PIPL Compliance
中国个人信息保护法合规声明
Our commitment to China's Personal Information Protection Law
Effective Date: January 1, 2026 | Last Updated: January 1, 2026
重要声明 | Important Notice
This policy applies to individuals in the People's Republic of China. If you are located in China, this policy governs how we handle your personal information in accordance with PIPL.
Table of Contents | 目录
1. Introduction to PIPL Compliance
This page explains how Reputation.report complies with China's Personal Information Protection Law (PIPL), which became effective on November 1, 2021.
The PIPL is China's comprehensive data protection law, similar to the European Union's GDPR. It establishes rules for the collection, storage, use, processing, transmission, provision, and disclosure of personal information.
Scope of Application: The PIPL applies to: - Organizations processing personal information of individuals in China - Organizations outside China that process personal information for providing products/services to individuals in China - Organizations outside China that analyze or assess behavior of individuals in China
Reputation.report is committed to full compliance with PIPL requirements when processing personal information of individuals in the People's Republic of China.
Last Updated: January 1, 2026
2. Key Definitions Under PIPL
Personal Information (个人信息): Any information related to an identified or identifiable natural person, recorded electronically or by other means, excluding information that has been anonymized.
Sensitive Personal Information (敏感个人信息): Personal information that, if leaked or illegally used, may easily lead to infringement of human dignity or harm to personal or property safety, including: - Biometric data - Religious beliefs - Specific identity - Medical and health information - Financial account information - Location tracking data - Personal information of minors under 14
Personal Information Processing (个人信息处理): Collection, storage, use, processing, transmission, provision, disclosure, and deletion of personal information.
Personal Information Processor (个人信息处理者): An organization or individual that independently determines the purpose, method, and other matters of personal information processing.
Entrusted Party (受托方): An organization or individual that processes personal information on behalf of a personal information processor.
3. Legal Bases for Processing
Under PIPL Article 13, we process personal information only when we have a valid legal basis:
1. Consent (同意): We obtain your separate consent before processing your personal information. For sensitive personal information, we obtain your explicit consent and inform you of the necessity and impact.
2. Contract Performance (合同履行): Processing is necessary to conclude or perform a contract to which you are a party, such as providing our reputation management services.
3. Legal Obligations (法定职责): Processing is necessary to fulfill our statutory duties or obligations under applicable laws and regulations.
4. Public Interest (公共利益): Processing is necessary for public health emergencies or to protect the life, health, or property of individuals in emergency situations.
5. Public Disclosure (公开披露): Processing personal information that you have made public yourself or that has been lawfully disclosed.
Consent Requirements: - Consent must be given voluntarily and explicitly - Separate consent required for sensitive personal information - Separate consent required for cross-border transfers - You may withdraw consent at any time - Withdrawal does not affect the lawfulness of prior processing
4. Personal Information We Collect
Basic Personal Information: - Name (姓名) - Contact information (联系方式): phone number, email address - Identity document numbers (when required for verification) - Employment information (职业信息): company, job title
Online Activity Information: - IP address (IP地址) - Device identifiers (设备标识符) - Browsing history on our website (浏览记录) - Service usage records (服务使用记录)
Reputation-Related Information: - URLs of content concerning you - Background information about your case - Documentation supporting removal requests
Financial Information (if applicable): - Payment card details (processed by secure payment processors) - Billing address - Transaction history
Sensitive Personal Information We May Process: - Identity verification documents - Detailed personal history (when necessary for reputation management)
We minimize the collection of sensitive personal information and only process it when strictly necessary and with your explicit consent.
5. Purpose of Processing
We process your personal information for the following purposes:
Service Delivery (服务提供): - Fulfilling reputation management services - Communicating about your case - Providing customer support
Legal Compliance (法律合规): - Complying with applicable laws and regulations - Responding to lawful requests from authorities - Exercising or defending legal claims
Security (安全保障): - Protecting against fraud and unauthorized access - Maintaining the security of our systems - Investigating potential violations
Business Operations (业务运营): - Processing payments - Analyzing and improving our services - Maintaining business records
Communication (with consent): - Sending promotional materials - Providing newsletters and updates
Limitation Principle: We only process personal information for the stated purposes. If we need to use your information for other purposes, we will obtain your separate consent.
6. Cross-Border Data Transfers
Overview: As an international company, we may transfer personal information outside of China. PIPL imposes strict requirements on cross-border transfers.
Legal Mechanisms: We rely on the following mechanisms for cross-border transfers:
1. Security Assessment (安全评估): For large-scale data transfers, we undergo security assessments conducted by the Cyberspace Administration of China (CAC) as required.
2. Standard Contracts (标准合同): We use CAC-approved standard contracts with overseas recipients, ensuring they provide equivalent protection to PIPL.
3. Certification (认证): Where applicable, we work with certified organizations that have passed personal information protection certification.
Transfer Requirements: Before transferring personal information outside China, we: - Inform you of the recipient's name, contact information, and purpose - Obtain your separate consent - Ensure the overseas recipient can provide equivalent protection - Take necessary measures to ensure compliance
Data Localization: Critical information infrastructure operators and processors handling large volumes of personal information store such data within China as required by law.
7. Your Rights Under PIPL
PIPL grants you comprehensive rights over your personal information:
Right to Know and Decide (知情权和决定权): - Be informed about our processing activities - Decide whether to consent to processing - Withdraw consent at any time
Right to Access (查阅权): - Request access to your personal information - Obtain copies of your data
Right to Rectification (更正权): - Request correction of inaccurate information - Request completion of incomplete information
Right to Erasure (删除权): - Request deletion of your personal information when: - Processing purpose has been achieved - Service period has expired - You withdraw consent - Processing violates laws or agreements
Right to Explanation (解释权): - Request explanation of our processing rules - Understand the basis for automated decision-making
Right to Portability (可携带权): - Request transfer of your personal information to another processor - Receive data in a structured, commonly used format
Right to Refuse Automated Decision-Making: - Object to decisions made solely by automated processing - Request human review of automated decisions
Exercising Your Rights: Submit requests to: china-privacy@reputation.report
8. Security Measures
Technical Measures (技术措施): - Encryption of personal information in transit and at rest - Access controls and authentication systems - Network security monitoring and intrusion detection - Regular security testing and vulnerability assessments - Data backup and recovery procedures
Organizational Measures (组织措施): - Designated personal information protection officer - Employee training on data protection - Confidentiality agreements with employees - Access limited to authorized personnel only - Regular internal audits and compliance reviews
Incident Response (事件响应): In case of a data breach: 1. Immediate containment and investigation 2. Notification to regulatory authorities within required timeframe 3. Notification to affected individuals 4. Remediation and prevention measures
Data Retention: - We retain personal information only as long as necessary - Retention periods based on legal requirements and business needs - Secure deletion or anonymization when no longer needed
9. Protection of Minors
Special Protection for Minors Under 14: Under PIPL, personal information of minors under 14 years of age is treated as sensitive personal information.
Our Policy: - Our services are not directed to individuals under 18 - We do not knowingly collect personal information from minors - We require parental/guardian consent for processing minor's information
If We Discover Minor's Information: - We will take immediate steps to delete such information - We will notify parents/guardians if contact information is available
Parental Rights: Parents and guardians have the right to: - Access their child's personal information - Correct inaccurate information - Request deletion of information - Withdraw consent for processing
Contact: If you believe we have collected information from a minor, contact: china-privacy@reputation.report
10. Local Representative in China
Designated Representative: In accordance with PIPL Article 53, we have designated a representative in China to handle personal information protection matters:
Representative Information: Reputation.report China Representative 北京信任大道123号500室 中国北京市 100001
Email: china-representative@reputation.report Phone: +86-10-XXXX-XXXX
Responsibilities: Our China representative: - Handles inquiries from Chinese regulatory authorities - Receives and responds to requests from individuals in China - Coordinates with our global privacy team - Maintains required records within China
Working Hours: Monday - Friday: 9:00 AM - 6:00 PM (China Standard Time)
Response Time: We aim to respond to all inquiries within 15 business days as required by PIPL.
11. Automated Decision-Making
Our Use of Automated Processing: We may use automated systems to: - Analyze online content and search results - Prioritize removal requests - Monitor reputation changes - Generate reports and alerts
Transparency: When using automated decision-making: - We ensure transparency about the logic involved - We do not make decisions affecting your rights solely through automation - Human review is available upon request
Your Rights: Under PIPL Article 24, you have the right to: - Request explanation of automated decision-making - Refuse decisions made solely through automated processing - Request human intervention and review - Challenge automated decisions that significantly affect you
Safeguards: We implement: - Regular audits of automated systems - Human oversight of significant decisions - Non-discriminatory algorithm design - Impact assessments for high-risk processing
12. Updates to This Policy
Policy Updates: We may update this PIPL Compliance Statement to reflect: - Changes in our processing activities - Updates to PIPL or related regulations - Guidance from regulatory authorities - Changes to our business operations
Notification: We will notify you of material changes by: - Email notification to registered users - Prominent notice on our website - In-app notifications where applicable
Effective Date: Changes take effect upon posting unless otherwise specified. Your continued use of our services after changes indicates acceptance.
Review: We recommend reviewing this policy periodically to stay informed about our data protection practices.
13. Contact Information
For PIPL-Related Inquiries:
China Privacy Team: Email: china-privacy@reputation.report
China Representative: Reputation.report China Representative 北京信任大道123号500室 中国北京市 100001 Phone: +86-10-XXXX-XXXX
Global Data Protection Officer: Email: dpo@reputation.report
Regulatory Authority: Cyberspace Administration of China (国家互联网信息办公室) Website: www.cac.gov.cn
Complaints: If you are not satisfied with our response, you have the right to: - File a complaint with the relevant regulatory authority - Seek legal remedies through the courts
Language: This policy is available in both English and Simplified Chinese. In case of discrepancy, the Chinese version shall prevail for users in China.
我们致力于保护您的个人信息。如有任何疑问,请随时与我们联系。
Related Policies | 相关政策
中文摘要
Reputation.report 致力于遵守中华人民共和国《个人信息保护法》。我们保护您的个人信息,尊重您的权利,包括知情权、决定权、查阅权、更正权、删除权等。如有任何疑问,请联系我们的中国代表。
联系邮箱: china-privacy@reputation.report