Asia-Pacific China

PIPL Handler Obligations: Duties of Personal Information Handlers

What PIPL demands of personal information handlers: security measures, protection officers, impact assessments, audits, breach response, and entrusted processing.

Regulation

PIPL Articles 9, 51-59

Max Penalty

RMB 50 million or 5% of prior year's turnover

Enforcing Authority

Cyberspace Administration of China (CAC)

Official Source

www.cac.gov.cn

Executive Summary

  • A 'personal information handler' is PIPL's controller: whoever autonomously determines purposes and methods. Handlers bear the Article 51 duty stack: internal management systems, classification, encryption/de-identification, access controls, training, and incident plans.
  • Handlers above CAC-set volumes must appoint a personal information protection officer; foreign handlers in scope must establish a China entity or representative.
  • Personal information protection impact assessments (Articles 55-56) are mandatory for sensitive data, automated decision-making, entrusting/sharing/disclosing data, exports, and other high-impact processing, retained for three years.
  • Regular compliance audits are required (Article 54), and the 2025 CAC audit measures let regulators compel professional third-party audits.
  • Breach duties (Article 57): remediate immediately and notify authorities and individuals; notification to individuals can be waived only if harm can effectively be avoided.

PIPL assigns its duty stack to the “personal information handler,” the organization that decides why and how personal information is processed. The obligations will look familiar from GDPR, but three run harder in China: impact assessments attach to a fixed statutory list of activities, compliance audits are a formal regulatory instrument with their own 2025 measures, and above-threshold handlers owe structural commitments (an officer, and for foreign handlers, a China presence).

RegulationPIPL Articles 9, 20-21, 51-59
Max penaltyRMB 50M or 5% of prior year’s turnover
Enforcing authorityCAC
Audit rulesCAC compliance audit measures, effective 1 May 2025

The duty stack

Security and governance (Article 51). Formulate internal management systems and operating procedures; implement classified management of personal information; apply encryption and de-identification as appropriate; set access permissions and train staff; adopt and drill incident response plans. This is the checklist regulators walk through in rectification orders.

People and presence (Articles 52-53). Above-CAC-threshold handlers designate a personal information protection officer, publish contact details, and file them. Foreign handlers within Article 3(2) scope establish a dedicated institution or designated representative in China and report its details, the structural anchor for enforcement against offshore companies.

Assessments (Articles 55-56). The PIPIA list is statutory: sensitive data, automated decision-making, entrusting, sharing, disclosure, exports, and other high-impact processing. Content: are purpose and method lawful, legitimate, and necessary; what is the impact and risk to individuals; are the safeguards legal, effective, and proportionate. Keep reports three years. Exports layer the transfer-specific assessment on top, per the cross-border guide.

Audits (Article 54 + 2025 measures). Regular self-audits of compliance with laws and administrative regulations; over 10 million individuals processed means at least one audit every two years; regulators can compel third-party professional audits after incidents, with rectification loops.

Entrusted processing (Articles 21, 59). Processor-equivalents work under contracts fixing purpose, duration, method, categories, protections, and rights/duties; they may not subcontract without consent of the handler, must return or delete data at contract end, and owe security assistance duties. Joint handlers (Article 20) allocate responsibilities by agreement but face joint and several liability.

Breach (Article 57). Remediate immediately; notify the authority and individuals with the statutory content; individual notice is waivable only if harm is effectively avoided, and the regulator can reinstate it.

Where programs fail

The recurring gaps in CAC enforcement notices: security measures documented but not implemented (the Didi decision itemized both), missing PIPIAs for sensitive processing, no filed officer or representative, and entrusted parties operating without conforming contracts. The PIPL roadmap sequences remediation; the rights guide covers the request-handling machinery these duties feed; and a free scan baselines what your public surfaces collect and share in the first place.

Frequently Asked Questions

Is a 'handler' the same as a GDPR controller?

Functionally yes: the organization that autonomously decides purposes and methods of processing. PIPL's counterpart to the processor is the 'entrusted party', governed by Article 21 contracts and Article 59 assistance duties. Joint handling under Article 20 requires an agreement allocating rights and duties, with joint and several liability toward individuals.

Who needs a personal information protection officer?

Handlers processing personal information above the volume prescribed by the CAC (the supporting national standard uses 1 million individuals as the working line) must designate an officer responsible for supervising processing and protection measures, publish their contact details, and file them with the regulator.

When is a PIPIA required?

Article 55: processing sensitive personal information, using data for automated decision-making, entrusting processing, providing data to other handlers, public disclosure, cross-border transfers, and any other processing with major influence on individuals. The assessment covers legality/necessity, impact and risks, and safeguard effectiveness, with reports kept three years.

What do the 2025 audit measures add?

The CAC's Administrative Measures for Personal Information Protection Compliance Audits (effective 1 May 2025) formalize Article 54: handlers processing over 10 million individuals' data must audit at least every two years, and regulators can order a professional-agency audit after major incidents or high-risk findings, with rectification reports back to the regulator.

What must happen after a breach in China?

Immediate remediation, then notification to the performing authority and affected individuals covering categories, causes, possible harm, measures taken, and mitigation steps individuals can take. Notice to individuals is waivable only where measures effectively avoid harm; the regulator can still order it if it judges harm possible.

Regulatory Crosswalk

GDPR controller/processorPIPLChina DSL

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.