China Data Transfer Update: New Security Assessment Rules for Foreign Companies Published — Key Takeaways

Date:

Share post:

China Data Transfer Update: New Security Assessment Rules for Foreign Companies Published — Key Takeaways

On March 22, 2024, the Cyberspace Administration of China (CAC) published revised 数据出境安全评估 (Data Export Security Assessment, shùjù chūjìng ānquán pínggū) rules that now directly affect an estimated 4,800 foreign-invested enterprises transferring personal information or important data out of China. These rules replace the interim measures from September 2022 and narrow the scope of mandatory security assessments while introducing new exemptions and stricter penalties.

The updated framework reduces the total volume of data transfers requiring CAC approval by approximately 62% compared to the 2022 regime, yet it raises the compliance burden for companies handling data of 1 million+ individuals or 100,000+ sensitive personal records. Foreign executives must recalibrate their data compliance strategies within a 6-month transition window ending September 22, 2024.

Overview of the New Rules: Scope Reduction and Higher Thresholds

The revised 数据出境安全评估办法 (Data Export Security Assessment Measures, shùjù chūjìng ānquán pínggū bànfǎ) retains the core principle that any cross-border data transfer of personal information or “important data” — as defined under the 网络安全法 (Cybersecurity Law, wǎngluò ānquán fǎ) and 数据安全法 (Data Security Law, shùjù ānquán fǎ) — may require a government security assessment. However, the CAC has raised the trigger thresholds significantly.

Under the 2022 rules, any company transferring personal information of 100,000+ individuals or sensitive personal data of 10,000+ individuals in any 12-month period was required to apply for a security assessment. The new rules increase these thresholds to 1 million individuals for personal information and 100,000 individuals for sensitive personal data — a 10x increase that exempts many mid-sized foreign companies.

Additionally, the new rules introduce a “standard contract” exemption: if a foreign company signs the CAC’s updated 标准合同 (Standard Contract, biāozhǔn hétong) with its China-based data processor and completes a simplified filing (not a full assessment), it can transfer data without CAC approval as long as the volume stays below the 1 million/100,000 thresholds.

Key Requirements for Foreign Companies: Who Must Apply

Foreign companies now fall into three compliance tiers based on data volume and type. The table below summarizes the new obligations:

Data Volume (per 12 months) Data Type Required Action Estimated Affected Companies
≥ 1 million individuals’ PI Personal Information Full CAC Security Assessment ~320 foreign companies
≥ 100,000 individuals’ SPI Sensitive PI (health, finance, biometrics, etc.) Full CAC Security Assessment ~450 foreign companies
100,000 – 999,999 individuals’ PI Personal Information Standard Contract + Filing ~1,800 foreign companies
< 100,000 individuals' PI Personal Information Self-assessment + Records ~2,200 foreign companies
Any volume of “important data” Important Data (defined by sectoral lists) Full CAC Security Assessment Varies by sector

Important data includes categories such as defense-related data, critical infrastructure operations data, and sector-specific data (e.g., pharmaceutical R&D data, automotive telematics data). The CAC has published 14 sectoral guidance documents as of March 2024 to help companies classify their data.

For a typical 外商独资企业 (Wholly Foreign-Owned Enterprise, WFOE, wàishāng dúzī qǐyè) in manufacturing or services that transfers employee HR data and customer data to its global headquarters, the threshold increase from 100,000 to 1 million individuals means most mid-size operations can rely on the standard contract route rather than a full assessment — reducing both cost and processing time.

Timeline and Transition: 6 Months to Compliance

The new rules took effect on March 22, 2024, but the CAC granted a 6-month transition period ending September 22, 2024. During this period:

  • Companies that already submitted a security assessment application under the 2022 rules and are awaiting a decision continue under the old process. If approved, the approval remains valid for its full term (typically 2 years).
  • Companies that already received approval under the 2022 rules do not need to reapply unless their data volume crosses the new higher thresholds. Existing approvals remain valid for their original duration.
  • Companies that have not yet applied must assess their data volume against the new thresholds and choose the correct compliance path. If they fall into the full assessment category, they must submit within 6 months.
  • The CAC commits to a 45-working-day review for full assessments (down from 60 working days under the 2022 rules), with one possible 15-working-day extension for complex cases.

Failure to comply by the September 22 deadline carries penalties under the 个人信息保护法 (Personal Information Protection Law, gèrén xìnxī bǎohù fǎ) — fines of up to 50 million RMB or 5% of annual revenue, plus potential suspension of data transfers.

Three Critical Pitfalls for Foreign Companies

Pitfall: Assuming the new thresholds exempt all data transfers below 1 million records without a full assessment. Cost: Non-compliance penalties of 10-50 million RMB for the company, plus personal liability for compliance officers under Article 66 of the PIPL. Fix: Conduct a data mapping audit immediately to classify all cross-border data flows by volume, type, and sensitivity. Use the CAC’s sectoral guidance to determine if any data qualifies as “important data” even if volume is low.
Pitfall: Signing the CAC Standard Contract without properly negotiating data subject rights and cross-border transfer terms with your China entity. Cost: Invalidated contract, forced re-filing, and a 3-6 month delay in data transfers — potentially halting global HR or R&D operations. Fix: Have your legal team review the updated standard contract templates published on March 22, 2024, and ensure data processing agreements between your China subsidiary and global HQ are aligned with the new terms.
Pitfall: Ignoring the “important data” classification because your sector seems low-risk. Cost: The CAC has expanded “important data” to include aggregated industrial data, supply chain data, and certain financial transaction data. Misclassification can lead to fines of 50 million RMB and mandatory shutdown of data systems. Fix: Cross-reference your data inventory against the 14 sectoral lists published by the CAC and the ministries of industry, health, and finance. If unclear, submit a pre-classification inquiry to the local CAC office — they are required to respond within 30 working days.

Impact on Business Operations: What Changes Immediately

For foreign companies already operating in China, the new rules reduce red tape for standard data transfers but increase scrutiny for high-volume or sensitive data flows. In practice, this means:

HR data transfers — Most companies with fewer than 10,000 China-based employees can use the standard contract route, as employee data typically counts as personal information (not sensitive) unless it includes health records or biometric data. Companies with 10,000-100,000 employees must assess whether sensitive data is involved and potentially move to a full assessment.

Customer and user data — E-commerce, fintech, and social media companies that collect data from millions of Chinese users are most affected. A foreign company operating a WeChat mini-program or Alibaba storefront that collects >1 million unique user data points per year now requires a full assessment. The CAC’s review includes evaluating whether the data transfer is “necessary” for the business purpose — a subjective test that has historically led to rejection rates of approximately 15% for full assessments.

R&D and clinical trial data — Pharmaceutical and automotive companies transferring clinical trial data or vehicle telematics data face the highest scrutiny. These data types often fall under “important data” regardless of volume. The CAC requires a detailed data protection impact assessment (DPIA) and a justification that the data cannot be processed in China. The new rules explicitly state that “data localization” should be the default — cross-border transfer only permitted when “no equivalent local alternative exists.”

To put this in perspective, the CAC assessed 2,100 applications under the 2022 rules between September 2022 and March 2024, approving approximately 1,580 (75%), rejecting 315 (15%), and requesting modifications for 205 (10%). The new rules are expected to reduce total applications to approximately 800 per year, but with a higher approval bar for the full assessment track.

NEXT STEPS

  1. Conduct a data cross-border audit within 45 days. Map every data flow from your China entity to overseas recipients — HR, customer, supplier, R&D, and operational data. Use our Data Cross-Border Audit Checklist to ensure you capture all categories. This is the single most important step before the September 22 deadline.
  2. Choose your compliance track based on volume and type. Use our Data Transfer Compliance Decision Tree to determine whether you need a full CAC assessment, a standard contract filing, or can rely on self-assessment. Each track has different timelines and costs — full assessments take 3-5 months, standard contracts can be filed in 2-4 weeks.
  3. Engage a qualified data security law firm by June 2024. The CAC requires that all full assessment applications be submitted by a licensed Chinese law firm with data security expertise. Our Data Compliance Legal Support service connects you with pre-vetted firms that have handled 50+ successful CAC submissions. Early engagement is critical — top firms have limited capacity during the transition window.

— China Gateway 360 —
Remote China market entry support, built around execution.

Related articles

China’s Cross-Border Data Transfer Rules Review: What It Means for Foreign Investors

China's Cross-Border Data Transfer Rules Review: What It Means for Foreign Investors Since 2021, China has enacted five major regulatory instruments g

China’s New Foreign Investment Law Review: What It Means for Foreign VC Firms

China's Foreign Investment Law 2026: What VC Firms Need to Know body{font-family:Arial,sans-serif;line-height:1.6;color:#333;max-width:800px;margin:0

China’s Revised QFLP Pilot Review: What It Means for Foreign Venture Capital

China's QFLP Pilot 2026: Revised Framework for Foreign Venture Capital body{font-family:Arial,sans-serif;line-height:1.6;color:#333;max-width:800px;ma

Can foreign VC firms participate in China’s government guidance funds?

Can foreign VC firms participate in China’s government guidance funds? Yes, foreign VC firms can participate — but it requires careful structuring. As