: internal systems, classified management, encryption and de-identification, access authority and training, incident plans | 0 |
52 | Art. 52 Person in charge of personal information protection above the CAC threshold, contact details published and reported | 0 |
53 | Art. 53 Overseas processors within Article 3(2) establish a specialised agency or representative in China and report it | 0 |
54 | Art. 54 Regular compliance audits | 0 |
55-56 | Art. 55-56 Personal information protection impact assessment before sensitive, automated, shared, published or cross-border processing, with records kept three years | 0 |
57 | Art. 57 Breach: immediate remediation and notification to the departments and the individuals with the prescribed content | 0 |
58 | Art. 58 Large internet platforms: compliance system with an independent external supervisory body, platform rules, expulsion of violators, public responsibility reports | 0 |
59 | Art. 59 Entrusted parties secure the information and assist the processor | 0 |
6 | Art. 6 Explicit, reasonable and directly related purposes with minimum impact; collection limited to the minimum scope | 0 |
63-64 | Art. 63-64 Cooperate with inspections, act on interviews and ordered audits, and rectify risks | 0 |
7 | Art. 7 Openness and transparency: processing rules disclosed, purposes, means and scope explicit | 0 |
8 | Art. 8 Quality: accuracy and completeness guaranteed to avoid adverse impact | 0 |
9-10 | Art. 9-10 Responsibility for processing and security; prohibited conduct | 0 |
CH1 | Chapter I: General provisions and principles (Articles 5 to 10) | 0 |
CH2 | Chapter II Section 1: General processing rules (Articles 13 to 27) | 0 |
CH2S | Chapter II Sections 2 and 3: Sensitive personal information, minors and state organs (Articles 28 to 36) | 0 |
CH3 | Chapter III: Cross-border provision (Articles 38 to 41) | 0 |
CH4 | Chapter IV: Individuals' rights and the processor's duties to honour them (Articles 44 to 50) | 0 |
CH5 | Chapter V: Obligations of personal information processors (Articles 51 to 59) | 0 |
CH6 | Chapter VI: Cooperation with the departments with protection duties (Articles 63 and 64) | 0 |
GOV | The state's role, the regulators and the individual's remedies (Articles 1, 2, 11, 12, 42, 43, 60 to 62, 65, 70) | 0 |
LAW | The Personal Information Protection Law: what it is, what is held, and its implementing instruments | 0 |
PEN | Legal liability (Articles 66 to 69, 71) | 0 |