Sensitive PI is a statutory subset — not ‘anything embarrassing’.
Under PIPL, sensitive personal information is PI that, once leaked or used unlawfully, can easily infringe dignity or endanger personal or property safety. The law lists biometrics, religious beliefs, specific identity, medical health, financial accounts, location tracking, and PI of minors under 14, plus other types specified by law. Processing SPI generally needs a specific purpose, sufficiency of necessity, strict protection, and separate consent unless another PIPL basis applies. A PIA is the usual companion. Do not call every HR file SPI; do not ignore geolocation SDKs.
4 questions before you choose the route.
This page identifies the right question and evidence. It does not determine the legal outcome on a reader’s facts.
Is it on the SPI list or equivalent?
Biometrics, health, accounts, tracking, under-14.
ListIs it necessary?
PIPL requires necessity, not convenience.
NecessitySeparate consent or another basis?
Open the separate-consent sibling.
ConsentHas a PIA been done?
SPI processing is a classic PIA trigger.
PIAWorking rule: Map the regulated role before marketing or launch in China.
The signal ledger.
These facts move the question beyond a label and into a product, money-flow and control analysis.
Bring a compact evidence docket—not a pitch deck.
Give a compliance team or counsel the operating facts that reveal the perimeter.
Questions people ask before they build.
Short answers for orientation. The right result can change with the service model and current rules.
Is a national ID number SPI?
Specific identity can be SPI in context; do not assume a passport scan is ‘ordinary PI’.
Is employee bank account SPI?
Financial accounts are listed. Payroll still happens — with SPI controls, not a free pass.
Primary authorities
Reviewed sources support orientation, not a fact-specific assessment.
