China Data Compliance for Foreign Companies: PIPL, Cross-Border Transfers, and What Actually Gets Enforced
A practical PIPL roadmap for foreign-invested companies — consent and notice rules, the three cross-border transfer routes, security assessments, and enforcement trends since 2021.
TL;DR — the essentials
- PIPL applies to any company processing personal information in China — foreign-invested companies have no carve-out, and intra-group transfers to overseas HQ count as cross-border transfer requiring one of three legal routes.
- The three transfer routes: CAC security assessment (for large volumes or critical infrastructure), standard contract filing (the default for most companies), or personal information protection certification.
- The 2024 Provisions relaxed thresholds significantly — most routine intra-group HR and customer data transfers now file standard contracts rather than triggering full security assessments, and exemptions now cover some necessary transfers.
- Enforcement concentrates on apps and consumer platforms, but B2B companies are not exempt: violations surface through complaints, audits, and — increasingly — during M&A due diligence and listed-company compliance checks.
- The compliance core is cheap and procedural: data mapping, privacy notices, consent flows, DPA clauses, and a transfer filing. Penalties run up to RMB 50 million or 5% of annual revenue for serious violations.
PIPL in one paragraph
The Personal Information Protection Law (个人信息保护法, PIPL, effective November 2021) is China’s GDPR-analogue, with sharper teeth in some places and more state-orientation in others. It applies to processing of personal information of individuals in China, including by foreign companies outside China that target or analyse people in China. For a foreign-invested company, the practical surface area is: employee data, customer data, website/app analytics, marketing lists, and — the part that always surprises HQ — any routine flow of that data to systems or personnel outside China.
Personal Information Protection Law (2021), Arts. 4, 13 — scope and legal bases for processing; Arts. 17, 23 — notice and separate consent requirements; Arts. 28–32 — sensitive personal information regime; Arts. 38–40 — the three cross-border transfer routes and CAC security assessment jurisdiction; Art. 55 — personal information protection impact assessments (PIPIA); Art. 66 — penalties up to RMB 50 million or 5% of prior-year revenue for serious violations, plus personal liability for responsible officers. Cross-Border Data Transfer Provisions (CAC, March 2024) — filing thresholds, exemptions, and the relaxation of assessment scope. Data Security Law (2021) and Cybersecurity Law (2017) sit alongside PIPL as the broader data governance framework.
The obligations that apply to almost everyone
Regardless of size or B2B/B2C orientation, a foreign-invested company needs:
- A data map and processing records — what personal information is collected, on what legal basis, where it flows (this is also the input to the transfer analysis). Arts. 51/55 require both.
- Privacy notices — at the point of collection, in Chinese, with purpose/basis/retention/rights content. A page copied from the EU GDPR notice usually fails the specificity test.
- Consent architecture — PIPL’s consent is granular: separate consent for sensitive categories (biometrics, health, financial, location of minors), for sharing with third parties, and for offshore transfer. Consent fatigue is managed by lawful-basis design, not by bundling.
- DPA and vendor governance — processing agreements with processors and sub-processors, audit rights, and security-incident notice chains.
- Individual rights response — access, correction, deletion, portability, and withdrawal of consent within statutory timelines.
- Impact assessments (PIPIA) for high-risk processing and every cross-border transfer, retained at least 3 years.
Cross-border transfer: the decision tree
This is the section HQ asks about, because modern HRIS, CRM, and support systems mean data leaves China constantly.
Step 1 — Is the transfer exempt? The 2024 Provisions exempt, among others: transfers necessary for concluding/performing a contract the individual is party to (cross-border shopping, visa/immigration, flight bookings); HR management under lawfully adopted policies or collective contracts; emergency life/health situations; and data that after anonymisation is no longer personal information. Exemption use should be documented in a short memo, not assumed.
Step 2 — Count the volumes (cumulative from 1 January each year):
| Situation | Route |
|---|---|
| Critical information infrastructure operator (CII) | Security assessment — mandatory |
| Personal info > 1 million individuals | Security assessment |
| Sensitive personal info > 10,000 individuals | Security assessment |
| Everything below those lines | Standard contract filing (most companies land here) |
Step 3 — File the standard contract: sign the CAC-issued SCC template with the offshore recipient, complete a PIPIA, and file both with the provincial CAC within 10 working days of effectiveness. No waiting for approval unless the filing is flagged. This is a filing regime, not a licence — which is why it became the default route.
Two practical notes: volumes are counted per recipient and per data category, so splitting a large transfer across entities to stay under thresholds is visible and risky; and Shanghai, Beijing and the FTZs have piloted negative-list approaches that simplify filings for low-risk categories — worth checking if your entity sits in one.
Enforcement reality check
Public enforcement has concentrated on consumer apps and platforms: illegal collection via SDKs, forced bundled consent, pre-installed tracking, excessive permissions. The penalty headline (RMB 5bn against Didi) is a state-security case, not a template for ordinary companies.
The realistic exposure for a foreign-invested company:
- Complaint-driven investigations — a former employee or a customer complaint to the local CAC/网信办 or AMR triggers a look at notices and consents.
- Interlocking audits — labour, tax, or advertising investigations that surface data practices (a marketing list without consent basis is found by an ad-law enforcement team).
- M&A and listing due diligence — undisciplined data practices are now a valuation and rep-and-warranty problem in transactions.
- Personal liability — Art. 66 reaches the responsible individuals (typically the DPO/GM), which concentrates minds in ways corporate fines do not.
None of this is exotic: the companies that struggle are those that never mapped their data or assumed the China entity’s practices were HQ’s GDPR programme with different letterhead.
The 90-day compliance sprint (what a mid-size WFOE actually does)
- Weeks 1–2: data map across HR, sales, marketing, IT; identify offshore flows
- Weeks 3–4: close the easy gaps — Chinese-language notices, consent flows at collection points, retention schedule
- Weeks 5–8: execute the transfer route — SCC signature, PIPIA, provincial CAC filing
- Weeks 9–12: vendor DPA remediation, individual-rights response procedure, incident response plan, PIPIA archive discipline
The sprint output is not a certificate — China has no PIPL certification for ordinary compliance — but a defensible file: map, notices, consents, filings, assessments. In inspections and transactions, that file is the difference between a caution and a case.
Frequently asked questions
Does PIPL really apply to our China subsidiary sending employee data to our own HR system abroad?
What are the thresholds for the CAC security assessment vs standard contract?
We only collect business contact data — names, titles, work emails of clients. Does PIPL apply?
Need help with this? Brad advises clients on exactly this — from WFOE setup to tax structuring and compliance. Tell him about your situation.
Ask BradAsk a question about this article
日本語でのご質問も歓迎します。