{"id":"6fff6d04-0c28-450c-8050-328e0594c7cb","entityType":"agent","slug":"clawhub-lm203688-china-data-compliance","name":"china-data-compliance","canonicalUrl":"https://www.xpersona.co/agent/clawhub-lm203688-china-data-compliance","canonicalPath":"/agent/clawhub-lm203688-china-data-compliance","generatedAt":"2026-10-11T10:52:20.370Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-11T08:28:33.267Z","emptyReason":null},"description":"Ensure applications comply with Chinese data protection laws (PIPL, Cybersecurity Law, Data Security Law). Teach AI agents how to implement privacy policies,... Skill: china-data-compliance Owner: lm203688 Summary: Ensure applications comply with Chinese data protection laws (PIPL, Cybersecurity Law, Data Security Law). Teach AI agents how to implement privacy policies,... Tags: PIPL:2.3.0, agent:1.0.0, china:2.3.0, chinese:1.1.0, compliance:2.3.0, consent:1.0.0, cybersecurity:2.3.0, data-privacy:1.1.0, data-protection:2.3.0, latest:2.3.0, legal:1.0.0, localization:1.0.0, pi","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.1K downloads reported by the source. Last updated 10/11/2026.","installCommand":"clawhub skill install s17cdyvvd1aax9tdkqfbq8wey986vhn0:china-data-compliance","sourceUrl":"https://clawhub.ai/lm203688/china-data-compliance","homepage":"https://clawhub.ai/lm203688/skills/china-data-compliance","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/lm203688/china-data-compliance","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/lm203688/skills/china-data-compliance","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":61,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Ensure applications comply with Chinese data protection laws (PIPL, Cybersecurity Law, Data Security Law). Teach AI agents how to implement privacy policies,..."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-11T08:28:33.267Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T08:28:33.267Z","emptyReason":null},"stars":null,"forks":null,"downloads":1112,"packageName":null,"latestVersion":"2.3.0","tractionLabel":"1.1K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T08:28:33.204Z","emptyReason":null},"lastUpdatedAt":"2026-10-11T08:28:33.267Z","lastCrawledAt":"2026-10-11T08:28:33.204Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-12T08:28:33.204Z","lastVerifiedAt":null,"highlights":[{"version":"2.3.0","createdAt":"2026-05-28T14:15:04.222Z","changelog":"v2.3.0: Added compatibility field (11 platforms), when_to_use+argument-hint, Next Best Skill cross-recommendation","fileCount":3,"zipByteSize":6362},{"version":"2.2.0","createdAt":"2026-05-28T05:00:09.481Z","changelog":"Updated GitHub repo link to working mirror","fileCount":3,"zipByteSize":5943},{"version":"2.1.0","createdAt":"2026-05-27T23:55:41.783Z","changelog":"Added GitHub repo link: https://github.com/lm203688/china-compliance-skills","fileCount":3,"zipByteSize":5771},{"version":"1.1.0","createdAt":"2026-05-27T01:41:40.798Z","changelog":"Added Web App link - 合规通在线检测工具","fileCount":3,"zipByteSize":5682},{"version":"1.0.0","createdAt":"2026-05-26T09:32:59.857Z","changelog":"Initial release: 5 compliance workflows (PIPL checklist, data localization, cross-border transfer assessment, security impact assessment, app privacy compliance) + consent management code + user rights API + pre-launch checklist","fileCount":3,"zipByteSize":5370}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17cdyvvd1aax9tdkqfbq8wey986vhn0:china-data-compliance","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-lm203688-china-data-compliance/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-lm203688-china-data-compliance/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-lm203688-china-data-compliance/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-lm203688-china-data-compliance/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-lm203688-china-data-compliance/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-lm203688-china-data-compliance/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-11T10:52:20.369Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-lm203688-china-data-compliance/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-lm203688-china-data-compliance/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-lm203688-china-data-compliance/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-lm203688-china-data-compliance/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-11T08:28:33.267Z","emptyReason":null},"readme":"Skill: china-data-compliance\n\nOwner: lm203688\n\nSummary: Ensure applications comply with Chinese data protection laws (PIPL, Cybersecurity Law, Data Security Law). Teach AI agents how to implement privacy policies,...\n\nTags: PIPL:2.3.0, agent:1.0.0, china:2.3.0, chinese:1.1.0, compliance:2.3.0, consent:1.0.0, cybersecurity:2.3.0, data-privacy:1.1.0, data-protection:2.3.0, latest:2.3.0, legal:1.0.0, localization:1.0.0, pipl:1.1.0, privacy:2.3.0\n\nVersion history:\n\nv2.3.0 | 2026-05-28T14:15:04.222Z | user\n\nv2.3.0: Added compatibility field (11 platforms), when_to_use+argument-hint, Next Best Skill cross-recommendation\n\nv2.2.0 | 2026-05-28T05:00:09.481Z | user\n\nUpdated GitHub repo link to working mirror\n\nv2.1.0 | 2026-05-27T23:55:41.783Z | user\n\nAdded GitHub repo link: https://github.com/lm203688/china-compliance-skills\n\nv1.1.0 | 2026-05-27T01:41:40.798Z | user\n\nAdded Web App link - 合规通在线检测工具\n\nv1.0.0 | 2026-05-26T09:32:59.857Z | user\n\nInitial release: 5 compliance workflows (PIPL checklist, data localization, cross-border transfer assessment, security impact assessment, app privacy compliance) + consent management code + user rights API + pre-launch checklist\n\nArchive index:\n\nArchive v2.3.0: 3 files, 6362 bytes\n\nFiles: skill-card.md (2654b), SKILL.md (10421b), _meta.json (140b)\n\nFile v2.3.0:SKILL.md\n\n---\nname: china-data-compliance\ndescription: \"Ensure applications comply with Chinese data protection laws (PIPL, Cybersecurity Law, Data Security Law). Teach AI agents how to implement privacy policies, consent management, data localization, cross-border transfer assessment, and security impact assessment. Covers: PIPL compliance checklist, personal information consent flow, data localization implementation, cross-border data transfer assessment, and security impact assessment (网络安全审查). Triggers on: 中国数据合规, china data compliance, 个人信息保护法, PIPL compliance, 网络安全法, cybersecurity law, 数据安全法, data security law, 数据本地化, data localization, 跨境数据传输, cross-border data transfer, 隐私政策, privacy policy china, 个人信息同意, consent management china, 网络安全审查, security assessment china, 数据出境, data export china\"\nversion: \"2.3.0\"\nlicense: MIT-0\ncompatibility: \"Claude Code, Cursor, Windsurf, Codex CLI, Gemini CLI, OpenClaw, Kimi Code, Qwen Code, Aider, Amp\"\nhomepage: \"https://github.com/lm203688/china-compliance-skills-mirror\"\nwhen_to_use: \"Use when building applications for Chinese users that collect personal information, store data, or transfer data across borders. Also for PIPL合规, 数据出境评估, 隐私政策, 数据本地化, 网络安全审查, GDPR+PIPL dual compliance, or any China data protection question.\"\nargument-hint: \"<app description or data flow> [compliance scope: pipl|cybersecurity|data-security|all]\"\n---\n\n# China Data Compliance - 中国数据合规专家\n\nYou are an expert at ensuring applications comply with China's three-pillar data protection framework: PIPL (个人信息保护法), Cybersecurity Law (网络安全法), and Data Security Law (数据安全法).\n\n## Core Philosophy\n\n**In China, data compliance is not optional — it's a prerequisite for operating.** Non-compliance can result in service suspension, fines up to ¥50M or 5% of annual revenue, and criminal liability. You help agents build compliance into the architecture, not bolt it on after.\n\n## The Three Laws\n\n| Law | Focus | Key Requirement | Max Penalty |\n|-----|-------|----------------|-------------|\n| PIPL (2021) | Personal information | Consent + purpose limitation | ¥50M or 5% revenue |\n| Cybersecurity Law (2017) | Network security | Security assessment + data localization for CII | ¥1M + suspension |\n| Data Security Law (2021) | Data classification | Classification + cross-border assessment | ¥10M + suspension |\n\n## Workflow 1: PIPL Compliance Checklist\n\n### Step 1: Privacy Policy (隐私政策)\n```markdown\nRequired sections in Chinese privacy policy:\n1. 信息收集范围 (What data you collect)\n2. 使用目的 (Why you collect it)\n3. 共享与披露 (Who you share with)\n4. 存储地点与期限 (Where and how long)\n5. 用户权利 (User rights: access, delete, export)\n6. 未成年人保护 (Under-14 protection)\n7. 跨境传输 (Cross-border transfer, if applicable)\n8. 更新机制 (How you notify changes)\n```\n\n### Step 2: Consent Management\n```javascript\n// PIPL consent flow implementation\nclass PIPLConsent {\n  // Separate consent required for:\n  // 1. Core service data collection\n  // 2. Marketing communications\n  // 3. Third-party sharing\n  // 4. Cross-border transfer\n  // 5. Sensitive personal information (biometrics, health, finance)\n  // 6. Under-14 data (parental consent required)\n\n  async collectConsent({ purpose, dataTypes, isSensitive, isCrossBorder }) {\n    // Each purpose needs SEPARATE consent (not bundled)\n    // Sensitive data needs EXPLICIT consent (not implied)\n    // Cross-border needs SEPARATE consent + security assessment\n    \n    return {\n      consentId: generateId(),\n      purpose,\n      dataTypes,\n      timestamp: Date.now(),\n      version: this.policyVersion,\n      method: isSensitive ? 'explicit' : 'general',\n      withdrawable: true  // Must always be withdrawable\n    };\n  }\n\n  async withdrawConsent(consentId) {\n    // Must stop processing within 15 days\n    // Must delete data within 30 days\n    // Cannot refuse core service if user withdraws non-essential consent\n  }\n}\n```\n\n### Step 3: User Rights Implementation\n```javascript\n// PIPL user rights API\nconst userRights = {\n  // Right to access (查阅权)\n  async exportData(userId) { /* Return all data about user */ },\n  \n  // Right to delete (删除权)\n  async deleteData(userId) { /* Delete within 30 days */ },\n  \n  // Right to correct (更正权)\n  async correctData(userId, field, value) { /* Update personal info */ },\n  \n  // Right to portability (可携带权)\n  async portData(userId) { /* Export in standard format */ },\n  \n  // Right to refuse automated decision (拒绝自动化决策权)\n  async optOutAutomation(userId) { /* Human review available */ },\n  \n  // Right to withdraw consent (撤回同意权)\n  async withdrawConsent(userId) { /* Stop processing, keep minimum */ }\n};\n```\n\n## Workflow 2: Data Localization (数据本地化)\n\n### When Required\n- **Critical Information Infrastructure (CII)** operators: MUST store in China\n- **Personal information handlers**: If processing >1M users or cumulative export >100K users\n- **Important data**: As classified by sector regulators\n\n### Implementation\n```bash\n# Tencent Cloud (China regions)\n# Store data in ap-shanghai or ap-guangzhou\ntccli cos create-bucket --Bucket my-data-cn --Region ap-shanghai\n\n# Alibaba Cloud (China regions)\naliyun oss mb oss://my-data-cn --region cn-shanghai\n\n# Database must be in China region\n# MySQL: ap-shanghai (Tencent) / cn-shanghai (Alibaba)\n# Redis: ap-shanghai (Tencent) / cn-shanghai (Alibaba)\n```\n\n### Architecture Pattern\n```\n[China Users] → [China CDN] → [China Servers (Shanghai)]\n                                    ↓ (replicated, not primary)\n                            [Global Servers (if needed)]\n```\n\n## Workflow 3: Cross-Border Data Transfer Assessment (数据出境安全评估)\n\n### Step 1: Determine if Assessment is Required\n```javascript\nfunction needsAssessment({ userCount, dataTypes, isCII, hasImportantData }) {\n  // Mandatory assessment if ANY of these:\n  if (isCII) return true;  // CII operator\n  if (hasImportantData) return true;  // Important data\n  if (userCount > 1000000) return true;  // >1M users' PI\n  if (dataTypes.includes('sensitive') && userCount > 10000) return true;  // >10K users' sensitive PI\n  if (cumulativeExportUsers > 100000) return true;  // Cumulative >100K users\n  \n  // Otherwise: standard contract or certification may suffice\n  return false;\n}\n```\n\n### Step 2: Assessment Report Template\n```markdown\n# 数据出境安全评估报告\n\n## 1. 出境数据情况\n- 数据类型和数量\n- 接收方信息\n- 传输方式和技术措施\n\n## 2. 合法性基础\n- 同意情况\n- 合同必要性\n- 法定义务\n\n## 3. 风险评估\n- 数据泄露风险\n- 数据滥用风险\n- 接收方法律环境风险\n\n## 4. 保护措施\n- 加密传输\n- 访问控制\n- 审计日志\n\n## 5. 应急预案\n- 数据泄露响应\n- 用户通知机制\n```\n\n## Workflow 4: Security Impact Assessment (网络安全审查)\n\n### When Required\n- Platform operators with >1M users before IPO\n- CII operators purchasing network products/services\n- Data processors affecting national security\n\n### Assessment Process\n```\n1. Self-assessment → 2. Submit to CAC → 3. Initial review (30 days) → 4. Deep review (90 days) → 5. Decision\n```\n\n## Workflow 5: App Privacy Compliance (App隐私合规)\n\n### Pre-Launch Checklist\n- [ ] Privacy policy accessible before registration\n- [ ] Separate consent for each data collection purpose\n- [ ] No forced consent (can use app without non-essential consent)\n- [ ] No background collection without explicit consent\n- [ ] SDK list disclosure (all third-party SDKs)\n- [ ] Under-14 special protection mode\n- [ ] Account deletion function (within 15 days)\n- [ ] Data export function\n- [ ] No unauthorized sharing with third parties\n- [ ] No tracking after uninstall\n\n### Common Rejection Reasons (App Store / Ministry review)\n1. Privacy policy not visible before first use\n2. Collecting data not mentioned in privacy policy\n3. Bundled consent (forcing all-or-nothing)\n4. No account deletion function\n5. Background location/collection without consent\n6. SDK not disclosed in privacy policy\n\n## Safety Rules\n\n1. **Never skip consent** — PIPL requires separate, explicit, informed consent\n2. **Data minimization** — only collect what you need, delete when purpose is fulfilled\n3. **China storage first** — default to China regions for Chinese user data\n4. **Document everything** — keep consent records, assessment reports, audit logs\n5. **Regular review** — laws update frequently; review compliance quarterly\n6. **Legal counsel** — this skill provides technical guidance, not legal advice; always consult a China data lawyer for production systems\n\n## 🌐 Web App — 合规通\n\n**不想写代码？直接用Web版：**\n\n👉 **https://1341839497-jv04655vcs.ap-shanghai.tencentscf.com/**\n\n- 免费检测5次/月\n- Pro版 ¥99/月：无限次检测 + 批量检测 + API接入\n- 支持小红书/抖音/百度/淘宝/京东5大平台\n- 150+违禁词库 + SEO合规检查 + 安全替换建议\n\n## Quick Reference\n\n| Requirement | Threshold | Action |\n|-------------|-----------|--------|\n| Data localization | CII operator | Store all data in China |\n| Cross-border assessment | >1M users PI | Submit to CAC |\n| Security assessment | Pre-IPO >1M users | Submit to CAC |\n| Privacy policy | All apps | Required before first use |\n| Consent management | All PI processing | Separate per purpose |\n| Account deletion | All apps | Must provide within 15 days |\n| Under-14 protection | All apps with minor users | Parental consent + special mode |\n\n## Next Best Skill\n\n- **Primary**: [cn-seo-optimizer](https://github.com/lm203688/china-compliance-skills-mirror/tree/main/skills/cn-seo-optimizer) — after data compliance is in place, check content for advertising law violations\n- **Related**: [cn-geo-monitor](https://github.com/lm203688/china-compliance-skills-mirror/tree/main/skills/cn-geo-monitor) — optimize brand visibility in Chinese AI search engines\n\n## 📦 Open Source Skill Library\n\nThis skill is part of **[China Compliance Skills](https://github.com/lm203688/china-compliance-skills-mirror)** — 4 premium AI agent skills for Chinese content compliance. Star ⭐ the repo to support!\n\nFile v2.3.0:_meta.json\n\n{\n  \"ownerId\": \"kn7a6kxswmnbamxxthy2pgjrkn86vpfy\",\n  \"slug\": \"china-data-compliance\",\n  \"version\": \"2.3.0\",\n  \"publishedAt\": 1779977704222\n}\n\nFile v2.3.0:skill-card.md\n\n## Description:\n\nEnsure applications comply with Chinese data protection laws, including PIPL, Cybersecurity Law, and Data Security Law, by guiding privacy policies, consent management, data localization, cross-border transfer assessment, and security impact assessment.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[lm203688](https://clawhub.ai/user/lm203688)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and compliance engineers use this skill when building applications for Chinese users that collect personal information, store data, or transfer data across borders. It helps agents draft implementation guidance, checklists, data-flow assessments, and technical patterns for China data compliance.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill promotes an external commercial web app that may receive compliance content without clear data-handling disclosure.\n\nMitigation: Do not paste sensitive policy drafts, business data, personal information, or regulated content into the external app unless its operator, terms, and data handling have been independently reviewed.\n\nRisk: Legal thresholds and cloud-region commands may become outdated or may not match a specific deployment context.\n\nMitigation: Treat the guidance as a starting point and require current legal, security, and infrastructure review before using it for production compliance decisions.\n\n## Reference(s):\n\n- [ClawHub skill listing](https://clawhub.ai/lm203688/skills/china-data-compliance)\n- [China Compliance Skills repository](https://github.com/lm203688/china-compliance-skills-mirror)\n- [cn-seo-optimizer related skill](https://github.com/lm203688/china-compliance-skills-mirror/tree/main/skills/cn-seo-optimizer)\n- [cn-geo-monitor related skill](https://github.com/lm203688/china-compliance-skills-mirror/tree/main/skills/cn-geo-monitor)\n\n## Skill Output:\n\n**Output Type(s):** [Markdown, Code, Shell commands, Configuration, Guidance]\n\n**Output Format:** [Markdown with checklists, tables, code snippets, shell commands, and architecture notes]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May include legal and infrastructure compliance guidance that requires current professional review before production use.]\n\n## Skill Version(s):\n\n2.3.0 (source: frontmatter and server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v2.2.0: 3 files, 5943 bytes\n\nFiles: skill-card.md (2541b), SKILL.md (9381b), _meta.json (140b)\n\nFile v2.2.0:SKILL.md\n\n---\nname: china-data-compliance\ndescription: \"Ensure applications comply with Chinese data protection laws (PIPL, Cybersecurity Law, Data Security Law). Teach AI agents how to implement privacy policies, consent management, data localization, cross-border transfer assessment, and security impact assessment. Covers: PIPL compliance checklist, personal information consent flow, data localization implementation, cross-border data transfer assessment, and security impact assessment (网络安全审查). Triggers on: 中国数据合规, china data compliance, 个人信息保护法, PIPL compliance, 网络安全法, cybersecurity law, 数据安全法, data security law, 数据本地化, data localization, 跨境数据传输, cross-border data transfer, 隐私政策, privacy policy china, 个人信息同意, consent management china, 网络安全审查, security assessment china, 数据出境, data export china\"\n---\n\n# China Data Compliance - 中国数据合规专家\n\nYou are an expert at ensuring applications comply with China's three-pillar data protection framework: PIPL (个人信息保护法), Cybersecurity Law (网络安全法), and Data Security Law (数据安全法).\n\n## Core Philosophy\n\n**In China, data compliance is not optional — it's a prerequisite for operating.** Non-compliance can result in service suspension, fines up to ¥50M or 5% of annual revenue, and criminal liability. You help agents build compliance into the architecture, not bolt it on after.\n\n## The Three Laws\n\n| Law | Focus | Key Requirement | Max Penalty |\n|-----|-------|----------------|-------------|\n| PIPL (2021) | Personal information | Consent + purpose limitation | ¥50M or 5% revenue |\n| Cybersecurity Law (2017) | Network security | Security assessment + data localization for CII | ¥1M + suspension |\n| Data Security Law (2021) | Data classification | Classification + cross-border assessment | ¥10M + suspension |\n\n## Workflow 1: PIPL Compliance Checklist\n\n### Step 1: Privacy Policy (隐私政策)\n```markdown\nRequired sections in Chinese privacy policy:\n1. 信息收集范围 (What data you collect)\n2. 使用目的 (Why you collect it)\n3. 共享与披露 (Who you share with)\n4. 存储地点与期限 (Where and how long)\n5. 用户权利 (User rights: access, delete, export)\n6. 未成年人保护 (Under-14 protection)\n7. 跨境传输 (Cross-border transfer, if applicable)\n8. 更新机制 (How you notify changes)\n```\n\n### Step 2: Consent Management\n```javascript\n// PIPL consent flow implementation\nclass PIPLConsent {\n  // Separate consent required for:\n  // 1. Core service data collection\n  // 2. Marketing communications\n  // 3. Third-party sharing\n  // 4. Cross-border transfer\n  // 5. Sensitive personal information (biometrics, health, finance)\n  // 6. Under-14 data (parental consent required)\n\n  async collectConsent({ purpose, dataTypes, isSensitive, isCrossBorder }) {\n    // Each purpose needs SEPARATE consent (not bundled)\n    // Sensitive data needs EXPLICIT consent (not implied)\n    // Cross-border needs SEPARATE consent + security assessment\n    \n    return {\n      consentId: generateId(),\n      purpose,\n      dataTypes,\n      timestamp: Date.now(),\n      version: this.policyVersion,\n      method: isSensitive ? 'explicit' : 'general',\n      withdrawable: true  // Must always be withdrawable\n    };\n  }\n\n  async withdrawConsent(consentId) {\n    // Must stop processing within 15 days\n    // Must delete data within 30 days\n    // Cannot refuse core service if user withdraws non-essential consent\n  }\n}\n```\n\n### Step 3: User Rights Implementation\n```javascript\n// PIPL user rights API\nconst userRights = {\n  // Right to access (查阅权)\n  async exportData(userId) { /* Return all data about user */ },\n  \n  // Right to delete (删除权)\n  async deleteData(userId) { /* Delete within 30 days */ },\n  \n  // Right to correct (更正权)\n  async correctData(userId, field, value) { /* Update personal info */ },\n  \n  // Right to portability (可携带权)\n  async portData(userId) { /* Export in standard format */ },\n  \n  // Right to refuse automated decision (拒绝自动化决策权)\n  async optOutAutomation(userId) { /* Human review available */ },\n  \n  // Right to withdraw consent (撤回同意权)\n  async withdrawConsent(userId) { /* Stop processing, keep minimum */ }\n};\n```\n\n## Workflow 2: Data Localization (数据本地化)\n\n### When Required\n- **Critical Information Infrastructure (CII)** operators: MUST store in China\n- **Personal information handlers**: If processing >1M users or cumulative export >100K users\n- **Important data**: As classified by sector regulators\n\n### Implementation\n```bash\n# Tencent Cloud (China regions)\n# Store data in ap-shanghai or ap-guangzhou\ntccli cos create-bucket --Bucket my-data-cn --Region ap-shanghai\n\n# Alibaba Cloud (China regions)\naliyun oss mb oss://my-data-cn --region cn-shanghai\n\n# Database must be in China region\n# MySQL: ap-shanghai (Tencent) / cn-shanghai (Alibaba)\n# Redis: ap-shanghai (Tencent) / cn-shanghai (Alibaba)\n```\n\n### Architecture Pattern\n```\n[China Users] → [China CDN] → [China Servers (Shanghai)]\n                                    ↓ (replicated, not primary)\n                            [Global Servers (if needed)]\n```\n\n## Workflow 3: Cross-Border Data Transfer Assessment (数据出境安全评估)\n\n### Step 1: Determine if Assessment is Required\n```javascript\nfunction needsAssessment({ userCount, dataTypes, isCII, hasImportantData }) {\n  // Mandatory assessment if ANY of these:\n  if (isCII) return true;  // CII operator\n  if (hasImportantData) return true;  // Important data\n  if (userCount > 1000000) return true;  // >1M users' PI\n  if (dataTypes.includes('sensitive') && userCount > 10000) return true;  // >10K users' sensitive PI\n  if (cumulativeExportUsers > 100000) return true;  // Cumulative >100K users\n  \n  // Otherwise: standard contract or certification may suffice\n  return false;\n}\n```\n\n### Step 2: Assessment Report Template\n```markdown\n# 数据出境安全评估报告\n\n## 1. 出境数据情况\n- 数据类型和数量\n- 接收方信息\n- 传输方式和技术措施\n\n## 2. 合法性基础\n- 同意情况\n- 合同必要性\n- 法定义务\n\n## 3. 风险评估\n- 数据泄露风险\n- 数据滥用风险\n- 接收方法律环境风险\n\n## 4. 保护措施\n- 加密传输\n- 访问控制\n- 审计日志\n\n## 5. 应急预案\n- 数据泄露响应\n- 用户通知机制\n```\n\n## Workflow 4: Security Impact Assessment (网络安全审查)\n\n### When Required\n- Platform operators with >1M users before IPO\n- CII operators purchasing network products/services\n- Data processors affecting national security\n\n### Assessment Process\n```\n1. Self-assessment → 2. Submit to CAC → 3. Initial review (30 days) → 4. Deep review (90 days) → 5. Decision\n```\n\n## Workflow 5: App Privacy Compliance (App隐私合规)\n\n### Pre-Launch Checklist\n- [ ] Privacy policy accessible before registration\n- [ ] Separate consent for each data collection purpose\n- [ ] No forced consent (can use app without non-essential consent)\n- [ ] No background collection without explicit consent\n- [ ] SDK list disclosure (all third-party SDKs)\n- [ ] Under-14 special protection mode\n- [ ] Account deletion function (within 15 days)\n- [ ] Data export function\n- [ ] No unauthorized sharing with third parties\n- [ ] No tracking after uninstall\n\n### Common Rejection Reasons (App Store / Ministry review)\n1. Privacy policy not visible before first use\n2. Collecting data not mentioned in privacy policy\n3. Bundled consent (forcing all-or-nothing)\n4. No account deletion function\n5. Background location/collection without consent\n6. SDK not disclosed in privacy policy\n\n## Safety Rules\n\n1. **Never skip consent** — PIPL requires separate, explicit, informed consent\n2. **Data minimization** — only collect what you need, delete when purpose is fulfilled\n3. **China storage first** — default to China regions for Chinese user data\n4. **Document everything** — keep consent records, assessment reports, audit logs\n5. **Regular review** — laws update frequently; review compliance quarterly\n6. **Legal counsel** — this skill provides technical guidance, not legal advice; always consult a China data lawyer for production systems\n\n## 🌐 Web App — 合规通\n\n**不想写代码？直接用Web版：**\n\n👉 **https://1341839497-jv04655vcs.ap-shanghai.tencentscf.com/**\n\n- 免费检测5次/月\n- Pro版 ¥99/月：无限次检测 + 批量检测 + API接入\n- 支持小红书/抖音/百度/淘宝/京东5大平台\n- 150+违禁词库 + SEO合规检查 + 安全替换建议\n\n## Quick Reference\n\n| Requirement | Threshold | Action |\n|-------------|-----------|--------|\n| Data localization | CII operator | Store all data in China |\n| Cross-border assessment | >1M users PI | Submit to CAC |\n| Security assessment | Pre-IPO >1M users | Submit to CAC |\n| Privacy policy | All apps | Required before first use |\n| Consent management | All PI processing | Separate per purpose |\n| Account deletion | All apps | Must provide within 15 days |\n| Under-14 protection | All apps with minor users | Parental consent + special mode |\n\n## 📦 Open Source Skill Library\n\nThis skill is part of **[China Compliance Skills](https://github.com/lm203688/china-compliance-skills-mirror)** — 4 premium AI agent skills for Chinese content compliance. Star ⭐ the repo to support!\n\nFile v2.2.0:_meta.json\n\n{\n  \"ownerId\": \"kn7a6kxswmnbamxxthy2pgjrkn86vpfy\",\n  \"slug\": \"china-data-compliance\",\n  \"version\": \"2.2.0\",\n  \"publishedAt\": 1779944409481\n}\n\nFile v2.2.0:skill-card.md\n\n## Description: <br>\nProvides technical guidance for building applications that address China's PIPL, Cybersecurity Law, and Data Security Law requirements, including consent, localization, cross-border transfer assessment, and security impact assessment. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[lm203688](https://clawhub.ai/user/lm203688) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and compliance-focused teams use this skill to draft and review technical patterns for China-facing apps, including privacy policy sections, consent flows, China-region storage, data export assessments, and security review checklists. <br>\n\n### Deployment Geography for Use: <br>\nChina-facing products and services; agent use may be global. <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Compliance guidance may be incomplete or unsuitable for a specific China-facing project. <br>\nMitigation: Treat the skill as technical guidance, not legal advice, and confirm production decisions with qualified legal or compliance counsel. <br>\nRisk: The optional third-party web app may receive sensitive data if users paste content into it. <br>\nMitigation: Vet the operator, terms, and data-handling practices first; do not submit personal, regulated, confidential, or business-sensitive data without approval. <br>\nRisk: Broad templates and thresholds may be applied to projects that are not actually China-facing. <br>\nMitigation: Confirm the project's user base, data flows, and regulatory scope before applying China-specific implementation patterns. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/lm203688/china-data-compliance) <br>\n- [Optional third-party web app](https://1341839497-jv04655vcs.ap-shanghai.tencentscf.com/) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Guidance, Markdown, Code, Shell commands, Configuration] <br>\n**Output Format:** [Markdown guidance with checklist tables and example JavaScript and shell command snippets] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Includes compliance-oriented templates and examples; not legal advice.] <br>\n\n## Skill Version(s): <br>\n2.2.0 (source: server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v2.1.0: 3 files, 5771 bytes\n\nFiles: skill-card.md (2244b), SKILL.md (9374b), _meta.json (140b)\n\nFile v2.1.0:SKILL.md\n\n---\nname: china-data-compliance\ndescription: \"Ensure applications comply with Chinese data protection laws (PIPL, Cybersecurity Law, Data Security Law). Teach AI agents how to implement privacy policies, consent management, data localization, cross-border transfer assessment, and security impact assessment. Covers: PIPL compliance checklist, personal information consent flow, data localization implementation, cross-border data transfer assessment, and security impact assessment (网络安全审查). Triggers on: 中国数据合规, china data compliance, 个人信息保护法, PIPL compliance, 网络安全法, cybersecurity law, 数据安全法, data security law, 数据本地化, data localization, 跨境数据传输, cross-border data transfer, 隐私政策, privacy policy china, 个人信息同意, consent management china, 网络安全审查, security assessment china, 数据出境, data export china\"\n---\n\n# China Data Compliance - 中国数据合规专家\n\nYou are an expert at ensuring applications comply with China's three-pillar data protection framework: PIPL (个人信息保护法), Cybersecurity Law (网络安全法), and Data Security Law (数据安全法).\n\n## Core Philosophy\n\n**In China, data compliance is not optional — it's a prerequisite for operating.** Non-compliance can result in service suspension, fines up to ¥50M or 5% of annual revenue, and criminal liability. You help agents build compliance into the architecture, not bolt it on after.\n\n## The Three Laws\n\n| Law | Focus | Key Requirement | Max Penalty |\n|-----|-------|----------------|-------------|\n| PIPL (2021) | Personal information | Consent + purpose limitation | ¥50M or 5% revenue |\n| Cybersecurity Law (2017) | Network security | Security assessment + data localization for CII | ¥1M + suspension |\n| Data Security Law (2021) | Data classification | Classification + cross-border assessment | ¥10M + suspension |\n\n## Workflow 1: PIPL Compliance Checklist\n\n### Step 1: Privacy Policy (隐私政策)\n```markdown\nRequired sections in Chinese privacy policy:\n1. 信息收集范围 (What data you collect)\n2. 使用目的 (Why you collect it)\n3. 共享与披露 (Who you share with)\n4. 存储地点与期限 (Where and how long)\n5. 用户权利 (User rights: access, delete, export)\n6. 未成年人保护 (Under-14 protection)\n7. 跨境传输 (Cross-border transfer, if applicable)\n8. 更新机制 (How you notify changes)\n```\n\n### Step 2: Consent Management\n```javascript\n// PIPL consent flow implementation\nclass PIPLConsent {\n  // Separate consent required for:\n  // 1. Core service data collection\n  // 2. Marketing communications\n  // 3. Third-party sharing\n  // 4. Cross-border transfer\n  // 5. Sensitive personal information (biometrics, health, finance)\n  // 6. Under-14 data (parental consent required)\n\n  async collectConsent({ purpose, dataTypes, isSensitive, isCrossBorder }) {\n    // Each purpose needs SEPARATE consent (not bundled)\n    // Sensitive data needs EXPLICIT consent (not implied)\n    // Cross-border needs SEPARATE consent + security assessment\n    \n    return {\n      consentId: generateId(),\n      purpose,\n      dataTypes,\n      timestamp: Date.now(),\n      version: this.policyVersion,\n      method: isSensitive ? 'explicit' : 'general',\n      withdrawable: true  // Must always be withdrawable\n    };\n  }\n\n  async withdrawConsent(consentId) {\n    // Must stop processing within 15 days\n    // Must delete data within 30 days\n    // Cannot refuse core service if user withdraws non-essential consent\n  }\n}\n```\n\n### Step 3: User Rights Implementation\n```javascript\n// PIPL user rights API\nconst userRights = {\n  // Right to access (查阅权)\n  async exportData(userId) { /* Return all data about user */ },\n  \n  // Right to delete (删除权)\n  async deleteData(userId) { /* Delete within 30 days */ },\n  \n  // Right to correct (更正权)\n  async correctData(userId, field, value) { /* Update personal info */ },\n  \n  // Right to portability (可携带权)\n  async portData(userId) { /* Export in standard format */ },\n  \n  // Right to refuse automated decision (拒绝自动化决策权)\n  async optOutAutomation(userId) { /* Human review available */ },\n  \n  // Right to withdraw consent (撤回同意权)\n  async withdrawConsent(userId) { /* Stop processing, keep minimum */ }\n};\n```\n\n## Workflow 2: Data Localization (数据本地化)\n\n### When Required\n- **Critical Information Infrastructure (CII)** operators: MUST store in China\n- **Personal information handlers**: If processing >1M users or cumulative export >100K users\n- **Important data**: As classified by sector regulators\n\n### Implementation\n```bash\n# Tencent Cloud (China regions)\n# Store data in ap-shanghai or ap-guangzhou\ntccli cos create-bucket --Bucket my-data-cn --Region ap-shanghai\n\n# Alibaba Cloud (China regions)\naliyun oss mb oss://my-data-cn --region cn-shanghai\n\n# Database must be in China region\n# MySQL: ap-shanghai (Tencent) / cn-shanghai (Alibaba)\n# Redis: ap-shanghai (Tencent) / cn-shanghai (Alibaba)\n```\n\n### Architecture Pattern\n```\n[China Users] → [China CDN] → [China Servers (Shanghai)]\n                                    ↓ (replicated, not primary)\n                            [Global Servers (if needed)]\n```\n\n## Workflow 3: Cross-Border Data Transfer Assessment (数据出境安全评估)\n\n### Step 1: Determine if Assessment is Required\n```javascript\nfunction needsAssessment({ userCount, dataTypes, isCII, hasImportantData }) {\n  // Mandatory assessment if ANY of these:\n  if (isCII) return true;  // CII operator\n  if (hasImportantData) return true;  // Important data\n  if (userCount > 1000000) return true;  // >1M users' PI\n  if (dataTypes.includes('sensitive') && userCount > 10000) return true;  // >10K users' sensitive PI\n  if (cumulativeExportUsers > 100000) return true;  // Cumulative >100K users\n  \n  // Otherwise: standard contract or certification may suffice\n  return false;\n}\n```\n\n### Step 2: Assessment Report Template\n```markdown\n# 数据出境安全评估报告\n\n## 1. 出境数据情况\n- 数据类型和数量\n- 接收方信息\n- 传输方式和技术措施\n\n## 2. 合法性基础\n- 同意情况\n- 合同必要性\n- 法定义务\n\n## 3. 风险评估\n- 数据泄露风险\n- 数据滥用风险\n- 接收方法律环境风险\n\n## 4. 保护措施\n- 加密传输\n- 访问控制\n- 审计日志\n\n## 5. 应急预案\n- 数据泄露响应\n- 用户通知机制\n```\n\n## Workflow 4: Security Impact Assessment (网络安全审查)\n\n### When Required\n- Platform operators with >1M users before IPO\n- CII operators purchasing network products/services\n- Data processors affecting national security\n\n### Assessment Process\n```\n1. Self-assessment → 2. Submit to CAC → 3. Initial review (30 days) → 4. Deep review (90 days) → 5. Decision\n```\n\n## Workflow 5: App Privacy Compliance (App隐私合规)\n\n### Pre-Launch Checklist\n- [ ] Privacy policy accessible before registration\n- [ ] Separate consent for each data collection purpose\n- [ ] No forced consent (can use app without non-essential consent)\n- [ ] No background collection without explicit consent\n- [ ] SDK list disclosure (all third-party SDKs)\n- [ ] Under-14 special protection mode\n- [ ] Account deletion function (within 15 days)\n- [ ] Data export function\n- [ ] No unauthorized sharing with third parties\n- [ ] No tracking after uninstall\n\n### Common Rejection Reasons (App Store / Ministry review)\n1. Privacy policy not visible before first use\n2. Collecting data not mentioned in privacy policy\n3. Bundled consent (forcing all-or-nothing)\n4. No account deletion function\n5. Background location/collection without consent\n6. SDK not disclosed in privacy policy\n\n## Safety Rules\n\n1. **Never skip consent** — PIPL requires separate, explicit, informed consent\n2. **Data minimization** — only collect what you need, delete when purpose is fulfilled\n3. **China storage first** — default to China regions for Chinese user data\n4. **Document everything** — keep consent records, assessment reports, audit logs\n5. **Regular review** — laws update frequently; review compliance quarterly\n6. **Legal counsel** — this skill provides technical guidance, not legal advice; always consult a China data lawyer for production systems\n\n## 🌐 Web App — 合规通\n\n**不想写代码？直接用Web版：**\n\n👉 **https://1341839497-jv04655vcs.ap-shanghai.tencentscf.com/**\n\n- 免费检测5次/月\n- Pro版 ¥99/月：无限次检测 + 批量检测 + API接入\n- 支持小红书/抖音/百度/淘宝/京东5大平台\n- 150+违禁词库 + SEO合规检查 + 安全替换建议\n\n## Quick Reference\n\n| Requirement | Threshold | Action |\n|-------------|-----------|--------|\n| Data localization | CII operator | Store all data in China |\n| Cross-border assessment | >1M users PI | Submit to CAC |\n| Security assessment | Pre-IPO >1M users | Submit to CAC |\n| Privacy policy | All apps | Required before first use |\n| Consent management | All PI processing | Separate per purpose |\n| Account deletion | All apps | Must provide within 15 days |\n| Under-14 protection | All apps with minor users | Parental consent + special mode |\n\n## 📦 Open Source Skill Library\n\nThis skill is part of **[China Compliance Skills](https://github.com/lm203688/china-compliance-skills)** — 4 premium AI agent skills for Chinese content compliance. Star ⭐ the repo to support!\n\nFile v2.1.0:_meta.json\n\n{\n  \"ownerId\": \"kn7a6kxswmnbamxxthy2pgjrkn86vpfy\",\n  \"slug\": \"china-data-compliance\",\n  \"version\": \"2.1.0\",\n  \"publishedAt\": 1779926141783\n}\n\nFile v2.1.0:skill-card.md\n\n## Description: <br>\nHelps agents guide developers through China data-compliance implementation for PIPL, Cybersecurity Law, and Data Security Law, including privacy policies, consent management, data localization, cross-border transfer assessment, and security impact assessment. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[lm203688](https://clawhub.ai/user/lm203688) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and engineers use this skill to build China data-compliance workflows for privacy policies, consent flows, data localization, cross-border data transfer assessments, security impact assessments, and app privacy review. It should be treated as technical guidance, not legal advice. <br>\n\n### Deployment Geography for Use: <br>\nGlobal, with subject matter focused on China data-protection requirements. <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Users may treat technical compliance guidance as legal advice for production systems. <br>\nMitigation: Use the skill for implementation planning and have China-qualified legal counsel review production compliance decisions. <br>\nRisk: Optional linked web app or repository content may be operated outside the installed skill and may receive sensitive inputs. <br>\nMitigation: Verify the operator, data handling practices, and suitability for sensitive business, legal, or user-data inputs before using linked resources. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/lm203688/china-data-compliance) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Guidance, Markdown, Code, Shell commands, Configuration] <br>\n**Output Format:** [Markdown guidance with checklists, templates, JavaScript examples, shell commands, and architecture patterns] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [None] <br>\n\n## Skill Version(s): <br>\n2.1.0 (source: server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.1.0: 3 files, 5682 bytes\n\nFiles: skill-card.md (2173b), SKILL.md (9141b), _meta.json (140b)\n\nFile v1.1.0:SKILL.md\n\n---\nname: china-data-compliance\ndescription: \"Ensure applications comply with Chinese data protection laws (PIPL, Cybersecurity Law, Data Security Law). Teach AI agents how to implement privacy policies, consent management, data localization, cross-border transfer assessment, and security impact assessment. Covers: PIPL compliance checklist, personal information consent flow, data localization implementation, cross-border data transfer assessment, and security impact assessment (网络安全审查). Triggers on: 中国数据合规, china data compliance, 个人信息保护法, PIPL compliance, 网络安全法, cybersecurity law, 数据安全法, data security law, 数据本地化, data localization, 跨境数据传输, cross-border data transfer, 隐私政策, privacy policy china, 个人信息同意, consent management china, 网络安全审查, security assessment china, 数据出境, data export china\"\n---\n\n# China Data Compliance - 中国数据合规专家\n\nYou are an expert at ensuring applications comply with China's three-pillar data protection framework: PIPL (个人信息保护法), Cybersecurity Law (网络安全法), and Data Security Law (数据安全法).\n\n## Core Philosophy\n\n**In China, data compliance is not optional — it's a prerequisite for operating.** Non-compliance can result in service suspension, fines up to ¥50M or 5% of annual revenue, and criminal liability. You help agents build compliance into the architecture, not bolt it on after.\n\n## The Three Laws\n\n| Law | Focus | Key Requirement | Max Penalty |\n|-----|-------|----------------|-------------|\n| PIPL (2021) | Personal information | Consent + purpose limitation | ¥50M or 5% revenue |\n| Cybersecurity Law (2017) | Network security | Security assessment + data localization for CII | ¥1M + suspension |\n| Data Security Law (2021) | Data classification | Classification + cross-border assessment | ¥10M + suspension |\n\n## Workflow 1: PIPL Compliance Checklist\n\n### Step 1: Privacy Policy (隐私政策)\n```markdown\nRequired sections in Chinese privacy policy:\n1. 信息收集范围 (What data you collect)\n2. 使用目的 (Why you collect it)\n3. 共享与披露 (Who you share with)\n4. 存储地点与期限 (Where and how long)\n5. 用户权利 (User rights: access, delete, export)\n6. 未成年人保护 (Under-14 protection)\n7. 跨境传输 (Cross-border transfer, if applicable)\n8. 更新机制 (How you notify changes)\n```\n\n### Step 2: Consent Management\n```javascript\n// PIPL consent flow implementation\nclass PIPLConsent {\n  // Separate consent required for:\n  // 1. Core service data collection\n  // 2. Marketing communications\n  // 3. Third-party sharing\n  // 4. Cross-border transfer\n  // 5. Sensitive personal information (biometrics, health, finance)\n  // 6. Under-14 data (parental consent required)\n\n  async collectConsent({ purpose, dataTypes, isSensitive, isCrossBorder }) {\n    // Each purpose needs SEPARATE consent (not bundled)\n    // Sensitive data needs EXPLICIT consent (not implied)\n    // Cross-border needs SEPARATE consent + security assessment\n    \n    return {\n      consentId: generateId(),\n      purpose,\n      dataTypes,\n      timestamp: Date.now(),\n      version: this.policyVersion,\n      method: isSensitive ? 'explicit' : 'general',\n      withdrawable: true  // Must always be withdrawable\n    };\n  }\n\n  async withdrawConsent(consentId) {\n    // Must stop processing within 15 days\n    // Must delete data within 30 days\n    // Cannot refuse core service if user withdraws non-essential consent\n  }\n}\n```\n\n### Step 3: User Rights Implementation\n```javascript\n// PIPL user rights API\nconst userRights = {\n  // Right to access (查阅权)\n  async exportData(userId) { /* Return all data about user */ },\n  \n  // Right to delete (删除权)\n  async deleteData(userId) { /* Delete within 30 days */ },\n  \n  // Right to correct (更正权)\n  async correctData(userId, field, value) { /* Update personal info */ },\n  \n  // Right to portability (可携带权)\n  async portData(userId) { /* Export in standard format */ },\n  \n  // Right to refuse automated decision (拒绝自动化决策权)\n  async optOutAutomation(userId) { /* Human review available */ },\n  \n  // Right to withdraw consent (撤回同意权)\n  async withdrawConsent(userId) { /* Stop processing, keep minimum */ }\n};\n```\n\n## Workflow 2: Data Localization (数据本地化)\n\n### When Required\n- **Critical Information Infrastructure (CII)** operators: MUST store in China\n- **Personal information handlers**: If processing >1M users or cumulative export >100K users\n- **Important data**: As classified by sector regulators\n\n### Implementation\n```bash\n# Tencent Cloud (China regions)\n# Store data in ap-shanghai or ap-guangzhou\ntccli cos create-bucket --Bucket my-data-cn --Region ap-shanghai\n\n# Alibaba Cloud (China regions)\naliyun oss mb oss://my-data-cn --region cn-shanghai\n\n# Database must be in China region\n# MySQL: ap-shanghai (Tencent) / cn-shanghai (Alibaba)\n# Redis: ap-shanghai (Tencent) / cn-shanghai (Alibaba)\n```\n\n### Architecture Pattern\n```\n[China Users] → [China CDN] → [China Servers (Shanghai)]\n                                    ↓ (replicated, not primary)\n                            [Global Servers (if needed)]\n```\n\n## Workflow 3: Cross-Border Data Transfer Assessment (数据出境安全评估)\n\n### Step 1: Determine if Assessment is Required\n```javascript\nfunction needsAssessment({ userCount, dataTypes, isCII, hasImportantData }) {\n  // Mandatory assessment if ANY of these:\n  if (isCII) return true;  // CII operator\n  if (hasImportantData) return true;  // Important data\n  if (userCount > 1000000) return true;  // >1M users' PI\n  if (dataTypes.includes('sensitive') && userCount > 10000) return true;  // >10K users' sensitive PI\n  if (cumulativeExportUsers > 100000) return true;  // Cumulative >100K users\n  \n  // Otherwise: standard contract or certification may suffice\n  return false;\n}\n```\n\n### Step 2: Assessment Report Template\n```markdown\n# 数据出境安全评估报告\n\n## 1. 出境数据情况\n- 数据类型和数量\n- 接收方信息\n- 传输方式和技术措施\n\n## 2. 合法性基础\n- 同意情况\n- 合同必要性\n- 法定义务\n\n## 3. 风险评估\n- 数据泄露风险\n- 数据滥用风险\n- 接收方法律环境风险\n\n## 4. 保护措施\n- 加密传输\n- 访问控制\n- 审计日志\n\n## 5. 应急预案\n- 数据泄露响应\n- 用户通知机制\n```\n\n## Workflow 4: Security Impact Assessment (网络安全审查)\n\n### When Required\n- Platform operators with >1M users before IPO\n- CII operators purchasing network products/services\n- Data processors affecting national security\n\n### Assessment Process\n```\n1. Self-assessment → 2. Submit to CAC → 3. Initial review (30 days) → 4. Deep review (90 days) → 5. Decision\n```\n\n## Workflow 5: App Privacy Compliance (App隐私合规)\n\n### Pre-Launch Checklist\n- [ ] Privacy policy accessible before registration\n- [ ] Separate consent for each data collection purpose\n- [ ] No forced consent (can use app without non-essential consent)\n- [ ] No background collection without explicit consent\n- [ ] SDK list disclosure (all third-party SDKs)\n- [ ] Under-14 special protection mode\n- [ ] Account deletion function (within 15 days)\n- [ ] Data export function\n- [ ] No unauthorized sharing with third parties\n- [ ] No tracking after uninstall\n\n### Common Rejection Reasons (App Store / Ministry review)\n1. Privacy policy not visible before first use\n2. Collecting data not mentioned in privacy policy\n3. Bundled consent (forcing all-or-nothing)\n4. No account deletion function\n5. Background location/collection without consent\n6. SDK not disclosed in privacy policy\n\n## Safety Rules\n\n1. **Never skip consent** — PIPL requires separate, explicit, informed consent\n2. **Data minimization** — only collect what you need, delete when purpose is fulfilled\n3. **China storage first** — default to China regions for Chinese user data\n4. **Document everything** — keep consent records, assessment reports, audit logs\n5. **Regular review** — laws update frequently; review compliance quarterly\n6. **Legal counsel** — this skill provides technical guidance, not legal advice; always consult a China data lawyer for production systems\n\n## 🌐 Web App — 合规通\n\n**不想写代码？直接用Web版：**\n\n👉 **https://1341839497-jv04655vcs.ap-shanghai.tencentscf.com/**\n\n- 免费检测5次/月\n- Pro版 ¥99/月：无限次检测 + 批量检测 + API接入\n- 支持小红书/抖音/百度/淘宝/京东5大平台\n- 150+违禁词库 + SEO合规检查 + 安全替换建议\n\n## Quick Reference\n\n| Requirement | Threshold | Action |\n|-------------|-----------|--------|\n| Data localization | CII operator | Store all data in China |\n| Cross-border assessment | >1M users PI | Submit to CAC |\n| Security assessment | Pre-IPO >1M users | Submit to CAC |\n| Privacy policy | All apps | Required before first use |\n| Consent management | All PI processing | Separate per purpose |\n| Account deletion | All apps | Must provide within 15 days |\n| Under-14 protection | All apps with minor users | Parental consent + special mode |\n\nFile v1.1.0:_meta.json\n\n{\n  \"ownerId\": \"kn7a6kxswmnbamxxthy2pgjrkn86vpfy\",\n  \"slug\": \"china-data-compliance\",\n  \"version\": \"1.1.0\",\n  \"publishedAt\": 1779846100798\n}\n\nFile v1.1.0:skill-card.md\n\n## Description: <br>\nHelps agents produce technical guidance for applications implementing China data protection controls under PIPL, the Cybersecurity Law, and the Data Security Law. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[lm203688](https://clawhub.ai/user/lm203688) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and engineers use this skill to plan and implement China data compliance patterns such as privacy notices, consent flows, data localization, cross-border transfer assessment, and security review preparation. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Users may treat compliance guidance as legal advice. <br>\nMitigation: Use the skill as technical guidance and consult qualified China data compliance counsel before production decisions. <br>\nRisk: The skill includes a third-party web app link with unclear ownership and data-handling disclosures. <br>\nMitigation: Do not enter personal data, regulated business data, contracts, or compliance materials into that service until its operator, privacy terms, storage location, and retention practices have been reviewed. <br>\n\n\n## Reference(s): <br>\n- [ClawHub release page](https://clawhub.ai/lm203688/china-data-compliance) <br>\n- [Third-party web app referenced by skill](https://1341839497-jv04655vcs.ap-shanghai.tencentscf.com/) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Guidance, Markdown, Code, Shell commands, Configuration] <br>\n**Output Format:** [Markdown with checklists, code examples, shell commands, and architecture notes] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Non-executable guidance; may include templates and implementation snippets for human review.] <br>\n\n## Skill Version(s): <br>\n1.1.0 (source: server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.0: 3 files, 5370 bytes\n\nFiles: skill-card.md (2186b), SKILL.md (8799b), _meta.json (140b)\n\nFile v1.0.0:SKILL.md\n\n---\nname: china-data-compliance\ndescription: \"Ensure applications comply with Chinese data protection laws (PIPL, Cybersecurity Law, Data Security Law). Teach AI agents how to implement privacy policies, consent management, data localization, cross-border transfer assessment, and security impact assessment. Covers: PIPL compliance checklist, personal information consent flow, data localization implementation, cross-border data transfer assessment, and security impact assessment (网络安全审查). Triggers on: 中国数据合规, china data compliance, 个人信息保护法, PIPL compliance, 网络安全法, cybersecurity law, 数据安全法, data security law, 数据本地化, data localization, 跨境数据传输, cross-border data transfer, 隐私政策, privacy policy china, 个人信息同意, consent management china, 网络安全审查, security assessment china, 数据出境, data export china\"\n---\n\n# China Data Compliance - 中国数据合规专家\n\nYou are an expert at ensuring applications comply with China's three-pillar data protection framework: PIPL (个人信息保护法), Cybersecurity Law (网络安全法), and Data Security Law (数据安全法).\n\n## Core Philosophy\n\n**In China, data compliance is not optional — it's a prerequisite for operating.** Non-compliance can result in service suspension, fines up to ¥50M or 5% of annual revenue, and criminal liability. You help agents build compliance into the architecture, not bolt it on after.\n\n## The Three Laws\n\n| Law | Focus | Key Requirement | Max Penalty |\n|-----|-------|----------------|-------------|\n| PIPL (2021) | Personal information | Consent + purpose limitation | ¥50M or 5% revenue |\n| Cybersecurity Law (2017) | Network security | Security assessment + data localization for CII | ¥1M + suspension |\n| Data Security Law (2021) | Data classification | Classification + cross-border assessment | ¥10M + suspension |\n\n## Workflow 1: PIPL Compliance Checklist\n\n### Step 1: Privacy Policy (隐私政策)\n```markdown\nRequired sections in Chinese privacy policy:\n1. 信息收集范围 (What data you collect)\n2. 使用目的 (Why you collect it)\n3. 共享与披露 (Who you share with)\n4. 存储地点与期限 (Where and how long)\n5. 用户权利 (User rights: access, delete, export)\n6. 未成年人保护 (Under-14 protection)\n7. 跨境传输 (Cross-border transfer, if applicable)\n8. 更新机制 (How you notify changes)\n```\n\n### Step 2: Consent Management\n```javascript\n// PIPL consent flow implementation\nclass PIPLConsent {\n  // Separate consent required for:\n  // 1. Core service data collection\n  // 2. Marketing communications\n  // 3. Third-party sharing\n  // 4. Cross-border transfer\n  // 5. Sensitive personal information (biometrics, health, finance)\n  // 6. Under-14 data (parental consent required)\n\n  async collectConsent({ purpose, dataTypes, isSensitive, isCrossBorder }) {\n    // Each purpose needs SEPARATE consent (not bundled)\n    // Sensitive data needs EXPLICIT consent (not implied)\n    // Cross-border needs SEPARATE consent + security assessment\n    \n    return {\n      consentId: generateId(),\n      purpose,\n      dataTypes,\n      timestamp: Date.now(),\n      version: this.policyVersion,\n      method: isSensitive ? 'explicit' : 'general',\n      withdrawable: true  // Must always be withdrawable\n    };\n  }\n\n  async withdrawConsent(consentId) {\n    // Must stop processing within 15 days\n    // Must delete data within 30 days\n    // Cannot refuse core service if user withdraws non-essential consent\n  }\n}\n```\n\n### Step 3: User Rights Implementation\n```javascript\n// PIPL user rights API\nconst userRights = {\n  // Right to access (查阅权)\n  async exportData(userId) { /* Return all data about user */ },\n  \n  // Right to delete (删除权)\n  async deleteData(userId) { /* Delete within 30 days */ },\n  \n  // Right to correct (更正权)\n  async correctData(userId, field, value) { /* Update personal info */ },\n  \n  // Right to portability (可携带权)\n  async portData(userId) { /* Export in standard format */ },\n  \n  // Right to refuse automated decision (拒绝自动化决策权)\n  async optOutAutomation(userId) { /* Human review available */ },\n  \n  // Right to withdraw consent (撤回同意权)\n  async withdrawConsent(userId) { /* Stop processing, keep minimum */ }\n};\n```\n\n## Workflow 2: Data Localization (数据本地化)\n\n### When Required\n- **Critical Information Infrastructure (CII)** operators: MUST store in China\n- **Personal information handlers**: If processing >1M users or cumulative export >100K users\n- **Important data**: As classified by sector regulators\n\n### Implementation\n```bash\n# Tencent Cloud (China regions)\n# Store data in ap-shanghai or ap-guangzhou\ntccli cos create-bucket --Bucket my-data-cn --Region ap-shanghai\n\n# Alibaba Cloud (China regions)\naliyun oss mb oss://my-data-cn --region cn-shanghai\n\n# Database must be in China region\n# MySQL: ap-shanghai (Tencent) / cn-shanghai (Alibaba)\n# Redis: ap-shanghai (Tencent) / cn-shanghai (Alibaba)\n```\n\n### Architecture Pattern\n```\n[China Users] → [China CDN] → [China Servers (Shanghai)]\n                                    ↓ (replicated, not primary)\n                            [Global Servers (if needed)]\n```\n\n## Workflow 3: Cross-Border Data Transfer Assessment (数据出境安全评估)\n\n### Step 1: Determine if Assessment is Required\n```javascript\nfunction needsAssessment({ userCount, dataTypes, isCII, hasImportantData }) {\n  // Mandatory assessment if ANY of these:\n  if (isCII) return true;  // CII operator\n  if (hasImportantData) return true;  // Important data\n  if (userCount > 1000000) return true;  // >1M users' PI\n  if (dataTypes.includes('sensitive') && userCount > 10000) return true;  // >10K users' sensitive PI\n  if (cumulativeExportUsers > 100000) return true;  // Cumulative >100K users\n  \n  // Otherwise: standard contract or certification may suffice\n  return false;\n}\n```\n\n### Step 2: Assessment Report Template\n```markdown\n# 数据出境安全评估报告\n\n## 1. 出境数据情况\n- 数据类型和数量\n- 接收方信息\n- 传输方式和技术措施\n\n## 2. 合法性基础\n- 同意情况\n- 合同必要性\n- 法定义务\n\n## 3. 风险评估\n- 数据泄露风险\n- 数据滥用风险\n- 接收方法律环境风险\n\n## 4. 保护措施\n- 加密传输\n- 访问控制\n- 审计日志\n\n## 5. 应急预案\n- 数据泄露响应\n- 用户通知机制\n```\n\n## Workflow 4: Security Impact Assessment (网络安全审查)\n\n### When Required\n- Platform operators with >1M users before IPO\n- CII operators purchasing network products/services\n- Data processors affecting national security\n\n### Assessment Process\n```\n1. Self-assessment → 2. Submit to CAC → 3. Initial review (30 days) → 4. Deep review (90 days) → 5. Decision\n```\n\n## Workflow 5: App Privacy Compliance (App隐私合规)\n\n### Pre-Launch Checklist\n- [ ] Privacy policy accessible before registration\n- [ ] Separate consent for each data collection purpose\n- [ ] No forced consent (can use app without non-essential consent)\n- [ ] No background collection without explicit consent\n- [ ] SDK list disclosure (all third-party SDKs)\n- [ ] Under-14 special protection mode\n- [ ] Account deletion function (within 15 days)\n- [ ] Data export function\n- [ ] No unauthorized sharing with third parties\n- [ ] No tracking after uninstall\n\n### Common Rejection Reasons (App Store / Ministry review)\n1. Privacy policy not visible before first use\n2. Collecting data not mentioned in privacy policy\n3. Bundled consent (forcing all-or-nothing)\n4. No account deletion function\n5. Background location/collection without consent\n6. SDK not disclosed in privacy policy\n\n## Safety Rules\n\n1. **Never skip consent** — PIPL requires separate, explicit, informed consent\n2. **Data minimization** — only collect what you need, delete when purpose is fulfilled\n3. **China storage first** — default to China regions for Chinese user data\n4. **Document everything** — keep consent records, assessment reports, audit logs\n5. **Regular review** — laws update frequently; review compliance quarterly\n6. **Legal counsel** — this skill provides technical guidance, not legal advice; always consult a China data lawyer for production systems\n\n## Quick Reference\n\n| Requirement | Threshold | Action |\n|-------------|-----------|--------|\n| Data localization | CII operator | Store all data in China |\n| Cross-border assessment | >1M users PI | Submit to CAC |\n| Security assessment | Pre-IPO >1M users | Submit to CAC |\n| Privacy policy | All apps | Required before first use |\n| Consent management | All PI processing | Separate per purpose |\n| Account deletion | All apps | Must provide within 15 days |\n| Under-14 protection | All apps with minor users | Parental consent + special mode |\n\nFile v1.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn7a6kxswmnbamxxthy2pgjrkn86vpfy\",\n  \"slug\": \"china-data-compliance\",\n  \"version\": \"1.0.0\",\n  \"publishedAt\": 1779787979857\n}\n\nFile v1.0.0:skill-card.md\n\n## Description: <br>\nHelps agents plan China data compliance workflows for PIPL, Cybersecurity Law, and Data Security Law, including privacy notices, consent handling, data localization, cross-border transfer checks, security assessments, and app privacy launch checks. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[lm203688](https://clawhub.ai/user/lm203688) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers, product teams, and compliance reviewers use this skill to have an agent produce checklists, implementation sketches, and assessment templates for applications that process Chinese user data. <br>\n\n### Deployment Geography for Use: <br>\nChina and cross-border deployments involving data from China <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Legal thresholds, timelines, and regulator expectations may change or may not fit a specific organization. <br>\nMitigation: Verify the guidance against current Chinese law and qualified counsel before using it for production compliance decisions. <br>\nRisk: Generated implementation snippets and cloud-region examples may be incomplete for a real compliance program. <br>\nMitigation: Treat snippets as starting points and review consent records, data residency, audit logging, and user-rights workflows before deployment. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/lm203688/china-data-compliance) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [guidance, markdown, code, shell commands, configuration] <br>\n**Output Format:** [Markdown guidance with checklist tables and JavaScript or shell snippets] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Documentation-only guidance; implementation snippets should be reviewed before production use.] <br>\n\n## Skill Version(s): <br>\n1.0.0 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>","readmeExcerpt":"Skill: china-data-compliance Owner: lm203688 Summary: Ensure applications comply with Chinese data protection laws (PIPL, Cybersecurity Law, Data Security Law). Teach AI agents how to implement privacy policies,... Tags: PIPL:2.3.0, agent:1.0.0, china:2.3.0, chinese:1.1.0, compliance:2.3.0, consent:1.0.0, cybersecurity:2.3.0, data-privacy:1.1.0, data-protection:2.3.0, latest:2.3.0, legal:1.0.0, localization:1.0.0, pi","codeSnippets":[],"executableExamples":[{"language":"markdown","snippet":"Required sections in Chinese privacy policy:\n1. 信息收集范围 (What data you collect)\n2. 使用目的 (Why you collect it)\n3. 共享与披露 (Who you share with)\n4. 存储地点与期限 (Where and how long)\n5. 用户权利 (User rights: access, delete, export)\n6. 未成年人保护 (Under-14 protection)\n7. 跨境传输 (Cross-border transfer, if applicable)\n8. 更新机制 (How you notify changes)"},{"language":"javascript","snippet":"// PIPL consent flow implementation\nclass PIPLConsent {\n  // Separate consent required for:\n  // 1. Core service data collection\n  // 2. Marketing communications\n  // 3. Third-party sharing\n  // 4. Cross-border transfer\n  // 5. Sensitive personal information (biometrics, health, finance)\n  // 6. Under-14 data (parental consent required)\n\n  async collectConsent({ purpose, dataTypes, isSensitive, isCrossBorder }) {\n    // Each purpose needs SEPARATE consent (not bundled)\n    // Sensitive data needs EXPLICIT consent (not implied)\n    // Cross-border needs SEPARATE consent + security assessment\n    \n    return {\n      consentId: generateId(),\n      purpose,\n      dataTypes,\n      timestamp: Date.now(),\n      version: this.policyVersion,\n      method: isSensitive ? 'explicit' : 'general',\n      withdrawable: true  // Must always be withdrawable\n    };\n  }\n\n  async withdrawConsent(consentId) {\n    // Must stop processing within 15 days\n    // Must delete data within 30 days\n    // Cannot refuse core service if user withdraws non-essential consent\n  }\n}"},{"language":"javascript","snippet":"// PIPL user rights API\nconst userRights = {\n  // Right to access (查阅权)\n  async exportData(userId) { /* Return all data about user */ },\n  \n  // Right to delete (删除权)\n  async deleteData(userId) { /* Delete within 30 days */ },\n  \n  // Right to correct (更正权)\n  async correctData(userId, field, value) { /* Update personal info */ },\n  \n  // Right to portability (可携带权)\n  async portData(userId) { /* Export in standard format */ },\n  \n  // Right to refuse automated decision (拒绝自动化决策权)\n  async optOutAutomation(userId) { /* Human review available */ },\n  \n  // Right to withdraw consent (撤回同意权)\n  async withdrawConsent(userId) { /* Stop processing, keep minimum */ }\n};"},{"language":"bash","snippet":"# Tencent Cloud (China regions)\n# Store data in ap-shanghai or ap-guangzhou\ntccli cos create-bucket --Bucket my-data-cn --Region ap-shanghai\n\n# Alibaba Cloud (China regions)\naliyun oss mb oss://my-data-cn --region cn-shanghai\n\n# Database must be in China region\n# MySQL: ap-shanghai (Tencent) / cn-shanghai (Alibaba)\n# Redis: ap-shanghai (Tencent) / cn-shanghai (Alibaba)"},{"language":"text","snippet":"[China Users] → [China CDN] → [China Servers (Shanghai)]\n                                    ↓ (replicated, not primary)\n                            [Global Servers (if needed)]"},{"language":"javascript","snippet":"function needsAssessment({ userCount, dataTypes, isCII, hasImportantData }) {\n  // Mandatory assessment if ANY of these:\n  if (isCII) return true;  // CII operator\n  if (hasImportantData) return true;  // Important data\n  if (userCount > 1000000) return true;  // >1M users' PI\n  if (dataTypes.includes('sensitive') && userCount > 10000) return true;  // >10K users' sensitive PI\n  if (cumulativeExportUsers > 100000) return true;  // Cumulative >100K users\n  \n  // Otherwise: standard contract or certification may suffice\n  return false;\n}"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: china-data-compliance\ndescription: \"Ensure applications comply with Chinese data protection laws (PIPL, Cybersecurity Law, Data Security Law). Teach AI agents how to implement privacy policies, consent management, data localization, cross-border transfer assessment, and security impact assessment. Covers: PIPL compliance checklist, personal information consent flow, data localization implementation, cross-border data transfer assessment, and security impact assessment (网络安全审查). Triggers on: 中国数据合规, china data compliance, 个人信息保护法, PIPL compliance, 网络安全法, cybersecurity law, 数据安全法, data security law, 数据本地化, data localization, 跨境数据传输, cross-border data transfer, 隐私政策, privacy policy china, 个人信息同意, consent management china, 网络安全审查, security assessment china, 数据出境, data export china\"\nversion: \"2.3.0\"\nlicense: MIT-0\ncompatibility: \"Claude Code, Cursor, Windsurf, Codex CLI, Gemini CLI, OpenClaw, Kimi Code, Qwen Code, Aider, Amp\"\nhomepage: \"https://github.com/lm203688/china-compliance-skills-mirror\"\nwhen_to_use: \"Use when building applications for Chinese users that collect personal information, store data, or transfer data across borders. Also for PIPL合规, 数据出境评估, 隐私政策, 数据本地化, 网络安全审查, GDPR+PIPL dual compliance, or any China data protection question.\"\nargument-hint: \"<app description or data flow> [compliance scope: pipl|cybersecurity|data-security|all]\"\n---\n\n# China Data Compliance - 中国数据合规专家\n\nYou are an expert at ensuring applications comply with China's three-pillar data protection framework: PIPL (个人信息保护法), Cybersecurity Law (网络安全法), and Data Security Law (数据安全法).\n\n## Core Philosophy\n\n**In China, data compliance is not optional — it's a prerequisite for operating.** Non-compliance can result in service suspension, fines up to ¥50M or 5% of annual revenue, and criminal liability. You help agents build compliance into the architecture, not bolt it on after.\n\n## The Three Laws\n\n| Law | Focus | Key Requirement | Max Penalty |\n|-----|-------|----------------|-------------|\n| PIPL (2021) | Personal information | Consent + purpose limitation | ¥50M or 5% revenue |\n| Cybersecurity Law (2017) | Network security | Security assessment + data localization for CII | ¥1M + suspension |\n| Data Security Law (2021) | Data classification | Classification + cross-border assessment | ¥10M + suspension |\n\n## Workflow 1: PIPL Compliance Checklist\n\n### Step 1: Privacy Policy (隐私政策)\n```markdown\nRequired sections in Chinese privacy policy:\n1. 信息收集范围 (What data you collect)\n2. 使用目的 (Why you collect it)\n3. 共享与披露 (Who you share with)\n4. 存储地点与期限 (Where and how long)\n5. 用户权利 (User rights: access, delete, export)\n6. 未成年人保护 (Under-14 protection)\n7. 跨境传输 (Cross-border transfer, if applicable)\n8. 更新机制 (How you notify changes)\n```\n\n### Step 2: Consent Management\n```javascript\n// PIPL consent flow implementation\nclass PIPLConsent {\n  // Separate consent required for:\n  // 1. Core service data collection\n  // 2. Marketing communications\n  // 3. Third-party sharing\n  // 4. Cross-"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7a6kxswmnbamxxthy2pgjrkn86vpfy\",\n  \"slug\": \"china-data-compliance\",\n  \"version\": \"2.3.0\",\n  \"publishedAt\": 1779977704222\n}"},{"path":"skill-card.md","content":"## Description:\n\nEnsure applications comply with Chinese data protection laws, including PIPL, Cybersecurity Law, and Data Security Law, by guiding privacy policies, consent management, data localization, cross-border transfer assessment, and security impact assessment.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[lm203688](https://clawhub.ai/user/lm203688)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and compliance engineers use this skill when building applications for Chinese users that collect personal information, store data, or transfer data across borders. It helps agents draft implementation guidance, checklists, data-flow assessments, and technical patterns for China data compliance.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill promotes an external commercial web app that may receive compliance content without clear data-handling disclosure.\n\nMitigation: Do not paste sensitive policy drafts, business data, personal information, or regulated content into the external app unless its operator, terms, and data handling have been independently reviewed.\n\nRisk: Legal thresholds and cloud-region commands may become outdated or may not match a specific deployment context.\n\nMitigation: Treat the guidance as a starting point and require current legal, security, and infrastructure review before using it for production compliance decisions.\n\n## Reference(s):\n\n- [ClawHub skill listing](https://clawhub.ai/lm203688/skills/china-data-compliance)\n- [China Compliance Skills repository](https://github.com/lm203688/china-compliance-skills-mirror)\n- [cn-seo-optimizer related skill](https://github.com/lm203688/china-compliance-skills-mirror/tree/main/skills/cn-seo-optimizer)\n- [cn-geo-monitor related skill](https://github.com/lm203688/china-compliance-skills-mirror/tree/main/skills/cn-geo-monitor)\n\n## Skill Output:\n\n**Output Type(s):** [Markdown, Code, Shell commands, Configuration, Guidance]\n\n**Output Format:** [Markdown with checklists, tables, code snippets, shell commands, and architecture notes]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May include legal and infrastructure compliance guidance that requires current professional review before production use.]\n\n## Skill Version(s):\n\n2.3.0 (source: frontmatter and server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Ensure applications comply with Chinese data protection laws (PIPL, Cybersecurity Law, Data Security Law). Teach AI agents how to implement privacy policies,... Skill: china-data-compliance Owner: lm203688 Summary: Ensure applications comply with Chinese data protection laws (PIPL, Cybersecurity Law, Data Security Law). Teach AI agents how to implement privacy policies,... Tags: PIPL:2.3.0, agent:1.0.0, china:2.3.0, chinese:1.1.0, compliance:2.3.0, consent:1.0.0, cybersecurity:2.3.0, data-privacy:1.1.0, data-protection:2.3.0, latest:2.3.0, legal:1.0.0, localization:1.0.0, pi","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1059,"uniquenessScore":49,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-11T08:28:33.267Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-11T08:28:33.267Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-11T10:52:20.370Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}