{
  "id": "legal/china-cyber-security-law-data-localization",
  "signature": "AI tells a foreign company that it can freely transfer employee HR data out of China without government assessment",
  "signature_zh": "AI告诉外国公司，它可以在未经政府评估的情况下自由地将员工HR数据转移出中国",
  "regex": "(?i)(china.*data.*transfer|pipi.*cross.*border|cybersecurity.*law.*assessment|hr.*data.*china.*transfer|chinese.*data.*localization)",
  "domain": "legal",
  "category": "regulatory_barrier",
  "subcategory": null,
  "root_cause": "China's Personal Information Protection Law (PIPL) and the Cybersecurity Law require that cross-border transfer of personal information (including HR data) by critical information infrastructure operators or entities processing large volumes of data must undergo a security assessment by the Cyberspace Administration of China (CAC), or use a standard contract or certification; failure to do so can result in fines up to 5% of annual revenue.",
  "root_cause_type": "generic",
  "root_cause_zh": "中国的《个人信息保护法》（PIPL）和《网络安全法》要求，关键信息基础设施运营者或处理大量数据的实体将个人信息（包括HR数据）跨境转移，必须经过国家互联网信息办公室（CAC）的安全评估，或使用标准合同或认证；违规者可能被处以高达年收入5%的罚款。",
  "versions": [
    {
      "version": "PIPL (Personal Information Protection Law, 2021)",
      "introduced": null,
      "deprecated": null,
      "removed": null,
      "behavior_change": null,
      "status": "active"
    },
    {
      "version": "Cybersecurity Law of the PRC (2017)",
      "introduced": null,
      "deprecated": null,
      "removed": null,
      "behavior_change": null,
      "status": "active"
    },
    {
      "version": "Measures for Security Assessment of Cross-Border Data Transfer (2022)",
      "introduced": null,
      "deprecated": null,
      "removed": null,
      "behavior_change": null,
      "status": "active"
    }
  ],
  "os_specific": {},
  "dead_ends": [
    {
      "action": "",
      "why_fails": "For critical information infrastructure operators or entities processing data of 1 million+ individuals, a CAC security assessment is mandatory regardless of SCCs; SCCs are only an option for smaller-scale transfers",
      "fail_rate": 0.9,
      "condition": "",
      "sources": []
    },
    {
      "action": "",
      "why_fails": "PIPL defines personal information broadly; anonymization must be irreversible and the data must not be re-identifiable. Pseudonymized data is still considered personal information and is subject to the same rules",
      "fail_rate": 0.85,
      "condition": "",
      "sources": []
    },
    {
      "action": "",
      "why_fails": "A DPA addresses data processing, not cross-border transfer; the transfer itself requires either a CAC assessment, a standard contract, or certification under PIPL Article 38",
      "fail_rate": 0.95,
      "condition": "",
      "sources": []
    }
  ],
  "workarounds": [
    {
      "action": "Determine if your company is a Critical Information Infrastructure Operator (CIIO). If yes, you must undergo a CAC security assessment. File an application with the CAC through the provincial cyberspace administration, providing a data transfer impact assessment and a contract with the foreign recipient.",
      "success_rate": 0.75,
      "how": "Determine if your company is a Critical Information Infrastructure Operator (CIIO). If yes, you must undergo a CAC security assessment. File an application with the CAC through the provincial cyberspace administration, providing a data transfer impact assessment and a contract with the foreign recipient.",
      "condition": "",
      "sources": []
    },
    {
      "action": "If you are not a CIIO and process fewer than 1 million individuals' data, use the standard contract published by the CAC (effective June 2023). File the contract with the provincial CAC within 10 working days of signing.",
      "success_rate": 0.85,
      "how": "If you are not a CIIO and process fewer than 1 million individuals' data, use the standard contract published by the CAC (effective June 2023). File the contract with the provincial CAC within 10 working days of signing.",
      "condition": "",
      "sources": []
    },
    {
      "action": "For HR data specifically, consider processing and storing the data within China using a local server or cloud provider (e.g., Alibaba Cloud in Shanghai). Only transfer aggregated, anonymized reports outside China after ensuring irreversible anonymization.",
      "success_rate": 0.8,
      "how": "For HR data specifically, consider processing and storing the data within China using a local server or cloud provider (e.g., Alibaba Cloud in Shanghai). Only transfer aggregated, anonymized reports outside China after ensuring irreversible anonymization.",
      "condition": "",
      "sources": []
    }
  ],
  "workarounds_zh": [
    "Determine if your company is a Critical Information Infrastructure Operator (CIIO). If yes, you must undergo a CAC security assessment. File an application with the CAC through the provincial cyberspace administration, providing a data transfer impact assessment and a contract with the foreign recipient.",
    "If you are not a CIIO and process fewer than 1 million individuals' data, use the standard contract published by the CAC (effective June 2023). File the contract with the provincial CAC within 10 working days of signing.",
    "For HR data specifically, consider processing and storing the data within China using a local server or cloud provider (e.g., Alibaba Cloud in Shanghai). Only transfer aggregated, anonymized reports outside China after ensuring irreversible anonymization."
  ],
  "transition_graph": {
    "leads_to": [],
    "preceded_by": [],
    "frequently_confused_with": []
  },
  "official_doc_url": "https://www.gov.cn/zhengce/2021-08/20/content_5632566.htm",
  "official_doc_section": null,
  "error_code": null,
  "verification_tier": "ai_generated",
  "confidence": 0.84,
  "fix_success_rate": 0.8,
  "resolvable": "partial",
  "first_seen": "2024-06-10",
  "last_confirmed": "2024-06-01",
  "last_updated": "2024-06-01",
  "evidence_count": 1,
  "tags": [],
  "locale": "en",
  "aliases": []
}