Executive Summary
The China (Tianjin) Pilot Free Trade Zone created the country’s first comprehensive free-trade-zone negative list for outbound data in May 2024. The list identified 13 main categories and 46 subcategories of data that require a security assessment, giving companies a more concrete basis for identifying important data. In February 2026, Tianjin published trial management measures and an implementation guide for using the negative-list mechanism.
The commercial benefit is narrower than the phrase “everything outside the list can be exported freely” suggests. A qualifying FTZ data processor can be exempt from the three procedural mechanisms for data outside the applicable negative list: the CAC security assessment, the personal information export standard contract and personal information protection certification. The company must still comply with the Personal Information Protection Law, data-security duties, sector rules, contractual controls and the Tianjin management requirements. Eligibility also depends on the exporting entity and processing activity being within the FTZ scope.
Why the Tianjin Negative List Matters
Important-data identification has been one of the hardest parts of China data-export compliance. National law requires a security assessment for important data, but a business cannot make a reliable filing decision if the relevant data category is not defined. Tianjin’s list addressed that problem through sector and scenario descriptions. It was especially relevant to the FTZ’s industrial base, which includes automotive, advanced manufacturing, civil aviation, finance, biomedicine and port logistics.
For a multinational company, the value is operational predictability. Engineering teams can distinguish routine production information from listed data; logistics teams can map cross-border systems; and legal teams can document why a specific transfer falls inside or outside the local list. The mechanism does not eliminate judgement, but it gives management a better starting point than a generic national risk label.
Policy Background and Current Position
The national Provisions on Promoting and Regulating Cross-Border Data Flows took effect on 22 March 2024. They allow a pilot free trade zone, within the national data-classification framework, to prepare its own outbound-data negative list, obtain provincial approval and file it with the national cyberspace and data authorities. Data processors in the zone may use the exemption for data outside the filed list.
Tianjin released its 2024 list in May of that year. Official reporting described 13 main classes and 46 sub-classes requiring security assessment. The 2026 trial management measures and implementation guide provide the current administrative framework for using the list. Companies should work from the published documents and attachments, not from short media summaries, because the applicable definitions, territorial scope and evidence requirements determine whether the exemption is available.
Key Factors to Consider
1. FTZ Entity and Processing Scope
The first question is whether the data processor and relevant processing activity are within the Tianjin FTZ mechanism. A group cannot assume that a Tianjin registration automatically covers transfers made by another China affiliate or a system operated outside the zone. The exporter, data controller, system access and business process should be mapped entity by entity.
2. Data Classification
Classify the exported fields against the Tianjin list, national standards and any sector catalogue. The review should distinguish ordinary business data, personal information, sensitive personal information and important data. A mixed data set should not be labelled according to its least sensitive field. If a transfer combines listed important data with routine records, the important-data route controls unless the data set is redesigned.
3. Personal Information Obligations
Being outside the FTZ negative list does not switch off personal information protection. The processor still needs a lawful processing basis, appropriate notice, data minimization, security, individual-rights procedures and a personal information protection impact assessment where required. Contracts with overseas recipients should address purpose, retention, onward transfer, incident response and deletion.
4. Sector Rules and System Architecture
Automotive, finance, health, mapping, telecommunications and critical-infrastructure activities can be subject to additional rules. Remote access by an overseas headquarters can constitute a data export even where the database remains in China. The compliance file should therefore include architecture diagrams, user roles and access logs, not just a list of data fields.
Step-by-Step Compliance Process
- Identify the exporter. Confirm the Tianjin entity that decides the purpose and method of the transfer.
- Map the scenario. Record recipient, purpose, system, access method, frequency, retention and onward recipients.
- Create a field-level inventory. Separate data elements rather than classifying an entire application by its business name.
- Check the Tianjin negative list. Map each relevant field and scenario to the official categories and examples.
- Check national and sector rules. Confirm whether another authority has designated the data as important or imposed a separate export control.
- Test personal information thresholds and exemptions. Apply the national 2024 rules independently of the important-data analysis.
- Select the route. Document FTZ exemption eligibility or complete the applicable standard contract, certification or security assessment.
- Implement safeguards. Restrict data, encrypt transfers, control overseas access and establish incident procedures.
- Monitor changes. Reassess new fields, recipients, systems, purposes, volumes and changes to the negative list.
Options and Compliance Route Comparison
| Situation | Likely Procedural Position | Management Action |
|---|---|---|
| Tianjin FTZ processor, data outside the applicable negative list | Potential FTZ procedural exemption | Document entity, territorial and data-scope eligibility and retain the classification record |
| Data appears on the Tianjin list as important data | Security assessment | Complete risk self-assessment and prepare the CAC submission |
| Personal information below national thresholds and within an exemption | Potential national procedural exemption | Document the exemption and maintain PIPL controls |
| Personal information above the relevant thresholds | Standard contract, certification or security assessment depending on volume and sensitivity | Use the national route and complete the required impact assessment |
| Exporter or processing activity outside the Tianjin FTZ scope | Tianjin list may not be available | Apply national and other applicable local rules |
Costs and Timeline
The main cost is not the list itself; it is the work required to establish reliable facts. A focused transfer may need a short data inventory, legal classification and control memo. A group platform serving several China entities may require technical discovery, sector counsel, contract amendments and access-control changes. Budget should cover legal, privacy, security, IT and business-owner time.
Do not promise a fixed filing schedule before the route is confirmed. If the transfer qualifies for the FTZ exemption, implementation can still be delayed by incomplete architecture records or overseas-recipient controls. If a security assessment is needed, submission quality and authority questions affect timing. The most efficient project reduces unnecessary data before it starts the procedural work.
Risks and Challenges
- Using an English-language media summary instead of the official list and implementation guide.
- Assuming the exemption follows the corporate group rather than the eligible FTZ processor.
- Treating data outside the list as exempt from personal information protection and cybersecurity duties.
- Ignoring sector-specific important-data catalogues or a formal authority notification.
- Failing to count remote access and cloud administration as possible outbound transfers.
- Keeping listed and non-listed data in one export file when separation could reduce the compliance burden.
Common Mistakes
A common mistake is describing Tianjin’s mechanism as a list of data that can never leave China. The list instead identifies data requiring a security-assessment route. Another mistake is reducing the list to seven broad categories; the official 2024 release reported 13 main classes and 46 sub-classes. Companies also rely on a Tianjin address without proving that the relevant processor and activity fall within the FTZ mechanism.
Best Practices and Recommendations
Prepare a signed classification memo for each recurring transfer. Attach the data inventory, architecture diagram, list mapping, PIPL analysis, recipient controls and approval owner. Create a change-control trigger in procurement and IT governance so that a new field or overseas user reopens the analysis. Where possible, separate important or sensitive data from routine operational data and provide overseas teams only the fields they need.
FAQ
Was Tianjin the first FTZ to publish a comprehensive outbound-data negative list?
Official Tianjin reporting described the May 2024 release as the country’s first comprehensive FTZ data-export negative list.
Does data outside the list move without any legal obligations?
No. The FTZ mechanism can exempt specified procedural routes, but PIPL, data-security, sector and contractual obligations remain.
Does the list apply to every affiliate in a multinational group?
No. Eligibility must be assessed for the actual exporter, processing activity and territorial scope.
What if one data set contains both listed and ordinary data?
Redesign or separate the data set where possible. Otherwise, the listed important-data element can determine the route for the combined transfer.
Should a company rely on the 2024 list or the 2026 documents?
Use the current official list together with the 2026 trial management measures and implementation guide, and check for later amendments before each material project.
Conclusion
Tianjin’s negative-list mechanism improves predictability, but it works only when the company can prove who exports the data, where the processing occurs and how each field is classified. The strongest compliance file connects legal analysis to the actual system and is updated whenever the data or access model changes.
Official Sources
- CAC: Provisions on Promoting and Regulating Cross-Border Data Flows
- CAC: official directory of FTZ outbound-data negative lists
- Tianjin Economic-Technological Development Area: 2024 negative-list release
- Tianjin Data Bureau: 2026 trial management measures and implementation guide
- Personal Information Protection Law of the People’s Republic of China
