Cross-border data transfer rules (PIPL)
Under PIPL (in force 1 Nov 2021), personal information may leave China only through one of three mechanisms: a CAC security assessment, a standard contract (SCC), or certification. ...
2026-08-28
Under PIPL (in force 1 Nov 2021), personal information may leave China only through one of three mechanisms: a CAC security assessment, a standard contract (SCC), or certification. ...
2026-08-28
China's free-trade-zone (FTZ) data-export negative-list mechanism is moving from policy design to live, enforceable cases. 自贸试验区数据出境负面清单机制正从制度设计走向可落地的实际案例。Beijing, Hengqin (Guangdong), Chongqing and Nansha (Guangzhou) have each recorded its first negative-list data-export...
2026-08-28
The CAC "Provisions on Promoting and Regulating Cross-Border Data Flows" (CAC Decree No. 16, 22 March 2024) let free-trade zones formulate their own data-export negative lists under the national...
2026-08-28
China's third data-export route opened on 1 January 2026 under CAC and SAMR Order No. 20. 第20号令使个人信息保护认证成为可用通道,2026年1月1日起施行。Eligibility is narrow: non-CIIO handlers, 100,000 to under 1m individuals' non-sensitive data...
2026-08-28
PIPL took effect on 1 November 2021 and has extraterritorial reach, binding overseas processors that handle personal information of individuals in China. 《个人信息保护法》于2021年11月1日施行,并具有域外效力(第三条),约束处理中国境内自然人个人信息的境外处理者。Processing requires a documented lawful basis...
Cybersecurity / 网络安全, PIPL Compliance / 个保法合规
2026-08-28
The Measures for Network Data Security Risk Assessment, jointly issued by the CAC, MIIT and MPS, took effect on 20 August 2026. 由国家网信办、工业和信息化部、公安部联合制定的《网络数据安全风险评估办法》于 2026 年 8 月 20...
2026-08-28
The Personal Information Protection Law gives three cross-border paths — security assessment, standard contract, and certification — all now operable after the 2026 Certification Measures took effect on 1...
2026-08-28
Cross-border transfers of employee personal information are exempt from the security-assessment, standard-contract and certification routes where they implement cross-border HR management under a duly adopted labour rule or collective...
2026-08-28
PIPL creates two distinct governance roles: a personal information protection officer (PIPO) under Article 52, and a domestic dedicated institution or designated representative for overseas processors under Article 53....
2026-08-28
The CAC's January 2026 draft "Rules on Personal Information Collection and Use by Internet Applications" codifies consent, separate consent for sensitive data, and minimal collection for apps, SDKs, distribution...