Data leaves China only through doors the regulator built. Where GDPR lets exporters self-execute standard clauses, PIPL Article 38 routes every regulated transfer through a CAC security assessment, a filed standard contract, or an accredited certification, each preceded by an impact assessment and, where consent is the basis, a separate consent naming the overseas recipient. The March 2024 facilitation rules widened the exemptions considerably, so the first question is no longer “which mechanism” but “are we exempt.”
| Regulation | PIPL Arts. 38-43 + CAC implementing measures |
|---|---|
| Mechanisms | Security assessment / CAC standard contract / certification |
| Key relaxation | Facilitation Provisions, 22 March 2024 |
| Regulator | CAC |
The decision tree after March 2024
Step 1: exemptions. No mechanism is needed for transfers necessary to conclude or perform a contract with the individual (cross-border shopping, travel, payments, visa processing), HR management under lawfully adopted labor rules, emergencies protecting life or property, or where fewer than 100,000 individuals’ non-sensitive personal information is exported in a calendar year. Free trade zone negative lists can exempt more. Exemption from the mechanism is not exemption from PIPL: notice, any required separate consent, the protection impact assessment, and recipient-side safeguards still apply.
Step 2: forced assessment. A CAC security assessment (application through the provincial CAC to the national CAC) is mandatory for CIIOs exporting any personal information, any export of important data, transfers of more than 1 million individuals’ personal information, or more than 10,000 individuals’ sensitive personal information since 1 January of the prior year. Approvals are valid for three years, extendable.
Step 3: standard contract or certification. Everyone between the exemption floor and the assessment ceiling signs the CAC’s fixed-form standard contract with the overseas recipient and files it, with the impact assessment, within 10 working days, or obtains personal information protection certification from an accredited body, the route often marketed to multinational groups for intra-group flows.
What the impact assessment must cover
The PIA (Article 55-56 pattern) evaluates the legality, legitimacy, and necessity of the transfer’s purpose, scope, and method; the overseas recipient’s obligations, measures, and capability; the destination’s legal environment; and the risks to individuals’ rights, with the report retained at least three years. Build it once as a template and rerun per recipient and route.
Where this bites in practice
Common traps: SaaS telemetry and support access from abroad is a transfer even without bulk data movement; group HR systems hosted overseas needed the HR exemption to become manageable; and Article 41’s blocking rule against foreign judicial disclosure collides with US discovery, a legal-strategy problem, not a compliance checkbox. Sequence the work inside the PIPL roadmap, get the consent layer right per the separate-consent guide, and compare the EU-side mechanics in the GDPR transfers guide.