- China’s third data-export route opened on 1 January 2026 under CAC and SAMR Order No. 20.
第20号令使个人信息保护认证成为可用通道,2026年1月1日起施行。- Eligibility is narrow: non-CIIO handlers, 100,000 to under 1m individuals’ non-sensitive data or under 10,000 individuals’ sensitive data, and no important data.
适用面窄:非CIIO主体,10万至不满100万人非敏感或不满1万人敏感个人信息,且不含重要数据。- Splitting volumes to dodge the security assessment is expressly prohibited.
明令禁止以数量拆分等手段规避应当进行的出境安全评估。- Notification, separate consent and a five-point impact assessment must be completed before applying.
申请前须完成告知、取得单独同意,并开展涵盖五项法定重点的个人信息保护影响评估。- Certificates run three years and may be suspended or revoked if exports drift outside the certified scope.
证书有效期三年;出境情况与认证范围不一致的,可被暂停直至撤销。- The route is voluntary and market-based: an extra compliance option, not a new obligation.
该路径自愿、市场化,是增加的合规选择而非新增义务。
China’s Personal Information Export Certification: The Third Route Opens on 1 January 2026 | 个人信息出境认证办法:2026年1月1日起启用的第三条数据出境通道
Three Routes Out, and What Order No. 20 Changes
Article 38(1) of the Personal Information Protection Law (PIPL) gives three lawful export routes: (1) a security assessment organised by the national cyberspace administration (CAC); (2) personal information protection certification; and (3) concluding and filing the standard contract with the overseas recipient. Route (2) long existed mainly at the level of the rule — no accredited bodies, no clear criteria — so it was almost never used. The *Measures for Personal Information Export Certification*, Order No. 20 of the CAC and the State Administration for Market Regulation (SAMR), promulgated on 14 October 2025 and effective 1 January 2026, change that. Drawing on the PIPL, the Regulations on Network Data Security Management and the Regulations on Certification and Accreditation, they supply the missing institutions, thresholds, application path, certificate and supervision cycle.
Who Qualifies: Eligibility and Volume Bands
A handler must satisfy all of the following at once:
- it is not a critical information infrastructure operator (CIIO);
- counting cumulatively from 1 January of the current year, it has provided abroad the personal information of 100,000 or more but fewer than 1,000,000 individuals, excluding sensitive personal information, or the sensitive personal information of fewer than 10,000 individuals;
- the exported personal information does not include important data.
The count resets each 1 January, so a fast-growing business can exit the band mid-year; watch the running total.
The Anti-Splitting Rule
Handlers may not use quantity-splitting or similar devices to route through certification personal information that should lawfully undergo the security assessment. Groups with several Chinese entities feeding one overseas parent should assume the aggregate flow is what counts.
Before You Apply: Consent and the Five-Point PIPIA
Before filing, the handler must have given the statutory notification, obtained separate consent, and carried out a personal information protection impact assessment (PIPIA), which must examine:
- Whether the handler’s and the recipient’s processing purposes, scope and methods are lawful, legitimate and necessary.
- The scale, scope, type and sensitivity of the exported information and the risks to national security, the public interest and individual rights.
- Whether the obligations the recipient undertakes to bear, and its management and technical measures and capabilities, can safeguard security.
- The risk of the information being altered, destroyed, leaked, lost or unlawfully used after export, and whether channels for upholding individual rights remain unobstructed.
- The effect of the personal information protection policies and laws of the recipient’s country or region on information security and individual rights.
Who Certifies, and What the Certificate Is Worth
Certification is carried out by professional certification bodies holding personal information protection certification accreditation, applying the certification basic norms and the certification rules. A certificate is valid for three years and must be reported to the National Certification and Accreditation Information Public Service Platform. Supervision continues: where exports are inconsistent with the certified scope, or the handler no longer meets the requirements, the body must suspend the certificate until revocation; where exports breach the law, it must report promptly to the CAC and other competent authorities.
Who Regulates Whom
The CAC, with the national data administration and other departments, sets the standards and technical specifications. The market regulation department, with the CAC, sets the certification rules and the unified certificate and mark. A body must file with the CAC within 10 working days of accreditation. Departments at provincial level or above may summon a certified handler whose exports present significant risk or that suffers a personal information security incident.
Certification Against the Other Two Routes
| Route | Trigger | Gatekeeping step | Validity | Users |
|---|---|---|---|---|
| Security assessment | CIIO exports, important data, or volumes above the band | CAC declaration and assessment | Per that regime | Any handler triggering it |
| Certification | Non-CIIO; 100k–<1m non-sensitive or <10k sensitive; no important data | Accredited body audit plus supervision | 3 years | Voluntary, non-CIIO |
| Standard contract | Same bands as certification | Contract signed, filed with provincial CAC | Contract term | Non-CIIO |
Tsinghua law professor Shen Weixing explains why a private audit can be a lawful basis: certification packages the required safeguards as third-party review, continuing supervision, and remedies enforceable by data subjects. Wang Zhicheng of the CAC’s Data and Technology Support Centre notes the voluntary, market-based design lightens regulators’ load and widens compliance choices; Ding Xiaodong of Renmin University’s Law School sees the Measures as completing China’s export system. (Expert views.)
The Wider 2026 Data-Flow Liberalisation
The *Action Plan for Stabilising and Optimising the Use of Foreign Investment* (Shang Zi Fa [2026] No. 97), issued by MOFCOM, the NDRC and the Ministry of Finance on 16 June 2026, supports free trade zones and services-opening pilot cities in exploring scenario-based, field-level data export negative lists, and pushes for national standards for important-data identification catalogues in industry, telecommunications, geographic information, automotive, pharmaceuticals, seed industry, aerospace and civil aviation. Beijing and Guangdong have already issued FTZ negative lists through joint three-department notices.
Practical Steps for a Foreign-Invested Enterprise
- Count first, tracking cumulative exports from 1 January and separating sensitive from non-sensitive data.
- Rule out important data and CIIO status before assuming certification is available.
- Consolidate group flows; the anti-splitting rule bites at group level.
- Fix the consent stack and run the PIPIA against the five points, especially the recipient jurisdiction’s legal regime.
- Select an accredited body, verify its CAC filing, and monitor scope drift.
Related Reading
See our PIPL cross-border transfer overview and our field-level data export negative list article.
个人信息出境认证办法:2026年1月1日起启用的第三条数据出境通道
三条出境通道与第20号令的改变
《个人信息保护法》第三十八条第一款规定三条合法出境路径:(1)国家网信部门组织的出境安全评估;(2)个人信息保护认证;(3)与境外接收方按标准合同签约并备案。第(2)项长期停留在规定层面——机构资质稀缺、细则不明,企业极少采用。《个人信息出境认证办法》由国家互联网信息办公室、国家市场监督管理总局以第20号令于2025年10月14日公布,自2026年1月1日起施行,上位法为《个人信息保护法》《网络数据安全管理条例》《认证认可条例》,补齐了机构、门槛、申请路径、证书与持续监督等缺失环节。
适用条件与数量区间
处理者须同时满足以下全部条件:
- 属于非关键信息基础设施运营者(非CIIO);
- 自当年1月1日起累计向境外提供10万人以上、不满100万人个人信息(不含敏感个人信息),或者不满1万人敏感个人信息;
- 出境个人信息不包括重要数据。
累计数每年1月1日重新起算,快速增长的电商或SaaS业务可能年中越出区间,应盯住滚动累计值。
反规避条款
处理者不得采取数量拆分等手段,将依法应当通过出境安全评估的个人信息通过认证方式出境。多家中国主体向同一境外母公司回传数据的集团,应默认监管看合并总量。
申请前:同意与五项重点影响评估
申请前,处理者必须已依法履行告知义务、取得单独同意,并开展个人信息保护影响评估(PIPIA),重点评估:
- 处理者与境外接收方处理个人信息的目的、范围、方式的合法性、正当性、必要性;
- 出境个人信息的规模、范围、种类、敏感程度,及其对国家安全、公共利益、个人信息权益的风险;
- 境外接收方承诺承担的义务及其管理和技术措施、能力能否保障安全;
- 个人信息出境后遭篡改、破坏、泄露、丢失、非法利用的风险,以及权益维护渠道是否通畅;
- 境外接收方所在国家或地区的个人信息保护政策法规对出境信息安全与个人权益的影响。
由谁认证,证书意味着什么
认证由依法取得个人信息保护认证资质的专业认证机构实施,依据认证基本规范、个人信息保护认证规则开展。证书有效期3年,机构应向全国认证认可信息公共服务平台报送证书信息。监督持续:获证处理者出境情况与认证范围不一致或不再符合认证要求的,机构应暂停其使用直至撤销证书;出境活动违反法律法规的,应及时向国家网信部门和有关部门报告。
监管架构
国家网信部门会同国家数据管理部门等制定认证相关标准、技术规范;国家市场监督管理部门会同国家网信部门制定个人信息保护认证规则、统一认证证书及标志。专业认证机构自取得资质之日起10个工作日内向国家网信部门备案。省级以上网信部门等发现获证处理者出境活动存在较大风险或发生个人信息安全事件的,可依法约谈。
三条路径对比
| 路径 | 触发阈值 | 主管环节 | 有效期 | 适用主体 |
|---|---|---|---|---|
| 出境安全评估 | CIIO出境、含重要数据或超出认证区间 | 向网信部门申报评估 | 依该制度 | 触发任一条件者 |
| 个人信息保护认证 | 非CIIO;10万至不满100万人非敏感或不满1万人敏感;不含重要数据 | 有资质机构认证并持续监督 | 3年 | 自愿的非CIIO |
| 标准合同备案 | 与认证相同区间 | 签约并向省级网信部门备案 | 合同期限 | 非CIIO |
清华大学法学院教授申卫星解释第三方审核何以构成合法依据:认证把适当保障具体化为”经第三方审核+持续监督+对数据主体可执行的承诺与救济”。国家网信办数据与技术保障中心副主任王志成指出,自愿性、市场化、社会化服务设计既减轻监管负担,也赋予企业更多合规选择权;中国人民大学法学院副院长丁晓东认为,《办法》标志我国个人信息出境制度体系已构建完成。(专家观点。)
2026年更广的数据流动松绑
商务部、国家发展改革委、财政部《利用外资固稳促优行动方案》(商资发〔2026〕97号,2026年6月16日印发)明确:支持自由贸易试验区、国家服务业扩大开放试点城市探索在更多领域制定场景化、字段级数据出境负面清单,推动制定工业、电信、地理信息、汽车、医药、种业、航天、民航等行业领域重要数据识别目录国家标准。北京、广东已由地方三部门联合印发自贸试验区数据出境负面清单及管理办法。
外资企业的实操步骤
- 先做计数:自1月1日起跟踪累计出境量,区分敏感与非敏感数据。
- 先排除重要数据与CIIO身份,再判断认证是否可用。
- 合并集团数据流,反规避条款在集团层面生效。
- 修好同意链路并开展影响评估,尤其是接收方所在法域的法律制度评估。
- 选择有资质机构并核验其网信备案,同时监控认证范围漂移。
延伸阅读
可参阅本站PIPL跨境传输总览,以及字段级数据出境负面清单一文。
Sources
