Skip to main content

← Data Privacy & Cybersecurity practice hub

China Inbound Legal Guides · National framework

China Data Compliance Decision Guide 2026: PIPL, Transfers & Cybersecurity

China data compliance is not one filing. A foreign business must map the activity, classify the data, test important-data and critical-infrastructure status, calculate calendar-year export volumes, select any exemption or transfer mechanism, and preserve evidence for the conclusion.

6lawyer profiles listed
Updated16 Aug 2026
AudienceForeign businesses & individuals

At a glance

Data Privacy & Cybersecurity: typical process stages

Four high-level stages — details and local variations are in the guide below.

  1. MapPersonal & important data flows
  2. BasisPIPL notices, consents, contracts
  3. TransferAssessment, SCC or certification
  4. OperateVendors, incidents, audits
City hubs

Local guides & lawyers

Drill into city × practice hubs where available, or open the city legal market guide.

China data privacy and cybersecurity · planning companion

Build a data & cyber planning brief

Use high-level, non-confidential facts to organize a China personal-information, cross-border transfer, cybersecurity or incident discussion. This companion does not determine lawfulness, approve a transfer mechanism, certify compliance or decide incident-reporting duties.

01 · Start with the processing and system facts

Build a concise, non-confidential data brief

Select the closest current state. The selections organize questions; they do not determine legal bases, transfer routes, security grades or reporting duties.

02 · A planning sequence, not a universal checklist

Move from processing map to a controlled compliance file

Requirements vary by role, data categories, systems, vendors, destinations, sector rules and current regulator practice.

  1. 01

    Map processing and systems

    Identify data categories, purposes, systems, vendors, locations and accountability owners.

  2. 02

    Test legal bases and notices

    Separate necessity, consent, employment and other bases from the UX and recordkeeping evidence.

  3. 03

    Check cross-border and security layers

    Identify transfer mechanisms under consideration, contracts, assessments and cybersecurity dependencies.

  4. 04

    Build the operational evidence file

    Document systems, access, vendors and any regulator or incident contacts.

  5. 05

    Control next steps and counsel hand-off

    Avoid unsupported public statements and prepare a non-confidential brief for counsel.

03 · Prepare before contacting counsel

Review facts that may change transfer, security or incident routes

Use this browser-only checklist for orientation. Avoid confidential or sensitive personal information.

0 of 8 preparation topics reviewed

04 · Primary sources before assumptions

Verify the current data and cyber framework

Sources reviewed 28 August 2026. Official sources are reviewed at least quarterly and after a material PIPL, CSL, DSL, cross-border-transfer, standards or regulator-practice change.

05 · Choose the next useful route

Continue with guidance, location context or professional help

Use a bounded next step; this companion is not a filing or confidential intake tool.

Use boundaries

What this companion does—and does not—do

Does this companion approve a cross-border transfer route?

No. Transfer mechanisms, assessments and contracts depend on the complete processing facts and current rules.

Should I paste personal data, logs or incident reports here?

No. The controls submit nothing. Do not enter personal information, security logs, account credentials or privileged advice.

Does selecting a city decide the compliance route?

No. National data and cyber rules still control. City hubs add operational and counsel context only.

Legal planning desk with source documents, authority records and evidence file
Working file · authority, workflow and evidence

Direct answer: start with the facts, not the name of a statute. If mainland-China data is accessible abroad, screen for personal information, sensitive personal information and important data; then test the exemptions and thresholds below. A mechanism exemption does not remove the PIPL duties that still apply. The working output should be a decision memo, evidence pack, next deadline and a short list of unresolved facts for China counsel.

National L3 — Consumer Protection (2026): Full practice guide · GT vs CBEC · 10× damages · Prepaid 2025 · 12315 SOP · Lawyers.

1. What must a foreign business decide?

Direct answer

Determine what actually crosses the mainland-China boundary, classify it, identify the people and systems involved, calculate cumulative individuals from 1 January, and test important-data, CII, sector and FTZ rules before choosing a route. Do not treat an exemption from security assessment, SCC and certification as an exemption from PIPL notice, necessity, impact-assessment, security or rights obligations.

Input factDecisionRequired outputEscalate when
Remote access, API, replication or file transferIs data made available outside mainland China?Data-flow and access mapArchitecture or recipient location is unclear
Fields, purpose and affected peoplePI, sensitive PI, non-PI or potential important data?Classification recordSector catalogue or data status is uncertain
CII status, annual counts and scenarioAssessment, SCC, certification or mechanism exemption?Route memo and calculationA threshold, exemption condition or CII status is uncertain
Notice, legal basis, necessity and controlsWhat substantive PIPL duties remain?PIPIA, notice/consent record and control evidenceNecessity or legal basis is contested
Changes to data, recipient, purpose or volumeDoes the conclusion, filing or approval remain valid?Change log and review dateActual activity drifts from the approved scope

2. China Data Route Engine

Diagram branches
  • Security assessment is the high-volume or important-data path.
  • The standard contract is the common intra-group path when thresholds allow it.
  • Certification is an alternative group mechanism, not a shortcut around facts.
  • An exemption can remove a mechanism but not notice, consent or PIPIA where they still apply.

Use this as a screening tree, not an automated legal opinion. A “yes” or “no” must be supported by the evidence shown in the right-hand column.

StepQuestionIf yesIf no / evidence
1Will data collected or generated in mainland China be accessible outside mainland China?Continue to classification.Document the architecture and access controls; apply domestic duties.
2Does it contain PI, sensitive PI or data officially identified as important?Separate each category and count PI.For non-PI/non-important data generated in listed international activities, test Article 3.
3Has the data been notified or publicly identified as important data?Security-assessment route is relevant.Article 2 says a processor need not file merely on speculation; still screen sector/local catalogues.
4Is the exporter a CII operator?PI or important-data export generally enters security assessment, subject to stated exemptions.Continue to exemptions and volumes.
5Does Article 3, 4, 5 or an approved FTZ negative-list regime apply?Record the exact exemption, facts and evidence; then complete remaining substantive duties.Calculate cumulative exports since 1 January.
6At least 1 million ordinary-PI individuals or at least 10,000 sensitive-PI individuals?Security assessment.Continue.
7At least 100,000 but below 1 million ordinary-PI individuals, or any sensitive PI below 10,000?SCC or certification, if all route conditions are met.Below 100,000 ordinary PI may qualify for Article 5(4) mechanism exemption.
8Could the facts change during the calendar year?Install a count and change-control trigger.Set a scheduled review anyway.
Threshold transition

If SCC or certification is already in use and the annual count later crosses the assessment threshold, CAC’s January 2026 Q&A says the earlier exports from that year are included in the security-assessment filing scope.

3. Statutory threshold and exemption matrix

Fact patternPreliminary routeConditions / exclusionsEvidence outputAuthority
Non-CII; below 100,000 individuals’ ordinary PI since 1 JanuaryMechanism exemption may applyNo sensitive PI in this volume exemption; important data excluded; test other exemptions/overlaysCount methodology and exemption memo2024 Provisions, Arts 5(4), 5 final paragraph
Non-CII; 100,000 to below 1 million ordinary PISCC or certificationImportant data excluded; stated exemptions prevailSCC filing or certification evidence; PIPIA2024 Provisions, Art 8
Non-CII; below 10,000 sensitive-PI individualsSCC or certificationImportant data excluded; stated exemptions prevailMechanism file; sensitivity and necessity analysis2024 Provisions, Art 8
Non-CII; at least 1 million ordinary-PI individualsCAC security assessmentCalendar-year cumulative count; stated exemptions prevailSelf-assessment and filing dossier2024 Provisions, Art 7(2)
Non-CII; at least 10,000 sensitive-PI individualsCAC security assessmentCalendar-year cumulative count; stated exemptions prevailSelf-assessment and filing dossier2024 Provisions, Art 7(2)
Important data exported by non-CII processorCAC security assessmentFirst determine whether officially notified or published as importantClassification record and dossier2024 Provisions, Arts 2, 7(2)
CII operator exports PI or important dataCAC security assessmentStated exemptions may affect resultCII confirmation and dossier2024 Provisions, Art 7(1)
Contract with individual; cross-border HR; emergencyMechanism exemption may applyTransfer must be genuinely necessary; HR route requires lawfully adopted labour rules or collective contractNecessity/HR/emergency evidence memo2024 Provisions, Arts 5(1)–(3)

Important: the threshold matrix selects among the three outbound mechanisms. Article 10 separately preserves statutory notice, separate-consent and PIPIA duties. CAC’s July 2026 Q&A adds that no consent is needed where a PIPL Article 13(1)(2)–(7) ground applies, while outbound-transfer notice remains required.

4. Annual count calculation

Diagram branches
  • Thresholds count people, not CRM rows.
  • Keep a written annual counting method.
  • Below the line, standard contract or certification may still be available.
  • Crossing the line later in the year can force a security assessment.
Calculation diagram

Ordinary PI individuals exported since 1 January + individuals in the proposed transfer not already reflected in the working count = new cumulative annual total.

Decision markers: 100,000 changes the ordinary-PI route; 1,000,000 triggers assessment. Run a separate sensitive-PI count; 10,000 triggers assessment.

Assumptions to record: reporting date; systems and recipients covered; person-level deduplication method; ordinary versus sensitive fields; historic exports from 1 January; forecast population; and any excluded activity. The national rules state the thresholds, but edge-case counting methodology should not be invented. Flag uncertain deduplication, intermittent access or combined datasets for counsel or authority guidance.

'+memo.innerHTML+'';var blob=new Blob([doc],{type:'text/html;charset=utf-8'}),url=URL.createObjectURL(blob),a=document.createElement('a');a.href=url;a.download='china-data-transfer-decision-memo-'+new Date().toISOString().slice(0,10)+'.html';document.body.appendChild(a);a.click();a.remove();setTimeout(function(){URL.revokeObjectURL(url)},1000)}); })();

5. Compare the legal routes

Diagram branches
  • The trigger is volume and data type, not the vendor’s preferred clause.
  • Security assessment usually takes the longest.
  • Filing paths differ between CAC assessment and standard-contract filing.
  • PIPIA and contracts must match the route you claim.
IssueSCCCertificationSecurity assessment
Typical useQualifying intermediate PI transfersQualifying intermediate PI transfersCII, important data or higher-volume PI
CII / important dataNot the routeNot the routeRelevant route
Principal external stepContract with recipient and filingAssessment by qualified certification institutionProvincial channel to national CAC assessment
Core internal workData map, PIPIA, notice/basis, contract controlsData map, PIPIA, notice/basis, certifiable controlsSelf-assessment, legal document and dossier
Current validityMonitor contract, filing and changed facts3-year certificate; reapply 6 months before expiry3-year result; qualifying extension request within 60 working days before expiry
Failure signalFiled scope differs from actual flowActual flow differs from certified scopePurpose, parties, scope, volume or risk changes

6. Procedural timelines

Security-assessment sequence

  1. Screen: confirm trigger, important-data status, CII status, exemptions and annual volume.
  2. Prepare: complete the self-assessment, legal document with overseas recipient and filing materials under the current guide.
  3. Submit: use the provincial CAC channel; the third-edition guide also identifies the online filing system.
  4. Assess and respond: track requests, decision and approved scope.
  5. Operate: constrain the activity to the result and maintain a change log.
  6. Renew or refile: the result lasts 3 years. If extension conditions are met, apply within 60 working days before expiry; otherwise assess whether a new filing is required.

SCC and certification sequence

Map → count → PIPIA → notice/legal basis → choose route → sign SCC and file, or apply to a qualified certifier → operate within scope → monitor threshold and factual changes. Certification certificates are valid for 3 years; a continuing user applies 6 months before expiry. Crossing the assessment threshold during the year activates the transition rule above.

Personal-information compliance audit sequence

Trigger → scope → auditor/evidence → findings → remediation → report → recurrence. A processor handling more than 10 million individuals’ PI must audit at least once every 2 years. A regulator may require an external audit for specified risks or incidents. For a regulator-required audit, submit the audit report and, after completing remediation, submit the remediation report within 15 working days.

7. Annotated evidence and document structures

PIPIA structure

SectionWhat it must establishEvidence
Activity and purposeExact flow and a clear, reasonable, directly related purposeData-flow map and business request
Data and peopleCategories, sensitivity, minimum scope and current-year countInventory and reproducible query/report
RecipientEntity, location, role, onward transfers and rights channelDue-diligence and recipient file
Necessity and proportionalityWhy the overseas access and each field are neededAlternatives/minimisation analysis
Risk and controlsLeakage, misuse, loss, onward-transfer and foreign-law riskContractual, technical and organisational controls
ConclusionRoute, duties, owner, deadline and unresolved assumptionsApproval memo and change triggers

Scenario evidence packs

ScenarioEvidence packOwnerRefresh trigger
Global HRIS / recruitmentLabour rule or collective contract, decision map, necessity, minimum fields, notice/basis, recipient controls, PIPIAHR + legal/privacyNew platform, field, recipient or decision process
CRM / marketingData dictionary, notices, recipient/vendor list, SDK map, annual count, contract and PIPIAMarketing + privacyNew vendor, campaign or SDK
Cloud / SaaSArchitecture, administrator access, subprocessors, logs, encryption, route memo and PIPIAIT/security + privacyArchitecture or support-location change
M&AData-room matrix, redaction protocol, access list, classification screen and purpose limitsDeal team + legalBidder, adviser or access scope changes
IncidentChronology, affected data/people, containment, notification analysis and evidence logSecurity + legalEach incident and material new fact

8. Practical workflow: Map → Classify → Route → Evidence → Operate & Monitor

StageQuestionMandatory output
MapWhat actually happens, including remote access?Data-flow map
ClassifyWhat is the data/activity legally?Classification and important-data screening record
RouteWhich exemption or mechanism applies?Decision memo and calculation
EvidenceCan every assumption and duty be proved?PIPIA and evidence pack
Operate & MonitorWhat change invalidates the conclusion?Control owner, annual count and change log

9. Scope and legal hierarchy

Laws — PIPL / Data Security Law / Cybersecurity Law

Administrative regulations — Network Data Security Management Regulations (effective 1 January 2025)

Departmental rules — Data Export Security Assessment Measures / SCC Measures / Personal Information Export Certification Measures

Implementation provisions — 2024 Provisions on Promoting and Regulating Cross-Border Data Flows

Procedural guidance — CAC filing guides and official Q&As

Sector and local overlays — sector catalogues, regulator requirements and approved FTZ negative lists.

The controlling layer depends on the decision. A filing guide explains procedure but does not override a law or regulation. Sector and local overlays must be screened alongside the national baseline.

10. Important Data screen

Diagram branches
  • Check sector and local important-data catalogues.
  • Ask whether compromise would affect security or public interest.
  • If the answer may be yes, do not default to a standard contract.
  • If the answer is no, write down why.
ResultQuestionAction
Confirmed designationHas an authority notified the processor or publicly identified the data?Apply the relevant important-data controls and assessment route.
Potential signalDoes a relevant sector/local catalogue or classification rule describe the dataset?Map the provision to the fields and obtain targeted advice.
Escalation signalAre facts insufficient but consequences material?Record uncertainty; seek counsel/regulator confirmation before export.

Do not label all business data “important” and do not ignore the issue. Article 2 of the 2024 Provisions supplies the disciplined middle position: identify and file as required, but do not treat data as important for filing merely because of unsupported speculation where it has not been notified or publicly identified.

11. Action checklist and risk matrix

Use Green (supported), Amber (fact dependent), Red (route/blocker), or Grey (evidence missing).

TestEvidenceOwnerEscalation / due point
All transfers and remote access mappedArchitecture and access mapITBefore design approval
PI, sensitive PI and important-data screen completeInventory and classification recordPrivacy/legalBefore route selection
CII, sector and FTZ status checkedCorporate/legal confirmationLegalBefore route selection; annual review
Annual ordinary/sensitive PI counts reproducibleQuery, assumptions and forecastPrivacy/data ownerBefore go-live; threshold alerts
Exemption conditions provedNecessity, contract/HR/emergency memoBusiness + legalBefore relying on exemption
PIPIA, notice and legal basis completeApproved PIPIA and notice/consent recordPrivacyBefore transfer
Mechanism and filing/certification completeDossier, receipt, certificate or resultLegal/privacyBefore applicable transfer
Actual activity matches scopeLogs, recipient list and change controlIT + privacyContinuous; renew/refile trigger
Audit trigger and cadence recordedPopulation count and audit calendarPrivacy/auditAnnual governance review

12. Common mistakes and corrective evidence

FailureWhy it failsCorrective evidence
“Below 100,000 means PIPL does not apply.”Mechanism exemption is not a substantive-law exemption.Separate route memo from notice, basis, PIPIA, security and rights checklist.
Counting only one recipient or systemIt can understate the calendar-year export population.Central count covering all scoped flows and documented assumptions.
Treating the HR exemption as automaticLawfully adopted rules/collective contract and genuine necessity matter.HR legal-basis and field-level necessity memo.
Ignoring overseas administrator accessRemote availability may be an outbound provision on the facts.Identity, location, purpose and access-path map.
Calling all industrial data “important”It confuses confirmed rules with speculation.Confirmed / potential / escalate classification record.
Filing once and forgettingPurpose, parties, data, volume and controls drift.Change-control log, count alert and renewal calendar.

13. What changed: 2024–2026

DateChangeOperational impact
22 Mar 2024Cross-Border Data Flow Provisions took effectCurrent national exemptions, thresholds and 3-year assessment validity framework
1 Jan 2025Network Data Security Management Regulations took effectActive administrative-regulation layer for network data processing
1 May 2025PI Protection Compliance Audit Measures took effectAudit triggers, cadence, evidence and remediation reporting
27 Jun 2025Third-edition security-assessment filing guide issuedSimplified/updated materials and extension procedure
1 Jan 2026PI Export Certification Measures took effectFormal certification scope, 3-year certificate and 6-month renewal lead
30 Jan 2026CAC route-transition Q&AExplains treatment when annual volumes cross the assessment threshold
24 Jul 2026CAC notice/consent, extension and recruitment Q&AClarifies Article 13 grounds, extension conditions and recruitment necessity

14. FAQ decision index

The detailed conditional answers are collected in the FAQ accordion below. Use this index to identify the legal test behind each question rather than treating the answer as a universal rule.

Business questionControlling factual testEvidence to review
Can employee or applicant data enter a global HRIS?Overseas necessity, Article 5(2) HR conditions, data classification and volumeLabour rules/collective contract, decision map, minimum fields and PIPIA
Does the below-100,000 category solve the issue?Non-CII status, ordinary PI only, annual cumulative population and no important dataCount methodology, classification and separate substantive-PIPL checklist
Does overseas administrator access count?Whether mainland-China data becomes accessible abroad on the actual architectureIdentity, location, permissions, logs, purpose and access-path map
SCC or certification?Eligibility plus contractual, governance and certification-operating fitPIPIA, recipient controls, filing/certification scope and change process
How are thresholds counted or crossed later?Separate calendar-year ordinary/sensitive populations and transition timingReproducible person-level count, deduplication assumptions and forecast
Is the dataset important data?Official notification or published national, sector or local identificationCatalogue mapping and recorded escalation where classification remains uncertain
Does an exemption remove notice or PIPIA?Mechanism selection versus separate PIPL substantive dutiesLegal-basis, notice/consent, PIPIA, minimisation and security records
Is a compliance audit due?Population, elapsed audit period and regulator/incident triggerPopulation record, audit calendar, findings and remediation log

15. Source cards and evidence standard

Editorial labels: Binding rule requires the current primary text and provision; Official implementation position requires a government guide or Q&A; Practice observation must identify its source/date; Editorial inference must be stated as an inference. This guide uses no borrowed infographic or unsourced enforcement chart.

Rule / statusPrecise authorityQualification
Thresholds, exemptions and assessment validity — CLEAR RULE2024 Provisions, Arts 2–10Read exemptions and substantive duties separately
Mid-year threshold transition — OFFICIAL POSITIONCAC Q&A, 30 Jan 2026, Q1Earlier annual exports enter assessment scope
Notice/consent, extension and recruitment — OFFICIAL POSITIONCAC Q&A, 24 Jul 2026, Q1–Q3Fact-dependent necessity and Article 13 grounds
Security-assessment filing — CURRENT PROCEDURECAC Filing Guide (3rd ed.), 27 Jun 2025Use current forms and filing channel
Compliance audits — CLEAR RULEAudit Measures, Arts 4–12Distinguish periodic and regulator-required audits
Export certification — CLEAR RULECertification Measures, Arts 5–10Effective 1 Jan 2026; scope must match actual flow
Network-data regulation — CLEAR RULENetwork Data Security Management RegulationsEffective 1 Jan 2025

Last primary-source check: 12 August 2026. This is a screening and evidence-design guide, not legal advice. Confirm current texts, sector rules and local practice before acting.

16. Related tools and counsel

Find data privacy and cybersecurity lawyers or request a consultation. Frame the request around the unresolved fact: CII status, important-data classification, exemption necessity, route choice, PIPIA, filing or incident response.

Legal source archive with indexed legislation and official records
Source register · primary authorities and verification
Sources & trust

How to use this guide

Primary sources checked 12 August 2026: CAC cross-border provisions and Q&As, the third-edition security-assessment filing guide, compliance-audit measures, export-certification measures, and the Network Data Security Management Regulations.

Editorial, AI and verification policies

This page is general information for orientation. It is not legal advice and does not create an attorney–client relationship.

Review the Editorial Policy, AI Content Policy, and Lawyer Verification Policy.

FAQ

Common questions

Quick answers for foreign nationals and employers. Rules vary by city and change over time.

Can China employee data go into a global HRIS?

Potentially. Map overseas access, screen sensitive PI/important data, and test whether the Article 5(2) HR exemption is supported by lawfully adopted labour rules or a collective contract and genuine necessity. Even if a mechanism exemption applies, document the PIPL basis, notice, minimisation, PIPIA and recipient controls.

Are we exempt if fewer than 100,000 people are involved?

Only potentially from the three transfer mechanisms, and only for the non-CII ordinary-PI category subject to the rule’s conditions. Sensitive PI, important data, CII, sector/local rules and substantive PIPL duties can change the answer.

Does overseas administrator access count as a transfer?

Do not decide from the system label. Record who can access which fields, from where, for what purpose and whether data becomes available abroad; then apply the current outbound-data rules to that fact pattern.

Should we use SCC or certification?

Both can serve the qualifying intermediate category. Compare contractual filing and governance fit against certification scope, institution, evidence and continuing surveillance. Neither replaces the PIPIA, notice/basis analysis or important-data screen.

How do we count people for thresholds?

Maintain separate cumulative ordinary-PI and sensitive-PI populations from 1 January across scoped transfers. State deduplication, systems, recipients, historic exports and forecast assumptions. Escalate ambiguous counting rather than inventing a rule.

What if we cross a threshold later in the year?

CAC’s January 2026 Q&A says that when SCC/certification users cross the assessment threshold, they must file and include the PI exported through those earlier routes since 1 January in the assessment scope.

How do we know whether data is important data?

Check notification and published national, sector and local catalogues. Article 2 says unsupported speculation alone does not require treating data as important for assessment filing, but uncertainty with material consequences should be documented and escalated.

Does a mechanism exemption remove notice or PIPIA duties?

No. Article 10 preserves statutory notice, consent and PIPIA duties. CAC’s July 2026 Q&A explains that Article 13(1)(2)–(7) grounds can remove the need for consent, while outbound notice remains.

When is a PI compliance audit required?

A processor handling more than 10 million individuals’ PI must conduct one at least every 2 years. Regulators may require an external audit in specified risk or incident circumstances; regulator-required remediation has a 15-working-day post-completion reporting deadline.

When should we involve China counsel?

Escalate unresolved CII or important-data classification, sector/local overlays, threshold methodology, contested necessity or legal basis, first-time assessment, regulator contact, incidents, M&A and any material mismatch between the real flow and an exemption, filing, certificate or approval.

Consultation preparation

What to prepare before contacting counsel

Send a focused first package so counsel can check conflicts, understand scope, and identify urgent deadlines.

  • A concise timeline and the result you want to achieve.
  • Names of all parties and affiliates for a conflict check.
  • Key contracts, notices, correspondence, filings, or decisions.
  • Known deadlines, preferred language, location, and budget constraints.
Directory

Data Privacy & Cybersecurity lawyer profiles

China-based listings shown first. Review profiles for data privacy & cybersecurity, then request a free initial consultation.

Status shown per profileFree initial consultationChina-first directory sort
Cross-border legal details arranged for a prepared counsel enquiry
Next route · prepared enquiry

Move from orientation to a properly prepared legal brief.

Bring the parties, objective, relevant documents, chronology, known deadlines and the decision you need counsel to make.

Prepare your legal enquiry →

Need counsel on data privacy & cybersecurity?

Review listed lawyer profiles and request a free initial consultation. No obligation.