Practice Area · 05
China Data Privacy and Cross-Border Compliance
China’s data compliance regime affects how companies collect, use, store and transfer personal information and business data. Li & Shi China Counsel helps international companies navigate PIPL, DSL, CSL and cross-border data transfer obligations with practical, risk-based solutions.
HOME > SERVICE > Data Privacy & Compliance
Overview
Regulatory Insight
China’s data governance framework is built around the Personal Information Protection Law (PIPL), Data Security Law (DSL) and Cybersecurity Law (CSL). Together, these rules affect privacy notices, consent mechanisms, data minimisation, data classification, cybersecurity measures, vendor contracts, employee data, cross-border transfers and incident response.
Cross-border data transfer is a common risk area for multinational companies. The applicable compliance path may involve a security assessment, standard contractual clauses, certification or an exemption, depending on the data type, volume, purpose, recipient, sector and whether important data is involved. The 2024 cross-border data transfer rules created important facilitation mechanisms, but companies still need documentation, data mapping and internal controls.
We provide legal analysis that can be implemented by legal, compliance, HR, IT and business teams, rather than abstract regulatory summaries.
Law
Three-Law Snapshot
PIPL
Regulates personal information processing, consent, legal bases, individual rights, processor obligations and cross-border personal information transfers.
DSL
Establishes data classification and data security obligations, including heightened obligations for important data and sector-specific rules.
CSL
Imposes network security obligations and additional requirements for critical information infrastructure operators and certain network operators.
Service
Scope of Services
01
Data Compliance Audit
Map data flows, identify personal information and important data issues, review policies, consent mechanisms, storage, access control and vendor arrangements.
02
Cross-Border Data Transfer Review
Assess whether security assessment, SCC filing, certification or exemption applies; prepare documentation and remediation roadmap.
03
Privacy Documentation
Draft or review privacy notices, consent forms, employee privacy notices, data processing agreements and group data transfer documents.
04
Vendor and Platform Compliance
Review cloud, SaaS, HR, marketing, analytics and e-commerce vendor arrangements for China data compliance risks.
05
Incident Response
Advise on internal investigation, notification obligations, regulator communication and remedial measures following data or cybersecurity incidents.
06
Training and Ongoing Monitoring
Provide bilingual training for legal, HR, IT and business teams and annual reviews of regulatory changes affecting China operations.
Representative Matter
Cross-Border Data Transfer Remediation - Overseas SaaS Company
An overseas SaaS company providing services to Chinese enterprise customers required a review of personal information transferred from China to overseas servers. The issue involved employee data, platform user data, privacy notices, internal permissions and cross-border transfer documentation.
The remediation plan involved data mapping, legal basis analysis, document updates, standard contractual clause assessment or filing support where applicable, consent-flow improvements and internal training.