TLDR; Below is the English-translated version of China’s Measures for the Security Assessment of Outbound Data Transfers (数据出境安全评估办法, Cyberspace Administration of China Order No. 11), published July 7, 2022 and in effect since September 1, 2022.


If your company moves personal information or any “important data” out of mainland China — to a parent company, an overseas cloud region, or a third-party processor — these Measures define when that transfer must first clear a government-run security assessment rather than a lighter route. They operationalize the cross-border transfer rules of the Personal Information Protection Law (PIPL), the data-classification scheme of the Data Security Law, and the critical-information-infrastructure regime of the Cybersecurity Law, setting hard thresholds that trigger a mandatory filing with the Cyberspace Administration of China. For many international businesses this is the single most consequential data-compliance checkpoint, and one to confirm with counsel well before any data leaves the country.


Measures for the Security Assessment of Outbound Data Transfers (Published July 7, 2022 by Order No. 11 of the Cyberspace Administration of China; effective September 1, 2022)

Article 1. These Measures are formulated in accordance with the “Cybersecurity Law of the People’s Republic of China,” the “Data Security Law of the People’s Republic of China,” the “Personal Information Protection Law of the People’s Republic of China,” and other laws and regulations, in order to regulate data export activities, protect the rights and interests in personal information, safeguard national security and the public interest of society, and promote the secure and free flow of data across borders.

Article 2. These Measures apply to the security assessment of important data and personal information that a data processor collects and generates in the course of operations within the territory of the People’s Republic of China and provides to overseas recipients. Where laws or administrative regulations provide otherwise, those provisions shall apply.

Article 3. The security assessment of outbound data transfers adheres to combining prior assessment with continuous supervision and combining risk self-assessment with security assessment, so as to guard against the security risks of data export and to ensure the lawful, orderly, and free flow of data.

Article 4. Where a data processor provides data to overseas recipients under any of the following circumstances, it shall, through the provincial-level cyberspace administration department of its locality, declare a security assessment of the outbound data transfer to the national cyberspace administration department:

(1) where a data processor provides important data to overseas recipients;

(2) where a critical information infrastructure operator, or a data processor that processes the personal information of more than 1 million people, provides personal information to overseas recipients;

(3) where a data processor that has, cumulatively since January 1 of the preceding year, provided the personal information of 100,000 people or the sensitive personal information of 10,000 people to overseas recipients provides personal information to overseas recipients;

(4) other circumstances in which, as prescribed by the national cyberspace administration department, a security assessment of the outbound data transfer must be declared.

Article 5. Before declaring a security assessment of an outbound data transfer, a data processor shall conduct a self-assessment of the risks of the data export, focusing on the following matters:

(1) the legality, legitimacy, and necessity of the purpose, scope, and method of the data export and of the processing of the data by the overseas recipient;

(2) the scale, scope, type, and sensitivity of the outbound data, and the risks that the data export may pose to national security, the public interest, and the lawful rights and interests of individuals or organizations;

(3) whether the responsibilities and obligations that the overseas recipient commits to undertake, together with the management and technical measures and capabilities for performing those responsibilities and obligations, can ensure the security of the outbound data;

(4) the risk that the data is tampered with, damaged, leaked, lost, or transferred, or is illegally obtained or illegally used, during and after the export, and whether the channels for protecting the rights and interests in personal information are unobstructed, among other things;

(5) whether the data-export-related contract or other legally binding documents to be concluded with the overseas recipient (hereinafter collectively referred to as the “legal documents”) adequately stipulate the responsibilities and obligations for data security protection;

(6) other matters that may affect the security of the data export.

Article 6. To declare a security assessment of an outbound data transfer, the following materials shall be submitted:

(1) a declaration form;

(2) a self-assessment report on the risks of the outbound data transfer;

(3) the legal documents to be concluded between the data processor and the overseas recipient;

(4) other materials required for the security assessment work.

Article 7. The provincial-level cyberspace administration department shall complete a completeness check within 5 working days from the date of receiving the declaration materials. Where the declaration materials are complete, it shall forward them to the national cyberspace administration department; where the declaration materials are incomplete, it shall return them to the data processor and inform it, on a one-time basis, of the materials that need to be supplemented.

The national cyberspace administration department shall, within 7 working days from the date of receiving the declaration materials, determine whether to accept the declaration and notify the data processor in writing.

Article 8. The security assessment of an outbound data transfer focuses on assessing the risks that the data export activity may pose to national security, the public interest, and the lawful rights and interests of individuals or organizations, mainly including the following matters:

(1) the legality, legitimacy, and necessity of the purpose, scope, and method of the data export;

(2) the impact on the security of the outbound data of the data security protection policies, laws, and regulations and of the cybersecurity environment of the country or region where the overseas recipient is located; and whether the overseas recipient’s level of data protection meets the requirements of the laws and administrative regulations of the People’s Republic of China and of the mandatory national standards;

(3) the scale, scope, type, and sensitivity of the outbound data, and the risk that it is tampered with, damaged, leaked, lost, or transferred, or is illegally obtained or illegally used, during and after the export;

(4) whether data security and the rights and interests in personal information can be fully and effectively safeguarded;

(5) whether the legal documents to be concluded between the data processor and the overseas recipient adequately stipulate the responsibilities and obligations for data security protection;

(6) compliance with Chinese laws, administrative regulations, and departmental rules;

(7) other matters that the national cyberspace administration department considers necessary to assess.

Article 9. A data processor shall expressly stipulate the responsibilities and obligations for data security protection in the legal documents concluded with the overseas recipient, including at least the following:

(1) the purpose, method, and scope of the data export, and the use and method of the data processing by the overseas recipient;

(2) the location and period of overseas storage of the data, and the measures for handling the outbound data once the storage period is reached, the agreed purpose is accomplished, or the legal documents are terminated;

(3) binding requirements on the overseas recipient’s onward transfer of the outbound data to other organizations or individuals;

(4) the security measures to be taken where there is a substantial change in the actual control or business scope of the overseas recipient, or a change in the data security protection policies, laws, and regulations and the cybersecurity environment of the country or region where it is located, or the occurrence of other force majeure circumstances, that makes it difficult to ensure data security;

(5) the remedial measures, liability for breach, and means of dispute resolution for violating the data security protection obligations stipulated in the legal documents;

(6) the requirements for properly carrying out emergency response where the outbound data is subject to the risk of being tampered with, damaged, leaked, lost, or transferred, or being illegally obtained or illegally used, and the channels and methods for safeguarding individuals’ ability to protect their rights and interests in personal information.

Article 10. After accepting a declaration, the national cyberspace administration department shall, based on the circumstances of the declaration, organize the relevant departments of the State Council, the provincial-level cyberspace administration departments, specialized institutions, and others to conduct the security assessment.

Article 11. Where, during the security assessment, it is found that the declaration materials submitted by the data processor do not meet the requirements, the national cyberspace administration department may require it to supplement or correct them. Where the data processor fails, without a legitimate reason, to supplement or correct them, the national cyberspace administration department may terminate the security assessment.

The data processor is responsible for the authenticity of the materials it submits. Where it intentionally submits false materials, it shall be treated as having failed the assessment, and the corresponding legal liability shall be pursued in accordance with law.

Article 12. The national cyberspace administration department shall complete the security assessment of the outbound data transfer within 45 working days from the date of issuing the written acceptance notice to the data processor; where the circumstances are complex or materials need to be supplemented or corrected, the period may be extended as appropriate, and the data processor shall be informed of the expected extension period.

The assessment result shall be notified to the data processor in writing.

Article 13. Where a data processor has an objection to the assessment result, it may, within 15 working days of receiving the assessment result, apply to the national cyberspace administration department for a re-assessment; the result of the re-assessment shall be final.

Article 14. A result that passes the security assessment of an outbound data transfer is valid for 2 years, calculated from the date the assessment result is issued. Where any of the following circumstances arises during the period of validity, the data processor shall re-declare for assessment:

(1) where there is a change in the purpose, method, scope, or type of the data provided to overseas recipients, or in the use or method of the processing of the data by the overseas recipient, that affects the security of the outbound data, or where the overseas storage period for personal information and important data is extended;

(2) where there is a change in the data security protection policies, laws, and regulations and the cybersecurity environment of the country or region where the overseas recipient is located, or the occurrence of other force majeure circumstances, a change in the actual control of the data processor or the overseas recipient, or a change in the legal documents between the data processor and the overseas recipient, that affects the security of the outbound data;

(3) other circumstances that affect the security of the outbound data arise.

Where the period of validity expires and it is necessary to continue the data export activity, the data processor shall re-declare for assessment 60 working days before the expiration of the period of validity.

Article 15. The relevant institutions and personnel participating in the security assessment work shall, in accordance with law, keep confidential the state secrets, personal privacy, personal information, commercial secrets, confidential business information, and other data that they become aware of in the performance of their duties, and shall not disclose such data, illegally provide it to others, or illegally use it.

Article 16. Any organization or individual that discovers a data processor providing data to overseas recipients in violation of these Measures may report it to a cyberspace administration department at or above the provincial level.

Article 17. Where the national cyberspace administration department finds that a data export activity that has already passed assessment no longer meets the requirements for the security management of outbound data transfers in the course of actual processing, it shall notify the data processor in writing to terminate the data export activity. Where the data processor needs to continue the data export activity, it shall make rectifications as required, and shall re-declare for assessment after the rectification is completed.

Article 18. Violations of the provisions of these Measures shall be dealt with in accordance with the “Cybersecurity Law of the People’s Republic of China,” the “Data Security Law of the People’s Republic of China,” the “Personal Information Protection Law of the People’s Republic of China,” and other laws and regulations; where a crime is constituted, criminal liability shall be pursued in accordance with law.

Article 19. “Important data” as referred to in these Measures means data that, once tampered with, damaged, or leaked, or illegally obtained or illegally used, may endanger national security, economic operations, social stability, public health and safety, and the like.

Article 20. These Measures shall take effect on September 1, 2022. Data export activities already being carried out before these Measures take effect that do not conform to the provisions of these Measures shall complete rectification within 6 months from the date these Measures take effect.



Closing

The original document was published in Chinese by the Cyberspace Administration of China; we translated it into English, which is what you read above. This translation is provided for quick comprehension only and should be used at your own discretion and risk — always confirm the current requirements with qualified legal counsel.

If you need further help from our team, contact us today, and our experts will help you keep your presence in China compliant from the ground up.


Ready to make your app work in China?

Get Started Questions? Talk to an expert.

Ready to try 21YunBox?

Get Started