China’s Data-Outbound Negative List Goes Live: 2026 Milestones and a Compliance Route Map
- In August 2026 the data-outbound negative list regime moved from design to delivery: Beijing recorded China’s first banking-sector case (NH Bank’s Beijing branch), Guangdong’s FTZ list produced its first filed case in Hengqin, and Shanghai’s Lingang zone showcased the “data processing for inbound clients” model in the People’s Daily.
2026 年 8 月,数据出境负面清单制度从设计走向落地:北京落地全国首个银行业案例(韩国农协银行北京分行),广东自贸区清单在横琴产生首单备案,上海临港以《人民日报》报道展示”来数加工”模式。
- Under the negative-list mechanism, data that falls outside the list can exit the country without security-assessment applications, standard-contract filings or protection certification — the single biggest compliance-cost reduction in China’s cross-border data regime to date.
负面清单机制下,清单外数据出境免予申报数据出境安全评估、订立个人信息出境标准合同、通过个人信息保护认证——这是中国跨境数据制度迄今最大的一次合规成本削减。
- Beijing’s “1+9” design (one set of management measures plus nine sectoral lists) now covers 67 business scenarios and 612 data fields, adding medical devices, autonomous driving, trade logistics and banking to the original five sectors.
北京”1+9″制度设计(1 套管理办法 + 9 个领域清单)已覆盖 67 个业务场景、612 个数据字段,在原有 5 个领域基础上新增医疗器械、自动驾驶(智能网联汽车)、贸易物流、银行业 4 大领域。
- The national “Action Plan for Promoting High-Quality Development of Cybersecurity and Informatisation Enterprises (2026-2030)” issued by the CAC on 21 August 2026 pledges efficient implementation of security assessments, standard contracts and certification, and supports FTZs in issuing negative lists.
中央网信办 2026 年 8 月 21 日印发《促进网信企业高质量发展行动计划(2026—2030 年)》,承诺高效实施数据出境安全评估、标准合同、保护认证等制度,并支持自贸试验区制定发布数据出境负面清单。
- For foreign companies, the practical takeaway is a route map: check whether the business scenario and data fields are covered by a filed negative list in the FTZ where the entity operates; if covered, use the simplified path; if not, fall back to security assessment, standard contract or certification.
对外资企业的实操启示是一张路径图:核对经营所在自贸试验区已备案的负面清单是否覆盖本企业业务场景和数据字段;覆盖则走简化通道,未覆盖则回归安全评估、标准合同或认证路径。
China’s Data-Outbound Negative List Goes Live: 2026 Milestones and a Compliance Route Map | 数据出境负面清单落地:2026 年里程碑与合规路径图
Overview
For multinational companies operating in China, the most consequential regulatory development of mid-2026 is not a single law but the operationalisation of a mechanism: the data-outbound negative list for pilot free-trade zones. Conceived under the Provisions on Promoting and Regulating Cross-Border Data Flows, the negative-list mechanism allows each pilot FTZ to define, within the national data classification and grading framework, the categories of data that are exempt from the standard outbound-control procedures. Data outside the list exits freely; data on the list (or outside any list) continues to require security assessment, standard contracts or certification.
August 2026 turned the mechanism from paper into practice. On 6 August, Beijing’s cyberspace administration announced that NH Bank’s Beijing branch had become China’s first banking institution to complete compliant data outbound via the negative-list route — the first case in the financial sector. On 14 August, the media reported that Hengqin had completed the first negative-list filing case in Guangdong’s FTZ regime, with Macau International Airport’s cargo-terminal project as the filing subject. And on 20 August, the People’s Daily featured Shanghai’s Lingang New Area as the model for “data processing for inbound clients,” where foreign data is processed in a sealed offshore environment and transmitted back without crossing into the domestic network. Together with the CAC’s 21 August national action plan for cybersecurity and informatisation enterprises, these milestones define the 2026 compliance environment.
How the negative list works
The mechanism is simple in concept and powerful in effect. A pilot FTZ drafts a negative list for data outbound, obtains approval from the provincial cyberspace affairs commission, and files it with the national cyberspace administration and the National Data Administration. Once filed, data that falls outside the list is exempt from the security-assessment application, the standard-contract filing and the protection certification. Because of the “one place drafts, multiple places use” principle, other FTZs can reference an already-filed list for the same sectors rather than drafting from scratch — which is why Guangdong could quickly apply sectoral lists first developed elsewhere.
The system’s design philosophy was captured in a metaphor used by Hengqin’s authorities: if all data is a sheet of paper and the nationally controlled data is a circle drawn on it, the negative list defines the ring between the inner circle and the outer boundary — data in the ring moves more freely, while data in the inner circle still takes the compliance path. This dramatically reduces the “compliance anxiety” that previously led companies to over-block data transfers.
The 2026 milestones in detail
Beijing’s “1+9” design is currently the most comprehensive. Announced in May 2026 and built on the “two zones” (FTZ plus national comprehensive demonstration zone for opening the services sector), it covers the entire city, adding medical devices, autonomous driving (intelligent connected vehicles), trade logistics and banking to the original five sectors, and extending to 67 business scenarios and 612 data fields. The banking case followed earlier firsts: the first AI-sector negative-list case, and pharmaceutical/medical-device benchmarks including Sanofi, MSD and Cochlear, all facilitated through the Beijing Cross-Border Data Service Centre’s CBD workstation.
Guangdong’s list, filed with the CAC and the National Data Administration in May 2026, focuses on intelligent equipment manufacturing and personal-credit information services; Hengqin’s implementation rules introduced a “use first, report later” fast path, and the Macau International Airport cargo-terminal case validated the route. Shanghai went further in April 2026 by extending its negative-list coverage from the FTZ to the whole city and iterating the list content; the Lingang model combines the list with dedicated cross-border data lines, offshore data processing and public computing infrastructure, with Shanghai accounting for about 40% of the national total of completed security assessments.
Compliance route map for foreign companies
The negative list does not repeal the PIPL or the Data Security Law; it creates a faster lane inside the existing framework. The route map for a foreign-invested enterprise is:
- Determine whether the entity is within the pilot scope. The mechanism applies to entities in pilot FTZs (and, in Beijing and Shanghai, citywide extensions). Confirm the applicable version of the list for the entity’s registered location.
- Map the business scenario and data fields. Identify the outbound data scenarios (e.g., HR data of overseas-returned employees, R&D data, customer or device data) and the specific fields, and compare them with the filed list’s covered scenarios and fields.
- Choose the lane. If the scenario and fields fall outside the list (and the data is not in the nationally controlled categories), use the simplified outbound path without security assessment, standard contract or certification. If they fall on the list or are outside any list, proceed with security assessment, standard contract or certification as applicable.
- Keep the records. Even in the simplified lane, companies should document the basis for exclusion from the list and maintain the data-classification and grading records that regulators may review, particularly in sectors like banking where the CAC and the regulator have set industry-specific expectations.
- Monitor list updates. Lists are being iterated; the CAC’s 2026-2030 action plan supports FTZs in developing scenario-based, field-level lists and encourages the establishment of cross-border data service centres. Companies should track updates to the list applicable to their FTZ and re-screen their data scenarios periodically.
Related reading
- The Provisions on Promoting and Regulating Cross-Border Data Flows, which establish the negative-list mechanism.
- The PIPL and the Data Security Law, which set the underlying obligations that the negative list relaxes only within defined scope.
- The CAC’s “Action Plan for Promoting High-Quality Development of Cybersecurity and Informatisation Enterprises (2026-2030)”, which commits to efficient implementation and further list expansion.
Sources
- 中央网络安全和信息化委员会办公室《促进网信企业高质量发展行动计划(2026—2030 年)》: https://www.cac.gov.cn/2026-08/21/c_1789061449039952.htm
- 福建省商务厅《我国首个银行业数据出境负面清单备案落地北京》: https://swt.fujian.gov.cn/xxgk/jgzn/jgcs/zmsyqzcyjs/zmzcc_gzdt/202608/t20260813_7199304.htm
- 首都文明网(朝阳报)《全国首个银行业数据出境负面清单备案落地北京 CBD》: https://www.bjwmb.gov.cn/wmdt/cyq/10133261.html
- 中国网《我国首个银行业数据出境负面清单备案落地北京》: https://big5.china.com.cn/gate/big5/zw.china.com.cn/2026-08/07/content_118637480.shtml
- 南方日报(今日头条转载)《横琴数据出境 有了高速公路》: https://www.toutiao.com/article/7673675667824853567
数据出境负面清单落地:2026 年里程碑与合规路径图
概述
对于在华经营的跨国公司,2026 年年中最重要的监管动态不是某一部法律,而是一个机制的落地运行:自贸试验区数据出境负面清单。负面清单机制依据《促进和规范数据跨境流动规定》而设,允许各试点自贸区在国家数据分类分级保护制度框架内,界定免于常规出境管控程序的数据类别。清单外数据自由出境;清单内(或任何清单之外)的数据继续适用安全评估、标准合同或认证。
2026 年 8 月,该机制从纸面走向实践。8 月 6 日,北京市网信办宣布韩国农协银行北京分行成为我国首家通过负面清单实现数据合规出境的银行业机构——这是金融领域的首例。8 月 14 日,媒体报道横琴完成广东自贸区体制下首单负面清单备案案例,申报主体为澳门国际机场前置货站项目。8 月 20 日,《人民日报》专题报道上海临港新片区”来数加工”模式:外国数据在隔离的离岸环境中加工后直接出海,不进入境内网络。加上中央网信办 8 月 21 日发布的网信企业高质量发展行动计划,这些里程碑共同定义了 2026 年的合规环境。
负面清单如何运作
这一机制概念简单、效果显著。试点自贸区起草数据出境负面清单,经省级网信委批准,报国家网信部门、国家数据管理部门备案后实施。清单外数据出境免予申报安全评估、订立标准合同、通过保护认证。由于”一地制定、多地适用”原则,其他自贸区对同一领域可直接参照已备案清单,无需从零起草——这正是广东能够快速套用外地先行制定的行业清单的原因。
该制度的设计哲学可以用横琴方面的一个比喻来概括:假设所有数据是一张白纸,国家管控的数据是纸上画的一个圆,负面清单界定的就是内圆与外边界之间的圆环——环内数据出境更加便捷,而内圆数据仍走合规路径。这大幅缓解了过去企业因边界模糊而”过度设卡”的合规焦虑。
2026 年里程碑详解
北京”1+9″设计目前最为全面。该清单于 2026 年 5 月发布,依托”两区”(自贸试验区 + 国家服务业扩大开放综合示范区)政策叠加,实现全市域覆盖,在原有 5 个领域基础上新增医疗器械、自动驾驶(智能网联汽车)、贸易物流、银行业 4 大领域,覆盖至 67 个业务场景、612 个数据字段。银行业案例紧随此前多个”首单”而来:全国首个人工智能领域负面清单案例,以及赛诺菲、默沙东、澳科利耳等医药医疗器械标杆项目,均通过北京数据跨境服务中心商务中心区服务站落地。
广东清单于 2026 年 5 月报国家网信办、国家数据局审核备案,聚焦智能装备制造业和个人征信服务业两大领域;横琴落地管理细则并推出”先用后报”便捷路径,澳门国际机场货站案例验证了该通道。上海走得更远,2026 年 4 月把负面清单覆盖范围从自贸区扩展至全市并迭代清单内容;临港模式把清单与跨境数据专线、离岸数据加工、公共算力平台结合,上海累计完成的数据出境安全评估数量约占全国总量的四成。
外资企业合规路径图
负面清单并未废止《个人信息保护法》或《数据安全法》;它是在既有框架内开辟一条更快车道。外资企业的路径图如下:
- 确认是否属于试点范围。机制适用于试点自贸区内的主体(北京、上海已扩展至全市)。按主体注册地确认适用清单版本。
- 梳理业务场景与数据字段。识别出境数据场景(如外籍员工 HR 数据、研发数据、客户或设备数据)和具体字段,与已备案清单覆盖的场景和字段比对。
- 选择通道。场景和字段在清单之外(且不属于国家管控类别的),走简化出境路径,免于安全评估、标准合同、认证;在清单之上或任何清单之外,则分别适用安全评估、标准合同或认证。
- 留存记录。即使在简化通道内,企业也应留存在清单外的排除依据,并维护数据分类分级记录以备监管核查,特别是在银行业等监管机构已设定行业预期的领域。
- 跟踪清单更新。清单持续迭代;中央网信办 2026—2030 年行动计划支持自贸区制定场景化、字段级清单,并鼓励设立数据跨境服务中心。企业应跟踪本自贸区适用清单的更新,并定期重新筛查数据场景。
相关阅读
- 《促进和规范数据跨境流动规定》,负面清单机制的源头。
- 《个人信息保护法》与《数据安全法》,设定负面清单仅在限定范围内放松的底层义务。
- 中央网信办《促进网信企业高质量发展行动计划(2026—2030 年)》,承诺高效实施与进一步扩围。
来源
- 中央网络安全和信息化委员会办公室《促进网信企业高质量发展行动计划(2026—2030 年)》:https://www.cac.gov.cn/2026-08/21/c_1789061449039952.htm
- 福建省商务厅《我国首个银行业数据出境负面清单备案落地北京》:https://swt.fujian.gov.cn/xxgk/jgzn/jgcs/zmsyqzcyjs/zmzcc_gzdt/202608/t20260813_7199304.htm
- 首都文明网(朝阳报)《全国首个银行业数据出境负面清单备案落地北京 CBD》:https://www.bjwmb.gov.cn/wmdt/cyq/10133261.html
- 中国网《我国首个银行业数据出境负面清单备案落地北京》:https://big5.china.com.cn/gate/big5/zw.china.com.cn/2026-08/07/content_118637480.shtml
- 南方日报(今日头条转载)《横琴数据出境 有了高速公路》:https://www.toutiao.com/article/7673675667824853567