China has one of the world's strictest data cross-border transfer regimes. The Data Security Law (DSL), Personal Information Protection Law (PIPL), and Cybersecurity Law (CSL) create a three-layer compliance framework. Foreign companies operating in China must understand these rules before transferring any data abroad.
Three Legal Frameworks
| Law | Scope | Key Requirement |
|---|---|---|
| Cybersecurity Law (CSL, 2017) | Network operators, CIIOs | Data localization for CIIOs; security assessment for cross-border data |
| Data Security Law (DSL, 2021) | All data activities | Classify data (normal/important/core); "important data" export requires CAC assessment |
| PIPL (2021) | Personal information | Cross-border PI transfer requires: CAC assessment, SCC, or CAC certification + separate consent |
Three Pathways for Cross-Border Data Transfer
Pathway 1: CAC Security Assessment
Required when:
- Transferring "important data" abroad
- Data processor handles PI of 1M+ individuals
- Cumulative transfer of PI of 100K+ individuals or 1GB+ sensitive PI since Jan 1 of the prior year
- CIIOs transferring any data abroad
Process: Submit to provincial CAC -> CAC reviews (20 working days) -> approval/rejection. National CAC review for complex cases.
Timeline: 45-60+ days
Pathway 2: Standard Contractual Clauses (SCC)
Available when: NOT required to do security assessment AND NOT using certification pathway.
- Sign the CAC standard contract with the overseas recipient
- Conduct a PI protection impact assessment (PIPIA)
- File the contract + PIPIA with provincial CAC
- Simpler than security assessment but still requires filing
Timeline: 15-30 days for filing
Pathway 3: CAC Certification
For: Companies that want a certification-based approach (mainly for multinationals with internal cross-border data flows).
- Obtain certification from a CAC-approved certification body
- Currently limited to specific scenarios (intra-group transfers)
- More expensive but potentially faster for ongoing transfers
What Is "Important Data"?
"Important data" is data that, if leaked or tampered with, could affect national security, economic security, or public interest. Each industry has its own important data catalogue (determined by industry regulators):
- Automotive: Vehicle data (location, biometrics, driving behavior)
- Finance: Transaction data, customer financial data
- Healthcare: Medical records, genetic data
- Tech: Large-scale user data, AI training data
- Energy: Grid data, energy production data
If your data might be "important," consult with your industry regulator or a data lawyer.
Data Localization Requirements
Certain entities must store data in China and cannot transfer it abroad without CAC assessment:
- CIIOs (Critical Information Infrastructure Operators): Telecom, energy, transport, finance, water, healthcare, government
- Large platforms (>5M users): Must conduct annual algorithm audits + data reviews
- Automotive: Vehicle-generated data must be stored in China
- Finance: PBOC/CBIRC require local storage of financial data
- Healthcare: Medical records and genetic data must be stored locally
Practical Compliance Steps for Foreign Companies
- Data mapping: Identify what data you collect, where it is stored, and whether it is transferred abroad.
- Data classification: Determine if your data is "normal," "important," or "core."
- Choose a pathway: Security assessment (for important data/large PI), SCC (for smaller PI), or certification.
- Conduct PIPIA: Personal Information Protection Impact Assessment is required for all cross-border PI transfers.
- Obtain separate consent: Users must separately consent to cross-border PI transfer (not bundled with general consent).
- File with CAC: Submit the security assessment or SCC filing to your provincial CAC.
- Implement technical safeguards: Encryption, access controls, audit logs for all cross-border transfers.
Penalties
| Violation | Penalty |
|---|---|
| Unlawful cross-border data transfer | Up to ¥5M or 5% of prior year revenue; business suspension; license revocation |
| Responsible individuals | ¥100K-1M fine; criminal liability for serious cases |
| Failure to conduct PIPIA | Up to ¥500K; corrective order |
| Failure to obtain separate consent | Up to ¥500K or 5% of revenue; corrective order |