Data Transfer Update: China and EU Begin Cross-Border Data Adequacy Negotiations — Key Takeaways

Date:

Share post:

Data Transfer Update: China and EU Begin Cross-Border Data Adequacy Negotiations — Key Takeaways

On 28 February 2025, China and the European Union formally launched negotiations on a cross-border data adequacy agreement, a process that could reshape how over 1,200 EU-invested enterprises in China transfer data across borders. The talks aim to create a mutual recognition framework that would allow companies to move personal data between China and the EU without the cumbersome individual approvals currently required under China’s 数据跨境传输 (cross-border data transfer, shùjù kuàjìng chuánshū) rules. If successful, this would be the first adequacy decision between the EU and an Asian economy outside of Japan and South Korea, setting a precedent for digital trade governance.

What Are Adequacy Negotiations? A Primer on the Mechanism

An adequacy decision is a legal finding by the European Commission that a non-EU country provides a level of personal data protection “essentially equivalent” to that of the EU’s General Data Protection Regulation (GDPR). Once granted, data can flow freely from the EU to that country without requiring additional safeguards such as Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs). For China, the negotiations target a reciprocal arrangement: the Cyberspace Administration of China (CAC) would recognize EU protections as sufficient under China’s 个人信息保护法 (Personal Information Protection Law, PIPL, gèrén xìnxī bǎohù fǎ) and 数据安全法 (Data Security Law, DSL, shùjù ānquán fǎ).

The EU has so far granted adequacy to 16 countries and territories, including Japan (2019), South Korea (2021), and the UK (2021). Negotiations with China began after two years of technical-level dialogues, signaling a potential breakthrough in cross-border data governance. The timeline is ambitious: preliminary agreement is targeted by Q1 2026, though both sides acknowledge that substantial legal alignment work remains.

Why Now? The Strategic Context Driving the Talks

Several factors converged to bring China and the EU to the negotiating table. First, bilateral trade in goods and services reached €940 billion in 2024, requiring seamless data flows for supply chain management, cross-border e-commerce, and financial services. Second, China’s 2023 and 2024 regulatory relaxations—including the abolition of the mandatory data security assessment for “ordinary” business data under the 数据出境安全评估办法 (Measures for Data Export Security Assessment, shùjù chūjìng ānquán pínggū bànfǎ)—created a more welcoming environment for international dialogue. Third, the EU’s Digital Decade policy and China’s Digital Silk Road initiative both prioritize interoperable data governance frameworks, making this a logical next step.

For foreign companies, the stakes are high. A 2024 survey by the European Chamber of Commerce in China found that 68% of member companies cited cross-border data transfer restrictions as a top operational challenge, up from 52% in 2022. The current system requires companies to either conduct a formal security assessment (for “important data” or personal data above certain thresholds) or enter into a standard contract with the CAC—both processes taking 3–6 months on average. An adequacy agreement could reduce that to zero for covered data flows, saving an estimated €50 million annually in compliance costs across EU firms in China.

Key Challenges on the Table: Divergence in Legal Standards

Despite the optimistic start, significant hurdles remain—four in particular. First, scope of application: China’s PIPL defines “personal information” more broadly than GDPR, including anonymized data that the EU excludes, creating potential gaps in coverage. Second, enforcement mechanisms: The EU requires an independent supervisory authority with investigation and sanction powers, while China’s CAC is a policy-making body with enforcement shared across multiple agencies—a structural mismatch that the EU will need to accept or negotiate changes around. Third, onward transfers: China’s data localization laws require data on Chinese citizens to stay within China’s jurisdiction, whereas EU adequacy decisions typically allow onward transfers to third countries with equivalent protections—a fundamental tension. Fourth, national security exceptions: Both sides have them, but China’s 2024 Data Security Law amendments widened the scope of “national security” data that can be exempted from adequacy commitments, raising concerns in Brussels about potential circumvention.

A technical working group, co-chaired by the European Commission’s DG Justice and China’s CAC, has been established to address these points. The group’s first meeting in March 2025 produced a joint roadmap covering 12 priority issues, including data breach notification timelines, consent requirements, and the treatment of sensitive data categories such as health and biometrics. Both sides have signaled willingness to compromise, but the gap on onward transfers remains the most intractable issue.

Comparison: Current Data Transfer Regime vs. Potential Adequacy Framework

Dimension Current Regime (Pre-Adequacy) Potential Adequacy Framework
Legal basis for transfer SCCs or CAC Security Assessment Adequacy decision from EU + reciprocal CAC recognition
Approval time 3–6 months per filing Zero—automatic for covered data
Cost per filing €15,000–€40,000 (legal + admin) €0 for adequacy-covered transfers
Scope of data covered Personal data & “important data” under DSL Personal data only (non-important)
Onward transfer flexibility Requires separate approval Permitted with equivalent safeguards
Review frequency No automatic review Every 4 years (EU standard)

The table highlights that the adequacy framework would dramatically reduce compliance burdens for routine personal data transfers, but would not cover “important data” under China’s Data Security Law—a category that remains broadly defined and subject to case-by-case interpretation. Foreign companies handling financial, telecommunications, or public health data may still need to use the traditional security assessment route for those specific datasets.

Implications for Foreign Companies: What to Watch

If concluded, the adequacy agreement would primarily benefit three groups of foreign companies. First, EU-invested enterprises in manufacturing and logistics, where cross-border data flows involve supply chain coordination, inventory data, and employee records—all typically personal data under PIPL. Second, financial services firms that need to transfer customer transaction data to EU headquarters for risk analysis and compliance reporting. Third, pharmaceutical and research companies conducting clinical trials across China and EU sites, where patient data currently requires complex multi-layer approvals.

However, companies should not expect a complete overhaul. The adequacy deal is likely to include a “safety valve” allowing both sides to suspend the arrangement for specific sectors or data categories if concerns arise. Moreover, companies that handle “important data” (defined in the 2024 Data Security Law implementation rules as data that “could endanger national security, economic stability, or public interests”) will still need to conduct formal security assessments—a separate process that may remain in place regardless of adequacy.

For US-invested enterprises in China, the direct benefit is limited, as the adequacy deal is EU-specific. However, if successful, the framework could serve as a model for future US-China data talks, potentially under the auspices of the APEC Cross-Border Privacy Rules system. EU firms should begin auditing their current data flows to identify which transfers would qualify for adequacy treatment and which would remain under the standard contract or assessment route.

NEXT STEPS

  1. Audit Your Data Flows Now: Map all cross-border personal data transfers between China and the EU to prepare for the new regime. Use our Data Transfer Audit Checklist to identify which flows would benefit from adequacy treatment.
  2. Monitor the Negotiation Timeline: The working group meets quarterly through 2025. Subscribe to our China Data Compliance Updates for real-time analysis of each milestone.
  3. Plan for Dual Compliance: While adequacy is promising, maintain your current SCC and security assessment procedures as a fallback. Review our PIPL Compliance Guide 2025 to ensure you remain compliant regardless of the outcome.

— China Gateway 360 —
Remote China market entry support, built around execution.

Related articles

What are the grounds to set aside a CIETAC award in China?

What are the grounds to set aside a CIETAC award in China? body { font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, sans-serif; line

What is the cost of arbitration at CIETAC for foreign businesses?

What Is the Cost of Arbitration at CIETAC for Foreign Businesses? body { font-family: 'Segoe UI', Arial, sans-serif; line-height: 1.8; color: #333; ma

Can foreign companies sue a Chinese company in Chinese courts?

Can Foreign Companies Sue a Chinese Company in Chinese Courts? body { font-family: 'Segoe UI', Arial, sans-serif; line-height: 1.8; color: #333; max-w

How long does CIETAC arbitration take in China?

How Long Does CIETAC Arbitration Take in China? body { font-family: 'Segoe UI', Arial, sans-serif; line-height: 1.8; color: #333; max-width: 900px; ma