English中文
China flag

China

China Cross-Border Data Transfer Rules: CAC Security Assessment, Standard Contract, and Certification

By Recording Law Editorial Team12 min read
China Cross-Border Data Transfer Rules: CAC Security Assessment, Standard Contract, and Certification

Frequently Asked Questions

Do I need a CAC security assessment for every cross-border transfer out of China?

No. Order 16 sets three tiers. Below 100,000 non-sensitive individuals a year (with no important data and no CIIO status), a transfer can be exempt. Between 100,000 and under 1,000,000 non-sensitive individuals, or under 10,000 sensitive individuals, a Standard Contract or certification applies. The security assessment is mandatory only for CIIOs, any transfer of important data, or the highest-volume tier: 1,000,000 or more non-sensitive individuals, or 10,000 or more sensitive individuals, per year.

Is a completed CAC security assessment good indefinitely once I have it?

No. A security assessment result is valid for three years. Exporters who need to keep transferring on that basis must apply for renewal before the three years run out; an expired, unrenewed assessment does not keep the transfer lawful.

If my transfer qualifies for either the Standard Contract or certification, how do I choose?

Order 16 gives you the choice at that threshold tier; it does not mandate one over the other. In practice, the Standard Contract is built around a specific bilateral agreement with one overseas recipient, while certification is more often used for recurring, structured transfers within a single corporate group under a consistent data governance program. Which fits depends on your transfer pattern and corporate structure.

What exactly is "important data," and how do I know if mine qualifies?

There is no single, exhaustive national catalogue. Identification runs through sector-specific and regional catalogues or working rules; where none has been published for your industry, you are expected to assess your data against the general definition -- data that, if leaked or damaged, could endanger national security, economic operation, social stability, or public health and safety. If your data qualifies, the security assessment is mandatory regardless of how few individuals are affected.

I am under the 100,000-individual threshold. Does that automatically mean I am exempt?

Only if none of the data is important data and you are not a CIIO. Being under the headcount threshold does not override the important-data trigger or CIIO status -- both of those require the security assessment independent of volume.

Does completing a Standard Contract filing or certification remove the need for individual consent?

No. Cross-border transfer requires its own separate, standalone, informed consent from the individual, and a Personal Information Protection Impact Assessment (PIPIA), regardless of which of the three mechanisms applies. These sit underneath all three mechanisms rather than being replaced by any of them.

Does the threshold analysis change if the overseas recipient is our own parent company or an affiliate rather than an outside vendor?

Order 16's thresholds are built around the volume, sensitivity, and category of the data being transferred and the exporter's CIIO status, not around the corporate relationship between sender and recipient. A transfer to an affiliate or parent company is measured against the same thresholds as a transfer to an unrelated third party.

Is China actually enforcing these cross-border transfer rules, or is this mostly a paperwork requirement?

CAC enforcement has been active. In 2026, CAC ran a joint special campaign with MIIT and MPS (launched April 2, 2026) targeting unlawful data practices including cross-border transfer violations, and publicly named 33 apps found in violation of personal information protection rules on April 27, 2026.

Updates

CAC publicly named 33 apps found in violation of personal information protection rules.

CAC, MIIT, and MPS launched a joint special campaign targeting unlawful data practices in apps and SDKs, including cross-border transfer violations.

CAC and SAMR issued the Personal Information Protection Certification Measures covering cross-border transfer certification, effective January 1, 2026, formalizing the certification pathway.

CAC Order 16 (Provisions on Promoting and Regulating Cross-Border Data Flows) took effect, establishing the current exemption thresholds and the three-mechanism structure.

Sources and References

  1. CAC Order No. 16 -- Provisions on Promoting and Regulating Cross-Border Data Flows (effective March 22, 2024)(cac.gov.cn).gov
  2. CAC and SAMR -- Personal Information Protection Certification Measures for cross-border data transfers (issued October 14, 2025, effective January 1, 2026)(cac.gov.cn).gov
  3. CAC -- Network Data Security Management Regulations (State Council Order 790, effective January 1, 2025)(cac.gov.cn).gov
  4. CAC, MIIT, and MPS -- 2026 joint special campaign on data practices in apps and SDKs (launched April 2, 2026)(cac.gov.cn).gov
  5. CAC -- notice naming 33 apps found in violation of personal information protection rules (April 27, 2026)(cac.gov.cn).gov
  6. Personal Information Protection Law of the People's Republic of China, Article 57 (translation mirror, referenced for regulator/duty context)(personalinformationprotectionlaw.com)
Share: