← Blog

China PIPL AI Incident Reporting: Article 57 Notice and Response

Parminder Singh
Parminder Singh··7 min read
Summarize with AI

PIPL Article 57 requires a personal information handler to act immediately once a personal information leak occurs or might have occurred, and it treats distortion and loss the same way. The handler must take remedial measures and notify the relevant personal information protection authorities and individuals, with a conditional route for withholding individual notice when measures effectively avoid harm. AI incidents need request evidence, while cybersecurity triage remains outside an HTTP policy proxy.

Compliance & Regulationai-complianceai-governancecomplianceregulationauditforensic-audit
China PIPL AI Incident Reporting: Article 57 Notice and Response

A customer-service agent in Shanghai sends a complaint containing an identity number and medical detail to a foreign model endpoint. The prompt succeeds and the answer returns. A red alert appears on the security console ten minutes later. PIPL Article 57 starts with the event that occurred or might have occurred, rather than with certainty about the final harm.

My view is that an incident plan waiting for confirmed exfiltration has already chosen the wrong starting line.

TL;DR

  • PIPL Article 57 requires immediate remedial measures once a personal information leak occurs or might have occurred. Distortion and loss carry the same trigger.
  • The handler must notify the authorities performing personal information protection duties and the affected individuals, with prescribed content.
  • Individual notice may be withheld when effective measures avoid harm, but the competent authority can still require it.
  • Article 57 sets no general fixed-hour notification period. Record discovery and assessment precisely, then containment and notice.
  • HTTP request records support AI-channel reconstruction. Cybersecurity triage and endpoint forensics remain outside the proxy boundary, as do authority selection and notice delivery.

Article 57 starts before every fact is settled

The official National People's Congress text of the PIPL says a personal information handler shall immediately adopt remedial measures and notify the departments performing personal information protection duties and individuals when a personal information leak, distortion, or loss occurs or might have occurred.

The phrase "might have occurred" matters during an AI event. A prompt routed to an unapproved model may create a potential leak before the team confirms provider retention or onward access. A response delivered to the wrong authenticated user may create a potential disclosure while logs are still being reconciled. A corrupted model-generated profile raises the distortion branch instead.

Open the Article 57 record at that point. Capture the discovery event and the affected workflow. Record the suspected personal-information categories with the model route and recipient. Note the immediate measures. Keep known facts separate from hypotheses. The Stanford DigiChina translation provides a useful English rendering, while the Chinese statute controls.

Remedial measures and notification run together

Article 57 contains two linked duties. The handler takes remedial measures immediately and sends notifications to the relevant authorities and individuals. Article 57 itself sets no general fixed period, not 24 hours and not 72 hours. "Immediately" makes the chronology and the reason for each interval important.

For an AI channel, remedial action may include disabling a model route or pausing an agent workflow. It may also mean blocking a data class or revoking an application credential. Provider deletion requests and stopping delivery of an exposed response belong in the same set. Preserve the request identifiers and configuration state before a change removes evidence, where preservation is lawful and safe.

Record each action with an owner and timestamp. Note the scope and the verification result too. A screenshot of a disabled toggle shows a configuration at one moment. It says little about the requests already sent. The AI incident response plan supplies the wider command structure for containment and evidence preservation.

The authority notice has a fixed content list

Article 57 requires the notice to state the categories of information involved, the cause of the incident, the possible harm, the handler's remedial measures, the measures individuals can take to mitigate harm, and the handler's contact method.

Those fields set the minimum evidence target for an AI incident. Content classification identifies the information categories. Request and route records establish the model recipient and chronology. Application and IAM evidence support cause, together with endpoint and provider records. Legal and business owners assess possible harm. The response team supplies remedial measures, while communications and privacy teams define useful steps for affected individuals.

Authority selection requires legal analysis. Article 60 says the national cyberspace department coordinates personal information protection and supervision, while relevant State Council departments act within their responsibilities and local duties follow national provisions. Avoid hard-coding every PIPL event as a single-form CAC filing without checking the sector and the parallel legal regimes that apply in that location.

Individual notice has a conditional exception

The default Article 57 text includes notice to individuals. The handler may refrain from individual notice when its measures can effectively avoid the harm the incident would cause. That conclusion needs evidence showing what the measure changed and when it took effect. It also needs the people the measure protected and the residual paths that remained.

The authority retains the last word. If a department performing personal information protection duties believes harm may have occurred, it can require notice to individuals.

For an AI disclosure, a provider deletion confirmation may support the exception and rarely settles the whole event alone. Check provider logs and subprocessors. Abuse-monitoring retention and copied outputs matter as well, along with application logs and any downstream action. Match the confirmation to the exact request identifiers and effective time. I would keep the written no-notice decision beside those records, with the approving legal owner and residual-risk analysis.

Entrusted processing changes the evidence path

Article 59 requires an entrusted party handling personal information to take necessary security measures and assist the personal information handler in fulfilling PIPL duties. When a model provider or application vendor acts on instructions, the incident plan should identify its evidence and escalation obligations before production use.

The contract should name the incident contact and preservation process. It should cover access and retention facts, plus deletion confirmation. Subprocessors and support for individual notification belong there too. Test that route with a tabletop exercise rather than discovering the vendor ticket queue during an event.

The handler still needs its own chronology. Provider logs usually identify an API credential and endpoint. They may lack the employee or agent identity and the prompt's business purpose. The internal data classification and the policy that approved the request are missing as well. The PIPL audit-evidence guide covers those routine artifacts.

Article 51 makes response preparation an operating duty

Article 51 requires handlers to adopt measures based on purpose, method, data categories, effects on individual rights, and security risks. Internal management rules and categorized handling form part of the list, along with technical measures and access limits for the systems. Employee education and a personal information security incident response plan cover operations.

For an LLM deployment, test the plan against one concrete scene. Assume a payroll agent sends employee financial-account data to an unapproved overseas model at 09:14. Ask the team to name the people and information categories from current records. Have them state the endpoint and the cause, then the likely harm and the containment action. The last pass covers the authority path and the individual-notice decision, plus the contact method.

The exercise should link to the PIPL compliance checklist and PIPL controls mapping. Note every field based on estimation. Assign an owner and due date for each gap.

Cybersecurity triage sits outside the AI proxy boundary

Article 57 privacy response can overlap with the Cybersecurity Law and the Data Security Law. Sector rules and national or local cyber-incident processes can apply to the same event. Those regimes may define their own reporting channels and response duties. Legal and incident command should determine the full set for the event.

An HTTP AI policy proxy contributes evidence for requests deliberately routed through it. It cannot inspect a compromised laptop or investigate a provider's internal environment. Malware reversing and recovery of deleted endpoint files sit elsewhere. It does not select the competent authority or assess national-security and important-data issues. It also misses direct model calls and local inference that bypass its route.

Build one fact ledger across systems. Give each fact a correlation key and source. Add the timestamp and owner, then the confidence level and the relevance to the Article 57 notice. Privacy owns the PIPL analysis, and security owns containment and forensics. Application and identity owners contribute their records, and the data and provider teams do the same. Communications and local counsel supply their decisions.

DeepInspect

DeepInspect can preserve decision evidence for deliberately routed HTTP traffic between authenticated users or agents and LLM endpoints. It checks application-supplied identity and role against organizational policy before forwarding the request. Content classification goes through the same check, as do destination and model authorization. The outcome is recorded outside the calling application's write path.

That record can support the information-category and route sections of an Article 57 file, plus the chronology and remedial-action entries. Endpoint forensics and provider investigation remain with the handler and its incident team. Cybersecurity-law triage and authority selection stay there as well, together with harm analysis and delivery of notices. Traffic bypassing the proxy and local model execution sit outside its visibility.

Book a technical deep dive at deepinspect.ai.

Frequently asked questions

Does Article 57 contain a fixed notification deadline?

The article uses an immediate-action standard and gives no general number of hours for the notifications in its text. Record when the potential event became known and what facts were available. Log which remedial steps began and when the authority and individual decisions were made. State the reason for any elapsed time. Other laws or sector rules may add a fixed period.

Can effective remediation remove the authority notification?

Article 57's express exception concerns notice to individuals when measures effectively avoid harm. The statutory text still directs the handler to notify the departments performing personal information protection duties. Counsel should assess the precise facts and any applicable implementing or sector rules rather than extending the individual-notice exception to the authority notice.

Does every model error count as distortion under Article 57?

A model hallucination alone and a distortion of personal information present different facts. The analysis should identify the personal information and the handler's processing activity. It should also pin down the changed record or output. Name the affected individuals and the possible harm. Preserve the input and output with the source record. Keep the model version and downstream use so privacy and legal teams can classify the event.