Knowledge Centre · Data & Cyber
Data Privacy & Cybersecurity in China — Knowledge Centre
Multinationals do not search for “Article 38 of PIPL.” They ask: Can we use global HR systems? Can EU/US clouds hold China personal information? What is a cross-border transfer mechanism? This centre organises practical answers—then paths to counsel.
- PIPL core duties
- Transfer assessments · contracts
- Cyber CSL · DSL · MLPS themes
Start here — flagship guide
Business-first PIPL orientation for international operators
PIPL for International Businesses
Who is in scope, lawful bases, employee/customer data, sensitive PI, transfers, penalties mindset, checklist.
Open guide → New · RoadmapCross-Border Transfer Roadmap
Map → tier → pathway → PIA → contracts → operate. Project sequence for global systems.
Open roadmap → New · ComparePIPL vs GDPR
What dual-compliance programs can reuse—and what must be rebuilt for China.
Compare → New · TrackerData Privacy Tracker
Monthly watch list: PIPL, transfers, HRIS, SDKs, DSL/CSL interfaces.
Open tracker → InboundDoing Business in China
Entity, employment, and commercial context that generates most data flows.
Open centre → OutboundGoing Global
When Chinese groups process overseas data or sell SaaS abroad—pair with host privacy rules.
Open centre →Also live: Cross-border transfer roadmap · PIPL vs GDPR · Privacy regulatory tracker.
PIPL themes executives ask about
Personal Information Protection Law—operational questions first
Are we in scope?
Processing in China, and extraterritorial triggers for overseas controllers.
Read → GuideEmployee & HR data
Global HRIS, payroll vendors, and workplace monitoring friction points.
Read → GuideCustomer & marketing data
Consent, notices, and sensitive personal information red flags.
Read → GuideCross-border transfers
Security assessment, standard contracts, certification—when each pathway matters.
Read →Cross-border data & cloud
SaaS, regional HQs, and “one global instance” designs
Typical projects: connecting China subsidiaries to global ERP/HR/CRM; using overseas marketing clouds; sharing support tickets containing personal information; AI training sets with China-sourced data.
Start with the transfer section of the PIPL business guide, then engage counsel for mechanism selection and vendor contracts. Related commercial context: Business & Contract Law Guide.
Cybersecurity & data security (adjacent laws)
PIPL is not the only statute in the stack
- Cybersecurity Law (CSL) — network operation security, critical information infrastructure themes.
- Data Security Law (DSL) — data classification, important data, outbound data restrictions beyond PI.
- MLPS / grading protection — systems security baseline often raised in diligence and procurement.
This centre leads with personal information (PIPL). Sector “important data” and CII determinations are fact-specific—treat them as specialist workstreams.
Who this centre is for
- Foreign companies operating WFOEs/JVs with China employees or customers
- Global privacy / compliance teams mapping PIPL next to GDPR
- Chinese companies processing overseas personal information or listing abroad
- Vendors selling SaaS into China or hosting shared tenancy
Get counsel
Privacy and cybersecurity mandates are fact- and sector-specific. Use business/contract and dispute counsel as entry points; specialist privacy counsel for transfer mechanisms and incidents.
General information only—not legal advice. PIPL, DSL, CSL, and implementing rules change. Last reviewed: August 2026 · China Legal Portal Editorial