Research across the library

Search laws, regulations, standards and guides

Suggested searches

Current priorities

2026-07-03Revised Internet Information Service Measures draft2026-06-18Network data risk assessment: draft versus final

What These Guides Do

Explainers identify the controlling sources, describe how documents relate, and point to the next public pages to read. They do not reproduce complete supporting regulations or decide how a rule applies to a particular activity.

Start with a Research Theme

Guidance

Public personal information is not unrestricted data

A practical research framework for assessing reuse of published contact details and reviewing basic leakage risks, with separate legal-source notes and hypothetical examples.

Sources checked: 2026-09-09

Effective

PIPL impact assessment: triggers, evidence and the audit boundary

An impact assessment is a decision record for a defined processing activity, not a privacy policy or an audit certificate. Map the statutory trigger, test necessity and safeguards, and preserve the evidence behind the conclusion.

Sources checked: 2026-09-11

Effective

Personal information compliance audits: scope, timing and evidence

The 2025 audit measures distinguish regular internal or commissioned audits from authority-required professional audits. Build the programme around actual processing, defensible sampling and verified remediation, with the later small-processor rules applied separately.

Sources checked: 2026-09-11

Guidance

Important data in China: sector sources and identification steps

An evidence map for automotive, industrial, telecom and financial activities: identify the applicable source, distinguish sensitivity from important-data designation, and keep domestic reporting separate from export approval.

Sources checked: 2026-09-14

Guidance

China data export: choosing the right route

Start with the transfer, not the paperwork. Compare the current thresholds, exemptions, filing steps and renewal rules, with worked boundary cases and the September 2026 certification clarification.

Sources checked: 2026-09-16

Guidance

Security assessment filing: the third-edition guide

A practical reading of the full official guide and its five annexes: what changed from the second edition, how to reconcile the filing package, and how an extension application differs from a new assessment.

Sources checked: 2026-09-16

published

Network Data Security Regulation Overview

The Network Data Security Regulation is a State Council regulation effective 2025-01-01 that connects to China's CSL, DSL, PIPL, and network data governance framework.

Last updated: 2026-05-21

published

PIPL Compliance Reference Overview

A general informational PIPL compliance reference overview for source-based research. It is not a legal audit, legal advice, or company-specific compliance assessment.

Last updated: 2026-05-26

published

What Is Cross-border Data Transfer Under China Data Law?

Cross-border data transfer is a source-sensitive topic under China's data protection framework. The analysis may involve personal information, important data, network data, route mechanisms, and official CAC rules.

Last updated: 2026-05-21