What the cross-border instruments actually say
| Fact | Primary source |
|---|---|
| PIPL Article 3: the law applies to processing outside China of personal information of people in China where the purpose is providing products or services to them, or analysing or assessing their behaviour — no mainland infrastructure required. | Personal Information Protection Law, Article 3 |
| PIPL Article 38: exporting personal information requires one of a CAC security assessment, personal information protection certification, or the CAC standard contract with the overseas recipient. | Personal Information Protection Law, Article 38 |
| PIPL Article 39: the individual must be told the overseas recipient’s identity, purpose, method and data categories, and must give separate consent (单独同意) — a general privacy-policy acceptance does not carry it. | Personal Information Protection Law, Article 39 |
| PIPL Article 40: data localisation attaches to critical information infrastructure operators and to processors above a CAC-specified volume — not to every company processing Chinese personal information. | Personal Information Protection Law, Article 40 |
| 2024 Provisions, Article 5(4): a non-CIIO data processor exporting the personal information of fewer than 100,000 individuals (excluding sensitive personal information) cumulatively since 1 January of the current year is exempt from all three Article 38 mechanisms. | CAC Order No. 16 (2024), Provisions on Promoting and Regulating Cross-Border Data Flows, Article 5 |
| 2024 Provisions, Article 8: 100,000 to under 1,000,000 individuals (non-sensitive), or under 10,000 people of sensitive personal information, requires a standard contract or certification. | CAC Order No. 16 (2024), Article 8 |
| 2024 Provisions, Article 7: 1,000,000 or more individuals (non-sensitive), 10,000 or more people of sensitive personal information, or any important data, requires a security assessment; a passed assessment is valid for 3 years and extendable by 3 more (Article 9). | CAC Order No. 16 (2024), Articles 7 and 9 |
| 2024 Provisions, Article 2: a processor need not declare data as important data for assessment unless a relevant authority or region has notified it or published it as such. | CAC Order No. 16 (2024), Article 2 |
| PIPL Article 53: an overseas processor caught by Article 3 must establish a dedicated body or designate a representative inside China and report it to the authority. | Personal Information Protection Law, Article 53 |
| PIPL Article 66: in serious cases, a fine of up to RMB 50 million or 5% of the previous year’s turnover, with possible suspension of the business; the first paragraph also allows an order to suspend or terminate a non-compliant application. | Personal Information Protection Law, Article 66 |
Sources verified by the 21YunBox compliance team on 2026-08-28.
Most English-language summaries of China’s cross-border data rules describe the regime as it stood in 2021 and stop there. The three compliance routes they list are real, but a 2024 instrument then exempted a large share of ordinary companies from all three — and the difference between being in scope and being exempt is a specific, countable number.
This page quotes the operative articles and says what each one means for a foreign company running a website or app that reaches users in mainland China. Full texts are linked at the bottom; nothing here replaces reading them or taking Chinese legal advice.
Instruments: 《中华人民共和国个人信息保护法》 — Personal Information Protection Law (PIPL), in force since 1 November 2021, Chapter 3 being the cross-border chapter; and 《促进和规范数据跨境流动规定》 — Provisions on Promoting and Regulating Cross-Border Data Flows, Cyberspace Administration of China Order No. 16, in force since 22 March 2024.
The law reaches you before any server does
第三条 在中华人民共和国境内处理自然人个人信息的活动,适用本法。
在中华人民共和国境外处理中华人民共和国境内自然人个人信息的活动,有下列情形之一的,也适用本法:(一)以向境内自然人提供产品或者服务为目的;(二)分析、评估境内自然人的行为;(三)法律、行政法规规定的其他情形。
Article 3. This Law applies to the processing of natural persons’ personal information within the territory of the People’s Republic of China. It also applies to processing outside the territory of personal information of natural persons inside the territory where: (1) the purpose is to provide products or services to persons inside the territory; (2) the behaviour of persons inside the territory is analysed or assessed; (3) other circumstances provided by law or administrative regulation.
In practice: this is the article that surprises people. PIPL is not triggered by putting infrastructure in China. It is triggered by aiming at people in China. A site hosted entirely in Frankfurt, with no Chinese entity and no mainland server, that markets to Chinese users or runs analytics on their behaviour, is inside the scope of this law. Deciding not to serve from inside China does not opt you out of it.
Sending personal information out requires one of three routes
第三十八条 个人信息处理者因业务等需要,确需向中华人民共和国境外提供个人信息的,应当具备下列条件之一:(一)依照本法第四十条的规定通过国家网信部门组织的安全评估;(二)按照国家网信部门的规定经专业机构进行个人信息保护认证;(三)按照国家网信部门制定的标准合同与境外接收方订立合同,约定双方的权利和义务;(四)法律、行政法规或者国家网信部门规定的其他条件。
Article 38. Where a personal information processor genuinely needs to provide personal information outside the territory for business or other reasons, it shall meet one of the following conditions: (1) pass a security assessment organised by the State cyberspace authority under Article 40; (2) obtain personal information protection certification from a professional body as prescribed by the State cyberspace authority; (3) conclude a contract with the overseas recipient using the standard contract formulated by the State cyberspace authority, setting out both parties’ rights and obligations; (4) other conditions prescribed by law, administrative regulation, or the State cyberspace authority.
In practice: security assessment, certification, or standard contract. These three are what nearly every summary lists. What most of them omit is that limb (4) is not decorative — it is the hook the 2024 provisions hang on, and it is the reason the list above is no longer the whole answer.
And separate consent, on top of whatever consent you already had
第三十九条 个人信息处理者向中华人民共和国境外提供个人信息的,应当向个人告知境外接收方的名称或者姓名、联系方式、处理目的、处理方式、个人信息的种类以及个人向境外接收方行使本法规定权利的方式和程序等事项,并取得个人的单独同意。
Article 39. A personal information processor providing personal information outside the territory shall inform the individual of the overseas recipient’s name, contact details, purpose and method of processing, the categories of personal information, and how the individual may exercise their rights against the overseas recipient — and shall obtain the individual’s separate consent.
In practice: 单独同意, separate consent, is a distinct act. A general privacy-policy acceptance does not carry it. This obligation survives the 2024 exemptions — being exempt from the security assessment does not exempt you from telling people and asking them specifically.
Localisation applies to a defined group, not to everyone
第四十条 关键信息基础设施运营者和处理个人信息达到国家网信部门规定数量的个人信息处理者,应当将在中华人民共和国境内收集和产生的个人信息存储在境内。确需向境外提供的,应当通过国家网信部门组织的安全评估……
Article 40. Critical information infrastructure operators, and personal information processors whose processing reaches the volume specified by the State cyberspace authority, shall store personal information collected and generated within the territory inside the territory. Where it is genuinely necessary to provide it abroad, they shall pass a security assessment organised by the State cyberspace authority …
In practice: data localisation in China is frequently described as a blanket rule. Read the subject of the sentence: it attaches to critical information infrastructure operators and to processors above a volume threshold. Most foreign corporate sites are neither. Assuming localisation applies to you when it does not is expensive in the same way as assuming it does not when it does.
The 2024 provisions are where the thresholds actually live
第五条 数据处理者向境外提供个人信息,符合下列条件之一的,免予申报数据出境安全评估、订立个人信息出境标准合同、通过个人信息保护认证:……(四)关键信息基础设施运营者以外的数据处理者自当年1月1日起累计向境外提供不满10万人个人信息(不含敏感个人信息)的。
Article 5. Where a data processor provides personal information abroad and meets one of the following conditions, it is exempt from applying for a data export security assessment, from concluding a standard contract for personal information export, and from personal information protection certification: … (4) a data processor other than a critical information infrastructure operator that has cumulatively provided abroad, since 1 January of the current year, the personal information of fewer than 100,000 individuals (not including sensitive personal information).
In practice: this is the single most consequential sentence for an ordinary foreign company, and it is the one missing from most guidance written before 2024. Under 100,000 individuals a year, no sensitive data, not a CIIO — and all three of Article 38’s routes fall away. The counter runs per calendar year and resets on 1 January.
Article 5 also exempts transfers necessary to perform a contract the individual is party to — the text names cross-border shopping, shipping, remittance, payment, account opening, flight and hotel booking, visa processing, and examination services — and cross-border HR management under lawful employment rules.
The two thresholds above that
第八条 关键信息基础设施运营者以外的数据处理者自当年1月1日起累计向境外提供10万人以上、不满100万人个人信息(不含敏感个人信息)或者不满1万人敏感个人信息的,应当依法与境外接收方订立个人信息出境标准合同或者通过个人信息保护认证。
Article 8. A data processor other than a critical information infrastructure operator that has cumulatively provided abroad, since 1 January of the current year, the personal information of 100,000 or more but fewer than 1,000,000 individuals (not including sensitive personal information), or the sensitive personal information of fewer than 10,000 individuals, shall conclude a standard contract with the overseas recipient or obtain personal information protection certification.
第七条 ……(二)关键信息基础设施运营者以外的数据处理者向境外提供重要数据,或者自当年1月1日起累计向境外提供100万人以上个人信息(不含敏感个人信息)或者1万人以上敏感个人信息。
Article 7. … (2) a data processor other than a critical information infrastructure operator that provides important data abroad, or that has cumulatively provided abroad, since 1 January of the current year, the personal information of 1,000,000 or more individuals (not including sensitive personal information) or the sensitive personal information of 10,000 or more individuals — must apply for a security assessment through its provincial cyberspace authority.
In practice: three bands, one axis. Below 100,000 people: exempt. Between 100,000 and 1,000,000, or any sensitive data below 10,000 people: standard contract or certification. At or above 1,000,000, or 10,000 people of sensitive data, or any important data: security assessment. Critical information infrastructure operators sit outside the bands and go to assessment regardless. A passed assessment is valid for three years and can be extended by another three on application.
And a foreign processor has to have someone here
第五十三条 本法第三条第二款规定的中华人民共和国境外的个人信息处理者,应当在中华人民共和国境内设立专门机构或者指定代表,负责处理个人信息保护相关事务……
Article 53. A personal information processor outside the territory falling under the second paragraph of Article 3 shall establish a dedicated body or designate a representative within the territory to be responsible for personal information protection matters …
In practice: if Article 3 catches you, Article 53 follows. The obligation to have a named local point of accountability does not depend on holding an ICP filing or running any mainland infrastructure.
What non-compliance costs
第六十六条 ……情节严重的,由省级以上履行个人信息保护职责的部门责令改正,没收违法所得,并处五千万元以下或者上一年度营业额百分之五以下罚款,并可以责令暂停相关业务或者停业整顿……
Article 66. … where the circumstances are serious, the authority at provincial level or above shall order rectification, confiscate unlawful gains, and impose a fine of up to RMB 50 million or up to 5 per cent of the previous year’s turnover, and may order suspension of the relevant business or suspension for rectification …
In practice: unlike the filing regime, this one is genuinely monetary, and the turnover limb is not capped at a Chinese subsidiary’s revenue on its face. The first paragraph of the same article also allows an order to suspend or terminate a non-compliant application.
What these instruments do not decide
- Whether you need an ICP filing. A different regime with a different trigger — serving from inside mainland China. We set out what the filing rule requires.
- Whether your site is reachable. Nothing in PIPL makes a page load. That is the other gate, and we have measured what each delivery arrangement actually buys.
- Important data. Article 2 of the 2024 provisions says a processor need not declare data as important data unless a relevant authority or region has told it so or published it as such — a meaningful change from having to self-assess.
Why this decides architecture, not just paperwork
The two gates are separate but they interact here. Serving from inside mainland China puts you inside the ICP filing regime; it does not by itself create a cross-border transfer problem, and it can reduce one, because data collected and kept inside the territory is not being exported at all. Serving from outside avoids the filing regime and leaves Article 3 applying to you anyway. Neither direction is free, and the choice is made once, early, in the delivery design — which is why we treat reachability and permission as one decision rather than two. Our reference page on delivery options sets out how they fit together.
Primary sources: 《中华人民共和国个人信息保护法》, full text published by the Cyberspace Administration of China: cac.gov.cn; our article-by-article English rendering is at China Personal Information Protection Law. 《促进和规范数据跨境流动规定》(国家互联网信息办公室令第16号), full text in the State Council Gazette: State Council Gazette, 2024, No. 15.
Translations above are ours and are provided for orientation only. Where the English and the Chinese differ, the Chinese governs. Thresholds are stated as they appear in the instruments as at 28 August 2026. This page is not legal advice.