{"id":24234,"date":"2025-11-28T06:23:07","date_gmt":"2025-11-28T06:23:07","guid":{"rendered":"https:\/\/msadvisory.com\/?p=24234"},"modified":"2026-04-20T11:31:00","modified_gmt":"2026-04-20T11:31:00","slug":"cross-border-data-transfer-china","status":"publish","type":"post","link":"https:\/\/msadvisory.com\/cross-border-data-transfer-china\/","title":{"rendered":"Cross-Border Data Transfer in China: Latest CAC Rules and Compliance Framework"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"24234\" class=\"elementor elementor-24234\" data-elementor-post-type=\"post\">\n\t\t\t\t<div class=\"elementor-element elementor-element-fe0d10f e-flex e-con-boxed e-con e-parent\" data-id=\"fe0d10f\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-e7f427d elementor-widget elementor-widget-text-editor\" data-id=\"e7f427d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Cross-border data transfer in China has become a hot topic in recent years due to the country&#8217;s strict regulations and policies regarding data privacy and security. However, However, the March 2024 reforms have made it easier for businesses to transfer data overseas where they have a good reason.\u00a0<\/p><p>We explain how cross-border data transfers are regulated in China and summarise the March 2024 CAC reforms, which remain the current framework in 2026.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-521b5b1 elementor-widget elementor-widget-text-editor\" data-id=\"521b5b1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<h2>Overview of Cross-Border Data Transfer Regulations in China<\/h2><p>Three main laws govern data transfer in China. The key elements of each are explained below.<\/p><h3>1. Personal Information Protection Law (PIPL)<\/h3><p>Enacted in 2021, the PIPL sets out <a href=\"https:\/\/www.education.gov.au\/download\/14672\/chinas-personal-information-protection-law\/30396\/chinas-personal-information-protection-law\/pdf\" target=\"_blank\" rel=\"noopener\">comprehensive rules for processing personal information within China<\/a> and transferring personal information outside of China. <strong>It requires any transfer of personal information outside of China ensure equivalent data protection as provided under Chinese law<\/strong>. This can be achieved by obtaining certification under approved standards, entering into standard contractual clauses, or passing a security assessment by the Chinese authorities.<\/p><p>Additionally, companies are required to conduct a security assessment to ensure that the transfer does not pose any risks to national security or the public interest.<\/p><p><strong>The regulations cross-border transfer regulations have recently been relaxed.\u00a0<\/strong><\/p><h3>2. Data Security Law (DSL)<\/h3><p>Implemented in 2021, the DSL emphasizes the <a href=\"https:\/\/msadvisory.com\/china-social-security-system\/\" data-wpil-monitor-id=\"571\">security and control of data processed and generated in China<\/a>. It categorizes data based on its importance to national security, economic development, and social public interests, imposing stricter controls on &#8220;important data&#8221; and &#8220;core data.&#8221;<\/p><h3>3. Cybersecurity Law (CSL)<\/h3><p>Since 2017, the CSL has been China&#8217;s foundational cybersecurity and data protection legislation. It requires critical information infrastructure operators (CIIOs) to store personal information and important data collected and generated in China within the country.Cross-border transfer is permissible but subject to a stringent security assessment.<\/p><p>Companies that fail to comply may face fines, suspension of operations, or, in severe cases, criminal charges.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e448895 elementor-widget elementor-widget-text-editor\" data-id=\"e448895\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<h2>March 2024 Changes to the Data Transfer Regulations<\/h2><p>The Cyberspace Administration of China (CAC) issued <a href=\"https:\/\/www.whitecase.com\/insight-alert\/china-released-new-regulations-ease-requirements-outbound-cross-border-data-transfers\" target=\"_blank\" rel=\"noopener\">updated regulations on March 22, 2024<\/a> which continue to form the core compliance framework for cross-border data transfers in 2026.\u00a0These regulations <strong>introduce several <a href=\"https:\/\/msadvisory.com\/revision-to-china-corporate-law-key-changes-and-implications\/\" data-wpil-monitor-id=\"569\">key changes to ease businesses<\/a>&#8216; compliance burden<\/strong> while safeguarding sensitive information. The key changes are outlined below.<\/p><h3>1. Exemptions\u00a0<\/h3><p>The Regulations <a href=\"https:\/\/www.hoganlovells.com\/en\/publications\/china-finalizes-its-provisions-to-promote-and-regulate-cross-border-data-transfers\" target=\"_blank\" rel=\"noopener\">exempt certain categories of data transfers from stringent checks<\/a> if they do not include sensitive or significant personal information. For instance,<b> data involved in international trade, academic cooperation, and other specific activities are exempt<\/b> unless classified as &#8220;important data.&#8221; Personal information collected and processed outside mainland China is exempt as long as no sensitive domestic data is involved.<\/p><h3>2. Thresholds for Data Transfers<\/h3><p>The regulations now provide clearer guidance on what constitutes &#8220;important data&#8221; and modify the thresholds for when a security assessment by the CAC is required. Notably, <a href=\"https:\/\/www.reedsmith.com\/en\/perspectives\/2024\/03\/new-rules-adopted-for-crossborder-transfer-of-data-out-of-china\" target=\"_blank\" rel=\"noopener\">the threshold for general personal information has been raised<\/a>, reducing the instances where a security assessment is needed.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-345269c elementor-widget elementor-widget-text-editor\" data-id=\"345269c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><strong>Indicative thresholds and mechanisms for cross-border data transfers (2024 CAC rules, applicable in 2026)<\/strong><\/p><table><thead><tr><th>Data transfer scenario (non-CIIO)<\/th><th>Volume of personal information per calendar year<\/th><th>Typical CAC mechanism under the current framework\u00a0<\/th><th>Practical implication for businesses<\/th><\/tr><\/thead><tbody><tr><td>Low-volume, non-sensitive personal information<\/td><td>Non-sensitive personal information of fewer than 100,000 individuals, with no important data and no sector-specific rules triggered<\/td><td>No CAC security assessment, Standard Contract filing or certification required (but PIPL obligations still apply)<\/td><td>Many day-to-day cross-border transfers may fall into this category, reducing procedural burden while still requiring a lawful basis, transparency and appropriate safeguards.<\/td><\/tr><tr><td>Medium volume or limited sensitive personal information<\/td><td>Non-sensitive personal information of 100,000\u20131,000,000 individuals, or sensitive personal information of fewer than 10,000 individuals<\/td><td>Standard Contract filing or Personal Information Protection Certification usually required; no CAC-led security assessment in most cases<\/td><td><a href=\"https:\/\/msadvisory.com\/establishing-a-company-in-china-a-comparison-of-china-company-structures\/\" data-wpil-monitor-id=\"570\">Companies need structured<\/a> contracts or certifications but avoid the most onerous CAC assessment, making ongoing operations more manageable.<\/td><\/tr><tr><td>High-volume or important data<\/td><td>Important data transfers, non-sensitive personal information of more than 1,000,000 individuals, or sensitive personal information of more than 10,000 individuals<\/td><td>Mandatory CAC security assessment for cross-border data transfers<\/td><td>Reserved for the riskiest transfers; firms must plan for longer timelines, heavier documentation and close coordination with regulators.<\/td><\/tr><tr><td>Exempt scenarios (safe harbours)<\/td><td>Various volumes, where specific exemption conditions are satisfied (for example, contract performance, HR management, emergency protection, or certain Free Trade Zone negative list scenarios)<\/td><td>No security assessment, Standard Contract filing or certification required, even if volumes are otherwise high, provided exemption criteria and PIPL obligations are fully met<\/td><td>Businesses can design data flows to fall within exemptions (for example, HR and contract-based transfers), but must still document necessity, consent where needed, and risk assessments.<\/td><\/tr><\/tbody><\/table>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-349e075 elementor-widget elementor-widget-text-editor\" data-id=\"349e075\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<h3>3. Special Rules for Free Trade Zones (FTZs)<\/h3><p><a href=\"https:\/\/msadvisory.com\/china-2021-free-trade-zones-update\/\">FTZs<\/a> can create <a href=\"https:\/\/www.reedsmith.com\/en\/perspectives\/2024\/03\/new-rules-adopted-for-crossborder-transfer-of-data-out-of-china\" target=\"_blank\" rel=\"noopener\">negative lists<\/a> that specify the types of data subject to export requirements, which can simplify compliance for companies operating within these zones.<\/p><h3>4. Standard Contracts and Personal Information Protection Certification<\/h3><p>For data transfers involving the sensitive personal information of more than 10,000 individuals and general personal information of more than 1,000,000 individuals, a standard contract must be filed, or a personal information protection certification must be obtained. However, <b>these requirements are relaxed for less sensitive or fewer data subjects<\/b>.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a90fbad elementor-position-left elementor-vertical-align-middle elementor-position-top speak-expert-new elementor-widget elementor-widget-image-box\" data-id=\"a90fbad\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image-box.default\">\n\t\t\t\t\t<div class=\"elementor-image-box-wrapper\"><figure class=\"elementor-image-box-img\"><a href=\"https:\/\/msadvisory.com\/contact\/\" tabindex=\"-1\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/msadvisory.com\/wp-content\/uploads\/2024\/03\/shanghai-china.jpeg\" class=\"attachment-full size-full wp-image-21671\" alt=\"Shanghai China\" srcset=\"https:\/\/msadvisory.com\/wp-content\/uploads\/2024\/03\/shanghai-china.jpeg 1024w, https:\/\/msadvisory.com\/wp-content\/uploads\/2024\/03\/shanghai-china-300x169.jpeg 300w, https:\/\/msadvisory.com\/wp-content\/uploads\/2024\/03\/shanghai-china-768x432.jpeg 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure><div class=\"elementor-image-box-content\"><div class=\"elementor-image-box-title\"><a href=\"https:\/\/msadvisory.com\/contact\/\">Clarify Your Data Transfer Requirements<\/a><\/div><p class=\"elementor-image-box-description\">Unsure whether your data export falls under an exemption, SCC filing, or CAC assessment? MSA reviews your data flows and gives you a clear compliance path. Request a consultation.\n<span>Message &nbsp;\u2192<\/span><\/p><\/div><\/div>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f73cbc6 elementor-widget elementor-widget-text-editor\" data-id=\"f73cbc6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>China&#8217;s data residency requirements restrict cross-border transfer of personal information and business data significantly\u2014a framework creating operational friction for multinational companies accustomed to global data sharing norms. Local-processing requirements add infrastructure cost and complexity. <a href=\"https:\/\/msadvisory.com\/service\/accounting-tax-filing\/\">accounting &#038; tax filing<\/a> help design data infrastructure compliant with residency restrictions. MSA Asia ensures your systems align with local law. <a href=\"https:\/\/msadvisory.com\/contact\/\">Have a conversation<\/a> about data transfer compliance.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Cross-border data transfer in China has become a hot topic in recent years due to the country&#8217;s strict regulations and policies regarding data privacy and security. However, However, the March 2024 reforms have made it easier for businesses to transfer data overseas where they have a good reason.\u00a0 We explain how cross-border data transfers are [&hellip;]<\/p>\n","protected":false},"author":19,"featured_media":24326,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"iawp_total_views":456,"footnotes":""},"categories":[131],"tags":[],"class_list":["post-24234","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-legal"],"acf":[],"_links":{"self":[{"href":"https:\/\/msadvisory.com\/wp-json\/wp\/v2\/posts\/24234","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/msadvisory.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/msadvisory.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/msadvisory.com\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/msadvisory.com\/wp-json\/wp\/v2\/comments?post=24234"}],"version-history":[{"count":12,"href":"https:\/\/msadvisory.com\/wp-json\/wp\/v2\/posts\/24234\/revisions"}],"predecessor-version":[{"id":47438,"href":"https:\/\/msadvisory.com\/wp-json\/wp\/v2\/posts\/24234\/revisions\/47438"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/msadvisory.com\/wp-json\/wp\/v2\/media\/24326"}],"wp:attachment":[{"href":"https:\/\/msadvisory.com\/wp-json\/wp\/v2\/media?parent=24234"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/msadvisory.com\/wp-json\/wp\/v2\/categories?post=24234"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/msadvisory.com\/wp-json\/wp\/v2\/tags?post=24234"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}