China Data Export Compliance After PIPL: What Triggers a Security Assessment?

China Data Export Compliance After PIPL: What Triggers a Security Assessment?

China data export compliance after the Personal Information Protection Law (PIPL) is no longer a simple question of whether data leaves China. For foreign companies, the practical question is narrower and more important: does this transfer trigger a CAC security assessment, or can it rely on another route such as a standard contract, certification, or no filing at all? Many headquarters still assume any cross-border system access, HR reporting line, or regional CRM sync automatically requires a full filing. That assumption is often wrong, but the opposite assumption is equally dangerous.

Since the 2024 Provisions on Promoting and Regulating Cross-Border Data Flows, the compliance analysis has become more structured. The starting point is not the overseas server alone. It is the type of data, whether the company handles important data, whether it is a critical information infrastructure operator, how much personal information is involved from January 1 of the current year, and whether a statutory exemption applies. For foreign-invested companies that already run China HR, sales, procurement, after-sales, or shared-service functions, the real work is usually internal mapping and evidence collection rather than rushing into a filing.

This article focuses on one issue: when a foreign company in or dealing with China should expect a security assessment, and what should be done before the first submission. For a broader framework on China privacy obligations, see China’s Data Protection Laws: A Practical Guide for Foreign Companies. If the data flow is tied to treasury, settlement, or cross-border operational payments, the company should also review Cross-Border Payment Compliance: Agency, Data, and Criminal Red Lines.

Start with a four-step classification, not with the filing form

Foreign companies usually waste time because the legal team starts from the last step. They ask which filing package to prepare before deciding what category of transfer they actually have. A more defensible order is:

  1. Map the transfer scenario: which China entity or business line sends data, to which overseas recipient, for what operational purpose, by which system or manual process.
  2. Classify the dataset: important data, personal information, sensitive personal information, or operational data that contains neither personal information nor important data.
  3. Check whether an exemption applies under the 2024 rules.
  4. If no exemption applies, measure the annual volume and determine whether the route is security assessment, standard contract or certification, or neither.

This sequence matters because the security-assessment trigger is not designed for every ordinary business transfer. Under the current rules, some common scenarios can be exempt, while others still move into the formal security-assessment channel because of the data category or volume. A foreign parent that asks its China subsidiary to “upload everything to global systems first and sort it out later” creates avoidable filing and enforcement risk.

What usually triggers a CAC security assessment today

In practical terms, foreign companies should expect a security assessment in three recurring situations.

First, the transfer involves important data. This remains the highest-risk category. The compliance problem is not only whether the company believes the data is important. The harder issue is whether the company has been informed by a regulator, industry authority, pilot-zone list, sector rule, or other public framework that the dataset falls into an important-data category. If the data is in that bucket, the company should not assume a standard contract is enough.

Second, the transferring entity is a critical information infrastructure operator (CIIO) and provides personal information or important data overseas. This is not limited to technology companies. Depending on the sector, infrastructure role, and regulator view, companies in telecom, finance, transport, energy, public services, healthcare, or other sensitive sectors may face CIIO-related analysis even if they do not describe themselves that way internally.

Third, a non-CIIO data processor crosses the annual personal-information thresholds. The current framework distinguishes between ordinary personal information and sensitive personal information, and the count is cumulative from January 1 of the relevant year. Once the transfer reaches the higher threshold, security assessment rather than the lighter route becomes the expected path.

The question many foreign groups miss is that these thresholds are calculated at the data-processor level for outbound provision, not by reference to one project memo prepared at headquarters. A company may have separate HR, customer-support, procurement, and compliance-reporting transfers that look small individually but become material when aggregated. That is why legal teams should ask for a single cross-border transfer register, not four disconnected spreadsheets.

What does not automatically require a security assessment

After the 2024 rules, a number of common cross-border business flows no longer force a security assessment or even another outbound-transfer procedure, provided the company can evidence why the exemption applies.

Examples that often fall outside the security-assessment route include:

  • ordinary international trade, cross-border transport, marketing, or multinational manufacturing data that does not include personal information or important data;
  • personal information transferred because it is necessary to conclude or perform a contract with the individual, such as cross-border booking, remittance, payment, account opening, shipping, visa, or exam-related services;
  • employee personal information that must be transferred for cross-border HR management under lawful labor rules or collective arrangements;
  • emergency transfers necessary to protect life, health, or property; and
  • for non-CIIO companies, outbound transfers of fewer than 100,000 individuals’ personal information in the current year, excluding sensitive personal information, if no other trigger applies.

These exemptions are useful, but they are not a blank check. Foreign companies still need to show why the transfer is genuinely necessary, how the data set was limited, and why the exemption applies to the actual workflow rather than to a sanitized description prepared after the fact. If the transfer includes mixed datasets, internal email archives, product telemetry, chat exports, audit logs, or source documents from several business functions, the “exempt” label often collapses on closer review.

Checklist before choosing the filing route

Before deciding that a security assessment is or is not required, foreign companies should assemble the following internal materials:

  • a system-by-system map showing what leaves China, where it goes, and who can access it abroad;
  • a business-purpose memo for each transfer, written by the actual business owner rather than copied from a global privacy template;
  • a dataset inventory separating personal information, sensitive personal information, possible important data, and non-personal operational data;
  • headcount or subject-count methodology showing how personal-information volumes are calculated from January 1 of the current year;
  • draft intra-group or vendor arrangements describing overseas recipient obligations, onward transfer limits, retention, and incident response;
  • evidence supporting any claimed exemption, especially HR-management documents, customer-contract necessity explanations, or emergency rationale; and
  • an escalation note for any regulated industry or pilot-zone negative-list issue.

As of June 27, 2025, the CAC also published the third edition of the filing guide for data export security assessment and stated that the filing materials had been streamlined and that online filing is available through the official declaration system. That is helpful operationally, but it does not change the core threshold analysis. Filing efficiency is not a substitute for getting the classification right.

Common mistakes foreign companies keep making

  • Treating all outbound access as one issue. HR reporting, customer support, cybersecurity monitoring, and global ERP access often need separate legal analysis.
  • Ignoring important-data risk because no one internally owns it. The absence of an internal label does not prove the dataset is not important data.
  • Counting transfers by file, not by individual. The current thresholds focus on people, with annual cumulative counting.
  • Using the HR exemption too loosely. Global HR visibility does not automatically justify moving broad employee files, investigations, or health-related records overseas.
  • Assuming a standard contract is always the middle path. If important data or the higher thresholds are involved, the company may need a security assessment instead.
  • Letting IT architecture define the legal position. Mirroring all China data into a regional lake before legal review creates the wrong facts first and the compliance memo second.

Talk to a China Business Lawyer before the data map goes stale

For foreign companies, the most expensive mistake is not always a failed filing. It is running a transfer architecture for months on the assumption that the transfer was exempt, only to discover later that the data set contained sensitive personal information, was counted incorrectly, or touched a regulated category that should have been escalated. At that stage, remediation is more disruptive because the systems, vendors, and headquarters reporting lines are already built around the outbound flow.

The safer approach is to review the transfer map before the next system rollout, acquisition integration, regional reporting redesign, or shared-service migration. If your China business needs to move HR, customer, procurement, compliance, or operational data overseas, talk to a China business lawyer before choosing the filing route.


This article is general information, not legal advice. For advice on your situation, please get in touch.

About the author: Jianxing Pan is a lawyer and partner at Beijing Chang’an Law Firm. His practice focuses on dispute resolution, corporate matters, cross-border compliance, intellectual property, and related risk management for companies doing business in China.

Jianxing Pan, Attorney · Beijing Chang’an Law Firm
Focus areas: Cross-Border Compliance · Corporate Law · Dispute Resolution · Intellectual Property
June 2026

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *