Professional profile
About Ruiqing
Personal Information Protection and PIPL Compliance in Beijing
Ruiqing Long advises companies on personal information compliance under China’s Personal Information Protection Law (PIPL) and related rules, including privacy notices, separate consent design, vendor governance and regulatory response for organisations operating in or targeting individuals in China.
Ms. Long practices at Beijing Zhong Lun Law Firm in Chaoyang. She holds a Bachelor of Laws from Peking University, was admitted in 2023, and focuses on data and privacy matters for technology, consumer and foreign-invested clients. She works in English and Mandarin. Newer admission does not mean template advice: PIPL work is document-heavy and product-specific, and her practice is built around implementable controls rather than policy theatre.
PIPL sits alongside the Cybersecurity Law, Data Security Law, sector rules and standard-setting instruments on consent, impact assessments and cross-border transfer mechanisms. Companies fail when legal, product and security teams each own a fragment. Ms. Long maps processing activities to legal bases, identifies high-risk processing, and produces a remediation backlog product teams can ship against.
Notices, Consent and High-Risk Processing
She reviews privacy policies and in-app notice UX for transparency duties, separate consent points where required, and consistency between what the product does and what the notice claims. Common gaps include over-collection on registration, SDKs that transmit data without governance, and employee or CV screening processes that never received a lawful design.
For sensitive personal information and automated decision-making features, she structures impact assessments and approval records so that if a regulator asks “show your process,” the company has more than a slide deck. Vendor and processor contracts are updated to match actual data flows—not generic overseas templates pasted into a China appendix.
Incidents, Complaints and Regulatory Touchpoints
When individuals complain or a regulator issues an inquiry, speed and accuracy matter. Ms. Long helps assemble processing records, legal-basis charts and remediation evidence. She coordinates with cybersecurity counsel where system vulnerabilities and personal-information duties overlap, keeping roles clear so messages to authorities stay consistent.
- PIPL gap assessments and prioritised remediation roadmaps
- Privacy notice and consent-flow redesign with product teams
- Processor/vendor due diligence and contract alignment
- Complaint and regulatory inquiry response support
Engagement
Effective kick-offs need a system inventory (apps, websites, HR systems, CRM), a list of vendors, and any prior regulator correspondence. Contact this profile with your industry, whether you are a controller targeting China users from overseas, and whether an incident or inquiry is already active. Scope and fees are confirmed in writing before deep document review begins.
Foreign Headquarters, China Apps and Evidence for Audits
Many Chaoyang clients are China WFOEs or representative functions implementing global privacy programmes. Ms. Long builds “China annex” packages: lawful bases charted against PIPL, records of processing that name Chinese systems, and decision logs for high-risk features. She pushes back on global templates that assert consent for everything—an approach that is both inaccurate and operationally heavy.
Employee monitoring, whistleblowing hotlines and CCTV in offices are recurring gap areas. She separates employment necessity from broad surveillance habits and documents retention limits. Candidate screening and background checks receive the same scrutiny; HR vendors are processors that need contracts and minimum-necessary collection rules.
When sales teams promise enterprise customers “GDPR-equivalent” protections, she aligns marketing with what the China stack can actually deliver, reducing misrepresentation risk. Training sessions for product managers focus on decision points—new SDK, new overseas admin, new biometric feature—not annual slideshow compliance.
If a security incident spills personal information, she coordinates notification analysis with cybersecurity counsel, preserving a single factual timeline. Dual, conflicting notices are a avoidable failure mode she plans against from hour one.
Product Counsel Rituals and DPIA-Style Records
Ms. Long installs lightweight rituals: privacy review tickets on new data features, SDK allowlists, and quarterly residual-risk reviews for high-risk processing. She prefers short living documents over annual PDFs that rot. Engineers get examples from their own codebase, not generic foreign case studies alone.
When investors or enterprise customers issue privacy diligence questionnaires, she prepares evidence binders—policies, training logs, processor lists, incident metrics—that match answers. Inconsistency between sales security questionnaires and actual controls is a recurring deal hazard she eliminates early.
Children’s data, biometric pilots and workplace monitoring remain bright-line risk zones. She requires elevated approval and narrower retention. “We might need it later” is not a processing purpose she accepts without challenge.
Capability
