Research prompt
Personal information protection
Start with the PIPL when the activity involves identifiable natural persons, processing roles, sensitive personal information, individual rights or overseas provision.
Search the portal

Data governance · maintained regulatory reference
Use this maintained source map to identify the instrument family that may affect a China data or personal-information workstream. Confirm the activity, data, parties, systems and current official text before drawing a compliance conclusion.
Use a maintained source set, not one isolated rule
China data work can involve the PIPL, network and data-security rules, cross-border transfer mechanisms, important-data or sector requirements and operational guidance. This tracker keeps those routes visible without treating a tag as a legal conclusion.
Source set checked 21 August 2026 by China Legal Portal Editorial. Draft consultation texts are not shown as effective law.
Use prompts to locate the source family
Topic cards and tags are navigation aids. They do not determine whether data is personal or important, whether a transfer exists, or which mechanism applies.
Research prompt
Start with the PIPL when the activity involves identifiable natural persons, processing roles, sensitive personal information, individual rights or overseas provision.
Research prompt
Check the Network Data Security Management Regulations and adjacent cybersecurity or data-security rules for the system, operator and data activity.
Research prompt
Map whether the activity is an overseas provision of data, then test exemptions and the current security-assessment, standard-contract or certification route.
Research prompt
Do not infer important-data status from volume alone. Check notifications, published catalogues, sector rules and applicable FTZ negative lists.
Research prompt
Map controllers or processors, entrusted processing, joint decisions, overseas recipients, contracts, impact assessments and change events.
Research prompt
Recheck new systems, SDKs, HRIS or CRM changes, new data fields, recipients, countries, vendors, mergers and incident response.
Try a broader activity, data type, role or transfer term, then review the complete official source set.
Primary text before interpretation
Official NPC English reference text. Confirm the controlling Chinese text and applicable implementing measures.
↗02Official text of State Council Decree No. 790, effective 1 January 2025.
↗03Official CAC publication of the cross-border data-flow provisions effective on publication.
↗04Official measures for the standard contract route. Read with later cross-border data-flow provisions and current filing guidance.
↗05Official index for later rules, questions and updates. Draft consultation texts are not treated as effective instruments.
↗Data analysis is fact- and change-sensitive
Describe collection, use, storage, access, sharing, transfer, deletion and automated decisions.
Identify data fields, sensitivity, scale, affected individuals, important-data indicators and sector context.
Map processors, entrusted parties, joint decisions, recipients, vendors, systems and access locations.
Verify exemptions or mechanisms, impact assessments, contracts, filings and operational change triggers.
Continue from the source map
Map whether a China data export exists and which current route requires testing.
→02Find counsel for PIPL, cybersecurity, important-data and transfer questions.
→03Prepare a bounded, non-sensitive description of the activity, data, systems and recipients.
↗