All articles
china-piplPublished · 11 June 20267 min read

PIPL in Practice: What Foreign Businesses Actually Have to Do

China's Personal Information Protection Law is now a settled part of the compliance landscape. The harder question is what a realistic baseline looks like for foreign data-processing teams.

A product manager in Berlin pushes a feature update. A growth team in London runs a campaign through a Shanghai agency. A SaaS provider in Singapore quietly stores customer support transcripts that include the names, phone numbers and ID fragments of users in Chengdu. None of these teams think of themselves as operating in China. All of them are, for the purposes of the Personal Information Protection Law, processors of Chinese personal information — and all of them are within scope.

Three years after the Personal Information Protection Law took effect, the regulatory picture has settled enough that "we're waiting to see how it shakes out" is no longer a defensible posture. The Cyberspace Administration of China has issued implementing measures, revised them, and clarified thresholds. Foreign businesses now have enough signal to build a workable compliance baseline. This piece sets out what that baseline looks like in practice.

The extraterritorial trigger most teams underestimate

PIPL applies to processing inside China, and — critically — to processing outside China that targets individuals in China for the purpose of providing products or services, or analysing their behaviour. The drafting is broad and intentional. A consumer app available in Mandarin on a global app store, a B2C website that ships to mainland addresses, an analytics pipeline that segments users by Chinese city: each is a plausible trigger.

The practical consequence is that scope is rarely a clean yes or no. It is a question of which product lines, which user cohorts, and which datasets sit inside the law's reach. The first compliance task is therefore not drafting a privacy notice. It is mapping data: identifying where Chinese personal information enters your systems, where it is stored, who touches it, and where it leaves. Until that map exists, every downstream control is guesswork.

Consent: lawful basis, not a checkbox

PIPL is often described as a consent-led regime, and in foreign boardrooms this gets translated into "add a tick-box". That undersells the obligation. PIPL recognises several lawful bases — contractual necessity, statutory duty, HR administration, public interest, and others — but consent remains the workhorse, and the law sets a high standard for what counts.

Consent under PIPL must be informed, voluntary, and explicit. Where the processing involves sensitive personal information (financial accounts, health, biometric data, the personal information of minors under 14, location tracking, and similar categories) or cross-border transfer, separate consent is required. "Separate" means exactly that: a distinct, specific act of agreement, not a paragraph buried inside a general terms acceptance.

A workable consent architecture for foreign businesses generally includes:

  1. A layered notice that states, in plain Chinese, the identity of the processor, the categories of personal information, the purposes, the retention period, and the user's rights.
  2. Granular toggles for sensitive processing categories and for marketing, separated from the core service consent.
  3. A distinct cross-border consent flow that names the overseas recipient, the destination jurisdiction, and the purpose of the transfer.
  4. A withdrawal mechanism that is as easy to use as the original consent flow, with no dark patterns.
  5. An audit log that records, per user, what was consented to, when, and against which version of the notice.

The last point matters more than teams expect. Regulators and counterparties increasingly ask for evidence, not assertions.

Cross-border transfer: three routes, one decision

Moving Chinese personal information offshore is the area where foreign businesses most often discover their existing architecture is non-compliant. PIPL provides three principal mechanisms, refined by subsequent CAC measures:

  • CAC security assessment. Mandatory for critical information infrastructure operators, for processors handling personal information above prescribed volume thresholds, and for transfers of "important data". This is a government-led review, not a self-certification.
  • Standard Contractual Clauses (China SCCs). A template contract between the Chinese exporter and the overseas recipient, filed with the provincial CAC together with a personal information protection impact assessment. Suitable for mid-volume transfers below the assessment thresholds.
  • Personal information protection certification. Issued by CAC-accredited bodies. In practice this route is most useful for intra-group transfers within multinationals.

The 2024 relaxations introduced exemptions for certain low-volume transfers, transfers necessary to perform a contract with the individual (cross-border e-commerce, travel bookings, visa applications), and HR transfers necessary for cross-border employment management. These exemptions are real but narrow. They turn on volume counts, on the nature of the contractual necessity, and on whether sensitive personal information is involved. Treating an exemption as a permanent posture without periodic review is a common error.

Whichever route applies, every cross-border transfer requires a personal information protection impact assessment — documented, retained for at least three years, and updated when the processing changes materially.

The realistic compliance baseline

For a foreign business of moderate size handling Chinese user data, a defensible baseline looks roughly like this:

  • A data map covering all Chinese personal information flows, refreshed at least annually.
  • A Chinese-language privacy notice and a consent architecture that distinguishes general, sensitive, and cross-border consent.
  • A designated representative or entity inside China, where required, with contact details published.
  • A chosen cross-border transfer mechanism — assessment, SCCs, or certification — with the underlying impact assessment on file.
  • Vendor diligence covering any onward processor touching the data, including cloud and analytics providers.
  • An incident response procedure that meets PIPL's notification expectations to both regulators and affected individuals.
  • Internal training for product, engineering and marketing teams on what triggers a fresh impact assessment.

None of this is exotic. It is, broadly, the same discipline a mature GDPR programme already practises, with Chinese-specific overlays on consent granularity, cross-border filings, and language.

Where foreign teams typically get it wrong

Three patterns recur. First, treating PIPL as a translation exercise on a GDPR notice — the two regimes overlap but diverge on consent, on cross-border mechanics, and on the role of the state. Second, assuming that because data is hosted outside China, PIPL does not apply; extraterritoriality is the rule, not the exception. Third, leaving the cross-border filing until a regulator or a Chinese commercial counterparty asks for it, by which point the timeline is no longer yours to control.

The CAC security assessment route in particular is not a process that rewards last-minute preparation. SCC filings are faster but still require a properly evidenced impact assessment behind them.

China data privacy compliance is, in the end, a question of operational maturity rather than legal cleverness. The rules are knowable. The cost of ignoring them — enforcement action, blocked transfers, lost commercial deals with Chinese partners who now ask the questions themselves — is increasingly concrete.

For foreign teams that need PRC-qualified advice on a specific transfer structure, consent flow, or filing, Serene Jade's Chinese Lawyer service pairs you with bar-admitted mainland and Hong Kong counsel.

FAQ

Do we need a China entity just to file SCCs? Not necessarily. The Chinese exporter under the SCCs is whoever holds the personal information inside China — that may be your local subsidiary, a joint venture partner, or a Chinese platform you operate through. If you have no presence at all, the question becomes whether you should appoint a designated representative under PIPL Article 53.

Does sending data to Hong Kong count as a cross-border transfer? Yes. For PIPL purposes Hong Kong is treated as outside mainland China, so transfers there require one of the three mechanisms or a valid exemption, on the same footing as transfers to London or Frankfurt.

Can we rely on the contractual necessity exemption for our SaaS customer data? Only where the transfer is genuinely necessary to perform the contract the individual entered into — for example, fulfilling an order they placed. B2B SaaS transfers of end-user data, analytics, and most marketing use cases fall outside it and need SCCs, certification, or assessment.

WORK WITH US

Have a corridor matter we can help with?