China (PIPL)

China Decides Data Exports by Headcount, Not by Where the Data Is Going

Key Takeaways

  • A non-CIIO processor exporting fewer than 100,000 individuals' non-sensitive personal information in a calendar year is exempt from all three transfer mechanisms
  • A security assessment is required above 1,000,000 individuals' non-sensitive personal information, above 10,000 individuals' sensitive personal information, or for any export by a critical information infrastructure operator
  • PIPL Article 13 lists seven bases for processing and none of them is legitimate interests
  • "Separate consent" is a distinct statutory device required for cross-border provision, disclosure to another processor, public disclosure and sensitive data — and Article 28 makes all data of under-14s sensitive
  • Article 66 penalties reach RMB 50 million or 5% of prior-year turnover, plus RMB 100,000 to 1 million on responsible individuals and a bar on holding senior office

A Note on Language

The Personal Information Protection Law and the export rules below are Chinese-language instruments, and the renderings in this guide are this publication's translations of the official Chinese texts rather than authoritative wording. The National People's Congress does publish English texts of some laws, and labels that collection 仅供参考 — "for reference only". No official English version of the PIPL is treated here as authoritative, and nothing below should be read as a quotation of one.

Export Turns on Headcount, Not on Destination

The European model asks whether the receiving country protects data adequately. The Chinese model asks how many people are affected, whether their data is sensitive, and what kind of operator is sending it. The destination is, for the most part, not the question.

The operative instrument is Cyberspace Administration of China Order No. 16, the Provisions on Promoting and Regulating Cross-Border Data Flows, adopted at the CAC's 26th executive meeting of 2023 on 28 November 2023, published on 22 March 2024 and effective from publication. Article 13 gives it priority: where the 2022 Measures for Security Assessment of Data Exports (Order No. 11) or the 2023 Measures on Standard Contracts for the Export of Personal Information (Order No. 13) are inconsistent with it, Order No. 16 applies.

Two details from the superseded orders show what that priority rule does in practice. Order No. 11, the Measures for Security Assessment of Data Exports, was published on 7 July 2022 and took effect on 1 September 2022; its Article 14 set the validity of a passed assessment at two years. Order No. 16 Article 9 sets it at three, and Article 13 resolves the conflict in favour of the later instrument. A reader working from the 2022 measures alone would plan renewals a year too early.

Order No. 13, the Measures on Standard Contracts for the Export of Personal Information, was published on 24 February 2023 and took effect on 1 June 2023. Its Article 7 carries a requirement with no European counterpart: within 10 working days of the standard contract taking effect, the personal information processor must file it with the provincial cyberspace department, submitting the prescribed materials and bearing responsibility for their accuracy. EU standard contractual clauses are concluded privately and filed with nobody; the Chinese standard contract is a filing obligation as well as a contract. Article 8 requires a fresh impact assessment and a supplemented or re-concluded contract, with corresponding re-filing, where specified circumstances arise during the contract's term.

The thresholds in Articles 5, 7 and 8 are cumulative from 1 January of the current year, and count individuals rather than records:

Volume exported since 1 JanuaryRequirement
Fewer than 100,000 individuals' personal information, excluding sensitive personal information (non-CIIO)Exempt from security assessment, standard contract and certification — Article 5(4)
100,000 or more but fewer than 1,000,000 individuals' non-sensitive personal information, or fewer than 10,000 individuals' sensitive personal information (non-CIIO)Standard contract with the overseas recipient, or personal information protection certification — Article 8
More than 1,000,000 individuals' non-sensitive personal information, or more than 10,000 individuals' sensitive personal information, or any important data (non-CIIO)Security assessment, applied for through the provincial cyberspace department to the national one — Article 7
Any personal information or important data exported by a critical information infrastructure operatorSecurity assessment — Article 7(1)

Article 9 attaches a shelf life to the hardest route: a passed security assessment is valid for three years from the date the result is issued, and a processor needing to continue may apply through its provincial cyberspace department within 60 working days before expiry for a three-year extension.

Several categories fall outside the machinery entirely. Article 3 exempts data collected and generated in international trade, cross-border transport, academic cooperation, transnational manufacturing and marketing where it contains neither personal information nor important data. Article 4 exempts personal information collected and generated abroad, transmitted into China for processing and then sent back out, provided no domestic personal information or important data was introduced during processing — the pure offshore-processing case.

Article 5 adds three exemptions independent of volume: where export is genuinely necessary to conclude or perform a contract to which the individual is a party, with cross-border shopping, delivery, remittance, payment, account opening, flight and hotel booking, visa processing and examination services given as examples; where cross-border human resources management is carried out under lawfully established labour rules and a lawfully concluded collective contract, and employee data genuinely needs to go abroad; and where export is genuinely necessary in an emergency to protect a natural person's life, health or property. None of these covers important data.

Article 6 adds a geographic wildcard. Free trade pilot zones may draw up their own negative lists of data requiring assessment, standard contract or certification, subject to approval by the provincial cybersecurity and informatisation committee and filing with the national cyberspace and data authorities. Data outside a zone's negative list may be exported free of all three mechanisms — so the applicable rule can depend on which zone the exporter sits in.

Article 2 shifts the burden on important data in a way worth noting: where relevant departments or regions have not notified a processor or publicly announced data as important data, the processor need not declare it as important data for the export security assessment.

What the PIPL Requires Regardless of Route

Order No. 16 governs which mechanism applies. It does not displace the underlying statute. Article 38 of the Personal Information Protection Law sets out the four conditions, one of which a processor must satisfy to send personal information abroad: passing the CAC-organised security assessment under Article 40; obtaining personal information protection certification from a professional body per CAC rules; concluding a contract with the overseas recipient on the CAC's standard contract, setting out both parties' rights and obligations; or other conditions provided by law, administrative regulation or the CAC. Article 38 also requires the processor to take necessary measures to ensure the overseas recipient's processing meets the protection standard of the PIPL — an obligation that survives whichever route is used.

Article 40 imposes localisation on two classes: critical information infrastructure operators, and processors handling personal information in volumes the CAC specifies. Both must store domestically the personal information they collect and generate in China, and must pass the CAC security assessment where export is genuinely needed.

Article 39 layers a transparency and consent duty on top. Before providing personal information abroad, the processor must tell the individual the overseas recipient's name, contact details, processing purposes and methods, the categories of personal information involved, and how to exercise their PIPL rights against that recipient — and must obtain the individual's separate consent. Article 55(4) then requires a personal information protection impact assessment before any cross-border provision, recorded and retained.

A company clearing the Article 5(4) volume exemption therefore has not finished. It has escaped the assessment, contract and certification machinery, not the notice, separate-consent and impact-assessment obligations, which have no volume threshold at all.

Seven Bases, and Legitimate Interests Is Not One

Article 13 permits processing on one of seven grounds: the individual's consent; necessity to conclude or perform a contract to which the individual is a party, or to conduct human resources management under lawfully established labour rules and a lawfully concluded collective contract; necessity to perform a statutory duty or obligation; necessity to respond to a public health emergency or, in an emergency, to protect a natural person's life, health or property; processing within a reasonable scope to carry out news reporting or public opinion supervision in the public interest; processing within a reasonable scope of personal information the individual has made public themselves or that has otherwise been lawfully disclosed; and other circumstances provided by law or administrative regulation.

There is no legitimate interests basis. Among the regimes covered in this series, the PIPL is alone in omitting it: the EU and UK have Article 6(1)(f), Brazil has it in Article 7, and India substitutes a closed list of "certain legitimate uses". A Chinese processor cannot document a balancing test and proceed; it needs one of the seven.

The final paragraph of Article 13 supplies the corollary: where other provisions of the law require consent, consent is not needed if grounds (2) through (7) apply. The employment ground in Article 13(2) does substantial work as a result, and it is conditioned — it requires labour rules established according to law and a collective contract concluded according to law, not merely an employment relationship.

"Separate Consent" Is Its Own Legal Device

Article 14 sets the baseline: consent based on the individual's full knowledge, given voluntarily and explicitly, with any statutory requirement of separate or written consent applying on top. The PIPL then requires that heightened form — 单独同意, separate consent — at four specific points, and the pattern is what makes it distinctive rather than any one instance.

  • Article 23. Providing personal information to another personal information processor, after informing the individual of the recipient's name, contact details, processing purpose and methods, and the categories involved
  • Article 25. Publicly disclosing personal information the processor handles, which is otherwise prohibited outright
  • Article 29. Processing sensitive personal information, with written consent required where law or administrative regulation says so
  • Article 39. Providing personal information outside China

Separate consent means consent to that specific act, sought on its own rather than bundled into a general privacy notice or a single acceptance of terms. A consent flow that satisfies GDPR Article 7 by being freely given, specific, informed and unambiguous can still fail Article 39 if the cross-border element was folded into a broader acceptance.

Sensitive Data Includes Everyone Under Fourteen

Article 28 defines sensitive personal information functionally rather than by list alone: information that, once leaked or unlawfully used, is liable to cause harm to a natural person's dignity, or to endanger their personal or property safety. The enumerated examples are biometric identification, religious belief, specific identity, medical and health information, financial accounts and whereabouts or movement traces.

The list then closes with a category the other regimes handle separately: the personal information of minors under fourteen years of age. All of it is sensitive personal information by definition, whatever its subject matter. A child's name, in Chinese law, sits in the same category as an adult's biometric template.

Article 28's second paragraph adds a gate that consent alone does not open: sensitive personal information may be processed only where there is a specific purpose and sufficient necessity, and strict protective measures are taken. Article 29 then requires separate consent on top of that, and Article 55(1) requires an impact assessment before processing begins.

Reaching Companies Outside China, and Keeping Data From Leaving It

Article 3 applies the law to processing of natural persons' personal information within China, and extends it to processing carried out outside China of personal information of natural persons within China where the purpose is to provide products or services to them, where their behaviour is analysed or assessed, or in other circumstances provided by law or administrative regulation.

Article 53 attaches an obligation to that extraterritorial reach. A processor caught by Article 3's second paragraph must establish a dedicated body or designate a representative within China to handle personal information protection matters, and must report that body's name or the representative's name and contact details to the department performing personal information protection duties. Unlike GDPR Article 27, the designation is filed with the regulator rather than merely recorded internally.

Article 41 runs in the opposite direction and functions as a blocking provision. Competent PRC authorities handle requests from foreign judicial or law enforcement bodies for personal information stored within China under relevant laws and treaties or on the principle of equality and reciprocity. Absent approval from those competent authorities, a personal information processor may not provide personal information stored within China to a foreign judicial or law enforcement body. A US discovery order and Article 41 can therefore point in opposite directions, and Article 41 does not carve out that conflict.

Penalties Follow the People, Not Only the Company

Article 66 operates in two tiers. At the first, the department performing personal information protection duties may order correction, issue a warning, confiscate unlawful gains, and order suspension or termination of service by an offending application; where correction is refused, a fine of up to RMB 1 million follows, together with fines of RMB 10,000 to 100,000 on the directly responsible person in charge and other directly responsible personnel.

The second tier applies where the circumstances are serious, and is imposed by a provincial-level or higher department. It carries a fine of up to RMB 50 million or up to 5% of the previous year's turnover, alongside confiscation of unlawful gains and orders to correct. The department may also order suspension of the relevant business or suspension of operations for rectification, and may notify the relevant competent authorities to revoke the relevant business permit or the business licence.

The provision that has no counterpart elsewhere in this series comes last. Directly responsible persons in charge and other directly responsible personnel face fines of RMB 100,000 to 1 million, and the department may decide to prohibit them, for a period, from serving as a director, supervisor, senior manager, or person in charge of personal information protection at a relevant enterprise. The sanction attaches to the individual and follows them to their next employer.

Article 67 adds that violations are recorded in credit files and publicised under the relevant laws and administrative regulations, and Article 68 handles state organs separately — their failures draw an order to correct from a superior organ or the supervising department, and disciplinary sanctions on responsible personnel rather than fines.

Background

For the underlying law rather than this development: Technology & SaaS privacy law.

Frequently Asked Questions

When does a transfer out of China need a CAC security assessment?
Under Article 7 of CAC Order No. 16, where a critical information infrastructure operator provides any personal information or important data abroad; or where a non-CIIO processor provides important data abroad, or has cumulatively since 1 January of the current year provided the personal information of more than 1,000,000 individuals excluding sensitive personal information, or the sensitive personal information of more than 10,000 individuals. The result is valid three years under Article 9.
Is there a volume below which no transfer mechanism is needed?
Article 5(4) of Order No. 16 exempts a non-CIIO processor that has cumulatively provided abroad, since 1 January of the current year, the personal information of fewer than 100,000 individuals excluding sensitive personal information. That exemption covers the security assessment, standard contract and certification. It does not cover the PIPL's notice, separate-consent and impact-assessment duties, which have no volume threshold.
Does the PIPL have a legitimate interests basis?
No. Article 13 lists seven grounds — consent, contract or lawful human resources management, statutory duty, public health emergency or emergency protection of life and property, news reporting and public opinion supervision in the public interest, lawfully public information, and other circumstances provided by law or administrative regulation. Legitimate interests is not among them.
What is "separate consent" and when is it required?
It is a heightened form of consent sought for a specific act rather than bundled into a general notice. The PIPL requires it under Article 23 for providing personal information to another processor, Article 25 for public disclosure, Article 29 for sensitive personal information, and Article 39 for providing personal information outside China.
Is children's data treated as sensitive under the PIPL?
Yes, categorically. Article 28 defines sensitive personal information to include biometric identification, religious belief, specific identity, medical and health information, financial accounts and whereabouts information, and also the personal information of minors under fourteen years of age. That means all personal information of an under-14, not only data that would be sensitive for an adult.
Can a company hand data stored in China to a foreign court or regulator?
Article 41 provides that without approval from the competent PRC authorities, a personal information processor may not provide personal information stored within China to a foreign judicial or law enforcement body. Requests from such bodies are handled by the competent PRC authorities under relevant laws and treaties or on the principle of equality and reciprocity. Whether a particular foreign order conflicts with this is a question for counsel in both jurisdictions.

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.