Law / China

Provisions on Promoting and Regulating Cross-Border Data Flows

促进和规范数据跨境流动规定, issued by the Cyberspace Administration of China, effective 22 March 2024

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 22 March 2024.

A cross border transfer rule binding public and private bodies.

As of 23 August 2026.

What it requires

  • Confirm which volume tier applies before exporting personal information from China: under 100,000 individuals' non-sensitive personal information a year (or a listed necessary-business exemption) needs no mechanism, 100,000 to under 1,000,000 needs a standard contract or certification, and 1,000,000 or more, or sensitive personal information export above 10,000 individuals, needs the full CAC security assessment.
  • Complete a security assessment before any cross-border personal information export if operating as a critical information infrastructure operator, regardless of volume.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

This CAC regulation relaxes PIPL Article 38's cross-border transfer mechanisms by transfer volume, recited in the CAC promulgation notice. Exporting under 100,000 individuals' non-sensitive personal information in a year, or a listed necessary-business category such as contract performance, cross-border human-resources management, or emergency protection of life or property, needs no security assessment, standard contract, or certification at all.

Exporting 100,000 to under 1,000,000 individuals' non-sensitive personal information, or under 10,000 individuals' sensitive personal information, needs a standard contract or certification. Exporting 1,000,000 or more individuals' non-sensitive personal information, or 10,000 or more individuals' sensitive personal information, or any export by a critical information infrastructure operator, needs the full CAC security assessment. Free trade zones may adopt their own negative lists further narrowing what requires a mechanism.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_voice
  • processes_biometrics

Read the law

official CAC promulgation notice for the Provisions
(a press notice reciting the volume tiers and effective date, not the article-numbered regulation text)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app