- Under PIPL (in force 1 Nov 2021), personal information may leave China only through one of three mechanisms: a CAC security assessment, a standard contract (SCC), or certification.
依《个人信息保护法》(2021 年 11 月 1 日施行),个人信息出境仅可经三种机制之一:安全评估、标准合同或认证。- The applicable route is driven mainly by who is exporting and the cumulative volume counted from 1 January of the current year.
所适用的路径主要取决于出境方身份,以及自当年 1 月 1 日起累计的数量。- A CIIO exporting any PI, or a non-CIIO above 1 million non-sensitive PI / 10,000 sensitive PI / important data, must undergo the CAC security assessment.
CIIO 出境任何个人信息,或非 CIIO 超过 100 万人非敏感个人信息 / 1 万人敏感个人信息 / 重要数据的,须申报安全评估。- A non-CIIO exporting 100,000–1,000,000 non-sensitive PI (or under 10,000 sensitive PI) uses the standard contract or certification.
非 CIIO 出境 10 万至不满 100 万人非敏感个人信息(或不满 1 万人敏感个人信息)的,适用标准合同或认证。- A non-CIIO providing fewer than 100,000 individuals’ non-sensitive PI in the year is exempt from all three mechanisms.
非 CIIO 当年累计提供不满 10 万人非敏感个人信息的,免予三种机制。- Regardless of route, separate consent from the individual and a Personal Information Protection Impact Assessment (PIPIA, retained ~3 years) are mandatory.
无论采用何种路径,取得个人的单独同意并完成个人信息保护影响评估(PIPIA,留存约 3 年)均为强制义务。- Exemptions exist for contract necessity, cross-border HR management, emergencies, and data outside an FTZ’s published negative list.
为订立/履行合同的必需、跨境人力资源管理、紧急情况,以及自贸区负面清单之外的数据,可获豁免。
Cross-border data transfer rules (PIPL) | 跨境数据传输规则(个保法)
Overview
For any foreign business operating in China, moving personal information (PI) out of the country — to a global HR system, a overseas parent, or a foreign cloud — triggers China’s cross-border data-transfer regime. The *Personal Information Protection Law* (PIPL, in force since 1 November 2021) makes cross-border PI provision lawful only through one of three recognised mechanisms, and the 2024 *Provisions on Promoting and Regulating Cross-border Data Flows* clarified the thresholds that decide which mechanism applies. The trend is liberalisation, but the obligations are real and the thresholds are quantitative. This article explains the three mechanisms, the volume thresholds, the exemptions, and the baseline duties (separate consent and impact assessment).
Informational guidance only; the rules are technical and evolving, so validate your specific data flows with qualified PRC data-compliance counsel.
The three lawful mechanisms
A processor that needs to provide PI outside China must use one of three routes:
- CAC security assessment (安全评估). A review by the Cyberspace Administration of China (the national network regulator, CAC) for the highest-risk transfers.
- Standard contract (标准合同, SCC). The processor concludes the official *Personal Information Export Standard Contract* (PIESC) with the overseas recipient and files it with the provincial CAC.
- Certification (认证). The transfer is covered by personal-information-protection certification issued by a qualified certification body.
The choice among them is driven primarily by who is exporting and how much PI is involved.
Thresholds that decide the route
Under the 2024 Provisions, the triggers are calculated cumulatively from 1 January of the current year:
- Security assessment is required when:
- the exporter is a Critical Information Infrastructure Operator (CIIO) exporting any PI or important data; or
- a non-CIIO exporter ships important data abroad; or
- a non-CIIO exporter, since 1 Jan, has cumulatively provided more than 1,000,000 individuals’ PI (non-sensitive) or more than 10,000 individuals’ sensitive PI.
- Standard contract or certification applies when a non-CIIO exporter, since 1 Jan, has cumulatively provided 100,000 to less than 1,000,000 individuals’ PI (non-sensitive) or fewer than 10,000 individuals’ sensitive PI.
- Below the thresholds — essentially free: a non-CIIO exporter providing fewer than 100,000 individuals’ non-sensitive PI in the year is exempt from the assessment, the standard contract, and certification.
| Exporter / volume (since 1 Jan) | Mechanism required |
|---|---|
| CIIO exporting any PI / important data | Security assessment |
| Non-CIIO, important data, or >1m non-sensitive PI, or >10k sensitive PI | Security assessment |
| Non-CIIO, 100k–1m non-sensitive PI, or <10k sensitive PI | Standard contract or certification |
| Non-CIIO, <100k non-sensitive PI | Exempt |
Exemptions
The 2024 Provisions also exempt certain transfers from the three mechanisms entirely, including transfers:
- necessary to conclude or perform a contract with the individual (e.g., cross-border shopping, remittance, payment, flight/hotel booking, visa processing, examinations);
- necessary for cross-border HR management under lawfully formulated labour rules and collective contracts;
- necessary to protect an individual’s life, health, or property in an emergency;
- and, within Free Trade Zones, transfers of data outside the zone’s published negative list (FTZs may set their own negative lists exempting specified data from the mechanisms, filed with the national CAC and data authority).
Baseline duties regardless of route
Whichever mechanism applies, PIPL imposes duties that sit underneath all of them:
- Separate consent (单独同意). Providing PI abroad generally requires the individual’s separate consent, distinct from general privacy consent.
- Personal Information Protection Impact Assessment (PIPIA). The processor must conduct a PIPIA before export and retain it (commonly for at least three years).
- Accountability documentation. Notice to individuals of the overseas recipient, purpose, type of PI, and means of contact; and the overseas recipient must meet PIPL’s protection standards.
What to do next
- Map your data flows and count, per calendar year, the individuals whose PI you export and whether any is sensitive or important data.
- Determine your exporter type (CIIO or not) — CIIO status pulls even small transfers into security assessment.
- If you are below 100k non-sensitive PI, document the exemption rather than assuming you need to file.
- For the middle band, choose the standard contract (file with provincial CAC) or certification; for the top band, prepare a CAC security assessment.
- Always obtain separate consent and complete a PIPIA before any export; keep records.
- If operating in a Free Trade Zone, check the zone’s negative list — it may exempt data categories relevant to you.
Sources
- Cyberspace Administration of China (CAC) — Provisions on Promoting and Regulating Cross-border Data Flows (2024): https://www.cac.gov.cn/2024-03/22/c_1712776612187994.htm
- Cyberspace Administration of China (CAC) — Data Export Security Management Policy Q&A (2025): https://www.cac.gov.cn/2025-04/09/c_1745906286623776.htm
- Cyberspace Administration of China (CAC) — Expert reading on the Personal Information Export Certification scheme (2025): https://www.cac.gov.cn/2025-10/17/c_1762425522602315.htm
- State Council (gov.cn) — Personal Information Protection Law enacted (2021): https://www.gov.cn/xinwen/2021-08/20/content_5632486.htm
Related reading
- see also: Copyright & trade secrets for foreign firms / 著作权与商业秘密
- see also: Hiring local staff: contracts & social insurance / 雇佣本地员工:合同与社保
跨境数据传输规则(个保法)
概述
对任何在华经营的外国企业而言,将个人信息(PI)传出中国——传到全球 HR 系统、境外母公司或外国云——都会触发中国的跨境数据传输制度。《个人信息保护法》(PIPL,2021 年 11 月 1 日施行)规定,个人信息出境仅可经三种认可机制之一合法进行;2024 年《促进和规范数据跨境流动规定》进一步明确了决定采用何种机制的门槛。总体趋势是放宽,但义务真实存在,且门槛是定量的。本文说明三种机制、数量门槛、豁免情形,以及基础义务(单独同意与影响评估)。
本文仅为信息性指引;规则技术性强且不断演进,请就具体数据流咨询合格的中国数据合规律师。
三种合法机制
需要向境外提供个人信息的处理者,必须采用以下路径之一:
- 安全评估。 由国家网信部门(CAC)对最高风险传输进行的审查。
- 标准合同。 处理者与境外接收方订立官方《个人信息出境标准合同》(PIESC),并向省级网信部门备案。
- 认证。 传输由具备资质的认证机构出具的个人信息保护认证所覆盖。
三者之间的选择,主要取决于谁在出关以及涉及多少个人信息。
决定路径的数量门槛
依 2024 年规定,门槛按当年 1 月 1 日起累计计算:
- 须申报安全评估的情形:
- 出境方为关键信息基础设施运营者(CIIO),出境任何个人信息或重要数据;或
- 非 CIIO 出境重要数据;或
- 非 CIIO 自 1 月 1 日起累计向境外提供超过 100 万人非敏感个人信息或超过 1 万人敏感个人信息。
- 标准合同或认证适用的情形:非 CIIO 自 1 月 1 日起累计提供 10 万至不满 100 万人非敏感个人信息或不满 1 万人敏感个人信息。
- 低于门槛——基本自由: 非 CIIO 当年累计提供不满 10 万人非敏感个人信息的,免予安全评估、标准合同与认证。
| 出境方 / 数量(自 1 月 1 日起) | 所需机制 |
|---|---|
| CIIO 出境任何 PI / 重要数据 | 安全评估 |
| 非 CIIO、重要数据,或 >100 万非敏感 PI,或 >1 万敏感 PI | 安全评估 |
| 非 CIIO、10 万–100 万非敏感 PI,或 <1 万敏感 PI | 标准合同 或 认证 |
| 非 CIIO、<10 万非敏感 PI | 豁免 |
豁免情形
2024 年规定还将若干传输整体豁免于三种机制,包括:
- 为订立或履行个人作为一方当事人的合同所必需(如跨境购物、跨境汇款、跨境支付、机票酒店预订、签证办理、考试服务);
- 依依法制定的劳动规章制度和依法签订的集体合同实施跨境人力资源管理所必需;
- 紧急情况下为保护自然人生命健康和财产安全所必需;
- 以及,在自由贸易区内,传输该区已公布负面清单之外的数据(自贸区可自定负面清单,将指定数据豁免于三种机制,并报国家网信部门与数据主管部门备案)。
不分路径的基础义务
无论采用何种机制,PIPL 均设定了底层义务:
- 单独同意。 向境外提供个人信息一般须取得个人的单独同意,区别于一般隐私同意。
- 个人信息保护影响评估(PIPIA)。 处理者须在出境前完成 PIPIA 并留存(通常至少三年)。
- 问责文档。 向个人告知境外接收方、目的、个人信息种类与联系方式;境外接收方须达到 PIPL 的保护标准。
下一步建议
- 梳理数据流,并按自然年统计出境个人信息涉及的人数,以及是否含敏感或重要数据。
- 判定出境方类型(是否 CIIO)——CIIO 身份即便少量传输也纳入安全评估。
- 若低于 10 万非敏感 PI,应记录豁免依据,而非默认需要申报。
- 对中间区间,选择标准合同(向省级网信备案)或认证;对顶部区间,准备网信部门安全评估。
- 任何出境前均须取得单独同意并完成 PIPIA;保留记录。
- 若位于自贸区,核查该区负面清单——其可能豁免与你相关的数据类别。
来源
- 国家互联网信息办公室(CAC)——《促进和规范数据跨境流动规定》(2024):https://www.cac.gov.cn/2024-03/22/c_1712776612187994.htm
- 国家互联网信息办公室(CAC)——数据出境安全管理政策问答(2025):https://www.cac.gov.cn/2025-04/09/c_1745906286623776.htm
- 国家互联网信息办公室(CAC)——个人信息出境认证制度专家解读(2025):https://www.cac.gov.cn/2025-10/17/c_1762425522602315.htm
- 国务院办公厅(gov.cn)——《个人信息保护法》出台(2021):https://www.gov.cn/xinwen/2021-08/20/content_5632486.htm
相关阅读
- see also: 著作权与商业秘密 / Copyright & trade secrets for foreign firms
- see also: 雇佣本地员工:合同与社保 / Hiring local staff: contracts & social insurance
