China Law Key Words · 01 Practice
Data Privacy & Cybersecurity
Practical China law orientation, guides and related counsel
152 articles · Latest update 13 Sep 2026
Reading on this topic
Guides, answers and analysis related to this topic.
152 articles
-
06 Sep 2026
CAC Security Assessment for Data Exports
Certain exports of important data or personal information must pass a security assessment administered by the Cyberspace Administration of China. Under the current framework, the…
-
06 Sep 2026
Sensitive Personal Information Under China’s PIPL
Sensitive personal information is a protected subset of personal information under China’s Personal Information Protection Law. It is information that, if leaked or unlawfully use…
-
06 Sep 2026
Personal Information Handler Under PIPL
A PIPL personal information handler is the organisation that decides purpose and means — closer to a GDPR controller than to a processor. Reviewed 6 Sep 2026.Direct answerThe hand…
-
06 Sep 2026
Privacy Notices and Consent Under China’s PIPL
China’s Personal Information Protection Law requires a personal information processor to identify a lawful basis and give required information to individuals before processing. Co…
-
06 Sep 2026
Separate Consent Under PIPL
PIPL separate consent is a distinct, unbundled yes for listed high-risk acts — SPI, export, public disclosure — not another paragraph in the same tick-box. Reviewed 6 Sep 2026.Dir…
-
06 Sep 2026
China Personal Information Protection Impact Assessment
A PIPL PIA (PIPIA) is required before high-risk processing: SPI, export, automated decisions, entrusted/joint processing and public disclosure. Reviewed 6 Sep 2026.Direct answerA…
-
06 Sep 2026
China Standard Contract for Personal Information Export
The CAC standard contract (SCC) is one PIPL export tool: fill the official template, file it, and do not treat it as a GDPR SCC clone. Thresholds change. Reviewed 6 Sep 2026.Direc…
-
06 Sep 2026
Personal Information Protection Certification in China
PIPL certification is the third CBDT tool: a designated body certifies the handler/group processing. It is not ISO 27001 and not an SCC. Reviewed 6 Sep 2026.Direct answerCertifica…
-
06 Sep 2026
China Data Localisation Rules
China localisation is a cluster of CSL/DSL/PIPL and sector rules — CII, important data, autos, finance, health — not a single ‘all data must stay’ slogan. Reviewed 6 Sep 2026.Dire…
-
06 Sep 2026
MLPS in China
MLPS 2.0 is China’s multi-level protection scheme: classify the system, file when required (often class 3+), test, and remediate. ISO 27001 is not a filing. Reviewed 6 Sep 2026.Di…
-
06 Sep 2026
China Data Breach Notification
China has no single ‘72-hour GDPR clock’ for every incident: PIPL, CSL, DSL and sector rules each trigger notice to authorities and, where harm is likely, to individuals. Reviewed…
-
06 Sep 2026
Entrusted Processing Under PIPL
PIPL entrusted processing is the handler–vendor model: a contract, instruction limits, and no secondary purposes. It is not joint processing and not a CBDT path by itself. Reviewe…
-
04 Sep 2026
Cross-Border Employee and R&D Data from a Suzhou Factory After the 2024 CAC Rules: When Is a Transfer Exempt and When Does PIPL Still Require a Compliance Route?
A foreign-invested manufacturer in Suzhou uses global HR, quality and engineering platforms hosted overseas. Employee data goes to regional headquarters. Production data goes to a…
-
31 Aug 2026
Wenzhou Data Privacy and Cybersecurity Lawyers & Legal Guide
Looking for Data Privacy and Cybersecurity lawyers in Wenzhou? This guide starts with the local operating facts that should shape the instruction. Cross-border e-commerce creates…
-
31 Aug 2026
Quanzhou Data Privacy and Cybersecurity Lawyers & Legal Guide
Looking for Data Privacy and Cybersecurity lawyers in Quanzhou? This guide starts with the local operating facts that should shape the instruction. Export manufacturers increasing…
When the next step needs advice
Turn the legal issue into an actionable next step with guidance from a qualified lawyer.