China's privacy law tells you to audit yourself regularly.
It does not tell you how often, who runs it, or what the file has to contain.
That gap is where most foreign privacy teams lose the argument, because the regulator gets to arrive with its own view of what "regularly" meant.
What does Article 54 actually require, and why is a one-off audit not enough?
Here is the duty in full. It is one sentence.
"Personal information handlers shall regularly engage in audits of their personal information handling and compliance with laws and administrative regulations."
Three things are load-bearing in that sentence.
"Regularly." Not annually. Not biennially. The statute sets a recurring duty and fixes no calendar date and no interval anywhere in its 74 articles. A single audit completed once, however thorough, does not satisfy a duty written in the recurring tense. If you want a number, you will not find it in the law itself. Article 62 empowers the State cybersecurity and informatization department to formulate concrete rules and standards for personal information protection, so implementing measures below the statute are where any fixed cadence would live. Check those before you assume a frequency, and do not let a vendor tell you the statute says twelve months. It does not.
Two objects, not one. The audit covers your personal information handling and your compliance with laws and administrative regulations. The second limb is wider than PIPL. Sector rules and administrative regulations that touch your handling are in scope of the same audit.
"Personal information handler." Article 73 defines this as organizations and individuals that autonomously decide handling purposes, handling methods, and other handling matters. That is the party carrying the audit duty. Entrusted persons sit under Article 59, which requires them to adopt necessary measures and to assist handlers in fulfilling the obligations in the law. So your processors owe you assistance, and your audit has to test whether you actually got it.
One more detail worth knowing before you scope anything. The word "audit" appears in exactly two places in PIPL. Article 54, which you schedule. And Article 64, which the regulator orders. We will come back to the second one.
Does PIPL reach you if you have no entity in China?
Article 3 has two paragraphs and they do different work.
Paragraph 1 covers handling of personal information of natural persons within the borders of the People's Republic of China.
Paragraph 2 extends the law to handling activities outside the borders, of the personal information of natural persons inside the borders, where one of these is present:
- The purpose is to provide products or services to natural persons inside the borders.
- Analyzing or assessing activities of natural persons inside the borders.
- Other circumstances provided in laws or administrative regulations.
Read limb 2 slowly. It is not conditioned on selling anything. Analyzing or assessing the activities of people in China pulls you in on its own. A product analytics pipeline, a fraud model, a behavioural scoring engine that happens to include China-resident users, all sit inside that language.
There is no revenue threshold in Article 3. No employee count. No establishment test.
And PIPL extraterritorial scope carries a structural consequence that the GDPR analogue does not exactly mirror. Article 53 requires handlers outside the borders that are caught by Article 3, paragraph 2 to establish a dedicated entity or designate a representative within China, responsible for matters relating to their personal information handling activities, and to report that entity's or representative's name and contact method to the departments fulfilling personal information protection duties and responsibilities.
So the audit duty travels with you, and so does a named, filed point of contact the regulator can call.
Separately, Article 52 requires handlers processing personal information reaching a quantity set by the State cybersecurity and informatization department to appoint a personal information protection officer, disclose their contact methods, and report the name and contact methods to the departments. The threshold is set outside the statute, not inside it.
Which five handling activities force an impact assessment before you start?
Article 55 lists them, and the trigger is enumerated rather than risk-tested. Under the GDPR the equivalent assessment is generally gated on a prior finding of high risk. PIPL does not work that way. It names the activities.
A personal information protection impact assessment must be conducted in advance, and a record of the handling status made, for:
- Handling sensitive personal information.
- Using personal information to conduct automated decision-making.
- Entrusting personal information handling, providing personal information to other personal information handlers, or disclosing personal information.
- Providing personal information abroad.
- Other personal information handling activities with a major influence on individuals' rights and interests.
Now attach the definitions and the list gets much larger than it first reads.
Article 28 defines sensitive personal information as information that, once leaked or illegally used, may easily cause harm to the dignity of natural persons or grave harm to personal or property security, including biometric characteristics, religious beliefs, specially-designated status, medical health, financial accounts, individual location tracking, and the personal information of minors under 14. Financial accounts and location tracking are in that list. For most consumer businesses, trigger 1 is already live.
Article 73 defines automated decision-making as using computer programs to automatically analyze and assess personal behaviors, habits, interests and hobbies, or economic, health, credit and other conditions, and make decisions. That is a recommendation engine as much as a credit model.
Trigger 3 is the one that quietly generates the most assessments. Every entrustment, every provision to another handler, every disclosure. Each new processor onboarding is a PIPIA event, which is why the trigger register belongs in the same place you track third-party risk rather than in a separate legal folder.
Trigger 4 fires on every export, and it sits on top of Article 38, which requires one of four conditions for cross-border provision: a security assessment organized by the State cybersecurity and informatization department, certification by a specialized body, a standard contract with the foreign receiving side, or other conditions provided in law. Article 40 goes further for critical information infrastructure operators and handlers above a state-set volume, requiring domestic storage and a security assessment to send anything abroad.
What must a personal information protection impact assessment contain?
Article 56 gives three content heads and no template:
- Whether the purpose of the handling and the handling method are lawful, legitimate, and necessary.
- The influence on individuals' rights and interests, and security risks.
- Whether the protection measures adopted are legal, effective, and suited to the degree of risk.
Head 1 is a necessity test, and it is the one that fails under audit. Not because the answer is hard, but because nobody wrote it down at the time. "In advance" in Article 55 means the assessment predates the handling. A PIPIA reconstructed after go-live is evidence of a control gap, not evidence of a control.
Head 3 is a proportionality test against the measures you actually adopted. Article 51 is where those measures are enumerated: internal management structures and operational procedures, categorized management of personal information, technical measures such as encryption and de-identification, reasonable operational limits plus regular security education and training for employees, and personal information security incident response plans. Treat those six as the control spine your PIPIA head 3 is measured against.
What Article 56 does not say is as useful as what it does. There is no prescribed reviewer, no prescribed sign-off, no prescribed format, and no requirement to file the PIPIA with the regulator in the ordinary case. The discipline is yours to impose.
How long must you keep PIPIA reports and handling records, and what does that mean for your audit file?
The last line of Article 56 is short and it is the one clause in this whole area with a hard number.
"Personal information protection impact assessment reports and handling status records shall be preserved for at least three years."
Two artifacts, not one. The report, and the handling status record that Article 55 requires you to make alongside it. Teams routinely keep the first and never create the second.
"At least" sets a floor, not a ceiling.
This three-year retention floor collides with automation more often than people expect. Article 47 requires handlers to proactively delete personal information when the purpose is achieved or impossible to achieve, when the retention period expires, when the individual rescinds consent, or when handling breached law or agreement. That deletion duty runs on the personal information. The PIPIA report and the handling status record are compliance records governed by their own floor. If your deletion tooling is keyed on a data subject or a system rather than on a record class, it can sweep the file you are required to preserve.
The reason the file matters operationally: Article 63 lets the departments consult and reproduce contracts, records, account books, and other relevant materials related to your handling activities, and conduct on-site inspections. Your PIPIA archive is not an internal document in any meaningful sense. Keep it where your data registries already live, indexed to the processing activity it assessed, or you will be reassembling it under a clock.
When can the regulator order an audit you never scheduled?
This is the second appearance of the word "audit" in PIPL, and it belongs to someone else.
Article 64 gives the departments two triggers. Where, in the course of performing their duties, they discover that personal information handling activities present relatively large risks, or that a personal information security incident occurs, they may conduct a talk with the legal representative or primary person responsible of the handler, or require the handler to commission a specialized body to conduct an audit of its handling activities' compliance. The handler shall then adopt measures as required to correct the matter and eliminate the hidden danger.
Two things to sit with.
First, the trigger is not a finding of breach. "Relatively large risks" is a forward-looking judgment the department makes. You can be ordered into a third-party audit without having been found to have violated anything.
Second, this is a commissioned audit at your expense, by a specialized body, on the regulator's timetable, with your legal representative personally in the frame. Article 64 also requires the departments to transfer suspected criminal conduct to public security authorities.
An incident reaches them quickly. Article 57 requires handlers to immediately adopt remedial measures and notify both the departments and the individuals where a leak, distortion, or loss occurs or might have occurred. The notification must cover the categories of information, causes and possible harms, the remedial measures adopted and what individuals can do to mitigate harm, and the handler's contact methods. Where the handler's measures can effectively avoid harm, it may decide not to notify individuals, but the departments retain the right to require notification anyway.
Then Article 66 sets what non-compliance costs. The departments order corrections, give warnings, confiscate unlawful gains, and can order an offending application to suspend or terminate service. If the matter is not corrected, a fine of up to 1 million Yuan, with the directly responsible person in charge fined between 10,000 and 100,000 Yuan. Where circumstances are serious: up to 50 million Yuan or up to 5 percent of the previous year's revenue, suspension of business for rectification, referral for revocation of licences, individual fines of 100,000 to 1 million Yuan, and a possible bar on serving as a director, supervisor, senior manager, or personal information protection officer of related enterprises.
Read the first tier again. The 1 million Yuan fine attaches to failure to correct. Your Article 54 audit is the mechanism that finds the thing before the department does, and the record that proves you were correcting on your own initiative. That is the commercial argument for cadence, and it is why the audit belongs inside risk management rather than as a standalone legal exercise.
What does a defensible Article 54 audit file look like in practice?
The statute will not hand you a checklist. But every element below is anchored to a specific article, which means each one is a thing an inspector can ask for.
→ A written, recurring cadence you set yourself and can evidence, since Article 54 says "regularly" and fixes nothing. Document the reasoning for the interval you chose.
→ Scope covering both objects of Article 54: the handling itself, and compliance with the laws and administrative regulations that bear on it.
→ The six Article 51 measures tested as controls, including whether the security training actually ran.
→ A trigger register listing every Article 55 activity: sensitive personal information, automated decision-making, each entrustment or provision or disclosure, and every export.
→ The PIPIA report and the handling status record for each of those, held against the three-year floor in Article 56.
→ Entrustment agreements meeting Article 21 on purpose, time limit, method, categories, protection measures and both sides' duties, plus evidence you supervised the entrusted person rather than just contracted with them.
→ The Article 38 or Article 40 export mechanism identified per flow, not per company.
→ Article 52 personal information protection officer appointment, disclosure and filing where the volume threshold applies. For foreign handlers, the Article 53 dedicated entity or representative, with the name and contact method reported.
→ Article 13 legal basis and Article 17 notice, recorded per purpose.
→ The Article 50 mechanism for accepting and processing rights requests, and the log of any rejections.
→ Incident records against Article 57.
That list is reproducible. What is not reproducible by hand is keeping it current across every other regime that touches the same processing, which for most groups means GDPR, sector rules, and whatever lands next.
This is the problem the Aigis GRC engine was built for. One organizational profile maps deterministically against 245+ regulations across 28 jurisdictions, and every obligation traces to a verbatim quote from the legal text with article-level citation. Not a model's recollection of what PIPL says. The parsed statute. Answer once, assess everything, and the overlap between PIPL Article 55 and your existing assessment obligations resolves rather than duplicates.
A posture you can defend in front of a regulator, a board, or a plaintiff.
See your exposure mapped to the obligations that actually apply to you at agrc.ai.
FAQ: PIPL audit frequency, PIPIA triggers, and record retention
How often does PIPL require a compliance audit? Article 54 requires handlers to "regularly" audit their personal information handling and compliance with laws and administrative regulations. The statute fixes no interval and no calendar date. Article 62 empowers the State cybersecurity and informatization department to formulate concrete rules and standards, so any binding cadence would come from implementing measures below the statute rather than from PIPL itself. Set and document your own interval, and verify current departmental rules before relying on a specific number.
Does PIPL apply to a company with no entity or servers in China? It can. Article 3, paragraph 2 applies the law to handling outside China of the personal information of natural persons inside China where the purpose is to provide products or services to them, or where you are analyzing or assessing their activities, plus a catch-all for other circumstances provided in laws or administrative regulations. Article 53 then requires a caught foreign handler to establish a dedicated entity or designate a representative inside China and report its name and contact method to the authorities.
When is a personal information protection impact assessment mandatory? Article 55 requires one in advance, with a record of the handling status, for five activities: handling sensitive personal information, automated decision-making, entrusting or providing to another handler or disclosing personal information, providing personal information abroad, and other activities with a major influence on individuals' rights and interests. The trigger is the activity, not a prior high-risk finding.
How long must PIPIA reports be kept? Article 56 requires that personal information protection impact assessment reports and handling status records be preserved for at least three years. That is a floor, and it covers both artifacts.
Can a Chinese regulator order an audit outside your own schedule? Yes. Under Article 64, where the departments discover that handling activities present relatively large risks or that a personal information security incident has occurred, they may hold a talk with your legal representative or primary person responsible, or require you to commission a specialized body to audit your handling activities' compliance. You must then adopt measures to correct the matter and eliminate the hidden danger.


