This page anchors the MNC China data (HR/CRM) cluster to the statute stack so US/EU headquarters can map product architecture to real legal paths—not generic “GDPR in China” slogans.
General information only. PIPL, data-export security assessment, standard contract, and certification paths depend on volume, sensitivity, industry, and CAC/local practice. This is not legal advice and does not create an attorney–client relationship. Instruct qualified PRC privacy counsel before you connect global HRIS/CRM instances or ship employee files offshore.
Legal boundary: Prefer primary statutes, judicial interpretations, and official guidance when making decisions. Where this guide links to city hubs or lawyer listings, verify credentials and engagement terms directly with counsel. Full disclaimer · Request a consultation.
FAQ
Common questions
Quick answers for foreign nationals and employers. Rules vary by city and change over time.
Is SCC always enough for global Workday/SAP?
Not always. Volume thresholds, important data, CII, and sector rules can force security assessment or localisation. Run the decision tree spoke.
Does GDPR adequacy replace PIPL export rules?
No. China outbound transfer rules are independent of EU adequacy narratives.
Consultation preparation
What to prepare before contacting counsel
Send a focused first package so counsel can check conflicts, understand scope, and identify urgent deadlines.
A concise timeline and the result you want to achieve.
Names of all parties and affiliates for a conflict check.
Key contracts, notices, correspondence, filings, or decisions.
Known deadlines, preferred language, location, and budget constraints.
Topic counsel
Lawyers relevant to this topic
Review profiles matched to this guide, then request a free initial consultation.
Status shown per profileFree initial consultationTopic-matched shortlist