AI告诉一家跨国HR SaaS公司,根据标准合同条款,允许将员工数据从中国传输到全球HR系统
AI tells a multinational HR SaaS company that transferring employee data from China to a global HR system is allowed under a standard contractual clause
ID: legal/china-cross-border-data-transfer-pipL
版本兼容性
| 版本 | 状态 | 引入 | 弃用 | 备注 |
|---|---|---|---|---|
| PIPL 2021 | active | — | — | — |
| Measures for Security Assessment of Cross-Border Data Transfer 2022 | active | — | — | — |
| Standard Contract for Cross-Border Transfer of Personal Information 2023 | active | — | — | — |
根因分析
中国的《个人信息保护法》及相关法规(2023年)要求,关键信息基础设施运营者或传输大量数据(超过100万人数据或10万人敏感数据)时,跨境传输个人信息需经网信办安全评估;仅凭标准合同条款是不够的。
English
China's Personal Information Protection Law (PIPL) and related regulations (2023) require a security assessment by the CAC for cross-border transfers of personal information by critical information infrastructure operators or when transferring large volumes (over 1 million people's data or 100,000 people's sensitive data); standard contractual clauses alone are insufficient.
官方文档
https://www.cac.gov.cn/2023-02/22/c_1676308115876984.htm解决方案
-
If the volume exceeds thresholds, apply for a security assessment with the CAC. Prepare a data impact assessment, data mapping, and legal documentation. Example: follow the 'Measures for Security Assessment' template from the CAC.
-
If below thresholds, use the CAC-approved Standard Contract for Cross-Border Transfer of Personal Information. File it with the local cyberspace administration within 10 working days of signing.
-
Alternatively, obtain a certification from a recognized institution (e.g., China Cybersecurity Review Certification Center) for the data transfer. This is less common but valid.
无效尝试
常见但无效的做法:
-
80% 失败
Assuming that EU SCCs are accepted in China; China has its own standard contract that must be filed with the CAC, not EU SCCs.
-
70% 失败
Thinking that if the data is anonymized, no transfer rules apply; PIPL defines anonymization strictly, and pseudonymized data is still personal information.
-
65% 失败
Believing that consent from employees is sufficient; PIPL requires one of: security assessment, standard contract, or certification, plus separate consent for sensitive data.