AI tells a multinational HR SaaS company that transferring employee data from China to a global HR system is allowed under a standard contractual clause
ID: legal/china-cross-border-data-transfer-pipL
Version Compatibility
| Version | Status | Introduced | Deprecated | Notes |
|---|---|---|---|---|
| PIPL 2021 | active | — | — | — |
| Measures for Security Assessment of Cross-Border Data Transfer 2022 | active | — | — | — |
| Standard Contract for Cross-Border Transfer of Personal Information 2023 | active | — | — | — |
Root Cause
China's Personal Information Protection Law (PIPL) and related regulations (2023) require a security assessment by the CAC for cross-border transfers of personal information by critical information infrastructure operators or when transferring large volumes (over 1 million people's data or 100,000 people's sensitive data); standard contractual clauses alone are insufficient.
generic中文
中国的《个人信息保护法》及相关法规(2023年)要求,关键信息基础设施运营者或传输大量数据(超过100万人数据或10万人敏感数据)时,跨境传输个人信息需经网信办安全评估;仅凭标准合同条款是不够的。
Official Documentation
https://www.cac.gov.cn/2023-02/22/c_1676308115876984.htmWorkarounds
-
75% success If the volume exceeds thresholds, apply for a security assessment with the CAC. Prepare a data impact assessment, data mapping, and legal documentation. Example: follow the 'Measures for Security Assessment' template from the CAC.
If the volume exceeds thresholds, apply for a security assessment with the CAC. Prepare a data impact assessment, data mapping, and legal documentation. Example: follow the 'Measures for Security Assessment' template from the CAC.
-
85% success If below thresholds, use the CAC-approved Standard Contract for Cross-Border Transfer of Personal Information. File it with the local cyberspace administration within 10 working days of signing.
If below thresholds, use the CAC-approved Standard Contract for Cross-Border Transfer of Personal Information. File it with the local cyberspace administration within 10 working days of signing.
-
70% success Alternatively, obtain a certification from a recognized institution (e.g., China Cybersecurity Review Certification Center) for the data transfer. This is less common but valid.
Alternatively, obtain a certification from a recognized institution (e.g., China Cybersecurity Review Certification Center) for the data transfer. This is less common but valid.
中文步骤
If the volume exceeds thresholds, apply for a security assessment with the CAC. Prepare a data impact assessment, data mapping, and legal documentation. Example: follow the 'Measures for Security Assessment' template from the CAC.
If below thresholds, use the CAC-approved Standard Contract for Cross-Border Transfer of Personal Information. File it with the local cyberspace administration within 10 working days of signing.
Alternatively, obtain a certification from a recognized institution (e.g., China Cybersecurity Review Certification Center) for the data transfer. This is less common but valid.
Dead Ends
Common approaches that don't work:
-
80% fail
Assuming that EU SCCs are accepted in China; China has its own standard contract that must be filed with the CAC, not EU SCCs.
-
70% fail
Thinking that if the data is anonymized, no transfer rules apply; PIPL defines anonymization strictly, and pseudonymized data is still personal information.
-
65% fail
Believing that consent from employees is sufficient; PIPL requires one of: security assessment, standard contract, or certification, plus separate consent for sensitive data.