China CBDT roadmap · Export-path tree (companion) · SCC filing timeline/cost · HR/CRM architecture · Employee-data outbound · Going-global playbook.
Direct answer
This page is a decision guide. Walk the tree, fill the calculator assumptions, compare routes, then open the timeline and document anatomy for the terminal state. Unresolved facts stay unresolved. Start the master tree.
Do not mix the three tracks in one route matrix. Journey shortcuts: which route? · we already use an SCC · HR / recruitment · China staff on EU systems · something changed.
At a glance — which workstream first
EDITORIAL TEST Rows are starting hypotheses, not legal conclusions.
| If this is true | First test | Likely workstream | Do not do this |
|---|---|---|---|
| Mainland PI or possible important data is provided overseas (including remote view) | Export exists? Class? Exemption? | Track A | Start with an EU SCC |
| EU personal data is viewed or retrieved from mainland China; server still in the EEA | Chapter V transfer + exporter/importer roles | Track B | Treat hosting region as the whole map |
| Data were collected only outside China and no mainland PI / important data is mixed in | Overseas-collected pathway | Track C | Assume processing in China automatically resets the analysis |
| Unique persons or SPI sit near published volume conditions | Count + year-end forecast | Calculator | Count transfer events instead of persons |
| Vendor, country, team, dataset or volume changed after the last SCC / filing | Change gate | Re-tree | Rely on last year’s contract |
Scope / legal framework
In scope: classifying a China-related cross-border data operation; testing whether an export exists; separating PI, sensitive PI and important-data questions; testing mechanism exemptions; measuring thresholds; comparing SCC, certification and security assessment; sequencing filings; preparing PIPIA / SCC / assessment packs; running a GDPR Chapter V track when China-based staff access EU data.
Out of scope here: a country-by-country privacy encyclopedia, a fillable “approved” contract template, a city-lawyer directory as the product, or a claim that one signed EU SCC closes both sides.
How the authorities fit together
- National laws (binding law) — PIPL; Data Security Law; Cybersecurity Law.
- Administrative regulations — State Council instruments where they speak to data security / network products (apply only when they actually do).
- CAC departmental rules / measures (binding measure) — including the March 2024 Provisions on Promoting and Regulating Cross-border Data Flows, and the measures on security assessment, standard contract and certification as separately in force.
- Official CAC Q&A / implementation guidance — useful for practice; not drawn as equal to statute.
- FTZ and sector lists — negative lists and industry catalogues; location- and sector-specific.
- National / technical standards — classification and security practice; not a substitute for a statutory trigger.
- Editorial interpretation — this page. Labelled as such.
Track A — Data leaving mainland China
Use this track when personal information, sensitive PI or possible important data is provided from mainland China to an overseas recipient, including: physical transmission, remote access, API, shared global systems, overseas support access and intra-group access. Server location alone is not the test.
Master decision tree — which China data-export route may apply?
Every leaf is a preliminary route to validate. Display the unresolved facts. Then open the matching timeline and document anatomy.
- Node 1 — Is data provided from mainland China to an overseas recipient?
- No → a PRC cross-border transfer mechanism may not apply. Still check other PIPL/DSL/CSL duties and, if EU data is viewed from China, Track B.
- Yes → continue. Record every access path, not only batch exports.
- Node 2 — What data is involved? Classify separately: personal information · sensitive personal information · important data (identified/notified or reasonably in scope) · other/general data. Mixed datasets inherit the stricter applicable test.
- Node 3 — Is a mechanism exemption potentially available? Test, in order of the facts, not of convenience: overseas-collected · contractual necessity · cross-border HR · emergency · qualifying lower-volume PI · FTZ negative list.
Standing caveat: exemption from a transfer mechanism does not necessarily remove notice, separate-consent, PIPIA, security, rights or important-data duties.
- Node 4 — Calculate thresholds. Open the calculator before picking SCC vs certification vs assessment.
- Node 5 — Terminal states (pick one to validate)
- Potential exemption — why the branch might fit; conditions; unresolved facts; still-open PIPL duties; next: document the exemption file, do not stop the programme.
- Standard contract / SCC route — eligibility conditions appear to hold; next: PIPIA + execute + file. Compare · timeline.
- Certification route — typically intra-group / common processing; not a free substitute for SCC. Next: eligibility + body + monitoring.
- CAC security assessment — CIIO, important data, or volume/SPI conditions may point here. Next: self-assessment pack + provincial gate. timeline.
- Specialist review required — important-data doubt, CIIO doubt, mixed tracks, mid-year escalation, or FTZ/sector overlay.
Statutory matrix — rules, thresholds and exceptions
Figures below are the rule as stated in the 22 March 2024 CAC Provisions, restated for navigation. Confirm the instrument in force on the day you file. Measurement language in the measure is tied to estimated provision of PI overseas since 1 January of the current year for the volume tests — do not invent a different counting year without a source.
| Trigger / rule | Measurement period | Data category | Threshold / condition | Possible consequence | Exemptions to test first | Authority | Last verified |
|---|---|---|---|---|---|---|---|
| Lower-volume PI (non-CIIO) | Since 1 Jan of current year (as stated in the measure) | PI excluding sensitive PI | Estimated provision overseas of PI of fewer than 100,000 persons | May fall outside assessment / SCC / certification if other Art. 5 conditions hold | Necessity, HR, emergency, overseas-collected, FTZ | CAC Provisions Art. 5 | 15 August 2026 |
| Mid-volume PI (non-CIIO) | Same | PI excluding sensitive PI | 100,000 up to 1,000,000 persons | Possible SCC or certification route to validate | Art. 4–5, Art. 7 | Art. 6 | 15 August 2026 |
| High-volume PI (non-CIIO) | Same | PI excluding sensitive PI | 1,000,000 persons or more | May require security assessment | Art. 4–5, Art. 7 | Art. 6 | 15 August 2026 |
| Sensitive PI (non-CIIO) | Same | Sensitive PI | Fewer than 10,000 persons | Possible SCC or certification | Art. 4–5 (narrow) | Art. 6 | 15 August 2026 |
| Sensitive PI escalation | Same | Sensitive PI | 10,000 persons or more | May require security assessment | Art. 4–5 (narrow) | Art. 6 | 15 August 2026 |
| Important data | Not a headcount test | Important data | Identified / notified or otherwise in scope for outbound | Security-assessment analysis typically required | Do not “volume away” important data | DSL + CAC Arts. 2–3, 7–8 | 15 August 2026 |
| CIIO | Status-based | PI or important data | CIIO providing such data overseas | May require security assessment | Not a volume exemption | CSL + CAC Art. 8 | 15 August 2026 |
| Contract necessity | Transaction-specific | Usually PI needed to perform | Necessary to conclude/perform a contract to which the individual is a party (illustrations in Art. 5) | Potential mechanism exemption | Reject convenience, analytics, marketing add-ons | Art. 5 | 15 August 2026 |
| Cross-border HR | Employment relationship | Employee PI needed for HR | Necessary for cross-border HR under labour rules and collective contracts | Potential mechanism exemption | Does not automatically cover applicants or group-wide lakes | Art. 5 | 15 August 2026 |
| Emergency | Incident-specific | PI needed to protect life, health or property | Narrow emergency necessity | Potential mechanism exemption | Not a standing architecture | Art. 5 | 15 August 2026 |
| Overseas-collected then re-exported | Origin of collection | Non-mainland PI / data | No domestic PI or important data introduced | May fall outside “outbound” treatment in Art. 4 | Re-test if mainland data is joined | Art. 4 | 15 August 2026 |
| FTZ negative list | Zone + list version | As listed / not listed | In a participating FTZ and outside that zone’s negative list | Possible alternative pathway | Confirm zone, list, sector, current status | Art. 7 | 15 August 2026 |
| Change / reassessment | On material change | Any | New purpose, recipient, destination, category, volume, access path, or legal change | Re-open route; possible re-file | — | PIPL + route-specific measures | 15 August 2026 |
How to calculate China data-export thresholds
Inputs
- Unique natural persons (not rows, not API calls)
- Sensitive-PI count and non-sensitive-PI count, held separately
- Applicable measurement period in the measure you rely on
- Year-to-date volume and forecast year-end volume
- Previous exports already placed under SCC or certification
- Multiple overseas recipients (do not assume each recipient resets the count)
- Duplicate-person handling across HR, expense, CRM and support systems
Formula (editorial counting model)
Annual exported PI count = relevant unique natural persons whose PI is provided overseas during the applicable counting period.
Rule (what the 2024 Provisions speak to): estimated number of persons whose PI is provided overseas in the stated window. Our reading for this fact pattern: de-duplicate the same individual across systems; do not count transfer events; count SPI on its own line.
Worked example 1 — one employee in three systems
Assumptions: mainland employer exports HR core, expense and payroll fields for the same 800 employees to an overseas HQ HRIS. No applicants. No important-data flag. Non-CIIO. No SPI beyond what HR ordinarily holds — SPI still needs its own line if present.
Formula: unique employees = 800, not 2,400 events.
Calculation: 800 unique persons.
Result: place 800 on the non-SPI and, if applicable, SPI worksheets separately.
Legal consequence: volume alone may sit under a lower-volume or mid-volume band and the HR-necessity exemption still has to be tested field-by-field. Double-counting would falsely escalate the route.
Remaining uncertainty: which fields are SPI; whether contractors/dependents are in the file; whether former employees remain.
Worked example 2 — mid-year cross after an SCC
Assumptions: group filed an SCC when YTD unique persons were 70,000 non-SPI. A CRM go-live will add 50,000 new unique overseas-shared customers before 31 December. Same recipient country.
Calculation: 70,000 + 50,000 = 120,000 unique persons if no overlap; subtract overlap if the same people already sit in the SCC file.
Result: if unique non-SPI persons reach the mid-volume band in the measure, the possible route is no longer “lower-volume exemption”.
Legal consequence: validate whether SCC remains available, whether a new filing / change notice is required, and whether assessment conditions are approaching. Signing last quarter’s SCC does not freeze the count.
Remaining uncertainty: overlap; SPI in the CRM; whether the original SCC described this purpose.
Worked example 3 — SPI and non-SPI overlap
Assumptions: 12,000 unique customers exported; 2,500 of them have a sensitive field (e.g. precise location or a health-adjacent field — classification is itself a legal question).
Calculation: non-SPI worksheet 12,000; SPI worksheet 2,500. Do not subtract the 2,500 from the PI count unless the measure you rely on tells you to — the 2024 text runs SPI as a separate trigger.
Result: two independent tests. SPI at 2,500 may already point to SCC/certification even if total PI is modest; SPI at 10,000+ may point to assessment.
Remaining uncertainty: whether the field is SPI under PIPL; whether emergency/contract necessity covers those fields (usually not for analytics).
Exemption mini-trees
HR-management necessity
- Is there a genuine employment (or legally recognised labour) relationship under the rules you rely on?
- Is each exported field necessary for that HR purpose — or is it a group data-lake convenience?
- What labour rules / collective-contract clauses actually require the overseas recipient to see it?
- Who is the overseas recipient (HQ HR vs vendor vs “everyone with Okta”)?
- Minimisation: can the same purpose run with fewer fields, fewer people, or in-country access?
- Even if the mechanism exemption is available to test, record notice, security, retention and rights.
Recruitment overlay: applicants are often not “HR management of employees”. Ask: does overseas HQ actually participate in the hire; how many applicants; which fields; do all overseas mailboxes need the CV? CVs to a global inbox are a common false “HR exemption”.
Contract-necessity
Distinguish necessary to conclude/perform a contract with the individual (the illustrations in Art. 5 are transactional: cross-border shopping, delivery, payment, account opening, visa, hotel, ticket) from convenience, analytics, marketing and optional profiling. If the contract can be performed without the overseas disclosure, this branch is weak.
Emergency
Narrow. Life, health or property in an actual emergency. Not a standing architecture for “follow-the-sun support”.
FTZ / negative-list
Require: named FTZ · the negative list actually in force · industry/sector match · whether the exporter is in that zone · current legal status. National default is not “FTZ rules apply everywhere”.
Standard Contract vs certification vs CAC security assessment
These are not interchangeable products. Eligibility is statutory.
| Question | Standard Contract (China SCC) | Certification | CAC security assessment |
|---|---|---|---|
| When potentially available? | Non-CIIO flows that sit in the SCC/cert band of Art. 6 and are not forced to assessment | Same eligibility band; typically group or common-processing designs | CIIO, important data, or high-volume / high-SPI conditions in Art. 6–8 |
| Who can use it? | Eligible PI handlers meeting the measure | Eligible handlers that can complete a certification programme | Handlers whose facts trigger assessment |
| Key threshold conditions | See matrix — mid-volume PI or sub-10,000 SPI (non-CIIO) | Same band; not a bypass of assessment triggers | 1m+ PI, 10k+ SPI, important data, CIIO outbound |
| Filing / application required? | Yes — file the executed SCC + PIPIA with the provincial CAC (confirm current practice) | Certification process with a recognised body | Yes — application via provincial gate to CAC |
| Main assessment document | PIPIA + SCC annexes | Certification dossier | Self-assessment / risk report + application pack |
| Typical use case | Defined transfers to named overseas recipients | Intra-group recurring processing | High-risk or high-scale outbound |
| Intra-group suitability | Often used; still a contract + file | Often designed for groups | Used when triggers hit, group or not |
| Change trigger | Purpose, recipient, destination, categories, volume | Scope or control change | Facts in the assessment; validity window |
| Escalation trigger | Crossing into assessment band; important-data flag; CIIO | Same | Already the high route; watch validity / extension |
| Validity / continuing obligations | Contract + PIPL duties continue after filing | Surveillance / recertification | Validity period + extension / re-assessment practice |
| Main operational burden | PIPIA quality + annex accuracy + volume monitor | Programme design + audit | Dossier + regulator questions + time |
| Main advantage | Named, relatively standardised contract path | May fit stable intra-group processing | The path the high-risk triggers actually require |
| Key limitation | Not available once assessment triggers apply | Not a substitute for assessment; capacity/practice still maturing | Heavier; not optional if the trigger is real |
| Primary legal source | PIPL Art. 38 + SCC measures + 2024 Arts. 5–6 | PIPL Art. 38 + certification rules + 2024 Arts. 5–6 | PIPL Art. 40 + assessment measures + 2024 Arts. 6–8 |
Already on an SCC? Re-run the unique-person count and SPI line → test escalation → open change triggers → confirm whether the filed annex still describes the live purpose. Do not assume last year’s file covers this year’s CRM.
Procedural timelines
Statutory clocks, where they exist, sit on the assessment/SCC measures — not on this page’s editorial sequence. Steps marked “practice-dependent” have no single number here on purpose.
Security-assessment sequence
- Data-flow mapping — owner: business + privacy. Output: inventory.
- Classify data — owner: legal + security. Output: PI / SPI / important-data record.
- Self-assessment / impact work — owner: legal. Output: risk report.
- Prepare application — owner: legal + CISO. Output: pack.
- Provincial submission — completeness review (practice-dependent timing).
- CAC assessment process — statutory/practice timing in the assessment measures; confirm current text.
- Decision — implement only the approved scope.
- Validity-period monitoring — diary extension / reassessment triggers.
Standard-contract sequence
- Map transfer → test eligibility (tree + matrix) → complete PIPIA → negotiate/complete SCC annexes → execute → prepare filing package → file with the provincial CAC → implement safeguards → monitor volume and change → re-file / reassess when required.
Certification sequence
- Eligibility analysis → preparation → certification assessment → remediation → certification → continuing monitoring → material-change review.
Annotated document structures
These are anatomies, not fillable legal templates and not a substitute for the official forms.
PIPIA anatomy
| Section | Why it matters | Evidence to collect | Common drafting failure |
|---|---|---|---|
| 1. Processing activity | Scopes the rest of the file | System list, owners | Copy-paste “HR and related” |
| 2. Transfer description | Defines the export | Access paths, not only ETL | Server-region only |
| 3. Purpose and necessity | Exemption and minimisation | Why each field leaves China | Purpose = “group synergy” |
| 4–6. PI / SPI / individuals | Thresholds live here | Unique counts, SPI flag | Event counts; missing SPI line |
| 7–8. Overseas recipient and method | Onward transfer and access | Legal entity, hosting, subprocessors | Brand name, not legal entity |
| 9–10. Retention and rights | PIPL continues after the mechanism | TTL, DSAR path across borders | “See HQ policy” |
| 11–14. Risk, safeguards, contract, residual risk | This is the assessment | Controls mapped to the access path | ISO logo instead of path-level controls |
| 15–16. Approvals and record | Accountability | Signer, date, next review | Unsigned draft used as “the PIPIA” |
Supporting provision: PIPL Arts. 55–56 (impact assessment duties) — confirm current text for your activity type.
China SCC package anatomy
Main agreement · annexes (transfer description, roles, rights, safeguards) · onward-transfer controls · dispute/remedy · PIPIA linkage · filing support documents. If the annex does not match the live Okta group, the file is fiction.
Security-assessment pack anatomy
Application materials · self-assessment · transfer description · recipient information · contracts · security measures · categories and volumes · important-data analysis · remediation.
Operational records to keep live
Data-flow inventory · threshold register (YTD + forecast) · change log · recipient-diligence memo · annual transfer review.
Practical workflow (operating system)
The original eight steps remain useful after the tree, not instead of it.
- Draw the operation, not the group chart. One record per sales, HR, support, analytics and vendor workflow: subjects, categories, purposes, systems, locations, recipients, retention, every local or remote access path. Group ownership does not decide controller / joint controller / processor.
- Establish the local processing basis (Track B especially): purpose, lawful basis, necessity, transparency, minimisation, retention, rights, DPIA before reuse or export.
- Contract the vendor chain. Instructions, confidentiality, security, sub-processor control, assistance, audit, deletion/return. Map operational access, not the hosting-region label.
- China-based access is a Track B transfer question when the data are EU personal data. It is a Track A export question when mainland data are viewed from overseas.
- SCC and TIA work belongs on Track B (EU modules + annexes + TIA + supplementary measures). Do not reuse that pack as the PRC file.
- Run the mainland PRC interface on Track A — this page’s tree, matrix and calculator.
- Security and incident ownership on the actual access path: authentication, least privilege, logging, encryption/key control, export/download restrictions, vendor assurance, deletion, tested recovery. Incidents open separate EU/EEA and PRC notification assessments immediately.
- Change gate — below.
Track B — EU/EEA personal data accessed from China
This is a separate GDPR workstream. If mainland HQ, engineers, support or HR can retrieve or view EU personal data, put that access on the Chapter V map even where the server remains in Europe. Determine exporter/importer roles. Test adequacy, EU SCCs, BCRs or another lawful mechanism. Do not use Art. 49 derogations as a routine architecture. Complete the correct SCC module, annexes that match the live purposes, a transfer impact assessment, and supplementary measures that address the identified destination risk.
Do not imply that an EU SCC solves PRC outbound-data obligations, or the reverse.
Track C — Data collected outside China, processed in China, sent abroad again
- Where was the data originally collected?
- Has any mainland-China personal information been introduced (joined, enriched, overlayed)?
- Has any important data been introduced or generated in China?
- Does the China processing change the class or the recipients?
If the 2024 Art. 4 conditions appear to hold, a PRC outbound mechanism may not be the right frame — still document the negative: no domestic PI, no important data. If mainland data is joined, return to Track A.
Scenario desk
No card states a categorical legal outcome.
| Scenario | Facts to check | Exemption test | Threshold test | Route candidates | Escalation |
|---|---|---|---|---|---|
| Global HR database | Employee vs applicant; fields; who in HQ has access | HR necessity field-by-field | Unique employees + SPI | Potential HR exemption; else SCC/cert/assessment | Dependents, contractors, lake-wide access |
| Recruitment / applicant CVs | Does overseas HQ decide the hire? How many CVs? | Usually not the employee-HR branch | Applicant unique count + SPI (ID docs) | SCC / cert / minimise / keep in-country | Bulk CV dumps to global inbox |
| Global CRM | Customer PI generated in China; who syncs | Contract necessity only for performance fields | Customer unique persons YTD | Often SCC/cert; assessment if volume/SPI | Marketing overlays, enrichment |
| Foreign SaaS | Admin in China; hosting abroad; support access | Rarely an exemption for the whole tenant | All unique persons in the tenant | Vendor diligence + mechanism | Vendor subprocessors, new region |
| Overseas customer support | Tickets, recordings, follow-the-sun | Emergency only for true emergencies | Ticket unique persons | Minimise + SCC/cert | Call recording = SPI question |
| Centralized analytics | Purpose is not contract performance | Exemption usually weak | Full unique base | Mechanism + DPIA/PIPIA | Profiling, SPI inference |
| Overseas engineering access | Prod data, logs, break-glass | Not HR; not contract-with-individual | Whoever is in the logs | Access control first, then mechanism | Standing prod access |
| Centralized security monitoring | SIEM in HQ; packet/identity data | Narrow necessity only if truly required | Identities in telemetry | Specialist review | Content capture, important data |
| Intra-group data lake | Purposes multiply after landing | Almost never a single exemption | Whole lake unique persons | Often assessment or redesign | Secondary use |
| Overseas-collected data returned abroad | Any China PI joined? | Art. 4 first | Only if mainland PI appears | Track C or back to A | Enrichment in China |
Compliance risk matrix
Risk level = need for legal/compliance escalation, not PR severity.
| Fact / trigger | Why it matters | Risk | Immediate action |
|---|---|---|---|
| Potential important data | Volume tests do not save you | Critical | Stop treating it as ordinary PI; classification memo |
| Threshold near crossing | Route can flip mid-year | High | Forecast + diary; freeze new datasets if needed |
| Sensitive PI in the flow | Separate, lower numeric trigger | High | SPI worksheet; necessity test |
| New China-based remote access to EU data | Track B transfer | High | Chapter V map + TIA |
| Overseas recruitment access | HR exemption often fails | High | Close the global CV inbox until mapped |
| SCC signed but facts changed | Annex no longer true | High | Change gate + re-PIPIA |
| New subprocessors / destination country / dataset | New export | Medium–High | Re-tree that path |
| Acquisition / merger | Systems and counts collapse together | High | Day-1 access freeze + combined count |
| Server-location-only analysis | Misses remote export | High | Rebuild the access map |
| Missing year-to-date unique count | Cannot pick a route | Critical | Do not file or claim an exemption until counted |
Common mistakes
| Mistake | Why it happens | Why it matters | How to fix it |
|---|---|---|---|
| Start with the contract instead of the data flow | Legal owns paper; IT owns systems | Wrong mechanism for the live path | Inventory first, then tree |
| Test thresholds before exemptions | Spreadsheets feel objective | You may file a mechanism you did not need — or miss that PIPL still applies | Node 3 before Node 4 |
| Count transfer events instead of persons | Logs are easy | False escalation or false comfort | De-duplicate unique natural persons |
| Ignore the SPI line | SPI is harder to classify | 10k SPI can force assessment while PI looks “small” | Separate worksheet |
| Treat server location as the only access location | Vendor slide says “EU region” | Remote China/EU access is still a transfer | Map identities, not regions |
| Assume EU SCCs solve PRC requirements | One “international transfer” story | Wrong file, wrong regulator | Two tracks, two packs |
| Treat all group HR flows as necessary | Art. 5 is tempting | Lakes and applicant CVs fall out | Field-level necessity |
| Sign an SCC and stop monitoring volume | Filing feels like the end | Mid-year route change | Threshold register |
| Treat mechanism exemption as a PIPL holiday | Misread “no SCC needed” | Notice, PIPIA, security still bite | Standing caveat on every exemption leaf |
| Ignore change triggers | Programme is a project | Stale annexes | Change gate |
| Mix statutes with non-binding Q&A | Both appear on CAC.gov.cn | Wrong weight in a memo | Hierarchy diagram + source-card type |
| Use undated secondary sources for numeric rules | Blog numbers travel | Wrong band | Provision-level card, dated check |
Action checklist
- Identify exporter and overseas recipient (legal entities, not brands).
- Record all remote-access paths.
- Identify source of the data (mainland vs overseas collection).
- Classify PI, sensitive PI and potential important data separately.
- Record transfer purpose and test necessity.
- Test every available exemption before locking a mechanism.
- Calculate relevant unique-person counts; forecast year-end.
- Determine the potential route (conditional language only).
- Complete the required impact assessment (PIPIA and/or TIA).
- Check notice and, where applicable, separate-consent obligations.
- Review overseas-recipient safeguards and onward transfers.
- Prepare route-specific documents; complete filing/application steps.
- Record change triggers; assign threshold-monitoring ownership.
- Record sources supporting each material conclusion and the last source-verification date.
Signed decision record
The accountable owner signs: roles · lawful bases · notices · vendor terms · transfer mechanism or exemption hypothesis · TIA/PIPIA · PRC route · security measures · residual risks · incident contacts · next review date. This framework is not approval of a transfer or filing strategy.
Change-gate matrix
Reopen the record before a new country, product purpose, data category, system, vendor, sub-processor, China access team, material volume movement, or material legal change. Review high-risk transfers monthly and the full map at least annually.
Sequence: new vendor / country / data / volume / access → recalculate unique persons → re-test exemptions → re-select route → update PIPIA/SCC/assessment documents → diary the next check.
China data-export regulatory updates
| Date | Authority | Development | Practical effect | Affected module | Reviewed by |
|---|---|---|---|---|---|
| 22 Mar 2024 | CAC | Provisions on Promoting and Regulating Cross-border Data Flows | Current national exemption + volume architecture used on this page | Matrix, tree, calculator | Editorial + PRC reviewer (8 August 2026) |
| 15 August 2026 | Editorial | Page rebuilt as a decision guide; official texts re-checked | Two-date metadata; provision-level cards | Whole page | China Legal Portal Editorial |
When CAC or the NPCSC publishes a later instrument, update this table and the “checked through” date before changing numeric cells.
Evidence standard
Every material proposition on thresholds, numbers, deadlines, exemptions, filing, route selection, change triggers or validity must carry a provision-level source card adjacent to the claim. Bottom-of-page link lists are not enough.
Rule = what the source directly states. Our reading for this fact pattern = conditional editorial interpretation. Never merge those into one unsupported conclusion.
No original empirical charts on this page — the site does not yet publish an owned, methodologised dataset of inquiry-route distribution or filing outcomes. Decision trees, matrices, timelines and hierarchy lists are original diagrams, not statistics.
Primary links: PIPL · Data Security Law · Cybersecurity Law · CAC 2024 cross-border data provisions · EU GDPR · EU SCCs · EDPB Recommendations 01/2020
Change log: 15 Aug 2026 — rebuilt from an eight-step EU-first ops note into a three-track PIPL/CAC decision guide (direct answer, glance table, hierarchy, master tree, statutory matrix, calculator with three worked examples, exemption trees, route comparison, timelines, document anatomies, scenario desk, risk and change matrices, mistakes, checklist, decision FAQs, source cards).
Specialist child guides
Each child has one task. They do not replace the pillar tree.
- Exemptions — mechanism tests and remaining PIPL duties
- Thresholds — unique-person counts and bands
- SCC vs certification vs assessment — route comparison
- HR and recruitment data — necessity trees
- Important data and FTZ lists — non-volume triggers
- EU-to-China access (GDPR) — Track B
Get the data-transfer route reviewed
Bring origin and destination, data categories, SPI flag, important-data question, unique-person YTD and forecast, purpose, overseas recipient, current mechanism, and any upcoming change. Directory listings start a PRC-side conversation; they are not a Chapter V or CAC determination.
Get your data-transfer route reviewed Cross-border data-transfer counsel
Going Global knowledge centre · Primary sources desk · Companion path tree
General information for planning and counsel engagement — not legal advice and not an exemption, filing or route determination. Confirm the PIPL, DSL, CSL and CAC instrument versions that apply to your facts. Legally reviewed on 8 August 2026 · Law and official guidance checked through 15 August 2026 · China Legal Portal Editorial






