Direct answer
The PIPL is central, but operational compliance also depends on audit, impact-assessment, security, sector and network-data rules.
Current rules
Regulatory timeline
- Effective
PIPL takes effect
The central personal information protection law becomes effective.
Open official source - Effective
Compliance audit measures take effect
Audit duties and regulatory interfaces are formalized.
Open official source - Upcoming
Small-processor measures take effect
Eligible processors receive proportionate arrangements subject to exclusions.
Open official source
Versions and relationships
Practical sequence
- 01
Identify purposes, legal bases and owners.
- 02
Classify sensitive, minor and high-risk processing.
- 03
Maintain transparency, consent, personal information protection impact assessment and rights evidence.