Mandatory scheme

Personal information cross-border transfer compliance

Personal information cross-border transfer compliance — mandatory scheme, China. It binds organisations transferring personal information out of mainland China.

Jurisdiction
China
Record class
Mandatory scheme
Last verified

Where this applies

This record is scoped to China. Scope is part of the claim: a rule that binds one part of a country does not bind the whole of it, and this library states the scope its sources state.

Instrument

个人信息保护法 (PIPL), Art. 38, and 网络数据安全管理条例 (State Council Order No. 790, effective 1 January 2025)

Who it binds

Organisations transferring personal information out of mainland China

What it requires

PIPL Art. 38 gives three routes for a cross-border personal-information transfer: a CAC security assessment, a personal-information-protection certification, or a CAC standard contract — which route applies depends on transfer volume and data type, not a blanket rule. Order No. 16 (2024) loosened the 2022 thresholds with exemptions (contract necessity, HR management, emergencies, under 100,000 people/year) and tiers the standard-contract/certification routes against the mandatory-assessment route by volume. PIPL Art. 66 sets penalties up to RMB 1,000,000 (or RMB 10,000–100,000 for the individual responsible), rising to up to RMB 50,000,000 or 5% of the prior year's turnover for severe cases, plus possible business suspension or licence revocation.

Route to the authority

Last verified:

This page is for information only; it is not legal advice, and it does not establish whether this record applies to your business. Verify current status through the official source above.

Cite this page

Attributing this record helps other researchers verify it independently.

"Personal information cross-border transfer compliance." Certifidex, FutureTechnologies. Last verified 21 August 2026. https://certifidex.com/countries/cn/data-security-cross-border-transfer

All China records →