{
  "id": "legal/china-cross-border-data-transfer-pipL",
  "signature": "AI tells a multinational HR SaaS company that transferring employee data from China to a global HR system is allowed under a standard contractual clause",
  "signature_zh": "AI告诉一家跨国HR SaaS公司，根据标准合同条款，允许将员工数据从中国传输到全球HR系统",
  "regex": ".*(cross-border|data transfer|PIPL|China).*(employee|HR|SaaS|standard contractual clause).*",
  "domain": "legal",
  "category": "regulatory_barrier",
  "subcategory": null,
  "root_cause": "China's Personal Information Protection Law (PIPL) and related regulations (2023) require a security assessment by the CAC for cross-border transfers of personal information by critical information infrastructure operators or when transferring large volumes (over 1 million people's data or 100,000 people's sensitive data); standard contractual clauses alone are insufficient.",
  "root_cause_type": "generic",
  "root_cause_zh": "中国的《个人信息保护法》及相关法规（2023年）要求，关键信息基础设施运营者或传输大量数据（超过100万人数据或10万人敏感数据）时，跨境传输个人信息需经网信办安全评估；仅凭标准合同条款是不够的。",
  "versions": [
    {
      "version": "PIPL 2021",
      "introduced": null,
      "deprecated": null,
      "removed": null,
      "behavior_change": null,
      "status": "active"
    },
    {
      "version": "Measures for Security Assessment of Cross-Border Data Transfer 2022",
      "introduced": null,
      "deprecated": null,
      "removed": null,
      "behavior_change": null,
      "status": "active"
    },
    {
      "version": "Standard Contract for Cross-Border Transfer of Personal Information 2023",
      "introduced": null,
      "deprecated": null,
      "removed": null,
      "behavior_change": null,
      "status": "active"
    }
  ],
  "os_specific": {},
  "dead_ends": [
    {
      "action": "",
      "why_fails": "Assuming that EU SCCs are accepted in China; China has its own standard contract that must be filed with the CAC, not EU SCCs.",
      "fail_rate": 0.8,
      "condition": "",
      "sources": []
    },
    {
      "action": "",
      "why_fails": "Thinking that if the data is anonymized, no transfer rules apply; PIPL defines anonymization strictly, and pseudonymized data is still personal information.",
      "fail_rate": 0.7,
      "condition": "",
      "sources": []
    },
    {
      "action": "",
      "why_fails": "Believing that consent from employees is sufficient; PIPL requires one of: security assessment, standard contract, or certification, plus separate consent for sensitive data.",
      "fail_rate": 0.65,
      "condition": "",
      "sources": []
    }
  ],
  "workarounds": [
    {
      "action": "If the volume exceeds thresholds, apply for a security assessment with the CAC. Prepare a data impact assessment, data mapping, and legal documentation. Example: follow the 'Measures for Security Assessment' template from the CAC.",
      "success_rate": 0.75,
      "how": "If the volume exceeds thresholds, apply for a security assessment with the CAC. Prepare a data impact assessment, data mapping, and legal documentation. Example: follow the 'Measures for Security Assessment' template from the CAC.",
      "condition": "",
      "sources": []
    },
    {
      "action": "If below thresholds, use the CAC-approved Standard Contract for Cross-Border Transfer of Personal Information. File it with the local cyberspace administration within 10 working days of signing.",
      "success_rate": 0.85,
      "how": "If below thresholds, use the CAC-approved Standard Contract for Cross-Border Transfer of Personal Information. File it with the local cyberspace administration within 10 working days of signing.",
      "condition": "",
      "sources": []
    },
    {
      "action": "Alternatively, obtain a certification from a recognized institution (e.g., China Cybersecurity Review Certification Center) for the data transfer. This is less common but valid.",
      "success_rate": 0.7,
      "how": "Alternatively, obtain a certification from a recognized institution (e.g., China Cybersecurity Review Certification Center) for the data transfer. This is less common but valid.",
      "condition": "",
      "sources": []
    }
  ],
  "workarounds_zh": [
    "If the volume exceeds thresholds, apply for a security assessment with the CAC. Prepare a data impact assessment, data mapping, and legal documentation. Example: follow the 'Measures for Security Assessment' template from the CAC.",
    "If below thresholds, use the CAC-approved Standard Contract for Cross-Border Transfer of Personal Information. File it with the local cyberspace administration within 10 working days of signing.",
    "Alternatively, obtain a certification from a recognized institution (e.g., China Cybersecurity Review Certification Center) for the data transfer. This is less common but valid."
  ],
  "transition_graph": {
    "leads_to": [],
    "preceded_by": [],
    "frequently_confused_with": []
  },
  "official_doc_url": "https://www.cac.gov.cn/2023-02/22/c_1676308115876984.htm",
  "official_doc_section": null,
  "error_code": "CN-PIPL-38",
  "verification_tier": "ai_generated",
  "confidence": 0.88,
  "fix_success_rate": 0.8,
  "resolvable": "partial",
  "first_seen": "2023-09-01",
  "last_confirmed": "2024-06-01",
  "last_updated": "2024-06-01",
  "evidence_count": 1,
  "tags": [],
  "locale": "en",
  "aliases": []
}