Research across the library

Search laws, regulations, standards and guides

Suggested searches

Current priorities

2026-07-03Revised Internet Information Service Measures draft2026-06-18Network data risk assessment: draft versus final

The decision is conditional, not a choice of three products

First establish what leaves China, who provides it, who can access it abroad and whether a specific exemption applies. For remaining regulated transfers, test the security-assessment triggers before considering a standard contract or certification. A cheaper contract or an existing certificate cannot cure an assessment obligation.

This guide is an editorial synthesis of the national route framework, not an individual clearance decision. The 2024 provisions prevail over inconsistent parts of the earlier assessment and standard-contract measures. Certification now has operative measures, effective 1 January 2026. Special-sector restrictions and an applicable local negative list must also be checked.

Define the activity before counting people

Prepare a transfer inventory with the Chinese provider, recipient, locations, purpose, data fields, access permissions, onward recipients and retention period. Treat a transfer as a processing activity, not just an exported spreadsheet: remote access from outside China can matter even when the server remains in China.

The October 2025 CAC Q&A distinguishes overseas access to domestic data from access by a foreign employer's employee physically inside China without an outbound transfer. Nationality or group ownership alone is not the technical boundary. Document actual access locations and controls instead of labelling every foreign-owned company a recipient abroad.

Identify personal information, sensitive personal information and important data separately. Under-14 children's personal information is sensitive; removing names does not necessarily make records anonymous. Important-data identification depends on the applicable official rules and designations. Do not infer that no public nationwide list means there are no sector obligations.

Test an exemption against the actual purpose

An exemption removes the specified export mechanisms for the qualifying activity; it is not a permission to process unnecessary data. Keep the factual and legal basis with the transfer record. Articles 3–6 take priority where their conditions are met; do not run their qualifying transfers mechanically through the residual thresholds.

The following is a decision aid, not the text of an official checklist. The small-processor provision has a separate scope: processing fewer than 100,000 individuals is not the same test as exporting fewer than 100,000 individuals in a year.

BasisQualifying activityBoundary to record
No PI or important dataArticle 3 covers relevant trade, transport, research, manufacturing and marketing data without either category.Check the fields and identifiability; a commercial label alone does not establish this.
Overseas-origin processingOverseas-collected PI is processed in China and sent out without introducing domestic PI or important data.Maintain origin and joining records for each dataset.
Individual's contractThe export is necessary to conclude or perform a contract to which the individual is a party.Not every group service agreement qualifies; exclude important data.
Cross-border HRNecessary employee-data export under lawfully established employment rules and lawfully concluded collective contracts.Substantiate necessity for the particular fields; exclude important data.
EmergencyNecessary to protect a natural person's life, health or property in an emergency.Record the emergency and necessary scope; exclude important data.
Small ordinary-PI volumeA non-CIIO exports fewer than 100,000 individuals' ordinary PI from 1 January of the current year.This volume exemption does not cover sensitive PI or important data.
Local negative listThe provider and activity fall within the approved local framework, and the data is outside its negative list.Verify current geography, sector, edition and local procedures, not just the city name.
Small processor: statutory dutyArticle 10 of the 2026 simplification provisions also covers necessary export to fulfil statutory duties or obligations within that instrument's scope.Confirm small-processor status and the actual statutory basis; no important data. Do not generalize this to every provider.

Apply the higher trigger first

The matrix applies after relevant exemptions and special provisions have been resolved. Ordinary PI below means PI excluding sensitive PI. The numerical branches refer to cumulative outbound individuals from 1 January of the current year, not the company's total customer database or number of database rows.

Test important data, CIIO status and both numerical counters together. Never read the sensitive-PI limb as making a zero-person export subject to certification. Conversely, ordinary PI below 100,000 does not by itself exempt a non-exempt sensitive-PI transfer.

Remaining activityRouteInterpretation
CIIO provides PI or important dataSecurity assessmentApply Article 7 after accounting for its express Articles 3–6 exception clause.
Non-CIIO: important data; or ordinary PI ≥1,000,000; or sensitive PI ≥10,000Security assessmentAny applicable trigger is enough; a lower number in the other category does not cancel it.
Non-CIIO, no important data: ordinary PI ≥100,000 and <1,000,000; or sensitive PI >0 and <10,000Standard contract or certificationOnly where no assessment trigger or applicable exemption determines the outcome.
Non-CIIO, no important data: ordinary PI <100,000 and no non-exempt sensitive PIOrdinary-PI volume exemptionRetain the evidence for the volume test and any separately exempt activity.

Make the count auditable

Use a person-based register for the legal threshold and a separate record of fields, records and access events for operational monitoring. Record the start date, cut-off date, provider, included activities, ordinary/sensitive classification, identity-matching method and treatment of repeated individuals. A raw spreadsheet row count is not a reliable proxy for people.

Keep any exclusion for an exempt activity traceable to a specific rule and evidence. Reconcile the counting method with the current filing guide or competent authority where activities overlap. This page does not prescribe a universal deduplication rule across different recipients or companies, and it does not authorize splitting a transfer to avoid assessment.

Forecasts should prompt an earlier review, not rewrite the statutory threshold. Assign someone to reconcile actual cumulative totals with the approved or contracted scope before new systems, recipients or data categories go live.

Compare the documents and the clocks

The mechanisms differ in decision maker, evidence and the point at which timing begins. Preparation time, supplementation, authority review and continuing supervision are not one interchangeable filing period. The table summarizes national rules; use the current official guide for the complete submission package.

MechanismPreparation and sequenceTiming and continued use
Security assessmentComplete the export risk self-assessment; prepare the application, report, recipient legal documents and required supporting materials. Submit through the provincial CAC to the national CAC.The assessment is normally completed within 45 working days of written acceptance; complexity or supplementary material can extend it. The result is valid for 3 years. This is not a guaranteed 45-day end-to-end launch timetable.
Standard contractConduct the PIPIA and sign the official standard contract without conflicting supplemental terms. Export may begin only after the contract takes effect, with other applicable duties satisfied.File with the provincial CAC within 10 working days of effectiveness. Do not describe filing as the national security-assessment approval. These measures do not impose a universal 3-year contract expiry.
PI export certificationPrepare the PIPIA and evidence for a qualified professional certification body; verify its qualification and CAC filing. A generic security certificate is not this export mechanism.The certificate lasts 3 years. For continued use, apply 6 months before expiry. The measures do not promise a universal completion time for every application.

What the September 2026 clarification changes

The 11 September CAC Q&A distinguishes certification as an eligible export route from voluntary certification to demonstrate protective capability. Voluntary certification may be sought at different export volumes, but it cannot replace a required security assessment. If a certified activity crosses an assessment threshold, certification evidence can accompany the assessment application; it does not waive it.

For procurement, check the official list of filed certification bodies and the scope of the proposed certificate. The Q&A is guidance explaining the existing regime, not a new effective date or permission to split volumes.

Worked cases: one fact can change the answer

These are hypothetical examples, not customer cases or legal opinions. Assume a non-CIIO, no important data, no relevant sector override and no specific exemption unless stated. Counts below are already validated cumulative individuals for the current year; they are not instructions for aggregating an unreviewed dataset.

FactsInitial resultWhy / next check
99,999 ordinary; 0 sensitiveOrdinary-PI volume exemptionBelow 100,000. Recheck classification and continuing duties.
100,000 ordinary; 0 sensitiveStandard contract or certificationThe lower boundary is inclusive, not only numbers greater than 100,000.
50,000 ordinary; 1 sensitiveStandard contract or certification for the non-exempt activityThe ordinary-PI volume exemption does not cover that sensitive-PI transfer.
999,999 ordinary; 9,999 sensitiveStandard contract or certificationBoth counters are below the assessment thresholds. Monitor both before scope increases.
1,000,000 ordinary; or 10,000 sensitiveSecurity assessmentEither inclusive upper boundary triggers assessment under the stated assumptions.
Domestic resident books a domestic hotel; data is sent to a foreign group systemNo automatic individual's-contract exemptionThe October 2025 Q&A expressly rejects that contract-exemption argument. Determine the applicable remaining route.

An exemption or certificate is not the end of the work

Under PIPL, establish a lawful processing basis, necessity, recipient safeguards and the required export notice. Where consent is the basis, obtain the required separate consent without bundling it with unrelated processing. The July 2026 Q&A confirms that Article 13(1)(2)–(7) activities do not require consent, while the export notice remains required. Do not confuse an export-mechanism exemption with a consent exemption.

Conduct the required prior PIPIA and retain its report and processing record for at least 3 years. For small processors, an available simplified format does not turn this into no assessment. Requests by foreign judicial or law-enforcement authorities also require the separate Article 41 analysis; an ordinary business-transfer contract is not that approval.

Build a review trigger into the activity register: new recipient or onward transfer, new purpose or sensitive fields, greater scale, longer retention, changed overseas law or a security incident. Determine whether the assessment, contract or certificate must be renewed or updated before treating the old documentation as sufficient.

ControlWhat to checkCommon error
Assessment extensionApply within the 60-working-day window before expiry; approval is required. Check all extension conditions, not just the numerical growth limit.Treating a 20% figure as an automatic allowance. July guidance uses the previously approved three-year quantity, not actual usage, as the growth baseline.
Standard-contract changeAssess Article 8 triggers, repeat PIPIA where required, supplement or re-sign and re-file.Assuming a new recipient or purpose is covered because the signature remains valid.
Certificate scopeTrack expiry and material scope changes; verify whether continuing conformity and the renewal application are maintained.Presenting an out-of-scope or suspended certificate as authorization for any export.
Recipient operationsRetain notice versions, rights-request arrangements, access controls, incident handling and onward-transfer conditions.Filing once and never checking how the recipient actually uses the data.

Turn the analysis into a reviewable decision record

A useful internal conclusion states the activity and cut-off date, the facts accepted, the relevant rule and source locator, the chosen route, unresolved assumptions, the evidence owner and the next review event. If a fact such as important-data status or overseas access is unresolved, record it as a decision dependency rather than selecting the easiest route.

The matrices above are original research aids. They do not reproduce the official filing annexes or certify readiness for an individual project. Use the linked guides for implementation detail, and keep the official Chinese instruments as the controlling sources. This page's verification date applies to the cited sources, not to every local or sector rule.

Official sources & revisions

: Replaced the legacy mechanisms overview with an evidence-led route sequence, exemption and threshold matrices, procedural clocks, hypothetical boundary cases and ongoing controls. Added the 11 September certification clarification; retained the canonical URL.

Examples and working tables are original research aids, not official forms or legal advice.

Suggest a correction

Continue researching