China Clarifies Thresholds and Rules for Cross-Border Data Certification
Regulators specify volume limits, anti-circumvention rules, and three designated certification bodies for outbound personal data transfers.

The Brief
Why it matters
China context
Editor's View
What to watch
- Application processing times and detailed evaluation criteria issued by the three designated certification institutions
- Regulatory enforcement actions against corporate data splitting or restructuring intended to evade security assessments
- Potential expansion of the registry of qualified professional certification bodies beyond the initial three institutions
Key Takeaways
- 1Certification applies to non-CIIOs transferring personal data of 100,000 to under one million individuals, or sensitive data of under 10,000 individuals, since January 1 of the calendar year.
- 2Data handlers are strictly barred from splitting data volumes to bypass mandatory regulatory security assessments.
- 3Organizations exceeding one million individuals or 10,000 sensitive records must apply for a security assessment, but regulators will reference prior certification records during review.
- 4Three institutions are formally authorized to handle certification applications: the China Cybersecurity Review and Market Regulation Big Data Center, the CAC Data and Technical Security Center, and B
Sources
- 数据出境安全管理政策法规问答(2026年9月) — Cyberspace Administration of China · 9/13/2026