Version & sources (verifiable)

ItemContent
Adoption & promulgation24 February 2023 (CAC Order No. 13)
Effective date1 June 2023
Currently in forceYes (as of 2026-09-23)
Chinese originalOfficial website of the Cyberspace Administration of China
English translationNo official English version. Translated by this journal from the official Chinese text and cross-checked article by article — unofficial translation, for reference only → 中文全文

Order of the Cyberspace Administration of China No. 13: The Measures for Standard Contract for Outbound Transfer of Personal Information, as adopted at the 2nd executive meeting of the Cyberspace Administration of China on 3 February 2023, are hereby promulgated and shall come into force on 1 June 2023.

Article 1 These Measures are formulated in accordance with the Personal Information Protection Law of the People’s Republic of China and other laws and regulations for the purpose of protecting the rights and interests of personal information and regulating the outbound transfer of personal information.

Article 2 Where a personal information handler provides personal information abroad by entering into a standard contract with the overseas recipient in accordance with Article 38, paragraph 1, item 3 of the Personal Information Protection Law of the People’s Republic of China, these Measures shall apply.

Article 3 Outbound transfer of personal information by way of concluding a standard contract shall adhere to the combination of independent contracting and record-filing administration, and the combination of protecting rights and interests with preventing risks, so as to ensure the secure and free cross-border flow of personal information.

Article 4 Where a personal information handler provides personal information abroad by way of concluding a standard contract, it shall meet all of the following circumstances:
(1) it is not a critical information infrastructure operator;
(2) it processes the personal information of fewer than 1,000,000 individuals;
(3) it has cumulatively provided abroad, since 1 January of the previous year, the personal information of fewer than 100,000 individuals; and
(4) it has cumulatively provided abroad, since 1 January of the previous year, the sensitive personal information of fewer than 10,000 individuals.
Where laws, administrative regulations or the national cyberspace administration provide otherwise, those provisions shall prevail.
A personal information handler shall not resort to means such as splitting quantities to provide abroad, by way of concluding a standard contract, personal information for which a security assessment of data export is required by law.

Article 5 Before providing personal information abroad, a personal information handler shall conduct a personal information protection impact assessment, focusing on the following matters:
(1) the lawfulness, legitimacy and necessity of the purposes, scope and methods of the processing of personal information by the personal information handler and the overseas recipient;
(2) the scale, scope, categories and sensitivity of the personal information to be exported, and the risks that the outbound transfer of personal information may pose to the rights and interests of individuals;
(3) the obligations undertaken by the overseas recipient, and whether its management and technical measures, capabilities and the like for performing those obligations can guarantee the security of the personal information to be exported;
(4) the risks of the personal information, after export, being tampered with, destroyed, leaked, lost, or illegally used, and whether the channels for safeguarding the rights and interests of individuals are unobstructed;
(5) the impact of the personal information protection policies, laws and regulations of the country or region where the overseas recipient is located on the performance of the standard contract; and
(6) other matters that may affect the security of the outbound transfer of personal information.

Article 6 The standard contract shall be concluded in strict accordance with the annex to these Measures. The national cyberspace administration may adjust the annex in light of actual circumstances.
A personal information handler may agree with the overseas recipient on other terms, provided that such terms do not conflict with the standard contract.
Outbound transfer of personal information may be carried out only after the standard contract takes effect.

Article 7 A personal information handler shall, within 10 working days from the date on which the standard contract takes effect, file the standard contract with the cyberspace administration of the province where it is located. The filing shall be accompanied by the following materials:

(1) the standard contract; and

(2) the personal information protection impact assessment report.

A personal information handler shall be responsible for the authenticity of the materials filed.

Article 8 During the validity period of the standard contract, where any of the following circumstances occurs, the personal information handler shall conduct a personal information protection impact assessment anew, supplement or re-conclude the standard contract, and perform the corresponding filing procedures:

(1) the purpose, scope, type, sensitivity, method, place of storage or retention period of the personal information provided abroad changes, or the purpose or method of processing by the overseas recipient changes, in a manner that may increase the risk to the rights and interests of individuals;

(2) the laws, regulations or cybersecurity environment of the country or region where the overseas recipient is located changes in a manner that may increase the risk to the rights and interests of individuals; or

(3) any other circumstance arises that may affect the rights and interests of individuals.

Article 9 Cyberspace administrations and their staff shall keep confidential the personal privacy, personal information, trade secrets and confidential business information obtained in the performance of their duties, and shall not disclose such information or provide it to others illegally, nor use it illegally.

Article 10 Any organisation or individual that discovers a personal information handler providing personal information abroad in violation of these Measures may report it to a cyberspace administration at or above the provincial level.

Article 11 Where a cyberspace administration at or above the provincial level discovers that an outbound personal information activity involves relatively large risks or that a personal information security incident has occurred, it may conduct regulatory talks with the personal information handler in accordance with the law. The personal information handler shall rectify as required and eliminate the risks.

Article 12 Where these Measures are violated, the case shall be handled in accordance with the Personal Information Protection Law of the People’s Republic of China and other laws and regulations; where a crime is constituted, criminal responsibility shall be pursued according to law.

Article 13 These Measures shall come into force on 1 June 2023. Outbound personal information activities that have already been carried out before these Measures come into force and do not comply with the provisions of these Measures shall be rectified within 6 months from the date on which these Measures come into force.