China - Outbound Data Security Measures (2022)
Measures for the Security Assessment of Outbound Data Transfers
出境数据安全评估措施
China
RAI-CN-NA-SAMODXX-2022The Measures for the Security Assessment of Outbound Data Transfers ("Data Outbound Security Assessment Measures") issued by the Cyberspace Administration of China (CAC) specify when and how data processors must assess the security of transferring important data and personal information abroad. The Measures set procedural requirements for self-assessment, provincial reporting, national assessment, mitigation, recordkeeping and continuous supervision to protect national security, public interest and personal rights while enabling lawful cross-border data flows.
Summary
Read full text ↗Plain English
Overview
The "Measures for the Security Assessment of Outbound Data Transfers" (数据出境安全评估办法) were promulgated by the Cyberspace Administration of China (CAC) and published in the Government Gazette on 7 July 2022. They took effect on 1 September 2022 and implement cross-border data transfer assessment requirements set out in the Personal Information Protection Law, the Data Security Law and the Cybersecurity Law. The Measures set out when data processors must perform security assessments for outbound transfers of important data and personal information, establish a process of self-assessment followed (where required) by provincial filing and national assessment, and define supervisory, remedial and sanctioning mechanisms. For the official promulgation and full text, see the Government Gazette publication and the CAC commentary and guidance pages including the CAC "expert interpretation" materials and the CAC-issued application guide.
Definitions
Key definitions in the Measures align with existing Chinese statutes and administrative interpretations. "Data processor" refers to an entity that collects and processes data during operations inside China. "Important data" is defined as data which, if tampered with, leaked or illegally obtained/used, may endanger national security, economic operation, social stability, public health or safety. "Providing data to overseas" includes transfer, storage, remote access, query, download or other forms of enabling overseas entities or individuals to obtain data. The Measures also reference thresholds for personal information transfer that trigger assessment obligations under the PIPL and other CAC rules.
Governance and Institutional Framework
The Measures place the Cyberspace Administration of China at the center of the assessment and supervision regime, with provincial-level CAC authorities handling intake and initial processing of assessment applications and the national CAC responsible for decisions on formal security assessments and corrective actions. Sectoral ministries (e.g., Ministry of Industry and Information Technology, National Health Commission) coordinate where sector-specific laws or national security concerns are implicated. The CAC has published explanatory materials and implementation guides to assist data processors; see the CAC site and the Government Gazette notice for the formal legal text and explanatory releases. Institutional roles include intake/filing by provincial CACs, technical review and on-site verification by national CAC teams, and engagement with other ministries for matters implicating specific national interests.
Key Focus Areas
The Measures concentrate on (1) defining the scope of transfers that require assessment (important data; personal information when specified thresholds are met; remote access by overseas parties), (2) a two-stage process combining risk self-assessment and, where applicable, formal security assessment by the national CAC, (3) mandatory documentation and templates for submissions (assessment applications, risk self-assessment reports, contractual and technical safeguards), (4) requirements that data processors take and document technical and organizational measures to protect data (classification, encryption, segregation, access controls, logging, incident response), (5) mandatory contractual obligations with overseas recipients (scope-limited use, no further transfer without consent, security obligations, supervision/cooperation provisions), (6) ongoing supervision, periodic reporting and record-keeping, and (7) remedial timelines and rectification requirements for non-compliant transfers. The Measures also emphasize protection of personal rights and interests and preservation of national security and public interest when assessing outbound transfers.
Implementation Framework
Operationally, data processors must: (a) classify data and identify whether the data falls into "important data" or constitutes personal information subject to threshold-based review; (b) conduct an internal risk self-assessment using the CAC-provided templates; (c) where the Measures require, submit an application through the provincial CAC to the national CAC with supporting documents and the self-assessment report; (d) respond to national CAC requests for supplementary information or on-site checks; (e) undertake remediation and implement the required safeguards before continuing transfers; and (f) establish continuous monitoring, recordkeeping and reporting mechanisms. The CAC has provided a submission guide and templates to standardize materials and accelerate review processes.
Monitoring and Evaluation
Monitoring is performed by provincial CAC offices (initial intake, advisory review) and the national CAC (formal assessment). The Measures require data processors to keep records of outbound transfers and assessments, to promptly report security incidents relating to outbound data and to cooperate with regulator inquiries and inspections. The national CAC may require periodic re-assessment or supervision where risk factors change. Performance metrics used in monitoring include completeness of documentation, effectiveness of technical controls, remedial action timeliness and incident history. The CAC's post-assessment oversight includes the authority to order cessation of outbound transfers that pose unacceptable risk.
Penalties, Liability, and Appeals
Sanctions for non-compliance are implemented pursuant to the Cybersecurity Law, the Data Security Law and the Personal Information Protection Law. The Measures themselves state that violations will be handled under those statutory frameworks and, where criminal conduct is established, criminal liability will be pursued. Administrative remedies can include fines, orders to suspend or terminate data export activities, revocation of permits or qualifications, public disclosure of violations and other administrative enforcement actions. Affected entities retain rights under administrative law to seek administrative reconsideration or to bring administrative litigation against enforcement actions where permitted by law.
Relationship to Other Instruments
The Measures implement and operationalize cross-border transfer rules in the PIPL (notably provisions on designated processors and transfer conditions), the DSL (important data protection and export restrictions) and the Cybersecurity Law (assessments for critical information infrastructure operators). They also work alongside CAC-issued guidance documents such as the "Data Outbound Security Assessment Application Guide (First Edition)" and sector-specific rules (e.g., financial, healthcare) and follow-up measures addressing remote access, cloud services and supply-chain security. Entities must assess obligations under all applicable instruments when planning outbound transfers.
International Alignment
While China's Measures are domestically focused and emphasize national security and data sovereignty, they reflect global regulatory themes: risk assessment prior to data export, contractual and technical safeguards, and supervisory oversight. The Measures share procedural similarities with adequacy assessments, standard contractual clauses and transfer impact assessments used in other jurisdictions, but differ in centralization (strong regulator-led assessment) and in emphasizing national-security-related "important data" categories. The Measures may interact with international frameworks and cross-border contracts, and organizations engaging in multinational operations should map CAC requirements onto international compliance obligations.
Implementation Timeline
| Event | Date |
|---|---|
| Adopted by national CAC office meeting | 2022-05-19 |
| Promulgated / published in Government Gazette | 2022-07-07 |
| Entry into force | 2022-09-01 |
| Deadline for rectification of pre-existing transfers | 2023-03-01 (six months after entry into force) |
Compliance Checklist
| Action | Status/Notes |
|---|---|
| Classify data and identify "important data" | Required — document classification rationale |
| Perform internal risk self-assessment using CAC template | Required before submission |
| Determine whether national CAC assessment is required | If transfer involves important data or reaches PIPL thresholds |
| Submit application to provincial CAC and national CAC as required | Include templates, contracts, technical measures |
| Implement contractual and technical safeguards (encryption, access control) | Mandatory and evidence must be provided |
| Maintain records and be ready for on-site inspection | Records must be retained per regulator guidance |
| Report incidents and cooperate with regulators | Timely reporting required |
Sources and References
| Source | Type |
|---|---|
| Data Outbound Security Assessment Measures (国家互联网信息办公室令 第11号) (full text) | Primary Source |
| CAC expert interpretation and commentary on data outbound security risks | Primary Source (regulator guidance) |
China's Security Assessment Measures for Outbound Data Transfers require companies operating in China to obtain government approval before transferring certain data outside the country. This regulation applies to any "data processor" in China – essentially, any entity collecting or processing data – that plans to send "important data" or significant volumes of personal information abroad. Important data is broadly defined as information that, if compromised, could endanger national security, economic operations, social stability, or public health and safety.
Companies must first conduct a thorough internal risk self-assessment of their proposed data transfer. For transfers involving important data, or personal information exceeding specific thresholds (as defined by other Chinese laws), they must then apply for a formal security assessment from the Cyberspace Administration of China (CAC). This process involves submitting detailed documentation, including risk reports, contractual agreements with overseas recipients, and evidence of technical and organizational safeguards. Key obligations include: - Ensuring overseas recipients commit to limited data use and no further unauthorized transfers. - Implementing robust technical measures like encryption, access controls, and logging. - Maintaining continuous monitoring, record-keeping, and incident reporting.
The Measures took effect on September 1, 2022, with a grace period until March 1, 2023, for pre-existing transfers to come into compliance. Non-compliance carries significant penalties, including substantial fines, orders to suspend or terminate data export activities, revocation of permits, and potential criminal liability for severe violations.
A critical practical pitfall for businesses is the expansive definition of "providing data to overseas." This isn't just about physically sending data; it also covers remote access, storage, querying, or downloading by overseas entities or individuals. This means even allowing an overseas team to access a database hosted in China could trigger assessment requirements. Companies must also proactively classify their data to identify what constitutes "important data," a category that can be subject to interpretation by authorities.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 13 marked completePlain-English obligations under China - Outbound Data Security Measures (2022). Not legal advice — verify against the official text before relying on it.
- #1Critical⏰ Before any outbound data transfer
Applies to: Data processors operating in China.
“classify data and identify whether the data falls into "important data" or constitutes personal information subject to threshold-based review”
- #2Critical⏰ Before any outbound data transfer requiring assessment
Applies to: Data processors planning outbound data transfers.
“conduct an internal risk self-assessment using the CAC-provided templates”
- #3Critical⏰ Before submitting an application
Applies to: Data processors after self-assessment.
“defining the scope of transfers that require assessment (important data; personal information when specified thresholds are met)”
- #4Critical⏰ Before initiating the outbound data transfer
Applies to: Data processors whose transfers require national assessment.
“submit an application through the provincial CAC to the national CAC with supporting documents and the self-assessment report”
- #5Critical⏰ Before initiating the outbound data transfer
Applies to: Data processors conducting outbound data transfers.
“data processors take and document technical and organizational measures to protect data (classification, encryption, segregation, access controls, logging, incident response)”
- #6Critical⏰ Before any outbound data transfer contract is signed
Applies to: Data processors transferring data to overseas recipients.
“mandatory contractual obligations with overseas recipients (scope-limited use, no further transfer without consent, security obligations, supervision/cooperation provisions)”
- #7Critical⏰ Ongoing
Applies to: Data processors conducting outbound data transfers.
“The Measures require data processors to keep records of outbound transfers and assessments”
- #8Critical⏰ Promptly after discovery
Applies to: Data processors conducting outbound data transfers.
“to promptly report security incidents relating to outbound data and to cooperate with regulator inquiries and inspections”
- #9Critical⏰ Upon request
Applies to: Data processors conducting outbound data transfers.
“to cooperate with regulator inquiries and inspections”
- #10Critical⏰ Before continuing transfers; by 2023-03-01 for pre-existing transfers
Applies to: Data processors with non-compliant outbound transfers.
“undertake remediation and implement the required safeguards before continuing transfers”
- #11Important⏰ Ongoing
Applies to: Data processors conducting outbound data transfers.
“establish continuous monitoring, recordkeeping and reporting mechanisms”
- #12Important⏰ Upon request
Applies to: Data processors undergoing security assessment.
“respond to national CAC requests for supplementary information or on-site checks”
- #13Important⏰ Upon CAC request
Applies to: Data processors with ongoing outbound data transfers.
“The national CAC may require periodic re-assessment or supervision where risk factors change.”
Related Regulations
Data Security Law of the People's Republic of China
China90% similar
Personal Information Protection Law of the People's Republic of China (PIPL)
China90% similar
Regulations on Network Data Security Management (网络数据安全管理条例)
China89% similar
Cybersecurity Law of the People's Republic of China
China89% similar
Interim Measures for the Administration of Generative AI Services (Generative AI Services Management Interim Measures)
China85% similar
© Regulations.AI — created on 13-Jun-2026