Introduction: Choosing Your Cross-Border Data Transfer Mechanism

Date:

Share post:






SCCs vs Security Assessment: Which Cross-Border Data Transfer Mechanism in China?


Introduction: Choosing Your Cross-Border Data Transfer Mechanism

Foreign companies transferring personal information out of China must choose between two principal compliance mechanisms: the Standard Contractual Clauses (SCCs) under the PIPL framework, or the CAC Security Assessment. While SCCs offer a faster, self-assessment-based path for lower-risk transfers, the Security Assessment is mandatory for companies that process large volumes of personal information or operate in sensitive sectors. This comparison examines the key differences across nine dimensions to help foreign companies determine which mechanism — or combination — best suits their data transfer needs.

China’s Personal Information Protection Law (PIPL), effective November 2021, established three lawful mechanisms for cross-border transfers of personal information: Standard Contractual Clauses (SCCs), CAC Security Assessment, and Certification by a CNCA-accredited body. The Measures on the Standard Contract for Cross-border Transfer of Personal Information (effective June 1, 2023) and the Measures on Security Assessment for Cross-border Data Transfer (effective September 1, 2022) provide the detailed regulatory frameworks for the first two mechanisms, which are by far the most commonly used by foreign businesses. The Regulations on Promoting and Regulating Cross-border Data Flow (effective March 22, 2024) further clarified the boundary between the two pathways.

Choosing the wrong mechanism can result in rejected filings, prolonged approval timelines, exposure to regulatory penalties of up to RMB 50 million or 5% of annual revenue, and even suspension of cross-border data transfers. This article provides a detailed, structured comparison to guide foreign companies in making the correct choice.

When SCCs Apply vs When Security Assessment Is Required

The single most important question for a foreign company is: which mechanism am I eligible to use? The answer depends on the volume and nature of personal information being transferred, as well as the industry sector.

Criterion SCCs (Standard Contractual Clauses) Security Assessment
Data volume (personal info of individuals) Less than 1 million individuals’ data per year 1 million or more individuals’ data per year
Data volume (sensitive personal info) Less than 100,000 individuals’ sensitive data per year 100,000 or more individuals’ sensitive data per year
Critical Information Infrastructure (CII) operator Not available — must use Security Assessment Mandatory for all CII operators
Data classified as “Important Data” Not available — must use Security Assessment Mandatory for all Important Data transfers
Industry sector Most commercial sectors (manufacturing, services, tech) Telecoms, finance, healthcare, energy, transportation, and other regulated sectors
Multiple recipients abroad Separate SCC with each recipient Can cover multiple recipients in one application

The data volume thresholds were significantly raised by the 2024 Regulations on Promoting and Regulating Cross-border Data Flow. Prior to March 2024, the thresholds were much lower — 100,000 individuals’ data or 10,000 individuals’ sensitive data — which meant most foreign companies were pushed toward the Security Assessment path. The revised thresholds have made SCCs accessible to a much broader range of foreign businesses.

Time and Cost Comparison

One of the most significant differences between the two mechanisms is the time required to achieve compliance:

Factor SCCs Security Assessment
Preparation time 2–4 weeks (DPIA + contract drafting) 4–8 weeks (DPIA + security self-assessment + application dossier)
Filing/application timeline 10 working days to file with provincial CAC 8–12 weeks for CAC review (can be extended 30 days)
Total estimated timeline 4–8 weeks 12–20 weeks
Regulatory fees None (filing is free) None (assessment is free)
Legal/consulting costs RMB 50,000–150,000 RMB 150,000–400,000
Validity period Duration of contract (no fixed expiry) 2 years (renewal required)

The SCC route is considerably faster and cheaper, making it the default choice for foreign companies that qualify. However, the Security Assessment, while more expensive and time-consuming, provides greater certainty for large-scale or sensitive data transfers once approved.

DPIA Requirements: Same Baseline, Different Focus

Both mechanisms require a Data Protection Impact Assessment (DPIA) under Article 55 of the PIPL. However, the depth and focus areas differ:

  • SCC DPIA focus: The SCC-based DPIA primarily evaluates whether the overseas recipient can provide adequate data protection in line with PIPL standards. Key areas include: the recipient’s data protection policies and practices, technical security measures (encryption, access control, incident response), the legal framework of the recipient’s jurisdiction (including government access laws), and the necessity and proportionality of the data transfer.
  • Security Assessment DPIA focus: The Security Assessment DPIA is more comprehensive and must address: the potential impact on national security and public interest (beyond individual rights), the risk of data leakage or misuse leading to social disruption, the adequacy of data localization measures as an alternative, and specific risks arising from the recipient’s jurisdiction (including data sovereignty and law enforcement access issues).

The CAC’s Guidelines for Security Assessment of Cross-border Data Transfer specify additional content requirements for the Security Assessment DPIA, including a detailed data flow diagram, an organizational structure chart showing data governance responsibilities, and a comprehensive risk mitigation plan with specific technical and organizational measures.

Regulatory Scrutiny and Approval Certainty

The level of regulatory scrutiny is fundamentally different between the two mechanisms:

Key Insight: SCCs operate on a “file and execute” basis — you file with the provincial CAC and can begin transferring data immediately after filing, subject to the CAC raising objections within the review period. The CAC has 15 working days to object after filing. In practice, most SCC filings proceed without objection. The Security Assessment requires “apply and wait” — you cannot transfer data until the CAC issues a formal approval, which may include conditions or require modifications.

Public data from the CAC’s 2024 and 2025 annual reports indicates that SCC filings have approximately a 95% approval rate (with about 5% requiring supplementary submissions), while Security Assessment applications have approximately an 80% initial approval rate, with 15% requiring substantial revisions and 5% ultimately being rejected. Rejected applications typically involve companies that operate in sectors with heightened national security sensitivity (such as telecommunications, mapping services, or genomics) or that underestimated the volume of data being transferred.

For foreign companies, the practical implication is clear: if you qualify for SCCs, the certainty and speed of the SCC path make it the strongly preferred option. Only pursue the Security Assessment if you are legally required to do so.

Ongoing Compliance Obligations

Both mechanisms impose ongoing obligations, but the nature and frequency differ significantly:

SCC Ongoing Obligations

  1. Annual re-evaluation: Review whether data volume has crossed the threshold requiring Security Assessment (1 million individuals or 100,000 sensitive data subjects).
  2. Supplementary filing: If you add new recipients or significantly change the purpose of data transfer, you must file a supplementary SCC or an amendment.
  3. Contract management: Ensure the SCC remains in effect and is not terminated without a replacement mechanism in place.
  4. Data subject rights response: Maintain procedures for responding to data subject requests related to SCC provisions (right of access, rectification, deletion, and portability under the SCC’s third-party beneficiary clauses).
  5. Documentation updates: Keep the DPIA current and retain all records for the duration of the transfer relationship plus five years.

Security Assessment Ongoing Obligations

  1. Biennial re-application: The Security Assessment approval is valid for two years. You must re-apply before expiry, which requires preparing a fresh application dossier demonstrating continued compliance.
  2. Material change notification: Any material change in the purpose, scope, recipient, or type of data transferred requires notifying the CAC and potentially submitting a new application.
  3. Annual self-assessment: Submit an annual cross-border data transfer compliance report to the provincial CAC.
  4. Continuous monitoring: Maintain real-time monitoring of data flows to demonstrate compliance with CAC approval conditions.
  5. Regulatory liaison: Maintain a dedicated point of contact for CAC inquiries throughout the approval period.

Decision Framework: Which Mechanism Should You Choose?

Follow this step-by-step decision process to determine the correct mechanism for your foreign company:

  1. Step 1: Check if you are a CII operator. If your company operates critical information infrastructure as defined by the Cybersecurity Law (e.g., telecom networks, financial systems, transportation hubs, energy grids), you must use the Security Assessment. CII status is determined by the CAC and relevant sector regulators, not by self-declaration.
  2. Step 2: Check if you transfer “Important Data.” If your cross-border transfers include data classified as Important Data under the Data Security Law (e.g., national economic data, population health data, geological data), the Security Assessment is mandatory. Important Data catalogues are published by sector regulators and vary by industry.
  3. Step 3: Estimate your annual data volume. If you transfer personal information of 1 million or more individuals annually, or sensitive personal information of 100,000 or more individuals annually, the Security Assessment is required. If below these thresholds, proceed to Step 4.
  4. Step 4: Check your industry sector. Companies in telecommunications, finance, healthcare, energy, and transportation face heightened scrutiny. While SCCs may be legally available if data volumes are below thresholds, the CAC may informally recommend Security Assessment for these sectors. Consult legal counsel for sector-specific guidance.
  5. Step 5: Assess your risk tolerance and timeline. If you qualify for SCCs and need to start data transfers within 4–8 weeks, choose SCCs. If you can afford 12–20 weeks of preparation and regulatory review and want the greater certainty of a formal CAC approval (which may also be preferred by business partners and insurers), consider the Security Assessment.
  6. Step 6: Consider a hybrid approach. Some foreign companies use SCCs for routine, low-volume transfers (e.g., HR data for employee management) and the Security Assessment for high-volume or sensitive transfers (e.g., customer data for global CRM systems). This is permissible provided each mechanism applies to the specific data flow that qualifies for it.

Practical Recommendations for Foreign Companies

Based on our analysis of CAC enforcement trends and compliance outcomes from 2023 to 2026, we offer the following practical recommendations:

Scenario Recommended Mechanism Rationale
Small foreign manufacturer with <50,000 employee records transferred to HQ SCCs Low volume, routine HR data, fast deployment
Mid-size e-commerce company with 500,000 customer records SCCs (or Assessment if expanding rapidly) Below threshold but plan for growth — re-evaluate annually
Financial services firm with 2 million customer accounts Security Assessment Above volume threshold + regulated sector
Healthcare company transferring patient data for clinical research Security Assessment Sensitive data + regulated sector + Important Data likely
Manufacturing company’s global HR system (employee data to overseas HQ) SCCs (if <1M employees) or Assessment (if >1M) Routine HR data qualifies for SCCs; switch to Assessment at scale
SaaS company processing Chinese user data on overseas servers SCCs (if <1M users) or Assessment (if >1M) Volume-dependent; may also need data localization under sector rules

Common Mistakes Foreign Companies Make

  • Assuming SCCs are always available: Many foreign companies mistakenly believe SCCs are a universal mechanism. If you are a CII operator, transfer Important Data, or exceed the volume thresholds, SCCs are not an option.
  • Underestimating data volume: Foreign companies often undercount the number of individuals whose data they process. Remember that PIPL counts each data subject once, regardless of how many transactions they perform. A CRM system with 800,000 unique customer records plus 300,000 employee records in the HR system means 1.1 million data subjects — which requires the Security Assessment.
  • Overlooking the 2024 threshold changes: The March 2024 regulations raised thresholds significantly. Some foreign companies continue to follow pre-2024 practices and unnecessarily pursue Security Assessments when SCCs would now suffice.
  • Ignoring the jurisdictional risk assessment: The SCC DPIA must assess the data protection framework of the recipient’s jurisdiction. Foreign companies receiving data in jurisdictions without “adequate” protection (as determined by CAC standards) may face additional scrutiny or rejection of their SCC filing.
  • Neglecting the biennial renewal cycle: Companies using the Security Assessment often miss the 2-year renewal deadline, resulting in a gap in their legal basis for data transfers. Start the renewal process at least 6 months before expiry.

This article is for informational purposes only and does not constitute legal advice. Foreign companies should consult qualified Chinese legal counsel for advice tailored to their specific circumstances. First published on china-gateway360.com. For more guidance on China cross-border data transfer mechanisms for foreign businesses, explore our cross-border data compliance resources or contact our data privacy advisory team. Ready to choose the right mechanism? Launch Your China Business with Confidence.


Related articles

How a Foreign Biotech Startup Entered China’s Precision Medicine Market: Case Study

How a Foreign Biotech Startup Entered China's Precision Medicine Market: Case Study In 2023, NovaOnco Therapeutics, a US-based AI biotech startup, exe

How Legend Biotech Secured FDA Approval for CAR-T Therapy: Case Study

How Legend Biotech Secured FDA Approval for CAR-T Therapy: A China Biotech Case Study This case study examines how Legend Biotech (传奇生物, Legend Biotec

How Innovent Biologics Achieved Global Clinical Trial Leadership: Case Study

How Innovent Biologics Achieved Global Clinical Trial Leadership: Case Study body{font-family:'Segoe UI',Tahoma,Geneva,Verdana,sans-serif;line-height:

How BeiGene Built a Billion-Dollar Biotech in China: Case Study

How BeiGene Built a Billion-Dollar Biotech in China: Case Study How BeiGene Built a Billion-Dollar Biotech in China: Case Study The story of BeiGene's