WorldPrivacyAtlas
Laws by country

Cross-Border Data Transfer

Personal Information Protection Law — cross-border provision of personal information

PIPL Arts. 38-40

China · November 1, 2021; CAC Provisions effective March 22, 2024

Art. 38 requires a handler exporting personal information to satisfy one of three routes first: a CAC security assessment, the CAC's standard contract with the overseas recipient, or certification by a CAC-accredited body. Art. 40 layers a data-localisation requirement on top for critical information infrastructure operators and for handlers processing above the volume threshold — they must store personal information collected in China domestically, and pass a security assessment to export it. The March 2024 Provisions materially relaxed the middle of that regime by raising the volume thresholds and creating exemptions: transfers of non-sensitive personal information covering fewer than 100,000 individuals, counted cumulatively from January 1 of the current year, need none of the three mechanisms. The thresholds are cumulative annual figures, not per-transfer, which is the detail businesses most often get wrong. Free-trade-zone negative lists can vary the position further, so confirm against the relevant FTZ list before relying on an exemption.

Personal Information Protection Law, Arts. 38-40; CAC Provisions on Promoting and Regulating the Cross-border Flow of Data (March 22, 2024)Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.