Skip to main content

Data Privacy & Cybersecurity · Counsel brief · 7 min · Updated 7 Sep 2026

Cross-Border Employee and R&D Data from a Suzhou Factory After the 2024 CAC Rules

Key takeaways
  1. A foreign-invested manufacturer in Suzhou uses global HR, quality and engineering platforms hosted overseas.
  2. Production data goes to an overseas R&D center.
  3. Quality incidents may include employee names and customer information.
Cite this article
Article
Cross-Border Employee and R&D Data from a Suzhou Factory After the 2024 CAC Rules: When Is a Transfer Exempt and When Does PIPL Still Require a Compliance Route?
Author
Shen Lu
Last updated
7 Sep 2026
Publisher
China Legal Portal

Shen Lu. “Cross-Border Employee and R&D Data from a Suzhou Factory After the 2024 CAC Rules: When Is a Transfer Exempt and When Does PIPL Still Require a Compliance Route?.” China Legal Portal, updated 7 Sep 2026. https://chinalegalportal.com/cross-border-employee-rd-data-suzhou-factory-after-2024-cac-rules

A foreign-invested manufacturer in Suzhou uses global HR, quality and engineering platforms hosted overseas. Employee data goes to regional headquarters. Production data goes to an overseas R&D center. Quality incidents may include employee names and customer information.

Management hears that China's 2024 cross-border data rules relaxed the requirements for multinational manufacturing and HR transfers.

The company concludes that all factory data can now be exported freely.

The issue

Personal-information processing must have a lawful basis and comply with the rules that apply to the data, purpose, recipient and transfer route. Cross-border or sensitive-data scenarios can trigger additional conditions.

The Business Impact

Map the data set, purpose, controller/processor roles, transfer path and security measures before collection or export. The practical risk usually sits in a processing or transfer step that lacks the required basis, notice or control.

That conclusion is unsafe.

The specific issue is: how should a foreign-invested manufacturer classify employee and R&D data to determine whether a transfer is exempt from security assessment, standard contract or certification, while still complying with the Personal Information Protection Law?

1. The 2024 rules simplify routes, not all obligations

The CAC Provisions on Promoting and Regulating Cross-Border Data Flows took effect March 22, 2024.[1]

They adjust when security assessment, standard contract or certification is required.

They do not repeal PIPL.

2. Article 3 manufacturing exemption

Article 3 provides an exemption for data collected and generated in activities such as international trade, cross-border transportation, academic cooperation, multinational manufacturing and marketing where the data transferred overseas does not contain personal information or important data.[1]

Key words:

  • no personal information;
  • no important data.

The company must classify.

3. Production data can contain personal information

Example: machine log includes:

  • operator ID;
  • badge number;
  • shift;
  • quality error.

That can be personal information.

Do not label entire dataset non-personal.

4. R&D data can contain important data

The company should identify whether regulators have notified or published classifications applicable to its sector.

Article 2 of 2024 rules states that data handlers need not treat data as important data for outbound security assessment if it has not been identified or publicly issued as important data by relevant departments or regions.[1]

Document this analysis.

5. Employee HR exemption

Article 5 provides an exemption where outbound employee personal information is necessary for cross-border HR management under lawfully adopted labor rules or collective contracts.[1]

This is useful for global HRIS.

But necessity matters.

6. HR exemption is not unlimited

Examples likely related:

  • payroll;
  • benefits;
  • performance;
  • global mobility.

Less clearly necessary:

  • unrelated analytics;
  • marketing;
  • broad employee monitoring.

Classify purpose.

7. PIPL lawful processing

PIPL requires a legal basis and compliance with principles of legality, legitimacy, necessity and good faith.[2]

Even if no cross-border filing is required, the employer must comply with PIPL processing rules.

8. Notice

Employees should receive privacy notices explaining:

  • categories;
  • purposes;
  • recipients;
  • overseas transfer.

9. Sensitive personal information

PIPL imposes additional requirements for sensitive personal information.[2]

Employee data may include:

  • health;
  • biometrics;
  • financial.

Apply stricter controls.

10. Overseas recipient management

PIPL requires personal information processors to take steps to ensure overseas recipients meet protection standards where cross-border provision occurs.[2]

Use data-transfer agreements and oversight.

11. Data mapping

Create system map:

  • Workday/HRIS;
  • ERP;
  • MES;
  • PLM;
  • QMS;
  • CRM.

For each:

  • data;
  • people;
  • destination;
  • purpose.

12. Separate personal and non-personal fields

Where possible:

  • pseudonymize;
  • remove names;
  • aggregate.

This can bring manufacturing analytics within exemption.

13. R&D collaboration

Before sending engineering data:

  • identify personal info;
  • important data;
  • trade secrets;
  • export controls.

Data compliance is not only privacy.

14. Semiconductor example

Wafer process data may appear non-personal.

But logs may identify engineers.

Remove identifiers where unnecessary.

15. Biomedicine example

Clinical or health data may be sensitive personal information.

Do not rely on manufacturing exemption.

16. Thresholds

The 2024 rules adjust thresholds for security assessment and standard-contract/certification routes.[1]

The company should count personal information transfers over relevant period.

Maintain transfer inventory.

17. CIIO

Critical information infrastructure operators face stricter rules.

Determine status.

18. Important data

Important data outbound can trigger security assessment.[1]

Do not self-declare casually.

19. Free trade zone negative lists

2024 rules permit FTZ negative-list mechanisms.[1]

If relevant to the entity, review current local implementation.

20. M&A data room

Cross-border diligence may involve employee data.

Minimize:

  • names;
  • ID;
  • health.

Use redaction.

21. Internal investigation data

HR exemption may not automatically cover investigation data.

Assess separately.

22. Global whistleblower hotline

Cross-border handling of complaint information can involve personal and sensitive data.

Design process.

23. Vendor SaaS

If overseas SaaS processes employee data:

  • contract;
  • security;
  • subprocessors.

24. Remote access

Overseas access can constitute outbound provision depending on facts.

Include remote access in map.

25. Data localization myths

China does not require every corporate dataset to be localized.

But regulated transfers require analysis.

26. 30-day compliance project

Week 1: system inventory.

Week 2: classification.

Week 3: transfer route.

Week 4: contracts/notices.

27. Case study

Suzhou automotive supplier sends MES data to Germany.

Data includes operator badge.

Solution: remove badge for analytics, separate HR transfer.

28. Case study

Global HR platform.

Employee records needed for compensation and mobility.

Assess Article 5 exemption plus PIPL compliance.

29. Evidence

Maintain:

  • data map;
  • legal analysis;
  • contracts;
  • notices;
  • threshold counts.

30. Security

Encrypt, access control, retention.

31. Incident plan

If overseas recipient breached:

  • notify;
  • investigate;
  • assess regulatory duties.

32. Trade secret overlay

R&D data may be valuable confidential information.

Use confidentiality protection.

33. Export-control overlay

Technical data may implicate export-control laws in some cases.

Data transfer team should flag.

34. Governance

Create cross-border data committee:

  • legal;
  • IT;
  • HR;
  • R&D.

35. New system intake

No new overseas system without data review.

36. Final test

Ask:

what exact fields leave China, why are they needed, and which legal category does each field fall into?

If answer is “factory data,” classification is inadequate.

Additional implementation detail: data-field classification

The most effective compliance exercise is to classify fields rather than whole databases. A manufacturing table can contain machine temperature, product serial number, operator name and customer ID. These fields may fall into different legal categories.

The company should document whether each field is personal information, sensitive personal information, important data, trade secret or ordinary business data. The outbound route can then be designed around the highest-risk fields rather than the system label.

Additional implementation detail: transfer minimization

If headquarters needs production analytics, remove employee identifiers before export. If global HR needs compensation data, do not include unrelated disciplinary or medical information. If R&D needs failure analysis, consider pseudonymizing customer identifiers.

Minimization can reduce both compliance burden and cybersecurity risk.

Additional implementation detail: overseas recipient controls

Contracts with overseas affiliates and SaaS providers should address purpose limitation, security, retention, onward transfer, incident notification and deletion. Access rights should be periodically reviewed.

The company should also maintain an outbound transfer ledger showing destination, purpose, data categories, volume and legal route. This is critical for threshold calculations.

Additional implementation detail: governance

Create a policy that requires privacy/legal review for any new overseas IT system or R&D collaboration. Procurement should not sign SaaS contracts before the data route is approved.

A 2024 exemption is useful only if the company can prove that its factual transfer fits the exemption.

Conclusion

The 2024 CAC rules materially simplify cross-border data compliance for multinational manufacturing and HR, but only when statutory conditions are met.

The practical principle is:

use exemptions at the data-field and purpose level, not as a blanket label for the company.


Operational appendix: implementation controls

This issue should be managed through a written project tracker rather than informal email. For each legal requirement, assign an owner, evidence file, deadline, decision status and escalation trigger. Management should distinguish legal requirements, commercial preferences and unresolved factual assumptions. That distinction reduces the risk that a business assumption is later treated as a legal conclusion.

The legal file should preserve the facts supporting each decision. If the company relies on an exemption, transfer mechanism, termination basis, ownership position or contractual remedy, retain the documents and analysis showing why. A later dispute or regulatory review often turns on evidence of what the company knew and how it reached the decision.

Before implementation, counsel should conduct a final consistency review across corporate documents, employment records, contracts, data systems and external communications. Many failures occur because separate workstreams use inconsistent dates, entities or descriptions. One master chronology and one controlled document set should be used.

After implementation, schedule a post-completion audit. Confirm that registrations, payments, system access, notices, records and contractual actions were actually completed. Legal projects fail when signed documents do not become operational reality.

[1] CAC Provisions on Promoting and Regulating Cross-Border Data Flows: https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm [2] Personal Information Protection Law: https://www.npc.gov.cn/npc/c2/c30834/202108/t20210820_313088.html

READER DISCUSSION

Discussion

Share experience or questions about this topic. This is a public discussion — not legal advice. Do not post confidential case details.

Have a question after reading? Leave it here, or Ask a Lawyer for a free initial intake.

Comments are moderated. China Legal Portal is a directory and information resource; no attorney–client relationship is formed by posting here.

End of brief

Shen Lu, Data Privacy & Cybersecurity lawyer

Author

Shen Lu

Suzhou Zhiming Law Firm · Data Privacy & Cybersecurity

Suzhou Zhiming Law Firm · Verified listing. This insight is educational and does not create an attorney–client relationship.

View lawyer profile

Data Privacy & Cybersecurity

Need a next step?

Take a focused intake, or browse listed data privacy & cybersecurity practitioners.

Submit an initial enquiry Find listed counsel

In the library

Go deeper on this topic

Educational information only — not legal advice. Laws change; consult qualified counsel for your situation. No attorney–client relationship is formed by using this site.

Disclaimer Editorial policy AI content policy