Jan Holthuis
Partner | Lawyer
Send me an e-mail
+86 (0)21 61730388
China's cross-border data transfer regime is no longer a paper framework. The three-pathway framework of CAC security assessment, Standard Contract filing, and personal information protection certification has been fully operational since 1 January 2026. Regulators have now shifted their focus decisively from rulemaking to implementation and enforcement. 2026 has been the year of enforcement: a RMB 10 million fine against Ctrip, a landmark case against Dior, and sweeping new rules for both small and giant data processors.
If your business moves personal data out of China — HR files, customer records, app data — here is what changed, and what to do about it.
The Three Routes Out of China
Every cross-border transfer of personal data now runs through one of three gates:
| Pathway | Trigger | Applicability |
| CAC Security Assessment | Critical infrastructure operators; important data exports; PI exports over 1 million people (or sensitive PI over 10,000) | Mandatory |
| SCC Filing or Certification | PI exports of 100,000–1 million people, or sensitive PI under 10,000 | Choose SCC filing or certification |
| Exemptions | Small exports, contract necessity, HR management, emergencies | Notice, consent and PIA duties still apply |
Exemptions are read narrowly — notice, consent and impact-assessment duties never go away.
Three Headlines You Need to Know
1.Resumes are not covered by the HR exemption.
The CAC's 24 July 2026 Q&A caught multinationals off guard: sending a China-based applicant's resume overseas is not HR data, so the HR-management exemption does not apply. If the overseas office has no role in hiring, the transfer is not permitted at all. If it does, only the minimum fields needed may be sent, and you still need a valid transfer mechanism, notice, separate consent, and a PIPIA. Auto-forwarding resumes without that groundwork is now a real enforcement risk.
2. Big platforms get a watchdog.
On 7 August 2026, the CAC published for public comment the Provisions on Personal Information Protection by Large Personal Information Processors (Draft for Comment). These draft rules target processors handling 10 million+ people's data.
Hit the threshold and you must self-report to the CAC, which will publish a public list of designated large processors.
Within six months, designated processors must stand up a supervision committee that is at least two-thirds external members (minimum seven), with real oversight of sensitive data and cross-border transfers.
3. Small processors get a break — large ones get scrutiny.
On 22 July 2026, the CAC and the Ministry of Public Security jointly issued the Provisions on Simplified Measures for Personal Information Protection by Small-Scale Personal Information Handlers, which took effect on 1 September 2026. New rules effective 1 September 2026 give processors handling fewer than 100,000 people's data real relief: simplified notice-and-consent (in some cases, just handing over data after disclosure counts as consent), self-assessment templates instead of full audits and PIPIAs, a more forgiving line on minor first-time slip-ups, and for some, a pass on standard export mechanisms.
However, the baseline protections for sensitive PI and minors' data are expressly preserved, and the simplified audit cycle runs at least once every five years.
4. One breach, one full audit — just ask Dior.
Dior (Shanghai)'s September 2025 penalty followed a May 2025 routine breach that exposed customer data sent to Paris with no transfer mechanism, no notice, no separate consent, and no encryption. Regulators do not stop at the incident; they use it as an entry point to examine the entire data governance framework.
The lesson: regulators do not stop at the breach. Any incident, complaint or inquiry can trigger a full review of your transfer mechanisms, consent records, and impact assessments.
Do not wait for a breach to find out your transfer mechanism does not exist. We help businesses map their China data flows, choose the right transfer route, build PIPIAs that hold up to scrutiny, and respond fast when an incident becomes an investigation.
Follow us!
Subscribe newsletter LinkedIn