Executive Summary
China’s cross-border data regime is no longer a single approval process. A foreign-invested company must first identify what data leaves China, whether the transfer contains personal information or important data, whether the exporter is a critical information infrastructure operator, and the cumulative number of individuals involved. Only then can it select the correct route: exemption, personal information protection certification, a standard contract, or a security assessment.
The most important current thresholds come from the Cyberspace Administration of China’s Provisions on Promoting and Regulating Cross-Border Data Flows, effective since 22 March 2024. For a non-CIIO data processor, fewer than 100,000 individuals’ non-sensitive personal information transferred from 1 January of the current year can generally fall within the procedural exemption. Transfers of 100,000 to fewer than 1 million individuals’ non-sensitive personal information generally require a standard contract or certification. A security assessment is required at 1 million individuals, at 10,000 individuals’ sensitive personal information, or whenever important data is exported. The underlying Personal Information Protection Law obligations still apply.
Why Cross-Border Data Compliance Matters
Foreign companies routinely create data exports without sending a spreadsheet overseas. Remote access by a regional headquarters, cloud hosting outside China, global HR systems, centralized customer support, overseas analytics and group cybersecurity monitoring can all create a cross-border data flow. A compliance analysis limited to the IT department will therefore miss commercial, HR, finance, research and supply-chain transfers.
The route also affects implementation timing. A company that discovers late in a system rollout that it needs a security assessment, a standard contract filing or a redesigned data set may have to delay the launch. The practical objective is not to maximize filings. It is to reduce the data and transfer scope to what the business genuinely needs, document the legal basis and use the least burdensome lawful route.
Regulatory Background and Market Context
The Personal Information Protection Law sets the national rules for processing personal information and establishes conditions for providing personal information outside China. The Data Security Law and sector rules govern important data. The 2022 Measures for Data Export Security Assessment created the national security-assessment process. The 2024 provisions then narrowed the cases that need formal procedures, raised relevant thresholds and authorized pilot free trade zones to create data-export negative lists.
Implementation has continued to evolve. The CAC reported in March 2025 that, during the first year of the 2024 provisions, average monthly security-assessment submissions fell by about 60% and standard-contract filings by about 50%. The reduction indicates that exemptions and clearer thresholds are changing compliance workloads, but it does not remove the need for a documented data inventory and personal information protection impact assessment where required.
Key Factors to Consider
1. What Counts as a Data Export?
A transfer can occur when data is transmitted or stored outside China, or when an overseas organization or individual can access, retrieve, download or export data stored in China. System architecture and access permissions matter as much as the physical location of a server.
2. Personal Information, Sensitive Personal Information and Important Data
These categories drive different obligations. Sensitive personal information includes information that, if leaked or misused, can easily harm personal dignity or safety, such as biometric, medical, financial-account, precise-location and certain minor-related information. Important data is assessed through national and sector classification rules. Under the 2024 provisions, data should not be treated as important data solely because the company is uncertain; the processor looks to formal notification or publicly issued catalogues and rules.
3. CIIO Status
Critical information infrastructure operators face stricter treatment. A CIIO exporting personal information or important data must use the security-assessment route. Companies should not self-declare CIIO status based only on industry sensitivity, but they should check formal designation and sector supervision.
4. Annual Volume and Data Minimization
The personal-information thresholds are calculated cumulatively from 1 January of the current year. Separate systems and business units should not be counted in isolation if the same data processor controls the transfers. Data minimization can change the applicable route: removing unnecessary fields, localizing historical records, restricting overseas access and separating sensitive information may reduce both risk and procedural burden.
Step-by-Step Compliance Process
- Map every transfer scenario. Record the China exporter, overseas recipient, system, business purpose, access method, data fields, frequency and retention period.
- Classify the data. Separate non-personal business data, personal information, sensitive personal information and possible important data.
- Confirm the legal basis. Identify the PIPL basis for processing and complete required notices, consents or human-resources documentation.
- Count individuals correctly. Calculate cumulative annual volumes for non-sensitive and sensitive personal information.
- Check exemptions. Test the contract-performance, cross-border HR, emergency, overseas-origin and low-volume exemptions in the 2024 provisions.
- Select the transfer route. Use an exemption, certification, standard contract or security assessment based on the facts.
- Complete the impact assessment. Document necessity, data scope, overseas-recipient controls, individual rights and security measures.
- Implement contract and technical controls. Limit access, encrypt data, set retention periods, create incident procedures and monitor onward transfers.
- Reassess material changes. New recipients, purposes, data categories, volumes or storage periods can require a new analysis or filing.
Options and Compliance Route Comparison
| Route | Typical Circumstances for a Non-CIIO | Core Action |
|---|---|---|
| Procedural exemption | Qualifying exempt scenario, including fewer than 100,000 individuals’ non-sensitive personal information in the current year | Document the exemption and continue underlying PIPL controls |
| Standard contract or certification | 100,000 to fewer than 1 million individuals’ non-sensitive personal information, or fewer than 10,000 individuals’ sensitive personal information, where no exemption applies | Complete the selected mechanism and related impact assessment |
| Security assessment | Important data, at least 1 million individuals’ non-sensitive personal information, or at least 10,000 individuals’ sensitive personal information | Apply through the provincial cyberspace authority to the CAC |
| FTZ negative-list treatment | Processor is within an eligible pilot FTZ and exported data falls outside the applicable filed negative list | Confirm territorial, entity and data-scope eligibility under the local rules |
Costs and Timeline
Compliance cost depends more on data complexity than company size. A business with one overseas HR platform may need a focused inventory, impact assessment and contract review. A manufacturer with global engineering, vehicle, supplier and telemetry systems may need several workstreams and sector-specific classification analysis. Internal cost normally includes legal, privacy, security, HR and IT time as well as system changes and translation.
A fixed approval timetable should not be promised before the route and submission quality are known. The company can shorten the project by validating the inventory, recipient details, contracts and security controls before filing. If the business can lawfully minimize or localize data, that design decision may be faster and more durable than relying on repeated submissions.
Risks and Challenges
- Assuming that encrypted or pseudonymized personal information is no longer personal information.
- Counting each system separately and missing the data processor’s cumulative annual total.
- Relying on consent when another lawful basis and employee governance process should be used.
- Ignoring remote access by overseas group companies or vendors.
- Treating a procedural exemption as an exemption from PIPL security, transparency and rights obligations.
- Using an FTZ negative list without confirming that the exporting entity and data processing activity fall within its scope.
Common Mistakes Foreign Companies Make
The most damaging mistake is choosing a compliance route before building the data inventory. Companies also repeat obsolete thresholds from the 2022 assessment measures without applying the 2024 provisions, classify every operational data set as important data out of caution, or assume that ordinary overseas access does not count as export. Another frequent error is filing a standard contract while the actual volume or important-data status requires a security assessment.
Best Practices and Recommendations
Maintain a cross-border data register owned jointly by legal, privacy and IT teams. Connect the register to procurement and system-change approvals so that a new overseas vendor cannot be activated without review. Use a decision memo for each transfer route, record the threshold calculation and set an annual monitoring trigger before the next threshold is reached. Contract controls should address onward transfer, incident reporting, deletion, audit rights and assistance with individual requests.
FAQ
Does transferring fewer than 100,000 individuals’ data mean no compliance work is required?
No. The procedural exemption can remove the need for a security assessment, standard contract or certification in a qualifying case, but lawful processing, notice, minimization, security and impact-assessment duties may still apply.
Does all important data require a security assessment?
An export of important data falls within the security-assessment route. The 2024 provisions also state that data should not be treated as important data unless the relevant department or region has notified the processor or publicly issued the relevant designation or catalogue.
Can an FTZ company export everything not listed?
Only within the scope of the applicable negative-list rules. The entity, processing location, data category and local implementation requirements must all be confirmed.
Do employee transfers have a special exemption?
Cross-border HR transfers that are necessary for human-resources management under lawfully adopted employment rules and a lawfully concluded collective contract can fall within an exemption under the 2024 provisions. Necessity, notice, security and other PIPL requirements still need analysis.
When should the assessment be repeated?
Reassess when the purpose, recipient, data category, volume, access method or retention period changes, and when a filing or assessment approval reaches its validity limit.
Conclusion
The reliable way to manage China data exports is to make the decision from facts, not from a generic checklist. Map the transfer, classify the data, calculate volume, test exemptions and then select the correct route. Companies that integrate this process into system and vendor governance can support global operations without treating every transfer as a separate emergency.
Official Sources
- CAC: Provisions on Promoting and Regulating Cross-Border Data Flows
- CAC: first-year implementation results for the 2024 provisions
- CAC: Measures for Data Export Security Assessment
- CAC: current data-export security-assessment guidance
- CAC: official FTZ data-export negative-list directory
- Personal Information Protection Law of the People’s Republic of China
