In China's increasingly stringent data protection legal environment, building an efficient data compliance team has shifted from an "option" to a "necessity." The parallel regulatory framework of the Personal Information Protection Law, the Data Security Law, and the Cybersecurity Law, coupled with the significantly increased penalties under the 2026 Cybersecurity Law amendment, requires enterprises to possess systematic compliance capabilities rather than relying solely on a single compliance officer. However, there is no one-size-fits-all template for building a compliance team. Enterprises need to design the most suitable organizational structure based on their scale, industry attributes, data processing complexity, and risk levels. This article will provide data compliance team building solutions and operational model references for enterprises of different sizes.
Lean Configuration for Small Businesses
For small businesses processing personal information of no more than 1 million individuals (typically with fewer than 200 employees), the cost-effectiveness of establishing an independent compliance department is generally low. It is recommended to adopt a streamlined configuration model: appoint a part-time compliance officer, often concurrently held by the legal manager, IT head, or administrative director. This officer should have a basic understanding of China’s three data protection laws, be capable of identifying major compliance risks, and implementing fundamental compliance measures. On this basis, external legal advisors (such as law firm data compliance teams) should be engaged to provide professional support for tasks requiring specialized expertise, such as drafting privacy policies, conducting compliance reviews, and assessing cross-border data transfers. Typical service models for external advisors include project-based fees and annual legal retainer arrangements, with annual retainer fees typically ranging from 100,000 to 300,000 RMB. Small businesses should also consider adopting compliance management SaaS tools to enhance efficiency and reduce reliance on human resources.
Core team of a medium-sized enterprise
- ›Dedicated DPO / Personal Information Protection Officer (1 person): Full-time responsibility for building and maintaining the PIPL compliance system, completing PIPO filings, managing data subject rights requests, and conducting privacy impact assessments. ---ITEM--- Security Engineering Team (2-3 people): Responsible for cybersecurity protection, technical implementation of security compliance, and monitoring and responding to security incidents. At least one member should possess qualifications related to security compliance assessments or CISP. ---ITEM--- External Audit Partner: Engage a professional organization to conduct annual compliance audits or security compliance assessments, with an annual budget of approximately 150,000 to 400,000 RMB. ---ITEM--- Part-time Legal Support: Can be handled by an internal legal team or outsourced legal advisors to manage legal matters such as data protection clauses in contract reviews and supplier Data Processing Agreements (DPA). ---ITEM--- Compliance Liaison Network: Designate part-time compliance liaisons in each business department to communicate compliance requirements and collect feedback on compliance issues.
Complete Organizational Structure of Large Enterprises
Large enterprises processing personal information of over 10 million individuals should establish an independent compliance department and implement a matrix management structure. The independent compliance department is typically situated within the legal department or reports directly to the Chief Compliance Officer (CCO). Key positions include: Chief Privacy Officer/DPO (1 person, at the management level), Privacy Compliance Managers (2-3 persons, responsible for product privacy reviews, cross-border data transfer management, and data subject rights management, respectively), Data Security Management Managers (1-2 persons, responsible for data classification and grading, and critical data management), and a Compliance Training and Awareness Specialist (1 person). Additionally, a security operations team led by the CISO should be established, typically comprising 5-15 members, responsible for security architecture, security operations (SOC), penetration testing, and technical implementation of security compliance standards. The key to matrix management lies in appointing part-time compliance liaisons within major business lines (such as product, technology, operations, and marketing) to form a governance model of "centralized management + distributed execution."
Collaboration Model between DPO and CISO
The DPO and CISO are the two most critical roles in a data compliance team, yet their responsibilities and core focuses are fundamentally distinct. The DPO is responsible for privacy governance, with a primary focus on ensuring that personal information processing activities comply with legal requirements. This includes reviewing legal bases, managing privacy policies, responding to data subject rights, conducting privacy impact assessments, and communicating with regulatory authorities. The CISO, on the other hand, is responsible for security implementation, with a core focus on protecting the confidentiality, integrity, and availability of corporate information assets. This involves designing security architectures, detecting and responding to threats, managing vulnerabilities, ensuring compliance with security standards, and overseeing security operations. A clear boundary for collaboration should be established between the two roles: the DPO defines "what to protect" and "why to protect," while the CISO determines "how to protect" and "with what to protect." It is recommended that the two hold a weekly work synchronization meeting and jointly submit a compliance and security report to management on a monthly basis.
Shared Responsibility Domain
- ›Data Breach Incident Response: The DPO is responsible for assessing the impact of the breach on data subjects and statutory reporting obligations (Article 57 of the PIPL requires immediate notification to regulatory authorities and affected individuals), while the CISO handles the technical aspects of incident investigation, evidence preservation, and vulnerability remediation. ---ITEM--- Risk Assessment: The DPO leads privacy impact assessments (PIA), and the CISO leads security risk assessments. Both should share assessment results and coordinate remediation priorities. ---ITEM--- Vendor Management: The DPO reviews vendor data processing agreements and privacy compliance status, while the CISO assesses vendor security capabilities and risk levels. Together, they determine vendor admission criteria. ---ITEM--- New Product/Feature Review: Privacy by Design and Security by Design review checkpoints are embedded into the product development lifecycle, with both the DPO and CISO participating. ---ITEM--- Training and Awareness Education: Jointly conduct comprehensive training covering both privacy compliance and information security dimensions to ensure employees understand data protection legal requirements and master basic security operational standards.
Special Structural Considerations for Multinational Enterprises
When multinational enterprises establish compliance teams in China, they need to address the coordination between global governance frameworks and local compliance requirements. It is recommended to adopt a dual-layer structure of "global framework + local adaptation": at the global level, the Group DPO/CPO sets global data protection policies and minimum standards; at the local level in China, the China PIPO adapts and enhances these policies according to Chinese legal requirements. Administratively, the China PIPO may report to the General Manager of the China region, while professionally reporting to the global DPO. However, in matters involving compliance with Chinese laws, the China PIPO should have independent decision-making authority. Special attention should be paid to compliance reviews involving cross-border data transfers, where the China PIPO should have veto power to ensure the company does not violate China's data export management requirements in global data flows.
Priority and Roadmap for Team Building
- ›Phase 1 (0-3 months): Appoint a PIPO and complete registration, conduct a comprehensive compliance gap assessment, and establish a foundational compliance framework.
- ›Phase 2 (3-6 months): Recruit core security personnel, complete cybersecurity classification and registration, and deploy basic security protection measures.
- ›Phase 3 (6-12 months): Establish a network of compliance liaisons, conduct organization-wide compliance training, and complete the first round of privacy impact assessments and cybersecurity evaluations.
- ›Phase 4 (12-18 months): Optimize compliance processes and toolchains, introduce a compliance management platform for automated monitoring, and establish a supplier compliance evaluation mechanism.
- ›Phase 5 (18-24 months): Achieve normalized compliance operations, conduct the first compliance audit, and continuously optimize team configuration and capability building.
Budget Planning Reference
The budget planning for the compliance team should cover four dimensions: human resource costs, external service fees, investment in technological tools, and training and certification expenses. For small enterprises, the annual compliance budget typically ranges from 300,000 to 800,000 yuan, with a primary focus on external services and tool investments. Medium-sized enterprises usually allocate an annual budget of 1 to 3 million yuan, with human resource costs and external services each accounting for approximately 40%, technological tools for 15%, and training and certification for 5%. Large enterprises can have an annual compliance budget of 5 to 20 million yuan or even higher, with human resource costs representing the largest share, around 50-60%. When justifying the budget, the security lead can reference the maximum corporate fine of 10 million yuan and the individual fine of 1 million yuan under the 2026 Cybersecurity Law amendment as a risk benchmark. This helps management understand the necessity of compliance investments and the return on investment. Compliance is not merely a cost center but a critical component of a company's trust capital.



