Loading…
Loading…
China's cross-border data transfer (CBDT) regime, as of the March 2024 Provisions, operates under three legal instruments: (1) the Cybersecurity Law (CSL, 2017), which establishes baseline data-security obligations for all network operators; (2) the Data Security Law (DSL, 2021), which introduces a national-security-anchored classification framework for "important data"; and (3) the Personal Information Protection Law (PIPL, 2021), which governs outbound transfers of personal information. The March 2024 Provisions do not replace these laws; they refine how the three regulatory pathways mandated by Article 38 of the PIPL (CAC security assessment, SCC, or certification) are triggered, and carve out broad categorical exemptions from all three.
Previous baseline (2022 rules): The Measures for Security Assessment of Outbound Data Transfer (effective 1 September 2022) and the Measures for Standard Contract for Outbound Transfer of Personal Information (effective 1 June 2023) established the prior framework. Under those rules, any outbound transfer of personal information by a non-CIIO data processor triggered mandatory SCC filing. The new Provisions raise the threshold to 100,000 cumulative personal-information records (or 10,000 sensitive records) before SCC or CAC security assessment is required, removing the compliance burden for smaller data flows entirely.
Revised threshold structure (non-CIIO data processors):
| Volume transferred (cumulative/year) | Required mechanism |
|---|---|
| < 100,000 PI records AND < 10,000 sensitive PI records | Exempt (no mechanism required) |
| 100,000 – 999,999 PI records OR 10,000 – 999,999 sensitive PI records | SCC or certification |
| ≥ 1,000,000 PI records OR any important data | CAC security assessment |
CIIOs remain subject to CAC security assessment for any outbound transfer of personal information or important data, regardless of volume.
FTZ pilot mechanism: The Provisions empower the central government (via State Council approval) to authorise designated FTZs to issue local negative lists. Any data categories not enumerated on a zone's negative list are treated as freely transferable within that zone. This creates a two-speed compliance environment: FTZ-domiciled enterprises face lighter requirements, incentivising MNC data-processing consolidation within designated zones.
intra-group transfers (below 100K threshold) significantly reduce compliance cost for most operational data flows. MNCs with Chinese operations can restructure shared-services and back-office arrangements without triggering CAC security assessment.
cloud providers (AWS, Azure, Google) and content-delivery networks routing non-Chinese customer data through Chinese infrastructure nodes.
involving personal data (below threshold) benefit from the contract-performance exemption; large retail banks with >1M customer records must still seek CAC assessment.
and non-FTZ locations; Shanghai Lingang (already designated as a PIPL pilot) is the most advanced zone. Expect incremental FDI into FTZ data-processing facilities.
most industries (only finance, automotive, and genomics have sector-specific definitions). Until sectoral catalogues are promulgated, non-CIIO processors retain uncertainty about whether specific data sets qualify as important data triggering mandatory CAC assessment.
Information Technology (MIIT) and sector regulators (CBIRC, CSRC, NHSA) have not issued final definitions for most industries.
be extended to additional FTZs — remains to be seen.
compliance-reduction rationale proves insufficient to attract MNC investment.