Skip to the content
Global Data RulesData governance rules, country by country

China

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in China — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: Very highEnforcement: Active

You can send data out of China, but only after clearing one of three official checks. A government security review. Or a government-written contract that you file with the regulator. Or a certificate from an approved body. Which one you need depends on how many people's data you move. It does not depend on where you send it. If you move small amounts, you need none of them. Some industries must keep the data in China.

Data governance in China

The eight things that decide how you handle data about people in China. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. China's privacy law applies even if you have no office and no staff there. It applies if you sell goods or services to people in China. It also applies if you analyse their behaviour. There is no revenue or staff limit that gets you out. If the law applies to you, you must open an office in China or name a representative there. You must give the regulator their contact details.

What you have to do here:
Appoint a representative

Where the data is allowed to live

Yes, in most cases, once you complete the right step. The step depends on how many people's data you move. It does not depend on the country you send it to. China has no list of banned countries and no list of approved countries. Below 100,000 people a year, you can usually send data abroad with no filing at all. Above that, you need a contract filed with the regulator, or a certificate. Above one million people, you need a full government security review. You also need that review if you hold data the state calls 'important'. Some industries have stricter rules that override all of this.

Ways to send data out:
Security review needed · Standard contract clauses · Certification scheme

What to do: Get the paperwork for one of the routes below signed before any data leaves China.

Sending data out of the country

There are three routes, and you do not pick freely. The amount of data you move decides which one you use. Route one is a government security review. The national internet regulator runs it through your provincial office. Approval lasts three years. It only covers the exact purpose, scope and method you declared. Route two is China's own standard contract. You sign it with the overseas recipient. You then file it with the provincial regulator along with a risk assessment. Route three is a certificate from an approved body. Since 1 March 2026 a national standard sits behind it. Whichever route you use, you also need each person's separate, specific consent before their data leaves China.

Ways to send data out:
Security review needed · Standard contract clauses · Certification scheme · Explicit consent · Needed for a contract

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The Cyberspace Administration of China leads, and it is fully staffed and busy. It runs a nationwide enforcement campaign every year. It tests apps itself and publishes the names of the ones that fail. It also puts out batches of worked enforcement cases. The police, the industry ministry and the market regulator enforce alongside it. Finance, health, mapping and securities regulators run their own rules. Fines are usually small and come with an order to fix the problem. The very large penalties written into the law are rarely used.

How long you must keep it — and when to delete it

There are rules in both directions, and they pull against each other. Minimums: you must keep network logs for at least six months. Accounting records have their own long minimum periods, set by a national schedule. Maximums: you may keep personal data only for the shortest time needed for the purpose you collected it for. You must delete it once that purpose is met, the service ends, or the person withdraws consent. Where a law sets a minimum, that minimum wins. You keep the record and stop using it for anything else.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Keep logs

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

Three deadlines apply at once. If you run critical national infrastructure, you have one hour to report a serious incident. You report it to your supervising department and to the police. Everyone else has four hours to tell the provincial internet office. On top of that, you must report within 24 hours any network data incident that could harm national security or the public interest. You must also tell the affected people straight away. You can use phone, text, message, email or a public notice.

What you have to do here:
Report cyber incidents · Report breaches to the regulator · Tell affected people

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things catch people out. (1) Sending data abroad needs each person's separate, specific consent. A line buried in a global privacy notice is not enough. (2) A child is anyone under 14. Their data counts as sensitive. You need a parent's consent and a separate set of rules for handling it. (3) You may not hand data stored in China to a foreign court, police force or regulator without Chinese government approval. This catches routine legal discovery and audit requests from abroad. (4) You must work out for yourself whether you hold 'important data', and then report it. The official lists are incomplete. (5) Many people say all personal financial data must be stored in China. We could not find that rule in the law they point to.

What you have to do here:
Get a parent's consent for children · Do not hand data to foreign authorities on demand · Independent audit
What it costs if you get it wrong:
Criminal liability

What's changing next

The next twelve months are about rules based on size. A draft published on 7 August 2026 would add heavy duties for any company holding data on ten million people or more. You would have to store the data in China. You would have to appoint a chief privacy officer. You would have to set up an outside supervision committee. You would have to publish an annual report. And you would have to answer requests to move data elsewhere within 30 working days. Comments closed on 7 September 2026, and it is not law yet. A second draft going the other way would make life simpler for small companies. Also watch the rules that can change without warning. Several can be switched on with no consultation at all.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries10 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Payments

Payments data needs a copy kept in the country

Official name: 非银行支付机构监督管理条例 · Regulation on the Supervision and Administration of Non-Bank Payment Institutions, State Council order no. 768, articles 18 and 33 · Directly binding regulation

In forceA copy must stay

Payment firms cannot run their China business from abroad. Their business systems and backups must sit inside China. Personal data collected in China must be used and stored in China. Sending it out needs both a legal basis and the user's separate consent.

In force since 1 May 2024

Enforced by People's Bank of China

How this country controls where data goes: Approval each time · Accepted routes: Security review needed, Explicit consent

Finance

Finance data needs a copy kept in the country

Official name: 征信业务管理办法 · Credit Reporting Business Management Measures, People's Bank of China order [2021] no. 4, articles 39 and 40 · Directly binding regulation

In forceA copy must stay

Credit bureaus must store all company and personal credit information they collect in China inside China. To send personal credit information abroad, follow the national data export rules. Company credit information can only go to a checked recipient, and only for trade or investment across borders.

In force since 1 January 2022

Enforced by People's Bank of China

How this country controls where data goes: Approval each time · Accepted routes: Security review needed, Government sign-off needed

Banking

Banking data needs a copy kept in the country

Official name: 中国人民银行业务领域数据安全管理办法 · Measures for Data Security Management in the Business Areas of the People's Bank of China, order [2025] no. 3, articles 22 and 24 · Directly binding regulation

In forceA copy must stay

The central bank's own data rulebook, in force since 30 June 2025. If another rule says the data must be stored in China, you must keep a copy there. Sending a copy abroad does not change that. Handing over the most sensitive category needs state approval. Splitting data up to stay under a threshold is banned.

In force since 30 June 2025

Enforced by People's Bank of China

How this country controls where data goes: Approval each time · Accepted routes: Security review needed, Government sign-off needed

Applies to every company5 rules

These bind you whatever business you are in, once the country's rules reach you.

General data protection law

Official name: 中华人民共和国个人信息保护法 · Personal Information Protection Law of the People's Republic of China · Act of parliament

In forceYes, with paperwork

China's main privacy law, fully in force since 1 November 2021. It applies to foreign companies that serve people in China. Before personal data leaves the country, you need one of the official routes plus each person's separate consent. Fines reach 50 million yuan (about 7 million US dollars) or 5 percent of the previous year's turnover. One part of the law is not yet active. It orders large companies to store data in China once they pass a size the regulator is meant to set. That number has never been published.

In force since 1 November 2021

Enforced by Cyberspace Administration of China

How this country controls where data goes: Approval each time · Accepted routes: Security review needed, Standard contract clauses, Certification scheme, Explicit consent

Government data rules

Official name: 促进和规范数据跨境流动规定 · Provisions on Promoting and Regulating Cross-Border Data Flows · Directly binding regulation

In forceYes, with paperwork

This rule decides which route you use. Ordinary personal data on fewer than 100,000 people a year needs nothing. Between 100,000 and one million people, you need the standard contract or a certificate. Above that, you need a full government security review. So does any important data. Free trade zones can set their own exemptions through published negative lists.

In force since 22 March 2024

Enforced by Cyberspace Administration of China

How this country controls where data goes: Approval each time · Accepted routes: Security review needed, Standard contract clauses, Certification scheme, Needed for a contract, To save someone’s life, Nothing required

Personal data needs a copy kept in the country

Official name: 中华人民共和国网络安全法(2025年修正) · Cybersecurity Law, article 39 (domestic storage by critical information infrastructure operators), as amended 28 October 2025 · Act of parliament

In forceA copy must stay

If the government names you critical national infrastructure, the rules tighten. Personal data and important data you collect in China must stay in China. A copy may go abroad only after passing a government security review. The amended law took effect on 1 January 2026. It raised the top fine to 10 million yuan (about 1.4 million US dollars).

In force since 1 June 2017Enforced from 1 January 2026

Enforced by Cyberspace Administration of China

How this country controls where data goes: Approval each time · Accepted routes: Security review needed

Who you would hear from

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The volume threshold that triggers the storage-in-China duty in the privacy law for processors that are NOT critical infrastructure

    We could not confirm the size that triggers this duty. The law points to a number the national internet regulator is meant to publish, and we found no published notice setting it. Lawyers often assume it matches the one-million-person figure in the transfer rules. No government document confirms that. If you are near this size, check with a Chinese adviser before you rely on it.

  • That personal financial information held by ordinary banks must be stored in China

    We found no rule requiring all personal financial data to be stored in China. We read the central bank's Financial Consumer Rights Protection Measures, in force 1 November 2020, and found no such article. The banking and insurance data rules of December 2024 contain no blanket storage duty either. The claim seems to rest on a 2011 central bank notice and a recommended, non-binding industry standard. We could not confirm that either is still current. If you are a bank or insurer, check before you rely on this.

  • The exact number of free trade zones with a published data export negative list

    We could not confirm how many free trade zones have published negative lists. The regulator's March 2026 statement names nine. Its own list index also shows a Guangdong list dated 25 December 2025, which would make ten. Check the zone you care about directly.

  • The article-level text of the overseas-listing confidentiality and archives rules

    We confirmed who issued this rule and that it started on 31 March 2023. We could not confirm the wording of the rule itself against a government source. Read the official text before you rely on the detail.

  • Whether accredited bodies are actually issuing cross-border personal information certificates in volume

    We could not confirm how many data export certificates have been issued. The national standard took effect on 1 March 2026, and the certification centre lists approved audit firms. Ask the certification centre if the number matters to you.

  • The detailed content of the Automotive Data Export Security Guidelines (2026 edition)

    We confirmed the eight departments that issued this guidance and the date of 30 January 2026. We could not confirm the wording of the guidance itself. Read the official text before you rely on the detail.

  • Whether any additional data export rule was published between 1 and 18 August 2026

    We checked the regulator's data governance index on 18 August 2026. The newest items were a policy questions and answers page dated 12 August 2026 and the draft rules of 7 August 2026. Newer rules may exist without appearing in that index. Check the regulator's site for anything published since.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.