PIPL is the PI statute; it is not GDPR, and it is not the whole China data stack.
PIPL applies to the processing of personal information of natural persons in the PRC, and in defined cases to overseas processing that targets people in China. Personal information is information related to an identified or identifiable natural person, recorded electronically or otherwise — excluding anonymised information. Sensitive PI, handlers, consent, PIAs and export paths are related pages Quick Answers. Cross-border transfer mechanics live on the CBDT basics page. Do not treat a GDPR RoPA as a PIPL file.
4 questions before you choose the route.
This page identifies the right question and evidence. It does not determine the legal outcome on a reader’s facts.
Is it personal information?
Identified or identifiable natural person — not a company name alone.
PIWho is the handler?
Organisation that decides purpose and means.
HandlerIs PIPL extra-territorial?
Overseas processors targeting PRC individuals can be in scope.
ReachWhich related pages answers the next question?
SPI, consent, PIA, CBDT — do not stuff this page.
SplitWorking rule: Map the regulated role before marketing or launch in China.
The signal ledger.
These facts move the question beyond a label and into a product, money-flow and control analysis.
Bring a compact evidence docket—not a pitch deck.
Give a compliance team or counsel the operating facts that reveal the perimeter.
Questions people ask before they build.
Short answers for orientation. The right result can change with the service model and current rules.
Does PIPL apply to employee data?
Usually yes. Employee data is a related pages page — do not skip PIAs and notices because ‘it is HR’.
Is this the same as the PIPL business guide?
The national guide and checklist stay on their URLs. This wiki page is the definition / orientation layer.
Primary authorities
Reviewed sources support orientation, not a fact-specific assessment.




