What data transfers from China require a security assessment for foreign companies?
A CAC security assessment is mandatory in four specific scenarios under China’s cross-border data transfer framework as of 2026. These scenarios are defined by the Measures on Security Assessment for Cross-Border Data Transfer (effective September 2022, as amended with the Data Flow Regulations March 2024) and apply to both Chinese domestic companies and foreign-invested enterprises operating in China. The most relevant thresholds for foreign companies involve data volume, data sensitivity, operator type, and sector-specific requirements — and failing to identify when a security assessment is required can result in penalties of up to RMB 50 million or 5% of annual revenue under PIPL Article 66.
Scenario 1: CIIO operators transferring any personal information overseas
Critical Information Infrastructure Operators (CIIOs) face the strictest requirements under the cross-border data transfer framework. If your company has been formally designated as a CIIO by a sector regulator (such as MIIT for telecommunications or PBOC for financial services), a CAC security assessment is required for any and all cross-border transfers of personal information, regardless of volume, sensitivity, or purpose.
As of 2026, approximately 340 foreign-invested enterprises have been designated as CIIOs by Chinese regulators, primarily in the financial services, telecommunications, energy, and transportation sectors. The number of designated foreign CIIOs has grown steadily from approximately 180 in 2023 to 340 in 2026, reflecting the expanding scope of China’s critical information infrastructure identification program., primarily in the financial services, telecommunications, energy, and transportation sectors. These companies cannot use SCCs or PIAB certification as alternatives — the security assessment is the sole legal pathway. The assessment must be completed before any cross-border data transfer begins, even for transfers that were previously conducted under SCCs or other mechanisms prior to CIIO designation.
An important point for foreign companies: CIIO designation is not self-declared. It is determined by sector regulators based on criteria including the size of the information system, the criticality of the sector, the potential impact of system disruption on national security and public interests, and the extent of harm from data breaches. Foreign companies that believe they may meet CIIO criteria should proactively clarify their status with the relevant regulator, as the penalties for conducting transfers without a required security assessment apply regardless of whether the company was formally notified of its CIIO status.
Scenario 2: Non-CIIO entities transferring important data overseas
The Data Security Law (DSL) defines “important data” as data that, if tampered with, destroyed, leaked, or illegally obtained or used, could harm national security, economic operations, social stability, or public interests. Under the CAC’s Measures, any entity — CIIO or non-CIIO — that transfers important data overseas must undergo a security assessment. There are no volume-based exemptions for important data transfers.
Foreign companies most frequently encounter important data in the following sectors:
| Sector | Examples of Important Data | Regulatory Catalogue |
|---|---|---|
| Automotive | Vehicle trajectory data for >1,000 vehicles, HD map data, driving behavior datasets | Automotive Data Security Management (MIIT) |
| Healthcare | Population-level health statistics, genetic data, disease outbreak data | Health and Medical Data Management (NHC) |
| Finance | Aggregate cross-border transaction data, credit scoring models, systemic risk indicators | Financial Data Security (PBOC) |
| Manufacturing | Supply chain data for dual-use items, production capacity data for strategic industries | Industry and Information Technology Data (MIIT) |
| Energy | Grid operation data, resource exploration results, consumption data for strategic minerals | Energy Data Management (NEA) |
As of early 2026, 18 sector-specific important data catalogues have been published, and an additional 6 are in draft form. Foreign companies should review all applicable catalogues for their industry to determine whether any data transferred overseas qualifies as important data and triggers the mandatory security assessment requirement.
Scenario 3: Non-CIIO entities transferring large volumes of personal information
Under the current framework (amended by the Data Flow Regulations effective March 2024), a CAC security assessment is required when a non-CIIO entity transfers personal information overseas and meets either of the following volume thresholds:
- More than 1 million individuals’ personal information transferred cumulatively since January 1 of the current calendar year. This is a significant relaxation from the original threshold (100,000 individuals) under the pre-2024 framework.
- More than 10,000 individuals’ sensitive personal information transferred cumulatively since January 1 of the current calendar year. Sensitive PI under PIPL includes: financial account information, identification documents, biometric data, health data, location data, minor data (children under 14), and any data used for user profiling.
Importantly, these thresholds are cumulative and annual — they reset on January 1 each year. A foreign company that transfers 600,000 customer records in January and 500,000 vendor records in August has crossed the 1 million threshold even though no single transfer exceeded it. The cumulative calculation also applies across all purposes and all departments of the Chinese entity — HR data, customer data, vendor data, and operations data must all be aggregated.
Scenario 4: Sector-specific mandatory assessments
Certain regulated industries have their own mandatory cross-border data security assessment requirements that operate in parallel with the general PIPL/DSL framework. These sector-specific rules may require assessments for data transfers that would not trigger a security assessment under the general framework:
- Financial sector: The PBOC’s Financial Data Security Rules require cross-border assessments for a broader range of financial data than the general PIPL/DSL thresholds. Any transfer of customer financial information, transaction data, or credit information by a bank, securities firm, or insurance company may require a sector-specific assessment in addition to (or instead of) the general CAC assessment.
- Healthcare and biotech: The NHC’s rules on population health data and genetic data require regulatory approval for cross-border transfers of human genetic resources (HGR) under the Human Genetic Resources Management Regulations, which is a separate assessment from the CAC security assessment and is administered by the Ministry of Science and Technology (MOST).
- Automotive: The MIIT’s automotive data security rules require a data security assessment for cross-border transfers of vehicle data, including trajectory data, in-vehicle camera data, and connected car service data, at thresholds that may be lower than the general PIPL/DSL thresholds.
- Mapping and surveying: The Ministry of Natural Resources (MNR) requires separate approval for cross-border transfers of geospatial data, including any data collected by mapping, surveying, or navigation systems attached to vehicles or mobile devices.
How do I determine if my company’s data transfers fall into these scenarios?
To determine whether your foreign company’s data transfers require a CAC security assessment, follow this decision process:
- Step 1: Identify your company’s regulatory status — Have you been designated as a CIIO? Do you operate in a CII-designated sector? If yes, proceed to security assessment requirement.
- Step 2: Classify your data — Conduct a data inventory to identify all data categories transferred overseas. Does any data qualify as “important data” under applicable sector catalogues? If yes, proceed to security assessment requirement.
- Step 3: Measure cumulative annual volume — Calculate the total volume of personal information transferred since January 1 of the current year. Is the cumulative PI volume >1 million? Or cumulative sensitive PI volume >10,000? If yes, proceed to security assessment requirement.
- Step 4: Check sector-specific requirements — Does your company operate in a regulated sector (finance, healthcare, automotive, geo-spatial) with additional assessment obligations? If yes, consult the sector regulator’s rules in addition to the CAC framework.
- Step 5: Document your determination — Even if no security assessment is required, document the basis for your determination (volume calculations, data classification results, regulatory status confirmation) as part of your compliance records.
Foreign companies that undergo a thorough data mapping exercise typically find that approximately 30% of cross-border data flows trigger at least one of these security assessment scenarios, with the highest trigger rates in financial services (65% of flows), healthcare (58%), and automotive (52%).
What are the consequences of failing to conduct a required security assessment?
| Violation Type | Penalty Range | Regulatory Basis |
|---|---|---|
| Cross-border transfer without required assessment | RMB 5 million – RMB 50 million or 5% of prior year revenue | PIPL Article 66 |
| Transfer of important data without assessment | RMB 2 million – RMB 20 million | DSL Article 46 |
| Failure to notify CAC of material changes | RMB 500,000 – RMB 5 million | PIPL Article 66 |
| Individual liability for responsible officers | RMB 50,000 – RMB 500,000 + potential travel ban | PIPL Article 66, DSL Article 46 |
Beyond financial penalties, companies that fail to conduct required security assessments may face suspension of data transfer activities, forced deletion of data already transferred overseas, public blacklisting, and enhanced regulatory scrutiny of all future compliance filings. In serious cases involving important data or large volumes of personal information, criminal liability under China’s Criminal Law may also apply.
Where to Go From Here
Based on what you just read:
- Ready to act? Read a step-by-step guide to determining whether your company’s data transfers require a security assessment
- Still comparing? See a side-by-side comparison of all four security assessment trigger scenarios
- Need numbers? Try an interactive data transfer assessment trigger checker for your specific data profile
What data transfers from China require a security assessment for foreign companies? — first published on China Gateway 360. Last updated: July 2026.
