Skip to main content
China Legal Guides · National framework

Sensitive Personal Information Under China’s PIPL

A practical guide to identifying and protecting sensitive personal information under China’s PIPL, including consent, notices, assessments and minors’ data.

63lawyer profiles listed
Updated10 Sep 2026
AudienceForeign businesses & individuals
Author China Legal Portal Editorial · Reviewer Tongyu Yan · Last reviewed · 6 min read · Editorial policy · AI content policy · Disclaimer · Not legal advice — confirm current rules with counsel and authorities

At a glance

Practice: typical process stages

Four high-level stages — details and local variations are in the guide below.

  1. FrameMap facts to PRC rules
  2. PlanOptions, risks & timeline
  3. ExecuteFilings, contracts, forums
  4. ReviewCompliance & next steps
City hubs

Local guides & lawyers

Drill into city × practice hubs where available, or open the city legal market guide.

Legal planning desk with source documents, authority records and evidence file
Working file · authority, workflow and evidence

Sensitive personal information is a protected subset of personal information under China’s Personal Information Protection Law. It is information that, if leaked or unlawfully used, can easily harm personal dignity or endanger personal or property safety. The statutory examples include biometric identification, religious beliefs, specifically designated status, medical and health information, financial accounts, location tracking and personal information of minors under 14.

Processing this information requires more than attaching a “sensitive” label. The processor should establish a specific purpose and sufficient necessity, apply strict safeguards, provide the enhanced notice required by law, obtain separate consent where consent is the applicable basis, and complete a personal-information protection impact assessment before the relevant processing.

Direct answer

Identify sensitive personal information field by field and use case by use case. For each item, document why it is needed, who can access it, how long it will be kept, which legal basis applies, what notice and consent are required, and what additional technical and organizational controls reduce the likely harm.

Not every identifier or confidential business record is automatically sensitive personal information. Classification turns on the statutory definition, listed categories, other applicable rules and the consequences of leakage or misuse. Context can change the analysis: an ordinary data point may reveal health, belief, precise movements or another protected characteristic when combined with other information.

Statutory definition and examples

Article 28 of the PIPL defines sensitive personal information by its potential consequences and lists important examples. Organizations should map, at minimum:

  • facial, fingerprint, voice or other biometric identification data;
  • religious-belief information;
  • information revealing specifically designated status;
  • medical, health, disability and treatment information;
  • bank accounts and other financial-account information;
  • precise location and movement tracking; and
  • any personal information of a minor under 14.

The list should not be treated casually as either fully open or mechanically exhaustive. Sector rules and processing context may affect classification. Internal taxonomies or recommended standards can support controls, but should not be described as conclusive legislation unless they have that status.

Specific purpose and sufficient necessity

The PIPL permits processing sensitive personal information only for a specific purpose and when sufficiently necessary, with strict protective measures. Write the purpose narrowly enough to test necessity. “Business operations,” “security” or “improving services” is usually too broad for meaningful review.

Ask whether the purpose can be achieved with ordinary personal information, lower precision, fewer fields, local verification without storage, or a shorter retention period. A lawful business objective does not establish that every proposed sensitive field is necessary.

Legal basis and separate consent

Where processing relies on consent, the PIPL generally requires separate consent for sensitive personal information. The request should be distinguishable from general terms and should explain the particular processing sufficiently for an informed choice. Written consent may be required where another law or administrative regulation says so.

Consent is not the only legal basis in the PIPL. Organizations should identify the applicable basis rather than collecting blanket consent for every purpose. Even where another basis applies, necessity, transparency, security and impact-assessment duties remain. Withdrawal and refusal consequences should not be designed to make optional processing effectively compulsory.

Enhanced notice

In addition to the ordinary notice elements, the processor must inform the individual of the necessity of processing sensitive personal information and its impact on the individual’s rights and interests, except where law permits non-notification. The notice should connect the data category to the actual purpose, recipients, retention and risk controls.

Avoid burying sensitive processing in a generic privacy notice. Product interfaces, employee notices and offline forms should present the information at the point where it can influence the person’s decision.

Personal information of minors under 14

All personal information of minors under 14 is sensitive personal information under the PIPL. Processing requires the consent of a parent or other guardian and dedicated personal-information processing rules.

Age assurance must be proportionate and should not collect excessive identity information merely to establish age. Map guardian verification, child-facing explanations, access controls, retention, rights handling and escalation for suspected unauthorized collection.

Protection impact assessment

Article 55 requires a personal-information protection impact assessment before processing sensitive personal information and for other listed high-risk activities. The assessment record should address:

  1. whether the purpose and method are lawful, legitimate and necessary;
  2. the impact and security risks to individuals;
  3. whether safeguards are lawful, effective and proportionate;
  4. data flows, recipients, systems and access roles;
  5. retention, deletion and incident handling; and
  6. residual risk and approval conditions.

The PIPL requires assessment reports and processing records to be retained for at least three years. Update the assessment when the purpose, technology, recipients, scale or risk materially changes.

Access, security and retention

Apply least-privilege access, strong authentication, encryption where appropriate, logging, segregation, backup protection and monitoring. Restrict bulk export and privileged-administrator access. Test whether support personnel and vendors can view raw data when masked or derived information would suffice.

Set retention by purpose and legal requirement, not indefinite convenience. Deletion should cover production systems, exports and downstream recipients, subject to lawful retention. Where deletion is technically difficult during a mandatory retention period, restrict processing to storage and necessary security measures as the law requires.

Sharing, vendors and overseas recipients

Determine whether another organization is an entrusted processor, separate personal-information processor, joint processor or overseas recipient. The contract and notice should reflect the real role. Entrusted processors need defined purpose, duration, method, categories, safeguards, rights and supervision; they may not determine new purposes for themselves.

Sharing sensitive information with another processor can trigger separate-consent and notice requirements. Overseas access or storage adds the PIPL cross-border mechanism, impact assessment and foreign-recipient obligations. A domestic lawful basis does not itself authorize export.

Incident readiness

Incident plans should prioritize risks to individuals, not only system recovery. Maintain detection, containment, evidence preservation, decision authority, regulator and individual notification analysis, and remediation steps. Sensitive-data inventories should identify affected systems, categories and individuals quickly.

The PIPL requires immediate remedial measures after leakage, tampering or loss and notification to the authorities and individuals under the statutory framework. Document any decision that individual notification is not required and remain prepared for an authority to direct notification.

Operational checklist

  1. Inventory sensitive fields and inferred sensitive attributes.
  2. Record the specific purpose and necessity for each use.
  3. Identify the PIPL basis and any separate or written consent.
  4. Provide the enhanced notice before processing.
  5. Complete and retain the impact assessment.
  6. Apply least privilege, logging, encryption and export controls.
  7. Set a defensible retention and deletion schedule.
  8. Classify vendors, sharing and overseas access correctly.
  9. Establish procedures for individual rights and consent withdrawal.
  10. Test incident response using a sensitive-data scenario.

Common mistakes

  • Marking all personal information as sensitive without a usable classification.
  • Treating a passport scan, health record or payroll account as ordinary administration.
  • Using broad bundled consent instead of a purpose-specific analysis.
  • Assuming consent removes the need for necessity or safeguards.
  • Completing an assessment after deployment rather than before processing.
  • Allowing unrestricted administrator or vendor access.
  • Keeping biometric or location history indefinitely.
  • Treating overseas access as ordinary vendor access.

Sources

General legal information only; not legal advice for a specific dataset, product, employee process, transfer or incident.

Legal source archive with indexed legislation and official records
Source register · primary authorities and verification
Sources & trust

How to use this guide

PIPL; CSL; DSL; CAC cross-border data transfer measures. Thresholds and catalogues change — check official texts. Editorial source-check 2026-09-06.

Editorial, AI and verification policies

This page is general information for orientation. It is not legal advice and does not create an attorney–client relationship.

Review the Editorial Policy, AI Content Policy, and Lawyer Verification Policy.

Consultation preparation

What to prepare before contacting counsel

Send a focused first package so counsel can check conflicts, understand scope, and identify urgent deadlines.

  • A concise timeline and the result you want to achieve.
  • Names of all parties and affiliates for a conflict check.
  • Key contracts, notices, correspondence, filings, or decisions.
  • Known deadlines, preferred language, location, and budget constraints.
Directory

Practice lawyer profiles

China-based listings shown first. Review profiles for practice, then submit an initial enquiry.

Status shown per profileFree initial intakeChina-first directory sort

Browse practice directory →

Cross-border legal details arranged for a prepared counsel enquiry
Next route · prepared enquiry

Move from orientation to a properly prepared legal brief.

Bring the parties, objective, relevant documents, chronology, known deadlines and the decision you need counsel to make.

Prepare your legal enquiry →

Need counsel on practice?

Review listed lawyer profiles and submit an initial enquiry. No obligation.