China Cross-Border Data Transfer and Data Localization: 2026 Compliance Guide for Foreign Businesses
A practical 2026 guide to China's cross-border data transfer pathways, exemptions, thresholds, sector-specific localization rules, enforcement, and the Hainan FTP negative list.
September 8, 2026 · Hainan Setup Editorial Team · 12 min read
A compliance lead asks whether global HR may receive employee records, overseas CRM needs assessment, and every database must stay onshore. One china cross-border data transfer project can produce different outcomes.
TL;DR — China’s data transfer rules in 2026 at a glance
- Three routes are operational. The amended Cybersecurity Law and CAC/SAMR Order No. 20 took effect January 1, 2026.
- China operates a tiered, threshold-based system — most routine transfers by foreign businesses are now exempt or lightly regulated. Monthly assessment acceptances fell about 60% and contract filings about 50%, per CAC’s first-anniversary briefing, March 2025.
- Count cumulatively since January 1 of the current year. For a non-CIIO: below 100,000 individuals is exempt; 100,000 to below 1 million, or below 10,000 sensitive-information subjects, uses contract or certification; higher bands, important data and CIIO transfers require assessment.
- Localization is targeted. CIIOs and financial, medical, mapping and automotive rules create sector-specific localization mandates.
- Negative lists matter. As of March 23, 2026, nine areas covered 22 sectors; Hainan Free Trade Port (Hainan FTP) covered 14 scenarios in five fields.
- Penalties are material. Didi received an RMB 8.026 billion penalty on July 21, 2022. PIPL Article 66 permits up to RMB 50 million or 5% of the prior year’s annual turnover for serious violations.
Why a 2026 refresh matters
Pre-2026 guidance often uses old numbering or defaults to assessment. Start with data, purpose, operator, sector, exemption and cumulative volume. A foreign-investment green channel exists; assessments averaged under 30 working days, per CAC’s first-anniversary briefing, versus 45 in earlier rules. See our Hainan FTP guide. For subscription software, the SaaS China entry guide connects the data architecture to entity, hosting and ICP decisions.
Does China Require Data Localization? (Short Answer: Only for CIIOs and Specific Sectors)
Myth vs Fact
Myth: “China requires all data to be stored locally.”
Fact: Article 39 of the amended Cybersecurity Law (effective January 1, 2026), formerly Article 37, requires a CIIO to store in China the personal information and important data it collects or generates during operations in China. Ordinary businesses have no universal localization duty, although sector rules and transfer requirements may apply.
CIIO status is notified, not self-declared
Under the Regulation on the Security Protection of Critical Information Infrastructure (State Council Order No. 745, effective September 1, 2021), the competent department identifies critical infrastructure and notifies the operator. CIIO status is regulator-designated and notified — not self-assessed. Article 39 covers personal information and important data collected or generated in China during CIIO operations; a necessary export requires assessment unless another applicable rule provides otherwise.
China data localization requirements by sector
| Operator or data type | Localization position | Main basis | Outbound route |
|---|---|---|---|
| CIIO personal information and important data | Store in China | Amended Cybersecurity Law Article 39, effective January 1, 2026 | CAC security assessment where a necessary transfer is made, subject to applicable exceptions |
| Banking personal financial information | Domestic storage, processing and analysis | Jin Gui [2024] No. 24; also a long-standing industry practice since 2011 | Financial-sector rules and applicable transfer route |
| Population-health information and health/medical big data | Domestic servers | 2014 and 2018 health measures | Assessment review where necessary; a new sectoral data-security measure for medical and health institutions was issued in February 2026, without using unverified article details |
| Internet map data | Servers in China | Regulation on Map Management Article 34 | Sector rules |
| Automotive important data | Store in China | Provisions on Automotive Data Security Article 11 | Security assessment; the 2026 Automotive Data Export Security Guidelines state nine exemption categories |
| Ordinary enterprise outside CIIO and listed sectors | No universal duty | CAC Order No. 16 | Exemption, contract, certification or assessment |
Verify any credit-reporting sector rule.
The Three Legal Pathways in 2026: Security Assessment, Standard Contract, Certification
PIPL Article 38 establishes assessment, certification and China SCC routes. CAC Order No. 16, effective March 22, 2024, connects exemptions, thresholds and negative lists. State Council Order No. 790, effective January 1, 2025, adds the administrative-regulation layer and an RMB 10 million tier in Articles 55–57.
Myth vs Fact
Myth: “All cross-border data transfers require a CAC security assessment.”
Fact: The system is tiered and threshold-based. A transfer may be exempt, qualify for a free-trade-zone negative-list exemption, use the China SCC or certification, or require security assessment. Count the affected individuals cumulatively since January 1 of the current year.
China data transfer thresholds and route comparison
| Decision point | CAC security assessment | Standard Contract (China SCC) | Personal information protection certification |
|---|---|---|---|
| Legal basis | Assessment measures; CAC Order No. 16 Article 7 | Contract measures; CAC Order No. 16 Article 8 | CAC/SAMR Order No. 20, effective January 1, 2026 |
| Who and what | CIIO data; important data; or non-CIIO cumulatively since January 1 of the current year at least 1 million individuals’ non-sensitive information or 10,000 individuals’ sensitive information | Non-CIIO at 100,000 to fewer than 1 million individuals’ non-sensitive information, or fewer than 10,000 individuals’ sensitive information, on the same cumulative basis | Same band as China SCC, with no important data |
| Handling body | Provincial authority receives; CAC assesses | Provincial filing within 10 working days after effect | Filed body; three as of March 23, 2026 |
| Portal | sjcj.cac.gov.cn | Provincial filing channel | data.isccc.gov.cn |
| Validity | Three years; request three more at least 60 working days before expiry | Refile after a relevant change | Three years |
| Timing reference | Average under 30 working days, per CAC’s first-anniversary briefing | Filing | Institution process |
| Anti-avoidance | Transfers cannot be split to avoid assessment | Artificial splitting does not change the applicable route | CAC/SAMR Order No. 20 expressly bars quantity splitting to evade assessment |
| Principal sources | CAC Order No. 16 and third-edition guide | Standard Contract measures | CAC/SAMR Order No. 20 |
Published October 14, 2025, CAC/SAMR Order No. 20 made certification operational on January 1, 2026. As of March 23, 2026, the filed bodies were the China Cybersecurity Review, Certification and Market Regulation Big Data Center; CAC Data and Technology Support Center; and China Electronics Standardization Institute Certification Center.
What if a transfer crosses the threshold mid-year?
The January 30, 2026 CAC Q&A says a company using the China SCC or certification that later exceeds 1 million individuals’ non-sensitive personal information or 10,000 individuals’ sensitive personal information must apply through the provincial authority for national assessment. Earlier exports under the contract or certification enter the assessment scope.
Important data: catalogue plus notification
CAC Order No. 16 uses catalogue + notification. Without notice or public identification, the processor need not submit data as important data: there is no self-designation duty. Follow applicable catalogues and notices; GB/T 43697-2024 supports classification work.
Exemptions That Matter to Foreign Businesses: A Scenario Checker
CAC Order No. 16 Articles 3–5 exempt qualifying business data without personal or important data; unchanged overseas-collected data; individual-contract necessity; cross-border HR; emergencies; and a non-CIIO below 100,000 individuals’ non-sensitive information.
| Business scenario | Initial route screen | Boundary to document |
|---|---|---|
| Group HR system synchronizes Chinese employee data needed for global personnel management | May use the HR exemption | Transfer must be necessary and based on lawfully adopted employment rules and a lawfully concluded collective contract; general PIPL duties remain |
| Cross-border e-commerce transfers fulfillment data | Contractual-necessity exemption may apply | Limit data and purpose to performance |
| Global CRM exports non-sensitive personal information of fewer than 100,000 individuals | Non-CIIO de minimis exemption | Count cumulatively since January 1 of the current year and screen for sensitive personal information and important data |
| Global CRM reaches 100,000 but fewer than 1 million individuals | China SCC or certification | The band excludes sensitive information from the ordinary-personal-information count; sensitive information has its own 10,000-person threshold |
| Transfer reaches at least 1 million individuals, at least 10,000 sensitive-information subjects, or includes notified/catalogued important data | CAC security assessment | Include earlier SCC or certification exports if the threshold is crossed during the year |
| Hainan FTP data outside its five-field, 14-scenario list | Exempt from three routes | Confirm entity, data and scope |
| Mainland Greater Bay Area city transfers personal information to Hong Kong | Greater Bay Area facilitation SCC | Applies to the nine mainland cities; onward provision outside the Greater Bay Area requires a separate route analysis |
HR exemption boundary
“Necessary for HR management” is a limiting condition, not a label for every employee-data feed.
The transfer needs lawfully adopted employment rules and a lawfully concluded collective contract. PIPL notice, rights and protection duties remain. Map payroll, analytics and monitoring separately.
The Greater Bay Area arrangement links nine mainland cities with Hong Kong and later Macau; onward provision needs separate analysis. Our market-entry team can classify ambiguous routes.
Free Trade Zone Negative Lists — and the Hainan FTP Angle
CAC Order No. 16 Article 6 allows FTZ negative lists. After provincial approval and national filing, data outside the list is exempt from assessment, contract and certification.
As of March 23, 2026, nine areas had lists spanning 22 industry fields. Registration alone is not a generic waiver.
| Area | Release position | Coverage | Structural feature |
|---|---|---|---|
| Tianjin | May 9, 2024 | Multiple fields | First free-trade-zone data-export negative list in China |
| Beijing | August 2024; reform plan April 29, 2026 | Automotive, pharmaceutical, retail, civil aviation, AI | Category, subcategory, field |
| Shanghai | February 2025; citywide April 24, 2026, per industry summaries | Reinsurance, shipping, commerce, meteorology | Four fields, nine scenarios, 29 subcategories, 109 items; 2026 official URL unavailable |
| Hainan FTP | February 19, 2025 | Deep sea, aerospace, seed industry, tourism, duty-free/commerce | Five fields and 14 scenarios |
| Zhejiang, Guangxi, Jiangsu, Chongqing, Fujian and others | Released during 2024–2026 | Part of the nine-area, 22-field total | Local scenario-based lists |
What the Hainan data negative list changes
Hainan’s 2024-version list covers 14 scenarios in deep-sea, aerospace, seed, tourism and duty-free/commerce. Data outside it is exempt from three routes. See Hainan’s data rules and the negative-list walkthrough for field-level detail.
Hainan’s international-data-center regulation took effect December 1, 2024. Island-wide independent customs operations began December 18, 2025. Yet no dedicated post-closure data-flow policy has been officially published as of this writing.
Post-closure evidence boundary
Do not infer a new data-transfer exemption from customs closure.
Test projects against the existing list, data-center regulation, closure date and later official publications—not a predicted policy.
Registration helps only when entity, activity and data fit. Review Hainan company registration support and the registration guide; formation does not prove qualification.
Enforcement Reality: Penalties, the Didi Case, and the EU-China Mechanism
- PIPL Article 66: for a serious violation, up to RMB 50 million or 5% of the prior year’s annual turnover; responsible personnel may face RMB 100,000–1 million and possible management restrictions.
- DSL Article 46: exporting important data contrary to DSL Article 31 may attract RMB 100,000–1 million, rising to RMB 1–10 million for a serious case, with possible suspension or license consequences. DSL Article 45 separately covers failures of general data-security duties, from RMB 50,000–500,000, rising to RMB 500,000–2 million for refusal to correct or serious consequences, and RMB 2–10 million for violations involving national core-data management.
- Regulation on Network Data Security Management (State Council Order No. 790), Articles 55–57: its liability chapter includes an RMB 10 million tier.
On July 21, 2022, CAC fined Didi Global Inc. RMB 8.026 billion under PIPL, DSL and CSL. Cheng Wei and Liu Qing were each fined RMB 1 million; CAC identified 16 unlawful facts.
The EU-China communication mechanism
The EU-China communication mechanism on cross-border data flows first met in Beijing on August 27, 2024, co-chaired by CAC and the European Commission’s Directorate-General for Trade. At the second meeting in Brussels on July 17, 2025, the parties agreed to establish an automotive-data working group. The mechanism does not replace a company’s PIPL or CAC Order No. 16 analysis.
2026 developments to monitor
As of March 23, 2026, CAC reported nine list areas covering 22 fields, three filed certification bodies and pre-assessment pilots in 14 areas. Materials included an April 2025 financial guide, the February 3 automotive guide from eight departments with nine exemptions, and the January 2026 Q&A.
According to public reports, a June 22, 2026 foreign-investment action plan supports more field-level lists and important-data catalogue standards. With no official URL in the evidence file, it is not a filing basis.
Putting It Together: A 2026 Compliance Checklist
Use three layers: exemptions and thresholds for the route; catalogue and notification for the data; and the applicable negative list for the location.
- Map transfers: system, parties, purpose, fields, sensitivity and cumulative count.
- Check status: CIIO notice and sector-localization rules. For a mainland-facing website, assess the China ICP license track separately.
- Select the route: provincial China SCC filing, data.isccc.gov.cn certification, or sjcj.cac.gov.cn assessment; reassess changes.
- Test Hainan fit: compare its list and data-center framework; separately map cross-border cash pooling.
- Retain evidence: align inventory, notices, assessments, contracts, approvals and system settings.
This guide is for information only, not legal advice.
Frequently asked questions
Does China require all data to be stored locally?
No. Article 39 of the amended Cybersecurity Law, formerly Article 37, applies to personal information and important data collected or generated in China by a CIIO. Financial, medical, mapping and automotive rules add sector-specific localization mandates. Ordinary companies are not subject to a universal localization duty, and CIIO status is regulator-designated and notified.
Is transferring employee HR data to an overseas headquarters exempt from China’s cross-border data transfer rules?
It may be exempt when the transfer is strictly necessary for cross-border HR management under lawfully adopted employment rules and a lawfully concluded collective contract. The exemption removes the three transfer-route requirements, not general PIPL duties such as notice and rights handling. Other transfers must still be counted and tested against the applicable thresholds.
How does Hainan Free Trade Port’s negative list for cross-border data transfer work?
Hainan’s 2024-version list, released February 19, 2025, covers 14 scenarios in five fields. Data outside the list is exempt from security assessment, the Standard Contract and certification under CAC Order No. 16. Hainan also has an international-data-center regulation, but no dedicated post-closure data-flow policy has been officially published as of this writing. For implementation context, revisit Hainan’s cross-border data rules explained.
Official sources
- Personal Information Protection Law — National People’s Congress
- Provisions on Promoting and Regulating Cross-Border Data Flows (CAC Order No. 16)
- Amended Cybersecurity Law — 2025 text
- Measures on Certification for Cross-Border Transfer of Personal Information (CAC/SAMR Order No. 20)
- Regulation on Network Data Security Management (State Council Order No. 790)
- Data Export Security Assessment Application Guide, third edition
- CAC policy Q&A, January 2026
- CAC two-year implementation briefing, March 23, 2026
- Didi enforcement notice
- Hainan negative list — Xinhua and Hainan Department of Commerce
- First EU-China mechanism meeting and second meeting
China data transfer planning
Turn systems, datasets and thresholds into an implementation sequence.
We map transfers, screen important data, compare routes and test Hainan negative-list fit, producing a work plan for authority and provider discussions.
Discuss a China data transfer planYou can also send us your system map and China operating plan or schedule a 30-minute consultation.
