Compliance

China Data Cross-Border Transfer Guide 2026: DSL, PIPL & CAC Rules

📅 July 29, 2026 ⏱️ 10 min read ✅ Reviewed July 2026

China has one of the world's strictest data cross-border transfer regimes. The Data Security Law (DSL), Personal Information Protection Law (PIPL), and Cybersecurity Law (CSL) create a three-layer compliance framework. Foreign companies operating in China must understand these rules before transferring any data abroad.

Three Legal Frameworks

LawScopeKey Requirement
Cybersecurity Law (CSL, 2017)Network operators, CIIOsData localization for CIIOs; security assessment for cross-border data
Data Security Law (DSL, 2021)All data activitiesClassify data (normal/important/core); "important data" export requires CAC assessment
PIPL (2021)Personal informationCross-border PI transfer requires: CAC assessment, SCC, or CAC certification + separate consent

Three Pathways for Cross-Border Data Transfer

Pathway 1: CAC Security Assessment

Required when:

  • Transferring "important data" abroad
  • Data processor handles PI of 1M+ individuals
  • Cumulative transfer of PI of 100K+ individuals or 1GB+ sensitive PI since Jan 1 of the prior year
  • CIIOs transferring any data abroad

Process: Submit to provincial CAC -> CAC reviews (20 working days) -> approval/rejection. National CAC review for complex cases.

Timeline: 45-60+ days

Pathway 2: Standard Contractual Clauses (SCC)

Available when: NOT required to do security assessment AND NOT using certification pathway.

  • Sign the CAC standard contract with the overseas recipient
  • Conduct a PI protection impact assessment (PIPIA)
  • File the contract + PIPIA with provincial CAC
  • Simpler than security assessment but still requires filing

Timeline: 15-30 days for filing

Pathway 3: CAC Certification

For: Companies that want a certification-based approach (mainly for multinationals with internal cross-border data flows).

  • Obtain certification from a CAC-approved certification body
  • Currently limited to specific scenarios (intra-group transfers)
  • More expensive but potentially faster for ongoing transfers

What Is "Important Data"?

"Important data" is data that, if leaked or tampered with, could affect national security, economic security, or public interest. Each industry has its own important data catalogue (determined by industry regulators):

  • Automotive: Vehicle data (location, biometrics, driving behavior)
  • Finance: Transaction data, customer financial data
  • Healthcare: Medical records, genetic data
  • Tech: Large-scale user data, AI training data
  • Energy: Grid data, energy production data

If your data might be "important," consult with your industry regulator or a data lawyer.

Data Localization Requirements

Certain entities must store data in China and cannot transfer it abroad without CAC assessment:

  • CIIOs (Critical Information Infrastructure Operators): Telecom, energy, transport, finance, water, healthcare, government
  • Large platforms (>5M users): Must conduct annual algorithm audits + data reviews
  • Automotive: Vehicle-generated data must be stored in China
  • Finance: PBOC/CBIRC require local storage of financial data
  • Healthcare: Medical records and genetic data must be stored locally

Practical Compliance Steps for Foreign Companies

  1. Data mapping: Identify what data you collect, where it is stored, and whether it is transferred abroad.
  2. Data classification: Determine if your data is "normal," "important," or "core."
  3. Choose a pathway: Security assessment (for important data/large PI), SCC (for smaller PI), or certification.
  4. Conduct PIPIA: Personal Information Protection Impact Assessment is required for all cross-border PI transfers.
  5. Obtain separate consent: Users must separately consent to cross-border PI transfer (not bundled with general consent).
  6. File with CAC: Submit the security assessment or SCC filing to your provincial CAC.
  7. Implement technical safeguards: Encryption, access controls, audit logs for all cross-border transfers.
FTZ exemption: Shanghai Lingang FTZ and Beijing FTZ have pilot programs for simplified cross-border data transfer. Companies in these FTZs may use a "negative list" approach (transfer freely unless on the list) instead of case-by-case assessment.

Penalties

ViolationPenalty
Unlawful cross-border data transferUp to ¥5M or 5% of prior year revenue; business suspension; license revocation
Responsible individuals¥100K-1M fine; criminal liability for serious cases
Failure to conduct PIPIAUp to ¥500K; corrective order
Failure to obtain separate consentUp to ¥500K or 5% of revenue; corrective order

Frequently Asked Questions

What are the rules for transferring data out of China?
China's Data Security Law (DSL) and Personal Information Protection Law (PIPL) require: (1) Security assessment by CAC for "important data" or PI of 1M+ individuals, (2) Standard Contractual Clauses (SCC) for smaller PI transfers, (3) CAC certification for certain data processors. All cross-border data transfers must have a lawful basis and user consent (for PI).
What is the CAC security assessment for cross-border data?
The Cyberspace Administration of China (CAC) security assessment is required when: transferring "important data," processing PI of 1M+ individuals, or when the data processor has processed PI of 100K+ individuals cumulatively. The assessment evaluates data volume, sensitivity, recipient country, and security measures. Timeline: 45-60+ days.
What is the Standard Contractual Contract (SCC) for China data export?
The CAC Standard Contract is a template contract for cross-border PI transfer that does NOT require a security assessment. Requirements: transfer <1M individuals' PI, no "important data," sign and file the standard contract with provincial CAC. Simpler than a security assessment but still requires filing.
Do foreign companies in China need to localize data?
Yes, for certain sectors. Critical Information Infrastructure Operators (CIIO) must store personal data and important data in China. Other companies can transfer data abroad after completing CAC security assessment or SCC filing. Financial, healthcare, and automotive sectors have additional data localization requirements.
What is the penalty for violating China data export rules?
Penalties under DSL/PIPL: up to ¥5M RMB fine or 5% of prior year revenue, business suspension, revocation of business license. Individuals responsible can face ¥100K-1M fines and criminal liability. The penalties are among the strictest in the world.

Ready to take the next step?

Use our free interactive tools to check market access, estimate costs, and discover tax incentives for your China entry.

Related Guides

Stay Informed

Weekly Policy Briefing

Get a curated digest of the latest Chinese policy changes, investment insights, and regulatory updates - delivered every Monday morning.

No spam. Unsubscribe anytime.