DraftThe August proposal consolidates two earlier platform drafts. Separate proposed designation and governance duties from obligations already in force before changing an internal compliance programme.
Sources checked: 2026-09-10
GuidanceA practical research framework for assessing reuse of published contact details and reviewing basic leakage risks, with separate legal-source notes and hypothetical examples.
Sources checked: 2026-09-09
GuidanceA working guide to the July 2026 official Q&A, with evidence checks, growth calculations and recruitment scenarios. Separate transfer mechanisms from notice, consent and necessity.
Sources checked: 2026-09-10
GuidanceUse the second-edition filing guide to assemble a consistent contract and impact-assessment package. Separate route eligibility, contract effectiveness, filing and later changes: they answer different questions.
Sources checked: 2026-09-11
EffectiveAn impact assessment is a decision record for a defined processing activity, not a privacy policy or an audit certificate. Map the statutory trigger, test necessity and safeguards, and preserve the evidence behind the conclusion.
Sources checked: 2026-09-11
EffectiveThe 2025 audit measures distinguish regular internal or commissioned audits from authority-required professional audits. Build the programme around actual processing, defensible sampling and verified remediation, with the later small-processor rules applied separately.
Sources checked: 2026-09-11
EffectiveA practical reading of the rules effective from 1 September 2026: the fewer-than-100,000-person test, platform coverage, simplified audit and impact-assessment records, and the limits of cross-border exemptions.
Sources checked: 2026-09-11
GuidanceAn evidence map for automotive, industrial, telecom and financial activities: identify the applicable source, distinguish sensitivity from important-data designation, and keep domestic reporting separate from export approval.
Sources checked: 2026-09-14
GuidanceStart with the transfer, not the paperwork. Compare the current thresholds, exemptions, filing steps and renewal rules, with worked boundary cases and the September 2026 certification clarification.
Sources checked: 2026-09-16
GuidanceA practical reading of the full official guide and its five annexes: what changed from the second edition, how to reconcile the filing package, and how an extension application differs from a new assessment.
Sources checked: 2026-09-16
publishedA neutral public-reference overview of source-based categories commonly discussed in China cross-border data transfer research.
Last updated: 2026-05-26
publishedThe 2024 Data Flow Provisions are CAC Order No. 16 and should be read with China's earlier cross-border data transfer rules and PIPL Article 38.
Last updated: 2026-05-21
publishedA standards version watch that separates the published 2020 standard from the June 2026 consultation draft.
Last updated: 2026-07-30
publishedThe 2024 Data Flow Provisions use cumulative current-year personal-information subject counts for several cross-border transfer thresholds, but they do not answer every practical counting-method question.
Last updated: 2026-06-20
publishedThe Network Data Security Regulation is a State Council regulation effective 2025-01-01 that connects to China's CSL, DSL, PIPL, and network data governance framework.
Last updated: 2026-05-21
publishedPIPL Article 38 is a gateway article for providing personal information outside China, but it must be read with related articles and implementing rules.
Last updated: 2026-05-26
publishedA general informational PIPL compliance reference overview for source-based research. It is not a legal audit, legal advice, or company-specific compliance assessment.
Last updated: 2026-05-26
publishedA side-by-side official-source comparison of three common China cross-border personal information transfer mechanisms, with limits on what a public reference page can determine.
Last updated: 2026-05-21
publishedThe Standard Contract Measures are CAC rules for the China standard contract route for cross-border transfer of personal information.
Last updated: 2026-05-21
publishedCross-border data transfer is a source-sensitive topic under China's data protection framework. The analysis may involve personal information, important data, network data, route mechanisms, and official CAC rules.
Last updated: 2026-05-21