Hainan's Cross-Border Data Negative List: What Digital Businesses Can Move Freely
Hainan FTP uses an industry-specific data export negative list covering 5 sectors and 14 scenarios. Learn what the framework means for ASEAN SaaS, e-commerce and AI businesses.
August 5, 2026 · Hainan Setup Editorial Team · 10 min read
If a business depends on cross-border data—SaaS telemetry, e-commerce transactions, customer support records or AI workloads—Hainan offers a policy framework worth examining. The value is not that “anything can be sent anywhere.” The value is greater clarity about which data scenarios remain controlled and when specified national data-export procedures may be waived.
On 20 February 2025, Hainan authorities published the Hainan Free Trade Port Data Export Management List (Negative List) (2024 Edition). The Cyberspace Administration of China’s official index records the Hainan notice and also shows that several other regions have since issued their own lists. Hainan should therefore be described as an early, specialized model—not the only place in China with a negative list.
The Hainan list covers 14 business scenarios across five locally important fields: deep-sea technology, seed breeding, commercial aerospace, tourism and duty-free retail. Its field-level approach helps a company determine whether planned data may fall inside an important-data category rather than treating every operational record as equally risky.
This article summarizes publicly available policy documents. Specific data compliance requirements depend on your industry, data types, volumes, purpose and recipients. Consult qualified counsel before making data-transfer decisions.
What is a data-export negative list, and why does it matter?
China’s national framework uses several tools for cross-border data transfers. Depending on the data and volume, a processor may need a government security assessment, a personal-information protection certification or a filed standard contract. National rules also provide exemptions for defined scenarios.
A free-trade-zone negative list adds a more precise industry lens. Hainan identifies important-data scenarios at a granular level so that an enterprise can compare the fields it handles against an articulated list. For transfers covered by the Hainan framework and outside the negative list, the relevant rules may exempt the enterprise from the three procedural routes above.
That statement has four important limits:
- The entity and activity must fall within the applicable Hainan framework. A server address or Hainan registration alone is not enough.
- “Outside the list” does not mean “outside the law.” Cybersecurity, data security, personal-information, sector and confidentiality duties remain.
- The company must know what it holds. A business cannot rely on an exemption if it has not classified its data and identified personal information, sensitive personal information and potential important data.
- Regulated services need separate permissions. Telecom, cloud, IDC, CDN, finance, healthcare and other activities can involve licensing or access rules independent of data-export procedure. A mainland-hosted website may also need a separate China ICP license assessment.
Operationally, the framework can reduce uncertainty. Instead of assuming a six-month process or promising instant transfer, a company can screen its exact fields, document why a route applies and seek clarification before building the system.
The five covered fields: deep sea, seeds, aerospace, tourism and duty-free
The 14 scenarios reflect Hainan’s industrial profile. They are not a list of five industries that are “closed”; they identify data within those sectors that may require closer control.
Deep-sea technology
Ocean surveys, scientific observation, seabed resources and equipment operations can generate location, resource and research data with national-security or public-interest implications. A marine technology company should separate ordinary corporate records from technical survey, geographic and strategic-resource datasets.
Seed breeding
Germplasm, breeding materials, genetic resources and experimental data can have strategic value. A seed company should not assume that a research collaboration permits raw breeding datasets or biological resources to be synchronized overseas.
Commercial aerospace
Launch operations, tracking, telemetry, remote sensing and satellite services may touch controlled technical or geographic information. A SaaS vendor supporting an aerospace customer should classify customer content, not merely its own application logs.
Tourism
Tourism platforms process passports, itineraries, payments, accommodation and location information. The sector’s risk is often personal-information intensive. A hotel group or booking platform needs purpose limitation, notice, recipient controls and security even where a transfer is outside an important-data scenario.
Duty-free retail
Duty-free operations combine identity, eligibility, transaction and consumer-behaviour data. A retailer should distinguish aggregated product analytics from identifiable purchase and travel records.
For businesses outside these five fields, the Hainan list may still be useful, but it does not create an automatic “free transfer” conclusion. National law and any other sector rules remain the starting point.
What may move with a lighter procedure?
Hainan’s international data-center legislation provides the clearest statutory wording. The Provisions on the Development of International Data Centers in the Hainan Free Trade Port were adopted on 29 November 2024 and took effect on 1 December 2024. The published text and official explanation state that qualifying international data-center business may be exempt from a data-export security assessment, personal-information standard contract and personal-information protection certification in two situations:
- overseas-collected and overseas-generated data is processed without introducing domestic personal information or important data; or
- the operator provides data outside Hainan’s data-export negative list to an overseas recipient.
The statute defines international data-center business narrowly: an enterprise registered with service facilities in Hainan uses an approved cross-border data channel to provide storage, processing, trading or other international data services only to overseas customers. It also requires legal compliance, cybersecurity, data security and personal-information protection.
This is more accurate than saying “no security assessment, no contract, transfer directly” for every Hainan company. The procedural exemption must be matched to its legal scope.
Consider three screening examples:
Singapore SaaS company. Product-performance logs may be synchronized with Singapore if they do not contain important data or unlawfully exported personal information and the transfer route fits. The company should minimize identifiers, separate customer content and document the recipient’s role. Our Singapore investor guide helps map the entity structure around the operating model.
Malaysian e-commerce group. Order records, addresses and support messages contain personal information. A Hainan operation cannot simply send the complete database to Kuala Lumpur because e-commerce is not one of the five named fields. The company still needs a lawful purpose, notice or consent where required, minimization, security and the correct export route. Review the wider China-entry structure in the Malaysia guide.
Thai AI startup. Training data should be screened for source, rights, personal information, confidential customer content and important data. Model weights or tokens are not automatically risk-free merely because raw records are transformed. Separate datasets and conduct a re-identification and leakage assessment before cross-border use.
The red lines that still apply
A practical data map should mark at least five high-risk categories:
- state secrets or data whose export is prohibited by law;
- important data requiring a security assessment where that assessment has not been completed;
- personal information transferred without satisfying the applicable Personal Information Protection Law conditions;
- sector-controlled information, such as regulated health, finance, geographic, research or telecom data;
- any data whose transfer would endanger national security, public interests or another party’s lawful rights.
Trade secrets and intellectual property are not automatically prohibited from leaving China, but contracts, confidentiality, employee authority, export-control rules and customer restrictions still matter. A company needs rights to use and disclose the material.
Create a field-level register containing data owner, source, subject, sensitivity, system, destination, purpose, frequency, volume, legal basis, retention and deletion. Reassess the route when the product or customer changes. “We are a SaaS company” is not a data classification.
Infrastructure behind the framework
Hainan’s policy is being paired with physical infrastructure. The ALC submarine cable reached Hong Kong in May 2026. Hainan’s official English portal reported that the landing station supports both ALC and SEA-H2X systems, strengthening connectivity toward Southeast Asia. Network availability, latency, redundancy and commercial service dates should still be confirmed with the operator.
Haikou has also been approved for full-service international communications gateways operated by the major carriers. An official provincial briefing described Hainan as the fourth province after Beijing, Shanghai and Guangdong to host gateways from all three national operators.
Compute capacity is expanding. Hainan’s 2026 government work report states that the world’s first commercial submarine data center and submarine intelligent-computing center had entered operation, while annual revenue of the core digital-economy industries exceeded RMB 260 billion. The official 2026 report is a stronger current reference than an unsupported “over RMB 100 billion” estimate.
The 2024 international data-center provisions support trusted domestic or overseas cloud services, computing chips and AI models, while requiring approved channels and security controls. Infrastructure improves feasibility; it does not decide a company’s legal route.
Practical implications for ASEAN digital businesses
SaaS and enterprise software
A Singapore or Malaysian SaaS provider can evaluate Hainan as a China delivery and support base. The architecture should separate platform telemetry, customer content, employee data and regulated-sector records. Data localization, export and telecom analysis must follow the exact service.
Cross-border e-commerce
Real-time inventory and product analytics can be easier to structure than identifiable order histories. Tokenize or aggregate analytics where possible and keep the minimum customer fields required for fulfilment and support.
AI and data services
Hainan may support international processing and “data comes in, service goes out” models. A provider still needs provenance, licensing, security testing, model governance and controls against memorization or re-identification. “Token export” should be a technical design, not a compliance slogan.
Data-intensive operations
Submarine connectivity and new compute capacity may improve cost or resilience. Compare carrier availability, service-level terms, power, disaster recovery, cybersecurity and permitted business scope before selecting a site. Our office and workspace service can help align premises with the team and technical footprint.
How to set up a data-compliant Hainan operation
- Define the service and regulated role. Identify customers, systems, data, telecom functions and where delivery occurs.
- Choose the entity and scope. Use the WFOE registration guide and company registration service to align the licence with the genuine activity.
- Classify fields before transfer. Map important data, personal information, sensitive personal information, confidential information and overseas-origin data.
- Select the transfer route. Determine whether a national exemption, Hainan negative-list route, international data-center provision, assessment, standard contract or certification applies.
- Build operational evidence. Maintain policies, access controls, logs, contracts, impact assessments, incident response, retention and deletion.
- Separate finance from data permission. An EF account can be discussed with a participating bank for eligible cross-border payments, but it does not authorize data transfer.
- Maintain substance. Real staff, premises, accounts and management support any policy-dependent structure; see the substantive-operation guide.
Eligible digital businesses may separately screen the conditional 15% corporate income tax and equipment-related zero-tariff framework. Neither incentive answers the data-compliance question.
Does the negative list apply to all data or only specific fields?
It is field- and scenario-specific. The transferor must still check national law, its sector, the data and the precise Hainan route.
Do national data-security laws still apply?
Yes. A procedural exemption does not remove cybersecurity, data-security, personal-information or sector obligations.
Can I transfer Chinese users’ personal information to my home country?
Potentially, subject to purpose, necessity, notice, consent or other lawful basis, recipient protection, volume and the applicable export mechanism. Seek qualified advice for the actual dataset.
Is Hainan more open than Singapore?
They are different legal environments. Hainan’s advantage is a more tailored route within China; Singapore remains governed by its own PDPA and transfer rules. A Singapore-headquarters plus Hainan-operating-company model can be useful when both sides have real functions.
What about trade secrets and intellectual property?
They are not automatically free to transfer. Confirm ownership, licences, confidentiality, export controls, contracts and customer restrictions before disclosure.
Related insights
- Hainan EF Account and cross-border settlement
- complete WFOE registration guide
- Hainan’s conditional 15% corporate income tax
If you are building a China–ASEAN digital operation, contact us with the proposed service, data map and locations. We can coordinate the entity, workspace and operating-readiness workstreams while specialist counsel assesses the transfer route.
This article provides general policy information for planning purposes and does not constitute legal or compliance advice. Data-transfer requirements depend on your specific industry, data types and volumes. Consult qualified legal counsel before making cross-border data-transfer decisions.
