China’s September 2026 Data Export Q&A: Where Certification Ends and the Security Assessment Begins
- The Cyberspace Administration of China released its Questions and Answers on Policies and Regulations for Data Export Security Management (September 2026) on 11 September 2026.
国家互联网信息办公室于 2026 年 9 月 11 日发布《数据出境安全管理政策法规问答(2026 年 9 月)》。
- A non-critical-information-infrastructure operator that has cumulatively provided overseas, since 1 January of the year, personal information of 100,000 or more but fewer than one million individuals (excluding sensitive personal information), or sensitive personal information of fewer than 10,000 individuals, and that does not involve important data, may discharge its data export compliance duty through personal information export certification.
非关键信息基础设施运营者自当年 1 月 1 日起累计向境外提供 10 万人以上、不满 100 万人个人信息(不含敏感个人信息),或者不满 1 万人敏感个人信息,且不包括重要数据的,可以通过个人信息出境认证方式履行数据出境合规义务。
- Whatever the volume, a personal information processor that has an outbound transfer may apply to a professional certification institution for personal information export certification, to demonstrate that the processing activity meets GB/T 35273 and GB/T 46068.
无论出境个人信息规模大小,存在个人信息出境行为的个人信息处理者均可向专业认证机构申请个人信息出境认证,证明有关处理活动符合 GB/T 35273 与 GB/T 46068 的要求。
- Where certified processing later reaches one million or more individuals’ personal information (excluding sensitive personal information), or 10,000 or more individuals’ sensitive personal information, since 1 January of the year, a data export security assessment must be filed for through the provincial cyberspace administration to the national one.
已通过认证但自当年 1 月 1 日起累计出境 100 万人以上个人信息(不含敏感个人信息),或者 1 万人以上敏感个人信息的,应当通过所在地省级网信部门向国家网信部门申报数据出境安全评估。
- Quantity splitting and similar methods may not be used to route, through certification, personal information that should lawfully undergo a data export security assessment.
不得采取数量拆分等手段,将依法应当通过数据出境安全评估的个人信息通过个人信息出境认证方式向境外提供。
- Before applying for certification, a processor must perform its duties of notice, obtaining separate consent and conducting a personal information protection impact assessment, and may apply to any professional institution that has completed filing.
申请认证前,个人信息处理者应当履行告知、取得个人单独同意、进行个人信息保护影响评估等义务,并可向已通过备案的任何一家专业机构申请。
- By September 2026, nine free trade zones or ports — Tianjin, Beijing, Hainan, Shanghai, Zhejiang, Guangxi, Jiangsu, Chongqing and Fujian — had filed and published data export negative lists.
截至 2026 年 9 月,全国已有天津、北京、海南、上海、浙江、广西、江苏、重庆、福建等 9 地自贸试验区(港)备案发布数据出境负面清单。
China’s September 2026 Data Export Q&A: Where Certification Ends and the Security Assessment Begins | 国家网信办《数据出境安全管理政策法规问答(2026 年 9 月)》:个人信息出境认证的量化边界与评估衔接
Overview
On 11 September 2026, the Cyberspace Administration of China released the Questions and Answers on Policies and Regulations for Data Export Security Management (September 2026). The stated purpose is to keep strengthening outreach on the policies and regulations governing data export security management, and to guide and help data processors to carry out data export activities efficiently and in compliance. Around 14 September 2026, local government websites carried the text in a concentrated way.
The Q&A answers three questions. Taken together, they fix the boundary between the personal information export certification route and the data export security assessment route, and they name the two national standards against which certification is measured. For foreign-invested groups whose China operations send personal information overseas, the document is the operative reference for deciding which compliance path applies.
Question 1: the certification route and its quantitative band
Personal information export certification is defined by reference to Article 38, paragraph 1, item 2 of the Personal Information Protection Law. It is a conformity assessment activity in which a professional certification institution that has lawfully obtained personal information protection certification qualifications certifies that a personal information processor’s activities — such as providing personal information overseas — comply with the relevant laws, administrative regulations, departmental rules, standards and technical specifications.
The Q&A then sets out the quantitative band in which certification is available. A non-critical-information-infrastructure operator may discharge its data export compliance duty through personal information export certification where, since 1 January of the year, it has cumulatively provided overseas either:
- personal information of 100,000 or more but fewer than one million individuals (excluding sensitive personal information); or
- sensitive personal information of fewer than 10,000 individuals;
and where important data is not involved.
The Q&A adds a broader proposition. Where a personal information processor has an outbound transfer of personal information, whatever the scale of that transfer, it may apply to a professional certification institution for personal information export certification, in order to demonstrate that the relevant processing activities meet the requirements of GB/T 35273 (Information Security Technology — Personal Information Security Specification) and GB/T 46068 (Data Security Technology — Security Certification Requirements for Personal Information Cross-border Processing Activities).
The Q&A also draws a hard line. Quantity splitting and similar methods may not be used to provide overseas, through the certification route, personal information that should lawfully pass through a data export security assessment.
Question 2: when certification must be upgraded to a security assessment
Certification is not a permanent alternative to assessment. Where a processor has already passed personal information export certification, but has cumulatively exported since 1 January of the year either one million or more individuals’ personal information (excluding sensitive personal information) or 10,000 or more individuals’ sensitive personal information, it must file for a data export security assessment with the national cyberspace administration through the provincial cyberspace administration at its place of domicile.
The Q&A provides a bridging mechanism for that filing. When filing, the processor may attach the relevant information about having passed personal information export certification, explaining the personal information protection level of the processor and of the overseas recipient, and the safeguards for personal information rights and interests. The cyberspace administration will take this into account in the course of the security assessment.
The practical reading is that certification and assessment sit on a single continuum. Certification is the lighter route in the lower band; when volume crosses the higher threshold, the assessment is mandatory, and the certification work already done is carried forward as supporting material rather than discarded.
Question 3: how to apply and what duties precede it
Applications follow the Measures for the Administration of Personal Information Export Certification. Before applying for certification to provide personal information overseas, a personal information processor must, in accordance with laws and administrative regulations, perform its duties of notice, obtaining separate consent, and conducting a personal information protection impact assessment.
On where to apply, the Q&A states that a processor may currently apply to any professional institution that has completed filing. By way of example it names the China Cybersecurity Review, Certification and Market Regulation Big Data Centre, with an enquiry telephone number of (010)88650936.
The two standards against which certification is measured
The Q&A ties certification to two national standards. GB/T 35273, the Information Security Technology — Personal Information Security Specification, is the long-standing baseline specification for personal information handling. GB/T 46068, the Data Security Technology — Security Certification Requirements for Personal Information Cross-border Processing Activities, is the certification-specific requirement for cross-border processing.
For a processor preparing an application, the two standards define the substance of the conformity assessment: not merely that a transfer was documented, but that the cross-border processing activity itself meets the stated requirements.
Enforcement context and regional negative lists
Two further developments frame the Q&A. On 15 September 2026, the Cyberspace Administration of China published ten typical enforcement cases in the fields of cybersecurity, data security and personal information protection. The cases cover website tampering, planting malicious programs, data breaches, personal information leaks, unlawful collection and use of personal information, unlawful export of personal information, failure to implement labelling requirements for AI-generated synthetic content, and new technologies or applications being put into service without assessment.
Separately, the Action Plan for Stabilising and Upgrading Foreign Investment calls for supporting free trade zones and national comprehensive pilot cities for opening up the services sector to explore, in more fields, scenario-based and field-level data export negative lists. By September 2026, nine free trade zones or ports had filed and published data export negative lists: Tianjin, Beijing, Hainan, Shanghai, Zhejiang, Guangxi, Jiangsu, Chongqing and Fujian.
What it means for foreign firms
Three practical points follow.
First, count before you choose a path. Determine whether the personal information you send overseas is sensitive, count the cumulative number of individuals since 1 January of the year, and test that figure against the bands. Below the certification thresholds, certification is available; at one million individuals’ non-sensitive personal information or 10,000 individuals’ sensitive personal information, the security assessment is mandatory.
Second, do not engineer around the thresholds. The Q&A expressly prohibits quantity splitting and similar methods. A structure that fragments flows to keep each stream under a threshold does not remove the underlying obligation, and the enforcement cases published on 15 September 2026 show that unlawful export of personal information is an active enforcement theme.
Third, use the certification work as assessment input. Where volume later crosses the higher band, the information about a passed certification may be attached to the assessment filing and will be taken into account. A processor that has documented its protection level and its safeguards is therefore better positioned when the heavier route is triggered.
Sources
- 贵州省大数据发展管理局转载 — 《数据出境安全管理政策法规问答(2026 年 9 月)》: https://drc.guizhou.gov.cn/ztzl/wlaqzs/202609/t20260918_90894948.html
- 国家互联网信息办公室 — 网络安全、数据安全、个人信息保护执法典型案例(2026 年 9 月 15 日): https://www.cac.gov.cn/2026-09/15/c_1790876152357946.htm
- 上海市互联网信息办公室转载 — 数据出境政策宣介: https://wsb.sh.gov.cn/ztzl/shzxzb/20260923/3a34c2e581c04aa4a3eb7dafedd9e404.html
- 商务部政策发布 — 《利用外资固稳促优行动方案》: https://www.mofcom.gov.cn/zcfb/index.html
- 内蒙古自治区党委网信办 — 政策法规宣介: http://www.nmgwx.gov.cn/centralSpirit/19297.jhtml
- 国家互联网信息办公室: https://www.cac.gov.cn/
Related reading
- see also: Guangdong’s Greater Bay Area Data Special Zone Work Plan (gba-data-special-zone)
- see also: Digital trade and IP rules in the 77-measure FTZ rollout (digital-trade-rules-replication)
国家网信办《数据出境安全管理政策法规问答(2026 年 9 月)》:个人信息出境认证的量化边界与评估衔接
概述
2026 年 9 月 11 日,国家互联网信息办公室发布《数据出境安全管理政策法规问答(2026 年 9 月)》。其目的表述为:持续加强数据出境安全管理政策法规宣介,指导和帮助数据处理者高效合规开展数据出境活动。2026 年 9 月 14 日前后,各地政府网站对该问答进行了集中转载。
该问答回答三个问题。三者合起来,划定了个人信息出境认证通道与数据出境安全评估通道之间的边界,并点明了衡量认证的两项国家标准。对在华业务需要向境外提供个人信息的外资集团而言,这份问答是判断适用哪条合规路径的现行依据。
问一:认证通道的适用情形与量化区间
个人信息出境认证以《个人信息保护法》第三十八条第一款第二项为规范依据。它是指由依法取得个人信息保护认证资质的专业认证机构,证明个人信息处理者向境外提供个人信息等个人信息处理活动符合相关法律、行政法规、部门规章、标准、技术规范的合格评定活动。
问答随后给出认证通道可用的量化区间。非关键信息基础设施运营者自当年 1 月 1 日起累计向境外提供下列情形之一的,可以通过个人信息出境认证方式履行数据出境合规义务:
- 10 万人以上、不满 100 万人个人信息(不含敏感个人信息);或者
- 不满 1 万人敏感个人信息;
且不包括重要数据。
问答还给出一个更宽的口径:个人信息处理者存在个人信息出境行为,不论出境个人信息规模大小,均可向专业认证机构申请个人信息出境认证,以证明有关处理活动符合 GB/T 35273《信息安全技术 个人信息安全规范》、GB/T 46068《数据安全技术 个人信息跨境处理活动安全认证要求》的要求。
问答同时划出一条硬线:不得采取数量拆分等手段,将依法应当通过数据出境安全评估的个人信息通过个人信息出境认证方式向境外提供。
问二:何时认证必须升级为安全评估
认证并非安全评估的永久替代。已通过个人信息出境认证,但自当年 1 月 1 日起累计出境100 万人以上个人信息(不含敏感个人信息)或者1 万人以上敏感个人信息的,个人信息处理者应当通过所在地省级网信部门向国家网信部门申报数据出境安全评估。
问答为这次申报设置了衔接机制。申报时,可以将通过个人信息出境认证的有关情况附后,说明个人信息处理者和境外接收方的个人信息保护水平、个人信息权益保障等情况,网信部门将在安全评估过程中予以参考。
实操理解是:认证与评估位于同一条连续线上。较低区间以认证为较轻路径;当数量跨过较高门槛,评估即为强制,此前完成的认证工作作为支撑材料承接下来,而非作废。
问三:如何申请,以及申请前应履行的义务
申请按照《个人信息出境认证办法》办理。个人信息处理者在申请认证向境外提供个人信息前,应当按照法律、行政法规的规定履行告知、取得个人单独同意、进行个人信息保护影响评估等义务。
关于向谁申请,问答指出,目前可向已通过备案的任何一家专业机构申请;文中举例机构为中国网络安全审查认证和市场监管大数据中心,咨询电话为 (010)88650936。
衡量认证的两项国家标准
问答把认证与两项国家标准绑定。GB/T 35273《信息安全技术 个人信息安全规范》是个人信息处理的长期基础性规范;GB/T 46068《数据安全技术 个人信息跨境处理活动安全认证要求》则是面向跨境处理活动的专门认证要求。
对准备申请的处理者而言,这两项标准界定了合格评定的实质:不仅是出境行为被记录,而是跨境处理活动本身符合规定要求。
执法背景与区域性负面清单
另有两项进展为问答提供背景。2026 年 9 月 15 日,国家互联网信息办公室发布网络安全、数据安全、个人信息保护等领域执法典型案例 10 例,涉及网页篡改、设置恶意程序、数据泄露、个人信息泄露、违法收集使用个人信息、违法出境个人信息、未落实人工智能生成合成内容标识要求、新技术新应用未经评估上线提供服务等情形。
此外,《利用外资固稳促优行动方案》提出,支持自由贸易试验区、国家服务业扩大开放试点城市探索在更多领域制定场景化、字段级数据出境负面清单。截至 2026 年 9 月,全国已有天津、北京、海南、上海、浙江、广西、江苏、重庆、福建等 9 地自贸试验区(港)备案发布数据出境负面清单。
对外资企业的实际含义
有三点实务结论。
其一,先盘清数量,再选择路径。判断拟出境个人信息是否属于敏感个人信息,统计自当年 1 月 1 日起的累计人数,并对照量化区间:低于认证门槛可走认证;达到 100 万人个人信息(不含敏感个人信息)或 1 万人敏感个人信息,则安全评估为强制。
其二,不要围绕门槛做技术性安排。问答明确禁止数量拆分等手段。把数据流切碎以使每一支低于门槛的架构,并不能消除底层义务;2026 年 9 月 15 日发布的执法典型案例也显示,违法出境个人信息是当前的执法重点之一。
其三,把认证成果用作评估输入。当数量日后跨过较高区间时,通过认证的有关情况可以附于评估申报材料并予以参考。已经记录自身保护水平与保障措施的处理者,在触发较重路径时因此处于更有利的位置。
来源
- 贵州省大数据发展管理局转载 — 《数据出境安全管理政策法规问答(2026 年 9 月)》:https://drc.guizhou.gov.cn/ztzl/wlaqzs/202609/t20260918_90894948.html
- 国家互联网信息办公室 — 网络安全、数据安全、个人信息保护执法典型案例(2026 年 9 月 15 日):https://www.cac.gov.cn/2026-09/15/c_1790876152357946.htm
- 上海市互联网信息办公室转载 — 数据出境政策宣介:https://wsb.sh.gov.cn/ztzl/shzxzb/20260923/3a34c2e581c04aa4a3eb7dafedd9e404.html
- 商务部政策发布 — 《利用外资固稳促优行动方案》:https://www.mofcom.gov.cn/zcfb/index.html
- 内蒙古自治区党委网信办 — 政策法规宣介:http://www.nmgwx.gov.cn/centralSpirit/19297.jhtml
- 国家互联网信息办公室:https://www.cac.gov.cn/
相关阅读
- 见:广东大湾区数据特区工作方案(gba-data-special-zone)
- 见:77 条试点措施中的数字贸易与知识产权规则(digital-trade-rules-replication)