TLDR; Below is the English-translated version of China’s Measures on the Standard Contract for the Outbound Transfer of Personal Information (个人信息出境标准合同办法, Cyberspace Administration of China Order No. 13), published February 24, 2023 and in effect since June 1, 2023.


If your company moves customer, employee, or user personal information out of mainland China — to overseas servers, affiliates, or vendors — these Measures set out one of the lawful export routes created by the Personal Information Protection Law (PIPL): the “standard contract” route of PIPL Article 38(3), available to data handlers whose volumes fall below the thresholds that would otherwise require a government-led security assessment. They define who qualifies, the personal information protection impact assessment that must be completed first, the contract that must be signed with the overseas recipient, and the 10-working-day filing owed to the provincial cyberspace administration once that contract takes effect. Alongside the Data Security Law and the Cybersecurity Law, PIPL forms the core of the cross-border data regime that every international business should confirm with qualified counsel before exporting data from the mainland.


Measures on the Standard Contract for the Outbound Transfer of Personal Information (Published February 24, 2023 by Order No. 13 of the Cyberspace Administration of China; effective June 1, 2023)

Article 1. These Measures are formulated in accordance with the “Personal Information Protection Law of the People’s Republic of China” and other laws and regulations, in order to protect the rights and interests in personal information and to regulate outbound transfers of personal information.

Article 2. These Measures apply where a personal information handler provides personal information to recipients outside the territory of the People’s Republic of China by entering into a standard contract for the outbound transfer of personal information (hereinafter referred to as the “standard contract”) with the overseas recipient.

Article 3. Carrying out the outbound transfer of personal information by entering into a standard contract shall adhere to combining autonomous contracting with filing-based administration, and combining the protection of rights and interests with the prevention of risks, so as to ensure the secure and free cross-border flow of personal information.

Article 4. A personal information handler that provides personal information overseas by entering into a standard contract shall meet all of the following conditions at the same time:

(1) It is not a critical information infrastructure operator;

(2) It processes the personal information of fewer than 1 million persons;

(3) It has provided overseas, cumulatively since January 1 of the preceding year, the personal information of fewer than 100,000 persons;

(4) It has provided overseas, cumulatively since January 1 of the preceding year, the sensitive personal information of fewer than 10,000 persons.

Where laws, administrative regulations, or the national cyberspace administration provide otherwise, those provisions shall prevail.

A personal information handler shall not use means such as splitting up quantities to provide overseas, through a standard contract, personal information that by law should undergo a security assessment for outbound transfer.

Article 5. Before providing personal information overseas, a personal information handler shall conduct a personal information protection impact assessment, focusing on the following:

(1) The legality, legitimacy, and necessity of the purpose, scope, and means by which the personal information handler and the overseas recipient process the personal information;

(2) The scale, scope, categories, and sensitivity of the personal information to be transferred overseas, and the risks that the outbound transfer may pose to the rights and interests in personal information;

(3) The obligations that the overseas recipient undertakes to assume, and whether the management and technical measures, capabilities, and the like for performing those obligations are able to ensure the security of the personal information transferred overseas;

(4) The risk that the personal information will be tampered with, damaged, leaked, lost, or illegally used after the outbound transfer, and whether the channels for safeguarding the rights and interests in personal information are unobstructed, among other matters;

(5) The impact that the personal information protection policies and regulations of the country or region where the overseas recipient is located have on performance of the standard contract;

(6) Other matters that may affect the security of the outbound transfer of personal information.

Article 6. The standard contract shall be concluded strictly in accordance with the annex to these Measures. The national cyberspace administration may adjust the annex in light of actual circumstances.

A personal information handler may agree on other terms with the overseas recipient, provided that they do not conflict with the standard contract.

The outbound transfer of personal information may be carried out only after the standard contract takes effect.

Editor’s note: The Standard Contract template referred to in this Article is a separate annex to the original document and is not reproduced in this translation; only the thirteen articles of the Measures are translated here.

Article 7. A personal information handler shall, within 10 working days from the date on which the standard contract takes effect, file a record with the provincial-level cyberspace administration of the place where it is located. The following materials shall be submitted for the filing:

(1) The standard contract;

(2) The personal information protection impact assessment report.

The personal information handler shall be responsible for the authenticity of the materials filed.

Article 8. Where any of the following circumstances arises during the term of validity of the standard contract, the personal information handler shall conduct a fresh personal information protection impact assessment, supplement or re-conclude the standard contract, and complete the corresponding filing formalities:

(1) A change occurs in the purpose, scope, categories, sensitivity, means, or storage location of the personal information provided overseas, or in the purpose or means by which the overseas recipient processes the personal information, or the period of overseas storage of the personal information is extended;

(2) A change occurs in the personal information protection policies and regulations of the country or region where the overseas recipient is located, or there is another such change that may affect the rights and interests in personal information;

(3) Other circumstances that may affect the rights and interests in personal information.

Article 9. The cyberspace administration and its staff shall, in accordance with law, keep confidential any personal privacy, personal information, commercial secrets, confidential business information, and the like that they become aware of in the performance of their duties, and shall not disclose such information, illegally provide it to others, or illegally use it.

Article 10. Any organization or individual that discovers a personal information handler providing personal information overseas in violation of these Measures may report it to the cyberspace administration at or above the provincial level.

Article 11. Where the cyberspace administration at or above the provincial level finds that an outbound transfer of personal information poses relatively large risks or that a personal information security incident has occurred, it may, in accordance with law, conduct a regulatory interview with the personal information handler. The personal information handler shall make rectifications as required and eliminate the hidden dangers.

Article 12. Violations of the provisions of these Measures shall be dealt with in accordance with the “Personal Information Protection Law of the People’s Republic of China” and other laws and regulations; where a crime is constituted, criminal liability shall be pursued in accordance with law.

Article 13. These Measures shall take effect on June 1, 2023. Outbound transfers of personal information already carried out before the implementation of these Measures that do not conform to the provisions of these Measures shall be rectified within 6 months from the date these Measures take effect.



Closing

The original document was published in Chinese by the Cyberspace Administration of China; we translated it into English, which is what you read above. This translation is provided for quick comprehension only and should be used at your own discretion and risk — always confirm the current requirements with qualified legal counsel.

If you need further help from our team, contact us today, and our experts will help you keep your presence in China compliant from the ground up.


Ready to make your app work in China?

Get Started Questions? Talk to an expert.

Ready to try 21YunBox?

Get Started