Editor's note: On March 22, 2024, after four months of internal approval, the Cyberspace Administration of China (hereinafter the “CAC”) finally officially issued the long-awaited Provisions on Promoting and Regulating Cross-Border Data Flows (hereinafter the “New Data Export Rules”). Industry practitioners noted that the phrase “regulating and promoting” in the draft for comments has become “promoting and regulating” in the official text, which may be understood as the state placing more emphasis on development than on security in cross-border data flows. It is expected that, beginning with these rules, future cross-border data-related policies will undergo structural adjustments with an increasing focus on promoting development.
Given that cross-border transactions and investments often require advisory or service support for data export, this article interprets the main provisions of the new rules and provides compliance tips for cross-border enterprises based on prior legal application, regulatory practice, and project experience, for reference.
01 Three Stages in China's Data Export Legislation and Supervision
1. Theoretical Research Stage
Since the implementation of the Cybersecurity Law in 2017, China has begun exploring data export regulatory policies. Based on theoretical research and comparative analysis, the CAC issued three draft versions of implementation rules for data export regulation (drafts for comments), focusing on core issues such as classified regulation of important data and personal information, applicable thresholds and the basic framework for security assessments, the content of data export agreements, and recipient responsibilities, in order to establish a data export regulatory policy suited to China's circumstances.
2. Practical Exploration Stage
After the Personal Information Protection Law came into effect in 2021, the paths for exporting personal information and important data were gradually clarified into three routes: security assessment, standard contracts, and certification. The CAC successively issued the Measures for Security Assessment of Data Exports, the Measures for Standard Contracts for the Export of Personal Information, the Announcement on Implementing Personal Information Protection Certification, and supporting implementation rules, practical guidelines, and template documents. Local cyberspace administrations also opened dedicated consultation windows and organized multiple policy briefings.
At this stage, the CAC formally launched practical exploration of data export security assessments and the filing of standard contracts for personal information. This accumulated practical experience while also exposing new issues and room for improvement.
3. Improvement and Refinement Stage
In response to concerns and suggestions from various parties, and to optimize the investment environment and improve the convenience of cross-border data flow management, the State Council and the CAC issued a series of policies and norms, such as the draft Provisions on Regulating and Promoting Cross-Border Data Flows (the “Draft for Comments”) and the Implementation Guidelines for the Standard Contract for Cross-Border Flow of Personal Information in the Guangdong-Hong Kong-Macao Greater Bay Area. These improved data export regulatory policies, made assessment and filing procedures more efficient, and continuously optimized relevant standards and prudence.
With the introduction of the New Data Export Rules, enterprise compliance costs have been reduced, and the institutional value of balancing data utilization and data flow has been achieved, marking the basic formation of China's data export legal system and the maturity of its regulatory practice.
02 Interpretation of the Main Content of the New Data Export Rules
1. Clarifying the declaration standards for security assessment of important data export, and providing that data processors that have not been notified or publicly released by relevant departments or regions as important data are not required to declare a data export security assessment as important data.
Article 2 of the New Data Export Rules: Data processors shall identify and declare important data in accordance with relevant provisions. Where data has not been notified or publicly released by the relevant department or region as important data, the data processor is not required to declare a data export security assessment for such data as important data.
“Important data” refers to data that, if tampered with, destroyed, leaked, illegally obtained, or illegally used, may endanger national security, economic operation, social stability, public health and safety, etc.—Article 19 of the Measures for Security Assessment of Data Exports.
Any export of important data is subject to a data export security assessment. In practice, it is difficult for ordinary enterprises to determine whether misuse of relevant data would affect national security. This provision clarifies that important data is identified through a top-down approach; enterprises are not required to identify and report their own important data catalogs, and instead relevant departments or regions will notify or publicly release such data. In other words, data processors that have not been notified or publicly identified as processing “important data” do not need to declare a data export security assessment.
Under China's Data Security Law, the authority and responsibility for formulating important data catalogs lies with the industry regulators and relevant regional departments, rather than the national cyberspace administration. To date, the identification of important data and the formulation of catalogs in China are still in their early stages. If this provision takes effect, it may accelerate the formulation of important data catalogs by various departments and regions and promote the further improvement of China's important data management mechanism.
2. Clarifying the Scope of Application of the Ex Ante Regulatory Mechanisms for Data Export
(1) Scope of data types: only personal information and important data apply
Article 3 of the New Data Export Rules: Where data collected and generated in activities such as international trade, cross-border transportation, academic cooperation, transnational manufacturing, and marketing is provided overseas and does not contain personal information or important data, it is exempt from the requirement to declare a data export security assessment, conclude a standard contract for the export of personal information, or obtain personal information protection certification.
The key point of this provision is to clarify the data types to which China's ex ante regulatory mechanisms for data export apply: only “personal information” and “important data” are regulated, while other ordinary business data may be exported freely.
The enumeration of “international trade, academic cooperation, transnational manufacturing, and marketing” in this provision clearly expresses support for these four types of activities. For example, production and sales statistics generated by enterprises in international trade, transnational manufacturing, and marketing may be freely shared with overseas entities as long as they do not contain personal information or important data; universities and other scientific research institutions may freely share research data such as experimental data and observation data that do not contain personal information or important data with overseas partners in the course of international scientific research cooperation.
(2) Specific data processing activities excluded from application
1. Domestic processing of data collected overseas where no domestic personal information or important data is introduced during processing
Article 4 of the New Data Export Rules: Where personal information collected and generated overseas by a data processor is transferred to China for processing and then provided overseas, and no domestic personal information or important data is introduced during processing, it is exempt from the requirement to declare a data export security assessment, conclude a standard contract for the export of personal information, or obtain personal information protection certification.
This provision will not only help Chinese enterprises undertake overseas data processing demand and promote the development of the data processing industry, but will also help overseas branches of Chinese enterprises going global that are headquartered in China aggregate data collected and generated overseas at their domestic headquarters for unified storage and other processing, and then allow overseas branches to subsequently access or transfer such data across borders.
The personal information protection regime protects the rights and interests of personal information subjects. Processing in China of personal information collected and generated overseas does not involve the rights and interests of personal information subjects within China, so it is exempt from ex ante regulatory procedures. It should be noted that the processing of such data in China should not involve the introduction of personal information or important data collected or generated within China.
2. Specific personal information processing scenarios that may be excluded
Article 5 of the New Data Export Rules: Where a data processor provides personal information overseas and meets any of the following conditions, it is exempt from the requirement to declare a data export security assessment, conclude a standard contract for the export of personal information, or obtain personal information protection certification:
(1) where it is necessary to provide personal information overseas for the conclusion or performance of a contract to which the individual is a party, such as cross-border shopping, cross-border mailing, cross-border remittance, cross-border payment, cross-border account opening, air ticket and hotel booking, visa processing, examination services, and the like;
(2) where it is necessary to provide employee personal information overseas for the implementation of cross-border human resources management in accordance with labor rules and policies formulated in accordance with the law and collective contracts concluded in accordance with the law;
(3) where it is necessary to provide personal information overseas in an emergency to protect the life, health, and property safety of natural persons;
(4) where a data processor other than a critical information infrastructure operator has cumulatively provided overseas personal information of fewer than 100,000 individuals since January 1 of the current year (excluding sensitive personal information).
The personal information provided overseas referred to in the preceding paragraph does not include important data.
Compared with the previously issued draft for comments, items (3) and (4) of this article are new and further expand the circumstances excluded from the application of the personal information export rules.
3. Expanding and Clarifying the Scope of Application of the Standard Contract for Export of Personal Information and Personal Information Protection Certification
Article 7 of the New Data Export Rules: Where a data processor provides data overseas and meets any of the following conditions, it shall declare a data export security assessment to the national cyberspace administration through the provincial cyberspace administration at its locality: (1) a critical information infrastructure operator provides personal information or important data overseas; (2) a data processor other than a critical information infrastructure operator provides important data overseas, or has cumulatively provided overseas personal information of 1 million or more individuals since January 1 of the current year (excluding sensitive personal information), or sensitive personal information of 10,000 or more individuals. Where the circumstances fall under Articles 3, 4, 5, or 6 of these Provisions, those articles shall apply.
Article 8 of the New Data Export Rules: Where a data processor other than a critical information infrastructure operator has cumulatively provided overseas personal information of 100,000 or more but fewer than 1 million individuals since January 1 of the current year (excluding sensitive personal information), or sensitive personal information of fewer than 10,000 individuals, it shall conclude a standard contract for the export of personal information with the overseas recipient in accordance with the law or obtain personal information protection certification. Where the circumstances fall under Articles 3, 4, 5, or 6 of these Provisions, those articles shall apply.
Sample of the "Notice of Filing of the Standard Contract for Export of Personal Information"
The above provisions optimize the relationship among China's three data export management mechanisms. The scope of application for the standard contract for the export of personal information and personal information protection certification has been expanded, making them more applicable. Among them, the prospects for personal information protection certification deserve particular attention. Personal information protection certification is a voluntary certification of a personal information processor's data protection capabilities. In practice, when applying for certification, a personal information processor will go through technical verification, on-site audits, rectification, and other stages. This is equivalent to certification bodies and technical verification bodies, based on their professional experience, helping the personal information processor undergo an in-depth examination to identify data protection weaknesses and propose improvement paths, thereby comprehensively enhancing the processor's data protection level. Compared with the standard contract for the export of personal information, personal information protection certification can cover a wider range of business scenarios and is more stable. Therefore, personal information protection certification has practical advantages for multinational companies, enterprises whose business is premised on processing personal information, and enterprises whose personal information export activities last for a relatively long period. Certification is an important mechanism for global cross-border data flows, is highly scalable, and helps align China's cross-border data management mechanisms with international practice. The EU's GDPR includes data protection certification, and international data cross-border cooperation mechanisms such as the Global Cross-Border Privacy Rules (CBPR) and the EU-U.S. Data Privacy Framework (DPF) are implemented through certification. It is particularly noteworthy that the key to implementing such certification is for the personal information processor to demonstrate compliance with a certain "certification rule," and certification rules are scalable—that is, if a certification mechanism is to be extended to other countries or regions, it is only necessary to adjust the common certification rules. A typical example is that the EU-U.S. DPF has been extended to apply to U.S.-UK data transfers and U.S.-Swiss data transfers.
4. Clarifying the Authority and Procedures for Pilot Free Trade Zones to Formulate Negative Lists, and Significant Opportunities for the Digital Economy in Pilot Free Trade Zones
Article 6 of the New Data Export Rules: Under the national data classification and hierarchical protection framework, a pilot free trade zone may formulate its own list of data within the zone that must be subject to data export security assessment, the standard contract for the export of personal information, and personal information protection certification (hereinafter the “negative list”), and after approval by the provincial cybersecurity and informatization committee, file it with the national cyberspace administration and the national data management authority. Data processors in a pilot free trade zone that provide data outside the negative list overseas are exempt from declaring a data export security assessment, concluding a standard contract for the export of personal information, or obtaining personal information protection certification.
This provision clarifies that pilot free trade zones may formulate lists of data requiring declaration, filing, and certification, i.e., “negative lists.” For data exports outside the negative list, data processors in the pilot free trade zone are not required to undergo ex ante regulatory procedures—namely, they are exempt from declaration, filing, and certification and may export the data. This clarifies the attitude of delegating data cross-border management authority and responsibility to pilot free trade zones, and helps further explore efficient and convenient channels for cross-border data flows in these zones.
However, the New Data Export Rules impose two new requirements:
(1) The negative list must comply with the national data classification and hierarchical protection framework, which means there can be no breakthrough with respect to important data. This has a relatively large impact on automobile, pharmaceutical, and financial institutions in pilot free trade zones.
(2) The negative list applies only to data processors within the pilot free trade zone, which may significantly affect the applicability of the negative list policy in such zones. Previously, the scope of application in some pilot free trade zone policy drafts extended to “data export activities carried out in the pilot free trade zone.”
While pilot free trade zones are entering an important period of opportunity, they also bear greater responsibility for ensuring data security protection capabilities within their areas. On the one hand, because the industrial development situations of different pilot free trade zones vary, the types of exported data will also differ. Each pilot free trade zone must be capable of grasping the demand for cross-border data flows and the level of data security protection within its area in order to formulate its “negative list” smoothly. On the other hand, although data outside the “negative list” in a pilot free trade zone is not required to undergo ex ante procedures for data export management, data security protection obligations must still be fulfilled. This means that pilot free trade zones should maintain a relatively high level of data security protection to safeguard the security of cross-border flows of data outside the list, which is also an important foundation for piloting cross-border data international cooperation.
03 Matters for Further Clarification under the New Data Export Rules
1. Does the Method for Calculating “Cumulatively Provided Overseas Since January 1 of the Current Year” Include Personal Information Already Exported Before January 1?
The specific details of this calculation method need to be clarified through subsequent regulatory practice. If the calculation focuses only on "incremental data," such as the number of new job applicants and new customers counted from January 1 of the current year, this will reduce the cross-border compliance procedures that enterprises need to complete because of newly added data. For example, certain enterprises may be exempt from cross-border compliance procedures because their newly added personal information (excluding sensitive personal information) for the year does not exceed 100,000 individuals; or because their newly added sensitive personal information does not exceed 10,000 individuals, they may prove the legality of data export by signing a standard contract or obtaining certification instead of undergoing a data export security assessment. Conversely, if the calculation is based on "stock" data, it means that enterprises that have already reached the threshold cannot use measures such as a minimum company-level exemption to reduce their compliance burden, especially for those whose data is mainly stored on overseas servers or are open on a long-term basis.
2. How Should Approved Data Export Security Assessment Decisions Be Handled?
For enterprises that, before the issuance of the New Data Export Rules, obtained conditional approval in a data export security assessment (i.e., certain data fields were prohibited from being exported), if those prohibited data fields fall under an exempt scenario under the New Data Export Rules, may the enterprise continue to transfer those prohibited data fields overseas in accordance with the New Data Export Rules?
04 Matters Enterprises Should Note After the New Data Export Rules
The introduction of the New Data Export Rules aims to convey institutional signals of inclusiveness, prudence, scientific approach, and facilitation. It is of positive significance for further optimizing the foreign investment environment, improving the convenience of data export, and reducing enterprise compliance costs. It will also affect the efficiency of future project declarations, the standards of assessment, and the scientific soundness of results. For example, some recent projects show that regulators have adopted a more pragmatic attitude when determining the "necessity standard."
1. Establish a Long-Term Data Export Statistics Mechanism
Companies with data export scenarios (whether previously subject to data export security assessment, filing of the standard contract for the export of personal information, or exempt enterprises) should establish a long-term data export statistics mechanism and carry out regular data inventory to ensure that they can keep track of the latest status at the company entity level of "the number of individuals whose personal information has been cumulatively provided overseas since January 1 of the current year." At the same time, statistical data should include both incremental and stock dimensions to meet the needs of future personal information protection compliance audits regarding verification of applicable cross-border compliance administrative procedures.
In addition, one major change under the New Data Export Rules is the strengthening of enterprises' self-assessment responsibilities. Therefore, in response to the evolving policy and enforcement environment, we recommend that even if enterprises are not required to carry out data export declaration, filing, or certification under the new rules, they should still conduct a personal information protection impact assessment for data export or a data export compliance self-assessment, or strengthen data export compliance audits within personal information protection compliance audits. Through assessment/audit work, they should analyze compliance gaps and implement rectification, ensure that enhanced notification, separate consent, and other compliance responsibilities are implemented, ensure that compliance work is documented, promote "building through assessment," and gradually establish and improve their data compliance systems.
2. Update Filing Materials Based on the Declaration Procedures
The formal implementation of the New Data Export Rules provides a good policy window. Enterprises should make full use of this window to accelerate the progress of assessment or filing projects according to the application of the new rules. Enterprises that previously failed security assessment may, after rectification, declare security assessment again or downgrade to standard contract filing. There have already been several successful cases in practice.
Where it is necessary to switch cross-border compliance administrative procedures under the New Data Export Rules (for example, switching from data export security assessment declaration to filing of the standard contract for personal information), companies are advised to adjust the content of their overall filing materials in accordance with the requirements of the New Data Export Rules and the second edition of the filing guidelines (including the latest templates for the data export risk self-assessment report and the personal information protection impact assessment report), such as removing exempt scenarios, and then explain the matter to the cyberspace administration and submit the filing materials.
3. Internal Compliance Records
The New Data Export Rules expressly strengthen regulatory requirements across the entire chain and all fields, before, during, and after data export. In recent years, the cyberspace administration has also established enforcement departments. Combined with the overlapping effects of the Counter-Espionage Law and the National Intelligence Law, enterprises should strengthen routine data export compliance management, establish response mechanisms for regulatory enforcement investigations, and improve corresponding risk isolation and insurance mechanisms to reduce potential legal risks and liabilities for the enterprise, its legal representative, key responsible persons, and personal information protection officers.
Companies exempt from cross-border compliance administrative procedures still need to implement obligations such as notification, obtaining separate consent from individuals, and conducting personal information protection impact assessments, and should prepare corresponding supporting records to respond to future personal information protection compliance audits of their data export compliance processes.
Conclusion
At present, global data governance is undergoing important changes, and countries around the world are striving to strike a balance between the convenience of data flows and data security needs. With the arrival of the intelligent era, data has become the cornerstone of the global economy and a core element of society. A country's data regulatory system should not represent the interests of only a few individuals or groups; it should embody the collective wisdom of a broad range of stakeholders and express the "collective intelligence" of a community with a shared future for mankind. In formulating the Provisions on Promoting and Regulating Cross-Border Data Flows, the demands of various domestic and international parties were fully considered, demonstrating that China's participation and influence in global data governance are increasing. This is consistent with China's long-adopted risk-oriented regulatory philosophy and is also a positive response to the dynamics of international data flows.
At the same time, we recognize that as international data flows continue to develop and the domestic and international legal environments change, China will face new challenges and opportunities in regulating cross-border data flows. As discussed in this article, the implementation of the Provisions on Promoting and Regulating Cross-Border Data Flows still faces many challenges, requiring the cyberspace administration and all industry parties to work together to find solutions.
We hope that the Provisions on Promoting and Regulating Cross-Border Data Flows will be dynamically adjusted in a timely manner based on the development of China's digital economy and actual circumstances. For example, the boundaries of cross-border data flows could be flexibly adjusted, and the scope of application of Article 5 could be further clarified and expanded through a list-based approach, thereby striking a balance between compliance and commercial interests while maintaining international development momentum. Effective regulation is a challenging task. We hope that global cross-border data regulation can adapt to the characteristics of data flows and achieve tolerant, measured dynamic adjustments.
Appendix
Cyberspace Administration of China Order
No. 16: The Provisions on Promoting and Regulating Cross-Border Data Flows were reviewed and adopted at the 26th office meeting of the Cyberspace Administration of China in 2023 on November 28, 2023, and are hereby promulgated, effective from the date of promulgation.
Zhuang Rongwen, Director of the Cyberspace Administration of China
March 22, 2024
Provisions on Promoting and Regulating Cross-Border Data Flows
Article 1 These Provisions are formulated in accordance with the Cybersecurity Law of the People's Republic of China, the Data Security Law of the People's Republic of China, the Personal Information Protection Law of the People's Republic of China, and other laws and regulations, for the purpose of ensuring data security, protecting personal information rights and interests, and promoting the lawful, orderly, and free flow of data, with respect to the implementation of the data export security assessment, the standard contract for the export of personal information, personal information protection certification, and other data export regimes.
Article 2 Data processors shall identify and declare important data in accordance with relevant provisions. Where data has not been notified or publicly released by relevant departments or regions as important data, the data processor is not required to declare a data export security assessment for such data as important data.
Article 3 Where data collected and generated in activities such as international trade, cross-border transportation, academic cooperation, transnational manufacturing, and marketing is provided overseas and does not contain personal information or important data, it is exempt from the requirement to declare a data export security assessment, conclude a standard contract for the export of personal information, or obtain personal information protection certification.
Article 4 Where personal information collected and generated overseas by a data processor is transferred to China for processing and then provided overseas, and no domestic personal information or important data is introduced during processing, it is exempt from the requirement to declare a data export security assessment, conclude a standard contract for the export of personal information, or obtain personal information protection certification.
Article 5 Where a data processor provides personal information overseas and meets any of the following conditions, it is exempt from the requirement to declare a data export security assessment, conclude a standard contract for the export of personal information, or obtain personal information protection certification:
(1) where it is necessary to provide personal information overseas for the conclusion or performance of a contract to which the individual is a party, such as cross-border shopping, cross-border mailing, cross-border remittance, cross-border payment, cross-border account opening, air ticket and hotel booking, visa processing, examination services, and the like;
(2) where it is necessary to provide employee personal information overseas for the implementation of cross-border human resources management in accordance with labor rules and policies formulated in accordance with the law and collective contracts concluded in accordance with the law;
(3) where it is necessary to provide personal information overseas in an emergency to protect the life, health, and property safety of natural persons;
(4) where a data processor other than a critical information infrastructure operator has cumulatively provided overseas personal information of fewer than 100,000 individuals since January 1 of the current year (excluding sensitive personal information).
The personal information provided overseas referred to in the preceding paragraph does not include important data.
Article 6 Under the national data classification and hierarchical protection framework, a pilot free trade zone may formulate its own list of data within the zone that is subject to data export security assessment, the standard contract for the export of personal information, and personal information protection certification (hereinafter the “negative list”), and after approval by the provincial cybersecurity and informatization committee, file it with the national cyberspace administration and the national data management authority.
Data processors in a pilot free trade zone that provide data outside the negative list overseas are exempt from declaring a data export security assessment, concluding a standard contract for the export of personal information, or obtaining personal information protection certification.
Article 7 Where a data processor provides data overseas and meets any of the following conditions, it shall declare a data export security assessment to the national cyberspace administration through the provincial cyberspace administration at its locality:
(1) a critical information infrastructure operator provides personal information or important data overseas;
(2) a data processor other than a critical information infrastructure operator provides important data overseas, or has cumulatively provided overseas personal information of 1 million or more individuals since January 1 of the current year (excluding sensitive personal information), or sensitive personal information of 10,000 or more individuals.
Where the circumstances fall under Articles 3, 4, 5, or 6 of these Provisions, those articles shall apply.
Article 8 Where a data processor other than a critical information infrastructure operator has cumulatively provided overseas personal information of 100,000 or more but fewer than 1 million individuals since January 1 of the current year (excluding sensitive personal information), or sensitive personal information of fewer than 10,000 individuals, it shall conclude a standard contract for the export of personal information with the overseas recipient in accordance with the law or obtain personal information protection certification.
Where the circumstances fall under Articles 3, 4, 5, or 6 of these Provisions, those articles shall apply.
Article 9 The validity period of a data export security assessment result is three years, calculated from the date the assessment result is issued. Upon expiration, if it is necessary to continue data export activities and no circumstances requiring a new declaration for data export security assessment have occurred, the data processor may, within 60 working days before the expiration, apply to the national cyberspace administration through the provincial cyberspace administration at its locality to extend the validity period of the assessment result. Upon approval by the national cyberspace administration, the validity period of the assessment result may be extended for three years.
Article 10 Where a data processor provides personal information overseas, it shall perform obligations such as notification, obtaining separate individual consent, and conducting a personal information protection impact assessment in accordance with laws and administrative regulations.
Article 11 Where a data processor provides data overseas, it shall comply with laws and regulations, fulfill data security protection obligations, and adopt technical measures and other necessary measures to ensure the security of data export. If a data security incident occurs or may occur, it shall take remedial measures and promptly report to the cyberspace administration at or above the provincial level and other relevant competent departments.
Article 12 Cyberspace administrations at all localities shall strengthen guidance and supervision over data processors' data export activities, improve the data export security assessment regime, and optimize assessment procedures; strengthen supervision across the entire chain and all fields before, during, and after data export; and where significant risks are identified in data export activities or a data security incident occurs, require the data processor to make rectifications and eliminate hidden dangers. Legal liability shall be pursued in accordance with the law against those that refuse to correct or cause serious consequences.
Article 13 If any provisions of the Measures for Security Assessment of Data Exports issued on July 7, 2022 (Order No. 11 of the Cyberspace Administration of China), the Measures for Standard Contracts for the Export of Personal Information issued on February 22, 2023 (Order No. 13 of the Cyberspace Administration of China), and other relevant provisions are inconsistent with these Provisions, these Provisions shall prevail.
Article 14 These Provisions shall take effect on the date of promulgation.
For more information on data export compliance matters, please contact the professional consulting team of Zhongxin Faxun.
This article is general information and not legal advice. Specific matters require assessment by appropriately qualified professionals.