top of page

China Cross Border Data Transfer Rules and the New Certification Pathway

19 hours ago
2 min read

China's Personal Information Protection Law has always set out three lawful mechanisms for moving personal information outside the country: a CAC security assessment, a standard contract with the overseas recipient, or third party certification. For several years, the certification route existed on paper without detailed implementing rules. That changed with the Measures for Certification of Cross-Border Personal Information Transfer, issued jointly by the Cyberspace Administration of China and the State Administration for Market Regulation in October 2025 and effective from 1 January 2026, which finally completed the three pathway framework.

Why the certification route matters

Certification opens a structured, auditable route for data exporters that fall below the thresholds requiring a mandatory security assessment but still need something more formal than a standard contract filing, obtained from a CAC accredited third party institution. A related national standard, covering the technical security requirements for certified cross-border processing, took effect on 1 March 2026, giving companies a clearer technical benchmark to build toward.

Regardless of which of the three mechanisms applies, every route still requires a completed Personal Information Protection Impact Assessment. This document effectively becomes the foundation for whichever pathway a company ultimately uses, so it makes sense to prepare it early rather than as a late addition to whichever filing turns out to be required.

The thresholds move during the year

Which mechanism a company needs depends on the volume and sensitivity of the data involved, and whether the company qualifies as a critical information infrastructure operator. These thresholds are counted cumulatively from the first of January each year, not per individual transfer, which means a company that starts the year comfortably under a threshold can cross it mid year as transfer volumes build, changing which mechanism is legally required partway through.

Higher stakes for getting it wrong

The amended Cybersecurity Law, also effective from 1 January 2026, raised the penalties for data compliance failures considerably, with fines now reaching a much higher ceiling for serious violations, and removed the requirement for regulators to issue a warning before fining a company for a first offence. Given the broadened extraterritorial reach of the law, foreign companies handling personal information connected to China should treat cross-border data transfer compliance as a standing workstream, reviewed at least annually, rather than a one off filing exercise completed at the point of market entry. New to China or ready to switch? Whether you are setting up a new China company or moving away from your current provider, Woodburn makes the process clear, compliant and straightforward.


Book a free call for offshore profits tax advice

Why Woodburn?

With 30+ years’ experience, Woodburn supports international businesses setting up and operating across Hong Kong and China.

We combine technical expertise, regional knowledge and hands-on corporate services with the direct communication and responsiveness of a specialist partner.




 
 
bottom of page