Skip to content
HAINAN SETUPChina market entry

China Cross-Border Data Transfer and Data Localization: 2026 Compliance Guide for Foreign Businesses

A practical 2026 guide to China's cross-border data transfer pathways, exemptions, thresholds, sector-specific localization rules, enforcement, and the Hainan FTP negative list.

September 8, 2026 · Hainan Setup Editorial Team · 12 min read

A compliance lead asks whether global HR may receive employee records, overseas CRM needs assessment, and every database must stay onshore. One china cross-border data transfer project can produce different outcomes.

TL;DR — China’s data transfer rules in 2026 at a glance

  • Three routes are operational. The amended Cybersecurity Law and CAC/SAMR Order No. 20 took effect January 1, 2026.
  • China operates a tiered, threshold-based system — most routine transfers by foreign businesses are now exempt or lightly regulated. Monthly assessment acceptances fell about 60% and contract filings about 50%, per CAC’s first-anniversary briefing, March 2025.
  • Count cumulatively since January 1 of the current year. For a non-CIIO: below 100,000 individuals is exempt; 100,000 to below 1 million, or below 10,000 sensitive-information subjects, uses contract or certification; higher bands, important data and CIIO transfers require assessment.
  • Localization is targeted. CIIOs and financial, medical, mapping and automotive rules create sector-specific localization mandates.
  • Negative lists matter. As of March 23, 2026, nine areas covered 22 sectors; Hainan Free Trade Port (Hainan FTP) covered 14 scenarios in five fields.
  • Penalties are material. Didi received an RMB 8.026 billion penalty on July 21, 2022. PIPL Article 66 permits up to RMB 50 million or 5% of the prior year’s annual turnover for serious violations.

Why a 2026 refresh matters

Pre-2026 guidance often uses old numbering or defaults to assessment. Start with data, purpose, operator, sector, exemption and cumulative volume. A foreign-investment green channel exists; assessments averaged under 30 working days, per CAC’s first-anniversary briefing, versus 45 in earlier rules. See our Hainan FTP guide. For subscription software, the SaaS China entry guide connects the data architecture to entity, hosting and ICP decisions.

Does China Require Data Localization? (Short Answer: Only for CIIOs and Specific Sectors)

Myth vs Fact

Myth: “China requires all data to be stored locally.”

Fact: Article 39 of the amended Cybersecurity Law (effective January 1, 2026), formerly Article 37, requires a CIIO to store in China the personal information and important data it collects or generates during operations in China. Ordinary businesses have no universal localization duty, although sector rules and transfer requirements may apply.

CIIO status is notified, not self-declared

Under the Regulation on the Security Protection of Critical Information Infrastructure (State Council Order No. 745, effective September 1, 2021), the competent department identifies critical infrastructure and notifies the operator. CIIO status is regulator-designated and notified — not self-assessed. Article 39 covers personal information and important data collected or generated in China during CIIO operations; a necessary export requires assessment unless another applicable rule provides otherwise.

China data localization requirements by sector

Operator or data type Localization position Main basis Outbound route
CIIO personal information and important data Store in China Amended Cybersecurity Law Article 39, effective January 1, 2026 CAC security assessment where a necessary transfer is made, subject to applicable exceptions
Banking personal financial information Domestic storage, processing and analysis Jin Gui [2024] No. 24; also a long-standing industry practice since 2011 Financial-sector rules and applicable transfer route
Population-health information and health/medical big data Domestic servers 2014 and 2018 health measures Assessment review where necessary; a new sectoral data-security measure for medical and health institutions was issued in February 2026, without using unverified article details
Internet map data Servers in China Regulation on Map Management Article 34 Sector rules
Automotive important data Store in China Provisions on Automotive Data Security Article 11 Security assessment; the 2026 Automotive Data Export Security Guidelines state nine exemption categories
Ordinary enterprise outside CIIO and listed sectors No universal duty CAC Order No. 16 Exemption, contract, certification or assessment

Verify any credit-reporting sector rule.

PIPL Article 38 establishes assessment, certification and China SCC routes. CAC Order No. 16, effective March 22, 2024, connects exemptions, thresholds and negative lists. State Council Order No. 790, effective January 1, 2025, adds the administrative-regulation layer and an RMB 10 million tier in Articles 55–57.

Myth vs Fact

Myth: “All cross-border data transfers require a CAC security assessment.”

Fact: The system is tiered and threshold-based. A transfer may be exempt, qualify for a free-trade-zone negative-list exemption, use the China SCC or certification, or require security assessment. Count the affected individuals cumulatively since January 1 of the current year.

China data transfer thresholds and route comparison

Decision point CAC security assessment Standard Contract (China SCC) Personal information protection certification
Legal basis Assessment measures; CAC Order No. 16 Article 7 Contract measures; CAC Order No. 16 Article 8 CAC/SAMR Order No. 20, effective January 1, 2026
Who and what CIIO data; important data; or non-CIIO cumulatively since January 1 of the current year at least 1 million individuals’ non-sensitive information or 10,000 individuals’ sensitive information Non-CIIO at 100,000 to fewer than 1 million individuals’ non-sensitive information, or fewer than 10,000 individuals’ sensitive information, on the same cumulative basis Same band as China SCC, with no important data
Handling body Provincial authority receives; CAC assesses Provincial filing within 10 working days after effect Filed body; three as of March 23, 2026
Portal sjcj.cac.gov.cn Provincial filing channel data.isccc.gov.cn
Validity Three years; request three more at least 60 working days before expiry Refile after a relevant change Three years
Timing reference Average under 30 working days, per CAC’s first-anniversary briefing Filing Institution process
Anti-avoidance Transfers cannot be split to avoid assessment Artificial splitting does not change the applicable route CAC/SAMR Order No. 20 expressly bars quantity splitting to evade assessment
Principal sources CAC Order No. 16 and third-edition guide Standard Contract measures CAC/SAMR Order No. 20

Published October 14, 2025, CAC/SAMR Order No. 20 made certification operational on January 1, 2026. As of March 23, 2026, the filed bodies were the China Cybersecurity Review, Certification and Market Regulation Big Data Center; CAC Data and Technology Support Center; and China Electronics Standardization Institute Certification Center.

What if a transfer crosses the threshold mid-year?

The January 30, 2026 CAC Q&A says a company using the China SCC or certification that later exceeds 1 million individuals’ non-sensitive personal information or 10,000 individuals’ sensitive personal information must apply through the provincial authority for national assessment. Earlier exports under the contract or certification enter the assessment scope.

Important data: catalogue plus notification

CAC Order No. 16 uses catalogue + notification. Without notice or public identification, the processor need not submit data as important data: there is no self-designation duty. Follow applicable catalogues and notices; GB/T 43697-2024 supports classification work.

Exemptions That Matter to Foreign Businesses: A Scenario Checker

CAC Order No. 16 Articles 3–5 exempt qualifying business data without personal or important data; unchanged overseas-collected data; individual-contract necessity; cross-border HR; emergencies; and a non-CIIO below 100,000 individuals’ non-sensitive information.

Business scenario Initial route screen Boundary to document
Group HR system synchronizes Chinese employee data needed for global personnel management May use the HR exemption Transfer must be necessary and based on lawfully adopted employment rules and a lawfully concluded collective contract; general PIPL duties remain
Cross-border e-commerce transfers fulfillment data Contractual-necessity exemption may apply Limit data and purpose to performance
Global CRM exports non-sensitive personal information of fewer than 100,000 individuals Non-CIIO de minimis exemption Count cumulatively since January 1 of the current year and screen for sensitive personal information and important data
Global CRM reaches 100,000 but fewer than 1 million individuals China SCC or certification The band excludes sensitive information from the ordinary-personal-information count; sensitive information has its own 10,000-person threshold
Transfer reaches at least 1 million individuals, at least 10,000 sensitive-information subjects, or includes notified/catalogued important data CAC security assessment Include earlier SCC or certification exports if the threshold is crossed during the year
Hainan FTP data outside its five-field, 14-scenario list Exempt from three routes Confirm entity, data and scope
Mainland Greater Bay Area city transfers personal information to Hong Kong Greater Bay Area facilitation SCC Applies to the nine mainland cities; onward provision outside the Greater Bay Area requires a separate route analysis

HR exemption boundary

“Necessary for HR management” is a limiting condition, not a label for every employee-data feed.

The transfer needs lawfully adopted employment rules and a lawfully concluded collective contract. PIPL notice, rights and protection duties remain. Map payroll, analytics and monitoring separately.

The Greater Bay Area arrangement links nine mainland cities with Hong Kong and later Macau; onward provision needs separate analysis. Our market-entry team can classify ambiguous routes.

Free Trade Zone Negative Lists — and the Hainan FTP Angle

CAC Order No. 16 Article 6 allows FTZ negative lists. After provincial approval and national filing, data outside the list is exempt from assessment, contract and certification.

As of March 23, 2026, nine areas had lists spanning 22 industry fields. Registration alone is not a generic waiver.

Area Release position Coverage Structural feature
Tianjin May 9, 2024 Multiple fields First free-trade-zone data-export negative list in China
Beijing August 2024; reform plan April 29, 2026 Automotive, pharmaceutical, retail, civil aviation, AI Category, subcategory, field
Shanghai February 2025; citywide April 24, 2026, per industry summaries Reinsurance, shipping, commerce, meteorology Four fields, nine scenarios, 29 subcategories, 109 items; 2026 official URL unavailable
Hainan FTP February 19, 2025 Deep sea, aerospace, seed industry, tourism, duty-free/commerce Five fields and 14 scenarios
Zhejiang, Guangxi, Jiangsu, Chongqing, Fujian and others Released during 2024–2026 Part of the nine-area, 22-field total Local scenario-based lists

What the Hainan data negative list changes

Hainan’s 2024-version list covers 14 scenarios in deep-sea, aerospace, seed, tourism and duty-free/commerce. Data outside it is exempt from three routes. See Hainan’s data rules and the negative-list walkthrough for field-level detail.

Hainan’s international-data-center regulation took effect December 1, 2024. Island-wide independent customs operations began December 18, 2025. Yet no dedicated post-closure data-flow policy has been officially published as of this writing.

Post-closure evidence boundary

Do not infer a new data-transfer exemption from customs closure.

Test projects against the existing list, data-center regulation, closure date and later official publications—not a predicted policy.

Registration helps only when entity, activity and data fit. Review Hainan company registration support and the registration guide; formation does not prove qualification.

Enforcement Reality: Penalties, the Didi Case, and the EU-China Mechanism

  • PIPL Article 66: for a serious violation, up to RMB 50 million or 5% of the prior year’s annual turnover; responsible personnel may face RMB 100,000–1 million and possible management restrictions.
  • DSL Article 46: exporting important data contrary to DSL Article 31 may attract RMB 100,000–1 million, rising to RMB 1–10 million for a serious case, with possible suspension or license consequences. DSL Article 45 separately covers failures of general data-security duties, from RMB 50,000–500,000, rising to RMB 500,000–2 million for refusal to correct or serious consequences, and RMB 2–10 million for violations involving national core-data management.
  • Regulation on Network Data Security Management (State Council Order No. 790), Articles 55–57: its liability chapter includes an RMB 10 million tier.

On July 21, 2022, CAC fined Didi Global Inc. RMB 8.026 billion under PIPL, DSL and CSL. Cheng Wei and Liu Qing were each fined RMB 1 million; CAC identified 16 unlawful facts.

The EU-China communication mechanism

The EU-China communication mechanism on cross-border data flows first met in Beijing on August 27, 2024, co-chaired by CAC and the European Commission’s Directorate-General for Trade. At the second meeting in Brussels on July 17, 2025, the parties agreed to establish an automotive-data working group. The mechanism does not replace a company’s PIPL or CAC Order No. 16 analysis.

2026 developments to monitor

As of March 23, 2026, CAC reported nine list areas covering 22 fields, three filed certification bodies and pre-assessment pilots in 14 areas. Materials included an April 2025 financial guide, the February 3 automotive guide from eight departments with nine exemptions, and the January 2026 Q&A.

According to public reports, a June 22, 2026 foreign-investment action plan supports more field-level lists and important-data catalogue standards. With no official URL in the evidence file, it is not a filing basis.

Putting It Together: A 2026 Compliance Checklist

Use three layers: exemptions and thresholds for the route; catalogue and notification for the data; and the applicable negative list for the location.

  1. Map transfers: system, parties, purpose, fields, sensitivity and cumulative count.
  2. Check status: CIIO notice and sector-localization rules. For a mainland-facing website, assess the China ICP license track separately.
  3. Select the route: provincial China SCC filing, data.isccc.gov.cn certification, or sjcj.cac.gov.cn assessment; reassess changes.
  4. Test Hainan fit: compare its list and data-center framework; separately map cross-border cash pooling.
  5. Retain evidence: align inventory, notices, assessments, contracts, approvals and system settings.

This guide is for information only, not legal advice.

Frequently asked questions

Does China require all data to be stored locally?

No. Article 39 of the amended Cybersecurity Law, formerly Article 37, applies to personal information and important data collected or generated in China by a CIIO. Financial, medical, mapping and automotive rules add sector-specific localization mandates. Ordinary companies are not subject to a universal localization duty, and CIIO status is regulator-designated and notified.

Is transferring employee HR data to an overseas headquarters exempt from China’s cross-border data transfer rules?

It may be exempt when the transfer is strictly necessary for cross-border HR management under lawfully adopted employment rules and a lawfully concluded collective contract. The exemption removes the three transfer-route requirements, not general PIPL duties such as notice and rights handling. Other transfers must still be counted and tested against the applicable thresholds.

How does Hainan Free Trade Port’s negative list for cross-border data transfer work?

Hainan’s 2024-version list, released February 19, 2025, covers 14 scenarios in five fields. Data outside the list is exempt from security assessment, the Standard Contract and certification under CAC Order No. 16. Hainan also has an international-data-center regulation, but no dedicated post-closure data-flow policy has been officially published as of this writing. For implementation context, revisit Hainan’s cross-border data rules explained.

Official sources

China data transfer planning

Turn systems, datasets and thresholds into an implementation sequence.

We map transfers, screen important data, compare routes and test Hainan negative-list fit, producing a work plan for authority and provider discussions.

Discuss a China data transfer plan

You can also send us your system map and China operating plan or schedule a 30-minute consultation.

Continue reading

Related Hainan insights.

Use the next guide to connect this decision to the rest of the company setup.