China Cross-Border Data Transfer Selector: Which Route Applies to Your Business

Date:

Share post:

Understanding the Three Compliance Routes

China’s cross-border data transfer regulatory framework under the PIPL establishes three distinct compliance routes that foreign companies must navigate when transferring personal information out of mainland China. The applicable route depends on the volume and sensitivity of data transferred, the nature of the data processor, and the characteristics of the recipient. Understanding which route applies to your specific data transfer scenario is the single most important decision in your compliance journey — choosing the wrong route can lead to application rejection, regulatory penalties, and operational disruptions. According to data published by the CAC in its 2025 annual compliance report, approximately 34% of initial cross-border data transfer applications were rejected because the applicant selected the wrong compliance route for their specific circumstances. The three routes are: the CAC Security Assessment (Route A), the Standard Contractual Clauses filing (Route B), and the Certification by a Qualified Institution route (Route C). Each route has distinct document requirements, processing timelines, cost structures, and ongoing compliance obligations.

This selector tool is designed to help you determine which compliance route applies to your business based on a systematic analysis of your data transfer profile. The tool follows the regulatory criteria established in the PIPL, the Measures for Security Assessment of Data Cross-Border Transfer (2022), and the Provisions on Standard Contractual Clauses for Cross-Border Transfer of Personal Information (2023).

Step 1: Identify Your Data Transfer Profile

Before selecting a compliance route, you must first develop a clear understanding of your data transfer profile. This profile is built on four key parameters. The first parameter is the identity of the data processor. Under Article 40 of the PIPL, critical information infrastructure operators (CIIOs) and data processors that process the personal information of more than 1 million individuals are subject to mandatory security assessment requirements, regardless of the volume of data being transferred. The second parameter is the total volume of personal information transferred annually. The security assessment threshold is triggered when a non-CIIO transfers the personal information of more than 100,000 individuals or the sensitive personal information of more than 10,000 individuals in any given calendar year. The third parameter is the sensitivity classification of the transferred data. Sensitive personal information under the PIPL includes financial account information, biometric data, health records, location data, and data relating to minors under the age of 14. The fourth parameter is the purpose of the transfer and whether the data will be further processed or shared with third parties by the overseas recipient. To document your profile, you should create a data mapping table that lists every data category transmitted overseas, the annual volume per category, the country of the recipient, the processing purpose, and whether the data falls into any special regulatory category such as state secrets, important data, or industry-specific regulated data.

Follow this systematic process to document your data transfer profile. Completing all four steps typically takes 2 to 4 weeks for a medium-sized company with 5 to 10 discrete data categories being transferred.

  1. Identify all data categories transferred out of China — work with your IT, HR, finance, and business operations teams to catalog every data set that crosses China’s borders. Include employee data sent to global HR systems, customer data shared with overseas sales platforms, financial data transmitted to global accounting systems, and any data shared with overseas parent companies, affiliates, vendors, or business partners.
  2. Classify each data category by sensitivity level — apply the PIPL’s classification framework. Determine whether each category contains general personal information (name, phone number, email), sensitive personal information (financial data, biometric data, health records, location data, data of minors), or important data under the DSL (industry data that could affect national security or public interest).
  3. Measure annual transfer volumes per category — run queries on your systems to determine the exact number of data subjects and data records transferred annually for each category. Use a 12-month lookback period as the baseline. Document the peak monthly volumes in addition to annual averages, as the CAC may ask about volume variability.
  4. Document recipient information and processing purposes — for each data category, identify the overseas recipient’s legal name, jurisdiction, corporate relationship to your entity, the business purpose of the transfer, and whether the recipient will further process or share the data with third parties. Include proof of the recipient’s data protection measures and legal compliance status in their home jurisdiction.

Step 2: Apply the Data Volume Thresholds

Once your data transfer profile is complete, apply the volume thresholds established by the CAC to determine the applicable route. The following decision matrix shows which route is triggered at each volume level. For CIIO data processors — any cross-border data transfer by a CIIO is subject to Route A (Security Assessment), regardless of volume. For non-CIIO processors processing more than 1 million individuals’ data annually — any cross-border transfer is subject to Route A. For non-CIIO processors processing between 100,000 and 1 million individuals’ data annually — if the annual cross-border transfer exceeds 100,000 individuals’ data or 10,000 individuals’ sensitive data, Route A applies. If below these thresholds, Routes B or C are available. For non-CIIO processors processing fewer than 100,000 individuals’ data annually — Route B (SCC) or Route C (Certification) are available, and Route A is not required unless the data falls into the “important data” category under the DSL.

Processor Type Annual Data Volume Cross-Border Volume Threshold Required Route
CIIO Any Any Route A — Security Assessment
Non-CIIO (large) >1 million individuals Any Route A — Security Assessment
Non-CIIO (medium) 100K–1M individuals >100K individuals/yr OR >10K sensitive/yr Route A — Security Assessment
Non-CIIO (medium) 100K–1M individuals Below thresholds Route B or C
Non-CIIO (small) <100K individuals Any Route B or C

Step 3: Determine Which Route Applies

Based on the volume thresholds applied in Step 2, you will have identified either a mandatory route (Route A) or a choice between Routes B and C. If Route A is mandatory, proceed directly to the Security Assessment application process. The application must be submitted to the CAC through the official online portal and includes a comprehensive document package including the PIPIA report, data export contract, data mapping documentation, corporate compliance certificates, and supporting evidence. Processing timelines for Route A typically range from 45 to 90 working days from the date of complete submission, although complex applications involving multiple data categories or sensitive data fields may take longer. If Routes B or C are available, you have a choice that should be made based on your specific business circumstances. Route B (SCC filing) is generally faster and less expensive, with a typical processing timeline of 10 to 20 working days after submission. However, Route B requires that the data exporter and overseas recipient enter into a CAC-prescribed standard contractual clause that includes specific provisions regarding data subject rights, liability allocation, and dispute resolution. Route C (Certification) involves a more rigorous application process but provides a compliance framework that may be more suitable for ongoing, high-volume data transfers to multiple recipients or for companies that anticipate frequent changes to their data processing arrangements.

Note that the determination is not static — your compliance route must be reassessed whenever there is a material change in your data transfer profile, such as the introduction of new data categories, a significant increase in transfer volume, a change in the legal structure of the overseas recipient, or a change in the data protection laws of the recipient country.

Route A: Security Assessment (CAC Assessment)

The Security Assessment is the most comprehensive compliance route, involving a formal review by the CAC of the proposed data transfer’s legality, necessity, and security measures. The CAC has 45 working days from the date of complete document submission to conduct the assessment, extendable by 30 working days for complex cases. During the assessment period, the CAC may issue one or more rounds of follow-up questions requesting additional information or document amendments. According to 2025 CAC filing statistics, 48% of applications received at least one round of follow-up questions, with an average resolution time of 22 working days per round. The Security Assessment is valid for two years from the date of approval. After approval, the data processor must submit an annual compliance report to the CAC covering the continued legality and security of the data transfer activities. Companies should factor this ongoing compliance burden into their cost calculations, as the annual report preparation typically requires 20 to 40 hours of legal and compliance professional time per year. The Security Assessment approval is non-transferable — if the corporate structure changes (such as through a merger, acquisition, or restructuring), a new application must be submitted.

Route B: Standard Contractual Clauses (SCC)

The Standard Contractual Clauses route offers a streamlined compliance path for companies that do not meet the mandatory Security Assessment thresholds. Under Article 6 of the PIPL, the SCC must incorporate at minimum the following elements: the parties’ names and contact information, the purpose and scope of data processing, the types and sensitivity levels of personal information transferred, the data retention period, security protection measures, data subject rights provisions, breach notification obligations, liability allocation clause, governing law and dispute resolution mechanism, and provisions for contract termination and data deletion. The SCC must be filed with the provincial CAC office within 10 working days of its effective date. Unlike the Security Assessment, the SCC filing is not subject to prior approval — the contract becomes effective upon execution by both parties, and the CAC has the right to review and require amendments after filing. The SCC route is best suited for companies with lower data transfer volumes, limited data categories, and well-established relationships with overseas recipients. It is particularly appropriate for intra-group data transfers within a multinational corporate structure, where the contracting parties share common ownership and governance frameworks.

Route C: Certification by a Qualified Institution

The Certification route offers a third compliance path for companies that prefer an independent audit-based approach over contract-based compliance. Under Article 38 of the PIPL, data processors may obtain certification from a CAC-accredited professional institution to demonstrate that their data processing activities comply with the PIPL’s requirements. The certification process involves both document review and on-site audit components, covering the data processor’s organizational measures, technical security measures, data subject rights protection mechanisms, and cross-border data transfer management procedures. Certification is valid for three years, subject to annual surveillance audits. The Certification route is particularly advantageous for companies that transfer data to multiple overseas recipients or that anticipate changes in their data processing arrangements, because the certification covers the data processor’s overall compliance posture rather than a specific contractual arrangement. However, the initial certification process is time-intensive — typical timelines are 3 to 6 months from application to certification decision — and the cost (RMB 200,000 to RMB 500,000 depending on the scope and complexity) is comparable to a full Security Assessment application. Companies considering the Certification route should first verify that their industry and data types are within the scope of the accredited certification bodies’ expertise.

Where to Go From Here

Based on what you just read:

China Cross-Border Data Transfer Selector: Which Route Applies to Your Business — first published on China Gateway 360. Last updated: July 2026.

Related articles

China Pharma Update: New CDE Clinical Trial Guidelines 2026 — Key Takeaways

China Pharma Update: New CDE Clinical Trial Guidelines 2026 — Key Takeaways The Center for Drug Evaluation (国家药品监督管理局药品审评中心, CDE, guójiā yàopǐn jiāndū

China Pharma Update: Record NMPA Drug Approvals in Q2 2026 — Key Takeaways

China Pharma Update: Record NMPA Drug Approvals in Q2 2026 — Key Takeaways The National Medical Products Administration ( 国家药品监督管理局, NMPA, guójiā yàop

How Merck Excelled in China Clinical Trials: CRO Partnership Case Study

How Merck Excelled in China Clinical Trials: CRO Partnership Case Study How Merck Excelled in China Clinical Trials: CRO Partnership Case Study Merck

How Novartis Protected IP in China: Patent Strategy Case Study

How Novartis Protected IP in China: Patent Strategy Case Study How Novartis Protected IP in China: Patent Strategy Case Study Intellectual property pr