Provisions on Promoting and Regulating Cross-Border Data Flows
Version and sources (verifiable)
Item Content Promulgated 22 March 2024 by the Cyberspace Administration of China (Order No. 16); effective on the date of promulgation Structure 14 articles Currently effective Yes (as of 2026-09-22) Chinese original https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm English version No official English translation published. This English text is a translation by our editorial team, cross-checked article by article against the official Chinese text; it is not an official translation and is for reference only. Where a term has an established rendering in official translations of the Cybersecurity Law, the Data Security Law and the Personal Information Protection Law, that rendering is used. Verification Retrieved 2026-09-22; 14 articles, correspondence with the Chinese text verified one-for-one, no gaps
Article 1 These Provisions are formulated in accordance with the Cybersecurity Law of the People’s Republic of China, the Data Security Law of the People’s Republic of China, the Personal Information Protection Law of the People’s Republic of China and other laws and regulations, for the purposes of safeguarding data security, protecting the rights and interests of personal information, and promoting the lawful, orderly and free flow of data, and in order to govern the implementation of the data export regimes — security assessment of data export, standard contracts for the export of personal information, and personal information protection certification.
Article 2 Data processors shall identify and report important data in accordance with relevant provisions. Where no department or region has notified or publicly released data as important data, the data processor is not required to report it as important data for the security assessment of data export.
Article 3 Where data collected and generated in activities such as international trade, cross-border transportation, academic cooperation, cross-border manufacturing and marketing are provided overseas and do not contain personal information or important data, the data processor is exempted from reporting for the security assessment of data export, from concluding standard contracts for the export of personal information, and from obtaining personal information protection certification.
Article 4 Where personal information collected and generated overseas by a data processor is transmitted into China for processing and is thereafter provided overseas again, and no personal information or important data within China was introduced in the course of processing, the data processor is exempted from reporting for the security assessment of data export, from concluding standard contracts for the export of personal information, and from obtaining personal information protection certification.
Article 5 Where a data processor provides personal information overseas and meets any of the following conditions, it is exempted from reporting for the security assessment of data export, from concluding standard contracts for the export of personal information, and from obtaining personal information protection certification:
(1) where it is genuinely necessary to provide personal information overseas for the conclusion or performance of a contract to which the individual is a party, such as cross-border shopping, cross-border delivery, cross-border remittance, cross-border payment, cross-border account opening, air ticket and hotel booking, visa application, and examination services;
(2) where it is genuinely necessary to provide employees’ personal information overseas for the implementation of cross-border human resources management in accordance with labour rules and regulations formulated according to law and collective contracts concluded according to law;
(3) where it is genuinely necessary to provide personal information overseas in an emergency to protect the life, health and property safety of natural persons;
(4) where a data processor other than a critical information infrastructure operator has cumulatively provided overseas the personal information of fewer than 100,000 individuals (excluding sensitive personal information) since 1 January of the current year.
The personal information provided overseas referred to in the preceding paragraph does not include important data.
Article 6 Within the framework of the national data classification and grading protection system, a pilot free trade zone may itself formulate a list of data within the zone that is to be included in the scope of the security assessment of data export, the standard contracts for the export of personal information, and personal information protection certification (hereinafter the “negative list”), and after approval by the provincial cyberspace and informatisation commission, shall file it with the national cyberspace administration department and the national data administration department. Where a data processor within a pilot free trade zone provides overseas data that is outside the negative list, it is exempted from reporting for the security assessment of data export, from concluding standard contracts for the export of personal information, and from obtaining personal information protection certification.
Article 7 Where a data processor provides data overseas and meets any of the following conditions, it shall, through the cyberspace administration department of the province where it is located, report to the national cyberspace administration department for the security assessment of data export:
(1) a critical information infrastructure operator provides personal information or important data overseas;
(2) a data processor other than a critical information infrastructure operator provides important data overseas, or has cumulatively provided overseas the personal information of more than 1,000,000 individuals (excluding sensitive personal information), or the sensitive personal information of more than 10,000 individuals, since 1 January of the current year.
Where any of the circumstances provided for in Articles 3, 4, 5 and 6 of these Provisions applies, those provisions shall prevail.
Article 8 Where a data processor other than a critical information infrastructure operator has cumulatively provided overseas the personal information of 100,000 or more but fewer than 1,000,000 individuals (excluding sensitive personal information), or the sensitive personal information of fewer than 10,000 individuals, since 1 January of the current year, it shall, in accordance with law, conclude with the overseas recipient a standard contract for the export of personal information, or obtain personal information protection certification. Where any of the circumstances provided for in Articles 3, 4, 5 and 6 of these Provisions applies, those provisions shall prevail.
Article 9 The result of a security assessment of data export is valid for three years, counted from the date on which the assessment result is issued. Where the validity period expires and the data processor needs to continue the data export activities and no circumstance requiring a fresh report for the security assessment of data export has occurred, the data processor may, within 60 working days before the expiry of the validity period, apply through the cyberspace administration department of the province where it is located to the national cyberspace administration department for an extension of the validity period of the assessment result. Upon approval by the national cyberspace administration department, the validity period of the assessment result may be extended by three years.
Article 10 Where a data processor provides personal information overseas, it shall, in accordance with laws and administrative regulations, perform obligations including informing the individual, obtaining the individual’s separate consent, and conducting a personal information protection impact assessment.
Article 11 Where a data processor provides data overseas, it shall comply with laws and regulations, perform its data security protection obligations, and adopt technical measures and other necessary measures to ensure the security of data export. Where a data security incident occurs or is likely to occur, it shall adopt remedial measures and promptly report to the cyberspace administration department at or above the provincial level and other competent departments.
Article 12 Cyberspace administration departments in all localities shall strengthen guidance and supervision over the data export activities of data processors, improve the security assessment system for data export, and optimise the assessment process; strengthen whole-chain, whole-process and all-round supervision before, during and after the event, and where data export activities present relatively high risks or a data security incident occurs, require the data processor to rectify and eliminate the hidden danger; and where the data processor refuses to rectify or causes serious consequences, pursue legal liability in accordance with law.
Article 13 Where relevant provisions such as the Measures for the Security Assessment of Data Export (Cyberspace Administration of China Order No. 11), promulgated on 7 July 2022, and the Measures for Standard Contracts for the Export of Personal Information (Cyberspace Administration of China Order No. 13), promulgated on 22 February 2023, are inconsistent with these Provisions, these Provisions shall prevail.
Article 14 These Provisions shall come into force on the date of promulgation.