Business, data and trade compliance review — conceptual illustration

China Data Export Compliance: Exemptions, Standard Contracts and Security Assessments

Business, data and trade compliance review — conceptual illustration
AI-generated illustration / AI生成主题示意图

Chinese articles

Legal review: 18 September 2026.

A China subsidiary’s overseas HR system, customer database or shared-service platform can raise data export questions even when the group considers the information internal. The useful starting point is a map of the actual data and overseas access: who provides it, who receives it, why it is needed, what fields are involved and how long they are retained.

The applicable route may be a security assessment, a Chinese standard contract, certification or an exemption from those mechanisms. The decision is not based only on the server location or the number of files. The framework below uses the 2024 cross-border data-flow provisions, the Network Data Security Management Regulations effective from 1 January 2025, and the certification measures effective from 1 January 2026.

1. Identify the operator and dataset

First identify whether the entity is a critical information infrastructure operator (CIIO) and whether the transfer includes important data. A company should check applicable regulator notifications and published sector or regional rules. Under Article 2 of the 2024 provisions, data not notified or publicly identified as important data by the relevant authorities or regions need not be declared for a security assessment as important data. That rule still requires the company to check the relevant classifications.

Next separate personal information from sensitive personal information and information that falls into neither category. Review the real export fields, attachments, logs and permissions. Removing names from a spreadsheet does not by itself establish that the remaining data are no longer personal information.

2. Test the exemptions against actual facts

The 2024 rules provide exemptions from the three export mechanisms for specified situations, including:

  • international trade and similar business data containing neither personal information nor important data;
  • personal information collected and generated overseas, processed in China and provided overseas without introducing domestic personal information or important data;
  • personal information genuinely necessary to conclude or perform a contract to which the individual is a party;
  • necessary cross-border employee HR management under lawfully adopted labour rules and lawfully concluded collective contracts;
  • necessary emergency transfers to protect life, health or property; and
  • qualifying non-CIIO transfers below the ordinary personal-information threshold.

Important data is excluded from the personal-information exemptions in Article 5. Free-trade-zone negative-list arrangements also have defined scope; the location of an office alone is not a complete eligibility analysis. Apply the specific exception before relying on the general threshold table.

3. Apply the annual thresholds when no relevant exemption applies

For a non-CIIO, count individuals cumulatively from 1 January of the current year. The following table assumes no important data and no applicable special exemption. If either information category reaches a higher route, the lower category does not remove that trigger.

Transfer scale Ordinary route
Fewer than 100,000 individuals’ personal information, excluding sensitive personal information; no sensitive personal information exported Exemption from security assessment, standard contract and certification
100,000 to fewer than 1 million individuals’ non-sensitive personal information, or sensitive personal information of fewer than 10,000 individuals Standard contract or certification
At least 1 million individuals’ non-sensitive personal information, or at least 10,000 individuals’ sensitive personal information Security assessment

A CIIO exporting personal information or important data, or a non-CIIO exporting important data, generally enters the security-assessment route, subject to applicable statutory exceptions. Sensitive information has no equivalent general “below 100,000” exemption. Separate departments should contribute to one processor-level export register; dividing one activity into smaller projects does not avoid a required assessment.

4. Understand what certification does

The Personal Information Export Certification Measures are already in force. Certification must follow the applicable professional certification process; a group’s internal privacy approval is not certification. The CAC’s September 2026 Q&A confirms that certification does not replace security assessment when annual exports reach the assessment threshold. Certification results may be submitted for reference in that assessment.

The same Q&A also allows voluntary certification as evidence of compliance capability beyond the mandatory certification route. This does not expand an exemption or authorise a transfer that requires a different statutory mechanism.

5. Keep the PIPL duties even when a mechanism is exempt

Review the lawful basis, necessity, notices, separate consent requirements where applicable, personal information protection impact assessment, security safeguards and overseas recipient obligations. These duties are distinct from choosing an export mechanism. A standard contract or exemption cannot cure unnecessary collection or unrestricted overseas access.

The CAC’s July 2026 Q&A illustrates the limit for recruitment: whether an overseas group company actually participates in the hiring decision affects the necessity analysis. Sending all applicants’ files abroad merely for headquarters visibility should not be treated as automatically covered by the employee HR exemption.

6. Build the review file before deployment

  1. Create a data-flow map covering systems, manual transfers, overseas recipients and onward access.
  2. Record the business purpose, individual categories, data fields, retention periods and sensitive-data classification.
  3. Document CIIO and important-data checks, the exemption analysis and annual counting method.
  4. Prepare required assessments, notices, recipient obligations and the selected mechanism’s documents.
  5. Assign an owner to monitor changes in data, recipients, purposes and volume.

Payment operations can involve employee, customer and counterparty information. The data transfer should be assessed separately from the fund transfer; the China funding and remittance route map addresses the payment side. For a coordinated review of operational contracts, data flows and banking documents, see cross-border business legal support.

Official sources

  1. CAC Order No. 16: Provisions on Facilitating and Regulating Cross-Border Data Flows (2024)
  2. State Council Order No. 790: Network Data Security Management Regulations
  3. CAC / SAMR Order No. 20: Measures for Personal Information Export Certification
  4. CAC: Data Export Policy Q&A, September 2026
  5. CAC: Data Export Policy Q&A, July 2026
  6. Personal Information Protection Law: Articles 13, 38–40 and 55–56

This article provides general legal information. The official materials cited were checked on 18 September 2026. Advice on a particular matter requires a review of the facts, applicable rules and handling authority.

Author: Jianxing Pan is a partner at Beijing Chang’an Law Firm. He began practising in 2019 and works across Beijing and Shenzhen, focusing on intellectual property, civil and commercial disputes, and corporate legal matters.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *