Introduction: Two Assessment Paths, One Compliance Destination

Date:

Share post:






CAC Assessment vs Self-Assessment: Which Compliance Path for Foreign Companies in China?


Introduction: Two Assessment Paths, One Compliance Destination

Foreign companies transferring personal information out of China must navigate a two-tier compliance assessment framework: the self-assessment (conducted internally by the data processor) and the CAC Security Assessment (conducted by the Cyberspace Administration of China). The self-assessment is required for all cross-border data transfers as part of the DPIA process, while the CAC Security Assessment is a formal regulatory review triggered by specific data volume and sensitivity thresholds. This comparison examines ten critical dimensions to help foreign companies understand when each applies, how they differ in scope and rigour, and how to prepare for both.

China’s cross-border data transfer regulatory framework, established by the PIPL (2021), the Data Security Law (2021), and the Measures on Security Assessment for Cross-border Data Transfer (2022), creates a two-tier assessment structure. The self-assessment is an internal compliance exercise that all data processors must complete before initiating any cross-border data transfer. The CAC Security Assessment is a formal regulatory review with potentially binding outcomes — it applies only to specific categories of transfers and processors that meet defined thresholds.

The 2024 Regulations on Promoting and Regulating Cross-border Data Flow introduced important clarifications, including higher volume thresholds for mandatory CAC Assessment and recognition that a properly conducted self-assessment can serve as the basis for lower-risk transfers. Understanding the distinction between the two is essential for foreign companies to allocate compliance resources efficiently and avoid regulatory penalties.

When Each Assessment Applies

The most critical distinction is the trigger for each assessment type:

Criterion Self-Assessment (Required for ALL transfers) CAC Security Assessment (Required only for specified high-risk transfers)
Legal basis PIPL Article 55 + Article 56 (DPIA requirement) PIPL Article 40 + DS Measures on Security Assessment
Applicable to Every personal information processor before any cross-border transfer CII operators, Important Data processors, processors handling 1M+ individuals’ data, sensitive data of 100K+ individuals
Trigger event Before first cross-border transfer + when material changes occur Before first cross-border transfer (if threshold met) + every 2 years (renewal)
Can it be substituted by the other? No — self-assessment is always required regardless of CAC Assessment No — CAC Assessment is a separate, additional requirement when thresholds are met
Volume threshold for mandatory application No threshold — applies to all transfers regardless of volume 1M+ individuals’ data OR 100K+ individuals’ sensitive data per year

A critical point often misunderstood by foreign companies: the self-assessment is NOT a substitute for the CAC Security Assessment, and vice versa. If your company meets the thresholds for mandatory CAC Assessment, you must complete BOTH a self-assessment (as part of your DPIA) AND submit to the formal CAC Security Assessment. If your company is below the thresholds, you still must complete the self-assessment but do not need a CAC Security Assessment.

Scope and Depth of Review

The self-assessment and CAC Security Assessment differ substantially in their scope, methodology, and depth of review:

Dimension Self-Assessment CAC Security Assessment
Conducted by Internal compliance team or external legal counsel on behalf of the processor Provincial CAC (initial review), then National CAC (final decision)
Documentation required DPIA report, data flow mapping, consent records, transfer agreement draft Full application dossier (including DPIA + Security Self-Assessment Report + agreement + corporate documents + data flow diagrams + risk mitigation plan)
Review criteria Legality, necessity, proportionality of transfer; adequacy of recipient’s protection; data subject rights impact National security and public interest impact; data sovereignty risks; recipient jurisdiction’s government access risk; data leakage and misuse potential; adequacy of processor’s governance
Outcome Internal compliance decision (proceed with transfer, modify, or halt) Binding regulatory decision (approve, approve with conditions, or reject)
Review timeline 2–4 weeks (self-managed) 8–12 weeks (can be extended by 30 working days)

The Self-Assessment Process: Step by Step

Every foreign company transferring personal information from China must complete a self-assessment as part of the Data Protection Impact Assessment (DPIA) required by PIPL Articles 55 and 56. The following steps outline the self-assessment process:

  1. Data flow mapping: Identify all personal information collected from individuals in China, document the data flow from collection to storage to transfer, and classify each data element by category (general personal information, sensitive personal information, Important Data).
  2. Legal basis identification: For each data processing purpose, identify the applicable legal basis under PIPL Article 13 (consent, contractual necessity, legal obligation, vital interests, public interest, legitimate interests, or publicly available information). For cross-border transfers, additionally verify that separate consent has been obtained under Article 39.
  3. Transfer mechanism selection: Determine whether the transfer qualifies for SCCs, requires CAC Security Assessment (based on volume/sensitivity thresholds and CII/Important Data status), or can use certification. Document the rationale for the chosen mechanism.
  4. Recipient assessment: Evaluate the overseas recipient’s data protection capabilities, including: data security policies and procedures, technical security measures (encryption standards, access control, incident response), the legal framework in the recipient’s jurisdiction (including government surveillance and law enforcement access laws), and the recipient’s track record of data protection compliance.
  5. Risk identification and mitigation: Identify risks to data subjects’ rights and interests arising from the transfer, including: unauthorized access, data leakage, re-identification risk, onward transfer without adequate protection, and inability of data subjects to exercise their rights against the overseas recipient. Document mitigation measures for each identified risk.
  6. Compliance conclusion: Document the decision to proceed with the transfer (or not), including any conditions, limitations, or additional safeguards that will be implemented.

The CAC Security Assessment Process: What to Expect

The CAC Security Assessment follows a formal, structured process with regulatory timelines and specific documentation requirements. Foreign companies that meet the mandatory thresholds should prepare for the following process:

  1. Pre-application preparation (4–8 weeks): Compile the full application dossier, which includes: the DPIA report, the Security Self-Assessment Report (a separate document from the DPIA, focusing on national security and public interest impact), the executed cross-border data transfer agreement (SCC or equivalent), corporate registration documents of the foreign company and its China entity, a detailed data flow diagram, and a risk mitigation plan. The Security Self-Assessment Report is the most time-consuming document — it requires the processor to self-evaluate its data security governance framework, technical protection measures, and compliance history.
  2. Provincial CAC submission: Submit the application dossier to the provincial-level CAC in the jurisdiction where the processor is registered in China. If the foreign company does not have a physical entity in China, submission is made through the China-based PIPL representative.
  3. Provincial CAC preliminary review (5–10 working days): The provincial CAC reviews the application for completeness and basic compliance. If the dossier is incomplete, the applicant has 5–10 working days to provide supplementary materials. The provincial CAC then forwards the application to the National CAC with its preliminary opinion.
  4. National CAC substantive review (7–45 working days): The National CAC conducts the substantive security assessment. The standard review period is 7 working days for straightforward applications. For complex cases involving sensitive data, large volumes, or sensitive recipient jurisdictions, the review can take up to 45 working days, with one possible extension of 30 working days.
  5. Decision and notification: The CAC issues a written decision: approval (unconditional), approval with conditions (specific measures the processor must implement), or rejection. Rejected applications may be resubmitted after a cooling-off period, typically 6 months unless the basis for rejection is addressed earlier.

Key Differences in Documentation Requirements

The documentation burden differs significantly between the two assessment types:

Document Self-Assessment CAC Security Assessment
DPIA report Required (core document) Required (as part of application dossier)
Security Self-Assessment Report Not required as separate document Required — detailed self-evaluation of security governance
Data flow diagram Recommended but not mandatory Mandatory — graphical representation of all data flows
Organisational chart (data governance) Not required Required — showing data protection responsibilities
Risk mitigation plan Internal document Formal document submitted to CAC
Corporate documents (business license, etc.) Not required Required — proof of legal establishment
Cross-border transfer agreement Draft or executed version Executed version + CAC filing/approval proof
Consent records (sample) As supporting evidence As supporting evidence

Risk Assessment: Different Focal Points

Perhaps the most important substantive difference between the two assessments is the scope of risk analysis:

  • Self-assessment risk focus: The self-assessment evaluates risks to data subjects’ rights and interests — individual-level risks such as identity theft, financial loss, discrimination, reputational damage, and loss of control over personal information. The assessment considers whether the overseas recipient provides an adequate level of protection and whether technical and organisational measures are sufficient to protect the data.
  • CAC Security Assessment risk focus: The CAC assessment evaluates risks at three levels: (a) individual level — same as the self-assessment; (b) public interest level — potential impact on social stability, public order, and economic development if data is misused or leaked; and (c) national security level — risks related to data sovereignty, foreign government access to Chinese citizens’ data, and the potential for data to be used in ways that harm China’s national security interests.

The national security lens is unique to the CAC Security Assessment and is the dimension that most foreign companies find difficult to prepare for. The CAC’s national security assessment considers factors such as the recipient’s country’s legal framework for government access to data (including intelligence-sharing alliances like the Five Eyes), the recipient country’s trade sanctions or technology restrictions against China, and the potential for data to be used in legal or administrative proceedings against China’s interests.

Cost and Timeline Comparison

Factor Self-Assessment CAC Security Assessment
Internal preparation cost RMB 20,000–80,000 (staff time, data mapping tools) RMB 80,000–200,000 (internal team + management time for application preparation)
External legal/consulting cost RMB 30,000–80,000 (optional — external counsel for DPIA review) RMB 150,000–400,000 (China-qualified counsel mandatory for complex applications)
Total estimated cost RMB 20,000–160,000 RMB 230,000–600,000
Timeline 2–4 weeks 12–20 weeks (including preparation + CAC review)
Re-application frequency When material changes occur Every 2 years (mandatory renewal)

Practical Recommendations: Preparing for Both

Given that the self-assessment is mandatory for all foreign companies transferring data from China, and the CAC Security Assessment is mandatory for companies meeting specified thresholds, the most efficient approach is to build a compliance program that serves both pathways:

  • Prepare self-assessment documentation to CAC Assessment standards. Even if your company is below the thresholds today, preparing self-assessment documentation with the rigour of a CAC Security Assessment application ensures you can quickly transition to the formal assessment process if data volumes grow or regulatory thresholds change.
  • Conduct a pre-audit self-assessment before engaging the CAC. Before submitting a formal CAC Security Assessment application, conduct an internal readiness review against the CAC’s published assessment criteria. This pre-audit identifies gaps and reduces the risk of the CAC finding deficiencies during its review.
  • Maintain a continuous self-assessment process. The self-assessment should not be a one-time exercise. Foreign companies should conduct self-assessments at least annually, or whenever there is a material change in data processing activities, to ensure ongoing compliance readiness.
  • Engage China-qualified legal counsel for the CAC Assessment. The CAC Security Assessment involves legal and procedural nuances that general data protection counsel may not be familiar with. Engage a law firm with specific CAC Security Assessment experience — ideally one that has guided other foreign companies through the process.
  • Document everything. For both assessment types, thorough documentation is the single most important success factor. Create a compliance documentation repository that includes all DPIAs, self-assessment reports, data flow maps, consent records, transfer logs, and risk assessments, maintained in both Chinese and English where applicable.

This article is for informational purposes only and does not constitute legal advice. Foreign companies should consult qualified Chinese legal counsel for advice tailored to their specific circumstances. First published on china-gateway360.com. For more guidance on China cross-border data compliance, explore our CAC compliance resources or contact our regulatory advisory team. Ready to prepare for your assessment? Launch Your China Business with Confidence.


Related articles

How a Foreign Biotech Startup Entered China’s Precision Medicine Market: Case Study

How a Foreign Biotech Startup Entered China's Precision Medicine Market: Case Study In 2023, NovaOnco Therapeutics, a US-based AI biotech startup, exe

How Legend Biotech Secured FDA Approval for CAR-T Therapy: Case Study

How Legend Biotech Secured FDA Approval for CAR-T Therapy: A China Biotech Case Study This case study examines how Legend Biotech (传奇生物, Legend Biotec

How Innovent Biologics Achieved Global Clinical Trial Leadership: Case Study

How Innovent Biologics Achieved Global Clinical Trial Leadership: Case Study body{font-family:'Segoe UI',Tahoma,Geneva,Verdana,sans-serif;line-height:

How BeiGene Built a Billion-Dollar Biotech in China: Case Study

How BeiGene Built a Billion-Dollar Biotech in China: Case Study How BeiGene Built a Billion-Dollar Biotech in China: Case Study The story of BeiGene's