ResourcesBlog
China adopts its own GDPR: What impact for your Whistleblowing Program?
October 28, 2021
1:40
 min read

China adopts its own GDPR: What impact for your Whistleblowing Program?

Article on the impact of China's GDPR-equivalent data protection law on whistleblowing programs.
Table of contents
Join Whispli's newsletter
By clicking "Join newsletter", you acknowledge Whispli's Privacy Policy.

Going into effect on November 1st, China introduces its new data privacy law: the Personal Information Protection Law (PIPL). Similar to the GDPR in Europe, the PIPL encompasses the protection of personal information inside and outside of China. In this context, handling sensitive conversations within your organisation will be heavily affected by the characteristics of this new legislation.

If your organisation is already compliant with the GDPR, most of your data privacy compliance systems will work in China. However, certain frequirements are unique to the PIPL:

 

Data localisation

The concept of data localisation refers to keeping the data of businesses within the borders of a country. The new Chinese laws make it nearly impossible to store and process data outside of China. Simply put, the data from your Chinese employees collected through your Whistleblowing Program must now be stored and processed on a server in China.

 

Local Case Managers

Since the personal information generated, collected and processed must stay within Chinese borders, your organisation will have to appoint a local representative to handle personal data collected in China. This Case Manager, or Critical Information Infrastructure Operator (CIIO), must be designated by the HQ/Parent company and will be in charge of collecting and processing the personal information of the employees based in China.

 

Standalone consent of data subjects

The law requires a controller to obtain standalone consent of data subjects when processing sensitive personal data and cross-border transfer of personal data. This can be done by adding a specific checkbox to gather consent during the Report completion for someone reporting a matter in China.

 

Data Protection Impact Assessment

Similarly to the GDPR, a DPIA is required by the PIPL under certain circumstances: cross-border transfer of personal data, contracting a third-party data processor, providing data to another controller and making personal data publicly available. Companies must designate a data controller, as the DPO in Europe, and conduct regular audits to verify the strength of the systems designed to ensure confidentiality.

 

To know how the PIPL will affect your business in detail, check out the first part of our series on the subject. 

If you have identified that your organisation and Whistleblowing Program might be affected by this new legislation or will be in the future, taking the step to quickly be compliant with the PIPL becomes a priority. Get in touch with our team to learn how we can help.  

Most popular articles to read

March 31, 2026
6:30
 min read
Why Your Conflict of Interest and Whistleblowing Systems Belong Together
Read more
Visual guide to navigating Chinese regulations for reputational risk and whistleblowing investigations.
February 5, 2026
4
 min read
Managing Reputational Risk and Investigations in China
Read more

Explore more resources

White paper: Secure and Anonymous Reporting in the Queensland Public Sector.
White papers
Enhancing Integrity Through Reporting Solutions in the Queensland Public Sector
Learn how reporting solutions can support Queensland’s public sector employees
White paper: Monitoring Compliance Program Metrics.
White papers
Whispli, Your Partner in Monitoring Compliance Program Metrics
Learn how to measure and improve your program’s effectiveness with key metrics
White paper: Strengthening Whistleblowing Programs for APRA CPS 230.
White papers
Strengthening Whistleblowing Programs under APRA CPS 230
Discover how to align your program with APRA CPS 230 and strengthen operational resilience
Discover our platform

Take case management to the next level

Move from fragmented reporting tools to a single, secure system of record designed for complex, global compliance environments.

Talk to our experts to see how Whispli supports whistleblowing, disclosures, and enterprise governance at scale.