China's data laws work as a stack: the Personal Information Protection Law (PIPL) governs personal information, the Data Security Law (DSL) classifies data, and the Cybersecurity Law (CSL) underpins security and localisation. Together they shape consent, classification and cross-border transfer.
The Personal Information Protection Law, China's comprehensive personal information statute, close in ambition to the GDPR.
The Data Security Law classifies data by importance and imposes graded security and handling duties.
The Cybersecurity Law underpins network security, critical information infrastructure and localisation.
Handling generally requires consent that is voluntary, explicit and fully informed.
A distinct, specific consent is required for sensitive personal information, cross-border transfer, and disclosure to third parties.
Handling personal information of minors under 14 requires guardian consent and a dedicated set of rules.
Conduct a personal information protection impact assessment for sensitive handling, transfers and automated decision-making.
To know about, and to restrict or refuse, the handling of their personal information.
To consult and obtain copies of their personal information.
To correct or complete inaccurate personal information.
To have personal information deleted in defined circumstances.
To have personal information transferred to a designated handler where conditions are met.
To require transparency and to refuse decisions made solely by automated means.
| Route | When it applies |
|---|---|
| Security assessment (CAC) | For critical information infrastructure operators and large-volume handlers, a government-led assessment. |
| Standard contract | Filing the CAC standard contractual clauses with the regulator for many routine transfers. |
| Certification | Certification by a recognised body as an alternative compliance route. |
Each route is paired with a transfer impact assessment and separate consent. Thresholds and exemptions change, verify current requirements.
Critical information infrastructure operators, and handlers processing volumes above prescribed thresholds, must store personal information collected in China domestically, and pass a security assessment before any transfer abroad.
Domestic storage for CIIOs and high-volume handlers.
A security assessment precedes cross-border movement.
DSL "important data" attracts additional handling and export controls.
We map your data flows against PIPL, DSL and CSL, design separate-consent and impact-assessment workflows, and help you select and evidence the right cross-border route.