A cross-border data transfer occurs when personal information or other regulated data collected or generated in mainland China is provided or made accessible outside the mainland.
The correct compliance path depends on the data type, scale, exporter status, recipient/use case and current CAC rules. There is no single ‘SCC route’ that works for every transfer.
5 questions before you choose the route.
This page identifies the right question and evidence. It does not determine the legal outcome on a reader’s facts.
Check personal vs important data
Identify the relevant facts, documents and operating role before choosing the route.
Decision factorCheck volume/sensitivity
Identify the relevant facts, documents and operating role before choosing the route.
Decision factorCheck cIIO/status of exporter
Identify the relevant facts, documents and operating role before choosing the route.
Decision factorCheck recipient and purpose
Identify the relevant facts, documents and operating role before choosing the route.
Decision factorCheck remote access/cloud/intra-group architecture
Identify the relevant facts, documents and operating role before choosing the route.
Decision factorWorking rule: Map the regulated role before marketing or launch in China.
The signal ledger.
These facts move the question beyond a label and into a product, money-flow and control analysis.
Bring a compact evidence docket—not a pitch deck.
Give a compliance team or counsel the operating facts that reveal the perimeter.
Questions people ask before they build.
Short answers for orientation. The right result can change with the service model and current rules.
Is every SaaS tool a “cross-border transfer”?
If personal information leaves the mainland (including to Hong Kong/Macao/Taiwan in many analyses, and to overseas SaaS regions), treat it as a potential transfer until counsel and the data map say otherwise.
Do intra-group transfers need a path?
Yes. Affiliates abroad are still overseas recipients. Parent-company access to China employee or customer data is a classic compliance trigger.
Where should I start?
Start with the CBDT roadmap and export path tool, then engage data counsel for filing strategy.
Primary authorities
Reviewed sources support orientation, not a fact-specific assessment.
Sources last checked: