Personal Information Security Specification. An English language summary is on China Law Blog: https://www.chinalawblog.com/2018/02/chinas-personal-information-security-specification-get-ready-for-may-1.html
That was a post from last year, when it went into action. In GDPR and Personal ISS (someone really should have thought of a better name) there are similar, and equivalent, separations of data collection, data retention, controller and user.
It maps, if not in order but in coverage similarly to GDPR.
I'm asking specifically for companies outside of China that may seek to handle personal information of customers in China.