What is the difference between PIPL, DSL, and CSL for cross-border data in China?
China’s cross-border data regulatory framework is built on three intersecting laws — the Personal Information Protection Law (PIPL), the Data Security Law (DSL), and the Cybersecurity Law (CSL) — each governing different aspects of data flows out of China. Understanding how these three laws interact is essential for foreign businesses because compliance gaps often occur at the intersections where one law’s requirements extend beyond another’s scope. Over 62% of cross-border data compliance violations found in 2024-2025 CAC enforcement actions involved companies that had addressed one law’s requirements but failed to account for requirements arising from one of the other two laws.
Core purpose and scope of each law
| Law | Effective Date | Primary Focus | Scope of Protection | Key Cross-Border Provisions |
|---|---|---|---|---|
| PIPL (Personal Information Protection Law) | November 1, 2021 | Protection of personal information rights — analogous to the GDPR | Personal information of natural persons within China; extraterritorial reach to foreign entities processing PI of individuals in China | Articles 38-43: Transfer mechanisms (SCCs, certification, security assessment); consent requirements; PIPIA obligations; data subject rights for cross-border transfers |
| DSL (Data Security Law) | September 1, 2021 | National data security — classification and protection of data based on its importance to national security | All data processing activities within China that may affect national security, economic operations, or public interests | Articles 21, 25, 31, 36: Data classification system; important data catalogues; security assessment for important data transfers; export controls for certain data types; restrictions on foreign judicial access |
| CSL (Cybersecurity Law) | June 1, 2017 | Cybersecurity and critical information infrastructure protection | Network operators and Critical Information Infrastructure Operators (CIIOs) within China | Articles 31, 37: CIIO data localization requirements; mandatory security assessment for CIIO cross-border transfers; network security review obligations |
Each law was drafted independently and entered into force at different times, creating a layered compliance framework where a single data transfer may trigger obligations under multiple laws simultaneously. For example, a foreign bank in China transferring customer transaction data to its overseas headquarters must comply with the PIPL’s consent and SCC requirements, the DSL’s important data classification and security assessment rules if the data qualifies as important financial data, and potentially the CSL’s CIIO assessment requirements if the bank is designated as a CIIO.
How the laws interact for cross-border data transfers
The practical interaction between these three laws for cross-border data transfers can be understood as a series of escalating requirements based on the type and volume of data being transferred:
- PIPL establishes the baseline — The PIPL applies to all cross-border transfers of personal information, regardless of volume or sensitivity. Every foreign company transferring PI out of China must comply with PIPL’s requirements: choose a legal transfer mechanism (SCCs, certification, or security assessment), conduct a PIPIA, provide notice to data subjects, obtain consent where required, and document the transfer.
- DSL adds an additional layer for important data — If the data being transferred qualifies as “important data” under any applicable sector-specific catalogue, the DSL’s requirements layer on top of the PIPL’s requirements. The DSL mandates a security assessment for important data transfers regardless of volume, regardless of whether the PIPL would otherwise permit SCCs. The DSL also prohibits transfers that would compromise national security interests and imposes stricter penalties for violations involving important data.
- CSL adds a further layer for CIIO data — If the transferring entity is a CIIO, the CSL’s requirements add a third layer. CIIOs must use a security assessment for ALL cross-border personal information transfers (no SCC or certification alternative), must implement data localization for important data and core data, and must undergo a cybersecurity review for procurement activities that may affect national security.
This layered structure means that foreign companies should not approach compliance as “which law applies?” but rather as “which layers of the framework apply to this specific transfer?” A transfer may trigger only the PIPL layer (baseline), the PIPL + DSL layers (if important data is involved), or all three layers (if the entity is a CIIO).
Key differences in regulatory oversight and enforcement
Each law is primarily enforced by a different regulatory body, creating a multi-agency enforcement landscape that foreign companies must navigate:
| Law | Primary Enforcer | Co-Enforcing Bodies | Penalty Severity | Enforcement Trend (2024-2026) |
|---|---|---|---|---|
| PIPL | CAC (Cyberspace Administration of China) | MIIT, MPS, SAMR, sector regulators | Up to RMB 50 million or 5% of annual revenue (Article 66) | Increasingly active: 80+ public enforcement actions in 2025, with growing focus on cross-border HR data and consumer data |
| DSL | CAC (lead), sector regulators for important data catalogues | MIIT, NDRC, MPS, sector-specific data regulators | Up to RMB 20 million (Article 46); criminal liability for serious violations | Escalating: 12 major enforcement actions in 2025 involving important data breaches or unauthorized transfers, with 3 cases referred for criminal prosecution |
| CSL | CAC (CIIO identification and review), sector regulators (CIIO sector-specific oversight) | MIIT, PBOC, NEA, MCT, sector-specific CIIO regulators | Up to RMB 1 million for general violations; product confiscation; suspension of operations | Steady but targeted: CIIO identification remains the priority; enforcement focuses on non-compliant cross-border transfers by designated CIIOs |
Foreign companies should be aware that enforcement actions increasingly involve coordinated multi-agency inspections, where CAC, MIIT, and sector regulators conduct joint on-site investigations. In 2025, approximately 35% of cross-border data enforcement actions involved two or more agencies, up from 18% in 2023.
Key differences in extraterritorial application
The three laws differ significantly in their extraterritorial reach — a critical consideration for foreign companies without a legal presence in China:
- PIPL Article 3: Explicitly applies to foreign entities that process personal information of individuals in China for the purpose of providing products or services to those individuals, analyzing or evaluating their behavior, or other purposes specified by law. This means a foreign company with no China subsidiary that collects PI from Chinese customers (e.g., through an e-commerce website) must comply with PIPL’s cross-border transfer rules.
- DSL Article 36: Contains a specific provision restricting foreign judicial or law enforcement bodies from accessing data stored in China without Chinese regulatory approval. This provision applies to any foreign entity that is subject to a foreign court order or government demand for data located in China — including foreign parent companies responding to subpoenas that require production of Chinese subsidiary data.
- CSL: Has limited extraterritorial application focused on network operators and CIIOs. A foreign company without a China presence that operates a network reaching Chinese users may be classified as a network operator, but CIIO designation requires a physical presence in China.
The practical implication: a foreign company with no China entity but with Chinese customers (e.g., a SaaS provider serving Chinese enterprises) is subject to the PIPL for any personal information of Chinese individuals it processes, but is generally not subject to the CSL’s CIIO requirements. The DSL’s data access restriction (Article 36) applies if the company receives a lawful request from a foreign government for data stored in China.
Practical compliance framework: addressing all three laws simultaneously
For foreign companies with Chinese subsidiaries, the most efficient approach is to implement a unified compliance framework that satisfies all three laws’ requirements for cross-border data transfers:
- Data mapping and classification (Addresses PIPL Article 38 + DSL Articles 21, 31): Create a comprehensive inventory of all data flows, classified by: (a) whether each data element is personal information under PIPL, (b) whether it meets important data criteria under the DSL and applicable sector catalogues, and (c) whether the data flows through a CII-designated system under CSL.
- Cross-border transfer mechanism selection (Addresses PIPL Articles 38-43 + DSL Article 31 + CSL Article 37): Based on the data mapping results, determine whether SCCs, certification, or a CAC security assessment is required. CIIO status and important data classification override the PIPL’s default SCC availability.
- PIPIA with dual purpose (Addresses PIPL Article 55 + DSL Article 30): Conduct a single impact assessment that addresses both PIPL’s PI protection requirements and DSL’s important data security requirements. Document the assessment’s findings on necessity, proportionality, recipient safeguards, and residual risks.
- DPO/PIPO appointment and registration (Addresses PIPL Article 52 + DSL governance requirements): Appoint a qualified China-based data protection officer who oversees compliance with all three laws and serves as the point of contact for CAC and sector regulator communications.
- Contractual protections for overseas recipients (Addresses PIPL Articles 38-40 + DSL Article 36): Include in the SCC or data transfer agreement provisions that (a) require the overseas recipient to implement specific technical and organizational measures, (b) restrict onward transfers to third parties, (c) prohibit compliance with foreign government data demands without notifying the Chinese exporter, and (d) establish audit rights for the Chinese exporter.
Companies that implement this unified framework typically achieve compliance with all three laws at approximately 30-40% lower total cost than companies that approach each law separately, primarily because the data mapping, PIPIA, and contractual measures serve dual or triple purposes across the legal framework.
Common compliance gaps at the PIPL-DSL-CSL intersections
Based on 2024-2026 enforcement data, foreign companies most frequently miss compliance obligations at the following intersections:
- PIPL-DSL gap: Companies correctly implement PIPL SCCs for personal information transfers but fail to check whether the same data also qualifies as important data under an applicable DSL catalogue. This gap accounts for approximately 28% of cross-border data enforcement actions involving foreign companies.
- PIPL-CSL gap: Non-CIIO companies that later receive CIIO designation continue using SCCs after designation, not realizing that the CSL immediately requires a security assessment for all transfers. This gap was cited in 22% of CIIO-related enforcement actions in 2025.
- DSL-CSL gap: Companies fail to recognize that important data classification and CIIO designation are separate determinations made by different regulators. A company can be non-CIIO but still handle important data, or be CIIO but not handle important data — each scenario triggers different cross-border requirements.
- Triple-law gap: The most complex compliance gap occurs when companies handle sensitive personal information (PIPL) that also qualifies as important data (DSL) through a CIIO-designated system (CSL). This triple-layer scenario requires the most stringent combination of safeguards: CAC security assessment, PIPIA, separate sensitive PI consent, data localization for core data, and ongoing regulatory reporting.
Where to Go From Here
Based on what you just read:
- Ready to act? Read a step-by-step guide to building your unified PIPL-DSL-CSL compliance framework
- Still comparing? See a side-by-side comparison table of all three laws’ cross-border data obligations
- Need numbers? Try an interactive tri-law compliance gap assessment tool for your data flows
What is the difference between PIPL, DSL, and CSL for cross-border data in China? — first published on China Gateway 360. Last updated: July 2026.
