Direct answer

Notify the right regulator for the statute that actually fired — not only your EU DPO template.

PIPL requires handlers to take remedial action and notify authorities and individuals when PI is leaked, tampered with or lost, with some relief if measures effectively avoid harm (authority notice may still apply). CSL and DSL add network and data-security incident duties; CAC and sector (finance, telecom, auto, health) have their own clocks and templates. There is no single PRC-wide 72-hour rule that matches GDPR for every dataset. Preserve logs, do not pay a ‘delete the post’ ransom as a strategy, and do not wait for perfect attribution. This page does not freeze sector hotlines.

The classification screen

4 questions before you choose the route.

This page identifies the right question and evidence. It does not determine the legal outcome on a reader’s facts.

01

What data and systems?

PI, SPI, important data, CII network.

Scope
02

Which statute fired?

PIPL and/or CSL/DSL/sector.

Statute
03

Who must be told?

CAC/MPS/sector and individuals if harm likely.

Who
04

Can you honestly say harm is avoided?

If not, individual notice is in play.

Harm

Working rule: Map the regulated role before marketing or launch in China.

What changes the answer

The signal ledger.

These facts move the question beyond a label and into a product, money-flow and control analysis.

Signal
Ask the operating question
Why it changes the route
GDPR 72h only
Did the EU team file in Brussels and stop?
PRC authorities are separate.
Silent patch
Did engineering rotate keys with no legal call?
Notice duties can already have started.
Vendor first
Did you wait for the SaaS RCA?
Handler duties are still yours.
Prepare before you escalate

Bring a compact evidence docket—not a pitch deck.

Give a compliance team or counsel the operating facts that reveal the perimeter.

01Incident logWhen known, what left, what systems.
02Data typesPI/SPI/important data/CII.
03RemediationContainment, reset, user comms draft.
Common confusions

Questions people ask before they build.

Short answers for orientation. The right result can change with the service model and current rules.

Is there a 72-hour rule?

Not as a universal PIPL copy of GDPR. Sector and CSL incident measures have their own clocks — read the current ones.

Do we notify individuals if we encrypted the disk?

If harm is truly avoided, PIPL allows a narrower individual notice — but that is a high bar and authorities may still need notice.

Primary authorities

Reviewed sources support orientation, not a fact-specific assessment.