Written by Brad Shu, Partner, DHH Law Firm Shanghai · All articles are informational only — not legal advice
Data & Privacy

China Data Compliance for Foreign Companies: PIPL, Cross-Border Transfers, and What Actually Gets Enforced

A practical PIPL roadmap for foreign-invested companies — consent and notice rules, the three cross-border transfer routes, security assessments, and enforcement trends since 2021.

TL;DR — the essentials

  • PIPL applies to any company processing personal information in China — foreign-invested companies have no carve-out, and intra-group transfers to overseas HQ count as cross-border transfer requiring one of three legal routes.
  • The three transfer routes: CAC security assessment (for large volumes or critical infrastructure), standard contract filing (the default for most companies), or personal information protection certification.
  • The 2024 Provisions relaxed thresholds significantly — most routine intra-group HR and customer data transfers now file standard contracts rather than triggering full security assessments, and exemptions now cover some necessary transfers.
  • Enforcement concentrates on apps and consumer platforms, but B2B companies are not exempt: violations surface through complaints, audits, and — increasingly — during M&A due diligence and listed-company compliance checks.
  • The compliance core is cheap and procedural: data mapping, privacy notices, consent flows, DPA clauses, and a transfer filing. Penalties run up to RMB 50 million or 5% of annual revenue for serious violations.

PIPL in one paragraph

The Personal Information Protection Law (个人信息保护法, PIPL, effective November 2021) is China’s GDPR-analogue, with sharper teeth in some places and more state-orientation in others. It applies to processing of personal information of individuals in China, including by foreign companies outside China that target or analyse people in China. For a foreign-invested company, the practical surface area is: employee data, customer data, website/app analytics, marketing lists, and — the part that always surprises HQ — any routine flow of that data to systems or personnel outside China.

The obligations that apply to almost everyone

Regardless of size or B2B/B2C orientation, a foreign-invested company needs:

  1. A data map and processing records — what personal information is collected, on what legal basis, where it flows (this is also the input to the transfer analysis). Arts. 51/55 require both.
  2. Privacy notices — at the point of collection, in Chinese, with purpose/basis/retention/rights content. A page copied from the EU GDPR notice usually fails the specificity test.
  3. Consent architecture — PIPL’s consent is granular: separate consent for sensitive categories (biometrics, health, financial, location of minors), for sharing with third parties, and for offshore transfer. Consent fatigue is managed by lawful-basis design, not by bundling.
  4. DPA and vendor governance — processing agreements with processors and sub-processors, audit rights, and security-incident notice chains.
  5. Individual rights response — access, correction, deletion, portability, and withdrawal of consent within statutory timelines.
  6. Impact assessments (PIPIA) for high-risk processing and every cross-border transfer, retained at least 3 years.

Cross-border transfer: the decision tree

This is the section HQ asks about, because modern HRIS, CRM, and support systems mean data leaves China constantly.

Step 1 — Is the transfer exempt? The 2024 Provisions exempt, among others: transfers necessary for concluding/performing a contract the individual is party to (cross-border shopping, visa/immigration, flight bookings); HR management under lawfully adopted policies or collective contracts; emergency life/health situations; and data that after anonymisation is no longer personal information. Exemption use should be documented in a short memo, not assumed.

Step 2 — Count the volumes (cumulative from 1 January each year):

Situation Route
Critical information infrastructure operator (CII) Security assessment — mandatory
Personal info > 1 million individuals Security assessment
Sensitive personal info > 10,000 individuals Security assessment
Everything below those lines Standard contract filing (most companies land here)

Step 3 — File the standard contract: sign the CAC-issued SCC template with the offshore recipient, complete a PIPIA, and file both with the provincial CAC within 10 working days of effectiveness. No waiting for approval unless the filing is flagged. This is a filing regime, not a licence — which is why it became the default route.

Two practical notes: volumes are counted per recipient and per data category, so splitting a large transfer across entities to stay under thresholds is visible and risky; and Shanghai, Beijing and the FTZs have piloted negative-list approaches that simplify filings for low-risk categories — worth checking if your entity sits in one.

Enforcement reality check

Public enforcement has concentrated on consumer apps and platforms: illegal collection via SDKs, forced bundled consent, pre-installed tracking, excessive permissions. The penalty headline (RMB 5bn against Didi) is a state-security case, not a template for ordinary companies.

The realistic exposure for a foreign-invested company:

  • Complaint-driven investigations — a former employee or a customer complaint to the local CAC/网信办 or AMR triggers a look at notices and consents.
  • Interlocking audits — labour, tax, or advertising investigations that surface data practices (a marketing list without consent basis is found by an ad-law enforcement team).
  • M&A and listing due diligence — undisciplined data practices are now a valuation and rep-and-warranty problem in transactions.
  • Personal liability — Art. 66 reaches the responsible individuals (typically the DPO/GM), which concentrates minds in ways corporate fines do not.

None of this is exotic: the companies that struggle are those that never mapped their data or assumed the China entity’s practices were HQ’s GDPR programme with different letterhead.

The 90-day compliance sprint (what a mid-size WFOE actually does)

  1. Weeks 1–2: data map across HR, sales, marketing, IT; identify offshore flows
  2. Weeks 3–4: close the easy gaps — Chinese-language notices, consent flows at collection points, retention schedule
  3. Weeks 5–8: execute the transfer route — SCC signature, PIPIA, provincial CAC filing
  4. Weeks 9–12: vendor DPA remediation, individual-rights response procedure, incident response plan, PIPIA archive discipline

The sprint output is not a certificate — China has no PIPL certification for ordinary compliance — but a defensible file: map, notices, consents, filings, assessments. In inspections and transactions, that file is the difference between a caution and a case.

Frequently asked questions

Does PIPL really apply to our China subsidiary sending employee data to our own HR system abroad?
Yes. Transfers to an overseas affiliate or parent — including routine HR data flowing to a group HRIS — are cross-border transfers under PIPL. They need one of the three legal routes (for typical employee volumes: standard contract filing with the provincial CAC), a separate consent from the employee covering the offshore transfer, and a transfer impact assessment retained on file. This intra-group HR flow is the single most common transfer situation for foreign-invested companies and the one regulators understand best.
What are the thresholds for the CAC security assessment vs standard contract?
Under the March 2024 Provisions: security assessment is required if the company is a critical information infrastructure operator, or transfers personal information of more than 1 million individuals, or sensitive personal information of more than 10,000 individuals, cumulatively since January 1 of the year. Below those lines, the standard contract route (or certification) applies. The 2024 Provisions also created exemptions — e.g. transfers necessary for cross-border shopping, HR management under collective contracts, and emergency situations — though relying on an exemption still requires documented analysis.
We only collect business contact data — names, titles, work emails of clients. Does PIPL apply?
Generally yes for individuals in China, though with lighter intensity. PIPL covers personal information broadly, and work contact data is personal information. However, the law distinguishes processing necessary for contract performance and legitimate HR/HR-adjacent purposes — where consent may not be the required basis — from marketing uses, which generally need consent or an appropriate legal basis plus opt-out mechanics. Keep a processing-record (处理记录) and honest legal-basis mapping; most B2B exposure is a documentation problem, not a fundamental one.

Need help with this? Brad advises clients on exactly this — from WFOE setup to tax structuring and compliance. Tell him about your situation.

Ask Brad

Ask a question about this article

日本語でのご質問も歓迎します。

Your question goes directly to Brad's inbox and is not published — no comment section, no public thread. Please don't include highly confidential details in a first message.

Brad Shu

Partner at DHH Law Firm Shanghai · Formerly Squire Sanders, Morrison Foerster & Jingtian Law Firm · Hangzhou Normal University (B.A. Biology) · Tsinghua University (LL.B.)

Brad Shu is a partner at DHH Law Firm Shanghai and has practiced Chinese law for two decades, including nearly ten years between the Beijing offices of US firms Squire Sanders and Morrison Foerster and leading local firm Jingtian & Gongcheng.