China Personal Information Protection Law (PIPL)
PIPL: Cross-Border Provision (Ch III)

China Personal Information Protection Law (PIPL) PIPL-Art40: Data Localisation and Security Assessment for CIIOs

Critical information infrastructure operators and handlers reaching the CAC-specified volume must store PI collected/generated in China domestically; any cross-border provision must pass a CAC security assessment unless exempted.

Other controls in PIPL: Cross-Border Provision (Ch III)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.