Asia-Pacific China

PIPL Cross-Border Transfers: Assessment, SCCs, Certification

China's three data export mechanisms under PIPL Article 38, the 2024 facilitation exemptions, thresholds, filings, and the separate-consent requirement.

Regulation

PIPL Articles 38-43; CAC Security Assessment Measures; SCC Measures; 2024 Facilitation Provisions

Max Penalty

RMB 50 million or 5% of prior year's turnover

Enforcing Authority

Cyberspace Administration of China (CAC)

Official Source

www.cac.gov.cn

Executive Summary

  • PIPL Article 38 allows personal information exports only through one of three mechanisms: a CAC security assessment, the CAC standard contract (filed with the provincial CAC), or protection certification.
  • The security assessment is mandatory for CIIOs, exporters of important data, and handlers transferring personal information of more than 1 million individuals (or sensitive information of more than 10,000) in a year.
  • The March 2024 Facilitation Provisions exempt low-volume transfers (under 100,000 non-sensitive individuals/year), contract-necessity transfers (travel, payments, shipping), and HR-management transfers.
  • Every transfer also requires separate consent (where consent is the basis), a personal information protection impact assessment, and notice naming the overseas recipient.
  • Article 41 prohibits providing data stored in China to foreign courts or law enforcement without Chinese government approval.

Data leaves China only through doors the regulator built. Where GDPR lets exporters self-execute standard clauses, PIPL Article 38 routes every regulated transfer through a CAC security assessment, a filed standard contract, or an accredited certification, each preceded by an impact assessment and, where consent is the basis, a separate consent naming the overseas recipient. The March 2024 facilitation rules widened the exemptions considerably, so the first question is no longer “which mechanism” but “are we exempt.”

RegulationPIPL Arts. 38-43 + CAC implementing measures
MechanismsSecurity assessment / CAC standard contract / certification
Key relaxationFacilitation Provisions, 22 March 2024
RegulatorCAC

The decision tree after March 2024

Step 1: exemptions. No mechanism is needed for transfers necessary to conclude or perform a contract with the individual (cross-border shopping, travel, payments, visa processing), HR management under lawfully adopted labor rules, emergencies protecting life or property, or where fewer than 100,000 individuals’ non-sensitive personal information is exported in a calendar year. Free trade zone negative lists can exempt more. Exemption from the mechanism is not exemption from PIPL: notice, any required separate consent, the protection impact assessment, and recipient-side safeguards still apply.

Step 2: forced assessment. A CAC security assessment (application through the provincial CAC to the national CAC) is mandatory for CIIOs exporting any personal information, any export of important data, transfers of more than 1 million individuals’ personal information, or more than 10,000 individuals’ sensitive personal information since 1 January of the prior year. Approvals are valid for three years, extendable.

Step 3: standard contract or certification. Everyone between the exemption floor and the assessment ceiling signs the CAC’s fixed-form standard contract with the overseas recipient and files it, with the impact assessment, within 10 working days, or obtains personal information protection certification from an accredited body, the route often marketed to multinational groups for intra-group flows.

What the impact assessment must cover

The PIA (Article 55-56 pattern) evaluates the legality, legitimacy, and necessity of the transfer’s purpose, scope, and method; the overseas recipient’s obligations, measures, and capability; the destination’s legal environment; and the risks to individuals’ rights, with the report retained at least three years. Build it once as a template and rerun per recipient and route.

Where this bites in practice

Common traps: SaaS telemetry and support access from abroad is a transfer even without bulk data movement; group HR systems hosted overseas needed the HR exemption to become manageable; and Article 41’s blocking rule against foreign judicial disclosure collides with US discovery, a legal-strategy problem, not a compliance checkbox. Sequence the work inside the PIPL roadmap, get the consent layer right per the separate-consent guide, and compare the EU-side mechanics in the GDPR transfers guide.

Frequently Asked Questions

Which transfer mechanism applies to us?

Count your annual volumes. CAC security assessment: CIIOs, important data, over 1 million individuals' personal information, or over 10,000 individuals' sensitive information. Below that: the CAC standard contract (signed and filed) or certification. Below 100,000 non-sensitive individuals with no important data: exempt under the 2024 provisions, though PIPL's consent and PIA duties still apply.

What did the March 2024 rules change?

The Provisions on Promoting and Regulating Cross-Border Data Flows raised assessment thresholds and created exemptions: transfers necessary for contracts with the individual (bookings, payments, visas), HR management under labor rules, emergencies, and sub-100,000-individual volumes. Free trade zones may run negative lists narrowing requirements further.

How does China's standard contract differ from EU SCCs?

The CAC SCC is a single fixed-form contract (no modules), must be filed with the provincial CAC within 10 working days of effect alongside the impact assessment, and sits under regulator supervision. EU SCCs are self-executed with no filing. A transfer out of China into the EU orbit often needs both instruments back to back.

Is separate consent always required for exports?

When consent is the lawful basis, yes: a standalone consent naming the foreign recipient, purposes, methods, categories, and rights procedures (Article 39). Where another basis carries the processing (e.g. contract necessity under the 2024 exemptions), separate consent is not required, one reason the exemption analysis matters.

Can we respond to a US subpoena with data held in China?

Not without approval. PIPL Article 41 and DSL Article 36 forbid providing data stored in China to foreign judicial or law-enforcement authorities without permission from the competent Chinese authority. Companies caught between US discovery and Chinese blocking statutes need legal strategies (comity motions, data minimization), not unilateral disclosure.

Regulatory Crosswalk

GDPR Chapter VPIPLChina DSL

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.