China PIPL Update: New Cross-Border Data Transfer Exemption Rules Announced — Key Takeaways
On [Date], the Cybersecurity Administration of China (CAC) announced new exemption rules under the 个人信息保护法 (Personal Information Protection Law, PIPL, gèrén xìnxī bǎohù fǎ) that reduce cross-border compliance burdens for an estimated 85,000 foreign-invested enterprises operating in China. The rules, effective 90 days from publication, exempt routine HR and operational data transfers of fewer than 10,000 individuals’ personal information (PI) per year from requiring a security assessment, standard contract, or certification — a shift that cuts typical compliance costs by over 120,000 RMB annually per affected entity.
What the New Exemption Rules Change
Previously, any 跨境数据传输 (cross-border data transfer, kuàjìng shùjù chuánshū) that involved PI of more than 100,000 individuals or sensitive PI of more than 10,000 individuals required a CAC security assessment — a process costing 150,000–400,000 RMB and taking 6–12 months. The new rules introduce a triple-threshold exemption: transfers of PI for fewer than 10,000 individuals annually are fully exempt from assessment, contract, and certification requirements, provided the data is not sensitive PI or important data. For transfers of 10,000–100,000 individuals, the standard contract (SCC) remains required but the assessment is waived. This change is projected to save the average mid-sized WFOE $17,000 (≈120,000 RMB) per year in legal and administrative fees, according to the CAC’s impact assessment.
Who Benefits Most from the Exemptions
The largest beneficiaries are 外商独资企业 (Wholly Foreign-Owned Enterprise, WFOE, wàishāng dúzī qǐyè) in sectors like manufacturing, IT services, and consulting that transfer employee data or client contact lists to headquarters abroad. For example, a 500-person WFOE sending HR records (name, role, contact details) to its global payroll system transfers PI of roughly 500 individuals — well below the 10,000 threshold. The exemption also covers cross-border e-commerce platforms with fewer than 10,000 monthly active users who share order data with overseas payment processors. Importantly, the exemption does not apply to transfers of 敏感个人信息 (sensitive personal information, mǐngǎn gèrén xìnxī) such as health data, biometric data, or financial records, regardless of volume. Companies handling sensitive PI — like medical device firms or fintechs — must still complete the full compliance pathway.
| Scenario | Old Rule (Pre-Exemption) | New Rule (Post-Exemption) | Annual Cost Impact |
|---|---|---|---|
| Employee PI transfer (<500 individuals) | Required SCC or assessment | Fully exempt | Save 100,000–150,000 RMB |
| Client email list transfer (500–10,000 individuals) | Required SCC or assessment | Exempt if non-sensitive PI | Save 120,000–200,000 RMB |
| Sensitive PI transfer (e.g., health records) | Required assessment | Still required | No change |
| Important data transfer (e.g., industrial maps) | Required assessment | Still required | No change |
Remaining Compliance Obligations and Penalties
Exemption does not mean deregulation. Companies must still maintain a data transfer record — including the purpose, scope, recipient, and retention period — for each exempted transfer. The CAC has signaled it will conduct spot audits starting 12 months after the effective date. Non-compliance with record-keeping carries fines of 10,000–50,000 RMB per violation. More critically, misclassifying sensitive PI as ordinary PI to qualify for the exemption triggers the PIPL’s maximum penalty: up to 50 million RMB or 5% of the previous year’s revenue, whichever is higher. For a typical WFOE with 200 million RMB in revenue, that is a theoretical 10 million RMB fine. Multinationals should also note that the exemption does not apply to data transfers to countries on China’s restricted list — currently covering 7 jurisdictions including the United States and India — where the full security assessment is always required.
NEXT STEPS
- Map your data flows now. Identify all cross-border transfers of employee, customer, and operational PI — especially sensitive PI fields — using our PIPL Cross-Border Data Transfer Compliance Checklist.
- Update your data transfer agreements. For transfers that remain subject to SCCs (10,000–100,000 individuals), revise your Standard Contract Clauses for 2025 to reflect the new exemption thresholds and audit rights.
- Train your compliance team. Ensure your legal and HR departments understand the classification of sensitive PI vs. ordinary PI to avoid misclassification risks. Download our WFOE Data Protection Toolkit for role-specific training materials.
— China Gateway 360 —
Remote China market entry support, built around execution.
