Tianjin FTZ Data Export Rules: 45 Data Types Under China’s First Cross-Border Negative List

Date:

Share post:

What Is the Tianjin FTZ Cross-Border Data Negative List?

The Tianjin Pilot Free Trade Zone (FTZ) Cross-Border Data Transfer Negative List (天津自贸区数据出境管理清单, Tiānjīn Zìmào Qū Shùjù Chūjìng Guǎnlǐ Qīngdān) is China’s first zone-level framework that identifies 45 specific data types across 13 categories requiring government security review before they can be transferred outside China. Released by the Tianjin FTZ Management Committee and Tianjin Municipal Commerce Bureau, it gives foreign companies operating in the zone a clear compliance map — data not on the list can flow with fewer regulatory hurdles.

Why This Matters for Your China Investment

If your business handles customer data, supply chain information, or operational analytics in China, cross-border data transfer (CBDT) rules directly affect where you can locate operations and how you manage IT infrastructure. Since China’s Personal Information Protection Law (PIPL, 个人信息保护法) took effect in 2021, companies exporting data faced three compliance routes: a CAC security assessment, a standard contract with the overseas recipient, or a protection certification — any one of which could take months and cost tens of thousands of dollars in legal fees.

The Tianjin FTZ negative list changes this equation. For the first time, companies operating in a specific zone know exactly which data triggers a security review. Data outside the 45 listed categories can be exported under a streamlined process. For a foreign manufacturer sending production data to headquarters or an e-commerce platform syncing customer analytics across regions, this clarity can reduce compliance costs by an estimated 30–50% compared to operating outside an FTZ.

And this is not a one-off. China’s Cybersecurity Administration (CAC) has authorized all 21 FTZs to publish their own negative lists under the 2024 Regulations to Promote and Standardize Cross-Border Data Flows. Shanghai’s Lingang New Area has already followed with general data whitelists for automotive, biopharma, and mutual fund sectors. More FTZ-level rules are expected through 2026, turning data compliance into a genuine location-selection variable for foreign investors.

The Details: What the Tianjin Framework Actually Covers

The negative list divides controlled data into two tiers. The first tier — 45 data types requiring a full CAC security assessment — spans 13 categories: strategic materials (petroleum, petrochemicals, natural gas), natural resources and basic geographical information, national defense industry and rare earths, smart vehicles, civil nuclear facilities, banking and insurance, economic and social statistics, telecommunications and broadcasting, housing fund data, postal and transportation, public health and biosecurity, public and cybersecurity, and internet services including e-commerce and platform service data.

If your business is a foreign auto parts supplier, your production data likely falls outside these categories — but R&D telemetry from connected vehicles in China might not. If you run a food import business, your logistics data is clear, but biosecurity-related testing data from Chinese labs could hit the public health category. The second tier covers data requiring a standard contract — a lighter compliance burden — for categories where the volume or sensitivity is lower.

The practical takeaway: most foreign manufacturing, retail, and professional services firms will find 90%+ of their operational data outside the strictest Tier-1 categories. The negative list removes the uncertainty that previously led companies to over-comply — storing all data onshore in expensive China-only servers — when they could have been using hybrid cloud models legally.

What You Should Do

If you are evaluating China market entry or expanding existing operations, data compliance should now be on your site-selection checklist alongside tax rates, labor availability, and logistics costs. Here is a three-step action plan:

  • Map your data flows first. Before choosing a location, catalog every data type your China operations will generate: customer PII, supply chain records, production telemetry, financial reporting, employee HR data. Flag any that could fall under the 13 Tianjin categories.
  • Compare FTZ data regimes. Tianjin published the strictest negative list — good if you want maximum clarity. Shanghai Lingang published whitelists — better if your sector (auto, pharma, funds) is explicitly covered. Other FTZs like Hainan and Guangdong are drafting their own lists. The right zone depends on your data profile.
  • Build compliance into your IT architecture from day one. Segregate regulated data from non-regulated data at the database level. A manufacturer that separates production telemetry (unregulated) from connected-vehicle R&D data (potentially regulated under “smart vehicles”) can export 80% of its data freely while only quarantining the sensitive 20%.

One Data Point

The number to remember: 45. That’s how many data types the Tianjin FTZ has explicitly listed as requiring a security assessment — meaning thousands of other data categories used by foreign businesses in daily operations face no such barrier. For context, the PIPL’s original scope was so broad that an estimated 70% of foreign firms in China reported over-complying on data localization, according to a 2023 European Chamber survey. The negative list approach shrinks that compliance surface dramatically.

Where to Go From Here

The Tianjin negative list is a template, not an endpoint. As more FTZs publish their own data frameworks through 2026, the competitive landscape for foreign investment will increasingly be shaped by data compliance clarity. For deeper guidance on PIPL enforcement and FTZ investment incentives:

— China Gateway 360 —
Remote China market entry support, built around execution.

Official Sources

Related articles

China Fair Competition Policy Week 2026: Review Local Incentives Before Relying on Them

Information date: 7 September 2026 — China’s State Administration for Market Regulation scheduled the 2026 Fair Competition Policy Publicity Week for 7–11 September and listed 95 activities focused on fair-competition po

China Cross-Border Cash Pooling Expands on 14 September: Revalidate the Treasury Perimeter

Information date: 7 September 2026 — A PBOC and SAFE notice issued on 14 August 2026 takes effect on 14 September and expands the integrated cross-border renminbi and foreign-currency cash-pooling policy nationwide, with

China Entry Checklist Case: Test a Representative Office Against a Subsidiary Before Filing

Information date: 7 September 2026 — China’s official business-service information distinguishes market-entry procedures and business forms; a representative office and a foreign-invested company do not provide the same

Registered Capital Resource: Turn China Company-Law Commitments Into a Funding Calendar

Information date: 7 September 2026 — China’s revised Company Law took effect on 1 July 2024 and generally requires shareholders of a newly formed limited liability company to pay subscribed capital within five years afte