Data Protection in China

Transfer of personal data in China

If a data controller wishes to share, disclose or otherwise transfer any personal information to a third party (including group companies), the data controller must:

  • if the third party is a separate data controller, inform the data subject of the purposes of the sharing, disclosure or transfer of the personal information the types of data shared, the name and contact information of the recipient, and obtain prior separate consent from the data subject;
  • perform a personal information protection impact assessment (PIPIA), and take effective measures to protect the data subjects according to the assessment results (e.g. putting in place a data transfer agreement or similar contractual protections) (see Collection & Processing)
  • record accurately and keep the information in relation to the sharing, disclosure or transfer of the personal information, including the date, scale, purpose and basic information of the data recipient of the sharing or assigning;
  • ensure personal information is only transferred where required for processing purposes; not share or transfer any personal biometric information or other types of particularly sensitive personal information where prohibited under relevant laws or regulations; and
  • ensure contractual measures are entered into to require the data processor to comply or assist the data controller in complying with obligations under data protection laws.

Cross-border transfers

Most personal information can be transferred or accessed outside of the PRC providing the following compliance steps are taken:

  • the data controller has completed one of the following mechanisms to legitimize overseas data transfer, unless the transfer is exempted from such requirement - for details please see below:
    • the data controller has passed a CAC security assessment;
    • the data controller has obtained certification from a CAC-accredited agency; or
    • the data controller has put in place CAC standard contractual clauses (SCCs) with the data recipient and filed the signed SCCs with the local CAC together with a cross-border transfer specific PIPIA report;
  • the data controller has adopted necessary measures to ensure the data recipient's data processing activities comply with standards comparable to those set out in the PIPL. In practice this means initial due diligence, sufficient contractual protections and ongoing monitoring etc.;
  • notice and separate, explicit consent has been given / obtained from the data subjects (see Collection & Processing); and
  • a PIPIA has been conducted (see Collection & Processing).

1. Exempted Transfers

According to the Regulations on Facilitating and Regulating the Cross–border Data Transfers, the following cross-border data transfers are exempted from having to follow any one of the legitimising mechanisms above ("Exempted Transfers”):

  • Collection outside of PRC the personal information being transferred outside of PRC was originally collected and generated outside of PRC and thereafter imported back into PRC, and the processing of such personal information within PRC does not involve any personal information or important data that is collected from or generated in PRC;
  • Cross-border HR management: the transfer is necessary for implementing cross-border human resource management in accordance with legally formulated employment policies and procedures or legally executed collective contracts;
  • Cross-border contract: the transfer is necessary for concluding or performing a contract between the data subject and the data controller (e.g. those contracts that relate to cross-border shipping, logistics, remittance, payments, bank account opening, flight and hotel booking, visa applications, examination services etc.); or
  • Emergency situation: the transfer is necessary for protecting the life, health or property security of any natural person under emergency circumstances.

Exempted Transfers 2 (cross-border HR management) and 3 (cross-border contracts) above rely on a “necessity” test. This means the data controller must prove that the cross-border data transfer is necessary in order for the exemption to apply. However, it remains unclear as to what would constitute a necessary basis for the cross-border transfer of personal information.

After carving out all the Exempted Transfers, the data controller shall determine the applicable mechanisms to legitimise the remainder of the personal information to be transferred (i.e. excluding the exempted personal information) as follows:

2. CAC security assessment

According to the Regulations on Facilitating and Regulating the Cross–border Data Transfers, a CAC security assessment is required for data controllers who meet any of the following thresholds:

  • a data controller intends to transfer any "important data" overseas;
  • a critical information infrastructure operator (CIIO) intends to transfer any personal information overseas;
  • a data controller intends to transfer non-sensitive personal information of more than 1,000,000 data subjects overseas since 1 January of the year when the calculation is conducted; or
  • a data controller intends to transfer sensitive personal information of more than 10,000 data subjects overseas since 1 January of the year when the calculation is conducted.

The CAC security assessment involves the data controller completing a self–assessment of its cross-border data transfers, which must then be submitted for approval by both the local and national CAC. It primarily assesses the impact of overseas transfers on national security, public interest, and the legitimate rights and interests of individuals or organisations. The Guidelines on Application of Security Assessment of Cross-border Data Transfers (Third Edition) (effective from 27 June, 2025) provide detailed guidance on how to prepare the application materials.

If the CAC security assessment is passed, the data controller will be granted a written approval. Such approval will be valid for 3 years and could be extended for another 3 years upon approval by both the local and national CAC, provided the data controller has made no change to its previously approved cross-border transfers.

3. China SCCs

According to the Regulations on Facilitating and Regulating the Cross–border Data Transfers, a China SCCs filing with the CAC is required for data controllers who meet any of the following thresholds:

  • a data controller intends to transfer non-sensitive personal information of between 100,000 and 1,000,000 data subjects overseas since 1 January of the year when the calculation is conducted; or
  • a data controller intends to transfer sensitive personal information of fewer than 10,000 data subjects overseas since 1 January of the year when the calculation is conducted.

For PRC data controllers that must follow the China SCCs filing route, they must put in place the China SCCs with the overseas data recipient, and then within 10 working days after the effectiveness of the China SCCs file a copy of the signed SCCs together with the corresponding PIPIA with the local CAC.

The Measures for the Standard Contract for the Outbound Transfer of Personal Information and the Guidelines on the Filing of Standard Contracts for the Outbound Transfer of Personal Information (Second Edition) provide clarification on how the SCCs may be implemented by data controllers as one of the mechanisms for overseas data transfer under the PIPL, how to prepare the corresponding PIPIA by using the standard template formulated by the CAC and the procedures for filing the signed SCCs and the PIPIA report.

4. CAC certification

According to the Measures for the Certification of the Outbound Transfer of Personal Information, from 1 January 2026, data controllers who should go through the China SCCs to legitimise their cross-border transfers will have the option of obtaining certification instead. However, as the certification requirements and standards are not yet fully established, and there is uncertainty about how a certification institution's approach may affect the certification results, many data controllers are still adopting a relatively cautious attitude towards this option.

5. Transfer of personal information within the Greater Bay Area

Given the close integration of cities within the Guangdong–Hong Kong–Macao Greater Bay Area (GBA), and that data flows between Hong Kong and other cities within the GBA are becoming increasingly frequent, the CAC and the Innovation, Technology and Industry Bureau of the Government of the Hong Kong Special Administrative Region (ITIB) and Office of the Privacy Commissioner for Personal Data, Hong Kong (PCPD) together formulated the Standard Contract for Cross-boundary Flow of Personal Information Within the Guangdong– Hong Kong–Macao Greater Bay Area (Mainland, Hong Kong) (GBA SCCs).

In addition to complying with other general data protection requirements (e.g. notice, consent and impact assessment, etc.) if the data controller and the data recipient are registered in Guangzhou, Shenzhen, Zhuhai, Foshan, Huizhou, Dongguan, Zhongshan, Jiangmen, Zhaoqing or Hong Kong SAR, they may consider signing the GBA SCCs to legitimize the transfer and file the signed GBA SCCs with the Guangdong CAC and PCPD.

6. Free Trade Zone rules

The Regulations on Facilitating and Regulating the Cross–border Data Transfers provides that Free Trade Zones (FTZs) have the authority to create their own lists of data, the cross-border transfer of which may require CAC security assessment, China SCCs or CAC certification.

Between 2024 and 2025, FTZs in Tianjin, Beijing, Fujian, Shanghai, Jiansu, Chongqing, Zhejiang, and Hainan each published its own "positive data list" or "negative data list" and also set out rules for handling cross-border transfers of data falling into or outside of the lists. In general, FTZs have relatively large discretion when implementing the rules, which may make case by case negotiations with the FTZs necessary.

Transfers to overseas judicial or law enforcement authorities

If an individual or organization wants to provide any data stored in the PRC to an overseas judicial or enforcement authority, it must obtain the approval of the Ministry of Justice in advance.

Continue reading

  • no results

Previous topic
Back to top