SCCs vs Security Assessment: Which Cross-Border Data Route for Your China Business?

Date:

Share post:

The CAC Security Assessment is mandatory for high-volume data processors and CIIOs, while Standard Contractual Clauses (SCCs) are available for organizations processing personal information of fewer than 1 million individuals annually that do not qualify as CIIOs — but the two routes differ in cost, duration, legal certainty, and ongoing compliance burden by approximately 300% across all metrics. A CAC Security Assessment costs an average of RMB 400,000-1,200,000 in preparation costs, takes 6-9 months from initiation to approval, and is valid for 2 years. Standard Contractual Clauses cost an average of RMB 100,000-300,000 to prepare and file, take 2-4 months to implement, and require refiling only on material changes. Choosing the wrong route — or failing to identify which route applies — exposes foreign companies to fines of up to RMB 50 million or 5% of annual revenue under PIPL Article 66. Understanding the precise eligibility criteria, process differences, and strategic considerations for each route is essential for any foreign company transferring personal information from China to overseas affiliates, headquarters, or service providers.

Who Must Use the CAC Security Assessment Route

The CAC Security Assessment (安全评估, ānquán pínggū) is the strictest of the three approved cross-border data transfer routes under PIPL Article 38. It is governed by the Measures for Security Assessment of Cross-Border Data Transfers (数据出境安全评估办法, shùjù chūjìng ānquán pínggū bànfǎ, effective September 2022, updated March 2026). Under these Measures, a CAC Security Assessment is mandatory for: Critical Information Infrastructure Operators (CIIOs) formally designated under the Cybersecurity Law (CSL, 网络安全法, wǎngluò ānquán fǎ); organizations that process the personal information of more than 1 million individuals annually and plan to transfer personal information abroad; organizations transferring important data (重要数据, zhòngyào shùjù) as defined in industry-specific catalogues under the Data Security Law (DSL, 数据安全法, shùjù ānquán fǎ); and organizations that have transferred the sensitive personal information of more than 10,000 individuals abroad in the preceding 12 months, even if their total processed personal information is below the 1 million threshold.

Foreign companies should carefully assess whether any of these criteria apply, as the consequences of incorrectly using the SCC route when the Security Assessment route is mandatory include invalidation of the transfer authorization and exposure to full PIPL penalties. The CAC’s 2025 enforcement actions included at least 4 cases where companies had inappropriately used SCCs for transfers requiring a Security Assessment, with fines averaging RMB 4.5 million per case. A 2025 survey by the China Data Security Association found that approximately 22% of FIEs initially self-assessed their data volume incorrectly, leading to the wrong route choice.

Who Can Use the SCC Route

Standard Contractual Clauses (SCCs, 标准合同条款, biāozhǔn hétong tiáokuǎn) under the Measures on Standard Contracts for Cross-Border Transfer of Personal Information (个人信息出境标准合同办法, gèrén xìnxī chūjìng biāozhǔn hétong bànfǎ, effective June 2023) are available for organizations that meet ALL of the following conditions: not formally designated as a CIIO; processes personal information of fewer than 1 million individuals annually; transfers personal information of fewer than 100,000 individuals abroad since January 1 of the prior year; transfers sensitive personal information of fewer than 10,000 individuals abroad; and does not involve the transfer of important data under any industry-specific catalogue.

The practical impact for foreign companies: a typical mid-size WFOE (外商独资企业, wàishāng dúzī qǐyè) with 200-500 employees and a relatively small customer base can usually use the SCC route, provided it does not process data for more than 1 million individuals and does not hold important data. For larger FIEs with significant customer-facing operations — especially in e-commerce, fintech, or social media — the Security Assessment route is more likely to be required. Companies should reassess their eligibility annually as data volumes grow, particularly during periods of business expansion or customer base growth.

Comparative Analysis: 10 Key Differences

DimensionCAC Security AssessmentStandard Contractual ClausesPractical Impact
Eligibility thresholdCIIO, >1M individuals, important data, or >10K sensitive PINon-CIIO, <1M individuals, no important dataSecurity Assessment required for larger/higher-risk profiles
Approval modelAffirmative CAC approval before transferFile-and-effect after 15-day CAC reviewSCCs are faster, lower rejection risk
Processing time45-90 working days (official); 6-9 months real-world15 working days (CAC review); 2-4 months totalSCCs are 3-4x faster
Validity period2 years from approval dateDuration of contract (review at 3 years)Security Assessment requires formal renewal every 2 years
Preparation costRMB 400,000-1,200,000RMB 100,000-300,000Security Assessment 3-4x more expensive
Renewal cost (annualized)RMB 200,000-600,000/yearRMB 33,000-100,000/yearSecurity Assessment 6x more expensive
CAC revocation riskCAC may revoke at any timeCAC may require modificationBoth carry regulatory risk
Documentation burdenFull DPIA + data flow map + security assessment + legal opinionsSigned SCC + DPIA + filing formSecurity Assessment 3-4x more documentation
Third-party beneficiary rightsNot explicitly providedData subjects have third-party rightsSCCs provide stronger individual protection
Public disclosure riskNon-compliance publicly namedFiling status not publicComparable — both carry naming risk

The CAC Security Assessment Process: Step by Step

  1. Determine applicability — Assess whether any of the four mandatory assessment criteria apply to your company. This requires a data classification audit and volume assessment under PIPL thresholds, typically taking 4-8 weeks for a mid-size FIE.
  2. Conduct a DPIA — Prepare a comprehensive Personal Information Protection Impact Assessment (PIPIA, 个人信息保护影响评估, gèrén xìnxī bǎohù yǐngxiǎng pínggū) covering the purpose, scope, necessity, and security measures of the proposed cross-border data transfer. The DPIA must address the legality and legitimacy of the data transfer, the potential impact on individual rights, and the effectiveness of security measures at the overseas data recipient. The DPIA must be retained for at least 3 years under PIPL Article 55-56.
  3. Engage PRC legal counsel — Work with a PRC-licensed law firm to prepare the assessment application, including basic information about the data exporter and importer, a detailed description of the data being transferred, the DPIA report, the data processing agreement with the overseas recipient, and relevant business licenses and certifications.
  4. Submit through provincial CAC — File the application with the provincial-level CAC office where your company is registered. The provincial CAC conducts an initial review (typically 7-15 working days) before forwarding to the national CAC.
  5. National CAC assessment — The national CAC conducts the formal security assessment, reviewing all materials, consulting with relevant industry regulators, and potentially requesting supplementary information. The CAC must issue a decision within 45 working days, extendable by up to 45 working days for complex cases.
  6. Receive and implement decision — If approved, the company receives a formal approval notice valid for 2 years, possibly with conditions. If denied, the company must cease cross-border transfers and may receive guidance on how to modify the application for resubmission.

The SCC Filing Process: Step by Step

  1. Confirm eligibility — Verify all five conditions for SCC use. Incorrect self-assessment can lead to enforcement actions. Reassess eligibility annually.
  2. Execute the standard contract — Use the CAC’s standard form including the names and contact information of both parties, the purpose and legal basis for the transfer, data categories and sensitivity, retention period, security measures, data subject rights, liability provisions, and dispute resolution terms.
  3. Conduct a DPIA — Prepare a PIPIA specific to the SCC-filed transfer. While less detailed than the Security Assessment DPIA, it must still cover legality, necessity, and security implications. Retain for at least 3 years.
  4. File with provincial CAC — Submit the executed SCC, DPIA, and filing form within 30 working days of contract execution. The CAC has 15 working days to review. If no objections raised, the SCC becomes effective and the company may proceed with transfers.

Strategic Decision Framework

  1. Your company is a CIIO or processes >1M individuals: Security Assessment is mandatory. Begin 9 months before intended transfer start. Budget RMB 600,000-1,200,000 for initial compliance. Engage specialized PRC data compliance counsel with CAC assessment experience.
  2. Your company processes 100,000-1M individuals and is not a CIIO: Evaluate both routes. SCC is preferred for cost and speed. If data volume is expected to exceed 1M within 2 years, starting with Security Assessment may be strategic to avoid a mid-cycle route change.
  3. Your company processes fewer than 100,000 individuals: SCC is the appropriate choice unless you handle important data. Budget RMB 100,000-300,000. Prepare for volume growth that may trigger Security Assessment eligibility.
  4. Your company transfers sensitive healthcare or financial data: Consider Security Assessment even below volume thresholds. Industry regulators (NHC for healthcare, PBOC for finance) may require Security Assessment-level review regardless of PIPL thresholds. Sector-specific important data catalogues are broader than general PIPL categories.
  5. Your company operates in an FTZ with pilot exemptions: Check whether your FTZ management authority has issued exemptions from cross-border data transfer requirements. Shanghai FTZ, Lingang, Hainan FTP, and Shenzhen Qianhai have pilot programs that may exempt certain non-personal business data from both routes, requiring formal documentation and advance registration.

Recent Regulatory Changes (2025-2026)

The March 2026 update to the Measures for Security Assessment of Cross-Border Data Transfers introduced a tiered assessment model with streamlined renewal for low-risk transfers, reducing documentation burden by approximately 40% for qualifying companies. The updated measures clarified the data volume calculation methodology: the 1 million individual threshold is now calculated based on unique data subjects in the preceding calendar year, including current and former employees, customers, suppliers, and business partners. The CAC’s Data Export Facilitation Measures (January 2026) created pilot exemptions in select FTZs for non-personal, non-important data, potentially reducing the need for either route for qualifying data categories. Foreign companies operating in FTZs should monitor their zone’s implementation progress: as of July 2026, the Shanghai FTZ and Lingang pilot programs are most advanced, with published guidance on exempt data categories and registration procedures.

Where to Go From Here

Choosing between the CAC Security Assessment and SCC routes depends on your data profile, volume, industry, and growth trajectory. Conduct a thorough data classification audit and consult with PRC data compliance counsel to make the right choice.

SCCs vs Security Assessment: Which Cross-Border Data Route for Your China Business? — first published on China Gateway 360. Last updated: July 2026.

Official Sources

Related articles

China Fair Competition Policy Week 2026: Review Local Incentives Before Relying on Them

Information date: 7 September 2026 — China’s State Administration for Market Regulation scheduled the 2026 Fair Competition Policy Publicity Week for 7–11 September and listed 95 activities focused on fair-competition po

China Cross-Border Cash Pooling Expands on 14 September: Revalidate the Treasury Perimeter

Information date: 7 September 2026 — A PBOC and SAFE notice issued on 14 August 2026 takes effect on 14 September and expands the integrated cross-border renminbi and foreign-currency cash-pooling policy nationwide, with

China Entry Checklist Case: Test a Representative Office Against a Subsidiary Before Filing

Information date: 7 September 2026 — China’s official business-service information distinguishes market-entry procedures and business forms; a representative office and a foreign-invested company do not provide the same

Registered Capital Resource: Turn China Company-Law Commitments Into a Funding Calendar

Information date: 7 September 2026 — China’s revised Company Law took effect on 1 July 2024 and generally requires shareholders of a newly formed limited liability company to pay subscribed capital within five years afte