DCC summary, not a translation. This practice guide is copyrighted jointly by the TC260 Secretariat and the Hong Kong PCPD, which prohibit translation without written authorization. The structured summary below is DCC’s own paraphrase grounded in the published text; specific clauses should be checked against the guide.
Published by: Secretariat of the National Information Security Standardization Technical Committee (全国网络安全标准化技术委员会秘书处) and the Office of the Privacy Commissioner for Personal Data, Hong Kong (香港个人资料私隐专员公署).
Document No.: TC260-PG-20245A. Version 1.0, November 2024. Drafters include CESI, the PCPD, the China Cybersecurity Review, Certification and Market Regulation Big Data Center, Beijing Institute of Technology, Central University of Finance and Economics, the Guangzhou Nansha development-zone administration, China Southern Power Grid, Huawei and OPPO.
Scope
The guide states the basic principles and requirements that personal information handlers and recipients in the GBA (Mainland, Hong Kong) must follow when moving personal information between the Mainland and Hong Kong by the “security mutual recognition” route (安全互认方式). It serves as the basis for certification of Mainland handlers and recipients and for recognition of Hong Kong handlers and recipients, and applies to entities registered or located in the nine Mainland GBA cities — Guangzhou, Shenzhen, Zhuhai, Foshan, Huizhou, Dongguan, Zhongshan, Jiangmen and Zhaoqing — or in the Hong Kong SAR that voluntarily apply for GBA cross-boundary security certification (Mainland) or for inclusion in the PCPD’s “GBA (Mainland, Hong Kong) Cross-boundary Personal Data Transfer Recognition List” (Hong Kong). Personal information that has been notified or published as important data is excluded. The abstract explains the guide’s place in the June 2023 memorandum between the CAC and Hong Kong’s Innovation, Technology and Industry Bureau: GBA parties may use either the GBA standard contract or the mutual-recognition route, and the exemptions in the Cross-border Data Flows Provisions continue to apply.
Definitions are deliberately bilateral. “Personal information” is determined by local law on each side (PIPL on the Mainland; “personal data” under the Personal Data (Privacy) Ordinance in Hong Kong); “handler” covers the PDPO’s “data user” and refers to the transferring party; “recipient” is the party receiving across the boundary; “cross-boundary processing” covers one-way and two-way transfers, remote access by query, retrieval, download or export, and processing in Hong Kong of Mainland individuals’ data that falls under PIPL Article 3(2).
Key contents
Basic principles (clause 3)
Lawfulness, legitimacy and good faith (comply with local law, no misleading, fraudulent or coercive processing, clear and lawful purposes, honor binding commitments); minimum necessity; openness and transparency (published processing rules, typically a privacy policy); protection of rights and interests (data quality); security; and clear accountability.
Processing requirements (clause 4)
Lawful basis (4.1). Mainland parties need one of the seven PIPL Article 13 bases; Hong Kong parties must comply with the PDPO including its Schedule 1 data protection principles.
Collection (4.2). Notify purpose, method, scope and categories at or before collection; publish processing rules stating the handler’s identity and contact details, purposes and methods, categories and retention period, categories, purposes and recipients of external provision, and rights procedures; consent must be voluntary, explicit and fully informed; minors’ data requires guardian consent under local law — parents or guardians for children under 14 on the Mainland, “prescribed consent” for minors under 18 in Hong Kong; and services may not be refused for withholding or withdrawing consent unless the processing is necessary for the service.
Storage, use and processing (4.3). Retain for the shortest period necessary; re-obtain consent when purpose, method or categories change; obtain consent and give notice for marketing use; offer non-personalized options or easy refusal for automated push and marketing, and explanation and the right to refuse solely automated decisions with significant effects, where local law so provides; joint handlers must allocate rights and obligations.
Entrusted processing, provision and disclosure (4.4). Entrustment agreements must fix purpose, term, method, categories, safeguards, mutual obligations and deletion or return on expiry, with supervision of the processor; provision to another handler requires notice of the recipient’s identity, contact details, purpose, method and categories and consent under local law, with re-consent if the recipient changes purpose or method; public disclosure requires consent and de-identification to reduce sensitivity.
Cross-boundary processing (4.5). General: before transfer, agree the purpose, method, categories and scale, transmission method, post-transfer storage location and period, and any provision to third parties in the same jurisdiction; adopt a cross-boundary security management system with encryption, de-identification and access controls; and keep records of cross-boundary processing for at least three years. Transferring handler: transfer only the minimum necessary; notify data subjects of the recipient’s identity and contact details, the agreed purpose, method, categories, retention and same-jurisdiction onward provision, and rights procedures, unless local law dispenses with notice; obtain consent under local law unless local law provides otherwise; conclude a binding document (binding corporate rules of a corporate group qualify) fixing the agreed terms, allocating protection responsibilities, requiring the recipient to give effect within a reasonable period to the rights data subjects enjoy under the handler’s local law, and prohibiting transfer to third parties outside the GBA; conduct a personal information protection impact assessment kept for at least three years, covering the lawfulness, legitimacy and necessity of both parties’ processing, the impact and risk to data subjects, and whether the recipient’s undertakings and its management and technical capabilities can secure the data; and supervise the recipient by contract, periodic audit of transfer records or self-assessment to prevent unauthorized onward provision outside the GBA. Recipient: process only per the agreed terms and binding document; keep data for the shortest necessary period and delete it and all backups on expiry; delete and confirm in writing when an entrustment contract fails, is revoked or terminates or on the handler’s instruction, or, where deletion is technically infeasible, cease all processing except storage and safeguarding; return or delete on wind-down of the cross-boundary business; apply least-privilege access for staff who access data across the boundary; on an actual or likely security incident, take remedial measures, immediately notify the handler and report to the local regulator with the categories involved, cause and harm, remedies taken, measures individuals can take and a contact point, notify individuals where local law requires, and keep records; never provide received data to organizations or individuals outside the GBA; provide to same-jurisdiction third parties only where there is a genuine business need, data subjects have been notified, consent has been obtained where the handler’s local law requires, and the agreed terms permit; obtain the handler’s prior consent for sub-processing and supervise the sub-processor; provide the handler with information needed to demonstrate compliance and facilitate compliance audits; give effect to data-subject rights within a reasonable period on the handler’s notice or the individual’s request; and, when refusing a request, explain the reason and the routes for complaint to the handler’s or recipient’s local regulator and for judicial remedy.
Rights and safeguards (clause 5)
Data subjects have rights under local law to access and copy, to correct and supplement, to demand explanation of processing rules, and to request deletion where the purpose is achieved or cannot be achieved, the data is no longer necessary, or processing breaches local law or the agreement. Handlers and recipients must provide convenient channels for access, copying, correction, supplementation, deletion and refusal; operate a request-handling mechanism that responds within local statutory periods and gives reasons for refusals; cease all processing except storage and safeguarding where retention periods have not expired or deletion is infeasible; and, where they discover or are notified by Mainland regulators that a transfer affects or may affect the lawful rights of individuals or organizations in the PRC or endangers China’s sovereignty, security or development interests, promptly stop the cross-boundary flow or processing by the Mainland handler or recipient and notify the counterparty.
Security requirements (clause 6)
Designate a person responsible for personal information protection to supervise processing and safeguards; adopt security management systems and operating procedures with regular training; encrypt sensitive personal information in transmission and storage; limit operating privileges and sign confidentiality agreements with staff handling sensitive data (biometric, religious, specific identity, financial account, medical and health, location tracking and minors’ data are listed as sensitive); apply encryption, de-identification, authentication, access control and security audit; and maintain an incident emergency plan with immediate remediation, regulator notification and individual notification under local law. A closing note preserves the supervisory powers of Mainland personal-information authorities and the PCPD, including complaint handling and investigation.
How it fits the regime
The GBA regime now has two lanes. The first is the GBA (Mainland, Hong Kong) standard contract of December 2023, a filing-based route mirrored for Macao in 2025. The second is the mutual-recognition lane this guide underpins: certification of Mainland parties by CAC-accredited bodies and PCPD recognition of Hong Kong parties, with the guide as the common rulebook — a regional analogue of the national personal-information export certification and its standard GB/T 46068, from which it borrows the binding-document, PIPIA and onward-transfer controls. Three features matter in practice. The “no transfer outside the GBA” rule is absolute for the recipient and is policed by the handler’s supervision duty — the CAC’s January 2026 Q&A confirms that any provision beyond the GBA falls back on the national routes. The local-law drafting means a Hong Kong recipient’s obligations are calibrated to the PDPO while its rights-fulfilment duty tracks PIPL when the data came from the Mainland. And the Mainland stop-transfer clause in 5.2(d) gives Chinese regulators a lever over flows already certified. For multinational groups with Hong Kong regional hubs, the binding-corporate-rules recognition in 4.5.2(d) is the provision most worth building on.