Skip to main content
Data Privacy & Cybersecurity

10 min read Last reviewed 2 Aug 2026

Cross-Border Transfer of Personal Information Under China's PIPL

Tongyu Yan explains the PIPL routes for transferring personal information outside China: security assessments, standard contract clauses and certification.

Statute Art. 38
Cross-Border Transfer of Personal Information Under China PIPL

Every multinational operating in China eventually confronts the same question: how can our Chinese entity lawfully move employee, customer, or vendor data to overseas headquarters, group IT systems, or foreign service providers? Under the Personal Information Protection Law of the People's Republic of China (PIPL), which took effect on 1 November 2021, the answer is a structured one. Chapter 3 of the PIPL establishes the legal framework for providing personal information to recipients outside the mainland, and the implementing rules issued since 2022 have turned that framework into a practical, enforceable compliance toolkit. In my practice advising foreign-invested enterprise groups in Shanghai on data compliance, virtually every cross-border engagement begins with the three lawful pathways set out in Article 38 of the PIPL: the security assessment organized by the Cyberspace Administration of China (CAC), personal information protection certification, and the standard contract.

Every multinational operating in China eventually confronts the same question: how can our Chinese entity lawfully move employee, customer, or vendor data to overseas headquarters, group IT systems, or foreign service providers? Under the Personal Information Protection Law of the People's Republic of China (PIPL), which took effect on 1 November 2021, the answer is a structured one. Chapter 3 of the PIPL establishes the legal framework for providing personal information to recipients outside the mainland, and the implementing rules issued since 2022 have turned that framework into a practical, enforceable compliance toolkit. In my practice advising foreign-invested enterprise groups in Shanghai on data compliance, virtually every cross-border engagement begins with the three lawful pathways set out in Article 38 of the PIPL: the security assessment organized by the Cyberspace Administration of China (CAC), personal information protection certification, and the standard contract.

The stakes are considerable. A cross-border transfer that lacks a valid legal basis exposes the exporting entity to corrective orders, suspension of processing, confiscation of unlawful gains, and administrative fines of up to RMB 50 million or five percent of prior-year turnover for serious violations under Article 66 of the PIPL. Beyond penalties, a blocked transfer path can paralyze global human resources systems, shared IT platforms, and customer relationship tools that the entire business depends on. This article explains how the rules operate in practice — which pathway applies to which data volumes and processor profiles, what each pathway demands in documentation and procedure, and the obligations that apply regardless of the route chosen.

Background & legal framework

The Three Lawful Pathways Under Article 38 of the PIPL

Article 38 provides that a personal information processor that genuinely needs to provide personal information to an overseas recipient because of business or other needs must satisfy at least one of four conditions. The first is passing a security assessment organized by the CAC as required by Article 40, which applies to critical information infrastructure operators and processors handling personal information at volumes specified by the CAC. The second is obtaining personal information protection certification from a professional institution in accordance with CAC rules. The third is concluding a contract with the overseas recipient using the standard contract formulated by the CAC, which must stipulate the rights and obligations of both parties and require the processor to supervise the recipient's processing activities so that they meet the protection standards of the PIPL. The fourth is a catch-all: any other conditions prescribed by laws, administrative regulations, or the CAC.

The fourth condition matters more than it may appear. It is the hook through which the CAC has introduced exemptions and facilitations — most importantly in the Provisions on Promoting and Regulating Cross-Border Data Flows, effective 22 March 2024 — as well as the negative-list approach piloted in free trade zones such as Shanghai's Lin-gang Special Area. The practical consequence is that a company must first determine whether it qualifies for an exemption before it commits to the heavier compliance machinery of a full assessment or certification exercise.

Step One: Classify the Data, the Volume, and the Processor

Pathway selection begins with classification. Article 40 of the PIPL imposes a domestic storage rule on two categories of processors: operators of critical information infrastructure, as identified under the Regulations on the Security Protection of Critical Information Infrastructure, and personal information processors whose handling volumes reach the level specified by the CAC. For these processors, personal information collected and generated within the mainland must be stored domestically, and any genuine need to provide it abroad can only be satisfied by passing the CAC-organized security assessment. Separately, Article 36 of the Data Security Law prohibits providing data stored within the mainland to foreign judicial or law enforcement authorities without approval — a restriction that no contract clause can override.

For all other processors, the thresholds set by the 2024 Provisions determine the route. Where the cumulative volume of personal information (excluding sensitive personal information) provided overseas since 1 January of the current year is less than 100,000 individuals, the transfer is exempt from the security assessment, the standard contract filing, and certification — provided no important data is involved. Where that cumulative volume is between 100,000 and 1,000,000 individuals, the processor must either conclude and file a standard contract or obtain certification. Where the cumulative volume reaches 1,000,000 individuals, or where 10,000 or more individuals' sensitive personal information is involved, a security assessment is required. The 2024 Provisions also exempt transfers that are necessary for concluding or performing a contract to which the individual is a party, such as cross-border shopping, ticket and hotel booking, remittance, or visa processing; transfers necessary for cross-border human resources management implemented under lawfully adopted labor rules and collective contracts; and transfers necessary in emergencies to protect the life, health, or property of individuals. These exemptions do not, however, release the processor from its informing and separate-consent duties under Article 39.

How the dispute was handled

Pathway One: The Security Assessment

The security assessment is the heaviest compliance lift, and it is mandatory for critical information infrastructure operators, for transfers involving important data, and for processors crossing the volume thresholds described above. The procedure is governed by the Measures for Security Assessment of Cross-Border Data Transfer, effective 1 September 2022. The processor submits an application to the CAC through the provincial cyberspace administration, accompanied by a data export risk self-assessment report, the contract or legal documents governing the transfer, and supporting materials describing the data's purpose, categories, and volumes. The self-assessment report must address the legality and necessity of the transfer, the sensitivity of the data, the recipient's security management capability, the risk to national security, public interests, and individual rights, and the measures available to the individual to enforce their rights abroad.

The CAC evaluates the application and issues its decision normally within 45 working days, extendable by a further 15 working days where the case is complex. A favourable assessment result is valid for three years; the processor must re-apply before expiry if the transfer continues, and must re-apply immediately if the purpose, method, categories, or volume of the data changes, or if the recipient or the destination jurisdiction changes. In my experience, the documents that most often delay an application are imprecise descriptions of data flows and weak necessity analyses — regulators expect a clear chain from business purpose to data category to volume.

Pathway Two: The Standard Contract

The standard contract is the default route for the majority of exporters. The Measures for the Standard Contract for Cross-Border Transfer of Personal Information, effective 1 June 2023, require the processor and the overseas recipient to conclude a contract on the model clauses issued by the CAC. The model clauses address the identity of the parties, the purpose, method, and categories of processing, retention periods, security safeguards, the individual's rights and the mechanisms for exercising them against the recipient, liability and breach, termination, and dispute resolution. Within ten working days of the contract taking effect, the processor must file it with the provincial cyberspace administration. A re-filing is required whenever the parties change, the processing purpose or categories change, retention periods are extended, or the recipient's security measures are downgraded.

Two practical points are often underestimated. First, the contract path is not available to processors that are subject to the mandatory security assessment; the filing mechanism will not cure a threshold violation. Second, signing the model contract is not the end of the processor's duties — Article 38 requires the processor to supervise the recipient's actual processing activities and to take necessary measures to ensure they meet PIPL standards. That supervision should be documented: periodic audits of the recipient, evidence of security safeguards, and a record of how individual-rights requests routed through the recipient were handled.

Practical implications

Pathway Three: Personal Information Protection Certification

Certification offers an alternative for processors that prefer a systemic rather than a transaction-by-transaction approach. Under the certification rules jointly issued by the CAC and the State Administration for Market Regulation in November 2022, specialized institutions designated by the CAC audit the processor against the personal information protection certification criteria, which build on national standards including GB/T 35273 on personal information security specifications and the associated certification technical documents developed under the TC260 framework. The certification examines the processor's entire personal information processing system — governance, security measures, impact assessments, and the controls applied to overseas recipients — rather than a single transfer.

For multinational groups that transfer data to multiple recipients in the same jurisdiction, or that wish to demonstrate a mature compliance posture to regulators and business partners alike, certification can be more efficient than managing dozens of individual contract filings. It also carries reputational value in procurement processes and cross-border due diligence. The trade-off is the depth of the audit and the ongoing maintenance burden: certification is not a one-time event, and surveillance audits require the processor to keep its documentation current.

Obligations That Apply to Every Pathway

No pathway is a shortcut around the procedural rights in the PIPL. Article 39 requires that, before providing personal information abroad, the processor inform the individual of the overseas recipient's identity and contact information, the purpose and method of processing, the categories of personal information involved, and the ways in which the individual may exercise their rights under the PIPL against the overseas recipient — and obtain the individual's separate consent. Separate consent means consent that is distinct from general privacy-policy acceptance: a dedicated choice, clearly explained, with a retrievable record. Article 55 further requires a personal information protection impact assessment before any cross-border transfer, and Article 56 requires the assessment records to be kept for at least three years.

In practice, I advise clients to treat these obligations as a single compliance package assembled before the transfer begins: a data inventory, a necessity analysis, the impact assessment, the consent mechanism, the pathway documentation, and the ongoing monitoring framework. The 2024 Provisions confirm that even exempt transfers remain subject to the informing and consent requirements, so there is no scenario in which notification design can be deferred. Where the transfer involves sensitive personal information, additional diligence is warranted because the thresholds for assessment are lower and the regulatory scrutiny is higher.

Practical Guidance for Multinational Enterprises

Drawing these rules together, a multinational enterprise preparing a cross-border transfer should work through a seven-step sequence: first, map the data flows and build an inventory of what is transferred, to whom, and in what volume; second, classify the data, including whether any important data or sensitive personal information is involved and whether the Chinese entity is a critical information infrastructure operator; third, apply the thresholds and exemptions to select the pathway; fourth, complete the personal information protection impact assessment before any transfer occurs; fifth, design and implement the Article 39 notification and separate-consent mechanism with an audit trail; sixth, execute the chosen pathway — submit the security assessment application, or conclude and file the standard contract, or engage a certification body; and seventh, put in place continuous monitoring of the overseas recipient, with re-filing or re-assessment triggers when the data, the recipient, or the purpose changes. Attempting to structure transfers through offshore entities or informal arrangements to avoid these requirements is a false economy; regulators examine the substance of the data flow, and enforcement actions in recent years have targeted precisely such evasive structures.

What parties should remember

Shanghai-based groups should also watch the pilot environment closely. The Lin-gang Special Area has been developing cross-border data flow facilitation measures and negative-list approaches that, once finalized, may streamline transfers for qualifying companies, and the municipal cyberspace administration has been an early adopter of digital filing channels. These developments do not change the baseline rules, but they can reduce friction for companies that are already in compliance.

The cross-border transfer regime under the PIPL is best understood not as a set of obstacles but as a predictable framework that rewards preparation. Companies that maintain an accurate data inventory, document necessity, and build their consent and monitoring mechanisms into their operating systems will find the pathway selection largely mechanical. In my experience, the enterprises that struggle are rarely those facing genuinely novel questions — they are those that begin the compliance exercise after the data has already moved. Beginning with the inventory, and engaging the framework early, is the single most effective step any multinational can take.

Sources & trust

How to use this article

This insight is general information for orientation on China-related legal topics. It is not legal advice and does not create an attorney–client relationship. Prefer primary statutes, courts, and official guidance when making decisions.

Editorial Policy · AI Content Policy · Lawyer Verification Policy · Listing standards · Disclaimer · Request a consultation

Share LinkedIn X Email
Tongyu Yan

About the author

Tongyu Yan

Shanghai AllBright Law Offices. Verified listing on China Legal Portal. Insights are educational and do not create an attorney–client relationship.

Discussion

Join the conversation

Share a professional question or experience. This is not legal advice — no attorney–client relationship is formed by posting here.

Next step

Need counsel on this topic?

Connect with verified data privacy & cybersecurity lawyers across China, or ask a free initial question.

Educational information only — not legal advice. Laws change; consult qualified counsel for your situation. No attorney–client relationship is formed by using this site. See our Disclaimer, Editorial Policy, and AI Content Policy.