Cross-border data transfer under PIPL: what changed and what to do
Moving personal information out of China is one of the few areas where a European compliance instinct actively misleads you. A process that would be routine under GDPR can, in China, require a security assessment, a signed standard contract, or a certification — and getting the classification wrong is where most of the risk sits.
The three routes, briefly
Under the Personal Information Protection Law, a transfer abroad generally travels one of three roads:
- Security assessment led by the Cyberspace Administration of China, for large
volumes or important data.
- Standard contract filed with the regulator, the workhorse for most mid-sized
transfers.
- Certification by an accredited body, useful for intra-group flows.
The 2024 provisions raised the volume thresholds and carved out several everyday scenarios — HR data needed to manage staff, transfers necessary to perform a contract with the individual — from the heavier mechanisms entirely.
Where FIEs still trip
The exemptions are real, but they are narrower than the headlines suggest. Two patterns recur:
- Treating an exemption as a blanket permission rather than a purpose-bound one.
- Never having mapped the data in the first place, so no one can say which route a
given flow actually needs.
If you cannot produce a current record of what personal information leaves the country, for what purpose, and on what legal basis, you do not yet have a cross-border position — you have an assumption.
A practical starting point
Start with the map, not the mechanism. A data inventory that ties each outbound flow to a purpose and a lawful route turns an abstract legal question into a short, decidable list. From there, most organisations find that the majority of their transfers sit comfortably inside an exemption or a standard contract — and that the genuinely assessment-grade flows are few, and worth the attention.
If you would like a second read on where your transfers fall, get in touch.