TLDR; Below is the English-translated version of China’s Provisions on Promoting and Regulating Cross-Border Data Flows (促进和规范数据跨境流动规定, Cyberspace Administration of China Order No. 16), adopted November 28, 2023 and in effect since March 22, 2024.
If your company moves customer, employee, or operational data out of mainland China, these Provisions are the 2024 rules that decide which cross-border route you must take — and, in many common cases, whether you need one at all. Issued by the Cyberspace Administration of China as Order No. 16, they relax and clarify the thresholds that trigger the Outbound Data Transfer Security Assessment Measures, the Personal Information Standard Contract Measures, and personal information protection certification, and they add exemptions and free-trade-zone negative lists on top of the baseline obligations set by the Personal Information Protection Law (PIPL). Because they change when each route applies, they should be read together with the measures they modify.
Provisions on Promoting and Regulating Cross-Border Data Flows (Adopted November 28, 2023; published and effective March 22, 2024 by Order No. 16 of the Cyberspace Administration of China)
Article 1. In order to safeguard data security, protect the rights and interests in personal information, and promote the lawful, orderly, and free flow of data, and in accordance with the “Cybersecurity Law of the People’s Republic of China,” the “Data Security Law of the People’s Republic of China,” the “Personal Information Protection Law of the People’s Republic of China,” and other laws and regulations, these Provisions are formulated with respect to the implementation of the outbound-data-transfer systems, including the security assessment for outbound data transfer, the standard contract for the outbound transfer of personal information, and personal information protection certification.
Article 2. Data processors shall identify and declare important data in accordance with the relevant provisions. Where data has not been notified or publicly released as important data by the relevant departments or regions, a data processor is not required to declare it as important data for a security assessment for outbound data transfer.
Article 3. Where data collected and generated in activities such as international trade, cross-border transportation, academic cooperation, transnational manufacturing, and marketing is provided overseas, and such data does not contain personal information or important data, it is exempt from declaring a security assessment for outbound data transfer, concluding a standard contract for the outbound transfer of personal information, and passing personal information protection certification.
Article 4. Where personal information collected and generated by a data processor overseas is transmitted into China for processing and then provided overseas, and no domestic personal information or important data is introduced during the course of processing, it is exempt from declaring a security assessment for outbound data transfer, concluding a standard contract for the outbound transfer of personal information, and passing personal information protection certification.
Article 5. Where a data processor provides personal information overseas and one of the following conditions is met, it is exempt from declaring a security assessment for outbound data transfer, concluding a standard contract for the outbound transfer of personal information, and passing personal information protection certification:
(1) Where it is genuinely necessary to provide personal information overseas in order to conclude or perform a contract to which the individual is a party, such as cross-border shopping, cross-border delivery, cross-border remittance, cross-border payment, cross-border account opening, airline ticket and hotel booking, visa processing, or examination services;
(2) Where it is genuinely necessary to provide employees’ personal information overseas in order to carry out cross-border human resources management in accordance with labor rules and regulations formulated in accordance with law and collective contracts concluded in accordance with law;
(3) Where it is genuinely necessary to provide personal information overseas in order to protect the life, health, and property safety of natural persons in an emergency;
(4) Where a data processor other than a critical information infrastructure operator has provided overseas, cumulatively since January 1 of the current year, the personal information of fewer than 100,000 individuals (not including sensitive personal information).
The personal information provided overseas referred to in the preceding paragraph does not include important data.
Article 6. Within the framework of the national data classification and grading protection system, a pilot free trade zone may, on its own, formulate a list of data within the zone that needs to be brought within the scope of administration of the security assessment for outbound data transfer, the standard contract for the outbound transfer of personal information, and personal information protection certification (hereinafter referred to as the “negative list”); after approval by the provincial-level cybersecurity and informatization commission, the list shall be filed for the record with the national cyberspace administration department and the national data administration department.
Where a data processor within a pilot free trade zone provides overseas data that is outside the negative list, it may be exempt from declaring a security assessment for outbound data transfer, concluding a standard contract for the outbound transfer of personal information, and passing personal information protection certification.
Article 7. Where a data processor provides data overseas and one of the following conditions is met, it shall declare a security assessment for outbound data transfer to the national cyberspace administration department through the provincial-level cyberspace administration department of its locality:
(1) A critical information infrastructure operator provides personal information or important data overseas;
(2) A data processor other than a critical information infrastructure operator provides important data overseas, or has provided overseas, cumulatively since January 1 of the current year, the personal information of 1 million or more individuals (not including sensitive personal information) or the sensitive personal information of 10,000 or more individuals.
Where a situation falls under the circumstances provided for in Articles 3, 4, 5, or 6 of these Provisions, those provisions shall apply.
Article 8. Where a data processor other than a critical information infrastructure operator has provided overseas, cumulatively since January 1 of the current year, the personal information of 100,000 or more but fewer than 1 million individuals (not including sensitive personal information), or the sensitive personal information of fewer than 10,000 individuals, it shall, in accordance with law, conclude a standard contract for the outbound transfer of personal information with the overseas recipient or pass personal information protection certification.
Where a situation falls under the circumstances provided for in Articles 3, 4, 5, or 6 of these Provisions, those provisions shall apply.
Article 9. The result of passing a security assessment for outbound data transfer is valid for three years, calculated from the date on which the assessment result is issued. Where, upon expiration of the period of validity, it is necessary to continue carrying out outbound-data-transfer activities and no circumstance has arisen that would require a renewed declaration of a security assessment for outbound data transfer, the data processor may, within 60 working days before the expiration of the period of validity, submit to the national cyberspace administration department, through the provincial-level cyberspace administration department of its locality, an application to extend the period of validity of the assessment result. With the approval of the national cyberspace administration department, the period of validity of the assessment result may be extended by three years.
Article 10. Where a data processor provides personal information overseas, it shall, in accordance with the provisions of laws and administrative regulations, fulfill obligations such as notification, obtaining the separate consent of the individual, and conducting a personal information protection impact assessment.
Article 11. Where a data processor provides data overseas, it shall comply with the provisions of laws and regulations, fulfill its data security protection obligations, and take technical measures and other necessary measures to safeguard the security of outbound data transfer. Where a data security incident occurs or may occur, it shall take remedial measures and promptly report to the cyberspace administration department at or above the provincial level and other relevant competent authorities.
Article 12. Cyberspace administration departments in all localities shall strengthen guidance and supervision over the outbound-data-transfer activities of data processors, improve and perfect the security assessment system for outbound data transfer, and optimize the assessment process; they shall strengthen whole-chain and whole-field supervision before, during, and after the event, and where they find that outbound-data-transfer activities pose a relatively large risk or that a data security incident has occurred, they shall require the data processor to make rectifications and eliminate hidden dangers; where a data processor refuses to make corrections or causes serious consequences, legal liability shall be pursued in accordance with law.
Article 13. Where the relevant provisions of the “Measures for the Security Assessment of Outbound Data Transfer” promulgated on July 7, 2022 (Order No. 11 of the Cyberspace Administration of China), the “Measures on the Standard Contract for the Outbound Transfer of Personal Information” promulgated on February 22, 2023 (Order No. 13 of the Cyberspace Administration of China), and the like are inconsistent with these Provisions, these Provisions shall apply.
Article 14. These Provisions shall take effect as of the date of promulgation.
Closing
The original document was published in Chinese by the Cyberspace Administration of China; we translated it into English, which is what you read above. This translation is provided for quick comprehension only and should be used at your own discretion and risk — always confirm the current requirements with qualified legal counsel.
If you need further help from our team, contact us today, and our experts will help you keep your presence in China compliant from the ground up.