Posted in

Personal Information Compliance and Cross-Border Data for Foreign Firms: The 2026 Simplification and the Three Outbound Paths

  • The Personal Information Protection Law gives three cross-border paths — security assessment, standard contract, and certification — all now operable after the 2026 Certification Measures took effect on 1 January 2026.
    《个人信息保护法》确立安全评估、标准合同、认证三条出境路径;随2026年《个人信息出境认证办法》1月1日施行,三者均已可操作。
  • A July 2026 rule simplifies compliance for “small” processors (under 100,000 individuals), letting one park/estate rule cover many tenants and exempting minor outbound transfers from assessment, contract or certification.
    2026年7月新规为”小型”处理者(不满10万人)简化合规,允许”一份规则管多家”,并对少量出境免予评估、合同或认证。
  • The cross-border thresholds: under 100,000 individuals (or under 10,000 sensitive) may use contract or certification; over 100,000 (or over 10,000 sensitive) requires a security assessment.
    出境阈值:累计向境外提供不满10万人(或不满1万敏感)可走合同或认证;超100万人(或超1万敏感)须申报安全评估。
  • The Network Data Security Risk Assessment Measures (Decree No. 24) take effect on 20 August 2026, requiring annual risk assessments for important-data handlers.
    《网络数据安全风险评估办法》(第24号令)2026年8月20日施行,重要数据处理者须每年开展风险评估。
  • Even via certification, separate individual consent and a personal-information protection impact assessment remain mandatory;自贸区 negative lists may set local carve-outs.
    即便走认证,仍须取得单独同意并开展个人信息保护影响评估;自贸区负面清单可设定本地豁免。
  • Practical step: size your outbound volume, pick contract/certification vs assessment, and for SMEs use the simplified-rule and exemption pathways from the July 2026 measures.

实操建议:先核算出境体量,在合同/认证与评估间选型;中小微企业善用2026年7月新规的简化规则与豁免路径。

Personal Information Compliance and Cross-Border Data for Foreign Firms: The 2026 Simplification and the Three Outbound Paths | 个人信息保护与数据出境合规:小型处理者简化规定与出境三路径(2026)

China’s *Personal Information Protection Law (PIPL)*, together with the *Cybersecurity Law*, *Data Security Law* and the *Network Data Security Management Regulation*, forms a layered regime. For foreign-invested firms, two questions dominate: how to process personal information lawfully, and how to move it cross-border. A batch of 2026 measures makes both more operational — and, for small processors, lighter.

The three cross-border paths

PIPL provides three lawful outbound routes: (1) a security assessment organised by the cyberspace authority; (2) a standard contract filed with the authority; and (3) certification by a recognised professional institution. The *Measures for the Certification of Personal Information Outbound Transfer* (CAC + SAMR) took effect on 1 January 2026, completing the triad. A 2026 CAC policy Q&A fixes the volumes: a processor (other than a CIIO) providing abroad 100,000–1,000,000 individuals’ information (non-sensitive) or under 10,000 sensitive items in a year may use contract or certification; above those thresholds, a security assessment is required.

The July 2026 simplification for small processors

In July 2026 the CAC and the Ministry of Public Security issued the *Simplified-Measures Provisions for Small Personal-Information Processors*, effective 1 September 2026. A “small processor” handles fewer than 100,000 individuals. The provisions let a park, industrial base or commercial-property manager publish one unified processing rule covering many tenant processors, so small firms need not each draft their own. Critically, the provisions exempt minor outbound transfers from the assessment, standard-contract or certification obligations across six scenarios (contract performance, cross-border HR, emergencies, legal duties, and others), while preserving protection intensity.

The newly enforced risk-assessment duty

On 18 June 2026 the CAC, the MIIT and the Ministry of Public Security jointly issued the *Network Data Security Risk Assessment Measures* (Decree No. 24), effective 20 August 2026 — the first dedicated inter-agency rule on data-security risk assessment. Important-data handlers must conduct an annual risk assessment; general handlers are encouraged to do so at least every three years. Foreign firms in industrial, telecom, automotive, medical or other sectors should map whether they hold important data and calendar the assessment.

What stays mandatory

Regardless of route, separate individual consent and a personal-information protection impact assessment remain required. Certification is valid for three years and may be revoked; a foreign processor without a China establishment must appoint a local institution or representative to apply. Free-trade-zone negative lists (Tianjin, Beijing, Shanghai, Hainan, Zhejiang, Guangxi, Jiangsu, Chongqing) may specify local carve-outs, so a registered FIE should check the local list first.

Practical steps

  1. Count your data. Track cumulative outbound individuals/sensitive items against the thresholds.
  2. Pick the route. Under threshold → standard contract or certification; over → security assessment.
  3. SMEs: use the simplification. Adopt the park/estate unified rule and claim the minor-transfer exemption where eligible.
  4. Diarise the assessment. Important-data handlers — annual; others — at least triennial.
  5. Keep consent and PIA. No route waives separate consent or the impact assessment.

个人信息保护与数据出境合规:小型处理者简化规定与出境三路径(2026)

中国的《个人信息保护法》与《网络安全法》《数据安全法》《网络数据安全管理条例》共同构成分层监管。对外商投资企业而言,两个问题最关键:如何合法处理个人信息,以及如何跨境传输。2026年的一系列措施让两者更具可操作性,对小型处理者则更轻。

出境三条路径

《个人信息保护法》确立三条合法出境路径:(1)网信部门组织的安全评估;(2)向主管部门备案的标准合同;(3)经认可专业机构开展的认证。国家网信办与市场监管总局的《个人信息出境认证办法》于2026年1月1日施行,补齐”三件套”。2026年网信办政策问答明确体量:非关键信息基础设施运营者一年内累计向境外提供10万—100万人信息(非敏感)或不满1万敏感信息,可走合同或认证;超过阈值须申报安全评估。

2026年7月小型处理者简化

2026年7月,国家网信办与公安部发布《小型个人信息处理者个人信息保护简化措施规定》,自2026年9月1日施行。”小型处理者”指处理不满10万人个人信息的主体。规定允许园区、产业基地或商业物业管理者发布”一份规则管多家”的统一处理规则,小型企业无需各自起草。关键的是,规定在六类情形(订立合同、跨境人力资源管理、紧急情况、履行法定职责等)下,对少量出境免予评估、标准合同或认证义务,同时保留保护强度。

新强化的风险评估义务

2026年6月18日,国家网信办、工信部、公安部联合发布《网络数据安全风险评估办法》(第24号令),自2026年8月20日施行——首部专门的数据安全风险评估跨部门规章。重要数据处理者须每年开展风险评估;一般处理者鼓励至少每三年一次。工业、电信、汽车、医疗等行业的在华外资企业应梳理是否持有重要数据并排入日程。

仍属强制的事项

无论走哪条路径,取得单独同意并开展个人信息保护影响评估仍属强制。认证有效期三年,可被撤销;无中国住所的外国处理者须指定本地机构或代表协助申请。天津、北京、上海、海南、浙江、广西、江苏、重庆等自贸区负面清单可规定本地豁免,注册外资企业应优先核对本地清单。

实操步骤

  1. 清点数据。 按阈值跟踪累计出境人数/敏感条数。
  2. 选定路径。 未超阈值→标准合同或认证;超阈值→安全评估。
  3. 中小微企业用简化。 采用园区统一规则,并在符合条件时主张少量出境豁免。
  4. 记入评估日程。 重要数据处理者每年一次;其他至少三年一次。
  5. 保留同意与影响评估。 任何路径都不免除单独同意与影响评估。

Practitioner Quick Reference

  • Three outbound paths: security assessment, standard contract, certification — all operable since 1 Jan 2026.
    三条出境路径:安全评估、标准合同、认证——2026年1月1日起均可操作。
  • Thresholds: <100k individuals (or <10k sensitive) → contract/certification; above → security assessment.
    阈值:不满10万人(或不满1万敏感)→合同/认证;超出→安全评估。
  • SME simplification: “small” = under 100k individuals; one park rule may cover many tenants; minor transfers exempt.
    中小微简化:”小型”=不满10万人;园区一份规则可覆盖多租户;少量出境豁免。
  • Risk assessment from 20 Aug 2026: important-data handlers annually; others at least triennially.
    风险评估自2026年8月20日:重要数据处理者每年;其他至少三年一次。
  • Consent + PIA mandatory: no route waives separate consent or the impact assessment.
    同意与影响评估强制:任何路径都不免除单独同意与影响评估。

Common Pitfalls

  • Assuming certification replaces consent: separate individual consent is still required.
    以为认证取代同意:仍须取得单独同意。
  • Over-looking the FTZ list: local negative lists may carve out sectors differently.
    忽视自贸区清单:本地负面清单可能对行业有不同豁免。
  • Underestimating volume: crossing the threshold mid-year triggers a retrospective assessment.
    低估体量:年中累计越阈须将已出境数据纳入安全评估。

2026 Watchlist

  • Decree No. 24 in force (20 Aug 2026): important-data handlers begin annual assessments.
    第24号令施行(2026-08-20):重要数据处理者启动年度评估。
  • FTZ negative lists: more pilot zones may publish field-level outbound carve-outs.
    自贸区负面清单:更多试点区域或发布字段级出境豁免。
  • CAC Q&A updates: watch further PIPL and data-export policy clarifications.
    CAC问答更新:关注个保法及数据出境政策的进一步澄清。

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *