PIPL · DSL · CSL · cross-border transfer
China's PIPL, together with the Data Security Law and Cybersecurity Law, imposes obligations that parallel and in some respects exceed GDPR.
The Personal Information Protection Law (PIPL) reaches any organization processing the personal information of individuals in China — wherever the processor is located. The Data Security Law (DSL) and Cybersecurity Law (CSL) layer on data-classification and network-security duties.
We handle data mapping and classification, privacy notices and consent mechanisms for customers and employees, data-processor agreements, and the three cross-border transfer routes — security assessment, the China Standard Contract, or certification — plus incident response. The most common violation we see is companies silently uploading Chinese employee or customer data into a global system without a lawful transfer mechanism.
Reference: Personal Information Protection Law (2021) · Data Security Law (2021) · Cybersecurity Law (2017)
We work in English and Chinese, on your timeline. Initial consultations are confidential and without obligation.