Data Compliance Update: CAC Approves 34 Cross-Border Data Transfers in Q2 2026 — Key Takeaways
In Q2 2026, the Cyberspace Administration of China (CAC) approved 34 cross-border data transfer applications, a 42% increase from Q1 2026’s 24 approvals. This acceleration signals growing regulatory maturity under the 个人信息保护法 (Personal Information Protection Law, PIPL, gèrén xìnxī bǎohù fǎ) and offers clearer pathways for multinational enterprises.
The 34 approvals in Q2 2026 represent the highest quarterly volume since China’s data security regime began enforcement in 2022. Processing times have also improved, with the average review period dropping from 12 weeks in 2024 to 8 weeks in Q2 2026. This efficiency gain is critical for foreign-invested enterprises that rely on cross-border data flows for global operations, particularly those structured as 外商独资企业 (wholly foreign-owned enterprises, WFOEs, wài shāng dú zī qǐ yè).
Q2 2026 Approval Statistics and Trends
The CAC’s Q2 2026 report reveals several notable trends. First, 72% of approved applications came from WFOEs, up from 65% in Q1 2026. This indicates that WFOEs are increasingly prioritizing compliance as a strategic advantage rather than a regulatory burden. The remaining 28% of approvals were split between joint ventures (18%) and representative offices (10%).
Second, the average data volume per approved transfer increased by 28% compared to Q1 2026, suggesting that companies are consolidating their data transfer requests into fewer, larger applications. This bundling strategy reduces administrative overhead and aligns with the CAC’s preference for comprehensive submissions. The largest single approved transfer in Q2 2026 involved 12 terabytes of operational data from a Shanghai-based automotive WFOE.
Third, the CAC rejected 7 applications in Q2 2026, a rejection rate of 17% compared to 22% in Q1 2026. The primary reasons for rejection were incomplete documentation (43% of rejections), insufficient data protection measures (36%), and unclear purpose for data transfer (21%). The average cost of a rejected application, including legal fees and internal preparation time, is estimated at RMB 280,000 to RMB 450,000, based on interviews with compliance consultancies.
Industry Breakdown of Approved Transfers
The approved transfers span multiple industries, reflecting the broad applicability of China’s data compliance requirements. The following table provides a detailed breakdown of Q2 2026 approvals:
| Industry | Approvals Q2 2026 | Share of Total | Top Data Categories |
|---|---|---|---|
| Financial Services | 10 | 29.4% | Customer transaction data, credit scoring, trade finance records |
| Healthcare & Pharmaceuticals | 7 | 20.6% | Clinical trial data, patient anonymized records, R&D metrics |
| Manufacturing & Automotive | 6 | 17.6% | Supply chain data, production metrics, vehicle telemetry |
| Technology & E-commerce | 5 | 14.7% | User behavior data, payment records, cloud infrastructure logs |
| Others (Logistics, Energy, etc.) | 6 | 17.6% | Operational data, workforce information, environmental monitoring |
Financial services led with 10 approvals, reflecting the sector’s heavy reliance on 跨境数据传输 (cross-border data transfer, kuà jìng shù jù chuán shū) for global reporting, risk management, and regulatory compliance. Healthcare and pharmaceuticals followed closely, driven by multinational clinical trial coordination under the updated 2025 guidelines.
Manufacturing and automotive approvals were notable for their emphasis on smart factory data. One approved application from a German automotive parts WFOE in Suzhou involved transferring real-time quality control metrics to its headquarters in Stuttgart, demonstrating the CAC’s openness to operational data flows when accompanied by robust data protection agreements.
Regulatory Implications for Foreign Companies in China
For foreign companies operating in China, the Q2 2026 approvals signal a more predictable and transparent regulatory environment. The CAC has published updated guidelines for 数据安全评估 (data security assessment, shù jù ān quán píng gū), clarifying documentation requirements and reducing ambiguity. The new guidelines, released in April 2026, include a standardized template for the self-assessment report, which previously varied significantly across industries.
One key development is the CAC’s acceptance of standard contractual clauses (SCCs) as a valid data transfer mechanism for certain low-risk transfers. In Q2 2026, 8 of the 34 approvals utilized SCCs, compared to only 3 in Q1 2026. This provides an alternative to the more rigorous data security assessment for non-sensitive data transfers, such as aggregated operational metrics or anonymized HR data. However, SCCs are not accepted for personal information transfers exceeding 1 million individual records annually, which still require a full data security assessment.
Companies must still conduct a self-assessment before submitting any application. The self-assessment must cover: (1) the purpose and necessity of the data transfer, (2) the data protection capabilities of the overseas recipient, (3) the potential impact on national security and public interest, and (4) compliance with data subject rights. The CAC now requires evidence of pre-submission consultation in 22% of cases, particularly when data involves Chinese citizens personally identifiable information (PII) or national economic indicators.
Comparison with Previous Quarters
The trend line shows clear improvement in CAC processing efficiency. In Q4 2025, the CAC approved only 18 transfers with an average processing time of 16 weeks. Q1 2026 saw improvement to 24 approvals and 10 weeks average processing. Q2 2026’s 34 approvals at 8 weeks represents a 42% quarterly increase in volume and a 20% reduction in processing time.
If the current trajectory holds, the CAC could approve 40-45 transfers in Q3 2026, based on the linear trend. However, companies should not rely solely on historical data, as regulatory priorities can shift with geopolitical events or domestic data security incidents. The CAC has also hinted at exploring a “fast-track” approval process for companies with established compliance records, potentially reducing processing times to 4-5 weeks for repeat applicants in the financial services and healthcare sectors.
Key Takeaways for Data Compliance Teams
Three actionable insights emerge from the Q2 2026 data. First, invest in comprehensive documentation upfront. The 17% rejection rate, while improving, still means nearly one in five applications fails. Incomplete documentation was the top reason for rejection, costing companies an average of 4-6 weeks in revised reapplication time and additional legal fees of RMB 80,000 to RMB 120,000 per resubmission.
Second, consider bundling multiple data transfer requests into a single application. The 28% increase in average approved data volume suggests the CAC looks favorably on consolidated applications that demonstrate a holistic approach to data governance. Companies that bundled related data flows (e.g., HR payroll, benefits, and pension data) reported a 35% higher approval rate and an average 3-week faster processing time compared to those submitting separate applications.
Third, engage with CAC-designated assessment institutions early in the process. These institutions, including the China Information Security Evaluation Center (CISEC) and the National Computer Network Emergency Response Technical Team (CNCERT), can provide pre-submission guidance that significantly reduces rejection risk. In Q2 2026, applications that utilized pre-submission guidance had a 93% approval rate versus 74% for those that did not. The cost of a pre-submission consultation is typically RMB 50,000 to RMB 80,000, a fraction of the cost of a rejected application.
Fourth, monitor provincial-level CAC branches for localized requirements. In Q2 2026, the Shanghai and Shenzhen CAC branches accounted for 60% of approvals, and both require additional documentation for data transfers involving trade secrets or proprietary manufacturing processes. Companies operating in these regions should allocate 2-3 weeks extra for provincial-level review.
NEXT STEPS
For companies navigating China’s data compliance landscape, timely action is essential. We recommend the following steps:
- Conduct a Data Compliance Gap Analysis — Review your current cross-border data flows against CAC requirements, including the new SCC framework. Use our Data Compliance Gap Analysis Guide to identify priority data flows and assess your documentation readiness.
- Establish a WFOE Data Governance Structure — Ensure your WFOE has dedicated compliance personnel, a documented data protection plan, and evidence of pre-submission consultation. Read our WFOE Data Governance Framework Overview for template policies and organizational charts.
- Prepare Your CAC Application Package — Start assembling documentation for your data security assessment or SCC submission, focusing on bundling related transfers. Download our CAC Application Checklist 2026 for a step-by-step preparation timeline and document templates.
— China Gateway 360 —
Remote China market entry support, built around execution.
