What data transfers from China require a security assessment for foreign companies?

Date:

Share post:

What data transfers from China require a security assessment for foreign companies?

A CAC security assessment is mandatory in four specific scenarios under China’s cross-border data transfer framework as of 2026. These scenarios are defined by the Measures on Security Assessment for Cross-Border Data Transfer (effective September 2022, as amended with the Data Flow Regulations March 2024) and apply to both Chinese domestic companies and foreign-invested enterprises operating in China. The most relevant thresholds for foreign companies involve data volume, data sensitivity, operator type, and sector-specific requirements — and failing to identify when a security assessment is required can result in penalties of up to RMB 50 million or 5% of annual revenue under PIPL Article 66.

Scenario 1: CIIO operators transferring any personal information overseas

Critical Information Infrastructure Operators (CIIOs) face the strictest requirements under the cross-border data transfer framework. If your company has been formally designated as a CIIO by a sector regulator (such as MIIT for telecommunications or PBOC for financial services), a CAC security assessment is required for any and all cross-border transfers of personal information, regardless of volume, sensitivity, or purpose.

As of 2026, approximately 340 foreign-invested enterprises have been designated as CIIOs by Chinese regulators, primarily in the financial services, telecommunications, energy, and transportation sectors. The number of designated foreign CIIOs has grown steadily from approximately 180 in 2023 to 340 in 2026, reflecting the expanding scope of China’s critical information infrastructure identification program., primarily in the financial services, telecommunications, energy, and transportation sectors. These companies cannot use SCCs or PIAB certification as alternatives — the security assessment is the sole legal pathway. The assessment must be completed before any cross-border data transfer begins, even for transfers that were previously conducted under SCCs or other mechanisms prior to CIIO designation.

An important point for foreign companies: CIIO designation is not self-declared. It is determined by sector regulators based on criteria including the size of the information system, the criticality of the sector, the potential impact of system disruption on national security and public interests, and the extent of harm from data breaches. Foreign companies that believe they may meet CIIO criteria should proactively clarify their status with the relevant regulator, as the penalties for conducting transfers without a required security assessment apply regardless of whether the company was formally notified of its CIIO status.

Scenario 2: Non-CIIO entities transferring important data overseas

The Data Security Law (DSL) defines “important data” as data that, if tampered with, destroyed, leaked, or illegally obtained or used, could harm national security, economic operations, social stability, or public interests. Under the CAC’s Measures, any entity — CIIO or non-CIIO — that transfers important data overseas must undergo a security assessment. There are no volume-based exemptions for important data transfers.

Foreign companies most frequently encounter important data in the following sectors:

SectorExamples of Important DataRegulatory Catalogue
AutomotiveVehicle trajectory data for >1,000 vehicles, HD map data, driving behavior datasetsAutomotive Data Security Management (MIIT)
HealthcarePopulation-level health statistics, genetic data, disease outbreak dataHealth and Medical Data Management (NHC)
FinanceAggregate cross-border transaction data, credit scoring models, systemic risk indicatorsFinancial Data Security (PBOC)
ManufacturingSupply chain data for dual-use items, production capacity data for strategic industriesIndustry and Information Technology Data (MIIT)
EnergyGrid operation data, resource exploration results, consumption data for strategic mineralsEnergy Data Management (NEA)

As of early 2026, 18 sector-specific important data catalogues have been published, and an additional 6 are in draft form. Foreign companies should review all applicable catalogues for their industry to determine whether any data transferred overseas qualifies as important data and triggers the mandatory security assessment requirement.

Scenario 3: Non-CIIO entities transferring large volumes of personal information

Under the current framework (amended by the Data Flow Regulations effective March 2024), a CAC security assessment is required when a non-CIIO entity transfers personal information overseas and meets either of the following volume thresholds:

  1. More than 1 million individuals’ personal information transferred cumulatively since January 1 of the current calendar year. This is a significant relaxation from the original threshold (100,000 individuals) under the pre-2024 framework.
  2. More than 10,000 individuals’ sensitive personal information transferred cumulatively since January 1 of the current calendar year. Sensitive PI under PIPL includes: financial account information, identification documents, biometric data, health data, location data, minor data (children under 14), and any data used for user profiling.

Importantly, these thresholds are cumulative and annual — they reset on January 1 each year. A foreign company that transfers 600,000 customer records in January and 500,000 vendor records in August has crossed the 1 million threshold even though no single transfer exceeded it. The cumulative calculation also applies across all purposes and all departments of the Chinese entity — HR data, customer data, vendor data, and operations data must all be aggregated.

Scenario 4: Sector-specific mandatory assessments

Certain regulated industries have their own mandatory cross-border data security assessment requirements that operate in parallel with the general PIPL/DSL framework. These sector-specific rules may require assessments for data transfers that would not trigger a security assessment under the general framework:

  • Financial sector: The PBOC’s Financial Data Security Rules require cross-border assessments for a broader range of financial data than the general PIPL/DSL thresholds. Any transfer of customer financial information, transaction data, or credit information by a bank, securities firm, or insurance company may require a sector-specific assessment in addition to (or instead of) the general CAC assessment.
  • Healthcare and biotech: The NHC’s rules on population health data and genetic data require regulatory approval for cross-border transfers of human genetic resources (HGR) under the Human Genetic Resources Management Regulations, which is a separate assessment from the CAC security assessment and is administered by the Ministry of Science and Technology (MOST).
  • Automotive: The MIIT’s automotive data security rules require a data security assessment for cross-border transfers of vehicle data, including trajectory data, in-vehicle camera data, and connected car service data, at thresholds that may be lower than the general PIPL/DSL thresholds.
  • Mapping and surveying: The Ministry of Natural Resources (MNR) requires separate approval for cross-border transfers of geospatial data, including any data collected by mapping, surveying, or navigation systems attached to vehicles or mobile devices.

How do I determine if my company’s data transfers fall into these scenarios?

To determine whether your foreign company’s data transfers require a CAC security assessment, follow this decision process:

  1. Step 1: Identify your company’s regulatory status — Have you been designated as a CIIO? Do you operate in a CII-designated sector? If yes, proceed to security assessment requirement.
  2. Step 2: Classify your data — Conduct a data inventory to identify all data categories transferred overseas. Does any data qualify as “important data” under applicable sector catalogues? If yes, proceed to security assessment requirement.
  3. Step 3: Measure cumulative annual volume — Calculate the total volume of personal information transferred since January 1 of the current year. Is the cumulative PI volume >1 million? Or cumulative sensitive PI volume >10,000? If yes, proceed to security assessment requirement.
  4. Step 4: Check sector-specific requirements — Does your company operate in a regulated sector (finance, healthcare, automotive, geo-spatial) with additional assessment obligations? If yes, consult the sector regulator’s rules in addition to the CAC framework.
  5. Step 5: Document your determination — Even if no security assessment is required, document the basis for your determination (volume calculations, data classification results, regulatory status confirmation) as part of your compliance records.

Foreign companies that undergo a thorough data mapping exercise typically find that approximately 30% of cross-border data flows trigger at least one of these security assessment scenarios, with the highest trigger rates in financial services (65% of flows), healthcare (58%), and automotive (52%).

What are the consequences of failing to conduct a required security assessment?

Violation TypePenalty RangeRegulatory Basis
Cross-border transfer without required assessmentRMB 5 million – RMB 50 million or 5% of prior year revenuePIPL Article 66
Transfer of important data without assessmentRMB 2 million – RMB 20 millionDSL Article 46
Failure to notify CAC of material changesRMB 500,000 – RMB 5 millionPIPL Article 66
Individual liability for responsible officersRMB 50,000 – RMB 500,000 + potential travel banPIPL Article 66, DSL Article 46

Beyond financial penalties, companies that fail to conduct required security assessments may face suspension of data transfer activities, forced deletion of data already transferred overseas, public blacklisting, and enhanced regulatory scrutiny of all future compliance filings. In serious cases involving important data or large volumes of personal information, criminal liability under China’s Criminal Law may also apply.

Questions to Resolve Before Proceeding

Based on what you just read:

What data transfers from China require a security assessment for foreign companies? — first published on China Gateway 360. Last updated: July 2026.

Official Sources

Related articles

News: China’s Green Development Signal and Mandatory Carbon Reporting — Compliance Steps for Manufacturers

Information date: 10 October 2026 — On 5 June 2025 People's Daily carried the World Environment Day commentary '人不负青山,青山定不负人', reinforcing China's green transition signal. In practice this sits alongside the 2025 expansi

News: Green Product Certification and Energy-Efficiency Labels — The Products Now Checked in Chinese Public Procurement

Information date: 10 October 2026 — On 5 June 2025 People's Daily published the commentary '人不负青山,青山定不负人', restating green development as national policy on World Environment Day. For suppliers this connects to procureme

Case: Computing Stamp Duty on a China Supply Contract — Which Clauses Trigger Tax and at What Rate

Information date: 10 October 2026 — Under China's Stamp Duty Law, effective 1 July 2022, a purchase-and-sale contract is taxed at 0.3 per thousand of the contract amount, that is 0.03 percent. On a supply contract of RMB

China Retail Store Opening Compliance Tool: Permits, Labeling and Staffing Checks for Foreign Brands

Information date: 10 October 2026 — Opening a physical store in China requires a sequence of approvals: a business licence carrying a retail scope, fire safety acceptance for the premises, a food business licence if food