Promulgated by the Cyberspace Administration of China on June 24, 2022
Effective: June 24, 2022
Article 1 — These Provisions are formulated in accordance with the Personal Information Protection Law of the People’s Republic of China, the Cybersecurity Law of the People’s Republic of China, the Data Security Law of the People’s Republic of China, and other relevant laws and regulations, for the purpose of regulating the certification of cross-border transfer of personal information and protecting the rights and interests of personal information subjects.
Article 2 — These Provisions shall apply to the activities of certification of cross-border transfer of personal information carried out within the territory of the People’s Republic of China.
Article 3 — Personal information processors may, in accordance with law, commission specialized certification institutions recognized by the Cyberspace Administration of China to carry out the certification of cross-border transfer of personal information.
Article 4 — Where a personal information processor engages a specialized certification institution to carry out certification of cross-border transfer of personal information, it shall enter into a legally binding agreement with the overseas recipient in accordance with the requirements of the specialized certification institution, specifying the rights and obligations of both parties regarding the protection of personal information.
Article 5 — The certification of cross-border transfer of personal information shall be based on the principles of voluntariness, openness, fairness, and good faith.
Article 6 — A specialized certification institution conducting certification of cross-border transfer of personal information shall examine the following matters:
(1) Whether the personal information processor and the overseas recipient have entered into a legally binding document;
(2) Whether the organizational management, technical measures, and other necessary measures taken by the personal information processor and the overseas recipient are appropriate to protect the security of the personal information;
(3) Whether the rights of personal information subjects provided in the legally binding document between the personal information processor and the overseas recipient are fully protected;
(4) Whether the scope of personal information transferred across borders is the minimum necessary for the purposes of processing;
(5) Other matters that shall be examined in accordance with relevant laws and regulations.
Article 7 — Where a specialized certification institution finds that the certification requirements are met during the certification process, it shall issue a certification document; where the requirements are not met, it shall notify the personal information processor in writing and explain the reasons.
Article 8 — The personal information processor shall, before transferring personal information across borders, conduct a personal information protection impact assessment, focusing on the following:
(1) The legality, legitimacy, and necessity of the purpose, scope, and method of processing of the personal information by the personal information processor and the overseas recipient;
(2) The scale, scope, type, and degree of sensitivity of the personal information to be transferred across borders, and the risks that the cross-border transfer of personal information may pose to the rights and interests of personal information subjects;
(3) Whether the responsibilities and obligations undertaken by the overseas recipient, and the management, technical measures, and capabilities for performing such responsibilities and obligations, can ensure the security of the personal information to be transferred across borders;
(4) The risk of leakage, damage, tampering, or abuse of personal information after cross-border transfer, and whether individuals have convenient channels for safeguarding their rights and interests;
(5) The impact of the personal information protection policies and laws and regulations of the country or region where the overseas recipient is located on fulfilling the legally binding document.
Article 9 — The validity period of the certification shall be determined by the specialized certification institution based on actual circumstances, but shall not exceed three years. Upon expiration of the validity period, if certification is still required, the personal information processor shall re-apply for certification.
Article 10 — Where there is a change in the purpose, scope, type, or method of the cross-border transfer of personal information that affects the basis for certification, or where there is a change in the personal information protection policies and laws and regulations of the country or region where the overseas recipient is located, the personal information processor shall re-apply for certification.
Article 11 — Specialized certification institutions shall, when carrying out certification activities, keep confidential the trade secrets, personal privacy, and other information of personal information processors obtained during the certification process, and shall not disclose or illegally provide such information to others.
Article 12 — The Cyberspace Administration of China and relevant departments shall supervise and inspect the certification activities of specialized certification institutions for the cross-border transfer of personal information.
Article 13 — These Provisions shall be interpreted by the Cyberspace Administration of China.
Article 14 — These Provisions shall enter into force as of the date of promulgation.
Disclaimer: This English translation is provided for informational and reference purposes only. It is not an official translation and has no legal effect. While we strive for accuracy, this translation may contain errors or omissions. For any legal matters or official purposes, please consult the original Chinese text or seek professional legal advice. Dan Young Business Consultancy assumes no liability for any reliance placed on this translation.