Privacy education, consultancy & implementation, in 40+ jurisdictions.contact@vedhacon.com
China · PIPL, DSL & CSL

China's data regime, mapped for outbound business.

China's data laws work as a stack: the Personal Information Protection Law (PIPL) governs personal information, the Data Security Law (DSL) classifies data, and the Cybersecurity Law (CSL) underpins security and localisation. Together they shape consent, classification and cross-border transfer.

The stackConsentIndividual rightsTransfersLocalisationHow we help
Three laws, one regime

How the stack fits together

PIPL

The Personal Information Protection Law, China's comprehensive personal information statute, close in ambition to the GDPR.

DSL

The Data Security Law classifies data by importance and imposes graded security and handling duties.

CSL

The Cybersecurity Law underpins network security, critical information infrastructure and localisation.

Individual rights

What individuals can exercise

Know & decide

To know about, and to restrict or refuse, the handling of their personal information.

Access & copy

To consult and obtain copies of their personal information.

Correct

To correct or complete inaccurate personal information.

Delete

To have personal information deleted in defined circumstances.

Portability

To have personal information transferred to a designated handler where conditions are met.

Automated decisions

To require transparency and to refuse decisions made solely by automated means.

The hard part

Cross-border transfer routes

RouteWhen it applies
Security assessment (CAC)For critical information infrastructure operators and large-volume handlers, a government-led assessment.
Standard contractFiling the CAC standard contractual clauses with the regulator for many routine transfers.
CertificationCertification by a recognised body as an alternative compliance route.

Each route is paired with a transfer impact assessment and separate consent. Thresholds and exemptions change, verify current requirements.

Localisation

When data must stay in China

Critical information infrastructure operators, and handlers processing volumes above prescribed thresholds, must store personal information collected in China domestically, and pass a security assessment before any transfer abroad.

Local storage

Domestic storage for CIIOs and high-volume handlers.

Assessment before transfer

A security assessment precedes cross-border movement.

Important data

DSL "important data" attracts additional handling and export controls.

How we help

Choose a transfer route with confidence

We map your data flows against PIPL, DSL and CSL, design separate-consent and impact-assessment workflows, and help you select and evidence the right cross-border route.

Get a PIPL transfer review Compare with GDPR