- PIPL took effect on 1 November 2021 and has extraterritorial reach, binding overseas processors that handle personal information of individuals in China.
《个人信息保护法》于2021年11月1日施行,并具有域外效力(第三条),约束处理中国境内自然人个人信息的境外处理者。- Processing requires a documented lawful basis under Article 13; consent is prominent but not the only one, with eight bases including contract necessity and legal obligation.
处理须具备第十三条项下的合法性基础;同意最为常见但非唯一,八种基础含合同必需与法定义务。- Sensitive personal information (biometrics, health, financial accounts, minors under 14) requires separate consent and stricter safeguards.
敏感个人信息(生物识别、医疗健康、金融账户、不满十四周岁未成年人等)须取得单独同意并采取更严格保护。- A PIPIA is mandatory before sensitive-data, automated-decision, third-party-sharing, or cross-border processing, with the report retained for at least three years.
处理敏感数据、自动化决策、对外提供或跨境提供前必须事前开展个人信息保护影响评估(第五十五条),报告至少保存三年。- Processors reaching the CAC volume threshold must appoint a Personal Information Protection Officer, and overseas processors must set up a China entity or designate a local representative.
达到网信办量级阈值的处理者须指定个人信息保护负责人,境外处理者须在中国境内设专门机构或指定代表(第五十三条)。- CIIOs and threshold processors must localize personal information and pass a CAC security assessment before export; others may use certification or a standard contract, but separate consent is always required.
关键信息基础设施运营者及达阈值处理者须境内存储个人信息并通过网信办安全评估方可出境;其他可择认证或标准合同,但均须取得单独同意。- Data classification and early selection of the correct outbound pathway (security assessment vs. standard contract vs. certification) usually drive the compliance timeline.
数据分类与尽早选定出境路径(安全评估/标准合同/认证)通常决定合规工期。
PIPL Compliance for Foreign Companies | 外资企业的个人信息保护法合规
Overview
China’s Personal Information Protection Law (PIPL) took effect on 1 November 2021 and is the country’s comprehensive, GDPR-style statute governing the processing of personal information. It applies not only to companies established inside mainland China but also, under its extraterritorial reach, to overseas processors that handle the personal information of individuals in China in the course of providing products or services to them, or in analysing and assessing their behaviour. For a foreign-invested enterprise (FIE) operating in China — a WFOE, joint venture, representative office, or a foreign group serving Chinese users — PIPL compliance is a board-level obligation, not a back-office formality.
This article explains the core building blocks of PIPL compliance that foreign companies must understand: the lawful bases for processing, the obligation to conduct a Personal Information Protection Impact Assessment (PIPIA), the appointment of a data-protection officer and a local representative, and the rules on localization and cross-border transfer of personal data.
Lawful basis for processing
Under PIPL, a personal information processor may process personal data only where at least one of several lawful bases applies. Consent is the most prominent, but it is not the only one. The recognized bases are: (1) consent of the individual; (2) necessary for concluding or performing a contract to which the individual is a party; (3) necessary for human-resources management under lawfully formulated labour rules and collective contracts; (4) necessary to perform statutory duties or obligations; (5) necessary to respond to a public-health emergency or to protect life, property, or other significant lawful rights in an emergency; (6) necessary for news reporting or public supervision in the public interest; (7) processing of already-disclosed personal information within a reasonable scope; and (8) other circumstances prescribed by laws or administrative regulations.
For most FIEs, the practical mix is consent (for marketing, cookies, and product analytics) plus contract necessity (for core service delivery) plus legal obligation (for HR, tax, and regulatory filings). A foreign company should map each processing activity to a documented basis and avoid relying on consent where a stronger basis exists, because consent can be withdrawn at any time. Sensitive personal information — biometrics, health and medical data, financial accounts, religious belief, specific identity, whereabouts, and the personal information of minors under 14 — requires *separate* consent and stricter safeguards.
Personal Information Protection Impact Assessment (PIPIA, Article 55)
Where the risk to individuals is elevated, PIPL requires a prior impact assessment, the Chinese analogue of the GDPR DPIA. A PIPIA is mandatory before: processing sensitive personal information; using personal information for automated decision-making (profiling, credit scoring, algorithmic recommendations); entrusting, providing, or publicly disclosing personal information to other parties; transferring personal information outside China; and any other processing that may have a significant impact on individuals.
The assessment must cover whether the purpose and means are lawful, legitimate, and necessary; the impact on individuals’ rights and the security risks; and whether the protective measures are valid and proportionate. The report and the processing record must be retained for at least three years. PIPIA is a living document that should be refreshed whenever the processing changes materially, and it is distinct from the periodic compliance audit that Article 54 requires all processors to conduct.
Data-protection officer and local representative (Articles 52–53)
A processor that handles personal information up to the amount prescribed by the national cyberspace authority (CAC) must designate a person in charge of personal information protection — a role often called the Personal Information Protection Officer (PIPO). The officer supervises processing activities and the protective measures taken, and the processor must publish the officer’s contact information and file the name and contact details with the personal-information protection authority.
Critically for foreign companies, Article 53 provides that overseas processors caught by Article 3 must establish a dedicated entity within China or designate a representative in China to handle personal-information protection matters, and must submit the entity’s or representative’s name and contact details to the authorities. A foreign parent that processes Chinese users’ data from abroad therefore cannot remain invisible to Chinese regulators; it must have a local point of accountability. Large internet platforms with huge user bases face additional duties under Article 58, including an independent supervisory body composed mainly of external members.
Localization and cross-border transfer (Articles 38–40)
PIPL draws a hard line between domestic storage and outbound transfer. Critical Information Infrastructure Operators (CIIOs) and processors that handle personal information reaching the threshold set by the CAC must store within China the personal information collected and generated inside the country. Where outbound transfer is truly necessary, it must pass a CAC-organized security assessment. Other processors may rely on one of three alternative outward-transfer mechanisms: (a) the CAC security assessment; (b) personal-information protection certification by a specialized institution designated by the CAC; or (c) a standard contract concluded with the overseas recipient under the CAC template. In every cross-border case, the individual’s separate consent must be obtained, and the individual must be informed of the overseas recipient’s identity, contact details, purpose, means, and types of information, plus how to exercise their rights.
The CAC has progressively clarified these thresholds through the 2022 Measures on Security Assessment of Data Exports, the 2023 Standard Contract Measures, and the 2024 Provisions on Promoting and Regulating Cross-Border Data Flows. As a rule of thumb, routine intra-group HR or low-volume commercial data may qualify for the simplified standard-contract or exemption path, while large-scale or sensitive personal data, and all CIIO data, triggers the full security assessment. Foreign companies should classify their data, quantify volumes against the CAC thresholds, and choose the correct pathway early — the pathway, not the permission itself, usually drives the timeline.
What to do next
- Map your processing activities to a documented lawful basis under Article 13; default to contract necessity or legal obligation where consent is fragile.
- Run a PIPIA before any sensitive-data, automated-decision, third-party-sharing, or cross-border activity, and keep the report for at least three years.
- Appoint a Personal Information Protection Officer if you meet the CAC volume threshold, and publish and file the contact details.
- Establish a China entity or representative if your overseas group processes Chinese individuals’ data — this is mandatory, not optional.
- Classify data and select the right outbound pathway (security assessment vs. standard contract vs. certification) before moving any personal information offshore, and obtain separate consent.
Sources
- National People’s Congress (NPC) — 全国人民代表大会 — Full text and adoption record of the Personal Information Protection Law (adopted 20 August 2021, effective 1 November 2021).
- Cyberspace Administration of China (CAC) — 国家互联网信息办公室 — Cross-border data transfer rules, security assessment, standard contract measures, and DPO/representative filing requirements (official portal).
- Supreme People’s Procuratorate (SPP) — official English translation of PIPL — Authoritative English text of the law, including Articles 13, 38–40, 52–55.
- CAC 12377 platform — PIPL full text — Verbatim Chinese text of PIPL Articles 38–43 (cross-border provisions).
Related reading
- see also: Cybersecurity & MLPS (等保) for FIEs — overlapping obligations on data security and critical systems.
- see also: VIE structures & regulatory trends — how data-security review intersects with offshore listings.
- see also: Foreign-related dispute resolution — litigation vs. arbitration — enforcing data-compliance breaches across borders.
外资企业的个人信息保护法合规
概述
《中华人民共和国个人信息保护法》(PIPL)于 2021 年 11 月 1 日施行,是我国个人信息处理领域的综合性、对标欧盟 GDPR 的基本法律。其不仅适用于在中国大陆境内设立的企业,依其域外适用效力(第三条),境外处理者若在向中国境内自然人提供产品、服务,或对其行为进行分析、评估的过程中处理其个人信息,同样受其约束。对于在中国运营的外商投资企业(外商独资企业、合资企业、代表机构,或以境外主体服务中国用户的跨国集团)而言,个人信息保护合规是董事会层级的责任,而非后台事务。
本文梳理外资企业必须掌握的几项 PIPL 合规基石:处理的合法性基础、个人信息保护影响评估(PIPIA)义务、个人信息保护负责人与境内代表的设置,以及个人数据的本地化存储与跨境提供规则。
处理的合法性基础(第十三条)
依据 PIPL,处理者仅在具备法定情形之一时方可处理个人信息。 consent(同意)最为常见,却并非唯一基础。法律认可的合法性基础包括:(一)取得个人同意;(二)为订立、履行个人作为一方当事人的合同所必需;(三)按照依法制定的劳动规章制度和依法签订的集体合同实施人力资源管理所必需;(四)履行法定职责或者法定义务所必需;(五)为应对突发公共卫生事件,或者紧急情况下为保护自然人的生命健康和财产安全所必需;(六)为公共利益实施新闻报道、舆论监督等行为在合理范围内处理;(七)依照本法规定在合理范围内处理已公开的个人信息;以及(八)法律、行政法规规定的其他情形。
对多数外资企业而言,实操中的基础组合是:同意(用于营销、Cookie、产品分析)+ 合同必需(用于核心服务交付)+ 法定义务(用于人事、税务与监管报送)。企业应将每一项处理活动映射到书面记载的合法性基础,并避免在存在更强基础时仍依赖同意,因为同意可随时撤回。敏感个人信息——生物识别、医疗健康、金融账户、宗教信仰、特定身份、行踪轨迹以及不满十四周岁未成年人的个人信息——须取得”单独同意”并采取更严格保护。
个人信息保护影响评估(第五十五条)
当对个人权益的风险较高时,PIPL 要求事前开展影响评估,即我国对标 GDPR DPIA 的制度(PIPIA)。出现下列情形之一,必须事前评估:(一)处理敏感个人信息;(二)利用个人信息进行自动化决策(用户画像、信用评分、算法推荐);(三)委托处理、向他人提供、公开披露个人信息;(四)向境外提供个人信息;以及(五)其他对个人权益有重大影响的情形。
评估内容应包括:处理目的与方式是否合法、正当、必要;对个人权益的影响及安全风险;所采取的保护措施是否合法、有效并与风险程度相适应。评估报告与处理情况记录应至少保存三年。PIPIA 是动态文件,处理活动发生重大变化时须重新评估;它不同于第五十四条要求的、所有处理者均应定期开展的事后合规审计。
个人信息保护负责人与境内代表(第五十二、五十三条)
处理个人信息达到国家网信部门规定数量的处理者,应当指定个人信息保护负责人,负责对处理活动及保护措施进行监督,并公开其联系方式、将姓名与联系方式报送履行个人信息保护职责的部门。
对外资企业尤为关键的是第五十三条:在境外处理境内自然人个人信息、且受本法第三条约束的境外处理者,应当在境内设立专门机构或者指定代表,负责处理个人信息保护相关事务,并将其名称或代表的姓名、联系方式等报送监管部门。换言之,境外母公司若从中国境外处理中国用户数据,不可能对中国监管保持”隐身”,必须落实本地问责主体。用户数量巨大、业务类型复杂的重要互联网平台,还须依第五十八条履行额外义务,包括设立主要由外部成员组成的独立监督机构。
本地化与跨境提供(第三十八至四十条)
PIPL 在本土存储与出境之间划出明确界线。关键信息基础设施运营者,以及处理个人信息达到国家网信部门规定数量的处理者,应当将在境内收集和产生的个人信息存储在境内;确需向境外提供的,应当通过国家网信部门组织的安全评估。其他处理者可在三种出境机制中择一:(一)安全评估;(二)经专业机构进行的个人信息保护认证;(三)与境外接收方订立标准合同(依网信办范本)。无论采取何种路径,均须取得个人的单独同意,并告知境外接收方名称、联系方式、处理目的与方式、信息种类及个人行权途径。
网信办已通过 2022 年《数据出境安全评估办法》、2023 年《个人信息出境标准合同办法》及 2024 年《促进和规范数据跨境流动规定》逐步细化阈值。实务经验是:常规集团内人事或低量级商业数据,可能适用标准合同或豁免路径;大规模或敏感个人信息,以及所有 CIIO 数据,则触发完整安全评估。外资企业应先做数据分类、按网信办阈值核算量级,并尽早选定合规路径——通常制约工期的不是”是否允许”,而是所选路径本身。
下一步建议
- 梳理处理活动并对照第十三条记载合法性基础;在同意较为脆弱时优先适用合同必需或法定义务。
- 开展 PIPIA:凡涉及敏感数据、自动化决策、第三方共享或跨境提供,须事前评估并将报告保存至少三年。
- 指定个人信息保护负责人:若达到网信办量级阈值,须设岗并公开、报送联系方式。
- 设立境内机构或代表(第五十三条):境外集团若处理中国境内自然人数据,此项为强制要求,不可省略。
- 分类数据、选定出境路径(安全评估 / 标准合同 / 认证),并在任何个人信息出境前取得单独同意。
来源
- 全国人民代表大会(NPC) — 《个人信息保护法》全文及立法记录(2021 年 8 月 20 日通过,2021 年 11 月 1 日施行)。
- 国家互联网信息办公室(CAC) — 数据出境规则、安全评估、标准合同办法及负责人/代表报送要求(官方门户)。
- 最高人民检察院 PIPL 英文官方译本 — 含第十三、三十八至四十、五十二至五十五条的权威英文文本。
- 国家网信办 12377 平台 PIPL 全文 — PIPL 第三十八至四十三条(跨境条款)中文原文。
相关阅读
- 参见:网络安全与等保(外资适用)— 数据安全与关键信息系统的叠加义务。
- 参见:VIE 架构与监管趋势 — 数据安全审查如何与境外上市相交织。
- 参见:涉外争议解决:诉讼与仲裁 — 跨境执行数据合规违规后果。
