Framework overlap

Does China Personal Information Protection Law (PIPL) cover GDPR?

You hold China Personal Information Protection Law (PIPL) and have been told to do GDPR. Here is how much overlaps, control by control.

56% of GDPR you already have

China Personal Information Protection Law (PIPL) already covers about 56% of GDPR, leaving 12 of 27 controls as genuinely new work.

Already covered 15 Likely covered 0 New work 12

What is genuinely new work

Nothing in China Personal Information Protection Law (PIPL) reaches these. This is the list to scope.

GDPR-Art.10
Processing of personal data relating to criminal convictions
GDPR-Art.11
Processing which does not require identification
GDPR-Art.24
Responsibility of the controller
GDPR-Art.25
Data protection by design and by default
GDPR-Art.29
Processing under the authority of the controller or processor
GDPR-Art.30
Records of processing activities
GDPR-Art.32
Security of processing
GDPR-Art.36
Prior consultation
GDPR-Art.38
Position of the data protection officer
GDPR-Art.45
Transfers on the basis of an adequacy decision
GDPR-Art.47
Binding corporate rules
GDPR-Art.49
Derogations for specific situations
Show the 15 you already have
GDPR-Art.26
Joint controllers
GDPR-Art.27
Representatives of controllers or processors not established in the Union
GDPR-Art.28
Processor
GDPR-Art.33
Notification of a personal data breach to the supervisory authority
GDPR-Art.34
Communication of a personal data breach to the data subject
GDPR-Art.35
Data protection impact assessment
GDPR-Art.37
Designation of the data protection officer
GDPR-Art.39
Tasks of the data protection officer
GDPR-Art.44
General principle for transfers
GDPR-Art.46
Transfers subject to appropriate safeguards
GDPR-Art.5
Principles relating to processing of personal data
GDPR-Art.6
Lawfulness of processing
GDPR-Art.7
Conditions for consent
GDPR-Art.8
Conditions applicable to child's consent
GDPR-Art.9
Processing of special categories of personal data

How this is calculated

Already covered means a mapping runs from a control in China Personal Information Protection Law (PIPL) to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition