China - Outbound Data Security Measures (2022)

Measures for the Security Assessment of Outbound Data Transfers

出境数据安全评估措施

China

RAI-CN-NA-SAMODXX-2022
Effective: September 1, 2022
In Force(In Force)
RegulationData Protection and PrivacyRisk Management
Export PDF

The Measures for the Security Assessment of Outbound Data Transfers ("Data Outbound Security Assessment Measures") issued by the Cyberspace Administration of China (CAC) specify when and how data processors must assess the security of transferring important data and personal information abroad. The Measures set procedural requirements for self-assessment, provincial reporting, national assessment, mitigation, recordkeeping and continuous supervision to protect national security, public interest and personal rights while enabling lawful cross-border data flows.

Overview

The "Measures for the Security Assessment of Outbound Data Transfers" (数据出境安全评估办法) were promulgated by the Cyberspace Administration of China (CAC) and published in the Government Gazette on 7 July 2022. They took effect on 1 September 2022 and implement cross-border data transfer assessment requirements set out in the Personal Information Protection Law, the Data Security Law and the Cybersecurity Law. The Measures set out when data processors must perform security assessments for outbound transfers of important data and personal information, establish a process of self-assessment followed (where required) by provincial filing and national assessment, and define supervisory, remedial and sanctioning mechanisms. For the official promulgation and full text, see the Government Gazette publication and the CAC commentary and guidance pages including the CAC "expert interpretation" materials and the CAC-issued application guide.

Definitions

Key definitions in the Measures align with existing Chinese statutes and administrative interpretations. "Data processor" refers to an entity that collects and processes data during operations inside China. "Important data" is defined as data which, if tampered with, leaked or illegally obtained/used, may endanger national security, economic operation, social stability, public health or safety. "Providing data to overseas" includes transfer, storage, remote access, query, download or other forms of enabling overseas entities or individuals to obtain data. The Measures also reference thresholds for personal information transfer that trigger assessment obligations under the PIPL and other CAC rules.

Governance and Institutional Framework

The Measures place the Cyberspace Administration of China at the center of the assessment and supervision regime, with provincial-level CAC authorities handling intake and initial processing of assessment applications and the national CAC responsible for decisions on formal security assessments and corrective actions. Sectoral ministries (e.g., Ministry of Industry and Information Technology, National Health Commission) coordinate where sector-specific laws or national security concerns are implicated. The CAC has published explanatory materials and implementation guides to assist data processors; see the CAC site and the Government Gazette notice for the formal legal text and explanatory releases. Institutional roles include intake/filing by provincial CACs, technical review and on-site verification by national CAC teams, and engagement with other ministries for matters implicating specific national interests.

Key Focus Areas

The Measures concentrate on (1) defining the scope of transfers that require assessment (important data; personal information when specified thresholds are met; remote access by overseas parties), (2) a two-stage process combining risk self-assessment and, where applicable, formal security assessment by the national CAC, (3) mandatory documentation and templates for submissions (assessment applications, risk self-assessment reports, contractual and technical safeguards), (4) requirements that data processors take and document technical and organizational measures to protect data (classification, encryption, segregation, access controls, logging, incident response), (5) mandatory contractual obligations with overseas recipients (scope-limited use, no further transfer without consent, security obligations, supervision/cooperation provisions), (6) ongoing supervision, periodic reporting and record-keeping, and (7) remedial timelines and rectification requirements for non-compliant transfers. The Measures also emphasize protection of personal rights and interests and preservation of national security and public interest when assessing outbound transfers.

Implementation Framework

Operationally, data processors must: (a) classify data and identify whether the data falls into "important data" or constitutes personal information subject to threshold-based review; (b) conduct an internal risk self-assessment using the CAC-provided templates; (c) where the Measures require, submit an application through the provincial CAC to the national CAC with supporting documents and the self-assessment report; (d) respond to national CAC requests for supplementary information or on-site checks; (e) undertake remediation and implement the required safeguards before continuing transfers; and (f) establish continuous monitoring, recordkeeping and reporting mechanisms. The CAC has provided a submission guide and templates to standardize materials and accelerate review processes.

Monitoring and Evaluation

Monitoring is performed by provincial CAC offices (initial intake, advisory review) and the national CAC (formal assessment). The Measures require data processors to keep records of outbound transfers and assessments, to promptly report security incidents relating to outbound data and to cooperate with regulator inquiries and inspections. The national CAC may require periodic re-assessment or supervision where risk factors change. Performance metrics used in monitoring include completeness of documentation, effectiveness of technical controls, remedial action timeliness and incident history. The CAC's post-assessment oversight includes the authority to order cessation of outbound transfers that pose unacceptable risk.

Penalties, Liability, and Appeals

Sanctions for non-compliance are implemented pursuant to the Cybersecurity Law, the Data Security Law and the Personal Information Protection Law. The Measures themselves state that violations will be handled under those statutory frameworks and, where criminal conduct is established, criminal liability will be pursued. Administrative remedies can include fines, orders to suspend or terminate data export activities, revocation of permits or qualifications, public disclosure of violations and other administrative enforcement actions. Affected entities retain rights under administrative law to seek administrative reconsideration or to bring administrative litigation against enforcement actions where permitted by law.

Relationship to Other Instruments

The Measures implement and operationalize cross-border transfer rules in the PIPL (notably provisions on designated processors and transfer conditions), the DSL (important data protection and export restrictions) and the Cybersecurity Law (assessments for critical information infrastructure operators). They also work alongside CAC-issued guidance documents such as the "Data Outbound Security Assessment Application Guide (First Edition)" and sector-specific rules (e.g., financial, healthcare) and follow-up measures addressing remote access, cloud services and supply-chain security. Entities must assess obligations under all applicable instruments when planning outbound transfers.

International Alignment

While China's Measures are domestically focused and emphasize national security and data sovereignty, they reflect global regulatory themes: risk assessment prior to data export, contractual and technical safeguards, and supervisory oversight. The Measures share procedural similarities with adequacy assessments, standard contractual clauses and transfer impact assessments used in other jurisdictions, but differ in centralization (strong regulator-led assessment) and in emphasizing national-security-related "important data" categories. The Measures may interact with international frameworks and cross-border contracts, and organizations engaging in multinational operations should map CAC requirements onto international compliance obligations.

Implementation Timeline

EventDate
Adopted by national CAC office meeting2022-05-19
Promulgated / published in Government Gazette2022-07-07
Entry into force2022-09-01
Deadline for rectification of pre-existing transfers2023-03-01 (six months after entry into force)

Compliance Checklist

ActionStatus/Notes
Classify data and identify "important data"Required — document classification rationale
Perform internal risk self-assessment using CAC templateRequired before submission
Determine whether national CAC assessment is requiredIf transfer involves important data or reaches PIPL thresholds
Submit application to provincial CAC and national CAC as requiredInclude templates, contracts, technical measures
Implement contractual and technical safeguards (encryption, access control)Mandatory and evidence must be provided
Maintain records and be ready for on-site inspectionRecords must be retained per regulator guidance
Report incidents and cooperate with regulatorsTimely reporting required

Sources and References

SourceType
Data Outbound Security Assessment Measures (国家互联网信息办公室令 第11号) (full text)Primary Source
CAC expert interpretation and commentary on data outbound security risksPrimary Source (regulator guidance)
Plain English

China's Security Assessment Measures for Outbound Data Transfers require companies operating in China to obtain government approval before transferring certain data outside the country. This regulation applies to any "data processor" in China – essentially, any entity collecting or processing data – that plans to send "important data" or significant volumes of personal information abroad. Important data is broadly defined as information that, if compromised, could endanger national security, economic operations, social stability, or public health and safety.

Companies must first conduct a thorough internal risk self-assessment of their proposed data transfer. For transfers involving important data, or personal information exceeding specific thresholds (as defined by other Chinese laws), they must then apply for a formal security assessment from the Cyberspace Administration of China (CAC). This process involves submitting detailed documentation, including risk reports, contractual agreements with overseas recipients, and evidence of technical and organizational safeguards. Key obligations include: - Ensuring overseas recipients commit to limited data use and no further unauthorized transfers. - Implementing robust technical measures like encryption, access controls, and logging. - Maintaining continuous monitoring, record-keeping, and incident reporting.

The Measures took effect on September 1, 2022, with a grace period until March 1, 2023, for pre-existing transfers to come into compliance. Non-compliance carries significant penalties, including substantial fines, orders to suspend or terminate data export activities, revocation of permits, and potential criminal liability for severe violations.

A critical practical pitfall for businesses is the expansive definition of "providing data to overseas." This isn't just about physically sending data; it also covers remote access, storage, querying, or downloading by overseas entities or individuals. This means even allowing an overseas team to access a database hosted in China could trigger assessment requirements. Companies must also proactively classify their data to identify what constitutes "important data," a category that can be subject to interpretation by authorities.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 13 marked complete

Plain-English obligations under China - Outbound Data Security Measures (2022). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalBefore any outbound data transfer

    Applies to: Data processors operating in China.

    classify data and identify whether the data falls into "important data" or constitutes personal information subject to threshold-based review
  2. #2CriticalBefore any outbound data transfer requiring assessment

    Applies to: Data processors planning outbound data transfers.

    conduct an internal risk self-assessment using the CAC-provided templates
  3. #3CriticalBefore submitting an application

    Applies to: Data processors after self-assessment.

    defining the scope of transfers that require assessment (important data; personal information when specified thresholds are met)
  4. #4CriticalBefore initiating the outbound data transfer

    Applies to: Data processors whose transfers require national assessment.

    submit an application through the provincial CAC to the national CAC with supporting documents and the self-assessment report
  5. #5CriticalBefore initiating the outbound data transfer

    Applies to: Data processors conducting outbound data transfers.

    data processors take and document technical and organizational measures to protect data (classification, encryption, segregation, access controls, logging, incident response)
  6. #6CriticalBefore any outbound data transfer contract is signed

    Applies to: Data processors transferring data to overseas recipients.

    mandatory contractual obligations with overseas recipients (scope-limited use, no further transfer without consent, security obligations, supervision/cooperation provisions)
  7. #7CriticalOngoing

    Applies to: Data processors conducting outbound data transfers.

    The Measures require data processors to keep records of outbound transfers and assessments
  8. #8CriticalPromptly after discovery

    Applies to: Data processors conducting outbound data transfers.

    to promptly report security incidents relating to outbound data and to cooperate with regulator inquiries and inspections
  9. #9CriticalUpon request

    Applies to: Data processors conducting outbound data transfers.

    to cooperate with regulator inquiries and inspections
  10. #10CriticalBefore continuing transfers; by 2023-03-01 for pre-existing transfers

    Applies to: Data processors with non-compliant outbound transfers.

    undertake remediation and implement the required safeguards before continuing transfers
  11. #11ImportantOngoing

    Applies to: Data processors conducting outbound data transfers.

    establish continuous monitoring, recordkeeping and reporting mechanisms
  12. #12ImportantUpon request

    Applies to: Data processors undergoing security assessment.

    respond to national CAC requests for supplementary information or on-site checks
  13. #13ImportantUpon CAC request

    Applies to: Data processors with ongoing outbound data transfers.

    The national CAC may require periodic re-assessment or supervision where risk factors change.

© Regulations.AI — created on 13-Jun-2026