BRICS Digital TransformationPublic Service Platform
Knowledge · Standards · Practice
Return to Overseas Guide

Cross-border production and personnel data

Do transfers of data from China to an overseas plant require outbound-data procedures?

Applies toData transferred from China, or accessed remotely from outside China

Key points

Cross-border manufacturing data containing neither personal information nor important data is exempt from security assessment, standard-contract and certification procedures. Employee or customer data needs a separate assessment.

01

Data-flow identification

Overseas access to data in a Chinese system can be an outbound data activity; server location alone does not settle the question.

02

Data classification

Distinguish ordinary production data, personal information, sensitive personal information and important data before deciding the route.

03

Exemptions and filing requirements

Necessary cross-border HR management has a conditional exemption. Other personal data follows rules based on operator status, annual outbound headcount and sensitivity.

Outbound-data exemptions and filing requirements

Count unique people cumulatively from 1 January. Exclude scenarios under Articles 3, 4, 5(1)(1–3) and 6. Critical information infrastructure operators (CIIOs) are identified and notified by their competent authorities.

ScenarioApplicable procedureConditions and basis
Manufacturing and similar activity data containing no personal or important dataExempt from assessment, standard contract and certificationArticle 3. The exemption concerns these three procedures; data-security duties remain.
Employee data strictly necessary for cross-border HR management, excluding important dataExempt from the three procedures if conditions are metArticle 5: management must be based on lawfully established labour rules and lawfully concluded collective contracts, with necessity assessed. ID, passport and bank-account data are not automatically necessary.
No applicable exemption; non-CIIO; no important data; fewer than 100,000 people’s non-sensitive personal information and no sensitive personal informationExempt from the three proceduresArticle 5(1)(4); count people since 1 January of the current year.
No applicable exemption; non-CIIO; no important data; 100,000–under 1 million people’s non-sensitive information, or some sensitive personal information covering fewer than 10,000 peopleStandard contract or personal-information outbound certificationArticle 8; assessment takes precedence if its threshold is also met.
No applicable exemption; important data, CIIO personal data, or non-CIIO transfers reaching 1 million non-sensitive / 10,000 sensitive data subjectsSubmit for CAC security assessment through the provincial cyberspace authorityArticle 7. Identify important data under the relevant authority’s designation and published rules, not simply a dataset’s name.

Related policies and standards