Cross-border Data Transfer
Read the security assessment measures, standard contract measures, and 2024 data-flow provisions together with PIPL Article 38 and the core laws.
Open the source-reading guideNetwork and Cybersecurity
Connect the Network Data Security Regulation, CII protection framework, and cybersecurity review measures with the DSL and CSL.
Open the Cybersecurity LawAlgorithm and AI Governance
Compare the source roles of the algorithm recommendation, deep synthesis, and generative-AI measures without treating them as interchangeable.
Start with algorithm recommendation ruleseffectiveDepartmental RuleSource: Verified
个人信息保护合规审计管理办法
- Authority
- Cyberspace Administration of China
- Publication
- 2025-02-14
- Effective
- 2025-05-01
- Translation
- editorial summary only
- Audience
- Personal information processors and professional institutions
CAC Order No. 18 establishes administrative requirements for personal information protection compliance audits and has been effective since 1 May 2025.
Why it matters: The measures connect the PIPL's compliance-audit duties with audit frequency, professional institutions, processor responsibilities, and regulatory supervision.
Open public summaryeffectiveDepartmental RuleSource: Verified
人工智能生成合成内容标识办法
- Authority
- Cyberspace Administration of China; Ministry of Industry and Information Technology; Ministry of Public Security; National Radio and Television Administration
- Publication
- 2025-03-14
- Effective
- 2025-09-01
- Translation
- editorial summary only
- Audience
- AI service providers content distribution platforms and app distribution platforms
These joint measures govern explicit and implicit labeling of artificial intelligence-generated and synthetic content and took effect on 1 September 2025.
Why it matters: They add a verified labeling layer to the existing algorithm, deep-synthesis, and generative-AI governance framework.
Open public summaryeffectiveDepartmental RuleSource: Verified
人脸识别技术应用安全管理办法
- Authority
- Cyberspace Administration of China; Ministry of Public Security
- Publication
- 2025-03-21
- Effective
- 2025-06-01
- Translation
- editorial summary only
- Audience
- Personal information processors using facial recognition
These joint measures govern the application of facial-recognition technology and the processing of facial information. They took effect on 1 June 2025.
Why it matters: Facial information is sensitive personal information, so the measures provide important application-specific context for PIPL obligations.
Open public summaryeffectiveDepartmental RuleSource: Verified
国家网络身份认证公共服务管理办法
- Authority
- Cyberspace Administration of China; Ministry of Public Security; Ministry of Civil Affairs; Ministry of Culture and Tourism; National Health Commission; National Radio and Television Administration
- Publication
- 2025-05-23
- Effective
- 2025-07-15
- Translation
- editorial summary only
- Audience
- Online platforms service providers and individuals
These six-authority measures govern the national network identity authentication public service and took effect on 15 July 2025.
Why it matters: They create a specific source for digital identity authentication that must be distinguished from general identity-verification and personal-information rules.
Open public summaryeffectiveDepartmental RuleSource: Verified
个人信息出境认证办法
- Authority
- Cyberspace Administration of China; State Administration for Market Regulation
- Publication
- 2025-10-17
- Effective
- 2026-01-01
- Translation
- editorial summary only
- Audience
- Non-CIIO personal information processors within the specified thresholds
These joint CAC and SAMR measures govern the personal information export certification route and have been effective since 1 January 2026.
Why it matters: They create a binding departmental-rule layer for certification and specify the applicable range for eligible non-CIIO personal information processors.
Open public summaryupcomingDepartmental RuleSource: Verified
网络数据安全风险评估办法
- Authority
- Cyberspace Administration of China; Ministry of Industry and Information Technology; Ministry of Public Security
- Publication
- 2026-06-18
- Effective
- 2026-08-20
- Translation
- editorial summary only
- Audience
- Network data processors and important data processors
These final joint measures govern network data security risk assessments and take effect on 20 August 2026.
Why it matters: They finalize the 2025 consultation proposal and clarify assessment cycles, report submission, retention, and regulatory handling.
Open public summaryeffectiveDepartmental RuleSource: Verified
人工智能拟人化互动服务管理暂行办法
- Authority
- Cyberspace Administration of China; National Development and Reform Commission; Ministry of Industry and Information Technology; Ministry of Public Security; State Administration for Market Regulation
- Publication
- 2026-04-10
- Effective
- 2026-07-15
- Translation
- editorial summary only
- Audience
- Providers of anthropomorphic AI interaction services
These interim measures govern anthropomorphic artificial intelligence interaction services and took effect on 15 July 2026.
Why it matters: They add service-specific governance for interactions designed to simulate human personality or communication and sit alongside the broader generative-AI framework.
Open public summaryguidancePolicy GuidanceSource: Verified
关于加强智能体规范应用的实施意见
- Authority
- Cyberspace Administration of China; National Development and Reform Commission; Ministry of Education; Ministry of Science and Technology; Ministry of Industry and Information Technology
- Publication
- 2026-05-08
- Effective
- Under review
- Translation
- editorial summary only
- Audience
- Intelligent agent developers providers deployers and relevant authorities
This multi-authority implementation opinion addresses the regulated development and application of intelligent agents. It is policy guidance rather than a departmental rule.
Why it matters: It signals current policy priorities for intelligent-agent development while remaining legally distinct from binding AI service measures.
Open public summaryupcomingDepartmental RuleSource: Verified
互联网信息服务多渠道分发管理规定
- Authority
- Cyberspace Administration of China; Ministry of Industry and Information Technology; Ministry of Public Security; National Radio and Television Administration
- Publication
- 2026-05-29
- Effective
- 2026-09-01
- Translation
- editorial summary only
- Audience
- Internet information service providers and distribution channels
These joint provisions govern multi-channel distribution of internet information services and take effect on 1 September 2026.
Why it matters: They address responsibilities across content production and distribution channels and connect with existing internet information service and labeling rules.
Open public summaryeffectiveAdministrative RegulationSource: Verified
网络数据安全管理条例
- Authority
- State Council
- Publication
- 2024-09-24
- Effective
- 2025-01-01
- Translation
- Not prepared
- Audience
- Network data processors and platform operators
This State Council regulation provides a broad governance framework for network data processing. It addresses processing duties, personal information protection, important data, cross-border data activity, platform responsibilities, and regulatory oversight.
Why it matters: The regulation connects themes found across the PIPL, DSL, and CSL and gives readers a consolidated source for understanding how network data governance fits across those laws.
Open public summaryeffectiveRegulatory MeasureSource: Verified
数据出境安全评估办法
- Authority
- Cyberspace Administration of China
- Publication
- 2022-07-07
- Effective
- 2022-09-01
- Translation
- Not prepared
- Audience
- All industries
These CAC measures establish the public regulatory framework for security assessment of certain cross-border data transfers, including application materials, assessment factors, review stages, and validity concepts.
Why it matters: Security assessment is one of the central mechanisms in China's cross-border data transfer framework and must be read alongside the PIPL, DSL, and later data-flow provisions.
Open public summaryeffectiveRegulatory MeasureSource: Verified
个人信息出境标准合同办法
- Authority
- Cyberspace Administration of China
- Publication
- 2023-02-22
- Effective
- 2023-06-01
- Translation
- Not prepared
- Audience
- All industries
These CAC measures govern the China standard contract mechanism for certain cross-border transfers of personal information. They provide the regulatory context for the contract, filing concept, impact assessment relationship, and parties' responsibilities.
Why it matters: The standard contract is one of the conditions referenced by PIPL Article 38 and forms part of a wider source chain that includes the PIPL, CAC measures, official contract text, and later data-flow provisions.
Open public summaryeffectiveRegulatory ProvisionSource: Verified
促进和规范数据跨境流动规定
- Authority
- Cyberspace Administration of China
- Publication
- 2024-03-22
- Effective
- 2024-03-22
- Translation
- Not prepared
- Audience
- All industries
These 2024 CAC provisions adjust and clarify parts of the cross-border data transfer framework. They address specified transfer scenarios and interact with the earlier security assessment and standard contract measures.
Why it matters: The provisions are a key later source for understanding how China's cross-border data transfer framework developed after the earlier CAC measures.
Open public summaryeffectiveRegulatory ProvisionSource: Verified
互联网信息服务算法推荐管理规定
- Authority
- Cyberspace Administration of China; Ministry of Industry and Information Technology; Ministry of Public Security; State Administration for Market Regulation
- Publication
- 2021-12-31
- Effective
- 2022-03-01
- Translation
- Not prepared
- Audience
- Internet information service providers
These provisions regulate algorithmic recommendation services used by internet information service providers. They cover service governance, user rights, transparency, content management, and filing-related regulatory concepts.
Why it matters: They are an early central source in China's algorithm governance framework and provide context for later deep-synthesis and generative-AI measures.
Open public summaryeffectiveRegulatory ProvisionSource: Verified
互联网信息服务深度合成管理规定
- Authority
- Cyberspace Administration of China; Ministry of Industry and Information Technology; Ministry of Public Security
- Publication
- 2022-11-25
- Effective
- 2023-01-10
- Translation
- Not prepared
- Audience
- Deep synthesis service providers
These provisions govern deep-synthesis internet information services, including provider responsibilities, technical support roles, content governance, security management, and labeling concepts.
Why it matters: They form a major part of the public source chain for synthetic-content governance and connect algorithm regulation with later generative-AI rules.
Open public summaryeffectiveRegulatory MeasureSource: Verified
生成式人工智能服务管理暂行办法
- Authority
- Cyberspace Administration of China and six other authorities
- Publication
- 2023-07-10
- Effective
- 2023-08-15
- Translation
- Not prepared
- Audience
- Generative AI service providers
These interim measures regulate generative artificial intelligence services provided to the public in China. The separate 2025 AI-generated and synthetic content labeling measures are now effective and form a later verified layer of the source chain.
Why it matters: They are a central public source for understanding China's generative-AI service framework and its relationship with data, personal information, and content governance.
Open public summaryguidanceOfficial Q&A / Editorial Source MapSource: Verified
重要数据识别与行业规则官方来源地图
- Authority
- Cyberspace Administration of China
- Publication
- 2025-05-30
- Effective
- Under review
- Translation
- original bilingual source map
- Audience
- Automotive; industrial; telecommunications; natural resources; statistics; regional FTZ pilots
This public record provides a source-tracked, unofficial reference summary of a verified supporting regulation.
Why it matters: The record helps readers place the document within China's wider data protection, cybersecurity, and data governance framework.
Open public summaryguidanceGuidelineSource: Verified
个人信息出境标准合同备案指南(第二版)
- Authority
- Cyberspace Administration of China
- Publication
- 2024-03-22
- Effective
- Under review
- Translation
- original bilingual practical guide
- Audience
- All industries
This public record provides a source-tracked, unofficial reference summary of a verified supporting regulation.
Why it matters: The record helps readers place the document within China's wider data protection, cybersecurity, and data governance framework.
Open public summaryguidanceFAQ / Official InterpretationSource: Verified
数据出境安全管理政策法规问答(2026年7月)
- Authority
- Cyberspace Administration of China
- Publication
- 2026-07-24
- Effective
- Under review
- Translation
- original bilingual practical guide
- Audience
- All industries
This public record provides a source-tracked, unofficial reference summary of a verified supporting regulation.
Why it matters: The record helps readers place the document within China's wider data protection, cybersecurity, and data governance framework.
Open public summaryeffectiveAdministrative RegulationSource: Verified
关键信息基础设施安全保护条例
- Authority
- State Council
- Publication
- 2021-08-17
- Effective
- 2021-09-01
- Translation
- Review pending
- Audience
- CII operators and sector regulators
This State Council regulation develops the protection framework for critical information infrastructure, including identification, operator responsibilities, protection measures, and coordination among competent authorities.
Why it matters: It provides important implementing context for the CSL's critical information infrastructure framework and related cybersecurity review requirements.
Open public summaryeffectiveDepartmental RuleSource: Verified
网络安全审查办法
- Authority
- Cyberspace Administration of China and twelve other authorities
- Publication
- 2021-12-28
- Effective
- 2022-02-15
- Translation
- Review pending
- Audience
- CII operators network platform operators and relevant procurement or listing scenarios
These measures establish the cybersecurity review framework for specified network products and services and certain data processing activities, with a focus on national security risks.
Why it matters: They connect cybersecurity, critical information infrastructure, supply-chain, data processing, and national security review concepts.
Open public summaryeffectiveRegulatory ProvisionSource: Verified
汽车数据安全管理若干规定(试行)
- Authority
- Cyberspace Administration of China; National Development and Reform Commission; Ministry of Industry and Information Technology; Ministry of Public Security; Ministry of Transport
- Publication
- 2021-08-20
- Effective
- 2021-10-01
- Translation
- Review pending
- Audience
- Automotive data processors
These trial provisions address automotive data processing, including personal information and important data generated or collected in automotive activities. This public summary uses the verified 2021 official source and does not import draft-only amendment-status claims.
Why it matters: They illustrate how China's general data and personal information rules are supplemented by sector-specific requirements.
Open public summaryeffectiveRegulatory ProvisionSource: Verified
移动互联网应用程序信息服务管理规定
- Authority
- Cyberspace Administration of China
- Publication
- 2022-06-14
- Effective
- 2022-08-01
- Translation
- Review pending
- Audience
- App providers and app distribution platforms
These provisions govern mobile internet application information services and address responsibilities of application providers and application distribution platforms.
Why it matters: They provide sector-specific context for app governance, personal information protection, content management, and platform responsibilities.
Open public summaryupcomingDepartmental RuleSource: Verified
小型个人信息处理者个人信息保护简化措施规定
- Authority
- Cyberspace Administration of China; Ministry of Public Security
- Publication
- 2026-07-24
- Effective
- 2026-09-01
- Translation
- editorial summary only
- Audience
- Personal information processors handling personal information of fewer than 100000 persons subject to stated exclusions
These joint CAC and Ministry of Public Security provisions establish proportionate personal information protection measures for eligible small processors and take effect on 1 September 2026.
Why it matters: The provisions define a fewer-than-100,000-person eligibility threshold and address simplified audit, impact-assessment and selected cross-border compliance arrangements without displacing the PIPL or national data-export rules.
Open public summaryguidanceGuidelineSource: Verified
数据出境安全评估申报指南(第三版)
- Authority
- Cyberspace Administration of China
- Publication
- 2025-06-27
- Effective
- Under review
- Translation
- editorial summary only
- Audience
- Data processors within the security assessment scope
This public record provides a source-tracked, unofficial reference summary of a verified supporting regulation.
Why it matters: The record helps readers place the document within China's wider data protection, cybersecurity, and data governance framework.
Open public summary