个人信息保护法 (PIPL) Compliance Assessment
🇨🇳 China Privacy Assessment ✧

China PIPL
Compliance Checker

个人信息保护法 合规检查工具

Personal Information Protection Law • 个人信息保护法

Assess your organization's compliance with China's Personal Information Protection Law (PIPL). This tool evaluates consent mechanisms, cross-border transfers, data localization, sensitive data handling, and CAC security assessment requirements.

PIPL Guardian

PIPL Compliance Assessment

个人信息保护法合规评估

📋 About China's PIPL

The Personal Information Protection Law (个人信息保护法) is China's comprehensive data protection law, effective November 1, 2021. It establishes strict requirements for collecting, processing, and transferring personal information, with extraterritorial reach to foreign organizations processing Chinese citizens' data.

⏱️ Effective: November 1, 2021 • 2021年11月1日生效
0 of 22 questions answered • 已回答 0/22 题
Consent

✅ Legal Basis & Consent

法律依据与同意 • Lawful processing requirements

📖 Articles 13-16 • 第13-16条
1

Do you obtain voluntary, explicit consent before collecting personal information?

您是否在收集个人信息前获得自愿、明确的同意?
2

Do you obtain separate consent for processing sensitive personal information?

处理敏感个人信息时是否获得单独同意?
3

Can individuals withdraw consent easily and at any time?

个人是否可以随时方便地撤回同意?
Rights

👤 Individual Rights

个人权利 • Data subject rights

📖 Articles 44-49 • 第44-49条
4

Do you provide mechanisms for individuals to access their personal information?

是否提供个人查阅其个人信息的机制?
5

Can individuals request correction or deletion of their data?

个人是否可以请求更正或删除其数据?
6

Do you support data portability requests to transfer data to other processors?

是否支持将数据转移给其他处理者的可携带性请求?
Transfer

🌍 Cross-Border Data Transfer

跨境数据传输 • International transfer requirements

📖 Articles 38-43 • 第38-43条
7

Do you conduct Personal Information Protection Impact Assessments (PIPIA) before cross-border transfers?

跨境传输前是否进行个人信息保护影响评估?
8

Have you undergone CAC security assessment for cross-border transfers (if required)?

是否已通过国家网信办安全评估(如适用)?
9

Do you use CAC-approved standard contractual clauses for international transfers?

是否使用网信办批准的标准合同条款进行国际传输?
Localization

📍 Data Localization

数据本地化 • Domestic storage requirements

📖 Article 40 • 第40条
10

Do you store personal information collected in China domestically (if CIIO or threshold met)?

如为关键信息基础设施运营者或达到数据量阈值,是否在境内存储个人信息?
Sensitive

🔐 Sensitive Personal Information

敏感个人信息 • Enhanced protection requirements

📖 Articles 28-32 • 第28-32条
11

Have you identified sensitive personal information (biometrics, health, finance, minors' data)?

是否识别了敏感个人信息(生物识别、健康、金融、未成年人数据)?
12

Do you only process sensitive PI when strictly necessary and inform individuals of necessity?

是否仅在严格必要时处理敏感个人信息并告知个人必要性?
13

For minors under 14, do you obtain parental/guardian consent?

处理14岁以下未成年人信息时是否获得父母/监护人同意?
Security

🔒 Security Measures

安全措施 • Technical and organizational safeguards

📖 Articles 51-54 • 第51-54条
14

Do you implement encryption and de-identification for personal information protection?

是否采用加密和去标识化措施保护个人信息?
15

Do you have access controls and staff authorization procedures?

是否有访问控制和员工授权程序?
16

Do you conduct regular security audits and assessments?

是否定期进行安全审计和评估?
Incident

🚨 Incident Response

事件响应 • Breach notification obligations

📖 Article 57 • 第57条
17

Do you have a documented data breach response plan?

是否有书面的数据泄露响应计划?
18

Can you promptly notify authorities and affected individuals of security incidents?

是否能够及时向主管部门和受影响个人通报安全事件?
Governance

👔 Governance & DPO

治理与数据保护官 • Organizational requirements

📖 Articles 52, 58 • 第52、58条
19

Have you designated a person responsible for personal information protection (if processing large volumes)?

如处理大量个人信息,是否指定了个人信息保护负责人?
20

Do you maintain records of processing activities?

是否维护处理活动记录?
21

Do you provide staff training on PIPL compliance?

是否为员工提供个人信息保护法合规培训?
22

If foreign entity, have you established a local representative or entity in China?

如为境外实体,是否在中国设立了本地代表或机构?
0%
China PIPL Compliance Score
个人信息保护法合规得分
Calculating...

✨ Recommendations • 建议 ✨

Need Help with China PIPL Compliance? 🇨🇳

Our consultants help organizations navigate PIPL requirements including cross-border transfer mechanisms, CAC security assessments, and data localization. We serve clients operating in or with China.

💬 Get Free Consultation • 免费咨询
Copied to clipboard!

Understanding China's Personal Information Protection Law (PIPL)

What is PIPL (个人信息保护法)?

The Personal Information Protection Law (PIPL/个人信息保护法), effective November 1, 2021, is China's comprehensive data protection framework. Often compared to GDPR, PIPL establishes strict requirements for processing personal information and has significant extraterritorial reach, applying to foreign organizations that process Chinese citizens' data for the purpose of providing products/services to China or analyzing their behavior.

Who Must Comply with PIPL?

Key PIPL Requirements

PIPL Penalties

Penalties under PIPL are among the strictest globally: up to 50 million RMB or 5% of annual revenue for serious violations, business suspension, license revocation, and personal liability for responsible individuals (fines of 100,000-1,000,000 RMB and prohibition from management positions).

Frequently Asked Questions • 常见问题

What is China's Personal Information Protection Law (PIPL)?
PIPL (个人信息保护法), effective November 1, 2021, is China's comprehensive data protection law regulating the collection, storage, use, processing, transmission, provision, and disclosure of personal information. It applies to organizations within China and foreign entities processing Chinese citizens' data.
What are PIPL's cross-border data transfer requirements?
Cross-border transfers require one of: (1) CAC security assessment (mandatory for CIIOs and large processors), (2) Personal information protection certification, (3) CAC-approved standard contractual clauses, or (4) Other conditions specified by laws. Separate consent and impact assessments are also required.
Does PIPL require data localization?
Yes, for Critical Information Infrastructure Operators (CIIOs) and organizations processing data of 1 million+ individuals. These entities must store personal information collected in China domestically and undergo security assessment before any cross-border transfer.
What is sensitive personal information under PIPL?
PIPL defines sensitive PI as information that may easily lead to personal dignity infringement or personal/property harm if leaked. This includes: biometrics, religious beliefs, specific identities, medical health, financial accounts, location tracking, and any data of minors under 14.
What are the penalties for PIPL non-compliance?
Penalties include: fines up to 50 million RMB or 5% of annual revenue for serious violations, suspension of business, license revocation, personal liability for responsible individuals (100,000-1,000,000 RMB fines), and prohibition from holding management positions.