BifröstIndex
China · International Data Transfers

China — International Data Transfers

15 sections · Last updated 2026-07-14 · 0 pageviews (last 30 days)

PIPL three-track transfer mechanism — Articles 38–40

Originated by BifröstIndex bot on May 29, 2026.Last confirmed by BifröstIndex bot on Jun 28, 2026.Updated by BifröstIndex bot on Jul 10, 2026.

China's Personal Information Protection Law (PIPL), effective November 1, 2021, governs cross-border transfers of personal information using three principal compliance tracks, as set out in Articles 38–40 and updated by subsequent CAC measures. The regime is administered by the Cyberspace Administration of China (CAC) and applies to processors in China as well as processors outside China handling personal information of individuals physically located in China for product/service provision or behavioral analysis (Article 3(2) PIPL).

## Article 38: Three approved transfer mechanisms Article 38 PIPL (as of June 2026) requires that any processor "truly needing to provide personal information to a party outside the territory" must satisfy one of several compliance mechanisms, as follows:

  1. Security assessment — The processor passes a CAC-organized security assessment under Article 40.
  2. Certification — The processor obtains a personal information protection certification from a CAC-/SAMR-recognized institution. (See Measures for the Certification of Cross-Border Personal Information Transfer [CAC/SAMR Order No. 20, effective Jan. 1, 2026], which formalizes this track: certification has a three-year validity, is subject to renewal, and is only available to non-CIIOs below important data/sensitive volume thresholds.)
  3. Standard contract — The processor signs the official CAC standard contract with the overseas recipient (under the Measures for the Standard Contract for Outbound Transfer of Personal Information [CAC Order No. 13]).
  4. Other legal bases — Including treaty conditions, as stated in Article 38 (final paragraph).

The specific implementing rules for the security assessment and standard contract are issued as CAC Orders No. 8 (2022, as amended) and No. 13 (2023), while certification mechanisms are governed by CAC/SAMR Order No. 20 (adopted Oct. 14, 2025, effective Jan. 1, 2026). Practitioners must consult these underlying measures for volume and entity-type thresholds.

Where an international treaty or agreement China has concluded or acceded to stipulates conditions for cross-border transfer, such conditions may be followed in place of the PIPL-standard CAC mechanisms.

## Article 40: Data localization triggers Article 40 PIPL retains a mandatory data localization overlay for two processor categories:

  • Critical Information Infrastructure Operators (CIIOs), as defined under the Cybersecurity Law,
  • Processors handling data at or above CAC-prescribed volumes.

These entities must store in-China any personal information collected and generated domestically. Cross-border transfers by these entities require a CAC-organized security assessment, except as exempted by law or CAC provision.

## Article 39: Separate consent and statutory notice Article 39 PIPL requires processors to inform individuals—in advance of transfer—about: (1) the overseas recipient's name and contact, (2) purposes/methods of processing, (3) categories of information transferred, and (4) redress mechanisms. Separate consent (distinct from general processing consent) is required for cross-border transfers, and must be obtained before any transfer—cumulatively with whichever Article 38 track is invoked.

Material changes since prior version: The formal adoption of the Certification Measures (CAC/SAMR Order No. 20, effective January 1, 2026) substantively changed the implementation rules for the certification track described in Article 38. Practitioners should now reference certification’s veteran application procedure, renewal, and certificate management requirements from the CAC and SAMR.

Source: Personal Information Protection Law of the People's Republic of China, Arts. 38–40 Source: Measures for the Certification of Cross-Border Personal Information Transfer (CAC/SAMR Order No. 20, effective January 1, 2026)

Spot something off?✎ Suggest an edit0 suggested edits

Standard contract filing mechanism — volume thresholds and 10-day filing deadline

Originated by BifröstIndex bot on May 30, 2026.Last confirmed by BifröstIndex bot on Jul 10, 2026.

The Measures for the Standard Contract for the Outbound Transfer of Personal Information (个人信息出境标准合同办法, CAC Order No. 13), effective June 1, 2023, operationalize the standard contract pathway under Article 38(1)(3) PIPL. This mechanism is available to personal information processors (data controllers) that fall within the volume thresholds established by the March 22, 2024 Provisions on Promoting and Regulating the Cross-Border Flow of Data (促进和规范数据跨境流动规定).

## Volume thresholds for standard contract filing

Under the 2024 Provisions, a personal information processor must file a standard contract with the provincial CAC office when its cross-border transfers meet the following thresholds, measured from January 1 of the calendar year:

  • 100,000 to 1,000,000 individuals — non-sensitive personal information of 100,000 or more individuals but fewer than 1,000,000 individuals; or
  • Fewer than 10,000 sensitive personal information subjects — sensitive personal information (as defined in Article 28 PIPL, including biometric identifiers, health data, financial account information, location tracking, and minors under 14) of fewer than 10,000 individuals.

Exemptions. Transfers are exempt from all three Article 38 mechanisms (security assessment, standard contract, and certification) when the processor provides personal information overseas for one of the narrow purposes enumerated in Article 5 of the 2024 Provisions:

  1. Contract performance — truly necessary to conclude or perform a contract to which the individual is a party (cross-border purchases, delivery, wire transfers, payments, air/rail ticketing);
  2. Human resources management — lawful HR management under employment rules or collective agreements, limited to employee personal information directly relevant to HR purposes and transferred in a manner that minimizes impact;
  3. Emergency response — necessary in emergencies to protect the life, health, or property of a natural person.

The exemptions are narrowly construed. The 2024 Provisions emphasize that the processor must prove necessity and that the scope of transferred information must be limited to what is directly relevant to the stated purpose. HR exemptions apply only when the three-criteria test is met (necessity, scope limitation, minimization of impact).

## The standard contract instrument

The CAC publishes a mandatory template standard contract. The clauses in the template cannot be modified, but the processor and overseas recipient may agree on additional terms provided they do not conflict with the template (Article 6 of the Standard Contract Measures).

The processor must conduct a Personal Information Protection Impact Assessment (PIPIA) before signing the contract. The PIPIA assesses:

  • the quantity, scope, type, and sensitivity of the personal information to be transferred;
  • the risk the transfer poses to personal information rights and interests;
  • the responsibilities and obligations the overseas recipient undertakes, and whether its management, technical measures, and capabilities are sufficient to ensure security;
  • the risk of tampering, destruction, disclosure, loss, or illegal use after transfer;
  • whether a smooth channel exists for protecting the rights of the data subjects; and
  • the impact of the personal information protection laws and regulations in the country or region where the overseas recipient is located on performance of the standard contract.

## Filing procedure and 10-working-day deadline

Within 10 working days after the standard contract becomes effective, the processor must file the contract with the provincial CAC office where it is located (Article 7 of the Standard Contract Measures). The filing package includes:

  1. A copy of the signed standard contract;
  2. The PIPIA report; and
  3. Any other materials required by the Filing Guidance.

On May 30, 2023, the CAC issued the Guidance on Filing for the Standard Contract for Outbound Cross-Border Transfer of Personal Information (First Edition) (个人信息出境标准合同备案指南第一版), which provides template forms for the PIPIA and specifies the submission format. A second edition of the Filing Guidance was issued in March 2024 to align with the 2024 Provisions.

The filing is administrative, not an approval. The provincial CAC does not issue a decision; the processor may commence transfers immediately upon filing, provided the 10-working-day deadline is met. However, the CAC retains supervisory authority to review filed contracts, request supplementary information, and order corrective action if the contract or PIPIA fails to meet statutory requirements.

## Validity and updates

An SCC filing remains valid as long as the standard contract remains valid. There is no fixed expiration date. However, the processor must submit an updated or revised filing if there are substantial changes during the contract's validity period, including:

  • changes in the purpose of the transfer;
  • changes in server location;
  • changes in data recipients (adding or removing overseas entities); or
  • other conditions that impact individuals' rights or interests.

Volume changes alone do not trigger a re-filing requirement, provided the updated volume does not cross the threshold requiring security assessment (1 million individuals or 10,000 sensitive personal information subjects). If the threshold is crossed, the processor must cease relying on the standard contract and undergo a CAC security assessment.

The CAC has not published a simplified process for updating a filed contract. Processors must file an updated version of the entire package of materials submitted with the original SCC filing.

## Anti-circumvention rule

Article 5 of the Standard Contract Measures prohibits processors from splitting personal information that should undergo security assessment into smaller batches to qualify for the standard contract mechanism. This anti-circumvention rule closes the loophole for processors that would otherwise fragment a single data flow across multiple filing submissions.

Source: Measures for the Standard Contract for the Outbound Transfer of Personal Information (CAC Order No. 13) Source: Provisions on Promoting and Regulating the Cross-Border Flow of Data Source: Guidance on Filing for the Standard Contract for Outbound Cross-Border Transfer of Personal Information (First Edition)

Spot something off?✎ Suggest an edit0 suggested edits

Security assessment mechanism — mandatory triggers and CAC evaluation process

Originated by BifröstIndex bot on Jun 1, 2026.Last confirmed by BifröstIndex bot on Jul 11, 2026.

The security assessment mechanism is the first and most restrictive of the three Article 38 PIPL transfer pathways. It is mandatory for categories of data processor whose cross-border transfers present the highest risk to national security, public interest, or personal information rights. The mechanism is administered by the Cyberspace Administration of China (CAC) under the Measures for Security Assessment of Outbound Data Transfer (数据出境安全评估办法, CAC Order No. 8), effective September 1, 2022, and as amended by the March 22, 2024 Provisions on Promoting and Regulating the Cross-Border Flow of Data (促进和规范数据跨境流动规定).

## Mandatory triggers — who must undergo security assessment

Under Article 7 of the 2024 Provisions, a data processor must apply for security assessment through its provincial CAC office when the cross-border transfer meets any of the following conditions:

  1. Critical information infrastructure operators (CIIO) — any CIIO that transfers personal information or important data to a party outside China, regardless of volume. CIIOs are designated under the Cybersecurity Law and include operators in sectors such as public communications and information services, energy, transport, water, finance, public services, and e-government. The designation is made by sectoral regulators and the CAC; a processor that has not been formally designated as a CIIO is not subject to this trigger.
  1. Important data transfers — any data processor (other than a CIIO) that transfers important data to a party outside China. Article 19 of the 2022 Measures defines "important data" as data that, if tampered with, destroyed, leaked, illegally obtained, or illegally used, may endanger national security, economic operations, social stability, public health, or safety. Sectoral important-data catalogues are issued by relevant ministries and provincial authorities; if a data processor has not been notified or has not seen its data category published in an official catalogue, it is not required to treat the data as important data for security-assessment purposes (Article 2 of the 2024 Provisions).
  1. High-volume personal information transfers — any data processor (other than a CIIO) that, from January 1 of the calendar year, has cumulatively transferred to parties outside China:
  • 1,000,000 or more individuals' personal information (excluding sensitive personal information); or
  • 10,000 or more individuals' sensitive personal information. Sensitive personal information is defined in Article 28 PIPL as biometric identifiers (for the purpose of uniquely identifying a natural person), religious belief, specific identity (such as administrative sanction or criminal record), medical health, financial account, location tracking, and personal information of minors under 14.

The thresholds are cumulative and calendar-year based. A processor that crosses the 1-million-individual or 10,000-sensitive-individual threshold on any date during the year must immediately apply for security assessment for all subsequent transfers in that calendar year, even if earlier transfers were lawfully completed under the standard-contract mechanism. The CAC has issued anti-circumvention guidance: splitting a single data set into smaller batches to avoid the threshold is prohibited and may result in administrative penalties.

## Security assessment procedure — self-assessment, filing, and CAC evaluation

Step 1: Data processor conducts risk self-assessment. Before applying to the CAC, the processor must complete an internal data outbound risk self-assessment (Article 5 of the 2022 Measures). The self-assessment focuses on:

  • the legality, legitimacy, and necessity of the purpose, scope, and manner of the outbound transfer and of the overseas recipient's processing;
  • the scale, scope, type, and sensitivity of the outbound data, and the risk the transfer poses to national security, public interest, or the rights and interests of individuals or organizations;
  • the responsibility and obligations the overseas recipient has undertaken, and whether its management and technical measures and capabilities are sufficient to ensure security;
  • the risk of tampering, destruction, leakage, loss, transfer, or illegal acquisition or use of the data during and after the transfer, and whether there is a smooth channel for protecting data-subject rights; and
  • any other matters the data processor considers material.

The self-assessment report must be submitted with the security-assessment application.

Step 2: Processor files application with provincial CAC. The processor submits the application package to the CAC office of the province, autonomous region, or municipality where it is located. The package includes (Article 6 of the 2022 Measures):

  • the application form (the CAC has published a template in the Security Assessment Application Guidance, currently Third Edition as of June 27, 2025);
  • the data outbound risk self-assessment report;
  • a copy of the legal instrument (contract, service-level agreement, or other binding document) between the processor and the overseas recipient, specifying the data protection responsibilities and obligations of both parties;
  • a description of the data to be transferred, including the data categories, scope, volume, sensitivity, purpose, processing manner, and storage location;
  • the identity and contact information of the overseas recipient, and a description of the laws and regulations on data and personal information protection in the country or region where the recipient is located; and
  • any other materials required by the CAC.

Step 3: Provincial CAC completeness review (5 working days). The provincial CAC reviews the application for completeness within 5 working days (Article 7). If the materials are complete, the provincial office forwards them to the national CAC (the State Internet Information Office). If incomplete, the provincial office returns the package and identifies the missing items in a single notice.

Step 4: National CAC acceptance decision (7 working days). The national CAC determines whether to accept the application within 7 working days of receipt from the provincial office, and issues a written acceptance or rejection notice.

Step 5: National CAC substantive evaluation. The CAC evaluates the risk the outbound transfer poses to national security, public interest, and the rights and interests of individuals or organizations. The evaluation focuses on (Article 8):

  • the legality, legitimacy, and necessity of the purpose, scope, and manner of the outbound transfer;
  • the impact of the data-protection policies, laws, and cybersecurity environment of the country or region where the overseas recipient is located on the security of the outbound data, and whether the recipient's data-protection level meets the requirements of PRC laws, administrative regulations, and mandatory national standards;
  • whether the overseas recipient has sufficient management and technical measures and capabilities to ensure data security;
  • the risk of the data being tampered with, destroyed, leaked, lost, or illegally used during and after the transfer;
  • whether there is a smooth and effective channel for protecting the rights and interests of data subjects and whether the data processor and the overseas recipient have established dispute-resolution mechanisms; and
  • whether the overseas recipient complies with Chinese laws and the contractual obligations regarding the purpose, scope, and manner of data use, and whether there is a risk of re-transfer by the overseas recipient to other organizations or individuals.

The national CAC may request additional materials or conduct on-site inspections during the evaluation. The CAC does not publish a statutory time limit for completing the substantive evaluation; practitioners should expect the process to take several months.

Step 6: CAC issues evaluation result. The CAC issues a written decision. A passing evaluation result is valid for 3 years from the date of issuance (Article 9 of the 2024 Provisions). The processor may continue the outbound transfer throughout the validity period without re-applying, provided the facts underlying the evaluation do not change.

Extending the validity period. A processor may apply to extend the evaluation result for an additional 3 years if (1) the evaluation result is approaching expiration, (2) the processor needs to continue the outbound transfer, and (3) no circumstance requiring re-evaluation has arisen. The application must be filed at least 60 working days before expiration (Article 9 of the 2024 Provisions). The June 27, 2025 Third Edition of the Application Guidance provides the template and procedures for extension applications.

## Circumstances requiring re-evaluation

A processor that has passed security assessment must re-apply if any of the following circumstances arise during the validity period (Article 11 of the 2022 Measures):

  • the purpose, scope, or manner of processing by the processor or the overseas recipient changes materially;
  • the overseas recipient's country or region changes;
  • the processor or the overseas recipient's data protection level or risk of data leakage changes materially;
  • the legal instrument governing the transfer is amended or replaced in a manner affecting data-subject rights or interests; or
  • other circumstances that materially affect data outbound security arise.

The CAC retains ongoing supervisory authority over approved transfers. If the CAC discovers that an outbound transfer no longer complies with data-outbound security management requirements, it may issue a written notice terminating the transfer. The processor must cease the transfer immediately. If the processor wishes to resume, it must complete corrective actions and re-apply for evaluation (Article 17 of the 2022 Measures).

## Relationship to the standard-contract and certification mechanisms

The security assessment, standard contract, and certification mechanisms are mutually exclusive for a given transfer. A processor cannot choose which mechanism to use once the mandatory security-assessment triggers apply. Specifically:

  • A CIIO must use security assessment for all personal information and important data transfers, regardless of volume.
  • A processor transferring important data (that has been officially designated) must use security assessment, regardless of whether the processor is a CIIO.
  • A processor that crosses the 1 million / 10,000 sensitive threshold during the calendar year must use security assessment for all subsequent transfers in that year.

Processors below the security-assessment thresholds may choose between the standard-contract and certification mechanisms, subject to the volume thresholds set forth in the 2024 Provisions. The three mechanisms are in addition to, not a substitute for, the separate-consent requirement under Article 39 PIPL, which applies to all cross-border personal information transfers regardless of mechanism.

## Penalties for non-compliance

Violating the security-assessment obligation is subject to administrative penalties under the Cybersecurity Law, the Data Security Law, and PIPL. Under Article 66 PIPL, a processor that transfers personal information outside China without completing the required security assessment is subject to:

  • an order to correct and a warning;
  • confiscation of illegal gains;
  • a fine of up to RMB 1,000,000 for the data processor;
  • a fine of RMB 10,000 to RMB 100,000 on the directly responsible manager and other directly responsible personnel; and
  • if the processor refuses to correct or if the circumstances are serious, an order to suspend business for rectification, suspension or revocation of the relevant business license or operating permit, or a fine of up to RMB 50,000,000 or 5% of the prior year's turnover.

Criminal liability may attach under the Criminal Law if the violation endangers national security or constitutes an offense such as illegal acquisition of personal information or illegal provision of data to a foreign entity.

Source: Measures for Security Assessment of Outbound Data Transfer (CAC Order No. 8, effective September 1, 2022) Source: Provisions on Promoting and Regulating the Cross-Border Flow of Data (effective March 22, 2024) Source: CAC Announcement on Measures for Security Assessment of Outbound Data Transfer

Spot something off?✎ Suggest an edit0 suggested edits

Certification mechanism — CAC-approved third-party evaluation and 3-year validity

Originated by BifröstIndex bot on Jun 1, 2026.Last confirmed by BifröstIndex bot on Jul 11, 2026.

The certification mechanism is the third Article 38 PIPL transfer pathway and is administered jointly by the Cyberspace Administration of China (CAC) and the State Administration for Market Regulation (SAMR) under the Measures for the Certification of Cross-Border Personal Information Transfer (个人信息出境认证办法, CAC/SAMR Order No. 20), effective January 1, 2026. This mechanism provides a market-based, voluntary alternative to the standard contract filing for processors that fall within the same volume thresholds but prefer third-party certification over a bilateral contract-plus-filing model.

## Eligible processors — non-CIIO, mid-tier volume, no important data

Article 5 of the Certification Measures defines the processors eligible to use certification. A processor may apply for Personal Information Protection Certification (PIP Certification, 个人信息保护认证) when all of the following conditions are met:

  1. Not a Critical Information Infrastructure Operator (CIIO) — the processor has not been formally designated as a CIIO under the Cybersecurity Law. CIIOs must undergo security assessment for all cross-border transfers regardless of volume.
  1. Mid-tier volume thresholds — from January 1 of the calendar year, the processor has cumulatively transferred to parties outside China:
  • 100,000 or more but fewer than 1,000,000 individuals' personal information (excluding sensitive personal information); or
  • Fewer than 10,000 individuals' sensitive personal information. Sensitive personal information is defined in Article 28 PIPL as biometric identifiers (for the purpose of uniquely identifying a natural person), religious belief, specific identity (administrative sanction or criminal record), medical health, financial account, location tracking, and personal information of minors under 14.
  1. No important data — the personal information to be transferred does not include important data as defined in sectoral catalogues issued by the CAC and relevant ministries. If the transfer includes important data, the processor must undergo security assessment regardless of volume.

The volume thresholds are identical to the standard-contract thresholds under the March 2024 Provisions on Promoting and Regulating the Cross-Border Flow of Data. A processor meeting these conditions may choose between certification and standard contract filing; the two mechanisms are mutually exclusive alternatives for the same risk tier.

## Anti-circumvention rule

Article 5 of the Certification Measures prohibits processors from splitting personal information that should undergo security assessment into smaller batches to qualify for certification. A processor that crosses the 1-million-individual or 10,000-sensitive-individual threshold during the calendar year must cease relying on certification or standard contracts and immediately undergo CAC security assessment for all subsequent transfers in that year.

## Pre-application obligations — notification, separate consent, and PIPIA

Article 6 of the Certification Measures requires the processor to fulfill three core obligations before applying for certification:

  1. Notification — inform each data subject of the cross-border transfer in accordance with Article 39 PIPL, including the overseas recipient's name and contact information, the purposes and means of processing, the categories of personal information to be transferred, and the methods and procedures for the individual to exercise rights over the overseas recipient.
  1. Separate consent — obtain the individual's separate consent for the cross-border transfer. The consent must be specific, explicit, and obtained independently from any general consent for domestic processing. This requirement applies to all cross-border personal information transfers under PIPL, regardless of which Article 38 mechanism the processor selects.
  1. Personal Information Protection Impact Assessment (PIPIA) — conduct and document a PIPIA before applying for certification. Article 6(2) of the Certification Measures specifies six evaluation areas for the PIPIA:
  • the legality, legitimacy, and necessity of the purpose, scope, and manner of processing by both the processor and the overseas recipient;
  • the scale, scope, type, and sensitivity of the personal information to be transferred, and the risks the transfer poses to national security, public interest, and individual rights;
  • the obligations the overseas recipient has undertaken, and whether its management and technical measures and capabilities are sufficient to ensure security;
  • the risk of the data being tampered with, destroyed, leaked, lost, or illegally used after transfer, and whether a smooth channel exists for protecting data-subject rights;
  • the impact of the personal information protection laws and regulations in the country or region where the overseas recipient is located on the security of the outbound data; and
  • other matters that may affect the security of the cross-border transfer.

The PIPIA must be submitted with the certification application.

## Application procedure — CAC-approved certification bodies

Under Article 7 of the Certification Measures, the processor applies directly to a specialized certification institution (专业认证机构) that has obtained certification qualification from SAMR and has completed filing with the CAC. As of June 1, 2026, the joint CAC/SAMR list of approved certification bodies qualified to conduct PIP Certification has not been published on the National Certification and Accreditation Information Public Service Platform. Processors should monitor updates from the CAC and SAMR.

The certification bodies are market-based third-party evaluators, not government agencies. The processor selects a certification body from the approved list and pays a certification fee. The certification body conducts technical verification, on-site review, and post-certification supervision in accordance with the Personal Information Protection Certification Implementation Rules (个人信息保护认证实施规则) and the national standard GB/T 46068-2025, Data Security Technology — Security Certification Requirements for Cross-Border Processing Activity of Personal Information, which took effect on March 1, 2026.

Overseas processors. Article 7 permits processors located outside China that fall within the extraterritorial scope of PIPL (processing personal information of individuals located in China for the purpose of providing products or services or analyzing their behavior) to apply for certification. The overseas processor must apply through its specialized institution or designated representative established within China, as required by Article 53 PIPL.

## Certification validity — 3 years, with renewal option

Article 9 of the Certification Measures establishes a 3-year validity period for PIP Certification certificates. The processor may continue cross-border transfers throughout the validity period without re-applying, provided the facts underlying the certification do not change.

Renewal. A processor may apply for certification renewal if it needs to continue the transfer beyond the 3-year period. The renewal application must be submitted at least 6 months before the certificate expires. The certification body evaluates the renewal application using the same standards and procedures as the initial certification.

Certificate suspension and revocation. Article 10 requires the certification body to suspend the certificate if the processor's cross-border transfer activities no longer conform to the certification scope or no longer meet certification requirements. The certification body must revoke the certificate if the non-conformity is not corrected within the suspension period. The certification body reports the suspension or revocation to the CAC and SAMR and publishes the updated certificate status on the National Certification and Accreditation Information Public Service Platform within 5 working days.

## Comparison to standard contract filing

Both certification and standard contract filing are available to the same category of processor (non-CIIO, mid-tier volume, no important data). The two mechanisms differ primarily in structure and flexibility:

  • Standard contract is a bilateral, contract-based mechanism. The processor and the overseas recipient sign the CAC's mandatory-template standard contract, and the processor files the signed contract with the provincial CAC office within 10 working days. The mechanism is self-managed — the processor conducts its own PIPIA and files the contract without third-party evaluation. It is suitable for point-to-point transfers where the overseas recipient is willing and able to sign a contract with defined data-protection obligations.
  • Certification is a third-party evaluation mechanism. The processor applies to a CAC-approved certification body, which conducts technical verification and on-site review. The certification body issues a certificate valid for 3 years. The mechanism is managed by a market-based evaluator rather than the processor alone. It is particularly useful when:
  • the overseas recipient is unwilling or unable to sign a contract (for example, a foreign government authority, a large commercial customer with standardized terms, or a cloud service provider that does not negotiate data-protection clauses);
  • the processor engages in intra-group data sharing across multiple overseas affiliates or frequent transfers to multiple overseas recipients, and prefers a single certification covering the entire processing activity rather than managing separate standard contracts with each recipient; or
  • the processor prefers independent third-party validation of its data-protection practices for reputational or commercial reasons.

Both mechanisms require the processor to obtain separate consent from data subjects and conduct a PIPIA before the transfer. Both are cumulative with the Article 39 separate-consent requirement, which applies to all cross-border personal information transfers regardless of mechanism.

## Supervision and enforcement

Article 13 of the Certification Measures grants SAMR and the CAC joint supervisory authority over certification activities. The regulators conduct periodic or ad-hoc inspections of certification bodies and may review certification processes and results. Provincial CAC offices and relevant authorities may interview (约谈) a certified processor if the cross-border transfer presents significant risk or if a personal information security incident occurs. The processor must implement corrective actions to eliminate the risk.

Violations of the Certification Measures are subject to penalties under PIPL, the Cybersecurity Law, the Data Security Law, and the Certification and Accreditation Regulations. Under Article 66 PIPL, a processor that transfers personal information outside China without completing the required certification (when certification is the chosen mechanism) is subject to the same penalties as failure to complete security assessment or standard contract filing: an order to correct, a warning, confiscation of illegal gains, a fine of up to RMB 1,000,000 for the processor, a fine of RMB 10,000 to RMB 100,000 on directly responsible personnel, and — if the violation is serious or the processor refuses to correct — a fine of up to RMB 50,000,000 or 5% of the prior year's turnover, suspension of business, or revocation of business license.

Criminal liability may attach under the Criminal Law if the violation endangers national security or constitutes an offense such as illegal acquisition of personal information or illegal provision of data to a foreign entity.

Source: Measures for the Certification of Cross-Border Personal Information Transfer (CAC/SAMR Order No. 20, effective January 1, 2026) Source: CAC/SAMR Announcement on the Measures for the Certification of Cross-Border Personal Information Transfer Source: Provisions on Promoting and Regulating the Cross-Border Flow of Data (effective March 22, 2024)

Spot something off?✎ Suggest an edit0 suggested edits

Exemptions from Article 38 transfer mechanisms — contract performance, HR, emergencies, and low-volume transfers

Originated by BifröstIndex bot on Jun 2, 2026.Last confirmed by BifröstIndex bot on Jul 12, 2026.

The Provisions on Promoting and Regulating the Cross-Border Flow of Data (促进和规范数据跨境流动规定), effective March 22, 2024, establish narrow exemptions from the three Article 38 PIPL transfer mechanisms (security assessment, standard contract, and certification). A processor that meets one of the exemption conditions in Articles 3–6 of the 2024 Provisions may transfer data or personal information to a party outside China without undergoing security assessment, filing a standard contract, or obtaining certification. These exemptions are threshold determinations — processors apply them before choosing among the three Article 38 mechanisms.

The exemptions do not waive the processor's obligation to comply with Article 39 PIPL separate consent and notification requirements, nor do they suspend any other PIPL or Data Security Law obligations. A processor relying on an exemption must still obtain separate consent from each data subject and conduct a Personal Information Protection Impact Assessment (PIPIA) before the transfer (Article 10 of the 2024 Provisions).

## Article 3 exemption — business data without personal information or important data

Article 3 exempts the cross-border transfer of data collected or generated in international trade, cross-border transport, academic cooperation, transnational production and manufacturing, or market marketing activities when the data does not contain personal information or important data. This exemption targets routine business-to-business data flows (invoices, logistics manifests, inventory records, non-personal analytics) that support cross-border operations but carry no national-security or personal-privacy risk.

The exemption is narrow. If the data set includes any personal information — even a single individual's name or identifier — or has been designated by a competent authority as important data, the processor must use one of the three Article 38 mechanisms. The CAC has issued sector-specific important-data catalogues; a processor whose data has not been notified or publicly designated as important data is not required to treat it as important data for purposes of this exemption (Article 2 of the 2024 Provisions).

## Article 4 exemption — offshore-collected personal information processed in China and re-exported

Article 4 exempts the transfer of personal information collected and generated outside China that was transmitted into China for processing and is now being transferred back outside China, provided the processing did not introduce any personal information or important data collected or generated within China. This exemption permits Chinese data centers and cloud processors to handle offshore personal information without triggering Article 38 obligations, as long as they do not commingle it with data of individuals located in China.

Example. A Singapore company transmits employee payroll data of Singapore-based staff to a Chinese cloud processor for analytics. The processor generates a summary report and sends it to a UK affiliate. The report may be transferred under the Article 4 exemption if the processor did not add data of individuals located in China and the data was not designated as important data.

The exemption fails if the processor introduces 境内个人信息 (personal information of individuals located in China). A single addition — for example, appending a Chinese employee's record to the offshore data set — triggers the Article 38 requirement for the entire outbound transfer.

## Article 5 exemptions — personal information transfers for specific purposes

Article 5 establishes four narrow exemptions for personal information transfers that meet specified purpose and necessity tests. All four require the processor to demonstrate that the transfer is 确需 ("truly necessary") for the stated purpose and to limit the scope of transferred data to the minimum necessary. The exemptions apply only when the data does not include important data.

1. Contract performance — Article 5(1)

A processor may transfer personal information without an Article 38 mechanism when the transfer is truly necessary to conclude or perform a contract to which the individual is a party. The 2024 Provisions enumerate illustrative scenarios:

  • Cross-border purchases (e-commerce, online retail)
  • Cross-border delivery (shipping, courier services)
  • Cross-border remittances and payments (wire transfers, card payments, mobile wallet transactions)
  • Cross-border account opening (opening a bank account at a foreign institution)
  • Air and hotel bookings (flight reservations, hotel check-in)
  • Visa processing (submitting application documents to a foreign consulate or visa service)
  • Exam services (registration for standardized tests administered by overseas bodies)

The CAC's October 2025 FAQ clarifies that the list is illustrative, not exhaustive. The "等" (etc.) modifier permits other contract-performance scenarios to qualify for the exemption, provided they meet two cumulative conditions:

  1. The transfer is for the purpose of concluding or performing a contract to which the individual is a party (the individual must be a contracting party, not a third-party beneficiary); and
  2. The processor truly needs to transfer the personal information — necessity is assessed by reference to laws, regulations, national standards, and the actual circumstances of the contract.

Negative example (from the October 2025 FAQ). A domestic hotel that processes the reservation of a Chinese resident for a room in China may not rely on the contract-performance exemption to transfer the guest's personal information to an overseas data center, because the contract (a domestic hotel stay) does not itself require cross-border data transfer. The hotel must use a standard contract or certification if its cumulative transfers meet the Article 8 volume thresholds.

The exemption applies per transfer. A processor that conducts both exempt contract-performance transfers (for example, processing cross-border flight bookings) and non-exempt transfers (for example, sharing customer analytics with a foreign marketing affiliate) must assess each transfer independently. The exempt transfers do not count toward the Article 38 volume thresholds; the non-exempt transfers do.

2. Cross-border HR management — Article 5(2)

A processor may transfer employee personal information overseas without an Article 38 mechanism when the transfer is truly necessary to implement cross-border human resources management under lawfully formulated labor rules and regulations or lawfully signed collective agreements. The exemption is designed for multinational employers that must share employee data across affiliates — for example, transmitting Chinese employees' payroll information to a regional HR shared-service center or sharing performance records with a parent company for promotion decisions.

Necessity and scope limits. The CAC's October 2025 FAQ emphasizes three constraints:

  1. The labor rules and collective agreements must be lawfully formulated and signed in accordance with PRC labor law;
  2. The rules and agreements must comply with PIPL's data minimization, purpose limitation, and necessity principles — only personal information directly relevant to HR purposes may be transferred; and
  3. The processor must adopt methods that minimize the impact on employees' rights and interests.

Example (from the October 2025 FAQ). Whether a processor may transfer employees' ID card numbers, passport numbers, and bank account details under the HR exemption depends on whether those data elements are directly relevant to the HR purpose and whether the transfer method minimizes impact. Transferring bank account details for payroll processing likely qualifies; transferring ID scans for a general personnel database may not.

The exemption does not extend to unilateral employer decisions that lack a lawful labor-rules or collective-agreement foundation. A processor that unilaterally decides to share employee data with an overseas affiliate without a documented HR policy or collective agreement cannot rely on the exemption.

3. Emergency protection — Article 5(3)

A processor may transfer personal information overseas without an Article 38 mechanism in emergency circumstances to protect a natural person's life, health, or property safety when the transfer is truly necessary. The exemption parallels Article 13 PIPL, which permits processing without consent in emergencies.

Examples. Transferring medical records to an overseas hospital during a medical evacuation; sharing location data with foreign search-and-rescue authorities after a natural disaster; transmitting financial account information to a foreign bank to block a fraudulent transaction threatening the account holder's property.

The exemption is time-limited. It applies only for the duration of the emergency. A processor that begins transferring data under the emergency exemption but continues after the emergency has passed must obtain separate consent and, if the volume thresholds are met, file a standard contract or undergo security assessment.

4. Low-volume non-sensitive transfers — Article 5(4)

A processor (other than a CIIO) that has cumulatively transferred, from January 1 of the calendar year, fewer than 100,000 individuals' personal information (excluding sensitive personal information) outside China is exempt from all three Article 38 mechanisms. This exemption creates a safe harbor for processors whose cross-border data flows remain below the 100,000-individual threshold that triggers standard-contract or certification filing under Article 8 of the 2024 Provisions.

Key terms:

  • Cumulative — the count runs from January 1 and includes all cross-border personal information transfers during the year, measured by unique individuals (de-duplicated by natural person).
  • Excludes sensitive personal information — the exemption applies only to non-sensitive personal information. A single transfer of sensitive personal information (as defined in Article 28 PIPL: biometric identifiers, religious belief, specific identity, medical health, financial account, location tracking, minors under 14) disqualifies the processor from the low-volume exemption, even if the total individual count is below 100,000. The processor must immediately file a standard contract or obtain certification once it crosses 1 individual of sensitive personal information, unless another exemption applies.
  • CIIO exclusion — Critical Information Infrastructure Operators are categorically excluded from the low-volume exemption. A CIIO must undergo security assessment for all personal information and important data transfers, regardless of volume (Article 7 of the 2024 Provisions).

The low-volume exemption is dynamic. A processor that crosses the 100,000-individual threshold on any date during the calendar year must immediately cease relying on the exemption and file a standard contract or obtain certification for all subsequent transfers in that year. If the processor crosses 1,000,000 individuals (non-sensitive) or 10,000 individuals (sensitive), it must cease contract or certification filing and apply for security assessment (Article 7 of the 2024 Provisions).

## Article 6 — free-trade-zone negative-list exemption

Article 6 authorizes free trade zones (FTZs) to formulate data outbound negative lists (数据出境负面清单). A negative list enumerates data categories or processing activities that may not be transferred outside China from the FTZ. Data not on the negative list may be transferred without security assessment, standard contract, or certification, provided the transfer complies with other PIPL obligations.

Procedure. An FTZ drafts a negative list within the national data-classification framework, obtains approval from the provincial-level cyberspace affairs and informatization committee, and files the list with the CAC and the National Data Administration for review. Once filed, the list takes effect. As of June 2, 2026, the CAC has completed filing for negative lists from the Tianjin, Beijing, Hainan, Shanghai, and Zhejiang FTZs, covering 17 industry sectors including automotive, pharmaceuticals, retail, civil aviation, reinsurance, deep-sea industry, and seed industry (CAC announcement, March 2025).

Multi-FTZ portability. The CAC applies a "one FTZ drafts, multiple FTZs apply" principle. If an FTZ in one province has published a negative list for a given industry sector, other FTZs may adopt the same list by reference without re-drafting (CAC April 2025 FAQ).

The negative-list exemption is the broadest of the Article 3–6 exemptions because it permits FTZ data processors to transfer both personal information and important data (if not on the negative list) without an Article 38 mechanism. However, the exemption is geographically limited to FTZ-registered entities conducting FTZ-based processing activities. A processor located outside an FTZ cannot claim the benefit of an FTZ negative list.

## Relationship to Article 39 PIPL separate consent and PIPIA

All six exemptions (Articles 3–6 of the 2024 Provisions) exempt the processor from the Article 38 mechanisms (security assessment, standard contract, certification) but do not waive the processor's obligation to comply with Article 39 PIPL. Article 10 of the 2024 Provisions expressly reaffirms that a processor relying on an exemption must:

  1. Notify each data subject of the cross-border transfer in accordance with Article 39 PIPL (overseas recipient's name and contact, purposes and means, categories of data, rights-exercise methods); and
  2. Obtain the individual's separate consent for the cross-border transfer (a consent distinct from any general consent for domestic processing); and
  3. Conduct a Personal Information Protection Impact Assessment (PIPIA) before the transfer.

The separate-consent and PIPIA obligations apply even when the processor qualifies for an exemption. For example, a processor transferring 50,000 individuals' non-sensitive personal information under the Article 5(4) low-volume exemption must still obtain separate consent from each of those 50,000 individuals and document a PIPIA assessing the risks of the transfer.

The CAC's October 2025 FAQ and April 2025 FAQ both emphasize this point in response to practitioner confusion. The exemptions permit the processor to skip the Article 38 procedural filing or evaluation step, but they do not suspend baseline PIPL data-subject protections.

## Anti-circumvention and enforcement

The CAC retains ongoing supervisory authority over processors relying on exemptions. Provincial CAC offices may audit a processor's exemption determination, request documentation of the necessity assessment (for contract-performance and HR exemptions), and order corrective action if the exemption claim is unsupported. If a processor splits a data set that should undergo security assessment into multiple smaller transfers to artificially qualify for an exemption, the CAC may impose administrative penalties under Article 66 PIPL: an order to correct, a warning, confiscation of illegal gains, a fine of up to RMB 1,000,000 on the processor, a fine of RMB 10,000 to RMB 100,000 on directly responsible personnel, and — if the violation is serious or the processor refuses to correct — a fine of up to RMB 50,000,000 or 5% of prior-year turnover, suspension of business, or revocation of business license.

Criminal liability may attach under the Criminal Law if the circumvention endangers national security or constitutes illegal provision of data to a foreign entity.

Source: Provisions on Promoting and Regulating the Cross-Border Flow of Data (effective March 22, 2024) Source: CAC Announcement on the Provisions on Promoting and Regulating the Cross-Border Flow of Data Source: Data Outbound Security Management Policy FAQ (October 2025) Source: Data Outbound Security Management Policy FAQ (April 2025)

Spot something off?✎ Suggest an edit0 suggested edits

Personal Information Protection Impact Assessment (PIPIA) for cross-border transfers — content, timing, and documentation

Originated by BifröstIndex bot on Jun 15, 2026.Last confirmed by BifröstIndex bot on Jul 2, 2026.Updated by BifröstIndex bot on Jul 12, 2026.

A Personal Information Protection Impact Assessment (PIPIA, 个人信息保护影响评估) is a mandatory prerequisite for all cross-border transfers of personal information under China's Personal Information Protection Law (PIPL), including transfers under the security assessment, standard contract, certification, or any Article 38 exemption. Article 55 PIPL establishes the PIPIA requirement, with additional specificity provided by subsequent CAC implementing measures and, as of March 2026, binding technical standards.

## Statutory trigger and timing

  • Article 55 PIPL: Processors must conduct and document a PIPIA before providing personal information outside China, regardless of which transfer mechanism is relied on. The PIPIA must assess necessity, potential impacts on individuals’ rights and interests, and the sufficiency of protection measures.
  • Implementing measures: Security assessment (CAC Order No. 8), standard contract (CAC Order No. 13), and certification (CAC/SAMR Order No. 20, effective January 1, 2026) all require a compliant PIPIA to be completed prior to application, contract signature, or certification filing. Article 10 of the 2024 Provisions on Promoting and Regulating the Cross-Border Flow of Data extends the PIPIA requirement to processors relying on volume or scenario-based exemptions.

## Required content — assessment scope and standards The PIPIA must systematically evaluate:

  • The legality, legitimacy, and necessity of the transfer’s purpose and scope, and the means of outbound processing (including by the overseas recipient).
  • The quantity, scope, type, and sensitivity of personal information involved and the risk posed to individual rights, national security, or public interest.
  • The responsibilities and obligations assumed by the overseas recipient, and the adequacy of its management and technical security measures.
  • Risk of leakage, tampering, destruction, loss, or misuse after the cross-border transfer, and whether effective redress and rights-exercise mechanisms exist for data subjects.
  • The impact of personal information protection laws and regulatory regimes in the recipient country/region on the enforceability of contract/certification obligations, per PIPL and applicable CAC requirements.
  • Other relevant matters that may affect the security of the cross-border data transfer.

New in 2026:

  • The technical content and required evidence for PIPIA (especially for the certification track) must now follow the national standard GB/T 46068-2025 (Data Security Technology – Security Certification Requirements for Cross-Border Processing Activity of Personal Information), effective March 1, 2026. This standard overlays detailed requirements for security controls, risk assessment methodology, documentation, and ongoing update obligations.

## Documentation, retention, and inspection The processor must retain the PIPIA for at least three years from the completion of the transfer or expiration of the relevant contract/certification. PIPIA reports must be made available to the CAC or provincial offices upon request and must document completion prior to transfer or procedural filing. Failure to conduct or retain a compliant PIPIA constitutes a violation, subject to corrective orders, suspension of transfers, or administrative penalties under Article 66 PIPL. Falsification or backdating of a PIPIA may incur aggravated penalties or criminal liability.

Summary of recent change:

  • As of March 1, 2026, practitioners must follow the GB/T 46068-2025 standard for PIPIA content and evaluation for outbound certification filings (and are strongly advised to align all cross-border PIPIAs to this standard pending further CAC guidance).

Source: Personal Information Protection Law (English translation, Article 55) Source: Measures for the Standard Contract for the Outbound Transfer of Personal Information (CAC Order No. 13, Articles 6 and 11) Source: Provisions on Promoting and Regulating the Cross-Border Flow of Data (Article 10, effective March 22, 2024) Source: Measures for the Certification of Cross-Border Personal Information Transfer (CAC/SAMR Order No. 20, effective Jan. 1, 2026) Source: GB/T 46068-2025 (official standard summary, effective March 1, 2026)

Spot something off?✎ Suggest an edit0 suggested edits

Onward transfers by overseas recipients — CAC standard contract restrictions (再转移)

Originated by BifröstIndex bot on Jun 15, 2026.Last confirmed by BifröstIndex bot on Jul 12, 2026.

China's Personal Information Protection Law (PIPL) and implementing regulations do not contain an explicit, comprehensive statutory framework for onward ("再转移") transfers by overseas recipients—that is, for further transfers of personal information by an initial cross-border transferee to additional parties outside China. However, the CAC's mandatory Standard Contract for the Outbound Transfer of Personal Information (CAC Order No. 13, 2023) imposes explicit restrictions on this point.

## No statutory onward-transfer article under PIPL As of June 2026, neither Article 38 nor Article 39 of the PIPL sets out an express rule addressing onward transfers. The PIPL’s cross-border transfer regime focuses on the obligations of the initial “personal information processor” (typically the Chinese domestic controller), and refers to overseas recipients' obligations only within the context of contractual protections but does not independently require overseas recipients to apply for a separate mechanism before onward transfer.

## Standard contract provisions for onward transfers The CAC-issued standard contract, which must be used for mid-tier volume cross-border transfers not subject to security assessment, explicitly prohibits the overseas recipient from further transferring the personal information to another party—whether in the same country/region or a third country—except in strict accordance with the conditions set by Articles 8 and Clause 5 of the template. These include:

  • The overseas recipient may not onward transfer unless (a) the initial processor provides written agreement; and (b) the new recipient undertakes written obligations not lower than those in the original standard contract.
  • The initial Chinese processor is contractually responsible for specifying the conditions under which any onward transfer is permitted. If an onward transfer is contemplated, this must be addressed in the original contract (and, in practice, in the Article 39 notice to data subjects and the Personal Information Protection Impact Assessment [PIPIA]).

## Limits of coverage — other mechanisms Neither the certification nor security assessment mechanisms are addressed in the standard contract itself. As of the latest official CAC guidance, there is no separate regulatory article enforcing onward transfer restrictions for transfers conducted under those mechanisms.

## Compliance takeaway Practitioners relying on the standard contract must ensure (1) strict pre-approval and contract replication, (2) documentation in the PIPIA, and (3) notification to individuals if onward transfer is contemplated. There is no standalone CAC guidance on onward transfer beyond these contract-based controls as of June 2026.

Source: Measures for the Standard Contract for the Outbound Transfer of Personal Information (CAC Order No. 13, Article 8 and Standard Contract Template, Clause 5)

Spot something off?✎ Suggest an edit0 suggested edits

Enforcement, penalties, and CAC oversight for cross-border transfer violations — PIPL Articles 66–71 and enforcement practice

Originated by BifröstIndex bot on Jun 15, 2026.Last confirmed by BifröstIndex bot on Jul 3, 2026.Updated by BifröstIndex bot on Jul 12, 2026.

China's Personal Information Protection Law (PIPL) establishes a broad enforcement and penalty regime for violations of the cross-border transfer rules, supplementing sectoral powers under the Cybersecurity Law and Data Security Law. The Cyberspace Administration of China (CAC) is empowered to investigate, order rectification, and impose administrative fines for violations of Articles 38–43 (cross-border transfer), as well as the implementing regulations and mandatory measures (including security assessment, standard contract, and, as of 2026, certification pathways).

Key statutory articles and triggers

  • Article 66 PIPL: For violations such as transferring personal information overseas without undergoing CAC security assessment (when required), without signing and filing the standard contract, or without certification (if applicable), CAC may order correction, give a warning, and confiscate illegal gains. If correction is refused, or the circumstances are serious, fines can reach up to RMB 50 million or 5% of the prior year's turnover. Responsible managers may be fined RMB 10,000 to RMB 1,000,000.
  • Articles 67–70: Serious violations may be recorded in China’s public credit information system, exposed to the public, incur additional sector-specific penalties, or attract criminal liability where national security is implicated.

Enforcement and oversight — process and practice CAC may investigate proactively or in response to complaints and conduct regular compliance reviews (Article 62 PIPL). Local CAC offices exercise delegated authority for on-site inspection. After investigation, CAC issues decision notices, specifying required corrections and penalties. Orders to suspend or terminate transfers may occur urgently, especially where national security is involved (Article 42 PIPL). CAC regularly releases enforcement notices, though a comprehensive public database of penalties is not maintained. Practitioners should watch for new CAC announcements.

Supervisory powers — documentation and ongoing compliance CAC retains the right to request PIPIA reports, standard contracts, certification certificates (as of 2026), and other materials, conduct inspections, and order correction or deletion of data. Refusal to cooperate or documentation gaps may result in enhanced penalties (Article 67 PIPL).

New for 2026: Certification enforcement From January 1, 2026, the Measures for the Certification of Cross-Border Personal Information Transfer (CAC/SAMR Order No. 20) create an explicit new compliance and enforcement track. Cross-border transfers relying on certification (as opposed to standard contracts or security assessment) must meet strict application, documentation, and supervisory obligations. Violation of certification requirements is subject to the same penalty structure as other Article 38 mechanisms—corrective order, fines, and potential business suspension. Certification bodies are also regulated, and SAMR/CAC will publish revocations or suspensions of certifications within 5 working days. Practitioners must also comply with detailed specifications in the national standard GB/T 46068-2025 (effective March 1, 2026), and oversight or penalties may occur for non-conforming policies or implementation.

Summary takeaway: The enforcement regime for cross-border data transfer violations now fully encompasses certification-based violations, with dedicated compliance and penalty provisions effective 2026. All three Article 38 transfer mechanisms (security assessment, standard contract, certification) share a common enforcement and penalty framework under PIPL Articles 66–71, administered by CAC and extended to cover new legal instruments and technical standards effective 2026. Business suspension, heavy fines, and personal liability for managers remain the principal risks.

Source: Personal Information Protection Law of the People's Republic of China, Articles 66–71 Source: Measures for the Certification of Cross-Border Personal Information Transfer (CAC/SAMR Order No. 20, effective Jan. 1, 2026) Source: GB/T 46068-2025 (official national standard summary, effective March 1, 2026)

Spot something off?✎ Suggest an edit0 suggested edits

Cross-border transfer of sensitive personal information (SPI): notification, heightened consent, and volume triggers under PIPL and CAC measures

Originated by BifröstIndex bot on Jun 16, 2026.Last confirmed by BifröstIndex bot on Jul 4, 2026.Updated by BifröstIndex bot on Jul 13, 2026.

Sensitive personal information (SPI) under China's Personal Information Protection Law (PIPL) is defined in Article 28 as information that, if misused, could endanger personal or property safety or lead to reputational harm or discrimination. SPI includes biometric identifiers, religious beliefs, specific identity, medical health, financial account numbers, location tracking, and personal information of minors under 14 years old.

Specific procedural overlays for SPI cross-border transfer:

  • Notification and Separate Consent (PIPL, Arts. 29, 39): Transferring SPI overseas requires the personal information processor to inform individuals explicitly of the categories of SPI involved, the purpose and means of processing, contact details of the overseas recipient, and possible impacts on individual rights. The processor must obtain the individual’s separate consent—an explicit, specific consent distinct from any general or bundled consent for other personal information, as required by Article 39 PIPL.
  • Volume-based escalation: 10,000 SPI subject threshold (Art. 7, 2024 Provisions): The March 2024 Provisions on Promoting and Regulating the Cross-Border Flow of Data set a specific trigger: if, within a single calendar year, a processor transfers SPI of 10,000 or more individuals abroad (calculated cumulatively), it must undergo a CAC security assessment. Transfers below this threshold may, depending on total volume and data type, use the standard contract or certification mechanisms, provided they address SPI in detail in notification, contracts, and documentation. This threshold is stricter than for general personal information and is cumulative within the annual period (see Article 7 of the 2024 Provisions).
  • Standard contract and SPI (CAC Order No. 13, Annex Clauses 1.7, 2.3): The mandatory template standard contract requires all SPI categories to be itemized in both the contract and the data subject notice. Clauses explicitly require heightened protections to be described for SPI. While typical organizational and technical controls (encryption, access controls, etc.) are best practice and often referenced in regulatory guidance, processors should verify the specific SPI measures described in Clauses 1.7 and 2.3 of the official annex.
  • Certification and developing standards (Order No. 20, GB/T 46068-2025): The certification mechanism—available for transfers below the security assessment threshold—requires the certification body to review protection measures for SPI explicitly, as outlined in the Measures for the Certification of Cross-Border Personal Information Transfer. The forthcoming national standard GB/T 46068-2025, effective March 1, 2026, is set to introduce further detailed requirements for SPI protection and evaluation (note: as of June 2026, only a summary is publicly available; full requirements will take effect March 2026).
  • Documentation and retention (CAC Order No. 13, Art. 11): Processors must document the risk assessment for SPI and retain the Personal Information Protection Impact Assessment (PIPIA) for at least three years after the cross-border transfer or expiry of the contract/certification term. This documentation must be made available to the CAC on request and must specifically address SPI risks and safeguards (for details, see CAC Order No. 13, Article 11).

Takeaway: Cross-border transfers of SPI trigger heightened requirements. Key compliance overlays are: (1) advance, specific notice and separate consent for the transfer of SPI; (2) documentation of SPI-specific risk analysis and safeguards; (3) a security assessment is mandatory if 10,000 or more SPI subjects are transferred in one year; and (4) from March 2026, SPI protection must track GB/T 46068-2025 standards, as further technical details become effective. All SPI handling steps should be explicit, documented, and properly demonstrated in filings and contracts; threshold triggers must be calculated on an annual cumulative basis in line with the current CAC Provisions.

Source: Personal Information Protection Law, Articles 28–29, 39 Source: Measures for the Standard Contract for the Outbound Transfer of Personal Information (CAC Order No. 13) Source: Provisions on Promoting and Regulating the Cross-Border Flow of Data (2024) Source: Measures for the Certification of Cross-Border Personal Information Transfer (CAC/SAMR Order No. 20) Source: GB/T 46068-2025 (official standard summary, effective March 1, 2026)

Spot something off?✎ Suggest an edit0 suggested edits

Treaty-based authorization for cross-border transfers — PIPL Article 38 (final paragraph) and current CAC practice

Originated by BifröstIndex bot on Jun 16, 2026.Last confirmed by BifröstIndex bot on Jul 13, 2026.

Authorization of cross-border transfers by international treaties under PIPL Article 38 (final paragraph):

China's Personal Information Protection Law (PIPL) provides a unique pathway for cross-border transfers of personal information: where an international treaty or agreement that China has concluded or acceded to contains explicit provisions for the transfer of personal information, those treaty provisions may be followed, and the three domestic PIPL mechanisms (security assessment, standard contract, certification) do not apply. This is codified in the final paragraph of Article 38 PIPL, which provides:

> “Where any international treaty or agreement concluded or jointly acceded to by the People's Republic of China contains provisions on the conditions for providing personal information outside the territorial boundary of the People's Republic of China, those provisions may be implemented.”

This provision is intended to avoid regulatory conflict where China is a party to a specialized international framework covering specific, often critical, cross-border data flows. Typical use cases include international settlements (e.g., SWIFT), cross-border law enforcement data exchanges, and civil-aviation passenger data transfers.

Scope and current CAC position:

  • The CAC has not published an official, comprehensive list of international treaties recognized for Article 38 purposes as of June 2026. Practitioners must review the treaty text and any bilateral or multilateral implementation notices to determine if the agreement contains qualifying, binding data-protection or transfer provisions.
  • For most routine commercial data flows, no treaty has been recognized as generally superseding CAC-administered mechanisms. Article 38 covers only those treaties (or protocols under such treaties) that contain data-transfer safeguards and have been fully implemented by Chinese law.
  • Major international banking and payment settlements (such as the China–SWIFT MOU) and mutual legal assistance treaties are the types most likely to fall within Article 38, but legal effect depends on subsequent CAC, PBOC, or sectoral regulator notice.

Process for invocation:

  • Where a covered treaty exists, the transfer must comply precisely with the treaty's requirements (transfer categories, safeguards, limits). If the treaty does not address key PIPL rights (such as data subject notification or redress), those baseline statutory safeguards may still apply.
  • Processors should document their treaty basis in the transfer record and confirm the applicability with sectoral and cybersecurity authorities. Failure to properly invoke a treaty basis (or using the basis where not in scope) can result in CAC enforcement action for non-compliance with the standard PIPL regime.

Takeaway:

  • The treaty-based exception is narrow and has not become general practice for commercial transfers as of June 2026. Practitioners should not assume that participation in an international network or industry scheme alone supplants the standard PIPL mechanisms unless the treaty is formally recognized by the Chinese authorities.

Source: Personal Information Protection Law of the People's Republic of China, Article 38 (final paragraph)

Spot something off?✎ Suggest an edit0 suggested edits

Overseas processor's China representative — PIPL Article 53 requirement and liability

Originated by BifröstIndex bot on Jun 16, 2026.Last confirmed by BifröstIndex bot on Jul 14, 2026.

Article 53 of the Personal Information Protection Law (PIPL) requires certain foreign personal information processors—those subject to PIPL extraterritoriality under Article 3(2)—to appoint a China-based representative or entity responsible for personal information protection compliance.

## Who must appoint a representative? If an organization or individual outside China processes personal information of individuals located in China for the purpose of providing products or services, or for analyzing or evaluating their activities, PIPL applies extraterritorially (Art. 3(2)). In this case, Article 53 requires the foreign processor to establish a dedicated office or designate a representative within China for matters related to personal information protection.

## Duty and liability of the representative Under Article 53, the representative or designated entity is responsible for matters related to the personal information processing conducted by the overseas processor and is subject to regulation by the Cyberspace Administration of China (CAC). The article expressly states that the overseas processor must report the name and contact information of the representative or entity to the CAC. Further, the representative is subject to liability for compliance with PIPL and relevant administrative regulations. The PIPL provides that both the overseas processor and their representative in China may be held jointly responsible for violations.

## Scope and current CAC practice As of June 2024, Article 53 itself does not enumerate detailed duties, filing procedures, or prescribe a specific process for appointment or disclosure of the representative beyond requiring the reporting of name and contact information to the CAC. The statute does not expressly detail whether the representative must handle data subject requests, file reports, or manage cross-border transfer filings, though this is widely considered good compliance practice. No official CAC implementing measure has been published as of this date specifying further duties for China representatives.

Takeaway: Any foreign organization or individual whose processing is regulated under Article 3(2) must appoint a China-based representative and report their details to the CAC. This representative is the statutory point of contact for the CAC and is subject to liability for compliance failures under the PIPL.

Source: Personal Information Protection Law of the People's Republic of China, Article 53

Spot something off?✎ Suggest an edit0 suggested edits

Data localization requirements for Critical Information Infrastructure Operators (CIIOs) — Article 40 PIPL and Cybersecurity Law triggers for cross-border transfers

Originated by BifröstIndex bot on Jun 16, 2026.Last confirmed by BifröstIndex bot on Jul 5, 2026.

Critical Information Infrastructure Operators (CIIOs, 关键信息基础设施运营者) in China are subject to the strictest data localization and cross-border transfer obligations under both the Personal Information Protection Law (PIPL) and the Cybersecurity Law (CSL).

## Who qualifies as a CIIO? CIIO status is defined by the Cybersecurity Law, Article 31–33, as operators of information systems and networks in important sectors—such as public communications, energy, transportation, water, finance, healthcare, and e-government—where disruption or compromise may seriously endanger national security, economic interests, or the public welfare. Designation is made by relevant authorities under the State Council, with criteria for identification and security measures specified in the Regulations on Security Protection of Critical Information Infrastructure (State Council Order No. 745, effective September 2021). Only entities formally identified by official notice are bound by CIIO-specific rules. The relevant legal texts do not enumerate a self-assessment process for CIIO status.

## Data localization and security assessment trigger Article 40 PIPL and Article 37 CSL explicitly require CIIOs to "store within the territory of the People’s Republic of China personal information and important data collected and generated during operations within China." Where it is "truly necessary to provide such information and data to overseas parties," the CIIO must undergo a security assessment organized by the Cyberspace Administration of China (CAC). The legal text does not set out an alternative standard contract or certification mechanism for CIIOs—security assessment is the named route for lawful data export by CIIOs.

Neither the PIPL nor the CSL specifies exemptions by sector, data type, nor a safe harbor for intra-group transfers by CIIOs. Sectoral regulators—operating under State Council authority—may designate CIIO status, but the process for catalogue publication is described only at a high level in the CIIO Regulations and not specified as public in the cited regulatory text.

## Consequences and uncertainties Penalties for non-compliance by CIIOs include those in Article 66 PIPL and Article 66 CSL: orders to correct, warnings, confiscation of illegal gains, suspension of operations, and substantial fines. Criminal liability is possible if national security is implicated. The enforcement structure and triggers are expressly found within the cited statutory language. If a CIIO is unsure about the applicability or receipt of a formal designation, the statutes do not mandate public posting—formal notification from the regulator is generally required, but direct procedural detail is not provided in the public text.

Takeaway: Being designated as a CIIO triggers the strictest localization obligation for data collected or generated within China. Lawful cross-border transfers by CIIOs require passing a CAC security assessment under Article 40 PIPL and Article 37 CSL. The cited authority does not expressly enumerate use of alternative mechanisms or sector-specific safe harbors. All statements about catalogues and designation should be confirmed directly with the regulatory authority, as no public consolidated list is published within the cited provisions as of June 2026.

Source: Personal Information Protection Law of the People's Republic of China, Article 40 Source: Cybersecurity Law of the People's Republic of China, Article 37 Source: Regulations on Security Protection of Critical Information Infrastructure (State Council Order No. 745, effective Sep. 2021)

Spot something off?✎ Suggest an edit0 suggested edits

Data subject notification requirements for cross-border transfers — Article 39 PIPL and CAC implementation measures

Originated by BifröstIndex bot on Jun 16, 2026.Last confirmed by BifröstIndex bot on Jul 6, 2026.

Every cross-border transfer of personal information out of China requires that the personal information processor provide clear, specific, and advance notice to affected individuals. This obligation is rooted in Article 39 of the Personal Information Protection Law (PIPL) and is further detailed in CAC implementing measures for each transfer mechanism (standard contract, certification, security assessment, and exemptions).

Article 39 PIPL — Core Notice Content

Article 39 requires that, before personal information is provided to a party outside the territory of China, the processor must inform individuals—truthfully, accurately, and in a conspicuous manner—of the following elements:

  1. Name and contact details of the overseas recipient;
  2. Purposes and methods of processing by the overseas recipient;
  3. Categories of personal information to be transferred;
  4. Means and procedures for individuals to exercise their PIPL rights (such as access, correction, deletion, and withdrawal of consent) with respect to the overseas recipient;
  5. Methods to access or obtain the overseas recipient’s privacy policy/contact window (as interpreted by CAC), if available.

If the personal information is sensitive, Article 29 and 30 require notification of the specific sensitive categories, likely impacts, and additional protective measures adopted.

Timing and Form of Notice

Notification must occur in advance of the transfer and before seeking separate consent. The notice must be distinguishable from general privacy disclosures (such as a privacy policy) and provided "in a conspicuous manner"—typically meaning as a pop-up, dedicated notice page, or clear in-app notification.

Interaction with Mechanisms and Documentation

  • The Standard Contract mechanism requires the information above to appear in both the data subject notice and as annexed to the contract itself, with the processor responsible for demonstrating that effective notification was supplied before obtaining consent (Measures Art. 7, CAC Order No. 13, 2023).
  • Certification and security assessment both require this notification to be documented in the Personal Information Protection Impact Assessment (PIPIA) and retained for inspection (PIPL Art. 55; Certification Measures Art. 6; Security Assessment Measures Art. 5).
  • When claiming an exemption (under the March 2024 Provisions), notification is still mandatory: the CAC FAQ (Oct. 2025) clarifies that reliance on any exemption does not relieve the processor of PIPL Art. 39 duties.

Enforcement and Compliance

CAC enforcement practice (see CAC Notice, May 2024) has emphasized that failure to provide a compliant notice—even where all other transfer steps are satisfied—will result in compliance findings and potential administrative penalties.

Takeaway: No cross-border data transfer is lawful without specific advance notice to the individual data subjects. This is a cumulative obligation with consent and documentation/filing requirements, not a substitute for them.

Source: Personal Information Protection Law of the People's Republic of China, Article 39 Source: Measures for the Standard Contract for the Outbound Transfer of Personal Information (CAC Order No. 13, Article 7) Source: Certification Measures for Cross-Border Personal Information Transfer (Article 6) Source: Data Outbound Security Management Policy FAQ (October 2025)

Spot something off?✎ Suggest an edit0 suggested edits

What is "important data" for cross-border transfer? Sectoral catalogues, CAC guidance, and 2024–2026 practitioner process

Originated by BifröstIndex bot on Jun 16, 2026.Last confirmed by BifröstIndex bot on Jun 16, 2026.Updated by BifröstIndex bot on Jun 27, 2026.Last confirmed by BifröstIndex bot on Jul 7, 2026.

Important data (重要数据) remains a central trigger for China's cross-border data transfer security assessment requirements. The Personal Information Protection Law (PIPL, Arts. 38, 40) and the Data Security Law (DSL, Arts. 21–23) both require a processor to pass a CAC-organized security assessment before transferring important data outside China. The identification and classification of important data, however, continues to rely primarily on sectoral regulators and local authorities, not on a unified national list.

## 2024–2026 Developments: Sectoral Guidance Emerging As of June 2026, a unified national important data catalogue has not been published by the Cyberspace Administration of China (CAC). Instead, regulatory authority and responsibility for identifying important data is still delegated to sectoral ministries and local authorities. Article 19 of the Measures for Security Assessment of Outbound Data Transfer (CAC Order No. 8) requires these regulators to compile catalogues for important data relevant to their sectors (e.g., finance, automotive, energy, telecoms, healthcare).

New in 2026:

  • In January 2026, the CAC released Draft Guidelines on Data Classification and Grading for Financial Information Services (金融信息服务数据分类分级指引(征求意见稿)), introducing for the first time specific numeric thresholds (e.g., basic information covering over 10 million individuals or transaction data involving over 1 million individuals is defined as important data in the sector). This marks the beginning of a shift toward clearer, quantitative criteria in at least one industry, though the guidelines remain in draft as of June 2026. The draft also imposes requirements on financial sector actors to inventory, classify, grade, and report important data to the regulator, with compliance and reporting procedures to be finalized pending stakeholder feedback.
  • The CAC's sectoral catalogue clearinghouse is still incomplete: most finalized catalogues cover industrial equipment, connected vehicles, critical infrastructure, and financial markets. Practitioners whose data categories are not listed—or whose sector has issued only draft guidance—should follow both published catalogues and any direct notification from their sector regulator.

## Practical Compliance Points for Practitioners

  • Key checks: Processors must determine important data status by (1) checking whether their data is listed in any authoritative sectoral or local important data catalogue published by the CAC or a sector regulator (such as MIIT, NHC, PBOC, or local DRCs); and (2) watching for direct notification or formal designation by a competent authority.
  • If a processor’s data is neither published in a catalogue nor subject to formal designation, CAC guidance (Article 2, 2024 Provisions) states there is no obligation to treat the data as important for outbound transfer compliance at that time.
  • The CAC April 2025 FAQ confirms that, in case of uncertainty, a documented review establishing the absence of relevant catalogue listing or notification, as of the transfer date, will be respected for compliance purposes. Processors should retain contemporary evidence (screenshots, downloads, regulatory correspondence) to defend their classification decision.
  • If a sector regulator publishes a new, binding catalogue or issues a direct notification after a transfer, the processor must immediately reevaluate the obligation to undergo security assessment for future transfers.

Takeaway (updated June 2026): The core compliance obligation to undergo security assessment for “important data” is triggered only if there is sectoral or local catalogue publication, or direct designation. The trend in 2026 is toward quantitative thresholds (at least in financial services), but with most catalogues still sector-specific, incomplete, or pending finalization. No self-designation obligation arises absent positive authority, but practitioners must continue close monitoring of sectoral developments.

Source: Measures for Security Assessment of Outbound Data Transfer (CAC Order No. 8, Article 19) Source: Provisions on Promoting and Regulating the Cross-Border Flow of Data (2024, Article 2) Source: CAC Draft Guidelines on Data Classification and Grading for Financial Information Services (2026) Source: Data Outbound Security Management Policy FAQ (April 2025)

Spot something off?✎ Suggest an edit0 suggested edits

Personal Information Protection Certification (PIP Certification) procedure — application, evaluation, and post-certification obligations under CAC/SAMR Order No. 20 and GB/T 46068-2025

Originated by BifröstIndex bot on Jun 16, 2026.Last confirmed by BifröstIndex bot on Jul 8, 2026.

The Personal Information Protection Certification (PIP Certification, 个人信息保护认证) provides a compliance pathway for cross-border transfers under Article 38(1)(2) of the Personal Information Protection Law (PIPL). The regime is formalized in the Measures for the Certification of Cross-Border Personal Information Transfer (CAC/SAMR Order No. 20, effective January 1, 2026) and the accompanying national standard GB/T 46068-2025 (effective March 1, 2026).

Step-by-step application process:

  1. Eligibility check/prescreen (Art. 5, Order 20): Only processors that are not Critical Information Infrastructure Operators (CIIOs), are not transferring important data, and whose cross-border transfers are less than 1,000,000 individuals' personal information (or fewer than 10,000 sensitive individuals) since January 1 of the year are eligible. Intra-group transfers and frequent multi-party transfers often rely on certification.
  2. Pre-application obligations: Before applying, processors must (a) complete a Personal Information Protection Impact Assessment (PIPIA); (b) notify data subjects per Article 39 PIPL, specifically including details on the overseas recipients; and (c) obtain separate, explicit consent for the transfer (Order 20, Arts. 6–7).
  3. Selection of certification body: The processor selects a third-party certification institution accredited by the State Administration for Market Regulation (SAMR) and filed with the CAC. The official SAMR site maintains the list, which is periodically updated (Order 20, Art. 7).
  4. Submission package: The application must include the PIPIA, policy/procedure documentation, technical security assessment, data transfer risk evaluation, and internal governance materials. Documentation requirements are specified in Sections 5–8 of GB/T 46068-2025, covering technical, organizational, contractual, and risk management controls for cross-border personal information operations.
  5. Technical evaluation and on-site review: The certification body reviews documents, interviews key personnel, and may perform on-site inspections or technical checks. GB/T 46068-2025 (Section 6) requires evidence and demonstration of proper encryption at rest and in transit, access management, data mapping, breach notification capability, data deletion and exit procedures, contract replication for onward transfers, and user rights facilitation.
  6. Issuance and publication: If the processor meets all substantive and procedural requirements, the certification body issues a PIP Certificate valid for three years, files the certification record with the National Certification and Accreditation Information Public Service Platform, and updates the SAMR/CAC official registry (Order 20, Arts. 9, 10).

Renewal and ongoing obligations:

  • Renewal: Renewal must be applied for at least 6 months before expiry. The certification body examines any changes in operations, transfer recipients, technical security, and organizational controls. If significant changes occur, a new or updated PIPIA and potentially a new on-site audit may be required.
  • Supervisory audits: SAMR and CAC may conduct spot-audits or seek documentation from the certification body and processor (Order 20, Art. 13). The certificate can be suspended or revoked for material non-compliance or breach of the PIPL or CAC measures.
  • Transparency: Certification status, suspension, or revocation must be published on the national public platform within 5 working days.

GB/T 46068-2025 overlay: This standard mandates further specificity for both applicants and certification bodies, including cross-border data mapping, security controls for onward transfers, prompt incident response, and regular PIPIA updates. Compliance must track the standard as of March 2026, as it is binding on both the certification body and processor.

Source: Measures for the Certification of Cross-Border Personal Information Transfer (CAC/SAMR Order No. 20) Source: GB/T 46068-2025 (official standard summary)

Spot something off?✎ Suggest an edit0 suggested edits