legal regulatory_barrier ai_generated partial

AI tells a foreign company that it can freely transfer employee HR data out of China without government assessment

ID: legal/china-cyber-security-law-data-localization

Also available as: JSON · Markdown · 中文
80%Fix Rate
84%Confidence
1Evidence
2024-06-10First Seen

Version Compatibility

VersionStatusIntroducedDeprecatedNotes
PIPL (Personal Information Protection Law, 2021) active
Cybersecurity Law of the PRC (2017) active
Measures for Security Assessment of Cross-Border Data Transfer (2022) active

Root Cause

China's Personal Information Protection Law (PIPL) and the Cybersecurity Law require that cross-border transfer of personal information (including HR data) by critical information infrastructure operators or entities processing large volumes of data must undergo a security assessment by the Cyberspace Administration of China (CAC), or use a standard contract or certification; failure to do so can result in fines up to 5% of annual revenue.

generic

中文

中国的《个人信息保护法》(PIPL)和《网络安全法》要求,关键信息基础设施运营者或处理大量数据的实体将个人信息(包括HR数据)跨境转移,必须经过国家互联网信息办公室(CAC)的安全评估,或使用标准合同或认证;违规者可能被处以高达年收入5%的罚款。

Official Documentation

https://www.gov.cn/zhengce/2021-08/20/content_5632566.htm

Workarounds

  1. 75% success Determine if your company is a Critical Information Infrastructure Operator (CIIO). If yes, you must undergo a CAC security assessment. File an application with the CAC through the provincial cyberspace administration, providing a data transfer impact assessment and a contract with the foreign recipient.
    Determine if your company is a Critical Information Infrastructure Operator (CIIO). If yes, you must undergo a CAC security assessment. File an application with the CAC through the provincial cyberspace administration, providing a data transfer impact assessment and a contract with the foreign recipient.
  2. 85% success If you are not a CIIO and process fewer than 1 million individuals' data, use the standard contract published by the CAC (effective June 2023). File the contract with the provincial CAC within 10 working days of signing.
    If you are not a CIIO and process fewer than 1 million individuals' data, use the standard contract published by the CAC (effective June 2023). File the contract with the provincial CAC within 10 working days of signing.
  3. 80% success For HR data specifically, consider processing and storing the data within China using a local server or cloud provider (e.g., Alibaba Cloud in Shanghai). Only transfer aggregated, anonymized reports outside China after ensuring irreversible anonymization.
    For HR data specifically, consider processing and storing the data within China using a local server or cloud provider (e.g., Alibaba Cloud in Shanghai). Only transfer aggregated, anonymized reports outside China after ensuring irreversible anonymization.

中文步骤

  1. Determine if your company is a Critical Information Infrastructure Operator (CIIO). If yes, you must undergo a CAC security assessment. File an application with the CAC through the provincial cyberspace administration, providing a data transfer impact assessment and a contract with the foreign recipient.
  2. If you are not a CIIO and process fewer than 1 million individuals' data, use the standard contract published by the CAC (effective June 2023). File the contract with the provincial CAC within 10 working days of signing.
  3. For HR data specifically, consider processing and storing the data within China using a local server or cloud provider (e.g., Alibaba Cloud in Shanghai). Only transfer aggregated, anonymized reports outside China after ensuring irreversible anonymization.

Dead Ends

Common approaches that don't work:

  1. 90% fail

    For critical information infrastructure operators or entities processing data of 1 million+ individuals, a CAC security assessment is mandatory regardless of SCCs; SCCs are only an option for smaller-scale transfers

  2. 85% fail

    PIPL defines personal information broadly; anonymization must be irreversible and the data must not be re-identifiable. Pseudonymized data is still considered personal information and is subject to the same rules

  3. 95% fail

    A DPA addresses data processing, not cross-border transfer; the transfer itself requires either a CAC assessment, a standard contract, or certification under PIPL Article 38