01

1. Start with the data flow, not the filing form

The first question is not whether a security assessment is required. It is who collects the data, where it is stored, who can access it, why it is needed, how long it is retained and whether an overseas recipient can pass it on. A defensible map usually covers systems, interfaces, exports and human access rights.

A dataset does not necessarily need to be physically copied abroad before a cross-border issue arises. Remote access by an overseas headquarters, affiliate or service provider should be included in the initial analysis.

  • System and database locations
  • Overseas accounts and remote permissions
  • Cloud, analytics, support and HR vendors
  • Data fields, population, sensitivity and retention
02

2. Classify before you count

The route depends on both the nature and volume of the data. The exporter should first determine whether competent authorities have identified, or public rules classify, any data as important data. Personal information should then be divided between sensitive and other personal information, with annual cumulative volumes measured on a documented basis.

China's Provisions on Promoting and Regulating Cross-Border Data Flows adjusted the thresholds for security assessment, standard-contract filing and certification, while creating defined exemptions. The result must be revisited when a product launches, a business is acquired, the customer base grows or a vendor changes.

03

3. Test exemption, standard contract or certification, then security assessment

Once classification and volumes are reliable, test the available routes in sequence: a specific exemption; a personal-information standard contract filing or certification; or, for higher-risk circumstances and important data, a data export security assessment.

Certain activities necessary for an individual contract, HR administration or emergency protection may qualify for exemptions. Convenience alone does not. The exporter should retain evidence of the scenario, necessity and limited data scope.

04

4. Preserve the baseline PIPL controls

An exemption generally affects the transfer mechanism, not the wider duties under China's Personal Information Protection Law. Purpose, legal basis, notice and consent, data minimisation, individual rights, security controls and oversight of the overseas recipient still require attention.

Higher-risk processing should be supported by a personal information protection impact assessment. The recipient agreement should address purpose, scope, retention, onward transfer, incident notification, audit support and deletion or return after termination.

05

5. Connect transfer work with the privacy audit programme

China's Measures for the Administration of Personal Information Protection Compliance Audits took effect on 1 May 2025. Organisations should establish a periodic audit mechanism proportionate to scale and risk, and be able to mobilise a focused audit where regulators require it or a significant risk event occurs.

For international operations, an audit should test more than policies. It should sample access rights, export logs, vendor performance, rights requests, deletion workflows and incident response. Findings should be assigned, remediated and verified.

06

6. Maintain a defensible evidence pack

A mature programme keeps a living evidence pack that can support regulatory engagement, transactions and new product reviews.

  • Data-flow map, system inventory and overseas access list
  • Classification and volume calculations
  • Legal basis, notices, consents and impact assessments
  • Recipient diligence, contracts and onward-transfer controls
  • Assessment, filing or certification records where applicable
  • Audit, remediation and incident-exercise records

Conclusion

China data transfer compliance is not a choice between three forms. It is a repeatable decision process tied to the way the business actually operates. Early coordination between legal, security, product, HR and procurement reduces duplicated remediation and avoids delay when a cross-border project becomes time-critical.