Skip to main content
China Outbound Legal Guides · Going Global from China

China Cross-Border Data Transfers: PIPL & CAC Decision Guide

The lawful China data-export route is fact-dependent. It turns on (1) the direction of the flow, (2) whether a legally relevant export exists — including remote view, API, shared global systems and intra-group access, not only a file leaving a China server — (3) the data class (personal information, sensitive PI, important data, other), (4) exporter status (including any CIIO analysis), (5) whether a current exemption from a transfer mechanism is available to test, (6) annual unique-person counts in the applicable measurement period, (7) which mechanism may then apply (standard contract, certification, or CAC security assessment), and (8) which continuing PIPL duties remain even if a mechanism is not required. An EU SCC does not close a PRC outbound analysis. A PRC mechanism does not close a GDPR Chapter V analysis.

Updated16 Aug 2026
AudienceChinese enterprises, investors, and outbound counsel
Legal planning desk with source documents, authority records and evidence file
Working file · authority, workflow and evidence

Audience: in-house legal, DPO/privacy, compliance, HR, IT/security, procurement, China management and foreign counsel mapping a live flow. Legally reviewed on 8 August 2026 (Niamh Walsh — EU/EEA Chapter V; Tongyu Yan — mainland PRC outbound). Law and official guidance checked through 15 August 2026. Those two dates are not the same thing. Editorial orientation — not a filing, exemption or route determination.

Not legal advice. Do not label a flow “compliant”, “approved”, “no issue” or “definitely exempt” from this page. Use potential exemption, possible route to validate, may require security assessment, requires fact-specific confirmation.

China CBDT roadmap · Export-path tree (companion) · SCC filing timeline/cost · HR/CRM architecture · Employee-data outbound · Going-global playbook.

Direct answer

This page is a decision guide. Walk the tree, fill the calculator assumptions, compare routes, then open the timeline and document anatomy for the terminal state. Unresolved facts stay unresolved. Start the master tree.

Do not mix the three tracks in one route matrix. Journey shortcuts: which route? · we already use an SCC · HR / recruitment · China staff on EU systems · something changed.

At a glance — which workstream first

EDITORIAL TEST Rows are starting hypotheses, not legal conclusions.

If this is trueFirst testLikely workstreamDo not do this
Mainland PI or possible important data is provided overseas (including remote view)Export exists? Class? Exemption?Track AStart with an EU SCC
EU personal data is viewed or retrieved from mainland China; server still in the EEAChapter V transfer + exporter/importer rolesTrack BTreat hosting region as the whole map
Data were collected only outside China and no mainland PI / important data is mixed inOverseas-collected pathwayTrack CAssume processing in China automatically resets the analysis
Unique persons or SPI sit near published volume conditionsCount + year-end forecastCalculatorCount transfer events instead of persons
Vendor, country, team, dataset or volume changed after the last SCC / filingChange gateRe-treeRely on last year’s contract

Scope / legal framework

In scope: classifying a China-related cross-border data operation; testing whether an export exists; separating PI, sensitive PI and important-data questions; testing mechanism exemptions; measuring thresholds; comparing SCC, certification and security assessment; sequencing filings; preparing PIPIA / SCC / assessment packs; running a GDPR Chapter V track when China-based staff access EU data.

Out of scope here: a country-by-country privacy encyclopedia, a fillable “approved” contract template, a city-lawyer directory as the product, or a claim that one signed EU SCC closes both sides.

How the authorities fit together

Track A — Data leaving mainland China

Use this track when personal information, sensitive PI or possible important data is provided from mainland China to an overseas recipient, including: physical transmission, remote access, API, shared global systems, overseas support access and intra-group access. Server location alone is not the test.

Master decision tree — which China data-export route may apply?

Every leaf is a preliminary route to validate. Display the unresolved facts. Then open the matching timeline and document anatomy.

  1. Node 1 — Is data provided from mainland China to an overseas recipient?
    • No → a PRC cross-border transfer mechanism may not apply. Still check other PIPL/DSL/CSL duties and, if EU data is viewed from China, Track B.
    • Yes → continue. Record every access path, not only batch exports.
  2. Node 2 — What data is involved? Classify separately: personal information · sensitive personal information · important data (identified/notified or reasonably in scope) · other/general data. Mixed datasets inherit the stricter applicable test.
  3. Node 3 — Is a mechanism exemption potentially available? Test, in order of the facts, not of convenience: overseas-collected · contractual necessity · cross-border HR · emergency · qualifying lower-volume PI · FTZ negative list.

    Standing caveat: exemption from a transfer mechanism does not necessarily remove notice, separate-consent, PIPIA, security, rights or important-data duties.

  4. Node 4 — Calculate thresholds. Open the calculator before picking SCC vs certification vs assessment.
  5. Node 5 — Terminal states (pick one to validate)
    • Potential exemption — why the branch might fit; conditions; unresolved facts; still-open PIPL duties; next: document the exemption file, do not stop the programme.
    • Standard contract / SCC route — eligibility conditions appear to hold; next: PIPIA + execute + file. Compare · timeline.
    • Certification route — typically intra-group / common processing; not a free substitute for SCC. Next: eligibility + body + monitoring.
    • CAC security assessment — CIIO, important data, or volume/SPI conditions may point here. Next: self-assessment pack + provincial gate. timeline.
    • Specialist review required — important-data doubt, CIIO doubt, mixed tracks, mid-year escalation, or FTZ/sector overlay.

Statutory matrix — rules, thresholds and exceptions

Figures below are the rule as stated in the 22 March 2024 CAC Provisions, restated for navigation. Confirm the instrument in force on the day you file. Measurement language in the measure is tied to estimated provision of PI overseas since 1 January of the current year for the volume tests — do not invent a different counting year without a source.

Trigger / ruleMeasurement periodData categoryThreshold / conditionPossible consequenceExemptions to test firstAuthorityLast verified
Lower-volume PI (non-CIIO)Since 1 Jan of current year (as stated in the measure)PI excluding sensitive PIEstimated provision overseas of PI of fewer than 100,000 personsMay fall outside assessment / SCC / certification if other Art. 5 conditions holdNecessity, HR, emergency, overseas-collected, FTZCAC Provisions Art. 515 August 2026
Mid-volume PI (non-CIIO)SamePI excluding sensitive PI100,000 up to 1,000,000 personsPossible SCC or certification route to validateArt. 4–5, Art. 7Art. 615 August 2026
High-volume PI (non-CIIO)SamePI excluding sensitive PI1,000,000 persons or moreMay require security assessmentArt. 4–5, Art. 7Art. 615 August 2026
Sensitive PI (non-CIIO)SameSensitive PIFewer than 10,000 personsPossible SCC or certificationArt. 4–5 (narrow)Art. 615 August 2026
Sensitive PI escalationSameSensitive PI10,000 persons or moreMay require security assessmentArt. 4–5 (narrow)Art. 615 August 2026
Important dataNot a headcount testImportant dataIdentified / notified or otherwise in scope for outboundSecurity-assessment analysis typically requiredDo not “volume away” important dataDSL + CAC Arts. 2–3, 7–815 August 2026
CIIOStatus-basedPI or important dataCIIO providing such data overseasMay require security assessmentNot a volume exemptionCSL + CAC Art. 815 August 2026
Contract necessityTransaction-specificUsually PI needed to performNecessary to conclude/perform a contract to which the individual is a party (illustrations in Art. 5)Potential mechanism exemptionReject convenience, analytics, marketing add-onsArt. 515 August 2026
Cross-border HREmployment relationshipEmployee PI needed for HRNecessary for cross-border HR under labour rules and collective contractsPotential mechanism exemptionDoes not automatically cover applicants or group-wide lakesArt. 515 August 2026
EmergencyIncident-specificPI needed to protect life, health or propertyNarrow emergency necessityPotential mechanism exemptionNot a standing architectureArt. 515 August 2026
Overseas-collected then re-exportedOrigin of collectionNon-mainland PI / dataNo domestic PI or important data introducedMay fall outside “outbound” treatment in Art. 4Re-test if mainland data is joinedArt. 415 August 2026
FTZ negative listZone + list versionAs listed / not listedIn a participating FTZ and outside that zone’s negative listPossible alternative pathwayConfirm zone, list, sector, current statusArt. 715 August 2026
Change / reassessmentOn material changeAnyNew purpose, recipient, destination, category, volume, access path, or legal changeRe-open route; possible re-filePIPL + route-specific measures15 August 2026

How to calculate China data-export thresholds

Inputs

  • Unique natural persons (not rows, not API calls)
  • Sensitive-PI count and non-sensitive-PI count, held separately
  • Applicable measurement period in the measure you rely on
  • Year-to-date volume and forecast year-end volume
  • Previous exports already placed under SCC or certification
  • Multiple overseas recipients (do not assume each recipient resets the count)
  • Duplicate-person handling across HR, expense, CRM and support systems

Formula (editorial counting model)

Annual exported PI count = relevant unique natural persons whose PI is provided overseas during the applicable counting period.

Rule (what the 2024 Provisions speak to): estimated number of persons whose PI is provided overseas in the stated window. Our reading for this fact pattern: de-duplicate the same individual across systems; do not count transfer events; count SPI on its own line.

Worked example 1 — one employee in three systems

Assumptions: mainland employer exports HR core, expense and payroll fields for the same 800 employees to an overseas HQ HRIS. No applicants. No important-data flag. Non-CIIO. No SPI beyond what HR ordinarily holds — SPI still needs its own line if present.

Formula: unique employees = 800, not 2,400 events.

Calculation: 800 unique persons.

Result: place 800 on the non-SPI and, if applicable, SPI worksheets separately.

Legal consequence: volume alone may sit under a lower-volume or mid-volume band and the HR-necessity exemption still has to be tested field-by-field. Double-counting would falsely escalate the route.

Remaining uncertainty: which fields are SPI; whether contractors/dependents are in the file; whether former employees remain.

Worked example 2 — mid-year cross after an SCC

Assumptions: group filed an SCC when YTD unique persons were 70,000 non-SPI. A CRM go-live will add 50,000 new unique overseas-shared customers before 31 December. Same recipient country.

Calculation: 70,000 + 50,000 = 120,000 unique persons if no overlap; subtract overlap if the same people already sit in the SCC file.

Result: if unique non-SPI persons reach the mid-volume band in the measure, the possible route is no longer “lower-volume exemption”.

Legal consequence: validate whether SCC remains available, whether a new filing / change notice is required, and whether assessment conditions are approaching. Signing last quarter’s SCC does not freeze the count.

Remaining uncertainty: overlap; SPI in the CRM; whether the original SCC described this purpose.

Worked example 3 — SPI and non-SPI overlap

Assumptions: 12,000 unique customers exported; 2,500 of them have a sensitive field (e.g. precise location or a health-adjacent field — classification is itself a legal question).

Calculation: non-SPI worksheet 12,000; SPI worksheet 2,500. Do not subtract the 2,500 from the PI count unless the measure you rely on tells you to — the 2024 text runs SPI as a separate trigger.

Result: two independent tests. SPI at 2,500 may already point to SCC/certification even if total PI is modest; SPI at 10,000+ may point to assessment.

Remaining uncertainty: whether the field is SPI under PIPL; whether emergency/contract necessity covers those fields (usually not for analytics).

Exemption mini-trees

HR-management necessity

  1. Is there a genuine employment (or legally recognised labour) relationship under the rules you rely on?
  2. Is each exported field necessary for that HR purpose — or is it a group data-lake convenience?
  3. What labour rules / collective-contract clauses actually require the overseas recipient to see it?
  4. Who is the overseas recipient (HQ HR vs vendor vs “everyone with Okta”)?
  5. Minimisation: can the same purpose run with fewer fields, fewer people, or in-country access?
  6. Even if the mechanism exemption is available to test, record notice, security, retention and rights.

Recruitment overlay: applicants are often not “HR management of employees”. Ask: does overseas HQ actually participate in the hire; how many applicants; which fields; do all overseas mailboxes need the CV? CVs to a global inbox are a common false “HR exemption”.

Contract-necessity

Distinguish necessary to conclude/perform a contract with the individual (the illustrations in Art. 5 are transactional: cross-border shopping, delivery, payment, account opening, visa, hotel, ticket) from convenience, analytics, marketing and optional profiling. If the contract can be performed without the overseas disclosure, this branch is weak.

Emergency

Narrow. Life, health or property in an actual emergency. Not a standing architecture for “follow-the-sun support”.

FTZ / negative-list

Require: named FTZ · the negative list actually in force · industry/sector match · whether the exporter is in that zone · current legal status. National default is not “FTZ rules apply everywhere”.

Standard Contract vs certification vs CAC security assessment

These are not interchangeable products. Eligibility is statutory.

QuestionStandard Contract (China SCC)CertificationCAC security assessment
When potentially available?Non-CIIO flows that sit in the SCC/cert band of Art. 6 and are not forced to assessmentSame eligibility band; typically group or common-processing designsCIIO, important data, or high-volume / high-SPI conditions in Art. 6–8
Who can use it?Eligible PI handlers meeting the measureEligible handlers that can complete a certification programmeHandlers whose facts trigger assessment
Key threshold conditionsSee matrix — mid-volume PI or sub-10,000 SPI (non-CIIO)Same band; not a bypass of assessment triggers1m+ PI, 10k+ SPI, important data, CIIO outbound
Filing / application required?Yes — file the executed SCC + PIPIA with the provincial CAC (confirm current practice)Certification process with a recognised bodyYes — application via provincial gate to CAC
Main assessment documentPIPIA + SCC annexesCertification dossierSelf-assessment / risk report + application pack
Typical use caseDefined transfers to named overseas recipientsIntra-group recurring processingHigh-risk or high-scale outbound
Intra-group suitabilityOften used; still a contract + fileOften designed for groupsUsed when triggers hit, group or not
Change triggerPurpose, recipient, destination, categories, volumeScope or control changeFacts in the assessment; validity window
Escalation triggerCrossing into assessment band; important-data flag; CIIOSameAlready the high route; watch validity / extension
Validity / continuing obligationsContract + PIPL duties continue after filingSurveillance / recertificationValidity period + extension / re-assessment practice
Main operational burdenPIPIA quality + annex accuracy + volume monitorProgramme design + auditDossier + regulator questions + time
Main advantageNamed, relatively standardised contract pathMay fit stable intra-group processingThe path the high-risk triggers actually require
Key limitationNot available once assessment triggers applyNot a substitute for assessment; capacity/practice still maturingHeavier; not optional if the trigger is real
Primary legal sourcePIPL Art. 38 + SCC measures + 2024 Arts. 5–6PIPL Art. 38 + certification rules + 2024 Arts. 5–6PIPL Art. 40 + assessment measures + 2024 Arts. 6–8

Already on an SCC? Re-run the unique-person count and SPI line → test escalation → open change triggers → confirm whether the filed annex still describes the live purpose. Do not assume last year’s file covers this year’s CRM.

Procedural timelines

Statutory clocks, where they exist, sit on the assessment/SCC measures — not on this page’s editorial sequence. Steps marked “practice-dependent” have no single number here on purpose.

Security-assessment sequence

  1. Data-flow mapping — owner: business + privacy. Output: inventory.
  2. Classify data — owner: legal + security. Output: PI / SPI / important-data record.
  3. Self-assessment / impact work — owner: legal. Output: risk report.
  4. Prepare application — owner: legal + CISO. Output: pack.
  5. Provincial submission — completeness review (practice-dependent timing).
  6. CAC assessment process — statutory/practice timing in the assessment measures; confirm current text.
  7. Decision — implement only the approved scope.
  8. Validity-period monitoring — diary extension / reassessment triggers.

Standard-contract sequence

  1. Map transfer → test eligibility (tree + matrix) → complete PIPIA → negotiate/complete SCC annexes → execute → prepare filing package → file with the provincial CAC → implement safeguards → monitor volume and change → re-file / reassess when required.

Certification sequence

  1. Eligibility analysis → preparation → certification assessment → remediation → certification → continuing monitoring → material-change review.

Annotated document structures

These are anatomies, not fillable legal templates and not a substitute for the official forms.

PIPIA anatomy

SectionWhy it mattersEvidence to collectCommon drafting failure
1. Processing activityScopes the rest of the fileSystem list, ownersCopy-paste “HR and related”
2. Transfer descriptionDefines the exportAccess paths, not only ETLServer-region only
3. Purpose and necessityExemption and minimisationWhy each field leaves ChinaPurpose = “group synergy”
4–6. PI / SPI / individualsThresholds live hereUnique counts, SPI flagEvent counts; missing SPI line
7–8. Overseas recipient and methodOnward transfer and accessLegal entity, hosting, subprocessorsBrand name, not legal entity
9–10. Retention and rightsPIPL continues after the mechanismTTL, DSAR path across borders“See HQ policy”
11–14. Risk, safeguards, contract, residual riskThis is the assessmentControls mapped to the access pathISO logo instead of path-level controls
15–16. Approvals and recordAccountabilitySigner, date, next reviewUnsigned draft used as “the PIPIA”

Supporting provision: PIPL Arts. 55–56 (impact assessment duties) — confirm current text for your activity type.

China SCC package anatomy

Main agreement · annexes (transfer description, roles, rights, safeguards) · onward-transfer controls · dispute/remedy · PIPIA linkage · filing support documents. If the annex does not match the live Okta group, the file is fiction.

Security-assessment pack anatomy

Application materials · self-assessment · transfer description · recipient information · contracts · security measures · categories and volumes · important-data analysis · remediation.

Operational records to keep live

Data-flow inventory · threshold register (YTD + forecast) · change log · recipient-diligence memo · annual transfer review.

Practical workflow (operating system)

The original eight steps remain useful after the tree, not instead of it.

  1. Draw the operation, not the group chart. One record per sales, HR, support, analytics and vendor workflow: subjects, categories, purposes, systems, locations, recipients, retention, every local or remote access path. Group ownership does not decide controller / joint controller / processor.
  2. Establish the local processing basis (Track B especially): purpose, lawful basis, necessity, transparency, minimisation, retention, rights, DPIA before reuse or export.
  3. Contract the vendor chain. Instructions, confidentiality, security, sub-processor control, assistance, audit, deletion/return. Map operational access, not the hosting-region label.
  4. China-based access is a Track B transfer question when the data are EU personal data. It is a Track A export question when mainland data are viewed from overseas.
  5. SCC and TIA work belongs on Track B (EU modules + annexes + TIA + supplementary measures). Do not reuse that pack as the PRC file.
  6. Run the mainland PRC interface on Track A — this page’s tree, matrix and calculator.
  7. Security and incident ownership on the actual access path: authentication, least privilege, logging, encryption/key control, export/download restrictions, vendor assurance, deletion, tested recovery. Incidents open separate EU/EEA and PRC notification assessments immediately.
  8. Change gatebelow.

Track B — EU/EEA personal data accessed from China

This is a separate GDPR workstream. If mainland HQ, engineers, support or HR can retrieve or view EU personal data, put that access on the Chapter V map even where the server remains in Europe. Determine exporter/importer roles. Test adequacy, EU SCCs, BCRs or another lawful mechanism. Do not use Art. 49 derogations as a routine architecture. Complete the correct SCC module, annexes that match the live purposes, a transfer impact assessment, and supplementary measures that address the identified destination risk.

Do not imply that an EU SCC solves PRC outbound-data obligations, or the reverse.

Track C — Data collected outside China, processed in China, sent abroad again

  1. Where was the data originally collected?
  2. Has any mainland-China personal information been introduced (joined, enriched, overlayed)?
  3. Has any important data been introduced or generated in China?
  4. Does the China processing change the class or the recipients?

If the 2024 Art. 4 conditions appear to hold, a PRC outbound mechanism may not be the right frame — still document the negative: no domestic PI, no important data. If mainland data is joined, return to Track A.

Scenario desk

No card states a categorical legal outcome.

ScenarioFacts to checkExemption testThreshold testRoute candidatesEscalation
Global HR databaseEmployee vs applicant; fields; who in HQ has accessHR necessity field-by-fieldUnique employees + SPIPotential HR exemption; else SCC/cert/assessmentDependents, contractors, lake-wide access
Recruitment / applicant CVsDoes overseas HQ decide the hire? How many CVs?Usually not the employee-HR branchApplicant unique count + SPI (ID docs)SCC / cert / minimise / keep in-countryBulk CV dumps to global inbox
Global CRMCustomer PI generated in China; who syncsContract necessity only for performance fieldsCustomer unique persons YTDOften SCC/cert; assessment if volume/SPIMarketing overlays, enrichment
Foreign SaaSAdmin in China; hosting abroad; support accessRarely an exemption for the whole tenantAll unique persons in the tenantVendor diligence + mechanismVendor subprocessors, new region
Overseas customer supportTickets, recordings, follow-the-sunEmergency only for true emergenciesTicket unique personsMinimise + SCC/certCall recording = SPI question
Centralized analyticsPurpose is not contract performanceExemption usually weakFull unique baseMechanism + DPIA/PIPIAProfiling, SPI inference
Overseas engineering accessProd data, logs, break-glassNot HR; not contract-with-individualWhoever is in the logsAccess control first, then mechanismStanding prod access
Centralized security monitoringSIEM in HQ; packet/identity dataNarrow necessity only if truly requiredIdentities in telemetrySpecialist reviewContent capture, important data
Intra-group data lakePurposes multiply after landingAlmost never a single exemptionWhole lake unique personsOften assessment or redesignSecondary use
Overseas-collected data returned abroadAny China PI joined?Art. 4 firstOnly if mainland PI appearsTrack C or back to AEnrichment in China

Compliance risk matrix

Risk level = need for legal/compliance escalation, not PR severity.

Fact / triggerWhy it mattersRiskImmediate action
Potential important dataVolume tests do not save youCriticalStop treating it as ordinary PI; classification memo
Threshold near crossingRoute can flip mid-yearHighForecast + diary; freeze new datasets if needed
Sensitive PI in the flowSeparate, lower numeric triggerHighSPI worksheet; necessity test
New China-based remote access to EU dataTrack B transferHighChapter V map + TIA
Overseas recruitment accessHR exemption often failsHighClose the global CV inbox until mapped
SCC signed but facts changedAnnex no longer trueHighChange gate + re-PIPIA
New subprocessors / destination country / datasetNew exportMedium–HighRe-tree that path
Acquisition / mergerSystems and counts collapse togetherHighDay-1 access freeze + combined count
Server-location-only analysisMisses remote exportHighRebuild the access map
Missing year-to-date unique countCannot pick a routeCriticalDo not file or claim an exemption until counted

Common mistakes

MistakeWhy it happensWhy it mattersHow to fix it
Start with the contract instead of the data flowLegal owns paper; IT owns systemsWrong mechanism for the live pathInventory first, then tree
Test thresholds before exemptionsSpreadsheets feel objectiveYou may file a mechanism you did not need — or miss that PIPL still appliesNode 3 before Node 4
Count transfer events instead of personsLogs are easyFalse escalation or false comfortDe-duplicate unique natural persons
Ignore the SPI lineSPI is harder to classify10k SPI can force assessment while PI looks “small”Separate worksheet
Treat server location as the only access locationVendor slide says “EU region”Remote China/EU access is still a transferMap identities, not regions
Assume EU SCCs solve PRC requirementsOne “international transfer” storyWrong file, wrong regulatorTwo tracks, two packs
Treat all group HR flows as necessaryArt. 5 is temptingLakes and applicant CVs fall outField-level necessity
Sign an SCC and stop monitoring volumeFiling feels like the endMid-year route changeThreshold register
Treat mechanism exemption as a PIPL holidayMisread “no SCC needed”Notice, PIPIA, security still biteStanding caveat on every exemption leaf
Ignore change triggersProgramme is a projectStale annexesChange gate
Mix statutes with non-binding Q&ABoth appear on CAC.gov.cnWrong weight in a memoHierarchy diagram + source-card type
Use undated secondary sources for numeric rulesBlog numbers travelWrong bandProvision-level card, dated check

Action checklist

  • Identify exporter and overseas recipient (legal entities, not brands).
  • Record all remote-access paths.
  • Identify source of the data (mainland vs overseas collection).
  • Classify PI, sensitive PI and potential important data separately.
  • Record transfer purpose and test necessity.
  • Test every available exemption before locking a mechanism.
  • Calculate relevant unique-person counts; forecast year-end.
  • Determine the potential route (conditional language only).
  • Complete the required impact assessment (PIPIA and/or TIA).
  • Check notice and, where applicable, separate-consent obligations.
  • Review overseas-recipient safeguards and onward transfers.
  • Prepare route-specific documents; complete filing/application steps.
  • Record change triggers; assign threshold-monitoring ownership.
  • Record sources supporting each material conclusion and the last source-verification date.

Signed decision record

The accountable owner signs: roles · lawful bases · notices · vendor terms · transfer mechanism or exemption hypothesis · TIA/PIPIA · PRC route · security measures · residual risks · incident contacts · next review date. This framework is not approval of a transfer or filing strategy.

Download / request the data-flow intake checklist

Change-gate matrix

Reopen the record before a new country, product purpose, data category, system, vendor, sub-processor, China access team, material volume movement, or material legal change. Review high-risk transfers monthly and the full map at least annually.

Sequence: new vendor / country / data / volume / access → recalculate unique persons → re-test exemptions → re-select route → update PIPIA/SCC/assessment documents → diary the next check.

China data-export regulatory updates

DateAuthorityDevelopmentPractical effectAffected moduleReviewed by
22 Mar 2024CACProvisions on Promoting and Regulating Cross-border Data FlowsCurrent national exemption + volume architecture used on this pageMatrix, tree, calculatorEditorial + PRC reviewer (8 August 2026)
15 August 2026EditorialPage rebuilt as a decision guide; official texts re-checkedTwo-date metadata; provision-level cardsWhole pageChina Legal Portal Editorial

When CAC or the NPCSC publishes a later instrument, update this table and the “checked through” date before changing numeric cells.

Evidence standard

Every material proposition on thresholds, numbers, deadlines, exemptions, filing, route selection, change triggers or validity must carry a provision-level source card adjacent to the claim. Bottom-of-page link lists are not enough.

Rule = what the source directly states. Our reading for this fact pattern = conditional editorial interpretation. Never merge those into one unsupported conclusion.

No original empirical charts on this page — the site does not yet publish an owned, methodologised dataset of inquiry-route distribution or filing outcomes. Decision trees, matrices, timelines and hierarchy lists are original diagrams, not statistics.

Primary links: PIPL · Data Security Law · Cybersecurity Law · CAC 2024 cross-border data provisions · EU GDPR · EU SCCs · EDPB Recommendations 01/2020

Change log: 15 Aug 2026 — rebuilt from an eight-step EU-first ops note into a three-track PIPL/CAC decision guide (direct answer, glance table, hierarchy, master tree, statutory matrix, calculator with three worked examples, exemption trees, route comparison, timelines, document anatomies, scenario desk, risk and change matrices, mistakes, checklist, decision FAQs, source cards).

Specialist child guides

Each child has one task. They do not replace the pillar tree.

Get the data-transfer route reviewed

Bring origin and destination, data categories, SPI flag, important-data question, unique-person YTD and forecast, purpose, overseas recipient, current mechanism, and any upcoming change. Directory listings start a PRC-side conversation; they are not a Chapter V or CAC determination.

Get your data-transfer route reviewed Cross-border data-transfer counsel

Going Global knowledge centre · Primary sources desk · Companion path tree

General information for planning and counsel engagement — not legal advice and not an exemption, filing or route determination. Confirm the PIPL, DSL, CSL and CAC instrument versions that apply to your facts. Legally reviewed on 8 August 2026 · Law and official guidance checked through 15 August 2026 · China Legal Portal Editorial

Legal source archive with indexed legislation and official records
Source register · primary authorities and verification
Sources & trust

How to use this guide

Primary sources cited on this page: Signed decision record; Does overseas remote access to China-hosted data count as a data export?; Does being under 100,000 individuals mean no filing is needed?; Do exemptions need to be tested before thresholds?; How are individuals counted across multiple systems?; What happens if a threshold is crossed after an SCC is signed?; Can applicant CVs be sent to overseas HQ?; Does the HR exemption cover every intra-group employee-data transfer?; Can certification be used instead of the Standard Contract?; How does important data change the analysis?; Does an EU SCC satisfy China requirements?; Does China-based access to EU-hosted data create a GDPR transfer?.

Editorial, AI and verification policies

This page is general information for orientation. It is not legal advice and does not create an attorney–client relationship.

Review the Editorial Policy, AI Content Policy, and Lawyer Verification Policy.

FAQ

Common questions

Quick answers for foreign nationals and employers. Rules vary by city and change over time.

Does overseas remote access to China-hosted data count as a data export?

It often does: providing PI to an overseas recipient includes retrieval/view from outside the mainland. Next → Node 1.

Does being under 100,000 individuals mean no filing is needed?

Not automatically. The lower-volume branch in the 2024 Provisions is conditional (non-CIIO, PI excluding SPI, and the rest of Art. 5). Important data and CIIO sit outside that comfort. PIPL duties may remain. Next → matrix.

Do exemptions need to be tested before thresholds?

Yes — otherwise you may pick a mechanism you did not need, or miss that the exemption is narrower than the dataset. Next → Node 3 then calculator.

How are individuals counted across multiple systems?

Unique natural persons, de-duplicated. Example 1. Next → calculator.

What happens if a threshold is crossed after an SCC is signed?

The filed route may no longer match the facts. Re-count, test escalation, and take the procedural step the new band requires. Example 2.

Can applicant CVs be sent to overseas HQ?

Only after a purpose, necessity and mechanism analysis. The employee-HR exemption often does not cover applicants. Next → HR / recruitment tree.

Does the HR exemption cover every intra-group employee-data transfer?

No. Necessity is field- and recipient-specific. A lake is not “HR”.

Can certification be used instead of the Standard Contract?

Only inside the same eligibility band, and only if a certification programme actually fits. It is not a bypass of assessment triggers. Next → comparison.

How does important data change the analysis?

It is not a headcount problem. It typically forces a security-assessment analysis. Next → risk matrix.

Does an EU SCC satisfy China requirements?

No. Separate tracks. Next → Track B vs Track A.

Does China-based access to EU-hosted data create a GDPR transfer?

Treat it as a potential Chapter V transfer and map roles. Next → Track B.

What changes require reassessment?

Purpose, category, recipient, destination, access team, volume band, vendor/sub-processor, or the law. Next → change gate.

Consultation preparation

What to prepare before contacting counsel

Send a focused first package so counsel can check conflicts, understand scope, and identify urgent deadlines.

  • A concise timeline and the result you want to achieve.
  • Names of all parties and affiliates for a conflict check.
  • Key contracts, notices, correspondence, filings, or decisions.
  • Known deadlines, preferred language, location, and budget constraints.
Directory

Destination and China-side counsel

Use International Lawyers for host-country counsel. Use Find Counsel when a PRC workstream (ODI, SAFE, onshore entities, mainland contracts) still sits beside the destination matter.

Status shown per profileFree initial consultationDestination + PRC routing

Browse data privacy & cybersecurity directory →

Cross-border legal details arranged for a prepared counsel enquiry
Next route · prepared enquiry

Move from orientation to a properly prepared legal brief.

Bring the parties, objective, relevant documents, chronology, known deadlines and the decision you need counsel to make.

Prepare your legal enquiry →

Need destination or China-side counsel?

Coordinate host-country lawyers with PRC counsel when funding, approvals, or onshore entities remain in the matter.