Quick Answer

Date:

Share post:






What records must foreign companies keep for PIPL cross-border data compliance?


Quick Answer

Foreign companies processing personal information of individuals in China must retain the following records for PIPL cross-border data compliance: (1) a completed Data Protection Impact Assessment (DPIA) documenting data flows, risks, and mitigation measures; (2) a legally binding cross-border data transfer agreement (Standard Contractual Clauses or equivalent); (3) records of informed consent obtained from data subjects; (4) logs of cross-border data transfers including dates, categories of data, recipient details, and purposes; (5) appointment documentation for the China-based PIPL representative; (6) audit records of periodic compliance reviews; and (7) breach notification reports. Most records must be retained for at least five years under applicable Chinese regulations, and must be available for CAC inspection upon request.

Detailed Answer

Understanding the PIPL Record-Keeping Obligation

The Personal Information Protection Law (PIPL) of the People’s Republic of China, effective November 1, 2021, imposes comprehensive record-keeping obligations on personal information processors — including foreign companies — that engage in cross-border data transfers. Article 6 of the PIPL establishes the principle of “minimal necessity,” requiring processors to maintain records that demonstrate compliance with all legal requirements. For foreign businesses operating in or serving customers in China, the record-keeping burden is substantial and carries significant penalties for non-compliance.

The Cyberspace Administration of China (CAC) has issued specific regulations under the PIPL that elaborate on record-keeping requirements, including the Measures on the Standard Contract for Cross-border Transfer of Personal Information (effective June 1, 2023) and the Measures on Security Assessment for Cross-border Data Transfer (effective September 1, 2022). These regulations, alongside the Regulations on Promoting and Regulating Cross-border Data Flow (effective March 22, 2024), create a layered compliance framework that foreign companies must navigate.

Failure to maintain adequate records can result in fines of up to RMB 50 million or 5% of annual revenue, suspension of operations, revocation of business licenses, and inclusion on the CAC’s public non-compliance list — which can severely damage a company’s reputation and future business prospects in China.

The Seven Essential Record Categories

Based on the PIPL, its implementing regulations, and CAC guidance, foreign companies must maintain the following seven categories of records for cross-border data compliance. Each category serves a distinct regulatory purpose and must be maintained with specific content requirements.

1. Data Protection Impact Assessment (DPIA)

Article 55 of the PIPL mandates that personal information processors conduct a DPIA before engaging in any of the following activities: processing sensitive personal information, automated decision-making, entrusting processing to third parties, providing personal information to other processors, disclosing personal information publicly, or transferring personal information outside of China. The DPIA is the cornerstone document of cross-border data compliance.

Required DPIA content includes:

  • Data flow mapping: A complete inventory of what personal information is collected, from which sources, through which channels, and where it is stored and transmitted.
  • Processing purpose and legality basis: Documentation of the specific business purpose for each data processing activity and the legal basis under PIPL (consent, contractual necessity, legal obligation, vital interests, public interest, or legitimate interests).
  • Risk identification: Analysis of potential risks to data subjects’ rights and interests, including unauthorized access, data leakage, misuse, and re-identification risks.
  • Mitigation measures: Description of technical and organizational measures implemented to address identified risks, including encryption, access controls, anonymization, and data minimization practices.
  • Impact assessment: Evaluation of the potential impact on data subjects, considering both the likelihood and severity of harm.
  • Compliance conclusion: A documented determination that the proposed processing is compliant and that appropriate safeguards are in place.

The DPIA must be documented in writing and retained for at least three years from the date of completion, according to Article 56 of the PIPL. However, given that cross-border transfer records must be kept for five years under related regulations, it is prudent to retain DPIAs for the longer period.

2. Cross-Border Data Transfer Agreements

Foreign companies that transfer personal information outside of China must enter into legally binding agreements with overseas recipients that specify each party’s data protection obligations. The form of this agreement depends on the chosen transfer mechanism:

Transfer Mechanism Agreement Requirement Record-Keeping Obligation
Standard Contractual Clauses (SCCs) Signed SCC in the CAC-prescribed format (6-month filing deadline) Keep signed SCC + filing receipt + any supplementary agreements
Security Assessment CAC assessment approval letter + application documentation Keep full application dossier + CAC approval + response to any CAC follow-up queries
Certification (e.g., by CNCA-accredited body) Certification certificate + contractual clauses incorporating certification obligations Keep certification certificate + audit reports + annual surveillance reports
Ad-Hoc Agreement (where permitted) Custom agreement meeting PIPL requirements Keep agreement + legal review confirming compliance with PIPL standards + supplementary data mapping

The signed agreement must be filed with the provincial CAC office within the prescribed timeframe (generally 10 working days from execution for SCCs, unless filing is via the provincial-level CAC). Foreign companies must retain the executed agreement, any amendments, and correspondence with the CAC regarding the filing or approval process for the duration of the data transfer relationship plus five years.

3. Informed Consent Records

Under Article 13 of the PIPL, consent is one of the primary legal bases for processing personal information. For cross-border data transfers, Article 39 specifically requires separate consent from data subjects. This means that general consent obtained for domestic processing does not extend to cross-border transfers — companies must obtain explicit, separate consent that is:

  • Informed: Data subjects must be told the name and contact information of the overseas recipient, the purpose and method of processing, the categories of personal information transferred, and the means and procedures for exercising their PIPL rights.
  • Freely given: Consent cannot be bundled with acceptance of terms of service or coerced through take-it-or-leave-it offers.
  • Specific: Consent must be obtained for each specific cross-border transfer purpose, not as a blanket authorization.
  • Unambiguous: Clear affirmative action is required — pre-ticked boxes or implied consent do not satisfy PIPL requirements.
  • Documented: Records must show when, how, and what information was provided to the data subject before consent was given.

Records to maintain: Foreign companies should keep consent management logs that include the consent version shown to the data subject (with timestamps), the mechanism used to obtain consent (click-through, signature, biometric, etc.), the specific disclosures made to the data subject, the data subject’s response, withdrawal or modification of consent (if applicable), and consent expiration or renewal dates. These records should be retained for at least the duration of the data processing plus five years.

4. Cross-Border Transfer Logs

Beyond the foundational agreements and consent records, foreign companies must maintain operational logs of each cross-border data transfer. The CAC expects that companies can produce, upon request, a detailed record of every transfer of personal information outside of China. This is one of the most commonly cited deficiencies in CAC compliance inspections.

Minimum log content for each transfer:

  1. Date and time of the transfer (in China Standard Time).
  2. Categories of personal information transferred (e.g., name, ID number, financial data, health data, biometric data).
  3. Volume of data transferred (number of data subjects affected and data volume in MB/GB).
  4. Purpose of the transfer (specific business function, not generic descriptions).
  5. Overseas recipient (legal name, jurisdiction, data processing location).
  6. Legal basis for the transfer (SCC filing number, Security Assessment approval reference, individual consent record ID).
  7. Technical method of transfer (API call, encrypted file transfer, cloud replication, manual export).
  8. Data protection measures applied (encryption standard, access control scope, data masking applied).
  9. Individual responsible for authorizing the transfer.

Transfer logs should be retained for no less than five years. Automated logging systems that capture transfer metadata at the network or application layer are strongly recommended, as manual logs are prone to errors and omissions that can result in compliance findings during a CAC inspection.

5. China-Based Representative Appointment Records

Article 53 of the PIPL requires foreign personal information processors that process the personal information of individuals in China to appoint a representative within China. This requirement mirrors Article 27 of the GDPR but applies to a broader range of foreign companies. The representative serves as the primary point of contact for data subjects and Chinese regulators.

Records to maintain include:

  • Appointment agreement between the foreign company and the China-based representative (individual or entity).
  • Contact information of the representative (legal name, business address in China, telephone number, email address).
  • Scope of authority document specifying the representative’s responsibilities (receiving data subject inquiries, cooperating with CAC investigations, receiving legal documents).
  • Termination and replacement records if the representative changes, including transition arrangements to ensure continuity of compliance.
  • Communication logs of interactions between the foreign company and the representative regarding compliance matters.

The representative’s contact information must be disclosed to data subjects (typically through the company’s privacy policy on its China-facing website) and filed with the relevant authority where applicable. Records of the representative appointment must be maintained throughout the duration of processing operations in China and for at least five years thereafter.

6. Compliance Audit Records

Article 54 of the PIPL requires personal information processors to conduct regular compliance audits. The frequency of audits depends on the nature and volume of data processing: companies handling large volumes of personal information (the CAC defines this as processing the personal information of more than one million individuals) should conduct audits at least annually, while smaller processors may conduct audits every two years.

Records to maintain include:

  • Audit engagement letter or internal authorization document.
  • Audit scope and methodology description.
  • Findings and recommendations report.
  • Corrective action plan with assigned responsibilities and deadlines.
  • Evidence of remediation (updated policies, technical controls implemented, training completed).
  • Management sign-off on audit findings and remediation.
  • External audit reports if audits are conducted by third-party firms (recommended for demonstrating good faith compliance).

Audit records must be retained for at least three years. However, given that audit findings often inform cross-border data transfer risk assessments and DPIA updates, it is recommended to retain audit records for the full five-year retention period applicable to cross-border transfer documentation.

7. Breach Notification Records

Article 57 of the PIPL requires immediate breach notification to the CAC and affected data subjects when a data breach occurs. The notification must include: the nature and categories of personal information involved, the number of affected data subjects, the possible consequences of the breach, remedial measures taken or proposed, and contact information for follow-up. Foreign companies must ensure their incident response procedures cover the specific requirements of Chinese regulators, which may differ from breach notification requirements in their home jurisdictions.

Records to maintain include:

  • Incident discovery log including date, time, and method of discovery.
  • Initial assessment report documenting the likely scope and impact.
  • CAC notification copy with timestamp of submission.
  • Data subject notification copy and method of delivery.
  • Internal investigation report documenting root cause analysis.
  • Remediation plan and completion evidence.
  • Post-incident review and lessons learned documentation.
  • Regulatory follow-up correspondence with the CAC.

Breach notification records have the longest retention requirement — at least five years from the date of the incident — as they may be referenced in subsequent compliance inspections or legal proceedings.

Record Retention Periods: A Summary Table

Record Type Minimum Retention Period Legal Basis
DPIA documentation 3 years PIPL Article 56
Cross-border transfer agreements (SCCs, etc.) 5 years after transfer relationship ends CAC SCC Measures
Informed consent records Duration of processing + 5 years PIPL Article 13 + CAC guidance
Cross-border transfer logs 5 years CAC Data Transfer Rules
Representative appointment records Duration of processing + 5 years PIPL Article 53
Compliance audit records 3 years (recommended: 5 years) PIPL Article 54
Breach notification records 5 years PIPL Article 57 + CAC practice

Common Record-Keeping Pitfalls for Foreign Companies

Based on CAC enforcement actions and compliance inspection findings published between 2022 and 2026, foreign companies most frequently fall short in the following areas:

  1. Incomplete DPIA documentation. Many foreign companies prepare DPIAs that address EU GDPR requirements but omit PIPL-specific elements such as the separate consent requirement for cross-border transfers (Article 39) and the specific risk assessment of Chinese government access requests. Chinese regulators expect the DPIA to explicitly address risks arising from China’s data security and national security laws, not just commercial privacy risks.
  2. Consent records that do not demonstrate “separate” consent. Foreign companies frequently use the same consent mechanism for both domestic processing and cross-border transfers. The PIPL requires separate, specific consent for cross-border transfers, and the records must clearly distinguish between the two consent events.
  3. Transfer logs that lack granularity. Companies often maintain high-level records of data transfers (monthly totals by recipient) rather than the transaction-level logs that the CAC expects. During a CAC inspection, companies may be asked to produce a list of all cross-border transfers within a specific date range, and generic logs without sufficient detail will be flagged as a deficiency.
  4. Failure to appoint a China-based representative. Many foreign companies operating exclusively through digital channels (e-commerce, SaaS, social media) assume the PIPL representative requirement does not apply to them. In fact, any foreign company that processes personal information of individuals in China — regardless of whether it has a physical presence in China — must appoint a representative.
  5. Inadequate audit frequency. Foreign companies processing data of more than one million individuals who conduct biennial or ad-hoc audits instead of annual audits are at risk of a non-compliance finding. The PIPL requires “regular” audits, and CAC guidance interprets “regular” as at least annually for larger processors.

How to Organize Your Record-Keeping Program

Establishing a PIPL-compliant record-keeping program requires a systematic approach. Foreign companies should consider the following framework:

  1. Create a PIPL compliance register — a centralized repository (physical or electronic, but preferably a secure digital platform) that houses all seven categories of records with indexed access for quick retrieval during CAC inspections.
  2. Implement automated logging — deploy technical controls that automatically capture cross-border transfer metadata at the network or application layer, reducing reliance on manual logging.
  3. Conduct quarterly record audits — review the completeness and accuracy of compliance records every quarter, not just during the annual compliance audit. This ensures gaps are identified and addressed promptly.
  4. Centralize responsibility — designate a PIPL compliance officer (either in China or working closely with the China-based representative) who is responsible for maintaining and updating all compliance records.
  5. Prepare an inspection-ready binder — organize all seven categories of records in a format that can be produced to the CAC within 24 to 48 hours. CAC inspections can be triggered by complaints, media reports, or random selection, and the initial response window is typically very short.

Quick Checklist for Foreign Companies

Record Category Status Action Items
DPIA Complete / In Progress / Not Started Include PIPL-specific risk assessment
Cross-border transfer agreement Complete / In Progress / Not Started File with provincial CAC within 10 working days
Informed consent records Complete / In Progress / Not Started Separate consent for cross-border transfers
Transfer logs Complete / In Progress / Not Started Automated logging system recommended
Representative appointment Complete / In Progress / Not Started Disclose contact info on China-facing website
Compliance audit records Complete / In Progress / Not Started Annual frequency for large processors
Breach notification records Complete / In Progress / Not Started Include incident response procedure specific to China

This article is for informational purposes only and does not constitute legal advice. Foreign companies should consult qualified Chinese legal counsel for advice tailored to their specific circumstances. First published on china-gateway360.com. For more guidance on China PIPL compliance for foreign businesses, see our resources on cross-border data transfer mechanisms and China data protection best practices. To discuss your specific PIPL record-keeping requirements, contact our compliance advisory team or explore our PIPL compliance toolkit. Ready to start your compliance journey? Launch Your China Business with Confidence.


Related articles

How a Foreign Biotech Startup Entered China’s Precision Medicine Market: Case Study

How a Foreign Biotech Startup Entered China's Precision Medicine Market: Case Study In 2023, NovaOnco Therapeutics, a US-based AI biotech startup, exe

How Legend Biotech Secured FDA Approval for CAR-T Therapy: Case Study

How Legend Biotech Secured FDA Approval for CAR-T Therapy: A China Biotech Case Study This case study examines how Legend Biotech (传奇生物, Legend Biotec

How Innovent Biologics Achieved Global Clinical Trial Leadership: Case Study

How Innovent Biologics Achieved Global Clinical Trial Leadership: Case Study body{font-family:'Segoe UI',Tahoma,Geneva,Verdana,sans-serif;line-height:

How BeiGene Built a Billion-Dollar Biotech in China: Case Study

How BeiGene Built a Billion-Dollar Biotech in China: Case Study How BeiGene Built a Billion-Dollar Biotech in China: Case Study The story of BeiGene's