Privacy Design®
Knowledge Base → Jurisdictions → 🇨🇳 China — Data Protection & Cross-Border Transfer Repository

🇨🇳 China — Data Protection & Cross-Border Transfer Repository

Reference-grade map of China’s data-governance regime, focused on cross-border data transfer (CBDT). Current as of 2026-09. Verify against primary texts before advising.

China’s regime rests on three pillars — PIPL, DSL and CSL — operationalised through CAC administrative measures, State Council regulations and SAMR/SAC national standards. For CBDT, the framework crystallised around the three PIPL pathways (security assessment · standard contract · certification), relaxed by the March 2024 Provisions and completed by the Certification Measures (in force 2026-01-01) with standard GB/T 46068-2025 (2026-03-01). The 2025 CSL amendment (2026-01-01) sharply raised penalties.

1. The three statutory pillars

2. Cross-border transfer mechanisms & measures

3. National standards (GB/T)

4. Official guidelines & Q&As

5. CBDT decision framework (post-March-2024)

For a non-CIIO exporter transferring only PI (not “important data”), counted cumulatively since 1 January of the current year:

PI volume exported per year Required mechanism
Non-sensitive PI of < 100,000 individuals (no sensitive PI) None (exempt)
Non-sensitive PI 100,000 – <1,000,000, or sensitive PI < 10,000 Standard Contract or Certification (exporter’s choice)
Non-sensitive PI ≥ 1,000,000, or sensitive PI ≥ 10,000 CAC Security Assessment (mandatory)
Any “important data”, or any CIIO exporting PI/important data CAC Security Assessment (mandatory, any volume)

Three pathways (PIPL Art. 38): (1) Security Assessment — government review, highest tier, valid 3 yrs; (2) Standard Contract — sign CAC SCC + file with PIPIA at provincial CAC within 10 working days; (3) Certification — from a SAMR-accredited/CAC-filed body (live since 2026-01-01, benchmarked to GB/T 46068-2025); useful for intra-group transfers.

Main exemptions (March 2024 Provisions — no mechanism even above thresholds):

Note: “important data” export always requires a security assessment; but absent an official designation/public catalogue, processors generally need not treat a dataset as important data (per the March 2024 Provisions & CAC Q&As).

🆕 Recent additions (auto)


Compiled 2026-09 from official/authoritative sources. Maintained in the KB — update entries as measures evolve.