Policy & RegulationAnalysis

China Clarifies Thresholds and Rules for Cross-Border Data Certification

Regulators specify volume limits, anti-circumvention rules, and three designated certification bodies for outbound personal data transfers.

Share
Individual using a VPN application on a laptop at a desk in a modern office setting.
Photo by Dan Nelson on Pexels

The Brief

The Cyberspace Administration of China has released official guidance clarifying the scope and procedures for obtaining personal information cross-border transfer certifications. Non-critical information infrastructure operators transferring personal data of between 100,000 and under one million individuals, or sensitive personal data of fewer than 10,000 individuals, can use certification to fulfill outbound transfer obligations. The regulator explicitly prohibited splitting data volumes to avoid mandatory security assessments, while outlining transition protocols if volume thresholds are crossed and naming three filed professional certification bodies.

Why it matters

The guidance provides concrete compliance parameters for multinational and domestic companies transferring personal data abroad from mainland China. By defining the operational boundary between certification and mandatory regulatory security assessments, Beijing offers businesses greater procedural predictability while signaling strict scrutiny against volume manipulation.

China context

Under China's Personal Information Protection Law and cross-border data transfer framework, organizations rely on three main outbound legal pathways: government security assessment, standard contracts, or third-party certification. Recent regulatory adjustments aim to streamline everyday corporate data flows while reserving formal state security reviews for large-scale or high-risk data exports.

Editor's View

EDITOR'S VIEW — Analysis and inference, not factual reporting. The clarification reflects the Cyberspace Administration of China's effort to operationalize the certification mechanism, which has historically seen slower enterprise adoption than standard contracts. By allowing voluntary certification to prove baseline compliance with national standards like GB/T 35273 and GB/T 46068, regulators are encouraging institutionalized data governance. Crucially, the commitment to consider prior certification during subsequent security assessments creates an incentive for growing companies to pursue early certification without fearing duplicative regulatory friction later.

What to watch

  • Application processing times and detailed evaluation criteria issued by the three designated certification institutions
  • Regulatory enforcement actions against corporate data splitting or restructuring intended to evade security assessments
  • Potential expansion of the registry of qualified professional certification bodies beyond the initial three institutions

Key Takeaways

  • 1Certification applies to non-CIIOs transferring personal data of 100,000 to under one million individuals, or sensitive data of under 10,000 individuals, since January 1 of the calendar year.
  • 2Data handlers are strictly barred from splitting data volumes to bypass mandatory regulatory security assessments.
  • 3Organizations exceeding one million individuals or 10,000 sensitive records must apply for a security assessment, but regulators will reference prior certification records during review.
  • 4Three institutions are formally authorized to handle certification applications: the China Cybersecurity Review and Market Regulation Big Data Center, the CAC Data and Technical Security Center, and B
The Cyberspace Administration of China has issued targeted regulatory guidance clarifying how organizations can utilize personal information cross-border transfer certification to meet outbound data compliance obligations. According to the regulatory Q&A, non-critical information infrastructure operators that cumulatively export the personal information of between 100,000 and under one million individuals, or the sensitive personal information of fewer than 10,000 individuals, within a calendar year may rely on the certification pathway, provided the data does not contain critical or important data. Handlers outside these exact brackets may also voluntarily apply for certification regardless of processing volume to demonstrate compliance with national standards GB/T 35273 and GB/T 46068. The regulator strictly prohibited entities from artificially splitting data volumes or engineering quotas to avoid mandatory government security assessments. If an organization that previously obtained certification subsequently crosses the threshold by transferring personal information of one million or more individuals, or sensitive data of 10,000 or more individuals, it must immediately submit to a formal cross-border data security assessment through its provincial cyberspace office. However, regulators noted that existing certification documentation can be submitted alongside the assessment filing, and cyberspace authorities will reference prior certification findings when reviewing data protection safeguards. Before submitting an application under the cross-border certification measures, handlers must fulfill preliminary statutory requirements, including notifying individuals, securing separate consent where required, and completing a personal information protection impact assessment. The regulator confirmed three professional institutions currently registered to accept cross-border certification applications: the China Cybersecurity Review and Market Regulation Big Data Center, the CAC Data and Technical Security Center, and Beijing CESI Certification Co., Ltd.

Sources

  1. 数据出境安全管理政策法规问答(2026年9月) — Cyberspace Administration of China · 9/13/2026