Sending or making China-origin data available to an organization or person outside mainland China can trigger China’s data-export rules. Remote access, overseas hosting, group platforms, support tools and disclosures to an offshore affiliate can matter even when no file is emailed. The first task is to map the actual data, recipients, systems and purposes.
The compliance route depends on important-data status, critical-information-infrastructure status, personal-information type and annual volume, and whether a specific exemption applies. Possible outcomes include CAC security assessment, the personal-information standard contract, certification or an exemption from those transfer mechanisms. An exemption does not remove baseline duties such as necessity, security, notice, impact assessment or separate consent where applicable.
Direct answer
Map each export activity, identify the China-side data processor and overseas recipient, classify the data and count unique individuals under the current rules. Screen first for important data and critical information infrastructure, then apply the current volume thresholds and exemption conditions. Complete the selected mechanism before the transfer and retain evidence that operations match the filed or approved scope.
Do not split one transfer program among systems or affiliates to avoid a threshold. Do not assume that an intragroup transfer, cloud dashboard or remote administrator is domestic processing.
What counts as a data export
An export can occur when data collected or generated in mainland China is transferred or stored outside mainland China or when an overseas organization or individual can query, retrieve, download or otherwise access it. Architecture and permissions matter more than contract labels.
Map production databases, backups, logs, support access, HR and CRM platforms, mobile analytics, collaboration tools and onward transfers. Identify where encryption keys and administrators are located and whether offshore access is technically possible.
Build the transfer inventory
For every activity record:
- China exporter and business owner;
- overseas recipient, affiliates and service providers;
- purpose and necessity;
- data fields and systems;
- personal, sensitive or important-data classification;
- individuals, volumes and counting period;
- access, storage, onward transfer and retention;
- legal mechanism or exemption; and
- notices, consents, assessments and contracts.
One project may contain several transfer activities with different recipients and purposes. Count and analyze them under the current aggregation rules rather than selecting the easiest route per contract.
Important data comes first
Important data can trigger CAC security assessment independently of personal-information volume. Under the 2024 Provisions, data processors generally do not need to treat data as important data unless relevant departments or regions have notified them or publicly issued a catalogue identifying it, but sectoral duties and later identification still require monitoring.
Document the catalogue and regulator check. Absence of a label is not permission to ignore sector rules, state secrets, work secrets, controlled technical information or other restrictions.
Critical information infrastructure operators
A critical information infrastructure operator exporting personal information or important data must generally use the CAC security-assessment route under the current framework. Do not self-designate casually, but do not assume ordinary company size proves that an entity is outside the regime. Preserve any official identification and sector communications.
Current personal-information thresholds
For a non-CIIO data processor, the 2024 Provisions generally require CAC security assessment where, from 1 January of the current year, exports reach at least one million individuals’ non-sensitive personal information or at least 10,000 individuals’ sensitive personal information. The count uses unique natural persons under CAC guidance and excludes activities that the operative rules exclude from counting.
Where the exporter reaches at least 100,000 but fewer than one million individuals’ non-sensitive personal information, or exports sensitive personal information below the 10,000-person assessment threshold, the standard contract or certification route generally applies unless an exemption governs.
For a non-CIIO exporter below 100,000 individuals’ non-sensitive personal information and exporting no sensitive personal information, the 2024 rules provide an exemption from assessment, standard contract and certification, subject to the full conditions.
Exemptions
The 2024 Provisions identify exemptions that can cover specified activities, including certain data generated outside China and merely processed in China without introducing China-origin personal information or important data; transfers necessary to enter into or perform a contract with the individual; qualifying cross-border HR management; emergencies protecting life, health or property; and certain low-volume non-sensitive exports by non-CIIOs.
International trade, transportation, academic cooperation, multinational manufacturing or marketing data without personal information or important data can also fall outside the mechanisms. Each exemption is fact-specific. Record necessity, data minimization, participants and the precise provision relied on.
An HR exemption does not automatically cover recruitment analytics or global talent pools. CAC’s July 2026 Q&A emphasizes necessity and indicates that overseas participation in hiring decisions must be assessed under the export framework with the required notice, separate consent and impact assessment where applicable.
Standard contract and certification
The personal-information standard contract is executed with the overseas recipient and filed through the applicable system and provincial CAC channel under current guidance. The parties should not modify mandatory terms incompatibly and must align appendices, impact assessment and actual flows.
Certification is a separate mechanism under current rules. Neither route is available where the transfer must undergo security assessment. The SCC-versus-certification comparison remains with record 2605.
CAC security assessment
Security assessment applies to important data, qualifying CIIO exports and transfers crossing the operative personal-information thresholds. The application goes through the provincial CAC authority to the national CAC using the current filing guide and online system.
The security-assessment specialist page owns submission, review and renewal detail. Do not begin a mandatory transfer while waiting for approval merely because commercial contracts are signed.
Baseline PIPL duties
Where personal information is exported, the processor should establish a lawful processing basis, provide the required notice, obtain separate consent where applicable, conduct a personal-information protection impact assessment, minimize data, adopt security measures and ensure the overseas recipient meets the PIPL protection standard.
Mechanism exemptions do not erase these duties. Also coordinate individual rights, incidents, government-access requests, onward transfers, deletion and audit evidence.
Contracts and recipient diligence
Map the recipient’s location, role, systems, subprocessors, public-authority access environment and incident history. Contract terms should cover purpose, categories, retention, security, onward transfer, rights assistance, incidents, audit, return or deletion and changes that affect the mechanism.
An Article 21 entrusted-processing agreement is not itself a data-export mechanism. Role mapping and export compliance are separate layers.
Change control and annual counting
Recalculate annual totals from 1 January, using de-duplicated individuals under CAC guidance. Include transfers already made through an SCC or certification when later assessing whether the annual assessment threshold is crossed, as confirmed in CAC’s January 2026 Q&A.
Review new recipients, purposes, data categories, sensitive fields, retention, corporate control and overseas legal changes before implementation. Amend, refile or reassess where required.
Transfer decision checklist
- Identify the exporter, recipient and all remote access.
- Classify important data and personal information.
- Confirm CIIO status.
- Count unique individuals from 1 January.
- Test each claimed exemption and necessity.
- Select assessment, SCC, certification or exempt route.
- Complete notice, consent and impact assessment.
- Contract with and assess overseas recipients.
- Implement technical controls and transfer logs.
- Monitor thresholds, changes, incidents and expiry.
Common mistakes
- Treating remote access as outside the export rules.
- Counting databases rather than unique individuals.
- Ignoring sensitive personal information or important data.
- Assuming an intragroup transfer needs no mechanism.
- Treating an exemption as a waiver of PIPL duties.
- Splitting transfers to avoid assessment.
- Using SCC after the assessment threshold is crossed.
- Failing to monitor onward transfer and changed scope.
Sources
- Provisions on Promoting and Regulating Cross-Border Data Flows, CAC, effective 22 March 2024.
- Measures for Security Assessment of Data Exports, CAC.
- CAC policy Q&A, January 2026.
- CAC policy Q&A, July 2026.
General legal information only; not legal advice for a particular dataset, exporter, recipient or transfer.



