For advice on how Safecall can help you run a whistleblowing programme that is compliant with China’s PIPL, call us on +44 (0) 191516 7720 or send us an email to [email protected].
Retour à la page d'aperçu de la législation
China’s Personal Information Protection Law (PIPL), which came into force on 1 November 2021, is the country’s primary data protection statute.
Broadly comparable in intent to the EU’s General Data Protection Regulation (GDPR), the PIPL governs how personal information relating to individuals in China is collected, processed, stored, and transferred – including across national borders. For organisations that operate a whistleblowing programme with employees in China, the PIPL creates a specific and material compliance challenge that must be addressed carefully. Every report submitted through a whistleblowing channel is likely to contain personal information within the meaning of the law. How that information is handled, and whether it can lawfully be transferred outside China for investigation, is now a regulated question with real enforcement consequences.
Why the PIPL Matters for Whistleblowing
A whistleblowing report submitted by an employee in China will almost always contain personal information. That information may include the name and contact details of the reporter, identifying details about the person accused of wrongdoing, and references to third parties such as witnesses or colleagues. In many cases, it will also include sensitive personal information – a category that attracts stricter obligations under the PIPL and includes financial account details, health and medical information, and data that could be used to identify an individual’s precise location.
For a multinational organisation running a centralised whistleblowing programme – where reports submitted anywhere in the world are processed and investigated by a team or service provider based outside China – this creates an immediate question under the PIPL: does transferring that report data outside China constitute a cross-border personal information transfer? In almost all cases, the answer is yes.
The PIPL Framework: Key Concepts
Before addressing the specific challenges the PIPL creates for whistleblowing programmes, it is helpful to understand its key features.
Personal information under the PIPL is broadly defined as any information recorded in electronic or other form that relates to an identified or identifiable natural person. This closely mirrors the GDPR definition, and in the context of a whistleblowing programme, will typically encompass everything contained in or related to a report. Anonymised information – data that has been irreversibly stripped of any identifier – falls outside the scope of the PIPL. Pseudonymised data, however, remains in scope because re-identification is still possible.
Sensitive personal information – which includes financial account data, biometric identifiers, health and medical information, religious beliefs, and precise location data – is subject to stricter requirements, including a specific necessity test and, in most cases, separate and explicit consent from the individual concerned.
The PIPL applies not only to organisations based in China but also, extraterritorially, to overseas organisations that process the personal information of individuals in China for the purpose of providing products or services, or for analysing or evaluating their behaviour. This means that even a whistleblowing service provider based entirely in the UK that receives and processes reports from employees in China is subject to the PIPL.
Cross-Border Data Transfer: The Core Challenge
The most significant practical challenge the PIPL creates for whistleblowing programmes is its regime for cross-border data transfers. Personal information collected in China may only be transferred outside China through one of three approved mechanisms.
1. CAC Security Assessment
A Security Assessment conducted by the Cyberspace Administration of China (CAC) is mandatory for transfers of “important data” and for transfers of personal information above specified volume thresholds – currently, transfers of personal information relating to more than one million individuals, or cumulative transfers of sensitive personal information relating to more than 100,000 individuals. The Security Assessment must be renewed every three years and, as of March 2025, the CAC has completed reviews of 298 Security Assessment submissions, of which 44 involved important data.
2. Standard Contractual Clauses
Standard Contractual Clauses (SCCs) as formulated by the CAC are available for transfers that fall below the Security Assessment thresholds. Unlike the EU model, Chinese SCCs must be filed with the relevant local CAC authority after signing and before the transfer takes place. For multinational corporations with multiple subsidiaries in China that share similar business activities, one subsidiary may submit the SCC filing on behalf of all related entities.
3. Third-Party Certification
The Measures for the Certification of Cross-Border Transfer of Personal Information, which came into force on 1 January 2026, introduced a structured third-party certification route for the first time. A CAC-accredited certification body reviews the exporter’s data protection practices, Personal Information Protection Impact Assessment (PIPIA), and operational controls, and issues a certificate serving as the lawful basis for the transfer. This route is particularly well-suited to multinationals with ongoing, high-volume, or complex cross-border data flows, and functions in a manner similar to Binding Corporate Rules under the GDPR.
Regardless of which transfer mechanism is used, organisations must always obtain separate consent from individual data subjects for cross-border transfers, unless another lawful basis applies.
The Consent Requirement
The PIPL is heavily consent-based. Before processing personal information – including the personal information contained in a whistleblowing report – organisations must provide individuals with a clear privacy notice disclosing who is collecting the data, why it is being collected, how it will be used, who it will be shared with, and the rights available to the individual.
For a whistleblowing programme, this creates a practical design challenge. Anonymous reporting – where the reporter does not identify themselves – is the gold standard for encouraging disclosures. However, where a report is submitted anonymously, obtaining individual consent for the processing of personal information contained within the report (particularly about the person accused of wrongdoing) may not be straightforward. Organisations should take legal advice on how to structure their privacy notices and consent frameworks for their specific whistleblowing programme design.
The Local Representative Requirement
Overseas organisations that process the personal information of individuals in China – including, therefore, overseas whistleblowing service providers – must appoint a China-based representative or establish a dedicated local entity to handle data protection compliance and to act as a point of contact for the relevant enforcement authorities. This requirement is set out in Article 53 of the PIPL. The name and contact details of that representative must be disclosed to the CAC.
This requirement has direct implications for how a UK-based whistleblowing service provider like Safecall must operate in relation to disclosures made by employees in China. It means that a compliant programme cannot simply direct Chinese employees to a standard global reporting channel without appropriate local compliance infrastructure in place.
Data Minimisation: The Practical Principle
The consistent guidance from specialists in this area is unambiguous: minimising cross-border data transfer is the most effective way to manage PIPL compliance risk in the context of a whistleblowing programme. In practice, this means:
- carrying out initial screening and triage of reports within China, before any information is transferred internationally
- anonymising or pseudonymising report content to the greatest extent possible before cross-border transfer
- limiting the categories of personal information included in cross-border transfers to those strictly necessary for the purpose of the investigation
- maintaining detailed logs of every cross-border transfer, kept for a minimum of six months, and being prepared for regulatory inspection of those records
Personal Information Protection Impact Assessments
Before transferring personal information outside China – and before processing sensitive personal information – organisations are required under the PIPL to conduct a Personal Information Protection Impact Assessment (PIPIA). The PIPIA must assess whether the processing purpose and method are lawful, legitimate, and necessary; the risks to the rights and interests of individuals; and whether the protective measures in place are appropriate and effective.
For an organisation operating a whistleblowing programme in China, a PIPIA specifically addressing the whistleblowing data flows – from initial report submission through to investigation and case closure – is a prudent and, in many cases, legally required step. This assessment should be completed before the programme goes live and reviewed whenever there are material changes to how the programme operates.
Enforcement: The Stakes Are Real
PIPL enforcement has moved from sporadic to systematic. Penalties for serious violations can reach CNY 50 million or 5% of the previous year’s global revenues – whichever is higher – and individuals directly responsible for violations may face personal fines of up to CNY 1 million and prohibition from serving in senior management roles. Amendments to China’s Cybersecurity Law that came into force in 2026 further increased administrative penalties for non-compliant cross-border transfers and strengthened the supervisory role of sectoral regulators.
In 2024, regulators investigated and resolved over 7,000 cases involving personal information infringement under the “Clean Network” operation. The 2025 Special Campaign Series for Personal Information Protection, jointly launched by the Cyberspace Administration of China (CAC), the Ministry of Industry and Information Technology (MIIT), the Ministry of Public Security (MPS), and SAMR, further demonstrated the authorities’ commitment to sustained, co-ordinated enforcement. Organisations that have treated PIPL compliance as a paper exercise are increasingly exposed.
Conclusion
The PIPL does not prevent organisations from operating a whistleblowing programme in China – but it does require that programme to be designed and managed with China’s data protection obligations clearly in mind. For multinationals that have deployed a global whistleblowing solution without considering PIPL compliance, the risk of operating a non-compliant cross-border data transfer is real and growing. The right approach is to build a China-specific compliance layer into your whistleblowing programme: one that minimises unnecessary data transfer, addresses the consent and notice requirements, conducts the required PIPIA, and uses the appropriate transfer mechanism for any information that does need to move across borders.
Our Recommendation
The compliance requirements the PIPL places on a whistleblowing programme are not insurmountable – but they do require expert handling. Organisations should not assume that a globally deployed whistleblowing solution automatically meets Chinese data protection requirements, and should not wait for an enforcement action to find out that it does not. The right time to address this is during programme design or review, not after a disclosure has already been transferred outside China without the appropriate legal basis. Safecall works with organisations operating in complex, multi-jurisdictional environments and can support you in thinking through a PIPL-compliant programme design – working alongside your legal advisers to ensure the approach you take is both operationally effective and legally sound.
Comment Safecall peut vous aider
Safecall provides anonymous reporting channels – including dedicated telephone hotlines and secure online portals – that operate 24 hours a day, 7 days a week, 365 days a year, in over 175 languages and dialects including Mandarin and Cantonese, and across more than 150 countries. Our call handlers have 25 or more years of interview experience each.
All data is held securely in the UK and our systems are fully GDPR compliant. For organisations with operations in China, we can work with you and your legal advisers to ensure your reporting channel is configured in a way that is sensitive to the PIPL’s requirements – including data minimisation, appropriate handling of sensitive personal information, and the structure of any cross-border data transfers. We help organisations build not just the infrastructure for reporting, but the confidence and culture that encourages employees to use it.
Références
[2] Data Security Law of the People’s Republic of China (DSL), effective 1 September 2021
[3] Cybersecurity Law of the People’s Republic of China (CSL), as substantially amended with effect from 1 January 2026
[4] Network Data Security Management Regulations, State Council, effective 1 January 2025
[6] Arnold & Porter, China Clarifies Cross-Border Data Transfer Rules (June 2025)
[7] Global Law Experts, Cross-Border Data Transfer China (May 2026)
[8] Whispli, China PIPL Compliance: How Whispli Ensures Data Protection
[9] Chambers and Partners, Data Protection & Privacy 2026 – China (March 2026)
[11] China Briefing, China Releases Cross-Border Data Transfer Certification Measures (October 2025)
[12] Recording Law, China Data Privacy Laws: PIPL, CSL & DSL Compliance Guide (2026)
The summaries provided on this website are designed for information and initial guidance only. Always seek additional specific advice from an appropriate legal specialist before making decisions based on whistleblowing legislation or data protection law. Safecall can provide recommendations for appropriate legal specialists if required. Please ask for more details.