How do foreign companies identify the right data transfer mechanism in China?

Date:

Share post:






How do foreign companies identify the right data transfer mechanism in China?


How do foreign companies identify the right data transfer mechanism in China?

Foreign companies operating in China face a complex regulatory landscape when transferring personal information across borders. China’s legal framework provides several pathways for lawful cross-border data transfers, and selecting the right mechanism is a critical compliance decision. The choice depends on a structured assessment of data volumes, data categories, industry sector, corporate structure, and the specific characteristics of the data processing activity. This FAQ provides a step-by-step decision framework for identifying the applicable transfer mechanism for your organization.

1. Overview of available data transfer mechanisms

China’s cross-border data transfer regime, established under the Personal Information Protection Law (PIPL), the Data Security Law (DSL), and the Cybersecurity Law (CSL), offers three primary transfer mechanisms and one supplementary pathway:

Mechanism Regulatory Instrument Status Typical Timeline
CAC Security Assessment Measures on Data Export Security Assessment (eff. Sept 2022) Active 4-10 months
Standard Contractual Clauses (SCCs) Measures on Standard Contracts for Cross-border Data Transfer (eff. June 2023) Active 2-6 months
Certification Personal Information Protection Certification (by CAC-accredited bodies) Emerging — limited use Ongoing
Data localisation exceptions CAC case-by-case approval Rarely used Variable

2. Step 1: Determine whether you are transferring “personal information” or “important data”

The first step is to classify the data being transferred. Chinese law distinguishes between:

Personal information

Any information relating to an identified or identifiable individual, recorded electronically or by other means. This includes names, ID numbers, phone numbers, email addresses, IP addresses, device identifiers, location data, and any data that can be combined with other information to identify an individual.

Sensitive personal information

A subset of personal information that, once leaked or illegally used, may easily infringe on the dignity of natural persons or harm personal or property safety. This includes biometric data, religious beliefs, specific identities, medical health data, financial accounts, location tracking, and personal information of minors under 14.

Important data

Defined by the Data Security Law as data that, if tampered with, destroyed, leaked, illegally obtained, or illegally used, may endanger national security, economic operations, social stability, or public health and safety. The specific catalogues of important data are defined by industry regulators — for example, the Automotive Data Security Management Provisions (for the automotive sector) and industry-specific important data catalogues in finance, healthcare, energy, and telecommunications.

If the transfer involves important data, the CAC Security Assessment pathway is mandatory regardless of volume. There is no alternative mechanism for important data transfers.

3. Step 2: Evaluate whether your company is a CIIO

Critical Information Infrastructure Operators (CIIOs) face stricter cross-border data transfer obligations. An entity may be designated as a CIIO if it operates in any of the following sectors and the failure of its information systems could severely harm national security, the economy, or public interests:

  • Public communications and information services
  • Energy (electricity, oil, gas)
  • Transportation (aviation, railways, shipping)
  • Water resources
  • Finance (banking, securities, insurance)
  • Public services (healthcare, education)
  • E-commerce and cloud computing

Designation as a CIIO is not voluntary — the relevant government authority determines CIIO status based on the entity’s importance to critical infrastructure. Companies that suspect they may be designated as CIIOs should consult with regulatory authorities proactively.

If your company is a CIIO and transfers personal information overseas, the CAC Security Assessment is mandatory regardless of data volume.

4. Step 3: Assess data transfer volumes and thresholds

For non-CIIO companies that are not transferring important data, the transfer mechanism is determined by data volume thresholds:

Scenario Data Transfer Volume Required Mechanism
High volume Personal information of 1M+ individuals annually CAC Security Assessment
High volume (sensitive) Sensitive personal information of 10K+ individuals in preceding year CAC Security Assessment
Moderate volume Personal information of fewer than 1M individuals AND sensitive data of fewer than 10K individuals SCC filing (or Certification)
Low volume / de minimis Below regulatory filing thresholds (expected to be clarified) May only need PIPIA documentation without formal filing

Important timing consideration: The “preceding year” for the 10K sensitive data threshold refers to the 12 months preceding the filing date. Companies should track cumulative transfers carefully, particularly if they experience seasonal spikes in data processing.

Aggregation across group entities: There is ongoing debate about whether data volumes should be aggregated across all China-based entities of the same multinational group. Prudent companies should assume aggregation applies — if a parent company, two WFOEs, and a representative office collectively transfer data of more than 1 million individuals, the Security Assessment threshold may be triggered even if no single entity exceeds the threshold individually.

5. Step 4: Decision framework — matching mechanism to your scenario

Using the outputs of Steps 1-3, apply the following decision tree:

  1. Does the transfer include important data?
    • Yes → CAC Security Assessment (mandatory)
    • No → Proceed to Step 2
  2. Is your company a CIIO?
    • Yes → CAC Security Assessment (mandatory)
    • No → Proceed to Step 3
  3. Does the transfer involve 1M+ individuals’ data annually?
    • Yes → CAC Security Assessment
    • No → Proceed to Step 4
  4. Does the transfer involve sensitive data of 10K+ individuals in the preceding year?
    • Yes → CAC Security Assessment
    • No → Proceed to Step 5
  5. Do you have a recognized personal information protection certification?
    • Yes → Certification pathway + SCC
    • No → SCC filing (standard pathway)

6. Factors beyond thresholds: Practical considerations

While the legal thresholds above provide the primary decision framework, several additional factors may influence the choice of transfer mechanism:

6.1. Number of overseas recipients and jurisdictions

If the company transfers data to multiple overseas recipients across different jurisdictions, each recipient-jurisdiction combination may require a separate SCC or Security Assessment. Companies with complex global data flows may find the SCC pathway more manageable for low-volume transfers to multiple recipients, while the Security Assessment may be more efficient for high-volume transfers to a small number of well-established recipients.

6.2. Nature of the data processing purpose

Transfers for core business operations (payroll, customer service, supply chain management) may benefit from the SCC pathway’s flexibility, while transfers for higher-risk purposes (profiling, automated decision-making, AI training) may face additional scrutiny regardless of the chosen mechanism.

6.3. Track record and enforcement risk

Companies in sectors with active CAC enforcement (e.g., ride-hailing, social media, fintech) should consider proactively pursuing the Security Assessment even if volumes are below the mandatory threshold, as this demonstrates a higher level of compliance commitment.

6.4. Recipient data protection capabilities

The Security Assessment requires the overseas recipient to demonstrate specific data protection capabilities. If the recipient lacks these or is unwilling to submit to contractual audit rights, the Security Assessment pathway will be difficult. The SCC pathway provides more structured contractual assurances.

6.5. Group-level compliance strategy

Multinational companies often prefer a consistent compliance approach across jurisdictions. Companies that have already implemented Binding Corporate Rules (BCRs) under the GDPR or similar frameworks may consider whether China’s SCC pathway can be aligned with existing global privacy compliance programs.

7. Sector-specific variations

Certain industry sectors have additional cross-border data transfer requirements that may override or supplement the general framework:

Sector Additional Requirements Implication for Mechanism Selection
Automotive Automotive Data Security Management Provisions — specific rules for vehicle data, driving data, and location data Stricter thresholds may push more transfers to Security Assessment pathway
Finance PBOC and NFRA regulations on financial data localisation and cross-border transfers Usually requires Security Assessment; some financial data cannot be transferred at all
Healthcare Health data classified as important data in many cases; additional restrictions under Medical Records Management provisions Health data transfers often mandate Security Assessment
E-commerce E-commerce Law requirements for platform data; consumer protection rules High-volume transfers common; Security Assessment typically required
Cloud services CAC Multi-Level Protection Scheme (MLPS) requirements; data localisation for certain cloud services Complex — may need both Security Assessment and localisation

8. Making the final decision: A practical approach

Once the applicable mechanism is identified through the decision framework above, companies should take the following practical steps:

  1. Document the decision process: Create a written record of how the mechanism was selected, including the data volume calculations, data category classifications, CIIO status assessment, and sector-specific considerations. This documentation demonstrates good-faith compliance efforts to regulators.
  2. Engage regulatory counsel: China’s cross-border data regulations are still evolving, and regulatory interpretations can vary by region and industry. Engage counsel with direct CAC filing experience.
  3. Prepare for the selected mechanism: Begin assembling the required documentation — PIPIA, data mapping, SCC agreement (for the SCC pathway) or the Security Assessment application package (for the Security Assessment pathway).
  4. Monitor for regulatory changes: China’s data protection landscape continues to evolve. New regulations, revised thresholds, or updated guidance may change which mechanism applies to your company’s data transfers. Subscribe to CAC regulatory updates and review the mechanism selection at least annually.
  5. Consider a hybrid approach: For companies with multiple data flows, a combination of mechanisms may be appropriate — Security Assessment for high-volume customer data, SCCs for lower-volume employee data, and localisation for the most sensitive categories.

Conclusion

Identifying the right data transfer mechanism for cross-border personal information transfers from China requires a systematic, step-by-step assessment. Companies must begin by classifying the data being transferred (personal information, sensitive personal information, or important data), determine whether they are a CIIO, and calculate their data transfer volumes against the regulatory thresholds. The CAC Security Assessment is mandatory for important data transfers, CIIO transfers, and high-volume transfers exceeding 1 million individuals (or 10,000 individuals for sensitive data). For transfers below these thresholds, the SCC filing pathway provides a more accessible mechanism. Additional sector-specific regulations in automotive, finance, healthcare, and other industries may further influence the choice. By following the structured decision framework outlined in this FAQ and engaging experienced China data privacy counsel, foreign companies can select the appropriate transfer mechanism with confidence and build a compliant cross-border data transfer program.


Related articles

How to Obtain Chemical Import Permits in China: 2026 Guide for Foreign Companies

How to Obtain Chemical Import Permits in China: 2026 Guide for Foreign Companies Why Chemical Import Permits Matter for Foreign Companies Entering Chi

How to Register Chemicals Under China REACH: 2026 Guide for Foreign Manufacturers

How to Register Chemicals Under China REACH: 2026 Guide for Foreign Manufacturers Why China REACH Registration Matters for Foreign Chemical Manufactur

How to Choose Between OEM and ODM in China: 2026 Procurement Guide for Sourcing Teams

How to Choose Between OEM and ODM in China: 2026 Procurement Guide for Sourcing Teams Why the OEM vs ODM Decision Matters for Your China Sourcing Stra

How to Negotiate Contracts with Suppliers in China: 2026 Guide for Foreign Companies

How to Negotiate Contracts with Suppliers in China: 2026 Guide for Foreign Companies In 2026, foreign companies negotiating contracts with Chinese sup