What happens if a foreign company fails a CAC data export security assessment?

Date:

Share post:






What happens if a foreign company fails a CAC data export security assessment?


What happens if a foreign company fails a CAC data export security assessment?

For foreign companies in China that process large volumes of personal information, passing the Cyberspace Administration of China (CAC) Data Export Security Assessment is a mandatory prerequisite for cross-border data transfers. But what happens if the assessment is not passed? The consequences are significant: the company must immediately cease all cross-border data transfers covered by the failed assessment, faces potential enforcement actions including fines and operational restrictions, and must pursue alternative compliance pathways or restructure its data processing operations to resume lawful transfers.

1. Understanding the CAC Security Assessment framework

The Data Export Security Assessment is established under the Measures on Data Export Security Assessment (effective September 1, 2022). It applies to foreign companies that meet any of the following thresholds:

  • Transferring personal information of 1 million or more individuals annually
  • Transferring sensitive personal information of 10,000 or more individuals in the preceding year
  • Transferring important data as defined by Chinese laws and regulations
  • Being identified by the CAC as a critical information infrastructure operator (CIIO)

The assessment evaluates whether the proposed cross-border data transfer poses risks to national security, public interests, or the lawful rights and interests of individuals. The CAC’s review is comprehensive, covering data categories, volumes, purposes, the recipient’s data protection measures, the legal framework of the receiving jurisdiction, and the adequacy of the data transfer agreement.

2. Immediate consequences of a failed assessment

When the CAC issues a notice that a Data Export Security Assessment has not been passed, the following immediate consequences take effect:

2.1. Mandatory cessation of data transfers

The most immediate and disruptive consequence is that the company must cease all cross-border data transfers covered by the failed application. This includes:

  • Suspending transfers of employee data to global HR systems
  • Halting transmission of customer data to overseas servers or parent company systems
  • Stopping the transfer of operational or analytics data to foreign affiliates
  • Discontinuing any other data flows identified in the assessment application

This cessation is legally binding upon receipt of the CAC’s notice. Continued data transfer after a failed assessment constitutes a separate violation of the PIPL and the Data Security Law (DSL), carrying additional penalties.

2.2. Business disruption

The operational impact on foreign companies can be severe:

  • Global HR operations: Companies that cannot transfer employee data to centralized payroll, benefits, or performance management systems may need to establish local China-based alternatives or migrate to separate China-hosted instances.
  • Customer service disruption: Companies that rely on global CRM systems may lose the ability to serve Chinese customers effectively or maintain unified customer profiles.
  • Financial reporting delays: Companies that consolidate global financial data may face delays in reporting or need to implement China-specific financial systems.
  • R&D and analytics interruptions: Foreign companies that transfer Chinese user data for product development or analytics may lose access to critical market insights.
  • Supply chain impacts: Manufacturing companies that need to share production data with overseas parent companies may face production delays or quality control gaps.

3. Options after a failed assessment

A failed CAC Security Assessment is not necessarily the end of the road. Foreign companies have several options:

3.1. Rectification and re-application

The CAC’s notice typically includes a detailed explanation of the reasons for the failure. Common reasons include:

  • Inadequate data protection impact assessment (PIPIA) that fails to address specific risks adequately
  • Insufficient technical and organizational measures by the overseas data recipient
  • The legal framework of the receiving jurisdiction does not provide adequate data protection
  • Inconsistencies or gaps in the data mapping documentation
  • Failure to demonstrate necessity and proportionality of the data transfer

After addressing these deficiencies, the company can re-submit a revised application. The re-submission process requires:

  1. Thoroughly addressing each deficiency identified by the CAC
  2. Potentially renegotiating data protection terms with the overseas recipient
  3. Updating the PIPIA with new risk assessments and mitigation measures
  4. Providing supplementary documentation on technical safeguards
  5. Demonstrating changes made since the previous submission

There is no mandatory waiting period before re-application, but companies should allow sufficient time to implement meaningful improvements rather than making superficial changes.

3.2. Downscoping to the SCC pathway

If the company’s data volumes and types can be adjusted, it may be possible to downscope the data transfer to qualify for the Standard Contractual Clauses (SCC) pathway instead. This could involve:

  • Reducing the volume of personal information transferred to below the 1 million individual threshold
  • Pseudonymizing or anonymizing data so it no longer qualifies as personal information
  • Implementing data localisation for certain categories of sensitive data
  • Splitting data flows so that only some transfers fall under the SCC mechanism

The SCC pathway has a less burdensome review process and may be more achievable for companies that can demonstrate adequate data protection measures.

3.3. Data localisation

As a last-resort compliance strategy, the company may need to implement full data localisation — keeping all Chinese personal information within China and processing it on China-hosted infrastructure. This requires:

  • Setting up local servers or cloud instances for Chinese data processing
  • Implementing systems that can operate without access to overseas corporate systems
  • Hiring local data processing and compliance staff
  • Ensuring that localised systems meet the same functional and security requirements as global systems

While data localisation is operationally burdensome and costly, it may be the only viable option for companies that repeatedly fail the Security Assessment or operate in sensitive industry sectors where the CAC maintains strict oversight.

4. Enforcement actions and penalties

Beyond the direct consequence of the failed assessment, the CAC and other regulatory bodies may initiate enforcement actions:

Violation Potential Penalty Legal Basis
Continuing data transfer after failed assessment Up to 50 million RMB or 5% of annual revenue PIPL Art. 66
Responsible individual (legal representative, DPO, senior manager) Up to 1 million RMB personal fine PIPL Art. 66
Failure to implement corrective measures within deadline Suspension of relevant business operations, revocation of license PIPL Art. 66
Serious violations affecting national security Criminal liability for responsible individuals DSL Art. 45, Criminal Law
Reputational penalty Public listing as “non-compliant entity” on CAC website Common regulatory practice
Restriction on future filings Heightened scrutiny or automatic rejection of subsequent filings for 1-3 years Regulatory discretion

5. Strategic considerations for foreign companies

Given the serious consequences of a failed assessment, foreign companies should adopt a proactive strategy:

  1. Invest in pre-filing preparation: Engage experienced China data privacy counsel to conduct a pre-submission readiness review. This can identify potential deficiencies before formal submission and significantly reduce the risk of failure.
  2. Maintain parallel compliance pathways: While preparing the Security Assessment application, simultaneously prepare contingency plans for the SCC pathway or data localisation. This ensures business continuity if the Security Assessment fails.
  3. Implement a data transfer fallback plan: Before submitting the Security Assessment, develop a detailed fallback plan that specifies how the company will operate if transfers are suspended. This should cover HR operations, customer service, financial reporting, and any other affected business functions.
  4. Negotiate with overseas recipients in advance: Ensure that the overseas data recipient is prepared to implement enhanced data protection measures if the CAC requires them. Pre-negotiate adjustments to data processing agreements to allow for rapid implementation of CAC-required changes.
  5. Monitor regulatory developments: China’s cross-border data transfer regime is evolving rapidly. Companies should monitor regulatory updates from the CAC and adjust their compliance strategies accordingly.
  6. Build relationships with local CAC offices: Some local CAC offices offer informal guidance channels. Establishing a constructive relationship can help companies understand regulatory expectations before formal submission.

6. Real-world considerations and risk mitigation

As of mid-2026, the CAC has processed several hundred Security Assessment applications. Industry reports indicate that the initial pass rate is approximately 50-70%, with many applications requiring at least one round of corrections before approval. Common pitfalls include:

  • Incomplete data mapping: Many companies fail to identify all data flows or data categories in their initial application.
  • Inadequate recipient vetting: Companies often underestimate the level of detail required about the overseas recipient’s data protection measures.
  • Insufficient risk analysis: The PIPIA must demonstrate a thorough understanding of cross-border data risks and provide concrete mitigation measures — generic risk statements are insufficient.
  • Jurisdictional concerns: Transfers to countries with limited privacy frameworks receive heightened scrutiny. Companies should document the specific legal protections available in the receiving jurisdiction.

Conclusion

Failing a CAC Data Export Security Assessment has serious consequences for foreign companies in China, from immediate cessation of cross-border data transfers to significant financial penalties and operational disruption. However, failure is not permanent — companies can rectify deficiencies, re-apply, downscope to the SCC pathway, or implement data localisation as alternatives. The most effective strategy is proactive: thorough preparation, parallel compliance planning, and early engagement with experienced China data privacy counsel significantly reduce the risk of failure and ensure business continuity. Foreign companies operating in China should view the Security Assessment not as a regulatory hurdle to overcome once but as an ongoing compliance obligation that requires continuous monitoring and adaptation as data processing activities and regulatory requirements evolve.


Related articles

How a Foreign Biotech Startup Entered China’s Precision Medicine Market: Case Study

How a Foreign Biotech Startup Entered China's Precision Medicine Market: Case Study In 2023, NovaOnco Therapeutics, a US-based AI biotech startup, exe

How Legend Biotech Secured FDA Approval for CAR-T Therapy: Case Study

How Legend Biotech Secured FDA Approval for CAR-T Therapy: A China Biotech Case Study This case study examines how Legend Biotech (传奇生物, Legend Biotec

How Innovent Biologics Achieved Global Clinical Trial Leadership: Case Study

How Innovent Biologics Achieved Global Clinical Trial Leadership: Case Study body{font-family:'Segoe UI',Tahoma,Geneva,Verdana,sans-serif;line-height:

How BeiGene Built a Billion-Dollar Biotech in China: Case Study

How BeiGene Built a Billion-Dollar Biotech in China: Case Study How BeiGene Built a Billion-Dollar Biotech in China: Case Study The story of BeiGene's