CN-PIPL-38 legal regulatory_barrier ai_generated partial

AI tells a multinational HR SaaS company that transferring employee data from China to a global HR system is allowed under a standard contractual clause

ID: legal/china-cross-border-data-transfer-pipL

Also available as: JSON · Markdown · 中文
80%Fix Rate
88%Confidence
1Evidence
2023-09-01First Seen

Version Compatibility

VersionStatusIntroducedDeprecatedNotes
PIPL 2021 active
Measures for Security Assessment of Cross-Border Data Transfer 2022 active
Standard Contract for Cross-Border Transfer of Personal Information 2023 active

Root Cause

China's Personal Information Protection Law (PIPL) and related regulations (2023) require a security assessment by the CAC for cross-border transfers of personal information by critical information infrastructure operators or when transferring large volumes (over 1 million people's data or 100,000 people's sensitive data); standard contractual clauses alone are insufficient.

generic

中文

中国的《个人信息保护法》及相关法规(2023年)要求,关键信息基础设施运营者或传输大量数据(超过100万人数据或10万人敏感数据)时,跨境传输个人信息需经网信办安全评估;仅凭标准合同条款是不够的。

Official Documentation

https://www.cac.gov.cn/2023-02/22/c_1676308115876984.htm

Workarounds

  1. 75% success If the volume exceeds thresholds, apply for a security assessment with the CAC. Prepare a data impact assessment, data mapping, and legal documentation. Example: follow the 'Measures for Security Assessment' template from the CAC.
    If the volume exceeds thresholds, apply for a security assessment with the CAC. Prepare a data impact assessment, data mapping, and legal documentation. Example: follow the 'Measures for Security Assessment' template from the CAC.
  2. 85% success If below thresholds, use the CAC-approved Standard Contract for Cross-Border Transfer of Personal Information. File it with the local cyberspace administration within 10 working days of signing.
    If below thresholds, use the CAC-approved Standard Contract for Cross-Border Transfer of Personal Information. File it with the local cyberspace administration within 10 working days of signing.
  3. 70% success Alternatively, obtain a certification from a recognized institution (e.g., China Cybersecurity Review Certification Center) for the data transfer. This is less common but valid.
    Alternatively, obtain a certification from a recognized institution (e.g., China Cybersecurity Review Certification Center) for the data transfer. This is less common but valid.

中文步骤

  1. If the volume exceeds thresholds, apply for a security assessment with the CAC. Prepare a data impact assessment, data mapping, and legal documentation. Example: follow the 'Measures for Security Assessment' template from the CAC.
  2. If below thresholds, use the CAC-approved Standard Contract for Cross-Border Transfer of Personal Information. File it with the local cyberspace administration within 10 working days of signing.
  3. Alternatively, obtain a certification from a recognized institution (e.g., China Cybersecurity Review Certification Center) for the data transfer. This is less common but valid.

Dead Ends

Common approaches that don't work:

  1. 80% fail

    Assuming that EU SCCs are accepted in China; China has its own standard contract that must be filed with the CAC, not EU SCCs.

  2. 70% fail

    Thinking that if the data is anonymized, no transfer rules apply; PIPL defines anonymization strictly, and pseudonymized data is still personal information.

  3. 65% fail

    Believing that consent from employees is sufficient; PIPL requires one of: security assessment, standard contract, or certification, plus separate consent for sensitive data.