Updated on 2026-07-27 GMT+08:00

Managing PIAs/DPIAs

What is PIA?

A Privacy Impact Assessment (PIA) is designed to ensure that the compliance and risk assessment of personal data processing comply with relevant laws and regulations.

Prerequisites

  • In a DI, the legal entity is configured as the Controller or Processor.
  • In the DI, the Data Subject Location is set to China.

Creating a PIA/DPIA

  1. Log in to the PCMC.
  2. In the navigation pane on the left, choose Risk Assessment > PIA/DPIA Management.
  3. Click Create in the upper left corner of the page. The Create PIA/DPIA page is displayed.
  4. Select a code from the S Code drop-down list box. Configure other parameters based on Table 1.

    Table 1 Basic information parameters

    Parameter

    Description

    Personal Data Inventory (DI)

    Select a DI to be bound.

    Assessment Report Name

    After a DI is selected, a report name will be automatically generated based on it. You are advised to use the S-code application name as the report prefix, for example, XXX Platform PIA Report.

    Country

    After a DI is selected, this parameter will be automatically set based on the country information in the DI.

    Does it involve cross-border (obtained from DI)

    If cross-border transfer is involved, you need to specify the exporting country/region and importing country/region.

    Exporter Country

    Select the exporting country/region of the PIA/DPIA. It determines the PIA or DPIA template to be used.

    Importer Country

    Select the importing country/region of the PIA/DPIA.

    Business Description & Data Flow Diagram (Optional)

    Provide a business data flow diagram to show the data collection, usage, storage, sharing, and deletion processes.

  5. Click Next Step. On the Determine PIA/DPIA parameters, configure parameters based on Table 2.

    Table 2 Determining the PIA/DPIA parameters

    Parameter

    Description

    Is it in a region using GDPR or with DPIA requirements?

    If the transferor is not in a region using GDPR, no DPIAs are required.

    If the transferor is in a region using GDPR, a DPIA is required.

    Data Processing Behavior

    The options vary depending on the value set for Is it in a region using GDPR or with DPIA requirements?

  6. Click Next Step. On the Assess Risk page, configure parameters based on Table 3.

    • If the transferor is a country that does not use GDPR, the questionnaire is as follows:
      Table 3 Risk assessment parameters

      No.

      Parameter

      Description

      1

      Is there a legal basis for collecting personal information?

      1. Obtained individual consent;
      2. Necessary for concluding or performing a contract where the individual is a party, or for implementing human resource management according to legally established labor regulations and collectively signed contracts;
      3. Necessary for performing legal duties or legal obligations;
      4. Necessary for responding to public health emergencies, or for protecting the life, health and property safety of natural persons in emergency situations;
      5. For the public interest, activities such as news reporting and public opinion supervision may process personal information within reasonable limits.
      6. Processing personal information that individuals have made public themselves or that has been lawfully made public within a reasonable scope in accordance with this Law;
      7. Other circumstances provided by laws and administrative regulations
      8. None of the above situations apply

      If 8 is selected, risks are identified.

      If 1 to 7 are selected, no risks are identified.

      (Optional) Click Add Evidence. The uploaded file cannot exceed 20 MB.

      2

      Does the collection of personal information comply with the principle of minimum necessity? Including but not limited to the types, quantity, storage period, collection frequency of personal information processed, etc.

      • If Yes is selected, no risks are identified.
      • If No is selected, risks are identified.

      3

      Has separate consent/authorization been obtained from users for the collection of sensitive personal information?

      Sensitive personal data refers to information that, if leaked, may lead to infringement on human dignity or pose a significant risk to personal and property safety. Examples include race or ethnicity, precise location data, and financial account information.

      4

      Does the collection of sensitive personal information comply with the principle of minimum necessity? Including but not limited to the types, quantity, storage period, collection frequency of sensitive personal information processed, etc.

      Sensitive personal data refers to information that, if leaked, may lead to infringement on human dignity or pose a significant risk to personal and property safety. Examples include race or ethnicity, precise location data, and financial account information.

      5

      Has guardian consent been obtained for processing minors' information?

      • If Yes or Not Involved is selected, no risks are identified.
      • If No is selected, risks are identified.

      6

      Does the content of the informed consent clearly and detailedly explain the purpose, impact, etc. of personal information processing?

      Check whether the privacy statement clearly describes personal information processing.

      7

      Is the form of informed consent convenient for review and save? Such as through pop-up windows and email sending.

      Select Yes or No based on actual conditions.

      8

      When the purpose and method of personal information processing, the types of personal information processed, the storage period, or the relevant information of the personal information processor (such as name, contact information, etc.) changes, is user consent obtained again?

      Select Yes or No based on actual conditions.

      9

      Should there be restrictions on the user profiling mechanism to avoid precise targeting of specific individuals?

      User profiling involves the automated processing of personal data to evaluate and predict personal preferences, behaviors, interests, and habits. For example, it can analyze the types of videos that a user likes.

      10

      When providing processed personal information to other personal information processors, has separate consent from the data subject been obtained?

      Select Yes or No based on actual conditions.

      11

      When processing special categories of personal data, are appropriate protective measures taken to protect the rights and interests of data subjects?

      For example, technical measures such as anonymization and encryption are taken during data processing based on the types and sensitivity of personal data to reduce the risk of personal data leakage or unauthorized access.

      12

      Is there a mechanism to track the quantity, frequency, user scale, user peak, etc. of business processing or potential processing of personal information?

      For example, perform regular tracking, or tracking and processing based on specific logic.

      13

      Have binding contracts or other documents been signed with third parties, which stipulate the processing purpose, method, data retention period, and processing method after expiration for personal information transferred to third parties?

      Example: data transmission agreement and data sharing constraint contract

      14

      Is personal information shared or transferred to third parties without data subject consent?

      Check whether a user's consent to third-party sharing has been explicitly obtained during consent notification.

      15

      Is sensitive personal information shared or transferred to third parties without separate individual consent?

      Check whether a user's consent to third-party sharing has been explicitly obtained during consent notification.

      16

      When providing personal information overseas, has separate consent from the individual been obtained?

      Check whether a user's separate consent to cross-border data transfer has been explicitly obtained during consent notification.

      17

      Before cross-border data transfer, have the cross-border compliance path (TIA/CAC's cross-border data risk assessment/cross-border contract signing and filing etc.) been completed?

      Provide information based on actual conditions.

      18

      Before cross-border data transfer, have technical safeguard measures (encryption, backup, log retention, permission management, etc.) been completed?

      Provide information based on actual conditions.

      19

      Before cross-border data transfer, have legal texts and agreements (cross-border standard contracts, clauses on cross-border data in DPA, DTA, etc.) been signed?

      Provide information based on actual conditions.

      20

      Have confidentiality agreements been signed with relevant personnel engaged in personal information processing positions, and have background checks been conducted on personnel who have extensive access to sensitive personal information?

      Provide information based on actual conditions.

      21

      Are effective complaint and rights protection channels provided?

      Example: feedback and dispute resolution channels, such as email and customer support

      22

      Is there a mechanism for users to control, opt-out or close for personalized display?

      Example: a button to hide content

      23

      Is targeted push management functionality provided, and can tags be managed?

      Provide information based on actual conditions.

      24

      Is there any restriction on data subjects' exercise of their rights without justification?

      For example, a user's rights are denied without any reason.

      25

      Are there convenient methods provided for querying, transferring, copying, correcting, supplementing, deleting, withdrawing consent, and deactivating accounts?

      For example, is there a channel for users to exercise their rights?

      26

      If a user refuses the collection of certain personal information by the service, does it affect the continued use of the service?

      Answer it based on the actual conditions. For example, can the software still be used after the user rejects its requests?

    • If the transferor country is a country that uses the GDPR, the questionnaire is as follows:

  7. Click Next. On the Generate Report page, check the report content.

    • Click Export PDF in the lower right corner to download the report.
    • Click Submit. In the displayed Initiate Approval dialog box, select high-risk service labels as needed, and click Confirm.

Approval Process

  • The PIA approval processes are as follows. You can check them in Personal Center.
    Figure 1 Intra-border approval process
    Figure 2 Cross-border approval process
  • The DPIA approval process is as follows. You can check it in Personal Center.