Regulatory Audit Generator — Business Scenario Compliance Checklist Builder
Identifies applicable laws and regulations based on the user's business scenario description, and outputs a structured compliance checklist covering major regulations such as GDPR, PIPL (Personal Information Protection Law), Advertising Law, Cybersecurity Law, and Data Security Law.
Quick Start
Users simply describe their business scenario, and the Agent will:
- Identify applicable regulations: Determine which laws and regulations apply based on the business scenario
- Generate a checklist: Output a structured list of check items
- Label risk levels: Prioritize by severity, marking high/medium/low risk
- Provide remediation recommendations: Offer actionable remediation guidance for each compliance risk
Users just need to say:
"We're launching a user profiling feature — help me create a compliance checklist."
The Agent will guide the user to provide necessary information, then output a complete compliance checklist.
1. Supported Regulatory Frameworks
Core Regulations
| Regulation |
Abbreviation |
Scope |
Key Focus Areas |
| Personal Information Protection Law |
PIPL |
Processing personal information within China |
Informed consent, data minimization, cross-border data transfer |
| General Data Protection Regulation |
GDPR |
Involving EU user data |
Lawful basis, data subject rights, DPO, DPIA |
| Data Security Law |
DSL |
Data processing activities within China |
Data classification & grading, security assessment, important data export |
| Cybersecurity Law |
CSL |
Network operators |
Multi-Level Protection Scheme (MLPS), log retention, security incident reporting |
| Advertising Law |
— |
Advertising publishing and operations |
Prohibited superlative claims, false advertising, medical advertising |
| E-Commerce Law |
— |
E-commerce operators |
Information disclosure, user reviews, bundled sales |
| Anti-Unfair Competition Law |
— |
Market business activities |
Commercial bribery, false advertising, trade secret infringement |
| Consumer Protection Law |
— |
Consumer rights related |
Right to know, fair trade rights, personal information |
Industry-Specific Regulations
| Industry |
Relevant Regulations / Standards |
| Finance |
Technical Specification for Personal Financial Information Protection (JR/T 0171), Data Security Management Measures for Banking and Insurance Institutions |
| Healthcare |
Population Health Information Management Measures, Medical Big Data Standards |
| Education |
Online Protection Chapter of the Minors Protection Law, Provisions on Protection of Children's Personal Information Online |
| Automotive |
Several Provisions on Automobile Data Security Management |
| Mobile Apps |
Methods for Identifying Illegal Collection and Use of Personal Information by Apps, Provisions on the Scope of Necessary Personal Information for Common Types of Mobile Applications |
2. Compliance Check Procedure (SOP)
Step 1: Gather Business Scenario Information
Confirm the following key information with the user:
| Dimension |
Information to Confirm |
Example |
| Business Description |
Specific content of the feature/service |
"User profiling feature that recommends products based on behavioral data" |
| User Group |
Geographic region and demographics of target audience |
"Mainland China users, including minors" |
| Data Types |
What data is collected/processed |
"Name, phone number, browsing history, location data" |
| Data Flow |
Data storage, transmission, and sharing details |
"Stored on Alibaba Cloud East China nodes, shared with third-party ad platforms" |
| Business Stage |
New launch / existing system needing remediation / M&A due diligence |
"New feature, planned for launch next month" |
| Existing Measures |
Current compliance measures already in place |
"Has a privacy policy, but no DPIA completed" |
If the user has not provided certain information, the Agent should proactively ask follow-up questions rather than assume or skip.
Step 2: Identify Applicable Regulations
Based on collected information, determine applicable regulations using the following rules:
IF processing personal information → PIPL
IF involving EU users → GDPR
IF involving data storage/transmission → Data Security Law + Cybersecurity Law
IF involving advertising/marketing content → Advertising Law
IF involving e-commerce transactions → E-Commerce Law
IF involving minors → Minors Protection Law + Provisions on Protection of Children's Personal Information Online
IF cross-border data transfer (overseas storage/transmission/access) → PIPL Chapter 3 + Measures for Security Assessment of Data Export
IF involving sensitive personal information → PIPL Chapter 2 Section 2 (separate consent + PIIA)
IF involving automated decision-making → PIPL Article 24 (transparency + right to refuse)
IF involving financial data → JR/T 0171
Step 3: Generate the Compliance Checklist
Output the checklist in the following structure:
Checklist Output Format
# [Business Scenario Name] Compliance Checklist
**Assessment Date**: YYYY-MM-DD
**Business Description**: [Brief description]
**Applicable Regulations**: [List of regulations]
## Checklist
| No. | Check Item | Legal Basis | Risk Level | Current Status | Remediation Advice |
|-----|-----------|-------------|------------|----------------|-------------------|
| 1 | [Check item description] | [Regulation name + article number] | High/Medium/Low | Compliant/Non-compliant/To be confirmed | [Specific advice] |
## Risk Summary
- High-risk items: X items
- Medium-risk items: X items
- Low-risk items: X items
## Priority Remediation Recommendations
1. [Highest priority remediation item and rationale]
2. [Second highest priority item and rationale]
Step 4: Output Remediation Priorities
Prioritize remediation actions according to the following rules:
| Priority |
Criteria |
Description |
| P0 — Immediate Action |
High risk + currently non-compliant |
May face administrative penalties, service shutdown |
| P1 — Complete This Week |
High risk + to be confirmed, or medium risk + non-compliant |
Significant compliance exposure |
| P2 — Complete This Month |
Medium risk + to be confirmed |
Requires further assessment and improvement |
| P3 — Ongoing Optimization |
Low risk |
Recommended improvement but not urgent |
3. Common Business Scenario Check Points
Scenario 1: User Registration and Login
| Check Item |
Legal Basis |
Description |
| Is there a privacy policy / user agreement? |
PIPL Art. 17 |
Must be displayed and consent obtained before registration |
| Is only necessary personal information collected? |
PIPL Art. 6 |
Registration stage should only require phone number/email; should not mandate ID numbers, etc. |
| Does third-party login disclose data sharing? |
PIPL Art. 23 |
Login via WeChat/Alipay must disclose what information is shared |
| Are passwords stored encrypted? |
CSL Art. 21 |
Plaintext password storage is prohibited |
| Is account deletion supported? |
PIPL Art. 47 |
A convenient account deletion channel must be provided |
Scenario 2: Marketing and Advertising
| Check Item |
Legal Basis |
Description |
| Is consent obtained for marketing SMS/emails? |
PIPL Art. 13, Advertising Law Art. 43 |
Explicit user consent is required |
| Is an unsubscribe mechanism provided? |
Advertising Law Art. 43 |
Each marketing message must include an opt-out method |
| Does ad copy contain prohibited superlative terms? |
Advertising Law Art. 9 |
Absolute terms like "best," "number one," "national-level" are prohibited |
| Can profiling-based recommendations be disabled? |
PIPL Art. 24 |
An option for non-personalized content must be provided |
| Are advertisements clearly labeled as "Ad"? |
Advertising Law Art. 14 |
Mass media channels must clearly mark advertisements |
Scenario 3: Cross-Border Data Transfer
| Check Item |
Legal Basis |
Description |
| Does it meet the security assessment filing threshold? |
Measures for Security Assessment of Data Export Art. 4 |
Processing personal information of 1M+ individuals, or cumulative export of 100K individuals / 10K sensitive records |
| Has the standard contract been signed? |
Standard Contract Measures for Personal Information Export |
Can sign the standard contract if below the filing threshold |
| Has a Personal Information Protection Impact Assessment been completed? |
PIPL Art. 55 |
PIIA must be completed before data export |
| Has the user been informed and separate consent obtained? |
PIPL Art. 39 |
Must disclose overseas recipient information |
| Overseas recipient's data protection capability |
PIPL Art. 38 |
Must assess the recipient's data protection standards |
Scenario 4: User Profiling and Personalized Recommendations
| Check Item |
Legal Basis |
Description |
| Is the automated decision-making logic disclosed? |
PIPL Art. 24 |
Must be transparent to users |
| Is an option to disable personalized recommendations provided? |
PIPL Art. 24 |
Users have the right to refuse |
| Has a PIIA been conducted for user profiling? |
PIPL Art. 55 |
Assessment is required when using personal information for automated decision-making |
| Do profiling tags involve sensitive information? |
PIPL Art. 28 |
Tags related to religion, health, finance, etc. are classified as sensitive information |
| Is the use scope of profiling results restricted? |
PIPL Art. 24 |
Must not impose unreasonable differential treatment in areas such as transaction pricing |
Scenario 5: GDPR Compliance (for EU Users)
| Check Item |
Legal Basis |
Description |
| Has a lawful basis for processing been established? |
GDPR Art. 6 |
One of six bases: consent, contract, legal obligation, legitimate interest, etc. |
| Has a DPO been appointed? |
GDPR Art. 37 |
Required for large-scale processing or processing of special category data |
| Has a DPIA been completed? |
GDPR Art. 35 |
Required for high-risk processing activities |
| Is the right to data portability supported? |
GDPR Art. 20 |
Data must be provided in a structured, machine-readable format |
| Can data breaches be reported within 72 hours? |
GDPR Art. 33 |
Supervisory authority must be notified within 72 hours of discovering a breach |
| Is the cookie banner compliant? |
GDPR + ePrivacy |
Active consent required; pre-checked boxes are not permitted |
| Are records of processing activities maintained? |
GDPR Art. 30 |
Required for organizations with 250+ employees or non-occasional processing |
4. Risk Level Criteria
| Risk Level |
Criteria |
Potential Consequences |
| High |
Violation of mandatory legal provisions; unlawful processing of sensitive personal information; lack of lawful basis; data export without assessment |
Administrative penalties (fines), service shutdown, criminal liability |
| Medium |
Compliance measures incomplete but foundational; insufficient notice; flawed consent mechanism; partial security measure gaps |
Regulatory interview, ordered remediation within deadline, user complaints |
| Low |
Best practices not met but not unlawful; incomplete documentation; processes can be optimized |
Audit findings, internal improvements |
5. Deliverables
The Agent should ultimately deliver the following to the user:
- Compliance Checklist Table: All check items with legal basis, risk levels, current status, and remediation advice
- Risk Summary: Count of high/medium/low risk items
- Priority Remediation Roadmap: Remediation action list ordered by P0–P3
- Supplementary Notes: Plain-language explanations of key compliance requirements to help non-legal staff understand
6. Disclaimers
- Regulatory Currency: Laws and regulations are continuously updated. Regulation references in the checklist should be verified against the latest versions. The Agent should remind users to check for the most recent regulatory developments.
- Not Legal Advice: This checklist is for reference only and does not constitute legal advice. For significant compliance decisions, consultation with a qualified attorney is recommended.
- Industry Variations: Different industries have specific regulatory requirements. The checklist should be adapted to account for industry-specific considerations.
- Ongoing Compliance: Compliance is not a one-time effort. Regular reassessment (at least every six months) is recommended.
References
- Personal Information Protection Law of the People's Republic of China (PIPL, 2021)
- Data Security Law of the People's Republic of China (DSL, 2021)
- Cybersecurity Law of the People's Republic of China (CSL, 2017)
- Advertising Law of the People's Republic of China (2018 Amendment)
- EU General Data Protection Regulation (GDPR, 2018)
- Measures for Standard Contracts for Personal Information Export (2023)
- Measures for Security Assessment of Data Export (2022)
- GB/T 35273-2020 Information Security Technology — Personal Information Security Specification
1---2name: regulatory-audit-generator3description: Builds compliance checklists for business scenarios involving GDPR, PIPL, or advertising/data laws. Outputs a structured checklist with check items, legal basis, risk levels, and actionable recommendations. Triggered by requests like "run a compliance check," "GDPR/PIPL compliance," "pre-launch review," "privacy impact assessment (PIA/DPIA)," or asking if a feature is compliant.4license: MIT5---6
7# Regulatory Audit Generator — Business Scenario Compliance Checklist Builder
8
9Identifies applicable laws and regulations based on the user's business scenario description, and outputs a structured compliance checklist covering major regulations such as GDPR, PIPL (Personal Information Protection Law), Advertising Law, Cybersecurity Law, and Data Security Law.
10
11## Quick Start
12
13Users simply describe their business scenario, and the Agent will:
14
151. **Identify applicable regulations**: Determine which laws and regulations apply based on the business scenario
162. **Generate a checklist**: Output a structured list of check items
173. **Label risk levels**: Prioritize by severity, marking high/medium/low risk
184. **Provide remediation recommendations**: Offer actionable remediation guidance for each compliance risk
19
20Users just need to say:
21> "We're launching a user profiling feature — help me create a compliance checklist."
22
23The Agent will guide the user to provide necessary information, then output a complete compliance checklist.
24
25---
26
27## 1. Supported Regulatory Frameworks
28
29### Core Regulations
30
31| Regulation | Abbreviation | Scope | Key Focus Areas |
32|------------|-------------|-------|-----------------|
33| Personal Information Protection Law | PIPL | Processing personal information within China | Informed consent, data minimization, cross-border data transfer |
34| General Data Protection Regulation | GDPR | Involving EU user data | Lawful basis, data subject rights, DPO, DPIA |
35| Data Security Law | DSL | Data processing activities within China | Data classification & grading, security assessment, important data export |
36| Cybersecurity Law | CSL | Network operators | Multi-Level Protection Scheme (MLPS), log retention, security incident reporting |
37| Advertising Law | — | Advertising publishing and operations | Prohibited superlative claims, false advertising, medical advertising |
38| E-Commerce Law | — | E-commerce operators | Information disclosure, user reviews, bundled sales |
39| Anti-Unfair Competition Law | — | Market business activities | Commercial bribery, false advertising, trade secret infringement |
40| Consumer Protection Law | — | Consumer rights related | Right to know, fair trade rights, personal information |
41
42### Industry-Specific Regulations
43
44| Industry | Relevant Regulations / Standards |
45|----------|--------------------------------|
46| Finance | Technical Specification for Personal Financial Information Protection (JR/T 0171), Data Security Management Measures for Banking and Insurance Institutions |
47| Healthcare | Population Health Information Management Measures, Medical Big Data Standards |
48| Education | Online Protection Chapter of the Minors Protection Law, Provisions on Protection of Children's Personal Information Online |
49| Automotive | Several Provisions on Automobile Data Security Management |
50| Mobile Apps | Methods for Identifying Illegal Collection and Use of Personal Information by Apps, Provisions on the Scope of Necessary Personal Information for Common Types of Mobile Applications |
51
52---
53
54## 2. Compliance Check Procedure (SOP)
55
56### Step 1: Gather Business Scenario Information
57
58Confirm the following key information with the user:
59
60| Dimension | Information to Confirm | Example |
61|-----------|----------------------|---------|
62| Business Description | Specific content of the feature/service | "User profiling feature that recommends products based on behavioral data" |
63| User Group | Geographic region and demographics of target audience | "Mainland China users, including minors" |
64| Data Types | What data is collected/processed | "Name, phone number, browsing history, location data" |
65| Data Flow | Data storage, transmission, and sharing details | "Stored on Alibaba Cloud East China nodes, shared with third-party ad platforms" |
66| Business Stage | New launch / existing system needing remediation / M&A due diligence | "New feature, planned for launch next month" |
67| Existing Measures | Current compliance measures already in place | "Has a privacy policy, but no DPIA completed" |
68
69**If the user has not provided certain information, the Agent should proactively ask follow-up questions rather than assume or skip.**
70
71### Step 2: Identify Applicable Regulations
72
73Based on collected information, determine applicable regulations using the following rules:
74
75```
76IF processing personal information → PIPL
77IF involving EU users → GDPR
78IF involving data storage/transmission → Data Security Law + Cybersecurity Law
79IF involving advertising/marketing content → Advertising Law
80IF involving e-commerce transactions → E-Commerce Law
81IF involving minors → Minors Protection Law + Provisions on Protection of Children's Personal Information Online
82IF cross-border data transfer (overseas storage/transmission/access) → PIPL Chapter 3 + Measures for Security Assessment of Data Export
83IF involving sensitive personal information → PIPL Chapter 2 Section 2 (separate consent + PIIA)
84IF involving automated decision-making → PIPL Article 24 (transparency + right to refuse)
85IF involving financial data → JR/T 0171
86```
87
88### Step 3: Generate the Compliance Checklist
89
90Output the checklist in the following structure:
91
92#### Checklist Output Format
93
94```markdown
95# [Business Scenario Name] Compliance Checklist
96
97**Assessment Date**: YYYY-MM-DD
98**Business Description**: [Brief description]
99**Applicable Regulations**: [List of regulations]
100
101## Checklist
102
103| No. | Check Item | Legal Basis | Risk Level | Current Status | Remediation Advice |
104|-----|-----------|-------------|------------|----------------|-------------------|
105| 1 | [Check item description] | [Regulation name + article number] | High/Medium/Low | Compliant/Non-compliant/To be confirmed | [Specific advice] |
106
107## Risk Summary
108
109- High-risk items: X items
110- Medium-risk items: X items
111- Low-risk items: X items
112
113## Priority Remediation Recommendations
114
1151. [Highest priority remediation item and rationale]
1162. [Second highest priority item and rationale]
117```
118
119### Step 4: Output Remediation Priorities
120
121Prioritize remediation actions according to the following rules:
122
123| Priority | Criteria | Description |
124|----------|----------|-------------|
125| P0 — Immediate Action | High risk + currently non-compliant | May face administrative penalties, service shutdown |
126| P1 — Complete This Week | High risk + to be confirmed, or medium risk + non-compliant | Significant compliance exposure |
127| P2 — Complete This Month | Medium risk + to be confirmed | Requires further assessment and improvement |
128| P3 — Ongoing Optimization | Low risk | Recommended improvement but not urgent |
129
130---
131
132## 3. Common Business Scenario Check Points
133
134### Scenario 1: User Registration and Login
135
136| Check Item | Legal Basis | Description |
137|-----------|-------------|-------------|
138| Is there a privacy policy / user agreement? | PIPL Art. 17 | Must be displayed and consent obtained before registration |
139| Is only necessary personal information collected? | PIPL Art. 6 | Registration stage should only require phone number/email; should not mandate ID numbers, etc. |
140| Does third-party login disclose data sharing? | PIPL Art. 23 | Login via WeChat/Alipay must disclose what information is shared |
141| Are passwords stored encrypted? | CSL Art. 21 | Plaintext password storage is prohibited |
142| Is account deletion supported? | PIPL Art. 47 | A convenient account deletion channel must be provided |
143
144### Scenario 2: Marketing and Advertising
145
146| Check Item | Legal Basis | Description |
147|-----------|-------------|-------------|
148| Is consent obtained for marketing SMS/emails? | PIPL Art. 13, Advertising Law Art. 43 | Explicit user consent is required |
149| Is an unsubscribe mechanism provided? | Advertising Law Art. 43 | Each marketing message must include an opt-out method |
150| Does ad copy contain prohibited superlative terms? | Advertising Law Art. 9 | Absolute terms like "best," "number one," "national-level" are prohibited |
151| Can profiling-based recommendations be disabled? | PIPL Art. 24 | An option for non-personalized content must be provided |
152| Are advertisements clearly labeled as "Ad"? | Advertising Law Art. 14 | Mass media channels must clearly mark advertisements |
153
154### Scenario 3: Cross-Border Data Transfer
155
156| Check Item | Legal Basis | Description |
157|-----------|-------------|-------------|
158| Does it meet the security assessment filing threshold? | Measures for Security Assessment of Data Export Art. 4 | Processing personal information of 1M+ individuals, or cumulative export of 100K individuals / 10K sensitive records |
159| Has the standard contract been signed? | Standard Contract Measures for Personal Information Export | Can sign the standard contract if below the filing threshold |
160| Has a Personal Information Protection Impact Assessment been completed? | PIPL Art. 55 | PIIA must be completed before data export |
161| Has the user been informed and separate consent obtained? | PIPL Art. 39 | Must disclose overseas recipient information |
162| Overseas recipient's data protection capability | PIPL Art. 38 | Must assess the recipient's data protection standards |
163
164### Scenario 4: User Profiling and Personalized Recommendations
165
166| Check Item | Legal Basis | Description |
167|-----------|-------------|-------------|
168| Is the automated decision-making logic disclosed? | PIPL Art. 24 | Must be transparent to users |
169| Is an option to disable personalized recommendations provided? | PIPL Art. 24 | Users have the right to refuse |
170| Has a PIIA been conducted for user profiling? | PIPL Art. 55 | Assessment is required when using personal information for automated decision-making |
171| Do profiling tags involve sensitive information? | PIPL Art. 28 | Tags related to religion, health, finance, etc. are classified as sensitive information |
172| Is the use scope of profiling results restricted? | PIPL Art. 24 | Must not impose unreasonable differential treatment in areas such as transaction pricing |
173
174### Scenario 5: GDPR Compliance (for EU Users)
175
176| Check Item | Legal Basis | Description |
177|-----------|-------------|-------------|
178| Has a lawful basis for processing been established? | GDPR Art. 6 | One of six bases: consent, contract, legal obligation, legitimate interest, etc. |
179| Has a DPO been appointed? | GDPR Art. 37 | Required for large-scale processing or processing of special category data |
180| Has a DPIA been completed? | GDPR Art. 35 | Required for high-risk processing activities |
181| Is the right to data portability supported? | GDPR Art. 20 | Data must be provided in a structured, machine-readable format |
182| Can data breaches be reported within 72 hours? | GDPR Art. 33 | Supervisory authority must be notified within 72 hours of discovering a breach |
183| Is the cookie banner compliant? | GDPR + ePrivacy | Active consent required; pre-checked boxes are not permitted |
184| Are records of processing activities maintained? | GDPR Art. 30 | Required for organizations with 250+ employees or non-occasional processing |
185
186---
187
188## 4. Risk Level Criteria
189
190| Risk Level | Criteria | Potential Consequences |
191|-----------|----------|----------------------|
192| High | Violation of mandatory legal provisions; unlawful processing of sensitive personal information; lack of lawful basis; data export without assessment | Administrative penalties (fines), service shutdown, criminal liability |
193| Medium | Compliance measures incomplete but foundational; insufficient notice; flawed consent mechanism; partial security measure gaps | Regulatory interview, ordered remediation within deadline, user complaints |
194| Low | Best practices not met but not unlawful; incomplete documentation; processes can be optimized | Audit findings, internal improvements |
195
196---
197
198## 5. Deliverables
199
200The Agent should ultimately deliver the following to the user:
201
2021. **Compliance Checklist Table**: All check items with legal basis, risk levels, current status, and remediation advice
2032. **Risk Summary**: Count of high/medium/low risk items
2043. **Priority Remediation Roadmap**: Remediation action list ordered by P0–P3
2054. **Supplementary Notes**: Plain-language explanations of key compliance requirements to help non-legal staff understand
206
207---
208
209## 6. Disclaimers
210
2111. **Regulatory Currency**: Laws and regulations are continuously updated. Regulation references in the checklist should be verified against the latest versions. The Agent should remind users to check for the most recent regulatory developments.
2122. **Not Legal Advice**: This checklist is for reference only and does not constitute legal advice. For significant compliance decisions, consultation with a qualified attorney is recommended.
2133. **Industry Variations**: Different industries have specific regulatory requirements. The checklist should be adapted to account for industry-specific considerations.
2144. **Ongoing Compliance**: Compliance is not a one-time effort. Regular reassessment (at least every six months) is recommended.
215
216---
217
218## References
219
220- Personal Information Protection Law of the People's Republic of China (PIPL, 2021)
221- Data Security Law of the People's Republic of China (DSL, 2021)
222- Cybersecurity Law of the People's Republic of China (CSL, 2017)
223- Advertising Law of the People's Republic of China (2018 Amendment)
224- EU General Data Protection Regulation (GDPR, 2018)
225- Measures for Standard Contracts for Personal Information Export (2023)
226- Measures for Security Assessment of Data Export (2022)
227- GB/T 35273-2020 Information Security Technology — Personal Information Security Specification