Notify the right regulator for the statute that actually fired — not only your EU DPO template.
PIPL requires handlers to take remedial action and notify authorities and individuals when PI is leaked, tampered with or lost, with some relief if measures effectively avoid harm (authority notice may still apply). CSL and DSL add network and data-security incident duties; CAC and sector (finance, telecom, auto, health) have their own clocks and templates. There is no single PRC-wide 72-hour rule that matches GDPR for every dataset. Preserve logs, do not pay a ‘delete the post’ ransom as a strategy, and do not wait for perfect attribution. This page does not freeze sector hotlines.
4 questions before you choose the route.
This page identifies the right question and evidence. It does not determine the legal outcome on a reader’s facts.
What data and systems?
PI, SPI, important data, CII network.
ScopeWhich statute fired?
PIPL and/or CSL/DSL/sector.
StatuteWho must be told?
CAC/MPS/sector and individuals if harm likely.
WhoCan you honestly say harm is avoided?
If not, individual notice is in play.
HarmWorking rule: Map the regulated role before marketing or launch in China.
The signal ledger.
These facts move the question beyond a label and into a product, money-flow and control analysis.
Bring a compact evidence docket—not a pitch deck.
Give a compliance team or counsel the operating facts that reveal the perimeter.
Questions people ask before they build.
Short answers for orientation. The right result can change with the service model and current rules.
Is there a 72-hour rule?
Not as a universal PIPL copy of GDPR. Sector and CSL incident measures have their own clocks — read the current ones.
Do we notify individuals if we encrypted the disk?
If harm is truly avoided, PIPL allows a narrower individual notice — but that is a high bar and authorities may still need notice.
Primary authorities
Reviewed sources support orientation, not a fact-specific assessment.
