Skip to main content

China Inbound Legal Guides · Data Privacy & Cybersecurity

Data Privacy & Cybersecurity

PIPL and data-security duties follow activity, classification, then a filing or localisation route. Map the flow before the vendor contract.

What data leaves China, and which transfer gate applies? Open the matching topic route or counsel — this hub does not decide the legal outcome on your facts.

China data-privacy and cybersecurity route covering PIPL scope, transfers, incidents and evidence.
LifecycleScope → security → export gate → evidence → incident
UpdatedAugust 2026
AudiencePrivacy, legal, security and product teams
Transfer filing and incident clocks

An export filing, system go-live or incident-notice window can change the next action. This is a compliance clock, not a family-safety route.

Open transfer gates

Signature · Data-flow & transfer-route mapper

What leaves China, in whose systems, under which PIPL path?

activity → classification → gate → route → evidence

  1. ActivityWhat PI or important data?
  2. ClassifyVolume, CIIO, important data
  3. GateCAC assessment / SCC / certification
  4. RouteLocalise, minimise, or file
  5. EvidenceDPIA, contracts, logs

Compliance lifecycle

Which data duty controls the next step?

  1. ScopeWhat is processed and who is the handler.
  2. SecurityCSL and MLPS as a separate file.
  3. ExportThe transfer mechanism and clock.
  4. EvidenceThe file you could show.
  5. IncidentContainment, notice and record.

Export gates

Name the mechanism before promising go-live.

This map does not decide whether a filing is required on your facts.

01Security assessment

When a CAC security assessment is the plausible path.

02Standard contract

When a China SCC filing is the working mechanism.

03Certification

When a certification route is in view.

04Exemption test

When a published exemption may change the path — still a test, not a waiver.

Start with the situation

What data leaves China, and which transfer gate applies?

Each topic owns one bounded decision, then connects to deeper guides, local context or counsel. This hub does not duplicate long-form analysis.

Common entry points

Already know what is happening?

01We send personal information out of ChinaStart with transfer routes, thresholds and filing clocks.02We need to know if PIPL appliesStart with handler duties and what counts as personal information.03There may be a data incidentStart with containment, notice and the evidence file.

Curated resources

Go deeper without losing the route.

Long-form analysis lives on canonical guides. This hub only points.

Local context

Add the city when regulator practice changes.

CAC and industry-regulator practice can differ after the national transfer or cybersecurity question is identified.

Open city and province guides

Counsel hand-off

Need data-privacy counsel?

This hub organises PIPL, cybersecurity and export questions. It does not decide whether a transfer is lawful or whether notice is required on your facts.

Find data-privacy counsel

Request a free consultation

Directory and legal information only — not legal advice. Confirm current rules with qualified counsel.

Editorial policy · Last reviewed August 2026 · Data Privacy & Cybersecurity