When a CAC security assessment is the plausible path.
China Inbound Legal Guides · Data Privacy & Cybersecurity
Data Privacy & Cybersecurity
PIPL and data-security duties follow activity, classification, then a filing or localisation route. Map the flow before the vendor contract.
What data leaves China, and which transfer gate applies? Open the matching topic route or counsel — this hub does not decide the legal outcome on your facts.

An export filing, system go-live or incident-notice window can change the next action. This is a compliance clock, not a family-safety route.
Signature · Data-flow & transfer-route mapper
What leaves China, in whose systems, under which PIPL path?
activity → classification → gate → route → evidence
Compliance lifecycle
Which data duty controls the next step?
Export gates
Name the mechanism before promising go-live.
This map does not decide whether a filing is required on your facts.
When a China SCC filing is the working mechanism.
When a certification route is in view.
When a published exemption may change the path — still a test, not a waiver.
Start with the situation
What data leaves China, and which transfer gate applies?
Each topic owns one bounded decision, then connects to deeper guides, local context or counsel. This hub does not duplicate long-form analysis.
PIPL scope & duties
Personal information, handlers, notices, consent and the core processing duties.
Cybersecurity & MLPS
Network-security duties and multi-level protection as a separate file from PIPL transfers.
Cross-border transfers
Export paths, CAC filings, standard contracts and certification — the gate that holds go-live.
Exemptions & thresholds
Volume, necessity and published exemption tests that can change which export mechanism applies.
Incidents & notification
Breach, leakage and the clock for containment, notice and evidence.
Programme & evidence
Records, DPIA-style notes, vendor maps and the file you would show a regulator or counsel.
Common entry points
Already know what is happening?
Curated resources
Go deeper without losing the route.
Long-form analysis lives on canonical guides. This hub only points.
China data compliance decision guide
National PIPL, transfer and cybersecurity decision desk — not a substitute for a filing pack.
Cross-border data transfer roadmap
Compare export mechanisms and the clocks that sit in front of go-live.
China data-export exemptions
Mechanism tests that can change whether a CAC filing or SCC path applies.
Cybersecurity law and MLPS
Multi-level protection as a network-security file beside PIPL.
Data breaches in China
Orientation for leakage, notice and next-step questions — not an incident playbook verdict.
Beijing data privacy and cybersecurity lawyers
Local counsel layer when regulator practice is material.
Local context
Add the city when regulator practice changes.
CAC and industry-regulator practice can differ after the national transfer or cybersecurity question is identified.
Open city and province guidesCounsel hand-off
Need data-privacy counsel?
This hub organises PIPL, cybersecurity and export questions. It does not decide whether a transfer is lawful or whether notice is required on your facts.
Find data-privacy counsel