🇨🇳 China — Data Protection & Cross-Border Transfer Repository
Reference-grade map of China’s data-governance regime, focused on cross-border data transfer (CBDT). Current as of 2026-09. Verify against primary texts before advising.
China’s regime rests on three pillars — PIPL, DSL and CSL — operationalised through CAC administrative measures, State Council regulations and SAMR/SAC national standards. For CBDT, the framework crystallised around the three PIPL pathways (security assessment · standard contract · certification), relaxed by the March 2024 Provisions and completed by the Certification Measures (in force 2026-01-01) with standard GB/T 46068-2025 (2026-03-01). The 2025 CSL amendment (2026-01-01) sharply raised penalties.
1. The three statutory pillars
- PIPL — Personal Information Protection Law. Law · NPC Standing Committee · adopted 2021-08-20, effective 2021-11-01 · in force. China’s comprehensive personal-information statute (GDPR analogue). Art. 38 sets the three lawful CBDT mechanisms — root authority for all transfer compliance. Translation (DigiChina)
- DSL — Data Security Law. Law · NPCSC · adopted 2021-06-10, effective 2021-09-01 · in force. National data-classification & hierarchical-protection system around “important data” and “national core data”; underpins important-data export controls and restricts providing China-stored data to foreign judicial/LE bodies without approval. Official (NPC)
- CSL — Cybersecurity Law (2017) + 2025 amendment. Law · NPCSC · orig. effective 2017-06-01; amendment effective 2026-01-01 · in force. Introduced data localisation for CIIOs and the original security-assessment trigger. The 2025 amendment raises penalties to RMB 10M (network operators/CIIOs) / RMB 1M (responsible individuals), removes the mandatory prior-warning step, and adds AI-governance provisions. Amendment analysis · Original text
2. Cross-border transfer mechanisms & measures
- Provisions on Promoting and Regulating Cross-Border Data Flows (“March 2024 Provisions”). CAC · effective 2024-03-22 (immediate) · in force. The key operational rule today — raised volume thresholds, created six broad exemptions, and authorised FTZ “negative lists.” Substantially eased the 2022 regime. Translation
- Measures for Security Assessment of Outbound Data Transfers. CAC · effective 2022-09-01 · in force (thresholds modified 2024). The mandatory, government-reviewed top-tier pathway for important data, CIIO transfers and high-volume PI. Approval now valid 3 years. Translation
- Measures on the Standard Contract (China SCCs). CAC · effective 2023-06-01 · in force. Mandatory China SCC template + filing (signed contract + PIPIA with provincial CAC within 10 working days). Default mid-volume pathway; EU-SCC analogue. Procedure guide
- Measures for Certification of Cross-Border PI Transfer. CAC + SAMR · adopted 2025-10-14, effective 2026-01-01 · in force. Finalises the third pathway — certification by a SAMR-accredited, CAC-filed body — for mid-scale non-CIIO exporters (~≥100k, <1M individuals/yr). First three certification bodies authorised 2025-12-30. Analysis
- Regulations on the Administration of Network Data Security (NDSMR). State Council · effective 2025-01-01 · in force. Top-level administrative regulation implementing CSL/DSL/PIPL across all “network data”; consolidates CBDT rules, important-data management and incident reporting — connective tissue between statutes and CAC measures. Official
3. National standards (GB/T)
- GB/T 46068-2025 — Security Certification Requirements for CBDT of PI. SAMR/SAC · issued 2025-08-29, effective 2026-03-01 · in force. First dedicated standard defining the substantive criteria certification bodies apply under the Certification Measures (CBDT documentation, responsibilities, overseas storage/security, data-subject rights, recipient commitments). SAMR standard record — Chinese Standard Title: Implementation Guidelines for Notification and Consent in Information Security Technology: Personal Information Processing English standard title: Information security technology—Implementation guidelines for notices and consent in personal information processing Standard status: Current
- GB/T 35273-2020 — Personal Information Security Specification. SAMR/SAC · effective 2020-10-01 · in force. Baseline best-practice standard for the PI lifecycle; predates PIPL but widely used as a practical compliance benchmark. Standard (EN) (citation — link removed)
4. Official guidelines & Q&As
- CAC Data-Export Guidelines & Q&As. CAC · 2nd-ed. Guidelines 2024-03-22; Q&A series 2024–2025 · current guidance. Practical procedure: simplified PIPIA template, online declaration portal, 3-year assessment validity, item-by-item necessity justification, thresholds, important-data, FTZ negative lists, group-company filings, certification route. CBDT Q&A III (Oct 2025)
5. CBDT decision framework (post-March-2024)
For a non-CIIO exporter transferring only PI (not “important data”), counted cumulatively since 1 January of the current year:
| PI volume exported per year | Required mechanism |
|---|---|
| Non-sensitive PI of < 100,000 individuals (no sensitive PI) | None (exempt) |
| Non-sensitive PI 100,000 – <1,000,000, or sensitive PI < 10,000 | Standard Contract or Certification (exporter’s choice) |
| Non-sensitive PI ≥ 1,000,000, or sensitive PI ≥ 10,000 | CAC Security Assessment (mandatory) |
| Any “important data”, or any CIIO exporting PI/important data | CAC Security Assessment (mandatory, any volume) |
Three pathways (PIPL Art. 38): (1) Security Assessment — government review, highest tier, valid 3 yrs; (2) Standard Contract — sign CAC SCC + file with PIPIA at provincial CAC within 10 working days; (3) Certification — from a SAMR-accredited/CAC-filed body (live since 2026-01-01, benchmarked to GB/T 46068-2025); useful for intra-group transfers.
Main exemptions (March 2024 Provisions — no mechanism even above thresholds):
- Data without PI or important data from international trade, transport, academic cooperation, or cross-border manufacturing/marketing.
- PI transfer necessary to perform a contract with the individual (cross-border shopping, travel/hotel, visa, payments).
- Employee PI transfer necessary for cross-border HR under lawful labour rules.
- PI transfer necessary to protect life/health/property in an emergency.
- Non-CIIO exporting non-sensitive PI of < 100,000 individuals since 1 Jan.
- Data not on the applicable FTZ “negative list” (e.g. Beijing, Shanghai/Lin-gang, Tianjin).
Note: “important data” export always requires a security assessment; but absent an official designation/public catalogue, processors generally need not treat a dataset as important data (per the March 2024 Provisions & CAC Q&As).
🆕 Recent additions (auto)
- 2026-09-01 Notice on the Reorganization of the National Network Security Standardization Technical Committee and the Recruitment of Committee Members (TC260 — Notices)
- 2026-08-01 Notice on Convening the National Network Security Standardization Technical Committee’s Second ‘Standards Week’ Activity in 2026 (TC260 — Notices)
- 2026-08-01 Notice on the Release of the Network Security Standard Practice Guide — Personal Users’ Security Guide for Using Artificial Intelligence Services (TC260 — Notices)
- 2026-08-01 Notice on Designating Responsible Experts and Editors for 48 Network Security National Standards and 13 National Standardization Guidance Technical Documents… (TC260 — Notices)
- 2026-08-01 Notice on Public Solicitation of Comments on the Network Security Standard Practice Guide — Cockpit Data Processing Security Requirements (Draft for Comment)… (TC260 — Notices)
- 2026-08-01 Announcement of the List of Selected Personal Information Protection Standard Application Practice Cases (TC260 — Notices)
- 2026-08-01 Notice on Soliciting Participating Units for the Network Security Technology Penetration Testing Methods Standard (TC260 — Notices)
- 2026-08-01 Notice on Soliciting Participating Units for the Network Security Technology Artificial Intelligence Model Development Security Guide Standard (TC260 — Notices)
- 2026-08-01 Notice on Soliciting Participating Units for the Network Security Technology Intelligent Computing Cloud Service Security Assessment Methods Standard (TC260 — Notices)
- 2026-08-01 Notice on Soliciting Participating Units for the Network Security Technology Artificial Intelligence Training and Inference Framework Security Requirements Standard (TC260 — Notices)
- 2026-08-01 Network Security Standardization Work Monthly Report — July 2026 (TC260 — News)
- 2026-08-01 Artificial Intelligence Security Standards Working Group (WG9) Third Full Members Meeting in 2026 Held in Shanghai (TC260 — News)
- 2026-08-01 Network Security Standardization Work Monthly Report — June 2026 (TC260 — News)
- 2026-07-01 Kickoff Meeting of 6 Artificial Intelligence Application Security National Standardization Guidance Technical Documents Held in Beijing (TC260 — News)
- 2026-06-01 Network Security Standard Application Practice Cases – Supply Chain Security Theme No. 8 (TC260 — News)
- 2026-06-01 Network Security Standard Application Practice Cases – Supply Chain Security Theme No. 9 (TC260 — News)
- 2026-06-01 Network Security Standard Application Practice Cases – Supply Chain Security Theme No. 7 (TC260 — News)
- 2026-06-01 Network Security Standardization Work Monthly Report — May 2026 (TC260 — News)
- 2026-06-01 2026 Data Security and Personal Information Protection Policy Briefing and Power Industry Network Security National Standards Implementation Application Depth Initiative… (TC260 — News)
- 2026-06-01 Network Security New Technologies and Standardization Seminar in the AI Era and Network Security Standards and Technology Industry Campus Outreach Activities Held in Beijing (TC260 — News)
Compiled 2026-09 from official/authoritative sources. Maintained in the KB — update entries as measures evolve.