Sensitive personal information is a protected subset of personal information under China’s Personal Information Protection Law. It is information that, if leaked or unlawfully used, can easily harm personal dignity or endanger personal or property safety. The statutory examples include biometric identification, religious beliefs, specifically designated status, medical and health information, financial accounts, location tracking and personal information of minors under 14.
Processing this information requires more than attaching a “sensitive” label. The processor should establish a specific purpose and sufficient necessity, apply strict safeguards, provide the enhanced notice required by law, obtain separate consent where consent is the applicable basis, and complete a personal-information protection impact assessment before the relevant processing.
Direct answer
Identify sensitive personal information field by field and use case by use case. For each item, document why it is needed, who can access it, how long it will be kept, which legal basis applies, what notice and consent are required, and what additional technical and organizational controls reduce the likely harm.
Not every identifier or confidential business record is automatically sensitive personal information. Classification turns on the statutory definition, listed categories, other applicable rules and the consequences of leakage or misuse. Context can change the analysis: an ordinary data point may reveal health, belief, precise movements or another protected characteristic when combined with other information.
Statutory definition and examples
Article 28 of the PIPL defines sensitive personal information by its potential consequences and lists important examples. Organizations should map, at minimum:
- facial, fingerprint, voice or other biometric identification data;
- religious-belief information;
- information revealing specifically designated status;
- medical, health, disability and treatment information;
- bank accounts and other financial-account information;
- precise location and movement tracking; and
- any personal information of a minor under 14.
The list should not be treated casually as either fully open or mechanically exhaustive. Sector rules and processing context may affect classification. Internal taxonomies or recommended standards can support controls, but should not be described as conclusive legislation unless they have that status.
Specific purpose and sufficient necessity
The PIPL permits processing sensitive personal information only for a specific purpose and when sufficiently necessary, with strict protective measures. Write the purpose narrowly enough to test necessity. “Business operations,” “security” or “improving services” is usually too broad for meaningful review.
Ask whether the purpose can be achieved with ordinary personal information, lower precision, fewer fields, local verification without storage, or a shorter retention period. A lawful business objective does not establish that every proposed sensitive field is necessary.
Legal basis and separate consent
Where processing relies on consent, the PIPL generally requires separate consent for sensitive personal information. The request should be distinguishable from general terms and should explain the particular processing sufficiently for an informed choice. Written consent may be required where another law or administrative regulation says so.
Consent is not the only legal basis in the PIPL. Organizations should identify the applicable basis rather than collecting blanket consent for every purpose. Even where another basis applies, necessity, transparency, security and impact-assessment duties remain. Withdrawal and refusal consequences should not be designed to make optional processing effectively compulsory.
Enhanced notice
In addition to the ordinary notice elements, the processor must inform the individual of the necessity of processing sensitive personal information and its impact on the individual’s rights and interests, except where law permits non-notification. The notice should connect the data category to the actual purpose, recipients, retention and risk controls.
Avoid burying sensitive processing in a generic privacy notice. Product interfaces, employee notices and offline forms should present the information at the point where it can influence the person’s decision.
Personal information of minors under 14
All personal information of minors under 14 is sensitive personal information under the PIPL. Processing requires the consent of a parent or other guardian and dedicated personal-information processing rules.
Age assurance must be proportionate and should not collect excessive identity information merely to establish age. Map guardian verification, child-facing explanations, access controls, retention, rights handling and escalation for suspected unauthorized collection.
Protection impact assessment
Article 55 requires a personal-information protection impact assessment before processing sensitive personal information and for other listed high-risk activities. The assessment record should address:
- whether the purpose and method are lawful, legitimate and necessary;
- the impact and security risks to individuals;
- whether safeguards are lawful, effective and proportionate;
- data flows, recipients, systems and access roles;
- retention, deletion and incident handling; and
- residual risk and approval conditions.
The PIPL requires assessment reports and processing records to be retained for at least three years. Update the assessment when the purpose, technology, recipients, scale or risk materially changes.
Access, security and retention
Apply least-privilege access, strong authentication, encryption where appropriate, logging, segregation, backup protection and monitoring. Restrict bulk export and privileged-administrator access. Test whether support personnel and vendors can view raw data when masked or derived information would suffice.
Set retention by purpose and legal requirement, not indefinite convenience. Deletion should cover production systems, exports and downstream recipients, subject to lawful retention. Where deletion is technically difficult during a mandatory retention period, restrict processing to storage and necessary security measures as the law requires.
Sharing, vendors and overseas recipients
Determine whether another organization is an entrusted processor, separate personal-information processor, joint processor or overseas recipient. The contract and notice should reflect the real role. Entrusted processors need defined purpose, duration, method, categories, safeguards, rights and supervision; they may not determine new purposes for themselves.
Sharing sensitive information with another processor can trigger separate-consent and notice requirements. Overseas access or storage adds the PIPL cross-border mechanism, impact assessment and foreign-recipient obligations. A domestic lawful basis does not itself authorize export.
Incident readiness
Incident plans should prioritize risks to individuals, not only system recovery. Maintain detection, containment, evidence preservation, decision authority, regulator and individual notification analysis, and remediation steps. Sensitive-data inventories should identify affected systems, categories and individuals quickly.
The PIPL requires immediate remedial measures after leakage, tampering or loss and notification to the authorities and individuals under the statutory framework. Document any decision that individual notification is not required and remain prepared for an authority to direct notification.
Operational checklist
- Inventory sensitive fields and inferred sensitive attributes.
- Record the specific purpose and necessity for each use.
- Identify the PIPL basis and any separate or written consent.
- Provide the enhanced notice before processing.
- Complete and retain the impact assessment.
- Apply least privilege, logging, encryption and export controls.
- Set a defensible retention and deletion schedule.
- Classify vendors, sharing and overseas access correctly.
- Establish procedures for individual rights and consent withdrawal.
- Test incident response using a sensitive-data scenario.
Common mistakes
- Marking all personal information as sensitive without a usable classification.
- Treating a passport scan, health record or payroll account as ordinary administration.
- Using broad bundled consent instead of a purpose-specific analysis.
- Assuming consent removes the need for necessity or safeguards.
- Completing an assessment after deployment rather than before processing.
- Allowing unrestricted administrator or vendor access.
- Keeping biometric or location history indefinitely.
- Treating overseas access as ordinary vendor access.
Sources
- Personal Information Protection Law of the PRC, National People’s Congress; effective 1 November 2021.
- Regulations on Network Data Security Management, State Council; effective 1 January 2025.
General legal information only; not legal advice for a specific dataset, product, employee process, transfer or incident.


