Measures for the Security Assessment of Data Export
Version and sources (verifiable)
Item Content Promulgated 7 July 2022 by the Cyberspace Administration of China (Order No. 11); deliberated and adopted at the 10th executive meeting of the CAC in 2022 on 19 May 2022; signed by Zhuang Rongwen, Director of the CAC Effective 1 September 2022 Structure 20 articles Currently effective Yes, as amended in operation by the Provisions on Promoting and Regulating Cross-Border Data Flows (2024) — see Article 13 of those Provisions, which prevails in case of inconsistency Chinese original https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm English version No official English translation published. This English text is a translation by our editorial team, cross-checked article by article against the official Chinese text; it is not an official translation and is for reference only. Verification Retrieved 2026-09-22; 20 articles, correspondence with the Chinese text verified one-for-one, no gaps
Article 1 These Measures are formulated in accordance with the Cybersecurity Law of the People’s Republic of China, the Data Security Law of the People’s Republic of China, the Personal Information Protection Law of the People’s Republic of China and other laws and regulations, for the purposes of regulating data export activities, protecting the rights and interests of personal information, safeguarding national security and the public interest, and promoting the secure and free flow of data across borders.
Article 2 These Measures apply to the security assessment of data processors providing overseas important data and personal information collected and generated in the course of operations within the territory of the People’s Republic of China. Where laws and administrative regulations provide otherwise, those provisions shall prevail.
Article 3 The security assessment of data export adheres to combining prior assessment with continuous supervision, and combining self-assessment of risks with security assessment, so as to prevent data export security risks and ensure the lawful, orderly and free flow of data.
Article 4 Where a data processor provides data overseas and any of the following circumstances applies, it shall, through the cyberspace administration department of the province where it is located, report to the national cyberspace administration department for the security assessment of data export:
(1) the data processor provides important data overseas;
(2) a critical information infrastructure operator, or a data processor that processes the personal information of more than 1,000,000 individuals, provides personal information overseas;
(3) a data processor that has cumulatively provided overseas the personal information of 100,000 individuals, or the sensitive personal information of 10,000 individuals, since 1 January of the previous year, provides personal information overseas;
(4) other circumstances requiring a report for the security assessment of data export as provided by the national cyberspace administration department.
Article 5 Before reporting for the security assessment of data export, a data processor shall carry out a self-assessment of the risks of data export, focusing on the following matters:
(1) the lawfulness, legitimacy and necessity of the purposes, scope and methods of the data export and of the overseas recipient’s processing of the data;
(2) the scale, scope, categories and sensitivity of the exported data, and the risks that the data export may pose to national security, the public interest, and the lawful rights and interests of individuals or organisations;
(3) the responsibilities and obligations undertaken by the overseas recipient and whether its management and technical measures and capabilities for performing those responsibilities and obligations can guarantee the security of the exported data;
(4) the risks of the exported data being tampered with, destroyed, leaked, lost, transferred, or illegally obtained or illegally used during and after export, and whether the channels for safeguarding personal information rights and interests are unobstructed;
(5) whether the contract relating to data export or other documents with legal effect (hereinafter collectively “legal documents”) to be concluded with the overseas recipient fully stipulate the responsibilities and obligations for data security protection;
(6) other matters that may affect the security of the data export.
Article 6 The following materials shall be submitted when reporting for the security assessment of data export:
(1) the application form;
(2) the report on the self-assessment of the risks of data export;
(3) the legal documents to be concluded between the data processor and the overseas recipient;
(4) other materials required for the security assessment work.
Article 7 The provincial cyberspace administration department shall complete a completeness check within 5 working days from the date of receipt of the application materials. Where the application materials are complete, it shall submit them to the national cyberspace administration department; where the application materials are incomplete, it shall return them to the data processor and inform it, in a single notification, of the materials to be supplemented.
The national cyberspace administration department shall, within 7 working days from the date of receipt of the application materials, decide whether to accept the application and notify the data processor in writing.
Article 8 The security assessment of data export focuses on assessing the risks that data export activities may pose to national security, the public interest, and the lawful rights and interests of individuals or organisations, mainly including the following matters:
(1) the lawfulness, legitimacy and necessity of the purposes, scope and methods of the data export;
(2) the impact of the data security protection policies, laws and regulations and the cybersecurity environment of the country or region where the overseas recipient is located on the security of the exported data, and whether the overseas recipient’s level of data protection meets the requirements of the laws, administrative regulations and mandatory national standards of the People’s Republic of China;
(3) the scale, scope, categories and sensitivity of the exported data, and the risks of the data being tampered with, destroyed, leaked, lost, transferred, or illegally obtained or illegally used during and after export;
(4) whether data security and personal information rights and interests can be fully and effectively safeguarded;
(5) whether the legal documents to be concluded between the data processor and the overseas recipient fully stipulate the responsibilities and obligations for data security protection;
(6) compliance with Chinese laws, administrative regulations and departmental rules;
(7) other matters that the national cyberspace administration department considers necessary to assess.
Article 9 A data processor shall clearly stipulate in the legal documents concluded with the overseas recipient the responsibilities and obligations for data security protection, including at least the following:
(1) the purposes and methods of the data export and the scope of the data, and the purposes and methods of the overseas recipient’s processing of the data;
(2) the place and period of storage of the data overseas, and the measures for handling the exported data upon expiry of the storage period, completion of the agreed purposes, or termination of the legal documents;
(3) binding requirements on the overseas recipient for the onward transfer of the exported data to other organisations or individuals;
(4) the security measures to be taken where the overseas recipient undergoes a substantive change in actual control or business scope, or where changes in the data security protection policies, laws and regulations and the cybersecurity environment of the country or region where it is located, or other force majeure circumstances, make it difficult to guarantee data security;
(5) the remedial measures, liability for breach and methods of dispute resolution for breach of the data security protection obligations agreed in the legal documents;
(6) the requirements for properly carrying out emergency response where the exported data is at risk of being tampered with, destroyed, leaked, lost, transferred, or illegally obtained or illegally used, and the ways and means of safeguarding individuals’ ability to protect their personal information rights and interests.
Article 10 After accepting a report, the national cyberspace administration department shall organise the relevant departments of the State Council, provincial cyberspace administration departments and specialised agencies to conduct the security assessment according to the circumstances of the report.
Article 11 In the course of the security assessment, where it is found that the application materials submitted by the data processor do not meet the requirements, the national cyberspace administration department may require it to supplement or correct them. Where the data processor fails to supplement or correct them without justified reasons, the national cyberspace administration department may terminate the security assessment.
The data processor is responsible for the authenticity of the materials it submits; where it deliberately submits false materials, the assessment shall be treated as failed and corresponding legal liability shall be pursued in accordance with law.
Article 12 The national cyberspace administration department shall complete the security assessment of data export within 45 working days from the date of issuing the written notice of acceptance to the data processor; where the circumstances are complex or materials need to be supplemented or corrected, the period may be appropriately extended and the data processor shall be informed of the estimated extension.
The assessment result shall be notified to the data processor in writing.
Article 13 Where a data processor objects to the assessment result, it may, within 15 working days of receipt of the assessment result, apply to the national cyberspace administration department for a re-assessment; the re-assessment result is final.
Article 14 The result of a passed security assessment of data export is valid for 2 years, counted from the date on which the assessment result is issued. Where any of the following circumstances occurs within the validity period, the data processor shall re-report for assessment:
(1) changes in the purposes, methods, scope and categories of the data provided overseas or in the purposes and methods of the overseas recipient’s processing of the data affect the security of the exported data, or the period of storage of personal information and important data overseas is extended;
(2) changes in the data security protection policies, laws and regulations and the cybersecurity environment of the country or region where the overseas recipient is located, other force majeure circumstances, changes in the actual control of the data processor or the overseas recipient, or changes to the legal documents between the data processor and the overseas recipient, affect the security of the exported data;
(3) other circumstances affecting the security of the exported data occur.
Where the validity period expires and the data processor needs to continue the data export activities, it shall re-report for assessment 60 working days before the expiry of the validity period.
Article 15 Relevant institutions and personnel participating in the security assessment work shall, in accordance with law, keep confidential the state secrets, personal privacy, personal information, trade secrets, confidential commercial information and other data learned in the performance of their duties, and shall not disclose them or illegally provide them to or illegally use them for others.
Article 16 Where any organisation or individual discovers that a data processor provides data overseas in violation of these Measures, it may report the matter to the cyberspace administration department at or above the provincial level.
Article 17 Where the national cyberspace administration department discovers that data export activities that have passed the assessment no longer meet the data export security management requirements in actual processing, it shall notify the data processor in writing to terminate the data export activities. Where the data processor needs to continue the data export activities, it shall rectify in accordance with the requirements and re-report for assessment after completion of the rectification.
Article 18 Where these Measures are violated, the matter shall be dealt with in accordance with the Cybersecurity Law of the People’s Republic of China, the Data Security Law of the People’s Republic of China, the Personal Information Protection Law of the People’s Republic of China and other laws and regulations; where a crime is constituted, criminal liability shall be pursued in accordance with law.
Article 19 For the purposes of these Measures, “important data” means data that, once tampered with, destroyed, leaked, or illegally obtained or illegally used, may endanger national security, economic operation, social stability, public health and safety, and the like.
Article 20 These Measures shall come into force on 1 September 2022. Where data export activities already carried out before these Measures come into force do not comply with these Measures, rectification shall be completed within 6 months from the date these Measures come into force.