China Data Transfer Rules: What Foreign Companies Must Know

Transferring data out of China has become increasingly complex. With the Personal Information Protection Law (PIPL), Data Security Law, and various regulations, foreign companies must navigate a maze of requirements. Here's what you need to know.

The Legal Framework

Three main laws govern data in China:

When Do These Rules Apply?

The rules apply if you:

Key Point: Even if your company has no physical presence in China, PIPL can apply if you process Chinese individuals' personal information for purposes like providing products/services to them or analyzing their behavior.

Cross-Border Transfer Requirements

To transfer personal information outside China, you must use one of these mechanisms:

1. Security Assessment by CAC

Mandatory for:

This involves submitting an application to the Cyberspace Administration of China (CAC) and can take several months.

2. Standard Contractual Clauses (SCCs)

For transfers not requiring security assessment, you can use China's standard contractual clauses:

3. Certification

Obtain certification from a recognized institution. This option is less commonly used and still developing.

Practical Compliance Steps

Step 1: Data Mapping

Understand what data you collect, where it's stored, and where it flows:

Step 2: Determine Your Pathway

Based on your data volumes and business type, identify which transfer mechanism applies.

Step 3: Implement Required Measures

Step 4: Ongoing Compliance

Common Scenarios

Multinational with China Subsidiary

If your China subsidiary shares employee data, customer data, or business data with headquarters, you likely need SCCs or security assessment depending on volumes.

SaaS Company Serving China Customers

If you process data of Chinese users on servers outside China, you need a lawful transfer mechanism and may need to appoint a China representative.

E-commerce Selling to China

Customer data collected from Chinese buyers must be handled according to PIPL, including cross-border transfer requirements.

Penalties for Non-Compliance

Recent Developments

The regulatory landscape continues to evolve:

Need Help with China Data Compliance?

I help foreign companies navigate China's data protection requirements, implement compliant transfer mechanisms, and manage regulatory filings.

Contact Me