AI告诉外国公司,它可以在未经政府评估的情况下自由地将员工HR数据转移出中国
AI tells a foreign company that it can freely transfer employee HR data out of China without government assessment
ID: legal/china-cyber-security-law-data-localization
版本兼容性
| 版本 | 状态 | 引入 | 弃用 | 备注 |
|---|---|---|---|---|
| PIPL (Personal Information Protection Law, 2021) | active | — | — | — |
| Cybersecurity Law of the PRC (2017) | active | — | — | — |
| Measures for Security Assessment of Cross-Border Data Transfer (2022) | active | — | — | — |
根因分析
中国的《个人信息保护法》(PIPL)和《网络安全法》要求,关键信息基础设施运营者或处理大量数据的实体将个人信息(包括HR数据)跨境转移,必须经过国家互联网信息办公室(CAC)的安全评估,或使用标准合同或认证;违规者可能被处以高达年收入5%的罚款。
English
China's Personal Information Protection Law (PIPL) and the Cybersecurity Law require that cross-border transfer of personal information (including HR data) by critical information infrastructure operators or entities processing large volumes of data must undergo a security assessment by the Cyberspace Administration of China (CAC), or use a standard contract or certification; failure to do so can result in fines up to 5% of annual revenue.
官方文档
https://www.gov.cn/zhengce/2021-08/20/content_5632566.htm解决方案
-
Determine if your company is a Critical Information Infrastructure Operator (CIIO). If yes, you must undergo a CAC security assessment. File an application with the CAC through the provincial cyberspace administration, providing a data transfer impact assessment and a contract with the foreign recipient.
-
If you are not a CIIO and process fewer than 1 million individuals' data, use the standard contract published by the CAC (effective June 2023). File the contract with the provincial CAC within 10 working days of signing.
-
For HR data specifically, consider processing and storing the data within China using a local server or cloud provider (e.g., Alibaba Cloud in Shanghai). Only transfer aggregated, anonymized reports outside China after ensuring irreversible anonymization.
无效尝试
常见但无效的做法:
-
90% 失败
For critical information infrastructure operators or entities processing data of 1 million+ individuals, a CAC security assessment is mandatory regardless of SCCs; SCCs are only an option for smaller-scale transfers
-
85% 失败
PIPL defines personal information broadly; anonymization must be irreversible and the data must not be re-identifiable. Pseudonymized data is still considered personal information and is subject to the same rules
-
95% 失败
A DPA addresses data processing, not cross-border transfer; the transfer itself requires either a CAC assessment, a standard contract, or certification under PIPL Article 38