China deep dives: PIPL business guide · Cross-border transfer roadmap · Centre: Data Privacy & Cybersecurity.
One-screen verdict
- Reuse: data inventories, RoPA-style records, processor due diligence habits, security baselines, rights-request operations, training culture.
- Rebuild / localise: Chinese notices and consent UX, lawful-basis narratives under PIPL, China outbound transfer pathways, sensitive PI handling, app/SDK governance for China stores, coordination with CSL/DSL.
- Never assume: “We signed EU SCCs, so China is covered.”
Side-by-side comparison
| Dimension | GDPR (EU focus) | PIPL (China focus) | Program implication |
|---|---|---|---|
| Core statute | General Data Protection Regulation + EU/member guidance | Personal Information Protection Law + implementing rules/standards | Maintain separate legal registers |
| Territorial reach | Establishment in EU or targeting / monitoring of people in EU | Processing in China; extraterritorial triggers for overseas handlers offering goods/services or analysing behaviour of people in China | Map both “who we target” and “where processing happens” |
| Personal data / PI | Personal data broadly defined | Personal information of natural persons; sensitive PI elevated category | Tag sensitive PI explicitly in China inventories |
| Lawful bases | Six bases (contract, legitimate interests, consent, legal obligation, etc.) | Consent-heavy culture in practice plus other statutory bases (e.g. contract, HR, legal duties)—not a copy of “legitimate interests” playbooks | Do not paste LI assessments as China basis without counsel |
| Notices | Transparency duties; layered notices common | Clear notice of processing rules; Chinese language UX expected for China users/employees | Localise—not only translate legalese |
| Individual rights | Access, erasure, portability, objection, etc. | Access, copy, correction, deletion, and related rights under PIPL | Reuse intake ops; localise legal responses |
| Processors | Article 28-style contracts; SCCs for restricted transfers | Processor agreements; China-specific outbound modules | Add China schedules to vendor paper |
| International transfers | Adequacy, SCCs, BCRs, derogations, Transfer Impact Assessments | Security assessment / standard contract / certification families (and evolving rules) | Run a China transfer project—see roadmap |
| DPAs / regulators | Supervisory authorities; one-stop-shop themes | Cyberspace and related authorities; app stores and platforms as practical enforcers | Incident and complaint playbooks need China contacts |
| Penalties mindset | High administrative fines; private claims | Significant administrative penalties; business restrictions; individual liability themes in serious cases | Board-level risk, not only privacy ops |
| Adjacent regimes | ePrivacy, sector laws, AI Act (emerging) | Cybersecurity Law, Data Security Law, MLPS, sector data rules, AI rules | Privacy team must interface with cyber/compliance |
Transfers — the biggest dual-compliance trap
EU programs optimise for Schrems II-style transfer tools. China programs optimise for PIPL outbound pathways and related assessments/filings. A single global SaaS instance may need both:
- EU → third country documentation (if EU personal data is in scope), and
- China → overseas documentation for China PI.
Sequence work with the cross-border data transfer roadmap. Do not let the EU workstream “check the box” for China by accident.
What mature GDPR programs can reuse
- System and vendor inventories (extend with China entities and China-facing apps)
- Security control libraries (access control, encryption, logging)—map to China expectations
- DSAR / rights-request workflows and SLAs (localise legal analysis)
- Vendor risk questionnaires (add China storage/access/SDK questions)
- Training platforms (add PIPL modules for HR, marketing, China GMs)
- Incident response skeletons (add China notification analysis)
China-only (or China-first) workstreams
- Chinese-language notices that match real processing—including employee monitoring and HRIS exports
- Sensitive PI identification and heightened controls
- Outbound pathway selection and compliance file
- App store / mini-program compliance and SDK pruning
- Coordination with CSL network security and DSL data classification where triggered
- Government and platform inquiry response playbooks
Dual-compliance checklist (China module on a GDPR base)
- [ ] China entities and extraterritorial “targeting China users” flagged in scope register
- [ ] Inventory includes China systems + global systems touching China PI
- [ ] Lawful-basis / consent narrative reviewed under PIPL—not only GDPR LI
- [ ] Chinese notices published and version-controlled
- [ ] Sensitive PI register exists
- [ ] China outbound pathway project opened (owner + deadline)
- [ ] Vendor contracts have China transfer/security schedules
- [ ] Marketing SDKs reviewed for China apps/sites
- [ ] Rights and incident playbooks name China counsel / contacts
- [ ] Training completed for China HR and marketing owners
- [ ] Board pack distinguishes EU residual risk vs China residual risk
Common mistakes
- English-only global notice for China employees and app users.
- EU SCCs filed; China pathway ignored.
- Legitimate interests memos used as universal China basis.
- One DPA template worldwide with no China outbound language.
- Privacy team isolated from cyber / MLPS / important-data owners.
FAQ
Can one privacy policy cover GDPR and PIPL?
Sometimes as a modular policy—but China-facing products usually need Chinese notices that are accurate locally. Accuracy beats length.
Is PIPL “stricter” than GDPR?
Different, not a simple ladder. Consent culture, transfer mechanics, and platform enforcement can feel stricter in practice for consumer apps; employment designs differ too.
We only have a small China WFOE—do we need dual programs?
If you have employees or customers in China, you need a proportionate China module. Start with PIPL guide and the transfer roadmap.
Where does AI fit?
Training and inference on China PI/content engage privacy plus emerging AI rules—do not hide AI use inside a GDPR DPIA only.
Get counsel
Data privacy centre Find counsel Business & contract lawyers
PIPL guide · Transfer roadmap · Inbound centre · Outbound playbook
General information only—not legal advice. GDPR and PIPL are complex regimes with active guidance and amendments. Confirm with qualified counsel in relevant jurisdictions. Last reviewed: August 2026 · China Legal Portal Editorial