Skip to main content
China Legal Guides · National framework

CAC Security Assessment for Data Exports

Prepare and maintain a CAC data-export security assessment, including triggers, application materials, review, validity, extension and change control.

63lawyer profiles listed
Updated10 Sep 2026
AudienceForeign businesses & individuals
Author China Legal Portal Editorial · Reviewer Tongyu Yan · Last reviewed · 6 min read · Editorial policy · AI content policy · Disclaimer · Not legal advice — confirm current rules with counsel and authorities

At a glance

Practice: typical process stages

Four high-level stages — details and local variations are in the guide below.

  1. FrameMap facts to PRC rules
  2. PlanOptions, risks & timeline
  3. ExecuteFilings, contracts, forums
  4. ReviewCompliance & next steps
City hubs

Local guides & lawyers

Drill into city × practice hubs where available, or open the city legal market guide.

Legal planning desk with source documents, authority records and evidence file
Working file · authority, workflow and evidence

Certain exports of important data or personal information must pass a security assessment administered by the Cyberspace Administration of China. Under the current framework, the route applies to qualifying exports by critical information infrastructure operators, exports of important data, and non-CIIO personal-information transfers crossing the operative annual thresholds.

The application is more than a form. The exporter must define the data and transfer architecture, complete a risk self-assessment, contract with overseas recipients, demonstrate necessity and security, and submit through the provincial CAC authority using the current filing guide. Operations must remain within the approved scope and be reassessed or renewed when required.

Direct answer

Confirm that security assessment is mandatory under the 2024 cross-border flow rules, freeze the intended scope, and complete a documented data-export risk self-assessment. Align the application form, data inventory, legal documents, technical architecture, impact analysis and overseas-recipient evidence. Submit through the current CAC system and provincial channel before the mandatory transfer begins.

After approval, maintain a control register for permitted purpose, recipients, data categories, volumes, retention and validity. Treat material change, incidents and expiry as compliance events, not administrative reminders.

When assessment is mandatory

The current framework generally requires assessment where:

  • a CIIO exports personal information or important data;
  • a non-CIIO data processor exports important data;
  • a non-CIIO, from 1 January of the current year, exports non-sensitive personal information of at least one million individuals; or
  • a non-CIIO exports sensitive personal information of at least 10,000 individuals in that period.

Apply exemptions and counting exclusions in the 2024 Provisions before concluding that a threshold is met. Conversely, do not use SCC or certification for a transfer that requires assessment.

Scope the assessed activity

Define the China exporter, each overseas recipient, purpose, business process, systems, transfer method, frequency, retention, onward transfer and deletion. Identify exact data fields, personal-information status, sensitivity, important-data basis and number of individuals.

Scope should match reality. Include remote access, APIs, logs, backups and support paths. Avoid vague “business data” descriptions or an application that covers only the primary recipient while undisclosed subprocessors receive the same data.

Risk self-assessment

Before filing, the data processor must assess legality, legitimacy and necessity; data volume, scope, type and sensitivity; risks to national security, public interests and individual or organizational rights; recipient capability and obligations; post-transfer security; and adequacy of the legal document.

Use evidence, not conclusions. Map controls to identified risks, assign remediation owners and close material gaps before submission. Preserve interviews, system diagrams, test results, policies and approvals supporting the report.

Overseas recipient diligence

Assess the recipient’s organization, experience, security governance, technical controls, incident history, data locations, subprocessors and ability to honor rights and deletion. Consider the destination’s laws and public-authority access environment insofar as they affect performance of the promised protections.

Where several affiliates receive data, document each role and access path. A parent guarantee does not substitute for operational diligence.

Legal document

The exporter and overseas recipient need a contract or other legally binding document allocating data-security responsibilities. Under the assessment measures, it should address purpose, method, scope, overseas use, retention and location; restrictions on onward transfer; security measures; changes in control or legal environment; individual rights and remedies; incidents; and return or deletion.

Make effectiveness conditional on obtaining required approval where appropriate. Align every appendix with the self-assessment and technical inventory.

Filing package

Use the current CAC Data Export Security Assessment Filing Guide, now in its third edition issued in June 2025, and the current online Data Export Declaration System. The package generally includes the application, self-assessment report, legal document and supporting materials required by the guide.

Corporate identity, authorization, translations, system diagrams and evidence must be internally consistent. Follow the provincial authority’s current intake instructions; incomplete or inconsistent materials can require supplementation before substantive review.

Submission and review

The data processor submits through the provincial CAC authority for transmission to the national CAC. Statutory processing stages and periods are subject to acceptance, supplementation, complexity and official notices. Build project timing around a conservative approval path.

Do not treat submission as permission. If assessment is mandatory, conduct the transfer only after a passing result and within its approved parameters.

Assessment factors

CAC evaluates the legality, legitimacy and necessity of the purpose, scope and method; risks created by volume, type and sensitivity; overseas-recipient duties and capacity; risks of tampering, destruction, leakage, loss, transfer or unlawful access; protection of personal-information rights; adequacy of the legal document; and other matters affecting security.

Sector classification, important data and national-security implications can be decisive even where individual counts are low.

Result and reconsideration

Possible outcomes include non-acceptance because the activity is outside the route, passing assessment or failing assessment. A failed activity must not proceed as proposed. The Measures provide a short period to seek reassessment of the result, and that final administrative route should be handled from the official notice with counsel.

Commercial teams should maintain alternatives such as localization, minimization or a different operational design without mischaracterizing the original scope.

Validity and extension

The 2022 Measures originally provided a two-year validity period. The 2024 Provisions extended a passing result to three years from issuance and allow an application to extend for another three years where the export activity has not changed and no triggering circumstance has arisen.

The June 2025 third-edition guide and CAC’s July 2026 Q&A describe current extension conditions, including unchanged purpose, scope, processor and recipient; limited projected volume growth; compliant legal documents; compliant operations during the prior period; and no major data-security incident. Apply the exact current guide and file before the stated deadline.

Changes requiring action

Reassessment can be required where purpose, method, scope, data type, recipient processing, retention, destination legal environment, control, legal documents or another factor changes in a way affecting security. Maintain a pre-change approval workflow for product, vendor and corporate transactions.

Do not wait for the three-year expiry if the approved facts no longer match operations. Stop, contain or redesign unauthorized scope as necessary and obtain advice on notification or refiling.

Operating after approval

Maintain a transfer register and technical enforcement for recipient, data fields, volumes, retention and onward access. Reconcile actual activity to approval at least periodically and before major releases. Test deletion, rights assistance and incident notification.

Preserve the result notice, submitted package, supplementation, control evidence, transfer logs, audits and change decisions. Approval is not a permanent certification of every future transfer.

Incidents and regulator contact

Activate the incident plan when exported data is compromised or the recipient cannot meet obligations. Preserve evidence, contain access, coordinate notifications and assess whether continuing transfer remains lawful. The CAC can require termination where an approved activity no longer meets requirements.

Keep regulator communications accurate and centrally controlled. Do not conceal material scope or provide inconsistent numbers across filings.

Readiness checklist

  1. Confirm CIIO, important-data and volume triggers.
  2. Apply current exemptions and counting rules.
  3. Freeze exporter, recipient, purpose and system scope.
  4. Complete field-level classification and data-flow maps.
  5. Conduct and approve the risk self-assessment.
  6. Remediate exporter and recipient control gaps.
  7. Execute an aligned legal document.
  8. Submit the third-edition guide package correctly.
  9. Operate within the passing result and preserve evidence.
  10. Monitor changes, incidents, renewal and extension conditions.

Common mistakes

  • Using superseded pre-2024 thresholds.
  • Ignoring important data because personal-information counts are low.
  • Treating submission as authorization.
  • Filing a generic self-assessment unrelated to architecture.
  • Omitting remote access or onward recipients.
  • Letting the contract contradict the application.
  • Assuming approval covers later products or affiliates.
  • Missing extension preparation or continuing after material change.

Sources

General legal information only; not legal advice for a particular assessment, dataset, recipient or regulator filing.

Legal source archive with indexed legislation and official records
Source register · primary authorities and verification
Sources & trust

How to use this guide

PIPL; CSL; DSL; CAC cross-border data transfer measures. Thresholds and catalogues change — check official texts. Editorial source-check 2026-09-06.

Editorial, AI and verification policies

This page is general information for orientation. It is not legal advice and does not create an attorney–client relationship.

Review the Editorial Policy, AI Content Policy, and Lawyer Verification Policy.

Consultation preparation

What to prepare before contacting counsel

Send a focused first package so counsel can check conflicts, understand scope, and identify urgent deadlines.

  • A concise timeline and the result you want to achieve.
  • Names of all parties and affiliates for a conflict check.
  • Key contracts, notices, correspondence, filings, or decisions.
  • Known deadlines, preferred language, location, and budget constraints.
Directory

Practice lawyer profiles

China-based listings shown first. Review profiles for practice, then submit an initial enquiry.

Status shown per profileFree initial intakeChina-first directory sort

Browse practice directory →

Cross-border legal details arranged for a prepared counsel enquiry
Next route · prepared enquiry

Move from orientation to a properly prepared legal brief.

Bring the parties, objective, relevant documents, chronology, known deadlines and the decision you need counsel to make.

Prepare your legal enquiry →

Need counsel on practice?

Review listed lawyer profiles and submit an initial enquiry. No obligation.