SCCs vs Security Assessment: Which Cross-Border Data Route for Your China Business?

Date:

Share post:

The CAC Security Assessment is mandatory for high-volume data processors and CIIOs, while Standard Contractual Clauses (SCCs) are available for organizations processing personal information of fewer than 1 million individuals annually that do not qualify as CIIOs — but the two routes differ in cost, duration, legal certainty, and ongoing compliance burden by approximately 300% across all metrics. A CAC Security Assessment costs an average of RMB 400,000-1,200,000 in preparation costs, takes 6-9 months from initiation to approval, and is valid for 2 years. Standard Contractual Clauses cost an average of RMB 100,000-300,000 to prepare and file, take 2-4 months to implement, and require refiling only on material changes. Choosing the wrong route — or failing to identify which route applies — exposes foreign companies to fines of up to RMB 50 million or 5% of annual revenue under PIPL Article 66. Understanding the precise eligibility criteria, process differences, and strategic considerations for each route is essential for any foreign company transferring personal information from China to overseas affiliates, headquarters, or service providers.

Who Must Use the CAC Security Assessment Route

The CAC Security Assessment (安全评估, ānquán pínggū) is the strictest of the three approved cross-border data transfer routes under PIPL Article 38. It is governed by the Measures for Security Assessment of Cross-Border Data Transfers (数据出境安全评估办法, shùjù chūjìng ānquán pínggū bànfǎ, effective September 2022, updated March 2026). Under these Measures, a CAC Security Assessment is mandatory for: Critical Information Infrastructure Operators (CIIOs) formally designated under the Cybersecurity Law (CSL, 网络安全法, wǎngluò ānquán fǎ); organizations that process the personal information of more than 1 million individuals annually and plan to transfer personal information abroad; organizations transferring important data (重要数据, zhòngyào shùjù) as defined in industry-specific catalogues under the Data Security Law (DSL, 数据安全法, shùjù ānquán fǎ); and organizations that have transferred the sensitive personal information of more than 10,000 individuals abroad in the preceding 12 months, even if their total processed personal information is below the 1 million threshold.

Foreign companies should carefully assess whether any of these criteria apply, as the consequences of incorrectly using the SCC route when the Security Assessment route is mandatory include invalidation of the transfer authorization and exposure to full PIPL penalties. The CAC’s 2025 enforcement actions included at least 4 cases where companies had inappropriately used SCCs for transfers requiring a Security Assessment, with fines averaging RMB 4.5 million per case. A 2025 survey by the China Data Security Association found that approximately 22% of FIEs initially self-assessed their data volume incorrectly, leading to the wrong route choice.

Who Can Use the SCC Route

Standard Contractual Clauses (SCCs, 标准合同条款, biāozhǔn hétong tiáokuǎn) under the Measures on Standard Contracts for Cross-Border Transfer of Personal Information (个人信息出境标准合同办法, gèrén xìnxī chūjìng biāozhǔn hétong bànfǎ, effective June 2023) are available for organizations that meet ALL of the following conditions: not formally designated as a CIIO; processes personal information of fewer than 1 million individuals annually; transfers personal information of fewer than 100,000 individuals abroad since January 1 of the prior year; transfers sensitive personal information of fewer than 10,000 individuals abroad; and does not involve the transfer of important data under any industry-specific catalogue.

The practical impact for foreign companies: a typical mid-size WFOE (外商独资企业, wàishāng dúzī qǐyè) with 200-500 employees and a relatively small customer base can usually use the SCC route, provided it does not process data for more than 1 million individuals and does not hold important data. For larger FIEs with significant customer-facing operations — especially in e-commerce, fintech, or social media — the Security Assessment route is more likely to be required. Companies should reassess their eligibility annually as data volumes grow, particularly during periods of business expansion or customer base growth.

Comparative Analysis: 10 Key Differences

Dimension CAC Security Assessment Standard Contractual Clauses Practical Impact
Eligibility threshold CIIO, >1M individuals, important data, or >10K sensitive PI Non-CIIO, <1M individuals, no important data Security Assessment required for larger/higher-risk profiles
Approval model Affirmative CAC approval before transfer File-and-effect after 15-day CAC review SCCs are faster, lower rejection risk
Processing time 45-90 working days (official); 6-9 months real-world 15 working days (CAC review); 2-4 months total SCCs are 3-4x faster
Validity period 2 years from approval date Duration of contract (review at 3 years) Security Assessment requires formal renewal every 2 years
Preparation cost RMB 400,000-1,200,000 RMB 100,000-300,000 Security Assessment 3-4x more expensive
Renewal cost (annualized) RMB 200,000-600,000/year RMB 33,000-100,000/year Security Assessment 6x more expensive
CAC revocation risk CAC may revoke at any time CAC may require modification Both carry regulatory risk
Documentation burden Full DPIA + data flow map + security assessment + legal opinions Signed SCC + DPIA + filing form Security Assessment 3-4x more documentation
Third-party beneficiary rights Not explicitly provided Data subjects have third-party rights SCCs provide stronger individual protection
Public disclosure risk Non-compliance publicly named Filing status not public Comparable — both carry naming risk

The CAC Security Assessment Process: Step by Step

  1. Determine applicability — Assess whether any of the four mandatory assessment criteria apply to your company. This requires a data classification audit and volume assessment under PIPL thresholds, typically taking 4-8 weeks for a mid-size FIE.
  2. Conduct a DPIA — Prepare a comprehensive Personal Information Protection Impact Assessment (PIPIA, 个人信息保护影响评估, gèrén xìnxī bǎohù yǐngxiǎng pínggū) covering the purpose, scope, necessity, and security measures of the proposed cross-border data transfer. The DPIA must address the legality and legitimacy of the data transfer, the potential impact on individual rights, and the effectiveness of security measures at the overseas data recipient. The DPIA must be retained for at least 3 years under PIPL Article 55-56.
  3. Engage PRC legal counsel — Work with a PRC-licensed law firm to prepare the assessment application, including basic information about the data exporter and importer, a detailed description of the data being transferred, the DPIA report, the data processing agreement with the overseas recipient, and relevant business licenses and certifications.
  4. Submit through provincial CAC — File the application with the provincial-level CAC office where your company is registered. The provincial CAC conducts an initial review (typically 7-15 working days) before forwarding to the national CAC.
  5. National CAC assessment — The national CAC conducts the formal security assessment, reviewing all materials, consulting with relevant industry regulators, and potentially requesting supplementary information. The CAC must issue a decision within 45 working days, extendable by up to 45 working days for complex cases.
  6. Receive and implement decision — If approved, the company receives a formal approval notice valid for 2 years, possibly with conditions. If denied, the company must cease cross-border transfers and may receive guidance on how to modify the application for resubmission.

The SCC Filing Process: Step by Step

  1. Confirm eligibility — Verify all five conditions for SCC use. Incorrect self-assessment can lead to enforcement actions. Reassess eligibility annually.
  2. Execute the standard contract — Use the CAC’s standard form including the names and contact information of both parties, the purpose and legal basis for the transfer, data categories and sensitivity, retention period, security measures, data subject rights, liability provisions, and dispute resolution terms.
  3. Conduct a DPIA — Prepare a PIPIA specific to the SCC-filed transfer. While less detailed than the Security Assessment DPIA, it must still cover legality, necessity, and security implications. Retain for at least 3 years.
  4. File with provincial CAC — Submit the executed SCC, DPIA, and filing form within 30 working days of contract execution. The CAC has 15 working days to review. If no objections raised, the SCC becomes effective and the company may proceed with transfers.

Strategic Decision Framework

  1. Your company is a CIIO or processes >1M individuals: Security Assessment is mandatory. Begin 9 months before intended transfer start. Budget RMB 600,000-1,200,000 for initial compliance. Engage specialized PRC data compliance counsel with CAC assessment experience.
  2. Your company processes 100,000-1M individuals and is not a CIIO: Evaluate both routes. SCC is preferred for cost and speed. If data volume is expected to exceed 1M within 2 years, starting with Security Assessment may be strategic to avoid a mid-cycle route change.
  3. Your company processes fewer than 100,000 individuals: SCC is the appropriate choice unless you handle important data. Budget RMB 100,000-300,000. Prepare for volume growth that may trigger Security Assessment eligibility.
  4. Your company transfers sensitive healthcare or financial data: Consider Security Assessment even below volume thresholds. Industry regulators (NHC for healthcare, PBOC for finance) may require Security Assessment-level review regardless of PIPL thresholds. Sector-specific important data catalogues are broader than general PIPL categories.
  5. Your company operates in an FTZ with pilot exemptions: Check whether your FTZ management authority has issued exemptions from cross-border data transfer requirements. Shanghai FTZ, Lingang, Hainan FTP, and Shenzhen Qianhai have pilot programs that may exempt certain non-personal business data from both routes, requiring formal documentation and advance registration.

Recent Regulatory Changes (2025-2026)

The March 2026 update to the Measures for Security Assessment of Cross-Border Data Transfers introduced a tiered assessment model with streamlined renewal for low-risk transfers, reducing documentation burden by approximately 40% for qualifying companies. The updated measures clarified the data volume calculation methodology: the 1 million individual threshold is now calculated based on unique data subjects in the preceding calendar year, including current and former employees, customers, suppliers, and business partners. The CAC’s Data Export Facilitation Measures (January 2026) created pilot exemptions in select FTZs for non-personal, non-important data, potentially reducing the need for either route for qualifying data categories. Foreign companies operating in FTZs should monitor their zone’s implementation progress: as of July 2026, the Shanghai FTZ and Lingang pilot programs are most advanced, with published guidance on exempt data categories and registration procedures.

Where to Go From Here

Choosing between the CAC Security Assessment and SCC routes depends on your data profile, volume, industry, and growth trajectory. Conduct a thorough data classification audit and consult with PRC data compliance counsel to make the right choice.

SCCs vs Security Assessment: Which Cross-Border Data Route for Your China Business? — first published on China Gateway 360. Last updated: July 2026.

Official Sources

Related articles

China Cross-Border Data Update: CAC Publishes 2026 Data Export Compliance Guidelines — Key Takeaways

China Cross-Border Data Update: CAC Publishes 2026 Data Export Compliance Guidelines — Key Takeaways The Cyberspace Administration of China (CAC, 国家互联

China Data Security Update: Sector-Specific Data Localisation Rules Released — Key Takeaways

China Data Security Update: Sector-Specific Data Localisation Rules Released — Key Takeaways In a major expansion of China's data governance framework

China PIPL Update: New Cross-Border Data Transfer Exemption Rules Announced — Key Takeaways

China PIPL Update: New Cross-Border Data Transfer Exemption Rules Announced — Key Takeaways On [Date], the Cybersecurity Administration of China (CAC)

China Cross-Border Data Update: MOFCOM Clarifies Export Rules for Foreign Enterprises — Key Takeaways

MOFCOM Clarifies Cross-Border Data Export Rules for Foreign Enterprises — Key Takeaways On March 22, 2025, China’s Ministry of Commerce (MOFCOM, 商务部,