Mandatory scheme
Personal information cross-border transfer compliance
Personal information cross-border transfer compliance — mandatory scheme, China. It binds organisations transferring personal information out of mainland China.
- Jurisdiction
- China
- Record class
- Mandatory scheme
- Last verified
Where this applies
This record is scoped to China. Scope is part of the claim: a rule that binds one part of a country does not bind the whole of it, and this library states the scope its sources state.
Instrument
个人信息保护法 (PIPL), Art. 38, and 网络数据安全管理条例 (State Council Order No. 790, effective 1 January 2025)
Who it binds
Organisations transferring personal information out of mainland China
What it requires
PIPL Art. 38 gives three routes for a cross-border personal-information transfer: a CAC security assessment, a personal-information-protection certification, or a CAC standard contract — which route applies depends on transfer volume and data type, not a blanket rule. Order No. 16 (2024) loosened the 2022 thresholds with exemptions (contract necessity, HR management, emergencies, under 100,000 people/year) and tiers the standard-contract/certification routes against the mandatory-assessment route by volume. PIPL Art. 66 sets penalties up to RMB 1,000,000 (or RMB 10,000–100,000 for the individual responsible), rising to up to RMB 50,000,000 or 5% of the prior year's turnover for severe cases, plus possible business suspension or licence revocation.
Route to the authority
Last verified:
This page is for information only; it is not legal advice, and it does not establish whether this record applies to your business. Verify current status through the official source above.