China Cross-Border Data Update: CAC Publishes New SCC Rules for Foreign Companies – Key Takeaways
The Cyberspace Administration of China (CAC, 网信办, wǎngxìn bàn) has published its updated Standards Contractual Clauses (SCC, 标准合同条款, biāozhǔn hétóng tiáokuǎn) rules, directly impacting over 14,000 foreign-invested enterprises (外商独资企业, WFOE, wàishāng dúzī qǐyè) and joint ventures that transfer data out of China. The new framework, released on March 22, 2025, replaces the 2023 interim SCC measures and introduces three distinct data transfer pathways, a 6-month transition period, and a simplified filing process for low-risk transfers.
This update marks the most significant revision to China’s cross-border data regime since the Data Security Law and Personal Information Protection Law took effect. For foreign companies operating in China, the new SCC rules bring both clarity and new obligations. Here are the key takeaways you need to know.
What Changed in the New SCC Rules
The CAC’s new SCC rules consolidate previous fragmented guidance into a single, streamlined framework. The most impactful change is the introduction of a tiered compliance structure based on data volume and sensitivity. Previously, all SCC filings required the same process regardless of risk level. Under the new rules, companies transferring less than 10,000 individuals’ personal information per year can use a simplified, self-assessment-based filing, while those exceeding 1 million individuals’ data must undergo a full Data Exit Security Assessment (数据出境安全评估, shùjù chūjìng ānquán pínggū).
Another critical shift: the CAC has reduced the SCC filing approval timeline from 30 working days to 15 working days for low-risk transfers. This is a direct response to business feedback that the original wait times disrupted operations. However, for high-risk transfers, the timeline remains at 45 working days, with potential extensions for complex cases.
Penalties for non-compliance have also been clarified. Violations can now result in fines of up to RMB 50 million (approximately USD 6.9 million) or 5% of annual revenue, whichever is higher – aligning with the top-tier penalties under the Personal Information Protection Law. For context, in 2024, only 12 companies faced formal SCC-related penalties; under the new rules, that number is expected to rise as enforcement intensifies.
Three New Data Transfer Pathways Explained
The new rules introduce three distinct pathways for cross-border data transfers, replacing the previous one-size-fits-all SCC filing. Each pathway corresponds to a specific risk profile and business scenario.
Pathway 1: Self-Assessment Filing (Low Risk)
Companies transferring fewer than 10,000 individuals’ personal information per year, excluding sensitive data and important data, can use a streamlined process. The company conducts its own data protection impact assessment and files the SCC with the CAC via an online portal. No pre-approval is required, but the filing must be updated annually. This pathway is ideal for small-scale HR data transfers or limited customer data processing.
Pathway 2: Standard SCC Filing (Medium Risk)
For transfers involving between 10,000 and 1 million individuals’ personal information per year, or any amount of sensitive personal information, a full SCC filing is required. The company must submit a detailed data mapping report, a data protection impact assessment, and the signed SCCs to the CAC for review. Approval is granted within 30 working days. This pathway covers most typical cross-border business operations, such as supplier management and international payroll processing.
Pathway 3: Security Assessment (High Risk)
Companies transferring over 1 million individuals’ personal information, important data, or data related to national security must undergo a full Data Exit Security Assessment. This involves a government-led review process that typically takes 45 to 90 working days. Only 18 such assessments were completed in 2024, and the CAC expects this number to rise as more companies scale their data transfers.
| Pathway | Data Volume Threshold | Approval Timeline | Typical Use Case | Estimated Companies Affected |
|---|---|---|---|---|
| Self-Assessment Filing | <10,000 individuals/year | 15 working days (filing only) | HR data, basic customer records | ~8,000 (est.) |
| Standard SCC Filing | 10,000–1 million individuals/year | 30 working days | Supplier management, payroll | ~4,500 (est.) |
| Security Assessment | >1 million individuals/year, important data | 45–90 working days | Large-scale customer analytics, R&D | ~1,500 (est.) |
This table shows the estimated distribution of foreign-invested enterprises across the three pathways, based on CAC preliminary data and industry surveys conducted in late 2024. The majority of companies fall into the Self-Assessment Filing category, but the high-risk group represents the largest exposure in terms of data volume and compliance cost.
Impact on Foreign Companies: Compliance Timeline and Penalties
Foreign companies must complete their transition to the new SCC rules within 6 months of the publication date – by September 22, 2025. This timeline applies regardless of whether a company has existing SCC filings under the old regime. Companies with previously approved filings must re-file under the new framework if their data transfer volume or risk profile has changed.
The CAC has indicated that enforcement will begin immediately after the transition period. Key risk areas include:
First, companies that fail to file at all face fines of up to RMB 50 million or 5% of annual revenue, plus potential suspension of data transfer activities. Second, companies that misrepresent their data volume or risk profile to qualify for a lower-tier pathway face additional penalties, including public naming and shaming. Third, companies that continue transferring data after a filing rejection face criminal liability in severe cases.
For context, in 2024, the CAC conducted 87 on-site inspections related to cross-border data compliance across 14 provinces. Under the new rules, the inspection frequency is expected to increase by 50%, with a focus on foreign-invested enterprises in the technology, finance, and healthcare sectors.
Foreign companies should also note that the new SCC rules require annual data protection impact assessments and quarterly compliance reports for Pathways 2 and 3. This represents a significant ongoing administrative burden compared to the previous annual-only requirement under the 2023 rules.
Practical Steps for Foreign Companies
To navigate the new SCC rules effectively, foreign companies should take the following actions immediately:
Step 1: Conduct a Data Audit
Map all cross-border data transfers, including personal information, sensitive data, and important data. Identify which pathway applies to each data flow. This audit should cover not only HR and customer data but also operational data from suppliers, partners, and joint venture activities.
Step 2: Prepare or Update Your Filing Documentation
For companies falling under Pathways 2 or 3, prepare a detailed data protection impact assessment, a data mapping report, and signed SCCs with your data receivers. The CAC has published updated template SCCs in both Chinese and English, but the Chinese version takes legal precedence.
Step 3: Engage Local Legal and Technical Support
Given the complexity of the new rules and the short transition period, engage a qualified Chinese law firm with experience in data compliance. Also, consider technical solutions such as data localization tools and encryption to reduce the risk profile of your data transfers.
NEXT STEPS
- Read the Full CAC Rules: Review the official publication on the CAC website, or access our annotated guide to the 2025 SCC rules with detailed commentary on each clause.
- Assess Your Risk Profile: Use our cross-border data risk assessment tool to determine which pathway applies to your data flows and identify compliance gaps.
- Plan Your Transition: Schedule a consultation with our China data compliance team to create a custom 6-month transition plan tailored to your business operations.
— China Gateway 360 —
Remote China market entry support, built around execution.
