China
China Cross-Border Data Transfer Rules: CAC Security Assessment, Standard Contract, and Certification

Moving personal information out of mainland China is a legal act in its own right, separate from the collection and processing rules that govern the data at home. China's data privacy framework treats a "cross-border transfer" as any provision of personal information collected or generated inside mainland China to a recipient outside it, whether that recipient is a cloud vendor, a corporate parent, or a business partner. The rules that decide which legal mechanism a given transfer needs come from a single instrument: the Cyberspace Administration of China's (CAC) Order No. 16, formally the Provisions on Promoting and Regulating Cross-Border Data Flows, effective March 22, 2024.
This page is a working guide to that Order. It does not restate China's broader privacy framework (PIPL, DSL, CSL); for that, start with the China data privacy laws overview page. This page exists to answer one operational question: given a specific transfer, which of the three legal mechanisms applies, and what does complying with it actually involve.
Which mechanism applies to your transfer
Order 16 sorts every cross-border transfer into one of three buckets. The variables that decide the bucket are: whether the exporter is a Critical Information Infrastructure Operator (CIIO), whether the data includes "important data," whether the personal information is "sensitive," and how many individuals' data moves out of China in a calendar year.
| Your situation | Mechanism required |
|---|---|
| You are a CIIO transferring any personal information, or any "important data" | CAC security assessment (mandatory) |
| You transfer "important data," regardless of CIIO status or headcount | CAC security assessment (mandatory) |
| Non-CIIO, non-sensitive personal information, 1,000,000+ individuals in the year | CAC security assessment (mandatory) |
| Non-CIIO, sensitive personal information, 10,000+ individuals in the year | CAC security assessment (mandatory) |
| Non-CIIO, non-sensitive personal information, 100,000 to under 1,000,000 individuals in the year | Standard Contract OR certification (your choice) |
| Non-CIIO, sensitive personal information, under 10,000 individuals in the year | Standard Contract OR certification (your choice) |
| Non-CIIO, non-sensitive personal information, under 100,000 individuals in the year | Exempt from all three mechanisms |
| Any volume, but the transfer is strictly necessary to conclude or perform a contract the individual is a party to (e.g., cross-border shopping, travel booking, remittance) | Exempt (named scenario) |
| Any volume, but the transfer is an employer's cross-border transfer of its own employees' data for HR management under a lawful labor policy or collective contract | Exempt (named scenario) |
| Any volume, but the transfer is necessary to protect an individual's life, health, or property in an emergency | Exempt (named scenario) |
Walking the decision tree
Work through these questions in order; the first one that changes the answer controls.
- Are you a Critical Information Infrastructure Operator? CIIO status is assigned by sector regulators to operators of infrastructure whose disruption would seriously harm national security, the economy, or public interest (typical sectors: telecom, energy, finance, transport, and public services). If yes, every cross-border transfer of personal information or important data you make requires a CAC security assessment. Stop here.
- Does the transfer include "important data"? If any of the data set qualifies as important data under the sector or regional identification rules that apply to your industry, the assessment is mandatory no matter how small the transfer is. Stop here.
- Does the transfer fall into one of the three named exemption scenarios, namely contract necessity, HR management of your own employees, or a life/health/property emergency? If yes, and none of the data is important data and you are not a CIIO, the transfer is exempt.
- Classify the personal information as sensitive or non-sensitive, then count the number of individuals whose data will move out of China across the calendar year, aggregated across your transfers to that use case (not per shipment).
- Compare the count against the two thresholds. Below 100,000 non-sensitive individuals with no sensitive data involved: exempt. Between 100,000 and under 1,000,000 non-sensitive, or under 10,000 sensitive: Standard Contract or certification. At or above 1,000,000 non-sensitive, or at or above 10,000 sensitive: security assessment.
Two practical traps sit inside step 4. First, the count is annual and cumulative for the transfer activity, not reset by treating a large transfer as a series of small ones. Second, "sensitive personal information" and "non-sensitive personal information" are two different counters with two different thresholds: a company moving both types abroad needs to track each population separately, because crossing either threshold independently triggers the assessment tier.

The CAC security assessment
This is the strictest of the three mechanisms and the only one available for CIIOs, important-data transfers, and the highest-volume personal information transfers.
Before filing, the exporter must complete a self-assessment of the transfer's risk. Order 16's self-assessment is meant to cover the legality, legitimacy, and necessity of the transfer's purpose, scope, and method; the volume, scope, type, and sensitivity of the data; the risk the transfer poses to national security, the public interest, and individual rights; the data protection obligations the overseas recipient will actually assume; and the security measures in place to prevent leakage, tampering, damage, loss, or misuse after the transfer.
Filing runs through a two-level structure: the application, self-assessment report, and legal documents governing the transfer (such as the agreement with the overseas recipient) go first to the provincial-level CAC office, which handles the initial intake before the matter is taken up at the national level for the actual assessment and decision. Processing an assessment application is not a fast process. Build meaningful lead time into any project timeline that depends on a completed assessment, and confirm current expected processing times directly with the provincial CAC office handling your filing, since these can shift.
Validity and renewal. A completed security assessment is valid for three years from the date of the result. Exporters who need to keep transferring on that basis past the three-year mark must apply for renewal before it lapses; letting the assessment expire without renewing puts the ongoing transfer outside a lawful basis.

The Chinese Standard Contract
For transfers in the middle tier (100,000 to under 1,000,000 non-sensitive individuals, or under 10,000 sensitive individuals, per year, for a non-CIIO exporter with no important data involved), the Standard Contract is generally the lighter-weight of the two available routes.
The mechanism works by having the exporter and the overseas recipient execute CAC's standard contract text governing the transfer. The exporter must also complete a Personal Information Protection Impact Assessment (PIPIA) covering the same categories of risk the security assessment self-assessment covers: purpose, scope, and necessity of the transfer; the type and sensitivity of the data; the risks to individuals; and the protective measures both sides commit to. The executed contract and the PIPIA are then filed with the provincial-level CAC.
A standard contract's core terms are fixed by CAC and are not meant to be varied by the parties in ways that reduce the protections the template provides. Exporters can add supplementary clauses addressing their specific transfer (for example, additional security obligations or sector-specific terms) as long as the additions do not conflict with or weaken the standard terms. A materially altered version of the template risks not qualifying as a valid Standard Contract filing at all, which is a common practical failure point.
Related reading: for how China's approach compares to the EU's mechanism of the same name, see standard contractual clauses.

Certification
Certification is the newer and, until recently, less-defined of the two middle-tier options. It works through an accredited, CAC-recognized certification body that assesses the exporter's (and often the recipient's, where they are affiliated entities such as a multinational group) personal information protection practices against the applicable technical standard and issues a certification covering the cross-border transfer activity.
The pathway was formalized by the CAC and the State Administration for Market Regulation (SAMR) through the Personal Information Protection Certification Measures for cross-border transfers, issued October 14, 2025 and effective January 1, 2026. Before that, certification existed on paper in Order 16 as one of the three mechanisms but lacked a complete operating framework; the 2025 Measures fill in the procedural detail: how a certification body is accredited, what the certification assessment covers, and how the certification is issued and maintained. The technical standard certification bodies apply during that assessment has itself been in motion; confirm the currently governing technical standard directly with a CAC-recognized certification body or counsel before relying on any specific standard number, since the basis has been subject to further regulatory notices since the Measures were issued.
In practice, certification is most often discussed as a fit for recurring, structured transfers within a single corporate group (for example, a multinational's China subsidiary transferring employee or customer data to its overseas headquarters under a consistent, ongoing data governance program), where a one-time certification of the group's practices can cover repeat transfers more efficiently than re-filing a Standard Contract for each one. The Standard Contract, by contrast, is built around a specific bilateral agreement between an exporter and one overseas recipient.

"Important data": the hardest category to pin down
Every other trigger in Order 16 is at least numeric: a headcount, a sensitivity classification, a CIIO designation. "Important data" is not. There is no single, exhaustive, publicly available national catalogue that lists exactly what counts as important data across every sector. Instead, identification works through a decentralized system: sector regulators and regional (often free-trade-zone or provincial) authorities issue their own catalogues or working rules identifying important data for the industries and areas under their supervision, and in the absence of a published catalogue or specific notification, a business is generally expected to assess its own data against the general definition: data that, if leaked, tampered with, or damaged, could directly endanger national security, economic operation, social stability, or public health and safety.
This matters enormously for the decision tree above, because the important-data trigger overrides every volume-based exemption. A transfer of important data affecting a single individual, or no individuals at all (aggregated business or operational data can qualify as important data independent of whether it is personal information), still requires the mandatory CAC security assessment. A company that correctly counts its personal-information headcount but never asks whether any of the underlying data set independently qualifies as important data can conclude, wrongly, that it is exempt or eligible for the lighter Standard Contract route.
Practically, this means the important-data question cannot be answered by a privacy team working from PIPL alone. It requires checking whether a sector-specific or regional catalogue applies to your industry and, where none has been published, making and documenting a reasoned assessment against the general definition, revisited whenever the nature of the data set changes.
Sequencing the compliance work
The mechanisms above are not independent boxes to check in isolation. In practice, get the sequence right:
- Determine CIIO status first. It is the single fact that removes any lighter-tier option from the table entirely.
- Classify the data set, sensitive versus non-sensitive personal information, and separately, whether any of it is or could be important data under a catalogue that applies to your sector or region.
- Count annual volume for each category (sensitive and non-sensitive tracked separately), aggregated across the full transfer activity for the year, not per shipment or per system.
- Map the result to the decision tree to identify which of the three mechanisms, or the exemption, applies.
- Complete the PIPIA regardless of mechanism. A Personal Information Protection Impact Assessment is required for cross-border transfers as a matter of course; it is not something the exemption tier, the Standard Contract, or certification lets you skip. It is a distinct document from (though it shares content with) the self-assessment report required for a security assessment filing.
- Obtain separate, standalone consent from the individuals whose data will be transferred. Cross-border transfer is treated as a distinct processing purpose requiring its own informed consent from the individual: a general consent to a privacy policy that does not specifically address cross-border transfer is not sufficient on its own.
- File with the correct authority for the mechanism selected: provincial CAC for both the security assessment application and the Standard Contract filing, or the accredited certification body for certification. Calendar the three-year renewal date if the security assessment route was used.
The most common practical failure point is treating the mechanism choice as the whole compliance job. Consent and the PIPIA sit underneath all three mechanisms and are frequently the piece that gets missed when a company focuses only on "which form do we file."
For a broader comparison of how China's overall approach to consent and cross-border transfer differs from the EU model, see GDPR vs. PIPL; for how China's export controls relate to the wider global trend of requiring certain data to stay in-country, see data localization laws by country.
Enforcement is active, not theoretical
CAC has continued to treat cross-border transfer compliance as an active enforcement priority in 2026, not a paperwork exercise that quietly went unenforced after Order 16 took effect.
On April 2, 2026, CAC launched a joint special campaign with the Ministry of Industry and Information Technology (MIIT) and the Ministry of Public Security (MPS) targeting unlawful data practices in mobile apps and SDKs, including cross-border transfer violations. Weeks later, on April 27, 2026, CAC publicly named 33 apps found in violation of personal information protection rules. Naming actions of this kind are typically followed by a compliance deadline for the named entities and, for repeat or unresolved cases, further administrative penalties.
The practical implication is not any single figure. It is that the exemption and threshold system is being actively checked, and that "important data" and CIIO-status calls in particular are treated as high-scrutiny areas where getting the classification wrong is a live enforcement risk, not a theoretical one.
Frequently Asked Questions
Do I need a CAC security assessment for every cross-border transfer out of China?
No. Order 16 sets three tiers. Below 100,000 non-sensitive individuals a year (with no important data and no CIIO status), a transfer can be exempt. Between 100,000 and under 1,000,000 non-sensitive individuals, or under 10,000 sensitive individuals, a Standard Contract or certification applies. The security assessment is mandatory only for CIIOs, any transfer of important data, or the highest-volume tier: 1,000,000 or more non-sensitive individuals, or 10,000 or more sensitive individuals, per year.
Is a completed CAC security assessment good indefinitely once I have it?
No. A security assessment result is valid for three years. Exporters who need to keep transferring on that basis must apply for renewal before the three years run out; an expired, unrenewed assessment does not keep the transfer lawful.
If my transfer qualifies for either the Standard Contract or certification, how do I choose?
Order 16 gives you the choice at that threshold tier; it does not mandate one over the other. In practice, the Standard Contract is built around a specific bilateral agreement with one overseas recipient, while certification is more often used for recurring, structured transfers within a single corporate group under a consistent data governance program. Which fits depends on your transfer pattern and corporate structure.
What exactly is "important data," and how do I know if mine qualifies?
There is no single, exhaustive national catalogue. Identification runs through sector-specific and regional catalogues or working rules; where none has been published for your industry, you are expected to assess your data against the general definition -- data that, if leaked or damaged, could endanger national security, economic operation, social stability, or public health and safety. If your data qualifies, the security assessment is mandatory regardless of how few individuals are affected.
I am under the 100,000-individual threshold. Does that automatically mean I am exempt?
Only if none of the data is important data and you are not a CIIO. Being under the headcount threshold does not override the important-data trigger or CIIO status -- both of those require the security assessment independent of volume.
Does completing a Standard Contract filing or certification remove the need for individual consent?
No. Cross-border transfer requires its own separate, standalone, informed consent from the individual, and a Personal Information Protection Impact Assessment (PIPIA), regardless of which of the three mechanisms applies. These sit underneath all three mechanisms rather than being replaced by any of them.
Does the threshold analysis change if the overseas recipient is our own parent company or an affiliate rather than an outside vendor?
Order 16's thresholds are built around the volume, sensitivity, and category of the data being transferred and the exporter's CIIO status, not around the corporate relationship between sender and recipient. A transfer to an affiliate or parent company is measured against the same thresholds as a transfer to an unrelated third party.
Is China actually enforcing these cross-border transfer rules, or is this mostly a paperwork requirement?
CAC enforcement has been active. In 2026, CAC ran a joint special campaign with MIIT and MPS (launched April 2, 2026) targeting unlawful data practices including cross-border transfer violations, and publicly named 33 apps found in violation of personal information protection rules on April 27, 2026.
Updates
CAC Order 16 (Provisions on Promoting and Regulating Cross-Border Data Flows) took effect, establishing the current exemption thresholds and the three-mechanism structure.
CAC and SAMR issued the Personal Information Protection Certification Measures covering cross-border transfer certification, effective January 1, 2026, formalizing the certification pathway.
CAC, MIIT, and MPS launched a joint special campaign targeting unlawful data practices in apps and SDKs, including cross-border transfer violations.
CAC publicly named 33 apps found in violation of personal information protection rules.
Sources and References
- CAC Order No. 16 -- Provisions on Promoting and Regulating Cross-Border Data Flows (effective March 22, 2024)(cac.gov.cn).gov
- CAC and SAMR -- Personal Information Protection Certification Measures for cross-border data transfers (issued October 14, 2025, effective January 1, 2026)(cac.gov.cn).gov
- CAC -- Network Data Security Management Regulations (State Council Order 790, effective January 1, 2025)(cac.gov.cn).gov
- CAC, MIIT, and MPS -- 2026 joint special campaign on data practices in apps and SDKs (launched April 2, 2026)(cac.gov.cn).gov
- CAC -- notice naming 33 apps found in violation of personal information protection rules (April 27, 2026)(cac.gov.cn).gov
- Personal Information Protection Law of the People's Republic of China, Article 57 (translation mirror, referenced for regulator/duty context)(personalinformationprotectionlaw.com)