What Records Must Foreign Companies Keep for PIPL Cross‑Border Data Compliance?

Date:

Share post:

What Records Must Foreign Companies Keep for PIPL Cross‑Border Data Compliance?

Foreign companies transferring personal information (PI) out of China must maintain six mandatory record categories under the Personal Information Protection Law (个人信息保护法, PIPL, gèrén xìnxī bǎohù fǎ). The Cyberspace Administration of China (CAC) requires these records to be retained for at least 3 years, and non‑compliance can lead to fines of up to RMB 50 million or 5% of annual revenue. Below we break down each record type, retention periods, and common pitfalls.

What is a Personal Information Impact Assessment (PIA) and do I need to keep it?

A Personal Information Impact Assessment (PIA) is a compulsory analysis that must be performed before any cross‑border transfer. The assessment must document: (1) the purpose and scope of the transfer, (2) the sensitivity and volume of data, (3) the overseas recipient’s data protection capabilities, (4) the risk of leakage or misuse, and (5) the measures taken to mitigate risks. Under Article 56 of the PIPL, the PIA report and its implementation log must be kept for at least 3 years from the date the transfer ends. Failure to produce a PIA when requested can trigger immediate suspension of data transfer activities.

Many foreign companies mistakenly treat the PIA as a one‑time document. In reality, it must be updated whenever the transfer purpose, method, or overseas recipient changes. A 2023 CAC enforcement action against a global e‑commerce firm resulted in a RMB 2 million fine because their PIA was two years out of date.

How long must I retain consent records for cross‑border transfers?

PIPL Article 15 requires separate, explicit consent from each data subject for the cross‑border transfer. You must keep records of: (i) the consent form provided to the individual, (ii) the time and method of consent collection, (iii) the version of the privacy notice in force at the time, and (iv) any withdrawal of consent. These records must be retained for the duration of the transfer plus 3 years afterward. The CAC recommends using a time‑stamped consent‑management system that logs every consent action.

Common oversight: Many firms only store the consent checkbox click without the accompanying privacy notice. If a data subject files a complaint, the regulator will ask for the exact version of the notice they agreed to.

What contract terms must be documented with overseas data recipients?

Article 38 of the PIPL mandates that a cross‑border data transfer contract be signed between the foreign company (as the controller) and the overseas recipient. The contract must include: (1) the purpose and duration of processing, (2) the categories of PI being transferred, (3) the recipient’s obligation to implement protective measures, (4) liability for breach, and (5) provisions for the data subject’s rights (e.g., access, deletion). A copy of the signed contract must be retained for at least 3 years after termination. The CAC’s Standard Contract for Cross‑Border Transfer (promulgated in 2023) is the preferred format for most foreign companies.

Table: Six Mandatory Record Categories Under PIPL Cross‑Border Transfers

Record Category Key Requirement Retention Period Authority
Personal Information Impact Assessment (PIA) Pre‑transfer analysis of risk 3 years after transfer ends Article 56
Consent & Notification Records Separate, explicit consent log Transfer duration + 3 years Article 15, 18
Cross‑Border Transfer Contract Signed with overseas recipient 3 years after termination Article 38
Security Assessment Certificate (if applicable) Outcome of CAC security review Indefinitely (audit requirement) Article 40
Data Processing Activity Logs Log of every cross‑border operation 3 years (rolling) Article 51
Representative Appointment Filing Name & contact of local rep As long as presence is required Article 53

When is a Security Assessment required and what records are needed?

If your company is a critical information infrastructure operator (CIIO) or transfers the personal data of more than 1 million individuals (cumulatively) or sensitive data of 100,000+ individuals per year, you must undergo a CAC cross‑border data security assessment. The certificate issued by the CAC must be retained indefinitely. Additionally, you must keep all materials submitted during the assessment (e.g., data mapping, PIA updates, legal opinion). Non‑CIIO firms that process smaller volumes can use the Standard Contract, but still need the contract and PIA records.

A 2024 case shows a fintech firm failed to retain its security assessment application documents. When the regulator audited, the company could not prove compliance, resulting in a 60‑day suspension of all cross‑border transfers and a penalty of RMB 10 million.

What data processing logs must be kept for cross‑border activities?

Article 51 of the PIPL requires records of all data processing operations, including cross‑border transfers. The CAC expects logs to capture: (1) time and date of transfer, (2) volume and type of data, (3) source and destination IP addresses (if applicable), (4) identity of the operator, and (5) any access or modification events. These logs must be retained for at least 3 years and be available for inspection within 24 hours of a regulator request. Many companies underestimate the granularity required – generic server logs are insufficient. You need a dedicated data‑flow tracking system.

Do foreign companies without a China entity need to appoint a representative?

Yes. Article 53 of the PIPL requires foreign companies that process PI of individuals in China (e.g., via e‑commerce or employee data) to appoint a representative (代表人, dàibiǎo rén) within China. The appointed representative’s name, contact information, and authorization scope must be filed with the local CAC branch. This filing document becomes part of your mandatory records. Failure to appoint or maintain an updated filing can result in removal of the company from the “white list” of compliant foreign enterprises in the CAC’s public registry.

Pitfall: Assuming a China subsidiary automatically satisfies the representative requirement. Cost: RMB 200,000 fine + 30‑day suspension of transfer activities. Fix: Formally appoint a separate representative (not the subsidiary’s legal rep) and file the appointment with the CAC within 15 business days.
Pitfall: Not updating the PIA when the overseas recipient changes their data protection policy. Cost: Regulatory investigation leading to a RMB 500,000 fine. Fix: Conduct an annual review of the PIA and create a change‑log that records each recipient’s policy update.
Pitfall: Destroying consent logs after two years instead of three. Cost: RMB 150,000 fine under Article 66. Fix: Implement a document‑retention policy that auto‑archives consent records for at least 36 months after the last transfer.

What are the penalties for inadequate record‑keeping?

The PIPL imposes escalating penalties. For minor record‑keeping failures, the CAC can issue a warning and order rectification. For serious violations (e.g., no PIA, missing contracts), fines range from RMB 200,000 to RMB 50 million, or 5% of the preceding year’s revenue (Article 66). Additionally, the company may be publicly blacklisted, which can affect cross‑border e‑commerce, hiring, and banking operations. In extreme cases, the responsible executives can be banned from holding similar positions for up to 5 years.

Decision Framework for Record‑Keeping Approach

If your company transfers PI of fewer than 1 million individuals per year and is not a CIIO, choose the Standard Contract route – which requires: PIA, consent records, contract, and processing logs. If you transfer data of 1 million+ individuals or are a CIIO, choose the Security Assessment route – which demands all the above plus a CAC security assessment certificate and supporting documentation. If you have no China entity, add the Representative Appointment Filing to both routes.

NEXT STEPS

  1. Audit your current records – Download our PIPL Cross‑Border Compliance Checklist to identify gaps in your PIA, consent logs, and contracts.
  2. Update your contract language – Read our Guide to the CAC Standard Contract for Cross‑Border Data Transfer to ensure your template meets the 2024 amendments.
  3. Schedule a compliance audit – Contact our team at China Gateway 360 Data Compliance Audit for a comprehensive review of your record‑keeping practices.

— China Gateway 360 —
Remote China market entry support, built around execution.

Related articles

How to Obtain Chemical Import Permits in China: 2026 Guide for Foreign Companies

How to Obtain Chemical Import Permits in China: 2026 Guide for Foreign Companies Why Chemical Import Permits Matter for Foreign Companies Entering Chi

How to Register Chemicals Under China REACH: 2026 Guide for Foreign Manufacturers

How to Register Chemicals Under China REACH: 2026 Guide for Foreign Manufacturers Why China REACH Registration Matters for Foreign Chemical Manufactur

How to Choose Between OEM and ODM in China: 2026 Procurement Guide for Sourcing Teams

How to Choose Between OEM and ODM in China: 2026 Procurement Guide for Sourcing Teams Why the OEM vs ODM Decision Matters for Your China Sourcing Stra

How to Negotiate Contracts with Suppliers in China: 2026 Guide for Foreign Companies

How to Negotiate Contracts with Suppliers in China: 2026 Guide for Foreign Companies In 2026, foreign companies negotiating contracts with Chinese sup