China’s data-export certification route: the CAC’s September 2026 Q&A gives multinationals the operational yardstick

  • On 11 September 2026 the Cyberspace Administration of China (CAC) published the “Data Export Security Management Policy and Regulation Q&A (September 2026)”, its first operational interpretation of the Personal Information Exit Certification route since the certification measures took effect.
    2026年9月11日,国家网信办公布《数据出境安全管理政策法规问答(2026年9月)》,这是《个人信息出境认证办法》施行以来监管层给出的第一份操作口径。
  • The certification route is available to non-critical information infrastructure operators that, from 1 January of the current year, export cumulative personal information of 100,000 or more but fewer than 1 million individuals (excluding sensitive personal information), or fewer than 10,000 individuals’ sensitive personal information, and that do not involve important data.
    认证路径适用于非关键信息基础设施运营者:自当年1月1日起累计向境外提供10万人以上、不满100万人个人信息(不含敏感个人信息),或者不满1万人敏感个人信息,且不涉及重要数据。
  • The CAC drew a clear red line: data handlers must not use quantity-splitting or similar tactics to route personal information that should undergo security assessment through the certification route instead — volumes are counted per natural person and cumulatively from 1 January each year.
    网信办划出明确红线:不得采取数量拆分等手段,将依法应当通过数据出境安全评估的个人信息伪装成认证方式出境——数量按自然人计、自当年1月1日起累计计算。
  • Once cumulative exports reach 1 million or more individuals (non-sensitive) or 10,000 or more (sensitive), the handler must declare data export security assessment through the provincial cyberspace administration; the assessment process can take the prior certification outcome into account as supporting material.
    一旦累计出境达到100万人以上(非敏感)或1万人以上(敏感个人信息),处理者应当通过所在地省级网信部门申报数据出境安全评估;申报时可将此前通过认证的情况附后,评估过程中予以参考。
  • Certification is open to handlers of any scale on a voluntary basis: any handler with cross-border personal information flows may apply to a CAC-registered professional body to demonstrate compliance with GB/T 35273 and GB/T 46068, independent of the mandatory thresholds.
    认证对任何规模的处理者均自愿开放:只要存在个人信息出境行为,不论规模大小,均可向已备案的专业认证机构申请认证,证明符合GB/T 35273《个人信息安全规范》与GB/T 46068《个人信息跨境处理活动安全认证要求》。
  • Before applying, handlers must complete the underlying legal obligations: inform individuals, obtain separate consent where required, and conduct a personal information protection impact assessment (PIPIA) — certification certifies, it does not replace, these duties.
    申请认证前必须履行基础义务:依法告知个人、取得单独同意(如需)、完成个人信息保护影响评估——认证是对合规水平的证明,不能替代这些义务本身。

China’s data-export certification route: the CAC’s September 2026 Q&A gives multinationals the operational yardstick | 数据出境认证路径的官方量尺:网信办2026年9月问答给出可执行口径

Overview

On 11 September 2026, the Cyberspace Administration of China (国家互联网信息办公室) published the Data Export Security Management Policy and Regulation Q&A (September 2026) (《数据出境安全管理政策法规问答(2026年9月)》). The document answers three representative questions, all of them about the personal information exit certification route (个人信息出境认证) — the mechanism created by the *Personal Information Exit Certification Measures* jointly issued by the CAC and the State Administration for Market Regulation (Order No. 20), in force since 1 January 2026.

For multinational groups running intra-group HR data, customer data and after-sales data flows out of China, the Q&A is the first authoritative statement of how certification interacts with the two other compliance routes — standard contracts and security assessment — and where the boundaries sit.

The three conditions for the certification route

The CAC confirms that certification as a compliance route (as distinct from voluntary certification) requires all three of the following:

  • The handler is not a critical information infrastructure operator (CIIO);
  • From 1 January of the current year, cumulative exports cover 100,000 or more but fewer than 1 million individuals’ personal information (excluding sensitive personal information), or fewer than 10,000 individuals’ sensitive personal information;
  • The exports do not involve important data.

The practical significance is the bandwidth comparison: the standard-contract route caps sensitive information at fewer than 10,000 individuals, while the certification route carries the same sensitive-information ceiling but allows non-sensitive personal information of up to 999,999 individuals. For cross-border businesses whose volumes sit in the middle band — regional HR platforms, loyalty programmes, shared service centres — certification can carry materially larger flows than standard contracts.

The anti-splitting red line

The Q&A states expressly that handlers must not adopt quantity-splitting or similar means to route personal information that should undergo security assessment through certification instead. The counting algorithm leaves little room: quantities are counted per natural person and accumulate from 1 January each year, so splitting by month, by business line or by receiving entity does not reset the denominator.

This targets a practice that has emerged since the certification measures took effect — structuring transfers so that each individual flow sits below the assessment threshold. The CAC’s message is that the thresholds are cumulative and substance-based, and that split flows will be re-aggregated when regulators review.

What happens when volumes grow

For handlers that certified first and then grew past the assessment threshold — 1 million or more individuals (non-sensitive) or 10,000 or more (sensitive) — the Q&A confirms the obligation to declare data export security assessment through the provincial cyberspace administration. The declaration can attach the prior certification materials, describing the handler’s and the overseas recipient’s protection level and the safeguards for individuals’ rights; the cyberspace authorities will take the certification into account during the assessment. Certification therefore functions as a compliance credit even when a handler outgrows the route.

Voluntary certification for any scale

Independent of the mandatory route, the Q&A reiterates that any handler with cross-border personal information flows may apply for certification voluntarily, regardless of volume. The certification body assesses conformity with GB/T 35273 (Information security technology — Personal information security specification) and GB/T 46068 (Data security technology — Security certification requirements for cross-border processing of personal information). Handlers may apply to any professional certification body registered with the authorities; the CAC’s Q&A lists contact details including the China Cybersecurity Review, Certification and Market Regulation Big Data Centre (中国网络安全审查认证和市场监管大数据中心).

For multinational groups, the commercial value of the certificate extends beyond Chinese law: overseas headquarters conducting data due diligence, and customers conducting supplier audits, can rely on a state-level certification in place of a stack of self-assessment documents.

The duties that sit underneath

Certification does not displace the underlying obligations under the Personal Information Protection Law. Before applying, a handler must have completed:

  • Notification of individuals regarding the cross-border processing;
  • Separate consent where the processing scenario requires it;
  • A personal information protection impact assessment (PIPIA).

The certification body examines whether these duties were performed; a certificate issued over an incomplete foundation would not survive regulatory scrutiny.

What this means for foreign-invested groups

  • Run the threshold arithmetic now. Count cumulative per-person export volumes from 1 January 2026 across all routes and entities; the result determines which route each flow must use for the rest of the year.
  • Do not split to stay under thresholds. The CAC has named quantity-splitting as a violation target; re-aggregation on review is the realistic downside, with the assessment route mandatory once volumes are re-counted.
  • Mid-band flows should price the certification route. For flows between 100,000 and 1 million individuals (non-sensitive), certification offers more bandwidth than standard contracts and lighter procedure than assessment.
  • Keep PIPIA and consent records certification-ready. The application package presumes they exist and are current.
  • Watch the assessment reference mechanism. Groups that certified early and later crossed the threshold can present certification as evidence of protection level, potentially smoothing the assessment.

Sources

  • 国家互联网信息办公室 — 数据出境安全管理政策法规问答(2026年9月)(2026年9月11日发布,认证适用情形、数量拆分红线、评估衔接口径): https://www.cac.gov.cn/2026-09/11/c_1790876549989064.htm
  • 国家互联网信息办公室 — 中央网信办(国家互联网信息办公室)官方网站(数据出境安全管理政策发布与法规库入口): https://www.cac.gov.cn/
  • 天津长安网 — 《减负不减责 守牢个人信息保护底线》(小型个人信息处理者简化措施规定与数据出境豁免口径解读,政府官方站点): https://tjcaw.gov.cn/mainindex/detail.html?id=18030870619192321

Related reading

  • see also: the data export negative list for free trade zones (data-exit-negative-list)
  • see also: PIPL compliance basics for foreign-invested enterprises (pipl-compliance-basics)

数据出境认证路径的官方量尺:网信办2026年9月问答给出可执行口径

概述

2026年9月11日,国家互联网信息办公室发布《数据出境安全管理政策法规问答(2026年9月)》。文件答复了三个代表性问题,全部指向个人信息出境认证路径——即国家网信办与市场监管总局以第20号令联合发布、自2026年1月1日起施行的《个人信息出境认证办法》所确立的机制。

对跨国集团而言,集团内部人力资源数据、客户数据与售后数据的出境流动是常态。这份问答首次以监管口径明确了认证路径与另外两条合规路径(标准合同、安全评估)之间的衔接关系和边界。

认证路径的三个适用条件

网信办确认,作为合规路径的认证(区别于自愿认证)须同时满足三项条件:

  • 处理者不是关键信息基础设施运营者
  • 自当年1月1日起,累计向境外提供的个人信息为10万人以上、不满100万人(不含敏感个人信息),或者不满1万人的敏感个人信息
  • 出境活动不涉及重要数据

其实务意义在于带宽对比:标准合同路径的敏感个人信息上限是不满1万人,认证路径的敏感信息上限相同,但非敏感个人信息可以承载至99.9万人。对跨境业务规模处于中间地带的企业——区域性人力资源平台、会员体系、共享服务中心——认证路径比标准合同能承载更大的出境量。

反拆分红线

问答明确:处理者不得采取数量拆分等手段,将依法应当通过数据出境安全评估的个人信息通过认证方式向境外提供。计算口径留下的操作空间很小:数量按自然人计、自当年1月1日起累计,按月度、按业务线、按接收方拆分数额都无法重置分母。

这一条针对的是认证办法施行后已经出现的规避动作——把每一笔出境都安排在评估阈值之下。监管的信号是:阈值按累计和实质计算,拆分的流量在核查时会被重新归集。

规模增长后怎么办

对于先认证、后越过评估阈值的处理者——累计达到100万人以上(非敏感)或1万人以上(敏感个人信息)——问答确认应当通过所在地省级网信部门申报数据出境安全评估。申报时可以将此前通过认证的情况附后,说明处理者与境外接收方的个人信息保护水平、个人权益保障等情况;网信部门将在评估过程中予以参考。认证因此即使在被”长出”阈值之后,仍然是一份合规信用记录。

任何规模均可自愿认证

独立于强制路径之外,问答重申:只要存在个人信息出境行为,不论规模大小,任何处理者都可以自愿申请认证。认证机构依据GB/T 35273《信息安全技术 个人信息安全规范》GB/T 46068《数据安全技术 个人信息跨境处理活动安全认证要求》开展合格评定。处理者可以向任何一家已通过备案的专业认证机构提出申请;问答列明了咨询渠道,包括中国网络安全审查认证和市场监管大数据中心。

对跨国集团而言,这张证书的商业价值不限于中国法域:境外总部做数据尽职调查、客户做供应商审计时,一份国家层面的认证证书比一叠自评材料更有说服力。

认证之下的基础义务

认证不能替代个人信息保护法规定的基础义务。申请之前,处理者应当已经完成:

  • 就跨境处理活动告知个人;
  • 按场景要求取得单独同意
  • 完成个人信息保护影响评估(PIPIA)

认证机构会核查这些义务是否履行;基础不完整的申请难以通过评定,即便侥幸获证也经不起后续监管检查。

对外资集团的启示

  • 现在就做阈值测算。 按2026年1月1日起累计的自然人数量,分主体、分路径统计出境规模;测算结果决定年内每一条出境流适用的合规路径。
  • 不要拆分规避阈值。 网信办已点名数量拆分为违规对象;现实的风险是核查时被重新归集,并强制转入评估路径。
  • 中间规模流量应给认证路径定价。 10万至100万人(非敏感)区间的流量,认证比标准合同带宽更大、比安全评估程序更轻。
  • 让PIPIA与同意记录保持”认证就绪”。 申请材料默认这些文件已存在且现行有效。
  • 关注评估参考机制。 先认证后越过阈值的企业,可以将认证作为保护水平的证明材料,可能让评估过程更顺畅。

来源

  • 国家互联网信息办公室 — 数据出境安全管理政策法规问答(2026年9月)(2026年9月11日发布): https://www.cac.gov.cn/2026-09/11/c_1790876549989064.htm
  • 国家互联网信息办公室 — 中央网信办(国家互联网信息办公室)官方网站: https://www.cac.gov.cn/
  • 天津长安网 — 《减负不减责 守牢个人信息保护底线》(官方解读文章): https://tjcaw.gov.cn/mainindex/detail.html?id=18030870619192321

相关阅读

  • 见:自贸区数据出境负面清单实务(data-exit-negative-list)
  • 见:外资企业个人信息保护法合规基础(pipl-compliance-basics)