Personal information must not be casually transferred overseas; legal conditions and thresholds apply
Transferring personal information of Chinese users to servers abroad constitutes a cross-border data transfer. Simply hosting servers overseas does not mean the data stays within China. There are four approved pathways for such transfers: a security assessment by the Cyberspace Administration, certification by authorized agencies, signing a standard contract, or compliance with other legal provisions. You must also disclose to users who receives their data, what it will be used for, and obtain their explicit consent for this specific purpose.
No cost involved. The simplest solution is to keep user da…
To lawfully provide personal information to overseas entities — whether to foreign companies or foreign server…
No cost involved. The simplest solution is to keep user data within China. If transfer overseas is unavoidable, follow standard contracts or obtain proper certification.
To lawfully provide personal information to overseas entities — whether to foreign companies or foreign servers — at least one of four conditions must be met: passing a security assessment by the Cyberspace Administration; obtaining personal information protection certification; signing a standard contract drafted by the Cyberspace Administration; or meeting other requirements set by laws or administrative regulations. Additionally, you must inform users of the overseas recipient’s name, contact details, processing purpose, methods, and types of data involved, and obtain their separate consent. Threshold limits apply based on cumulative user counts. For most businesses not classified as critical information infrastructure operators, the exemption threshold is “fewer than 100,000 personal records (excluding sensitive information) transferred overseas in a calendar year.” Below this threshold, no assessment, contract, or certification is required. Between 100,000 and 1,000,000 records, a standard contract or certification is mandatory. For over 1,000,000 records, or when sensitive information of more than 10,000 individuals is involved, a formal security assessment is required (effective nationwide since March 2024).
全国人大常委会 (2021). 个人信息保护法(第三十八、三十九、四十条). https://www.spp.gov.cn/spp/fl/202108/t20210820_527244.shtml ; 国家互联网信息办公室 (2024). 促进和规范数据跨境流动规定(网信办令第 16 号,第三、四、五、七、八条). https://www.gov.cn/gongbao/2024/issue_11366/202405/content_6954192.html ; 国家互联网信息办公室 (2022). 数据出境安全评估办法(网信办令第 11 号,第四条). https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm
Open source linkHosting servers overseas does not equate to “data never leaving China.” If a user registers within China and their data is sent to foreign servers, this is still a cross-border transfer. Certain scenarios are exempt from assessment, certification, or standard contracts: cross-border shopping, shipping, or booking flights/hotels, provided these actions are necessary to fulfill a contract involving the user. Note also that user counts are calculated on a cumulative basis starting from January 1 of each year, not as a rolling 12-month period.