Skip to content
DCC · DATA COMPLIANCE CHINA China data law, for overseas counsel.
§ LAW · CAC DATA EXPORT Q&A (APR 2025)

Policy Q&A on Data Export Security Management (April 2025).

数据出境安全管理政策问答(2025年4月)

Promulgated by: Cyberspace Administration of China (CAC).
Document No.: None (published as an official policy Q&A).
Published April 9, 2025.

Translation note — DCC. Translated in full from the official Chinese text published by the CAC on cac.gov.cn and on the 网信中国 (Cyberspace China) WeChat channel. Terminology follows DCC’s bilingual glossary. The batch explains the regime set by the Provisions on Promoting and Regulating Cross-border Data Flows and the Measures for the Security Assessment of Data Export.


The Cyberspace Administration of China continues to strengthen the dissemination of data export security management policy, guiding and helping data handlers carry out data export activities efficiently and in compliance. Having studied the inquiries received recently, it hereby publishes a number of representative questions and answers as follows.

Q1. How should the design of China’s data export security management system be understood?

A: As cross-border data flow activities become ever more frequent, many countries and regions around the world, proceeding from their own circumstances, have explored institutional arrangements for the security management of cross-border data flows and have enacted a series of laws, regulations, rules and standards. China’s establishment of a data export security management system is a requirement laid down by law. The Cybersecurity Law, the Data Security Law and the Personal Information Protection Law make express provision, at the level of statute, for data export activities. The relevant provisions do not target all data; they are limited to important data and personal information. For important data that genuinely needs to be exported, the law makes institutional arrangements: where a data export security assessment finds that the export will not endanger national security or the public interest, the data may be exported. For the export of personal information, the law provides multiple pathways, including the data export security assessment, personal information protection certification and the standard contract for the export of personal information. Taken as a whole, the provisions of Chinese law on data export management aim to ensure the secure and free cross-border flow of data that enterprises in China need for business purposes, while exercising necessary supervision over the cross-border flow of personal information and important data that touches on national security and public-policy objectives. General data that involves neither personal information nor important data may flow freely across borders; important data and personal information reaching the prescribed volumes may flow across borders in accordance with the law after passing the data export security assessment.

To implement the statutory provisions, the Cyberspace Administration of China has successively issued and implemented the Measures for the Security Assessment of Data Export, the Measures on the Standard Contract for the Outbound Transfer of Personal Information and the Provisions on Promoting and Regulating Cross-border Data Flows, and has published the Announcement on the Implementation of Personal Information Protection Certification together with its accompanying certification rules, clarifying the implementation paths of the data export security assessment, the standard contract for the export of personal information, personal information protection certification and the other systems, and, together with all localities and departments, carries out data export security management work in an orderly manner in accordance with the law.

Q2. How is consistency ensured among the standards of the data export negative lists formulated by different pilot free trade zones?

A: The Provisions on Promoting and Regulating Cross-border Data Flows make clear that pilot free trade zones (自贸试验区) may, within the framework of the national data classification and grading protection system, formulate their own data export negative lists (负面清单), which are implemented after approval by the provincial-level cybersecurity and informatization commission and filing with the national cyberspace administration and the national data administration; the export of data outside the negative list is exempt from declaring a security assessment, concluding a standard contract or passing protection certification. This is an innovative measure to promote and facilitate cross-border data flows in the pilot free trade zones. In the course of formulating a negative list, the opinions of the relevant competent departments are fully solicited; when a negative list is filed, the Cyberspace Administration of China, together with the National Data Administration, reviews the list; and for the same field, where one pilot free trade zone has already published a negative list, the other pilot free trade zones may apply it by reference and need not formulate a duplicate. The above work ensures that negative lists conform to the requirements of the national data classification and grading protection system and guarantees the consistency of negative-list standards among different pilot free trade zones.

Q3. How will the scope of application of the pilot free trade zone data export negative lists come to cover more fields?

A: Implementing the Provisions on Promoting and Regulating Cross-border Data Flows, the Cyberspace Administration of China and the National Data Administration have successively completed the filing of the data export negative lists of the pilot free trade zones (and free trade port) of Tianjin, Beijing, Hainan, Shanghai, Zhejiang and elsewhere, which play a promoting role for cross-border data flows in 17 fields including automobiles, pharmaceuticals, retail, civil aviation, reinsurance, the deep-sea industry and the seed industry. The Cyberspace Administration of China, together with the relevant departments, is guiding each pilot free trade zone to formulate data export negative lists in light of the characteristics of its own industrial development; as more negative lists are published and implemented, the fields covered will become ever broader. For the publication and implementation of pilot free trade zone data export negative lists, readers may follow the official website of the Cyberspace Administration of China (www.cac.gov.cn) and the websites of the relevant local pilot free trade zones.

Q4. How should the necessity of exporting personal information be understood and judged?

A: Article 6 of the Personal Information Protection Law provides: “The processing of personal information shall have a clear and reasonable purpose, shall be directly related to the processing purpose, and shall be carried out in the manner that has the least impact on individual rights and interests. The collection of personal information shall be limited to the minimum scope necessary to achieve the processing purpose, and personal information shall not be collected excessively.” Article 19 provides: “Except where laws or administrative regulations provide otherwise, the retention period for personal information shall be the shortest time necessary to achieve the processing purpose.”

According to the above statutory provisions, the factors for judging “necessity” comprise four aspects: direct relation to the processing purpose; the least impact on individual rights and interests; limitation to the minimum scope necessary to achieve the processing purpose; and a retention period that is the shortest time necessary to achieve the processing purpose. In implementing these statutory provisions, the Cyberspace Administration of China, when conducting data export security assessments, gives full consideration to the business scenario and actual needs of the matters declared by the data handler and assesses the necessity of the export of personal information; the key points of the assessment mainly include the necessity of the export activity itself, the necessity of the number of natural persons involved, and the necessity of the scope of personal information data items exported.

Data export involves a great many industries and fields. The Cyberspace Administration of China, together with the relevant industry competent departments, is progressively refining and clarifying the data export business scenarios and the necessary scope of personal information export for specific industries and fields, so as to provide enterprises and institutions with more detailed policy guidance for data export.

Q5. How is important data identified?

A: Under Article 62 of the Regulation on Network Data Security Management, important data means data in a specific field, of a specific group or a specific region, or reaching a certain degree of precision and scale, which, once tampered with, destroyed, leaked or illegally obtained or illegally used, may directly endanger national security, economic operation, social stability, or public health and safety. Appendix G, “Guide to the Identification of Important Data”, of Data Security Technology — Rules for Data Classification and Grading (GB/T 43697-2024) sets out a method for identifying important data. Data handlers may identify and declare important data on the basis of the relevant laws, regulations, technical standards and the like.

Q6. Does “important data” mean that the data cannot be exported?

A: For important data that genuinely needs to be exported, the law makes institutional arrangements: where a data export security assessment finds that the export will not endanger national security or the public interest, the data may be exported. As of March 2025, the Cyberspace Administration of China had completed a total of 298 data export security assessment projects. Of these, 44 declared projects involved important data; 7 received an assessment result of “not passed”, a non-pass rate of 15.9%. The 44 declared projects involved 509 important data items, of which 325 were approved for export after assessment, accounting for 63.9% of the total number of declared data items.

It should be specially noted that the Provisions on Promoting and Regulating Cross-border Data Flows make clear that data handlers shall declare important data in accordance with relevant provisions, and that where data has not been notified or publicly released as important data by the relevant departments or regions, the data handler need not declare it for data export security assessment as important data.

Q7. How is the role of foreign-invested enterprises brought into play in the formulation of industry technical standards?

A: The Cyberspace Administration of China guides the relevant professional bodies, in the course of formulating industry technical standards, to attach great importance to and actively encourage the participation of all parties, including Chinese and foreign enterprises, ensuring that standards formulation fully takes account of the needs of domestic and foreign stakeholders. First, the participation mechanism is open and transparent. The Cyberspace Administration of China guides the National Technical Committee 260 on Cybersecurity of Standardization Administration of China (全国网络安全标准化技术委员会, TC260) to adhere to the principle of open cooperation and broad participation and to solicit working-group member organizations publicly from society on a long-term basis. The committee members and the members of its working groups include a number of representative foreign-invested enterprises, which enjoy rights and obligations equal to those of domestic enterprises and institutions in participating in and discussing standards; foreign-invested enterprises that are working-group member organizations can participate throughout the entire process and can fully put forward opinions and suggestions at every stage of standards development. Second, the standards working procedures are open and transparent. By publicly soliciting from society standards needs and standards drafting participants, and by publicly soliciting comments from society on draft standards, all relevant parties are ensured fair and impartial participation in standards formulation.

Q8. Is there a more convenient channel for group companies to transfer personal information across borders?

A: On the one hand, where multiple domestic subsidiaries belong to the same group company and their data export business scenarios are similar, the group company may act as the declaring entity and make a consolidated declaration for data export security assessment or a consolidated filing of the standard contract for the export of personal information, improving the efficiency of data export work. On the other hand, the Cyberspace Administration of China is pushing forward the issuance of administrative measures on certification for the protection of personal information exports, guiding third-party professional certification bodies to certify personal information export activities: where either the domestic enterprise or the overseas recipient passes certification, the enterprise may carry out personal information export activities within the scope of the certification; and a multinational group that has passed certification may carry out personal information export activities within the group without having to conclude a separate standard contract for the export of personal information with each of its subsidiaries in each country.

Q9. Is there a specific procedure for applying to extend the validity period of a data export security assessment result?

A: The Provisions on Promoting and Regulating Cross-border Data Flows extended the validity period of a data export security assessment result from the original 2 years to 3 years, and at the same time made clear that where, upon expiry of the validity period, the data handler needs to continue data export activities and no circumstance requiring re-declaration for data export security assessment has arisen, the data handler may, within the 60 working days before expiry of the validity period, apply to the national cyberspace administration through the provincial-level cyberspace administration of its locality to extend the validity period of the assessment result; with the approval of the national cyberspace administration, the validity period of the assessment result may be extended by 3 years. At present, the Cyberspace Administration of China is actively listening to the views of all parties and accelerating its study of the procedure for extending the validity period of assessment results, and plans to clarify it by revising and issuing the relevant policy documents, so as to create more convenient conditions for data export by enterprises and institutions.

§ RELATED LAWS

See also.

§ COMMENTARY

Briefs on this law.

No briefs filed yet under this law.

§ SUBSCRIBE

The Monday brief.

One short email every Monday. New briefs on Chinese data-compliance rules from the previous week, with the source law cited.

Opt-in only. Unsubscribe anytime by replying "unsubscribe" to any issue.

SUPPORT DCC

Keep the publication free to read. Suggested support is $19.99, or choose your own amount.

Support →