Cross-border production and personnel data
Do transfers of data from China to an overseas plant require outbound-data procedures?
Applies toData transferred from China, or accessed remotely from outside China
Cross-border manufacturing data containing neither personal information nor important data is exempt from security assessment, standard-contract and certification procedures. Employee or customer data needs a separate assessment.
Data-flow identification
Overseas access to data in a Chinese system can be an outbound data activity; server location alone does not settle the question.
Data classification
Distinguish ordinary production data, personal information, sensitive personal information and important data before deciding the route.
Exemptions and filing requirements
Necessary cross-border HR management has a conditional exemption. Other personal data follows rules based on operator status, annual outbound headcount and sensitivity.
Outbound-data exemptions and filing requirements
Count unique people cumulatively from 1 January. Exclude scenarios under Articles 3, 4, 5(1)(1–3) and 6. Critical information infrastructure operators (CIIOs) are identified and notified by their competent authorities.
| Scenario | Applicable procedure | Conditions and basis |
|---|---|---|
| Manufacturing and similar activity data containing no personal or important data | Exempt from assessment, standard contract and certification | Article 3. The exemption concerns these three procedures; data-security duties remain. |
| Employee data strictly necessary for cross-border HR management, excluding important data | Exempt from the three procedures if conditions are met | Article 5: management must be based on lawfully established labour rules and lawfully concluded collective contracts, with necessity assessed. ID, passport and bank-account data are not automatically necessary. |
| No applicable exemption; non-CIIO; no important data; fewer than 100,000 people’s non-sensitive personal information and no sensitive personal information | Exempt from the three procedures | Article 5(1)(4); count people since 1 January of the current year. |
| No applicable exemption; non-CIIO; no important data; 100,000–under 1 million people’s non-sensitive information, or some sensitive personal information covering fewer than 10,000 people | Standard contract or personal-information outbound certification | Article 8; assessment takes precedence if its threshold is also met. |
| No applicable exemption; important data, CIIO personal data, or non-CIIO transfers reaching 1 million non-sensitive / 10,000 sensitive data subjects | Submit for CAC security assessment through the provincial cyberspace authority | Article 7. Identify important data under the relevant authority’s designation and published rules, not simply a dataset’s name. |
Related policies and standards
- Provisions on Promoting and Regulating Cross-border Data FlowsArticles 2–8 and 10–11; effective 2024-03-22
- CAC explanation of the cross-border data provisionsQuestions 6 and 11: operator identification and headcount calculation
- CAC outbound data policy Q&A (October 2025)Questions 3 and 5: HR necessity and overseas remote access
- CAC outbound data policy Q&A (January 2026)Question 1: contract, certification and assessment routes
- GB/T 43697–2024 Data security technology — Rules for data classification and gradingRecommended classification reference; effective 2024-10-01