Direct answer

A cross-border data transfer occurs when personal information or other regulated data collected or generated in mainland China is provided or made accessible outside the mainland.

The correct compliance path depends on the data type, scale, exporter status, recipient/use case and current CAC rules. There is no single ‘SCC route’ that works for every transfer.

The classification screen

5 questions before you choose the route.

This page identifies the right question and evidence. It does not determine the legal outcome on a reader’s facts.

01

Check personal vs important data

Identify the relevant facts, documents and operating role before choosing the route.

Decision factor
02

Check volume/sensitivity

Identify the relevant facts, documents and operating role before choosing the route.

Decision factor
03

Check cIIO/status of exporter

Identify the relevant facts, documents and operating role before choosing the route.

Decision factor
04

Check recipient and purpose

Identify the relevant facts, documents and operating role before choosing the route.

Decision factor
05

Check remote access/cloud/intra-group architecture

Identify the relevant facts, documents and operating role before choosing the route.

Decision factor

Working rule: Map the regulated role before marketing or launch in China.

What changes the answer

The signal ledger.

These facts move the question beyond a label and into a product, money-flow and control analysis.

Signal
Ask the operating question
Why it changes the route
Personal vs important data
How does the matter involve personal vs important data?
This operating fact can change the applicable legal route, evidence and next step.
Volume/sensitivity
How does the matter involve volume/sensitivity?
This operating fact can change the applicable legal route, evidence and next step.
CIIO/status of exporter
How does the matter involve cIIO/status of exporter?
This operating fact can change the applicable legal route, evidence and next step.
Recipient and purpose
How does the matter involve recipient and purpose?
This operating fact can change the applicable legal route, evidence and next step.
Remote access/cloud/intra-group architecture
How does the matter involve remote access/cloud/intra-group architecture?
This operating fact can change the applicable legal route, evidence and next step.
Prepare before you escalate

Bring a compact evidence docket—not a pitch deck.

Give a compliance team or counsel the operating facts that reveal the perimeter.

01Data flow mapInclude this in the compact fact file for review.
02Data categories/volumesInclude this in the compact fact file for review.
03Recipient listInclude this in the compact fact file for review.
04PIPIA/DPIAInclude this in the compact fact file for review.
05Contracts and current transfer-mechanism documentsInclude this in the compact fact file for review.
Common confusions

Questions people ask before they build.

Short answers for orientation. The right result can change with the service model and current rules.

Is every SaaS tool a “cross-border transfer”?

If personal information leaves the mainland (including to Hong Kong/Macao/Taiwan in many analyses, and to overseas SaaS regions), treat it as a potential transfer until counsel and the data map say otherwise.

Do intra-group transfers need a path?

Yes. Affiliates abroad are still overseas recipients. Parent-company access to China employee or customer data is a classic compliance trigger.

Where should I start?

Start with the CBDT roadmap and export path tool, then engage data counsel for filing strategy.

Primary authorities

Reviewed sources support orientation, not a fact-specific assessment.

Sources last checked: