PIPL assigns its duty stack to the “personal information handler,” the organization that decides why and how personal information is processed. The obligations will look familiar from GDPR, but three run harder in China: impact assessments attach to a fixed statutory list of activities, compliance audits are a formal regulatory instrument with their own 2025 measures, and above-threshold handlers owe structural commitments (an officer, and for foreign handlers, a China presence).
| Regulation | PIPL Articles 9, 20-21, 51-59 |
|---|---|
| Max penalty | RMB 50M or 5% of prior year’s turnover |
| Enforcing authority | CAC |
| Audit rules | CAC compliance audit measures, effective 1 May 2025 |
The duty stack
Security and governance (Article 51). Formulate internal management systems and operating procedures; implement classified management of personal information; apply encryption and de-identification as appropriate; set access permissions and train staff; adopt and drill incident response plans. This is the checklist regulators walk through in rectification orders.
People and presence (Articles 52-53). Above-CAC-threshold handlers designate a personal information protection officer, publish contact details, and file them. Foreign handlers within Article 3(2) scope establish a dedicated institution or designated representative in China and report its details, the structural anchor for enforcement against offshore companies.
Assessments (Articles 55-56). The PIPIA list is statutory: sensitive data, automated decision-making, entrusting, sharing, disclosure, exports, and other high-impact processing. Content: are purpose and method lawful, legitimate, and necessary; what is the impact and risk to individuals; are the safeguards legal, effective, and proportionate. Keep reports three years. Exports layer the transfer-specific assessment on top, per the cross-border guide.
Audits (Article 54 + 2025 measures). Regular self-audits of compliance with laws and administrative regulations; over 10 million individuals processed means at least one audit every two years; regulators can compel third-party professional audits after incidents, with rectification loops.
Entrusted processing (Articles 21, 59). Processor-equivalents work under contracts fixing purpose, duration, method, categories, protections, and rights/duties; they may not subcontract without consent of the handler, must return or delete data at contract end, and owe security assistance duties. Joint handlers (Article 20) allocate responsibilities by agreement but face joint and several liability.
Breach (Article 57). Remediate immediately; notify the authority and individuals with the statutory content; individual notice is waivable only if harm is effectively avoided, and the regulator can reinstate it.
Where programs fail
The recurring gaps in CAC enforcement notices: security measures documented but not implemented (the Didi decision itemized both), missing PIPIAs for sensitive processing, no filed officer or representative, and entrusted parties operating without conforming contracts. The PIPL roadmap sequences remediation; the rights guide covers the request-handling machinery these duties feed; and a free scan baselines what your public surfaces collect and share in the first place.