CN-PIPL-38 legal regulatory_barrier ai_generated partial

AI告诉一家跨国HR SaaS公司,根据标准合同条款,允许将员工数据从中国传输到全球HR系统

AI tells a multinational HR SaaS company that transferring employee data from China to a global HR system is allowed under a standard contractual clause

ID: legal/china-cross-border-data-transfer-pipL

其他格式: JSON · Markdown 中文 · English
80%修复率
88%置信度
1证据数
2023-09-01首次发现

版本兼容性

版本状态引入弃用备注
PIPL 2021 active
Measures for Security Assessment of Cross-Border Data Transfer 2022 active
Standard Contract for Cross-Border Transfer of Personal Information 2023 active

根因分析

中国的《个人信息保护法》及相关法规(2023年)要求,关键信息基础设施运营者或传输大量数据(超过100万人数据或10万人敏感数据)时,跨境传输个人信息需经网信办安全评估;仅凭标准合同条款是不够的。

English

China's Personal Information Protection Law (PIPL) and related regulations (2023) require a security assessment by the CAC for cross-border transfers of personal information by critical information infrastructure operators or when transferring large volumes (over 1 million people's data or 100,000 people's sensitive data); standard contractual clauses alone are insufficient.

generic

官方文档

https://www.cac.gov.cn/2023-02/22/c_1676308115876984.htm

解决方案

  1. If the volume exceeds thresholds, apply for a security assessment with the CAC. Prepare a data impact assessment, data mapping, and legal documentation. Example: follow the 'Measures for Security Assessment' template from the CAC.
  2. If below thresholds, use the CAC-approved Standard Contract for Cross-Border Transfer of Personal Information. File it with the local cyberspace administration within 10 working days of signing.
  3. Alternatively, obtain a certification from a recognized institution (e.g., China Cybersecurity Review Certification Center) for the data transfer. This is less common but valid.

无效尝试

常见但无效的做法:

  1. 80% 失败

    Assuming that EU SCCs are accepted in China; China has its own standard contract that must be filed with the CAC, not EU SCCs.

  2. 70% 失败

    Thinking that if the data is anonymized, no transfer rules apply; PIPL defines anonymization strictly, and pseudonymized data is still personal information.

  3. 65% 失败

    Believing that consent from employees is sufficient; PIPL requires one of: security assessment, standard contract, or certification, plus separate consent for sensitive data.