Skip to main content

China Law Key Words · Practice parent

Data Privacy and Cybersecurity

High-intent keyword centre for China data privacy and cybersecurity—PIPL, DSL, Cybersecurity Law, cross-border transfers, and the national practice guide for foreign businesses.

Last reviewed 21 August 2026

The rule in 60 seconds

Start with the rule, then map it to your situation

This briefing separates the core issue from the next research and counsel steps.

PIPL

Personal information

Notices, consent, sensitive PI, employee data, and data-subject rights under PIPL.

DSL / CSL

Security stack

Important data, MLPS grading, network operator duties, and sector overlays.

Key distinction: This is general orientation. Company type, documents, location and timing can change the analysis.

Which situation are you in?

Start with the event, then test the rule

Scenario 01

Personal information

Notices, consent, sensitive PI, employee data, and data-subject rights under PIPL.

Next review: Open the related guides and confirm how this issue presents in your documents.

Key steps

A simple sequence for this topic

01

Inventory China data

Personal info, important data, systems, and vendors.

02

Map outbound flows

HQ CRM, cloud, support tools, and processors.

03

Pick transfer paths

Assessment, SCC, certification, or redesign localisation.

04

Align HR and IT

Employee monitoring and HRIS feeds need dual bases.

Review checklist

What to check before you choose the next step

01

Inventory China data

Personal info, important data, systems, and vendors.

02

Map outbound flows

HQ CRM, cloud, support tools, and processors.

03

Pick transfer paths

Assessment, SCC, certification, or redesign localisation.

04

Align HR and IT

Employee monitoring and HRIS feeds need dual bases.

05

Prepare incident playbooks

Notification thresholds and bilingual runbooks.

06

Instruct counsel for high risk

CII, assessment, breach, or deal diligence.

Why this matters

The issue usually reaches beyond a single filing

Personal information

Notices, consent, sensitive PI, employee data, and data-subject rights under PIPL.

Security stack

Important data, MLPS grading, network operator duties, and sector overlays.

Outbound transfers

Security assessment, standard contracts, certification, and localisation design.

Programme design

Vendors, incidents, M&A diligence, and dual compliance with GDPR-style regimes.

Recommended reading path

Move from the rule to the right depth of guidance

Common situations

Recognise the issue before you choose the response

PIPL

Personal information

Notices, consent, sensitive PI, employee data, and data-subject rights under PIPL.

DSL / CSL

Security stack

Important data, MLPS grading, network operator duties, and sector overlays.

CBDT

Outbound transfers

Security assessment, standard contracts, certification, and localisation design.

Frequently asked questions

Questions readers commonly need answered next

Is this legal advice?

No. It is a keyword hub linking national guides and counsel directories.

Where is the full practice guide?

Open the Data Privacy & Cybersecurity L3 guide.

Do all transfers need CAC assessment?

Not always—volume, sector, and important-data triggers matter. Use the CBDT roadmap.

How do I find a lawyer?

Use the data privacy directory or Ask a Lawyer.

Guides & articles

Practical writing from counsel and the portal editorial team on this topic

When the next step needs advice

Turn the legal issue into an actionable company plan.

Use the directory to find relevant counsel or ask a focused question through China Legal Portal.