What is the Chinese Standard Contractual Clause for data transfer?

Date:

Share post:

What is the Chinese Standard Contractual Clause for Data Transfer?

The Chinese Standard Contractual Clause (SCC) — officially the Measures for the Standard Contract for Cross-border Transfer of Personal Information — is a legally binding template contract adopted by China’s Cyberspace Administration of China (CAC) to govern the cross-border transfer of personal information from China to overseas recipients, effective June 1, 2023. Under China’s 个人信息保护法 (Personal Information Protection Law, gèrén xìnxī bǎohù fǎ) or PIPL, organizations transferring personal data abroad must use one of three mechanisms: this standard contract, a security assessment, or third-party certification. The SCC is designed for low-to-medium-volume transfers involving fewer than 1 million individuals per year, with fines for non-compliance reaching up to 50 million RMB or 5% of annual revenue for serious violations.

What Are the Chinese Standard Contractual Clauses?

The Chinese SCC is not a voluntary contract — it is a mandatory template issued by the CAC that must be used as-is with no substantive modifications. The 标准合同条款 (Standard Contractual Clauses, biāozhǔn hétóng tiáokuǎn) cover all cross-border transfers of personal information where the data exporter is a Chinese entity (e.g., a WFOE, joint venture, or Chinese company) and the data importer is an overseas recipient.

Key rules under the SCC include:

  • The contract must be signed between the Chinese data exporter and the overseas data importer — not with the individual data subjects.
  • The contract must be filed with the CAC within 10 working days of taking effect.
  • The SCC template contains mandatory clauses on data purpose, retention period, liability, and data subject rights.
  • No changes to the standard provisions are allowed; only optional annexes (e.g., technical measures) can be customized.

The SCC is modelled after the EU’s Standard Contractual Clauses but includes China-specific requirements such as a mandatory data protection impact assessment (DPIA) and a requirement to allow the CAC to audit the overseas recipient.

When Do You Need the Chinese SCC (and When Can You Skip It)?

You must use the Chinese SCC if your organization transfers personal information from China to an overseas recipient and does not qualify for an exemption. The SCC is the most common mechanism for foreign companies operating in China, especially those with fewer than 1 million data subjects, because it avoids the time and cost of a full security assessment.

Thresholds for SCC vs. Security Assessment

Data Transfer Volume Mechanism Required Filing / Approval Timeline
Fewer than 100,000 individuals per year Chinese SCC File with CAC within 10 working days
100,000 to 1 million individuals per year Chinese SCC File with CAC within 10 working days
Over 1 million individuals per year Data cross-border security assessment Apply for CAC approval (60–90+ days)
Transfer of important data (e.g., state secrets, critical infrastructure data) Data cross-border security assessment Apply for CAC approval (90+ days)
Transfers within a multinational group (e.g., HR data to HQ) Chinese SCC or Security Assessment (depending on volume) File SCC within 10 days or apply for assessment

Decision Framework: If your organization transfers personal data of fewer than 1 million individuals annually and does not handle important data, choose the Chinese SCC. If you transfer data on 1 million+ individuals or handle important data, choose the Data Cross-Border Security Assessment.

Key Obligations Under the Chinese SCC

Signing the Chinese SCC is not the end — it triggers ongoing compliance obligations for both the Chinese exporter and the overseas importer.

For the Chinese Data Exporter

  • Conduct a DPIA (数据保护影响评估, shùjù bǎohù yǐngxiǎng pínggū) before signing the SCC. This must document the data categories, transfer purpose, risks, and mitigation measures.
  • File the SCC with the CAC within 10 working days of the contract taking effect. Filing is done online via the CAC portal; no pre-approval is needed, but the CAC can reject the filing within 10 working days if the contract is incomplete.
  • Maintain records of all transfers, DPIA reports, and data subject requests for at least 5 years.
  • Report data breaches to the CAC and affected individuals within 24 hours for severe breaches.

For the Overseas Data Importer

  • Contractual liability: The overseas recipient is jointly liable with the Chinese exporter for any damages caused by data breaches or non-compliance.
  • Audit rights: The CAC and the Chinese exporter have the right to audit the overseas recipient’s data protection practices.
  • Data subject rights: The overseas recipient must respond to requests for access, correction, deletion, and portability from Chinese data subjects within 30 days.
  • Sub-processor controls: The overseas recipient cannot engage sub-processors without prior written consent from the Chinese exporter and notification to data subjects.

How to File the Chinese SCC with the CAC

  1. Prepare your DPIA: Assess the necessity, proportionality, and risks of the cross-border transfer.
  2. Draft the contract: Use the CAC’s standard template (available in Chinese only) and fill in the annexes with specific data fields, retention periods, and technical measures.
  3. Sign the contract: Both parties (Chinese exporter + overseas importer) must sign the same version. Electronic signatures are accepted.
  4. File the contract: Submit the signed contract + DPIA report + supporting documents via the CAC’s online portal within 10 working days of signing.
  5. Await feedback: The CAC has 10 working days to issue a notice of rejection if the filing is incomplete. If no notice is received, the SCC is deemed effective.
  6. Maintain compliance: Keep records for 5 years, report breaches within 24 hours for severe incidents, and update the SCC if the purpose or data categories change.
Pitfall: Filing the SCC late or with an incomplete DPIA. Cost: The CAC can reject the filing, requiring a re-submission and effectively halting all cross-border transfers. In severe cases, fines of up to 5 million RMB per violation. Fix: Start the DPIA process at least 4–6 weeks before you plan to sign the SCC. Have a Chinese legal compliance partner review the filing before submission.
Pitfall: Assuming the SCC covers all transfers once signed. Cost: If the purpose, data category, or overseas recipient changes, the existing SCC becomes invalid. A new SCC must be signed and re-filed. Fix: Use a dynamic contract management system that monitors changes to data flows and automatically triggers contract updates. Assign a data compliance officer to track changes quarterly.
Pitfall: Not training your overseas team on data subject request obligations. Cost: Failure to respond to a Chinese data subject’s access request within 30 days can lead to individual complaints to the CAC and fines of up to 50,000 RMB per unresolved request. Fix: Set up a cross-border data subject request procedure with clear SLAs (e.g., 10 business days to respond, 30 days to fulfill). Appoint a China-based point of contact for all data subject communications.

Frequently Asked Questions

Q: Can I use the EU SCC instead of the Chinese SCC?
A: No. The Chinese SCC is a separate regulatory requirement under PIPL. Even if you already have an EU SCC in place, you must sign and file a separate Chinese SCC for data transfers out of China. The two contracts can coexist but must be independently compliant.

Q: What happens if I do not file the SCC?
A: Cross-border transfers without an SCC or alternative mechanism are illegal. The CAC can issue fines up to 50 million RMB or 5% of the organization’s annual turnover for serious violations, and can suspend all data transfers out of China. Individual liability for the legal representative also applies, including personal fines of up to 1 million RMB.

Q: Do I need a DPIA for every SCC?
A: Yes. The PIPL mandates a DPIA before any cross-border personal information transfer. The DPIA must be documented and kept on file for at least 5 years. It does not need to be submitted with the SCC filing but must be produced upon CAC request.

Q: How long is the SCC valid?
A: The SCC is valid for the duration of the data transfer purpose. There is no maximum validity period, but if the purpose, data types, or processing methods change, a new SCC must be signed. The CAC recommends reviewing the SCC annually as part of your compliance audit.

Q: Should I designate a China-based data protection officer (DPO)?
A: Yes — it is strongly recommended. While PIPL requires a DPO only for certain categories (e.g., critical information infrastructure operators, organizations processing large volumes of sensitive data), appointing a China-based DPO is best practice for any company using the SCC. The DPO will handle CAC communications, data subject requests, and annual compliance reviews.

NEXT STEPS

— China Gateway 360 —
Remote China market entry support, built around execution.

Related articles

How a British Heritage Brand Registered a Trademark in China in 6 Months: Luxury Case Study

How a British Heritage Brand Registered a Trademark in China in 6 Months: Luxury Case Study How a British Heritage Brand Registered a Trademark in Chi

How an Italian Luxury Brand Won Gen Z Consumers on Douyin in China: Luxury Case Study

How an Italian Luxury Brand Won Gen Z Consumers on Douyin in China: Luxury Case Study How an Italian Luxury Brand Won Gen Z Consumers on Douyin in Chi

How a French Fashion House Opened 20 Boutiques in China in 12 Months: Luxury Case Study

How a French Fashion House Opened 20 Boutiques in China in 12 Months: Luxury Case Study How a French Fashion House Opened 20 Boutiques in China in 12

Standalone Boutique vs Department Store: Which China Retail Format for Luxury Brands?

Standalone Boutique vs Department Store: Which China Retail Format for Luxury Brands? For luxury brands entering China, the choice between a standalon