China’s Personal Information Protection Law (PIPL), effective since November 1, 2021, is the country’s comprehensive data-privacy statute — often described as China’s counterpart to the EU’s GDPR, though its cross-border transfer regime works differently and, for most institutions, more restrictively. Any international research collaboration that collects, stores, analyzes, or receives personal information from individuals in mainland China — participant data in a multi-site clinical trial, survey responses, biospecimen-linked identifiers, even researcher contact details shared for a joint project — is potentially within PIPL’s scope, regardless of where the receiving institution is located. This guide covers what PIPL requires before personal information can leave China, the three legal transfer mechanisms available, the in-country representative obligation for offshore data handlers, and what it means in practice for research administrators managing China-linked data flows.
What PIPL covers, and why it applies beyond China’s borders
PIPL applies to processing of personal information of individuals located in China, and it has extraterritorial reach: under Article 3, it applies to processing outside China if the purpose is to provide products or services to people in China, to analyze or assess the behavior of people in China, or in other circumstances provided by law. A university, funder, or CRO based outside China that receives personal information originating from a China-based research site or partner is processing personal information within PIPL’s reach, even if no part of the institution is physically located in China.
Sensitive personal information — a category that includes biometric data, health and medical information, financial accounts, and information about minors under 14 — receives heightened protection throughout the law: processing it requires a specific purpose and necessity justification, separate consent, and (per the thresholds below) is more likely to trigger the strictest transfer mechanism. Most human-subjects research data — clinical, genomic, or biomedical records tied to identifiable individuals — falls into this sensitive category by default.
The three legal mechanisms for cross-border transfer
Article 38 of PIPL requires that a personal information handler transferring data outside China satisfy one of three mechanisms before the transfer occurs (unless a transfer falls under a specific exemption — see below):
- CAC security assessment. A government security assessment conducted by the Cyberspace Administration of China (CAC), required for the largest-volume or most sensitive transfers, and for critical information infrastructure operators (CIIOs) transferring any personal information overseas, or for transfers involving “important data.” This is the most burdensome route, involving a self-assessment report, application to the CAC, and government review.
- Standard Contractual Clauses (SCC) filing. The handler and the overseas recipient sign China’s official SCC template (issued by the CAC, distinct from the EU’s SCCs) and file it with the provincial-level CAC, together with a personal information protection impact assessment (PIPIA — see below).
- Personal Information Protection Certification. The handler obtains certification from a CAC-recognized third-party professional institution, attesting that its cross-border processing meets PIPL’s protection standards. This route was expanded by the CAC and State Administration for Market Regulation’s (SAMR) Measures for Certification of Cross-Border Personal Information Transfer, issued October 14, 2025 and taking effect January 1, 2026, which opened a structured certification path to mid-scale data exporters that fall below the mandatory security-assessment thresholds.
Which mechanism applies — or whether a transfer is exempt from all three — depends on data volume and sensitivity thresholds set out in the CAC’s March 2024 Provisions on Promoting and Regulating Cross-Border Data Flows, which eased what had been a considerably stricter 2022 baseline:
- Exempt: transfer of non-sensitive personal information involving fewer than 100,000 individuals (cumulative from January 1 of the current year) does not require any of the three mechanisms.
- SCC filing or certification: required for transfers of personal information involving 100,000 to 1,000,000 individuals, or sensitive personal information involving fewer than 10,000 individuals, cumulative from January 1 of the current year.
- Security assessment: required for transfers involving “important data,” or personal information exceeding 1,000,000 individuals, or sensitive personal information exceeding 10,000 individuals, cumulative from January 1 of the current year.
Because thresholds are cumulative and count from the start of the calendar year, an institution running an ongoing multi-year study with a China-based site needs to track cumulative transferred-subject counts, not just per-transfer volumes — a study that starts small can cross into a stricter mechanism mid-year. A small pilot study with a few dozen participants will typically fall under the exemption; a national multi-site clinical trial with thousands of Chinese participants, transferring identifiable health data, will likely require SCC filing at minimum and may require full security assessment depending on final subject counts.
“Important data” is a separate, broader category from personal information and is defined by sector-specific catalogues rather than a single bright-line rule; certain categories of scientific and biomedical research data (particularly human genetic resources data, which China separately regulates through the Human Genetic Resources Administration of China under the Ministry of Science and Technology) can be treated as important data or fall under parallel regulatory regimes independent of PIPL’s thresholds. Research teams working with China-sourced genomic or biospecimen data should not assume PIPL’s personal-information thresholds are the only relevant compliance layer.
Separate consent for cross-border transfer
PIPL requires “separate consent” (单独同意) for cross-border transfer of personal information — a specific, standalone consent for the transfer itself, distinct from a general consent to processing given at enrollment. A blanket consent form covering data collection, use, and international sharing in one undifferentiated clause is unlikely to satisfy this requirement; the individual must be informed specifically that their data will leave China, told the identity and contact details of the overseas recipient, the purpose and method of the overseas processing, and the categories of data involved, and must consent to that transfer as a discrete decision. For research relying on consent as the legal basis for cross-border transfer (rather than, for example, contractual necessity), informed-consent documentation and processes designed primarily around GDPR or U.S. Common Rule requirements will generally need a distinct PIPL-compliant transfer-consent clause, not a translated version of the same form.
Personal Information Protection Impact Assessment (PIPIA)
Before any cross-border transfer, PIPL requires the handler to conduct a Personal Information Protection Impact Assessment (PIPIA) — a documented risk assessment covering the legality, legitimacy, and necessity of the transfer’s purpose, scope, and method; the volume, scope, category, and sensitivity of the data involved; the risks the transfer poses to individuals’ rights and interests; and whether the protections the overseas recipient commits to (contractually or otherwise) are sufficient to safeguard the data once it leaves China, including the data-protection standards of the recipient’s jurisdiction. The PIPIA record must be retained for at least three years and is a required attachment to an SCC filing. In practice, a PIPIA for a research collaboration should assess the receiving institution’s data security controls, applicable data-protection law in the receiving country, sub-processing or further-transfer arrangements, and breach-notification and data-subject-rights procedures on the receiving side — the same substantive questions a GDPR transfer-risk assessment or U.S. institutional data-security review would ask, documented in the PIPIA format PIPL requires.
The in-China representative requirement for offshore handlers
Article 53 requires personal information handlers located outside China, but who fall within PIPL’s extraterritorial scope under Article 3, to establish a dedicated entity or appoint a representative within China responsible for matters related to the personal information they process, and to report that entity’s or representative’s name and contact details to the relevant Chinese regulator. This is separate from the personal information protection officer (PIPO) requirement under Article 52, which applies to handlers (onshore or offshore) processing personal information above a volume threshold set by the CAC, regardless of where the handler is located.
For a research institution outside China receiving personal information from a China-based partner site, this means the receiving institution itself may need a formally designated in-China representative or entity — not just a data-sharing agreement with the China-based site — if its own processing activities fall within Article 3’s extraterritorial triggers (for example, if it is directly analyzing or assessing the behavior of individuals located in China as part of the research). This is a distinct compliance obligation from anything GDPR or HIPAA require, and it is frequently missed by institutions applying a Western-style “we have a data transfer agreement” compliance model to a China-linked study.
Why this matters for international research collaborations
PIPL compliance failures carry real regulatory exposure: fines of up to RMB 50 million or 5% of the prior year’s annual revenue for serious violations, along with business suspension and personal liability for responsible individuals. Beyond the regulatory risk, unresolved PIPL compliance is an increasingly common practical blocker for China-linked research:
- Study start-up delays. SCC filing and security-assessment review both add lead time to study initiation that is easy to underestimate if PIPL compliance is scoped as a late-stage legal review rather than built into the collaboration design from the outset.
- Consent form redesign. Existing GDPR- or Common Rule-oriented consent templates typically need a PIPL-specific separate-consent clause added, not just a Mandarin translation of the existing form.
- Data localization pressure. Institutions sometimes respond to PIPL’s compliance burden by keeping identifiable China-sourced data on China-based infrastructure and transferring only de-identified or aggregated data internationally — which has downstream implications for data linkage, re-identification risk assessment, and what counts as “personal information” at all under PIPL’s own (broad) definition.
- Interaction with export control and other China-specific compliance layers. PIPL is a data-privacy law and operates independently of, but alongside, U.S. export control rules and China’s own research-security and human genetic resources regulations — a compliant PIPL transfer mechanism does not by itself clear a transfer under export control law, and vice versa.
Research administrators managing China-linked studies should treat PIPL cross-border transfer compliance as a distinct workstream from general international data-sharing agreements, engage PRC-qualified legal counsel to confirm which of the three transfer mechanisms applies given actual (and projected cumulative) data volumes, and build PIPIA documentation and separate-consent language into study design before data collection begins rather than as a retrofit.
Frequently asked questions
Does PIPL apply if my institution has no office or staff in China?
Potentially yes. PIPL’s extraterritorial scope under Article 3 turns on what the processing does — providing products or services to people in China, or analyzing/assessing the behavior of people in China — not on whether the processing entity has a physical presence there. A university receiving and analyzing survey or clinical data from China-based research participants can fall within scope with no China office at all.
Is PIPL the same as China’s rules on human genetic resources?
No. PIPL is a general personal-information-protection law. Human genetic resources (biospecimens, genomic and related data) are separately regulated in China, primarily through the Human Genetic Resources Administration of China (HGRAC) framework under the Ministry of Science and Technology, which has its own approval and export procedures. A research collaboration involving genetic data commonly needs to satisfy both regimes.
Can we just use the EU’s Standard Contractual Clauses instead of China’s?
No. China’s SCCs, issued by the CAC, are a distinct legal instrument from the EU’s SCCs under GDPR, with their own mandated template and filing process with the provincial CAC. A transfer governed by GDPR-style SCCs alone does not satisfy PIPL’s Article 38 requirement for a China-outbound transfer.
What counts toward the volume thresholds — every data subject ever, or per transfer?
The thresholds set out in the CAC’s March 2024 Provisions are cumulative, counted from January 1 of the current calendar year, not per individual transfer. An ongoing study should track cumulative subject counts across the year to determine which transfer mechanism currently applies, since crossing a threshold outside an initial assessment can change the required mechanism mid-study.
This guide summarizes PIPL’s cross-border transfer framework as a starting reference for research administrators; it is not legal advice. PIPL implementation rules, thresholds, and certification procedures have changed materially since 2021 and continue to evolve (most recently with certification measures taking effect January 1, 2026) — institutions should confirm current requirements with PRC-qualified counsel before relying on any specific mechanism or threshold for an active study.
Related CASRAI resources
- GDPR and Data Protection Compliance in Research Involving Personal Data
- GDPR Article 44 (International Data Transfers)
- Data Transfer Agreement (DTA)
- US-China Research Collaboration: Research Security and Compliance Concerns
- The Four Pillars of Export Control Compliance
- NSFC (National Natural Science Foundation of China): A Funding Overview for International Researchers







