Issued by the Cyberspace Administration of China on March 22, 2024
Effective: March 22, 2024
Table of Contents
Article 1 — These Provisions are formulated in accordance with the Cybersecurity Law of the People’s Republic of China, the Data Security Law of the People’s Republic of China, the Personal Information Protection Law of the People’s Republic of China, and other laws and regulations for the purpose of promoting and regulating the orderly and free cross-border flow of data in accordance with the law, safeguarding data security, and protecting personal information rights and interests.
Article 2 — A data processor shall, in accordance with laws and regulations, identify important data. Where the relevant authorities or regions have not issued a notice or publicly released a catalogue specifying that the data constitutes important data, the data processor shall not be required to declare for a data export security assessment as important data.
Article 3 — A data export security assessment shall not be required under any of the following circumstances where data is provided abroad: (1) personal information collected and generated outside the country that is transmitted into the country for processing and then provided abroad, provided that no domestic personal information or important data is introduced in the course of processing; (2) personal information that must be provided abroad for the purpose of concluding or performing a contract to which the individual is a party, such as cross-border shopping, cross-border mailing, cross-border remittances, cross-border payment, cross-border account opening, air ticket and hotel booking, and visa processing; (3) personal information of employees that must be provided abroad for the purpose of implementing human resources management in accordance with labor rules and regulations formulated in accordance with the law and collective contracts concluded in accordance with the law; or (4) personal information that must be provided abroad in an emergency to protect the life, health, and property safety of natural persons.
Article 4 — Where a personal information processor that is not a critical information infrastructure operator has provided abroad the personal information (excluding sensitive personal information) of less than 100,000 individuals cumulatively since January 1 of the current year, it shall not be required to declare for a data export security assessment, enter into a standard contract, or pass a personal information protection certification.
Article 5 — A free trade zone may, within the framework of the national data classification and classification protection system, formulate its own negative list of data that needs to be included in the scope of data export security assessments, standard contracts, and personal information protection certification (hereinafter referred to as the “Negative List”), which shall be implemented upon approval by the provincial-level cyberspace administration and filing with the Cyberspace Administration of China. Data processors in the free trade zone that provide abroad data not on the Negative List may be exempted from data export security assessments, entering into standard contracts, and passing personal information protection certification.
Article 6 — State organs and critical information infrastructure operators that provide personal information and important data abroad shall declare for a data export security assessment in accordance with relevant laws, administrative regulations, and departmental rules. Data processors that provide abroad sensitive personal information or important data collected and generated within the country by state organs shall declare for a data export security assessment in accordance with relevant laws, administrative regulations, and departmental rules.
Article 7 — A data processor that provides personal information abroad shall comply with the following provisions: (1) inform the individual of the name or personal name and contact information of the overseas recipient, the purpose and method of processing, the type of personal information, and the method and procedure for individuals to exercise their rights under laws and regulations with respect to the overseas recipient; (2) obtain the individual’s separate consent, except where laws and regulations provide that separate consent is not required; and (3) conduct a personal information protection impact assessment.
Article 8 — Local cyberspace administrations shall strengthen guidance and supervision of data processors’ data export activities, improve the efficiency of data export security assessments, and enhance the facilitation of cross-border data flow. Cyberspace administrations at all levels shall perform their regulatory duties in accordance with the law, and where they discover that data export activities involve significant risks or security incidents, they shall require data processors to take corrective measures in accordance with the law.
Article 9 — These Provisions shall take effect from the date of promulgation. Where relevant provisions previously issued are inconsistent with these Provisions, these Provisions shall prevail.
Disclaimer: This English translation is provided for reference and informational purposes only. While every effort has been made to ensure accuracy and completeness, this is not an official translation. The original Chinese text shall prevail as the authoritative version. Dan Young Business Consultancy makes no representations or warranties, express or implied, as to the accuracy, completeness, or suitability of this translation for any particular purpose. Readers should consult qualified legal professionals for advice on specific legal matters and refer to the official Chinese text for authoritative interpretation. Neither Dan Young Business Consultancy nor any of its affiliates shall be liable for any loss or damage arising from reliance on this translation.
Free PDF download of the complete article.