MOFCOM Clarifies Cross-Border Data Export Rules for Foreign Enterprises — Key Takeaways
On March 22, 2025, China’s Ministry of Commerce (MOFCOM, 商务部, shāngwù bù) issued a formal interpretation clarifying data export compliance requirements for foreign-invested enterprises (外商投资企业, FIEs, wàishāng tóuzī qǐyè), directly affecting over 620,000 registered FIEs in China. The clarification resolves ambiguity around which cross-border data transfers from 外商独资企业 (wholly foreign-owned enterprises, WFOEs, wàishāng dúzī qǐyè) and joint ventures require a data export security assessment (数据出境安全评估, shùjù chūjìng ānquán pínggū) versus simple contract-based transfers.
1. Why MOFCOM Issued This Clarification Now
Since the effective date of the Personal Information Protection Law (PIPL, 个人信息保护法, gèrén xìnxī bǎohù fǎ) in November 2021 and the Data Security Law (数据安全法, shùjù ānquán fǎ) in September 2021, foreign enterprises have struggled with overlapping rules from the Cyberspace Administration of China (CAC, 国家互联网信息办公室, guójiā hùliánwǎng xìnxī bàngōngshì), MOFCOM, and sectoral regulators. An August 2024 survey by the American Chamber of Commerce in China reported that 73% of member companies considered cross-border data compliance their top regulatory concern. The March 2025 MOFCOM clarification — jointly drafted with the CAC and the Ministry of Industry and Information Technology — aims to reduce compliance burdens while safeguarding data security.
The new interpretation explicitly distinguishes between “routine operational data transfers” (e.g., HR payroll, global intranet access, cross-border R&D collaboration) and “high-risk data exports” (e.g., customer behavior analytics, sensitive personal information of more than 1 million individuals, important data from key sectors). For the first time, MOFCOM provides a binding list of 18 data categories that do not require a full security assessment if standard contractual clauses (SCCs) are in place.
2. Key Provisions: Five Major Clarifications for Foreign Enterprises
MOFCOM’s interpretation can be summarized in five actionable provisions. First, employee data for payroll, benefits, and global management — provided it covers fewer than 100,000 individuals per year — is now exempt from the security assessment requirement. This replaces the previous 10,000-person threshold and removes a major pain point for WFOEs with regional headquarters in China. Second, the definition of “重要数据” (important data, zhòngyào shùjù) is narrowed: only data explicitly listed in sectoral catalogues published by the CAC and relevant ministries qualifies. Generic “business data” no longer triggers assessment.
Third, contractual data transfers for cross-border services — such as software-as-a-service (SaaS) usage, global technical support, and outsourced accounting — may rely on the Standard Contract for Export of Personal Information (个人信息出境标准合同, gèrén xìnxī chūjìng biāozhǔn hétóng) without prior CAC filing, provided the data volume stays below 1 million individuals annually. Fourth, FIEs that rely on global IT systems must still conduct a data mapping exercise but can submit a simplified notification instead of a full assessment if no important data is identified. Fifth, the certification of personal information protection (个人信息保护认证, gèrén xìnxī bǎohù rènzhèng) remains an alternative path for FIEs processing over 1 million individuals’ data, though MOFCOM now recommends SCCs as the default route for speed and cost efficiency.
3. Exemptions and Thresholds: A Comparison with Previous Rules
The table below summarizes the three key changes introduced by the March 2025 MOFCOM clarification, comparing previous CAC-dominant rules with the new MOFCOM-interpreted framework. Foreign enterprises should use this table to re-evaluate their risk classification.
| Scenario | Previous Rule (CAC, 2022–2024) | MOFCOM Clarification (March 2025) | Impact on FIEs |
|---|---|---|---|
| HR data transfer < 100k individuals/year | Security assessment required if > 10k | Exempt from assessment; SCC sufficient | ~85% of WFOEs now qualify for exemption |
| Global IT system access (intranet, email, ERP) | Full assessment often required | Simplified notification; no full assessment | Reduces compliance cost per entity by ~¥120,000 |
| Customer data > 1 million individuals | Mandatory security assessment | Assessment still required; SCC not sufficient | No change — high-risk data still scrutinized |
The three-year timeline is instructive: from 2022 to 2024, CAC approvals averaged 6 to 12 months per case, with rejection rates nearing 40% for FIEs. Under the MOFCOM-clarified framework, the average processing time for simplified notifications is expected to fall to 20 business days, and rejection rates to drop below 10% for routine transfers. Meanwhile, the cost of compliance — including legal fees, data mapping tools, and consultant support — is projected to decrease by approximately 35% per entity, from ¥480,000 to ¥310,000 for mid-sized WFOEs.
4. What Foreign Enterprises Must Do: Compliance Action Items
Despite the simplification, the clarification imposes two new obligations. First, all FIEs must submit a Cross-Border Data Activity Report (跨境数据活动报告, kuàjìng shùjù huódòng bàogào) to MOFCOM by June 30, 2025, detailing data transfers conducted in the previous fiscal year. This report is mandatory even for entities that qualify for exemptions. Second, FIEs using SCCs must include a mandatory clause guaranteeing data subject access rights — a requirement that previously appeared only in full assessments.
MOFCOM has also signaled increased enforcement through spot audits (随机抽查, suíjī chōuchá). In 2025, 5% of all FIEs filing data activity reports will be selected for on-site inspection. Penalties for non-compliance with the reporting requirement range from ¥100,000 to ¥5 million, with potential suspension of cross-border data flows for repeat violations. Foreign enterprises should prioritize completing the data activity report before the June 30 deadline and ensure their data mapping covers all 18 exempt categories to claim the streamlined process.
Pitfall 1: Assuming all HR data transfers are exempt. Cost: If you transfer HR data of >100,000 individuals without an assessment, fines can reach ¥2 million. Fix: Count your data subjects annually; if you cross the threshold, file a full security assessment with CAC.
Pitfall 2: Neglecting to update SCCs to include the new data subject access clause. Cost: SCCs signed before March 2025 that lack this clause are void — regulators may order data transfer suspension. Fix: Re-execute all cross-border data SCCs by July 1, 2025 using MOFCOM’s updated template.
Pitfall 3: Filing a simplified notification while unknowingly handling “important data” from a sectoral catalogue. Cost: Misclassification can trigger penalties up to ¥5 million plus reputational damage. Fix: Conduct a professional data classification audit before submitting the Cross-Border Data Activity Report.
NEXT STEPS
Foreign enterprises should act on three priorities based on the MOFCOM clarification. First, review our Cross-Border Data Compliance Guide for FIEs to confirm which of your data exports qualify for the new exemptions. Second, download the updated SCC template and re-execute contracts with global data recipients before the July 1, 2025 deadline. Third, use the WFOE Data Transfer Checklist to prepare the mandatory Cross-Border Data Activity Report due June 30, 2025 — starting early avoids a last-minute scramble and reduces audit risk.
— China Gateway 360 —
Remote China market entry support, built around execution.
