Can my foreign company use SCCs instead of a security assessment in China?
Yes — in most cases, foreign companies can use Standard Contractual Clauses (SCCs) instead of a CAC security assessment, provided they do not meet the mandatory assessment thresholds. The 2024 Data Flow Regulations significantly expanded the availability of SCCs, raising the volume threshold from 100,000 individuals’ personal information per year to 1 million individuals per year. This change alone is estimated to have reduced the number of foreign companies requiring a security assessment by approximately 40%, making SCCs the default compliance mechanism for the majority of foreign-invested enterprises in China.
When are SCCs insufficient and a security assessment is mandatory?
There are four scenarios where SCCs cannot replace a CAC security assessment. Foreign companies must be absolutely certain none of these apply before relying on SCCs as their transfer mechanism:
| Scenario | Description | Why SCCs Cannot Replace Assessment |
|---|---|---|
| 1. CIIO operator | Company is formally designated as a Critical Information Infrastructure Operator | CSL Article 37 mandates security assessment for ALL cross-border PI transfers by CIIOs — no alternative mechanism is permitted |
| 2. Important data transfer | Data being transferred qualifies as “important data” under applicable sector catalogues | DSL Article 31 + CAC Measures require security assessment for any important data transfer regardless of volume |
| 3. Large-volume PI transfer | Cumulative PI transferred exceeds 1 million individuals per year | SCCs are only permitted for transfers up to 1 million PI/year (or 10,000 sensitive PI/year) |
| 4. Sensitive PI threshold exceeded | Cumulative sensitive PI transferred exceeds 10,000 individuals per year | Even if total PI volume is under 1 million, exceeding the sensitive PI threshold triggers mandatory assessment |
Foreign companies that fall into any of these four categories must undergo a CAC security assessment. Attempting to use SCCs in these circumstances would constitute a violation of the PIPL and DSL, carrying penalties of up to RMB 50 million or 5% of annual revenue. A common compliance gap occurs when companies correctly classify their general PI volume as under 1 million but fail to separately track their sensitive PI volume, inadvertently crossing the 10,000 threshold without the required assessment.
What is the current SCC framework in China?
China’s SCC framework was established by the Measures on Standard Contracts for Cross-Border Transfer of Personal Information, which came into effect on June 1, 2023, and was amended by the Data Flow Regulations in March 2024. The key features of the current SCC framework as of 2026 are:
- CAC-prescribed template — The SCC must use the standard template published by the CAC. While parties may negotiate additional provisions, they cannot modify or delete the mandatory clauses, which cover data subject rights, recipient obligations, liability allocation, applicable law (Chinese law), and dispute resolution mechanisms.
- Filing requirement — The executed SCC must be filed with the provincial CAC office within 10 working days of coming into effect. Late filing does not invalidate the contract retroactively but may result in a warning and correction order.
- PIPIA requirement — Before entering into the SCC, the data exporter must complete a Personal Information Protection Impact Assessment (PIPIA) that specifically addresses cross-border transfer of the personal information covered by the contract.
- 15-day CAC review period — The provincial CAC has 15 working days to review the filing. If no correction notice is issued, the filing is deemed complete. If corrections are required, the parties have 30 working days to amend the contract.
- Annual re-assessment — The SCC must be reviewed annually and re-filed if there are material changes to the transfer purpose, data type, retention period, or the recipient’s data protection measures.
The filing fee for SCCs varies by province. As of 2026, most provinces do not charge a direct filing fee, though companies should budget for legal and consulting costs. The total cost of implementing SCCs for a typical foreign company (including legal drafting, PIPIA completion, and filing) ranges from RMB 100,000 to RMB 300,000 (USD 14,000 to USD 42,000) — substantially less than the RMB 500,000 to RMB 1,500,000 cost of a CAC security assessment.
Can SCCs cover multiple overseas recipients or multiple purposes?
The CAC’s SCC template is designed for bilateral contracts between a single data exporter in China and a single overseas recipient. However, the framework permits two alternative structures for more complex corporate arrangements. First, a foreign company with multiple overseas affiliates receiving data can execute separate SCCs with each recipient — each contract must be individually filed with the CAC and accompanied by its own PIPIA. Second, the CAC has confirmed that a single SCC can cover multiple transfer purposes provided that all purposes are explicitly identified and documented in the contract schedule. As of 2026, approximately 35% of SCC filings by foreign companies cover two or more distinct transfer purposes within a single contract, reducing the filing burden compared to executing separate SCCs for each data flow. Multi-party arrangements where a single Chinese entity transfers data to multiple overseas group companies remain the most common structure, and these can be managed through a master SCC with individual schedule annexes for each recipient jurisdiction.
What information must the SCC include?
The CAC’s standard SCC template requires the following information to be specified:
- Parties’ identification: Full legal names, addresses, contact information, and representative details of both the data exporter (Chinese entity) and the data recipient (overseas entity)
- Purpose of transfer: Specific, documented business purpose for the cross-border data transfer — general statements such as “global business operations” are insufficient
- Types of PI transferred: Detailed categorization of the personal information being transferred, classified by PIPL sensitivity levels
- Retention period: Specified period for which the recipient will retain the PI, with commitment to delete or anonymize after expiry
- Protective measures: Detailed description of the technical and organizational measures the recipient will implement to protect the PI
- Data subject rights: Mechanisms for data subjects to exercise their rights under PIPL (access, correction, deletion, portability, withdrawal of consent)
- Liability and compensation: Allocation of liability between exporter and recipient for data breaches and violations, including the procedure for compensating affected data subjects
- Dispute resolution: Governing law (Chinese law), jurisdiction (Chinese courts), and dispute resolution mechanism (mediation, arbitration, or litigation)
How do SCCs compare with the certification option?
For foreign companies that can use either mechanism, the choice between SCCs and PIAB certification depends on several factors:
| Comparison Factor | SCCs | PIAB Certification |
|---|---|---|
| Best for | Defined, limited-scope transfers (e.g., HR data to payroll processor, customer data to CRM, vendor data to global procurement system) | Ongoing, multi-purpose transfers across corporate groups (e.g., global ERP system with HR, finance, ops data) |
| Coverage | Per-contract (each transfer relationship requires a separate SCC filing) | Enterprise-wide (single certification covers all qualifying transfers by the certified entity) |
| Timeline | 1-3 months (drafting + 15-day filing review) | 3-6 months (certification audit + certification decision) |
| Cost (initial) | RMB 100,000-300,000 | RMB 300,000-800,000 |
| Ongoing burden | Annual PIPIA update + re-filing on material changes | Annual surveillance audit + certification renewal every 3 years |
| Administrative complexity | Low to medium (per-filing, per-contract) | Medium to high (enterprise-wide governance framework required) |
For a typical foreign company with a Chinese subsidiary that transfers employee data to global HR systems and customer data to a global CRM, SCCs are the simpler and more cost-effective option. For a multinational group with 5+ subsidiaries in China and extensive, multi-directional data flows, PIAB certification may be more efficient over a 3-5 year horizon.
What happens if my SCC is rejected or requires correction?
When the provincial CAC reviews an SCC filing and finds deficiencies, it issues a correction notice within the 15-day review period. The most common deficiencies and their remedies include:
- Inadequate PIPIA — The PIPIA fails to address one or more required elements. Fix: Expand the PIPIA to comprehensively cover all seven mandatory assessment criteria, with specific attention to recipient jurisdiction analysis and residual risk assessment.
- Insufficient purpose specificity — The transfer purpose is described too broadly. Fix: Narrow the purpose statement to the specific business activity (e.g., “global payroll processing for Chinese employees via SAP SuccessFactors system” instead of “global HR management”).
- Missing recipient safeguards — The SCC does not adequately describe the recipient’s data protection measures. Fix: Include a specific appendix listing the technical and organizational measures (encryption standards, access controls, breach notification procedures, audit rights).
- Inadequate data subject rights provisions — The mechanism for data subjects to exercise rights is not clearly defined. Fix: Specify a concrete procedure, including a China-based contact point, response timelines, and escalation channels.
The parties have 30 working days from receipt of the correction notice to amend the SCC and re-submit. If the corrections are satisfactory, the filing is deemed complete. If the parties fail to correct within 30 working days or if the corrections are still inadequate, the CAC may order the data transfer to cease.
Where to Go From Here
Based on what you just read:
- Ready to act? Read a step-by-step guide to drafting and filing China SCCs for your cross-border data transfers
- Still comparing? See a side-by-side comparison of SCCs vs. CAC security assessment vs. PIAB certification
- Need numbers? Try an interactive SCC vs. security assessment cost calculator for your data profile
Can my foreign company use SCCs instead of a security assessment in China? — first published on China Gateway 360. Last updated: July 2026.
