china-pipl skill
Guides compliance with China''s Personal Information Protection Law (PIPL, effective 1 November 2021). Covers consent requirements, cross-border transfer mechanisms (CAC security assessment, standard contracts, certification), separate consent triggers, and critical information infrastructure obligations. Keywords: PIPL, China data protection, CAC security assessment, cross-border transfer, separate consent, CIIO.
Is the china-pipl skill safe?
Clean: nothing in its files matched our rules. We read 1 file in the folder on 2026-09-28.
No findings.
Install the china-pipl skill
A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.
git clone --depth 1 https://github.com/ThomasMoreAI/legal-skills-open.git /tmp/legal-skills-open mkdir -p ~/.claude/skills cp -r /tmp/legal-skills-open/cn/data-protection/skills/china-pipl ~/.claude/skills/china-pipl
In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub
The instructions your agent would load
SKILL.md as published, without the frontmatter. Read it on GitHub
China PIPL Compliance
Overview
The Personal Information Protection Law of the People's Republic of China (PIPL, 个人信息保护法) was adopted by the Standing Committee of the National People's Congress on 20 August 2021 and took effect on 1 November 2021. The PIPL is China's first comprehensive national personal information protection law, operating alongside the Cybersecurity Law (CSL, effective 1 June 2017) and the Data Security Law (DSL, effective 1 September 2021) to form China's data governance framework.
The Cyberspace Administration of China (CAC, 国家互联网信息办公室) is the primary regulator, with enforcement authority shared among the Ministry of Public Security, the Ministry of Industry and Information Technology (MIIT), and sector-specific regulators.
Scope and Extraterritorial Application
Territorial Scope (Art. 3)
The PIPL applies to:
- Processing of personal information of natural persons within the territory of the PRC (Art. 3(1))
- Processing conducted outside the PRC of personal information of natural persons within the PRC where the purpose is:
- Providing products or services to natural persons within the PRC (Art. 3(2)(i))
- Analysing or assessing the behaviour of natural persons within the PRC (Art. 3(2)(ii))
- Other circumstances provided by laws or administrative regulations (Art. 3(2)(iii))
Extraterritorial Compliance (Art. 53)
Overseas personal information processors falling under Art. 3(2) must:
- Establish a dedicated entity or designate a representative within the PRC to handle personal information protection matters
- Report the name and contact information of the entity or representative to the relevant CAC department
Zenith Global Enterprises implementation: Zenith has designated its Shanghai office (Zenith Global Logistics (Shanghai) Co., Ltd) as the PRC representative entity, with the local Data Protection Manager serving as the designated contact.
Lawful Bases for Processing (Art. 13)
Key distinction from GDPR: The PIPL does not include a standalone legitimate interest basis. Art. 13(6) (processing lawfully disclosed information) is the closest analogue but far narrower in scope.
Consent Framework
General Consent Requirements (Arts. 14-16)
Separate Consent Triggers (单独同意)
The PIPL requires separate consent (单独同意, dāndú tóngyì) — consent obtained independently from other consent collection — for the following processing activities:
Zenith Global Enterprises implementation:
- Consent management platform configured with separate consent flows for each trigger scenario
- Customer onboarding includes distinct consent checkboxes for: (a) primary service processing, (b) data sharing with logistics partners, (c) cross-border transfer to headquarters, (d) credit assessment (sensitive PI)
- Employee consent flows include separate consent for: (a) employment data cross-border transfer, (b) background check (sensitive PI)
Sensitive Personal Information (Art. 28)
Definition
Sensitive personal information (敏感个人信息) is personal information that, once leaked or illegally used, may easily lead to infringement of the dignity of natural persons or harm to their personal or property safety. It includes:
- Biometric information
- Religious beliefs
- Specific identity information (including ID numbers)
- Medical and health information
- Financial account information
- Location tracking information
- Personal information of minors under 14 years of age
Processing Requirements (Arts. 28-32)
Zenith Global Enterprises Sensitive PI Register
Cross-Border Transfer Mechanisms (Arts. 38-43)
Three Mandatory Mechanisms
The PIPL provides three primary mechanisms for transferring personal information outside the PRC, applicable based on the processor's scale and nature:
1. CAC Security Assessment (Art. 40; CAC Measures effective 1 September 2022)
When required (mandatory for any of the following):
- Critical information infrastructure operators (CIIOs) transferring any personal information abroad
- Processors that process personal information of 1 million or more individuals
- Processors that have cumulatively transferred personal information of 100,000 or more individuals abroad since 1 January of the preceding year
- Processors that have cumulatively transferred sensitive personal information of 10,000 or more individuals abroad since 1 January of the preceding year
Process:
- Conduct a self-assessment (personal information protection impact assessment)
- Submit the application to the CAC through the provincial-level CAC office
- CAC completes the assessment within 45 working days (extendable by another 15 working days for complex cases)
- Assessment valid for 2 years from the date of the assessment result, renewable upon expiry
Zenith Global Enterprises status: As Zenith processes personal information of over 100,000 customers and employees in China, and has transferred personal information of more than 100,000 individuals abroad cumulatively, the CAC security assessment is the mandatory transfer mechanism.
2. Standard Contract for Cross-Border Transfer (Art. 38(2); CAC Measures effective 1 June 2023)
When applicable (must meet all conditions):
- The processor is not a CIIO
- The processor processes personal information of fewer than 1 million individuals
- Cumulative cross-border transfer of fewer than 100,000 individuals' personal information since 1 January of the preceding year
- Cumulative cross-border transfer of fewer than 10,000 individuals' sensitive personal information since 1 January of the preceding year
Process:
- Conduct a personal information protection impact assessment
- Execute the CAC-published standard contract with the overseas recipient
- File the executed contract with the provincial-level CAC office within 10 working days of effectiveness
Standard contract key provisions:
- Purpose, scope, and method of processing by the overseas recipient
- Overseas recipient's obligations regarding data protection
- Individual rights protection mechanisms
- Remedies and liability allocation
- Termination conditions
3. Personal Information Protection Certification (Art. 38(3); TC260 Specification effective November 2022)
When applicable:
- Cross-border transfers within a multinational group or between entities subject to the same PI protection policies
- Processors that meet the standard contract thresholds
Process:
- The processor and overseas recipient jointly apply to an accredited certification body
- Certification body evaluates compliance with the TC260 Specification for Cross-Border Processing Activities
- Certification valid for 3 years with annual supervision audits
- Both parties must accept supervision by the certification body and the CAC
CAC Relaxation Measures (March 2024)
The CAC issued the Provisions on Facilitating and Regulating Cross-Border Data Flows (effective 22 March 2024), which introduced exemptions:
Important: These exemptions do not apply to CIIOs, transfers of important data, or transfers exceeding the specified thresholds.
Zenith Global Enterprises Cross-Border Transfer Register
Critical Information Infrastructure (CII)
CIIO Obligations Under PIPL
Critical information infrastructure operators (关键信息基础设施运营者, CIIOs) face additional obligations:
CII Sector Identification
The following sectors are designated as CII under the Critical Information Infrastructure Security Protection Regulations (effective 1 September 2021):
- Public communications and information services
- Energy
- Transportation
- Water conservancy
- Finance
- Public services
- E-government
- National defence science and industry
- Other important network facilities and information systems that may endanger national security, people's livelihood, or the public interest if damaged
Zenith Global Enterprises assessment: As a logistics company, Zenith may be designated as CII under the transportation sector if its systems are determined to endanger national security or the public interest if damaged. Zenith maintains ongoing dialogue with the relevant sector authority (Ministry of Transport) regarding CII designation status.
Personal Information Protection Impact Assessment (PIPIA)
More skills from ThomasMoreAI/legal-skills-open
- A02民事诉讼案件的诉讼文书制备阶段。承接阶段一(战略把脉)的分析成果,将策略方案转化为可直接提交法院的正式法律文书,同时建立对方来文和法院来文的管理机制。当用户已完成阶段一、需要起草起诉状/答辩状、制作证据目录、或收到对方/法院文书需要处理时触发。适用于原告准备起诉材料,或被告准备应诉材料。
- A02-lyronlee二审程序的诉讼文书制备阶段。承接阶段一(战略分析)的分析成果,将上诉策略转化为可直接提交二审法院的正式法律文书。当用户已完成阶段一、需要起草上诉状或二审答辩状、制作新证据目录、或收到法院来文需要处理时触发。适用于上诉人准备上诉材料,或被上诉人准备应诉材料。
- Aad-compliance-review广告合规审核技能,用于审核广告素材是否符合中国广告法及相关法规。适用场景:(1) 用户提交广告文案、广告素材要求合规审核时;(2) 用户提到"广告审核""广告合规""广告法审查"等关键词时;(3) 用户要求检查广告内容是否存在违法违规风险时;(4) 用户提交房地产、食品、医疗、药品、互联网等行业广告要求专项审核时。审核依据涵盖《广告法》《反不正当竞争法》及行业专项法规。
- Aadmin-reviewReviews administrative case documents for procedural compliance across 38 checkpoints, covering filing, summons, handling outcomes, evidence, and rights protection. Use when auditing public security administrative case files in txt format for legal procedure violations.
- Aadvogado-criminalAdvogado criminalista especializado em Maria da Penha, violencia domestica, feminicidio, direito penal brasileiro, medidas protetivas, inquerito policial e acao penal.
- Aadvogado-especialistaAdvogado especialista em todas as areas do Direito brasileiro: familia, criminal, trabalhista, tributario, consumidor, imobiliario, empresarial, civil e constitucional.
- Aage-verification-methodsEvaluates and implements age estimation and verification technologies for online services. Covers facial age estimation, digital ID verification, self-declaration with risk assessment, AI-based age estimation, and the accuracy versus privacy tradeoff. Includes ICO guidance and euCONSENT framework. Keywords: age verification, age estimation, facial analysis, digital ID, children, online safety.
- Aai-privacy-assessmentGuides the combined DPIA and AI Act conformity assessment for AI systems processing personal data. Covers EDPB-EDPS Joint Opinion 5/2021, training data lawfulness under Art. 6 and Art. 9, Art. 22 automated decision-making, algorithmic bias detection, and NIST AI RMF MAP function. Keywords: AI privacy, DPIA, AI Act, algorithmic bias, automated decision-making, Art. 22, training data, NIST AI RMF.
- Aanalise-processo-penalAssessoria judicial completa para processos penais. Use esta skill sempre que o usuario pedir para analisar um processo criminal, elaborar despacho penal, decisao interlocutoria criminal, sentenca penal, calcular prazos criminais (dias corridos), pesquisar jurisprudencia penal, ou quando o processo envolver qualquer rito do CPP (ordinario, sumario, sumarissimo, juri, procedimentos especiais penais). Tambem use quando o usuario mencionar termos como "criminal", "penal", "CPP", "crime", "denuncia", "inquerito", "prisao", "liberdade provisoria", "habeas corpus", "tribunal do juri", "acao penal", "execucao penal", "LEP", "suspensao condicional", "sursis", "livramento condicional", "medida de seguranca", "transacao penal", "suspensao condicional do processo", "audiencia de custodia", "colaboracao premiada", "acordo de nao persecucao penal", ou qualquer procedimento regulado pelo Codigo de Processo Penal brasileiro.
- Aapac-transfersGuides management of cross-border data transfers under Asia-Pacific regulatory frameworks including APEC CBPR, ASEAN Model Contractual Clauses, Japan APPI supplementary rules, South Korea PIPA provisions, and Thailand/Singapore PDPA mechanisms. Keywords: APEC CBPR, ASEAN MCCs, APPI, PIPA, PDPA, APAC transfers.
- Aapec-cbpr-certGuides APEC Cross-Border Privacy Rules system certification process including self-assessment against the APEC Privacy Framework principles, accountability agent selection, intake questionnaire completion, certification decision, annual recertification, and Global CBPR Forum transition. Keywords: APEC, CBPR, cross-border privacy, accountability agent, certification, Global CBPR.
- Aarckit-at-bvergg[COMMUNITY] Generate Austrian public procurement documentation aligned with Bundesvergabegesetz 2018 — Oberschwellen/Unterschwellen determination, ANKÖ publication, BVergGVS secondary rules, and BVwG review pathway