China
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in China — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
You can send data out of China, but only after clearing one of three official checks. A government security review. Or a government-written contract that you file with the regulator. Or a certificate from an approved body. Which one you need depends on how many people's data you move. It does not depend on where you send it. If you move small amounts, you need none of them. Some industries must keep the data in China.
Data governance in China
The eight things that decide how you handle data about people in China. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. China's privacy law applies even if you have no office and no staff there. It applies if you sell goods or services to people in China. It also applies if you analyse their behaviour. There is no revenue or staff limit that gets you out. If the law applies to you, you must open an office in China or name a representative there. You must give the regulator their contact details.
- What you have to do here:
- Appoint a representative
The Personal Information Protection Law sets this out. Article 3 makes the law apply to companies based outside China. Article 53 says you must set up an office in China or name a representative there. You must report their details to the regulator. The same point comes up again when you send data abroad. Under article 7 of the Personal Information Outbound Certification Measures, a company outside China cannot apply for a certificate by itself. A Chinese entity or your named representative has to file for it. There is a separate rule if you hold personal data on more than one million people. You must file the name and contact details of your personal information protection officer with the municipal cyberspace office, which is the city-level internet regulator. The regulator opened an online filing system for this in July 2025. It set 29 August 2025 as the deadline for companies already above that number.
Sources
- Official sourceCyberspace Administration of ChinaPersonal Information Protection Law of the People's Republic of China, articles 3 and 53
cac.gov.cn
“本法第三条第二款规定的中华人民共和国境外的个人信息处理者,应当在中华人民共和国境内设立专门机构或者指定代表”
Link checked 18 August 2026
- Official sourceCyberspace Administration of ChinaAnnouncement on filing personal information protection officer details (threshold: one million people), 18 July 2025
cac.gov.cn
Link checked 18 August 2026
Where the data is allowed to live
Yes, in most cases, once you complete the right step. The step depends on how many people's data you move. It does not depend on the country you send it to. China has no list of banned countries and no list of approved countries. Below 100,000 people a year, you can usually send data abroad with no filing at all. Above that, you need a contract filed with the regulator, or a certificate. Above one million people, you need a full government security review. You also need that review if you hold data the state calls 'important'. Some industries have stricter rules that override all of this.
- Ways to send data out:
- Security review needed · Standard contract clauses · Certification scheme
The volume rules come from the Rules on Promoting and Regulating Cross-Border Data Flows, in force 22 March 2024. You need a government security review in three cases. First, if you run critical information infrastructure and send any personal data abroad. Second, if you send 'important data' abroad. Third, if you have sent the ordinary personal data of more than one million people abroad since 1 January of the current year. The review is also needed once you have sent sensitive personal data on more than 10,000 people in that period. Between 100,000 and one million people, and under 10,000 sensitive records, you use the standard contract or the certificate. Below 100,000 people of ordinary personal data, you need nothing. Free trade zones can make their own exceptions. Nine or more zones have published 'negative lists'. If your data is not on the local list, you need no paperwork at all. In March 2026 the regulator said the lists cover 22 fields. These include cars, retail, civil aviation, reinsurance, deep-sea industry, seed breeding, geographic information and meteorology, and company credit information. Some industries have stricter rules. Critical information infrastructure: the data must stay in China. Non-bank payments: systems and backups must sit in China. Credit reporting: the data must stay in China. Health and medical big data: the data must stay in China. Human genetic information: decided case by case, with a security review above 500 sequenced genomes. Internet map services: map data servers must be in China, and there is no way around it. Telecom, factory and radio data: it must stay in China where a law says so. You also may not hand it to a foreign industry regulator without ministry approval. Overseas share listings: audit working papers stay in China. Banks and insurers: conditions apply, but their rules contain no blanket order to keep data in China. Government systems: outsourcing needs approval.
Sources
- Official sourceCyberspace Administration of ChinaProvisions on Promoting and Regulating Cross-Border Data Flows, articles 5 to 8 (volume thresholds and exemptions)
cac.gov.cn
“自当年1月1日起累计向境外提供100万人以上、不满1000万人个人信息(不含敏感个人信息)”
Link checked 18 August 2026
- Official sourceCyberspace Administration of ChinaFree trade zone data export negative lists — regulator's index page (Tianjin, Beijing, Shanghai, Hainan, Zhejiang, Jiangsu, Guangxi, Chongqing, Fujian, Guangdong)
cac.gov.cn
Link checked 18 August 2026
- Official sourceCyberspace Administration of ChinaTwo years of the Cross-Border Data Flow Provisions — official progress statement, 23 March 2026
cac.gov.cn
“对汽车、零售、民航、再保险、深海业、种业、地理信息与气象、企业信用信息等22个领域数据跨境流动发挥促进作用”
Link checked 18 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves China.
Sending data out of the country
There are three routes, and you do not pick freely. The amount of data you move decides which one you use. Route one is a government security review. The national internet regulator runs it through your provincial office. Approval lasts three years. It only covers the exact purpose, scope and method you declared. Route two is China's own standard contract. You sign it with the overseas recipient. You then file it with the provincial regulator along with a risk assessment. Route three is a certificate from an approved body. Since 1 March 2026 a national standard sits behind it. Whichever route you use, you also need each person's separate, specific consent before their data leaves China.
- Ways to send data out:
- Security review needed · Standard contract clauses · Certification scheme · Explicit consent · Needed for a contract
Article 38 of the Personal Information Protection Law sets out the three routes. Article 39 says you must tell people who the overseas recipient is and get their separate consent. The main rulebook is the Rules on Promoting and Regulating Cross-Border Data Flows, dated 22 March 2024. There is no list of banned countries and no list of approved countries. China puts the rules on the company sending the data, not on the destination country. The regulator's April 2025 policy questions and answers confirmed three points. A security review result now lasts three years, up from two. You can ask for an extension 60 working days before it expires. And a company group can file one application covering several subsidiaries. The certificate route was completed by the Personal Information Outbound Certification Measures. These were joint order number 20 from the Cyberspace Administration and the market regulator, published 17 October 2025 and in force 1 January 2026. Certificates last three years. Only companies outside critical infrastructure, moving data on 100,000 to one million people, can use this route. A company based outside China must apply through a Chinese entity or its named representative. The national standard behind it, GB/T 46068-2025, took effect on 1 March 2026.
Sources
- Official sourceCyberspace Administration of ChinaPersonal Information Protection Law, articles 38 and 39 (three mechanisms; separate consent)
cac.gov.cn
“个人信息处理者向中华人民共和国境外提供个人信息的,应当向个人告知境外接收方的名称或者姓名、联系方式、处理目的、处理方式、个人信息的种类……并取得个人的单独同意。”
Link checked 18 August 2026
- Official sourceCyberspace Administration of China and State Administration for Market RegulationPersonal Information Outbound Certification Measures (joint order no. 20), in force 1 January 2026
cac.gov.cn
“中华人民共和国境外的个人信息处理者申请个人信息出境认证的,应当由其在境内设立的专门机构或者指定代表协助进行申请”
Link checked 18 August 2026
- Official sourceCyberspace Administration of ChinaData export security management policy Q&A, April 2025 — three-year validity, extensions, group filings
cac.gov.cn
“数据出境安全评估结果有效期由原来的2年延长至3年”
Link checked 18 August 2026
- Official sourceState Administration for Market Regulation / national standards portalGB/T 46068-2025 Data security technology — security certification requirements for cross-border processing of personal information
openstd.samr.gov.cn
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The Cyberspace Administration of China leads, and it is fully staffed and busy. It runs a nationwide enforcement campaign every year. It tests apps itself and publishes the names of the ones that fail. It also puts out batches of worked enforcement cases. The police, the industry ministry and the market regulator enforce alongside it. Finance, health, mapping and securities regulators run their own rules. Fines are usually small and come with an order to fix the problem. The very large penalties written into the law are rarely used.
Here is what we saw on 18 August 2026. On 2 April 2026 the internet regulator, the industry ministry and the Ministry of Public Security announced the 2026 privacy campaigns together. The campaigns cover apps and software kits, internet advertising, education, transport, healthcare and finance. They also cover criminal gangs trading personal data. The regulators promised to act hard on serious cases and on companies that refuse to fix problems. Lists of named apps followed on 27 April 2026, with 33 apps, and on 11 June 2026, with 30 apps. On 16 September 2025 the regulator published ten worked enforcement cases. They covered unpatched software holes, weak passwords, leaked databases, collecting too much data, and collecting biometric data unlawfully. One case involved a deep-synthesis service launched without its required security review. The results were warnings, orders to fix, fines and one app removal. Provincial internet offices handle the day-to-day work on data export filings. Eight more provinces became pre-assessment pilot sites during 2026. We rate the regulator active rather than aggressive. It does a lot and it goes looking for problems. But published fines are small, and very large fines are still rare.
Sources
- Official sourceCyberspace Administration of China, Ministry of Industry and Information Technology, Ministry of Public SecurityAnnouncement of the 2026 personal information protection special campaigns, 2 April 2026
cac.gov.cn
Link checked 18 August 2026
- Official sourceCyberspace Administration of ChinaNotice on personal information collection problems in 30 apps, 11 June 2026
cac.gov.cn
- Official sourceCyberspace Administration of ChinaRecent typical enforcement cases on network security, data security and personal information protection, 16 September 2025
cac.gov.cn
Link checked 18 August 2026
How long you must keep it — and when to delete it
There are rules in both directions, and they pull against each other. Minimums: you must keep network logs for at least six months. Accounting records have their own long minimum periods, set by a national schedule. Maximums: you may keep personal data only for the shortest time needed for the purpose you collected it for. You must delete it once that purpose is met, the service ends, or the person withdraws consent. Where a law sets a minimum, that minimum wins. You keep the record and stop using it for anything else.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Keep logs
Minimums. The Cybersecurity Law was renumbered by the amendment in force 1 January 2026. Its article 23 requires you to monitor and record network operation and security events. You must keep the relevant network logs for at least six months. The Accounting Archives Management Measures set minimum keeping periods by schedule. These are Ministry of Finance and National Archives Administration order number 79, in force 1 January 2016. They say plainly that those periods are minimums. Article 25 requires you to follow national rules before accounting archives are carried or sent out of China. Maximums. Article 19 of the Personal Information Protection Law limits keeping personal data to the shortest time needed for the purpose, unless another law says otherwise. Article 47 requires deletion in four cases. The purpose is achieved or can no longer be achieved. The service ends. The keeping period expires. Or the person withdraws consent. Where deletion is technically impractical, you must stop all use of the data except storage and security. Where the two directions clash, article 19 gives way to other laws and administrative regulations.
Sources
- Official sourceCyberspace Administration of ChinaCybersecurity Law as amended, article 23 — six-month minimum network log retention
cac.gov.cn
“采取监测、记录网络运行状态、网络安全事件的技术措施,并按照规定留存相关的网络日志不少于六个月”
Link checked 18 August 2026
- Official sourceCyberspace Administration of ChinaPersonal Information Protection Law, articles 19 and 47 — shortest necessary retention and deletion duties
cac.gov.cn
“除法律、行政法规另有规定外,个人信息的保存期限应当为实现处理目的所必要的最短时间。”
Link checked 18 August 2026
- Official sourceState Council GazetteAccounting Archives Management Measures (order no. 79), retention schedule and article 25 on moving archives abroad
gov.cn
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
Three deadlines apply at once. If you run critical national infrastructure, you have one hour to report a serious incident. You report it to your supervising department and to the police. Everyone else has four hours to tell the provincial internet office. On top of that, you must report within 24 hours any network data incident that could harm national security or the public interest. You must also tell the affected people straight away. You can use phone, text, message, email or a public notice.
- What you have to do here:
- Report cyber incidents · Report breaches to the regulator · Tell affected people
The National Cybersecurity Incident Reporting Measures took effect on 1 November 2025. Article 4 sets the deadlines. If you run critical information infrastructure, you report to your protecting department and to public security at once, and within one hour at the latest. Central and state bodies report within two hours through their own cybersecurity office. Everyone else reports to the provincial cyberspace office within four hours. Article 7 requires follow-up reports as the investigation develops. Article 11 offers lighter treatment if you had reasonable protections in place, followed your incident plan and reported on time. That is a real reason to report early. The 24-hour deadline sits in the Network Data Security Management Regulation. That is State Council order number 790, in force 1 January 2025. It also requires you to start your incident plan at once and to tell affected people directly. Article 57 of the Personal Information Protection Law adds one more duty. Tell the regulator and the affected people at once whenever personal data is leaked, altered or lost. The same applies if it may have been. Banks and insurers report to their own regulator as well.
Sources
- Official sourceCyberspace Administration of ChinaNational Cybersecurity Incident Reporting Measures, article 4 — one, two and four hour clocks, in force 1 November 2025
cac.gov.cn
“第一时间向保护工作部门、公安机关报告,最迟不得超过1小时”
Link checked 18 August 2026
- Official sourceState Council, published by the Ministry of Ecology and EnvironmentNetwork Data Security Management Regulation (State Council order no. 790), incident articles 10 and 11 — 24-hour reporting and user notification
mee.gov.cn
Link checked 18 August 2026
- Official sourceCyberspace Administration of ChinaPersonal Information Protection Law, article 57 — immediate notification of regulator and individuals
cac.gov.cn
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things catch people out. (1) Sending data abroad needs each person's separate, specific consent. A line buried in a global privacy notice is not enough. (2) A child is anyone under 14. Their data counts as sensitive. You need a parent's consent and a separate set of rules for handling it. (3) You may not hand data stored in China to a foreign court, police force or regulator without Chinese government approval. This catches routine legal discovery and audit requests from abroad. (4) You must work out for yourself whether you hold 'important data', and then report it. The official lists are incomplete. (5) Many people say all personal financial data must be stored in China. We could not find that rule in the law they point to.
- What you have to do here:
- Get a parent's consent for children · Do not hand data to foreign authorities on demand · Independent audit
- What it costs if you get it wrong:
- Criminal liability
(1) This comes from article 39 of the Personal Information Protection Law. (2) Article 28 treats information about children under 14 as sensitive personal information. Article 31 requires a guardian's consent plus a separate set of rules for handling it. This age is lower than India's under-18, and different again from Europe's range of 13 to 16. (3) Two laws ban giving data stored in China to foreign courts or law enforcement bodies. You need approval from the relevant Chinese authority first. They are article 36 of the Data Security Law and article 41 of the Personal Information Protection Law. Article 48 of the Data Security Law sets fines of 100,000 to one million yuan (about 14,000 to 140,000 US dollars). In serious cases the fine rises to one to five million yuan (about 140,000 to 700,000 US dollars), with suspension or loss of licence. The industry ministry has its own version. Industrial, telecom and radio data stored in China may not be given to a foreign industry, telecom or radio enforcement body without ministry approval. (4) 'Important data' triggers the heaviest route, a full government security review. But you largely have to identify it yourself, against national standard GB/T 43697-2024 and regional and industry lists that are still being published. The regulator's October 2025 questions and answers confirmed you cannot extend the two-month window for reporting newly identified important data. (5) The People's Bank of China's Financial Consumer Rights Protection Measures came into force on 1 November 2020. We found no rule there requiring personal financial information to be stored in China. The belief traces back to a 2011 central bank notice and to a recommended, non-mandatory industry standard. The storage rules we could verify apply to non-bank payment institutions and credit reporting agencies, not to banks in general. One more trap. If you hold data on more than one million people, you must file your privacy officer's details with the regulator. If you hold data on more than ten million people, you must run a compliance audit at least every two years.
Sources
- Official sourceCyberspace Administration of ChinaData Security Law, articles 36 and 48 — no data to foreign judicial or law enforcement bodies without approval
cac.gov.cn
“非经中华人民共和国主管机关批准,境内的组织、个人不得向外国司法或者执法机构提供存储于中华人民共和国境内的数据。”
Link checked 18 August 2026
- Official sourceCyberspace Administration of ChinaPersonal Information Protection Law, articles 31, 39 and 41 — under-14 consent, separate consent for export, foreign authority requests
cac.gov.cn
“个人信息处理者处理不满十四周岁未成年人个人信息的,应当取得未成年人的父母或者其他监护人的同意。”
Link checked 18 August 2026
- Official sourceCyberspace Administration of ChinaPersonal Information Protection Compliance Audit Measures (order no. 18), in force 1 May 2025 — audit every two years above ten million people
cac.gov.cn
“应当每两年至少开展一次个人信息保护合规审计”
Link checked 18 August 2026
- Official sourceCyberspace Administration of ChinaData export security management policy Q&A, October 2025 — exemptions, employee data, important data reporting window
cac.gov.cn
Link checked 18 August 2026
What's changing next
The next twelve months are about rules based on size. A draft published on 7 August 2026 would add heavy duties for any company holding data on ten million people or more. You would have to store the data in China. You would have to appoint a chief privacy officer. You would have to set up an outside supervision committee. You would have to publish an annual report. And you would have to answer requests to move data elsewhere within 30 working days. Comments closed on 7 September 2026, and it is not law yet. A second draft going the other way would make life simpler for small companies. Also watch the rules that can change without warning. Several can be switched on with no consultation at all.
None of the following is binding today. Draft Rules on Personal Information Protection by Large Personal Information Processors, published for comment 7 August 2026, with comments closing 7 September 2026. It carries the ten-million-person trigger and a clear duty to store data in China. Draft Simplified Personal Information Protection Measures for Small Processors, 3 April 2026. Draft Rules on Personal Information Collection and Use by Internet Applications, 10 January 2026. Draft Rules on Personal Information Protection by Large Network Platforms, 22 November 2025. Two things have already landed and now apply. The amended Cybersecurity Law applies from 1 January 2026. It raises the top fine to ten million yuan (about 1.4 million US dollars). It also adds an artificial intelligence article. The certificate route started on 1 January 2026, with its national standard from 1 March 2026. Four things can change with no new law, and they matter more than the drafts. The government can name you a critical information infrastructure operator at any time. That instantly turns your position from paperwork into keeping the data in China. Regional and industry lists of 'important data' are still being issued, and each new one can pull another dataset into the security review route. Free trade zone negative lists are revised zone by zone, and they can grow as easily as shrink. And a security review approval covers only the exact purpose, scope, method and categories you declared. A product change can cancel it without you noticing.
Sources
- Official sourceCyberspace Administration of ChinaConsultation on the draft Provisions on Personal Information Protection by Large Personal Information Processors, 7 August 2026
cac.gov.cn
Link checked 18 August 2026
- Official sourceCyberspace Administration of ChinaConsultation on the draft Simplified Personal Information Protection Measures for Small Processors, 3 April 2026
cac.gov.cn
- Official sourceCyberspace Administration of ChinaCybersecurity Law as amended by the decision of 28 October 2025, in force 1 January 2026
cac.gov.cn
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries10 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Payments data needs a copy kept in the country
Official name: 非银行支付机构监督管理条例 · Regulation on the Supervision and Administration of Non-Bank Payment Institutions, State Council order no. 768, articles 18 and 33 · Directly binding regulation
Payment firms cannot run their China business from abroad. Their business systems and backups must sit inside China. Personal data collected in China must be used and stored in China. Sending it out needs both a legal basis and the user's separate consent.
Enforced by People's Bank of China
How this country controls where data goes: Approval each time · Accepted routes: Security review needed, Explicit consent
What you have to do
- Keep the data in the countryBusiness systems and their backups must sit in China. Personal data collected in China must be used and stored there.
- Get consentYou need the user's separate consent before sending any data abroad.
Sources
- Official sourceState Council, republished by a municipal government portalRegulation on the Supervision and Administration of Non-Bank Payment Institutions (State Council order no. 768) — full text
pds.gov.cn
“非银行支付机构的业务系统及其备份应当存放在境内。”
Link checked 18 August 2026
- Official sourcePeople's Bank of ChinaRegulation on the Supervision and Administration of Non-Bank Payment Institutions — central bank's own copy
pbc.gov.cn
Finance data needs a copy kept in the country
Official name: 征信业务管理办法 · Credit Reporting Business Management Measures, People's Bank of China order [2021] no. 4, articles 39 and 40 · Directly binding regulation
Credit bureaus must store all company and personal credit information they collect in China inside China. To send personal credit information abroad, follow the national data export rules. Company credit information can only go to a checked recipient, and only for trade or investment across borders.
Enforced by People's Bank of China
How this country controls where data goes: Approval each time · Accepted routes: Security review needed, Government sign-off needed
What you have to do
- Keep the data in the countryCompany and personal credit information collected in China must be stored in China.
- Put a transfer safeguard in placeBefore sending company credit information abroad, check who the recipient is and why they want it. You must be satisfied the use is for trade or investment across borders.
Sources
- Official sourceState Council policy database / People's Bank of ChinaCredit Reporting Business Management Measures — full text
gov.cn
“征信机构在中华人民共和国境内开展征信业务及其相关活动,采集的企业信用信息和个人信用信息应当存储在中华人民共和国境内。”
Link checked 18 August 2026
Banking data needs a copy kept in the country
Official name: 中国人民银行业务领域数据安全管理办法 · Measures for Data Security Management in the Business Areas of the People's Bank of China, order [2025] no. 3, articles 22 and 24 · Directly binding regulation
The central bank's own data rulebook, in force since 30 June 2025. If another rule says the data must be stored in China, you must keep a copy there. Sending a copy abroad does not change that. Handing over the most sensitive category needs state approval. Splitting data up to stay under a threshold is banned.
Enforced by People's Bank of China
How this country controls where data goes: Approval each time · Accepted routes: Security review needed, Government sign-off needed
What you have to do
- Keep the data in the countrySome laws and central bank rules say data must be stored in China. A copy must stay there even when you also send it abroad.
- Assess high-risk projectsAssess the risk before you hand important data to anyone else. Sending core data needs approval through the national data security process.
Sources
- Official sourcePeople's Bank of China, republished by a municipal government portalMeasures for Data Security Management in the Business Areas of the People's Bank of China — full text
home.wuhan.gov.cn
“法律、行政法规和中国人民银行相关规定有境内存储要求的,业务数据还应当同时在中华人民共和国境内存储。”
Link checked 18 August 2026
- Official sourcePeople's Bank of ChinaMeasures for Data Security Management in the Business Areas of the People's Bank of China — central bank's own page
pbc.gov.cn
Banking rules
Official name: 银行保险机构数据安全管理办法 · Measures for Data Security Management by Banking and Insurance Institutions, articles 24, 36 and 60 · Directly binding regulation
Banks and insurers must run a security assessment before important data or personal data leaves China. They need the regulator's consent to collect industry-level important data from other institutions. These rules contain no blanket order to keep banking data inside China.
Enforced by National Financial Regulatory Administration
How this country controls where data goes: Approval each time · Accepted routes: Security review needed, Government sign-off needed
What you have to do
- Put a transfer safeguard in placeRun a security assessment under national policy before important data or personal data collected in China goes abroad.
- Tell people what you doYou must tell people how to use their rights against the overseas recipient.
Sources
- Official sourceNational Financial Regulatory Administration, State Council policy databaseMeasures for Data Security Management by Banking and Insurance Institutions — full text
gov.cn
“向境外提供在中华人民共和国境内运营中收集和产生的重要数据和个人信息,应当承担数据安全主体责任,并按照国家有关政策要求进行安全评估。”
Link checked 18 August 2026
- Official sourceNational Financial Regulatory AdministrationRegulator's Q&A on the Measures for Data Security Management by Banking and Insurance Institutions
gov.cn
Link checked 18 August 2026
Securities data needs a copy kept in the country
Official name: 关于加强境内企业境外发行证券和上市相关保密和档案管理工作的规定 · Provisions on Strengthening Confidentiality and Archives Administration Relating to Overseas Securities Offering and Listing by Domestic Enterprises (CSRC announcement no. 44 of 2023) · Directly binding regulation
If a Chinese company lists its shares abroad, the working papers behind the listing stay in China. A foreign securities regulator may want to inspect them or take evidence. It must go through the Chinese authorities. It cannot go straight to the company or its auditor.
Enforced by China Securities Regulatory Commission
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryAudit and advisory working papers produced in China for an overseas listing must be kept in China.
- Do not hand data to foreign authorities on demandInspection or evidence-gathering by an overseas securities regulator must go through Chinese authorities.
Sources
- Official sourceChina Securities Regulatory Commission, Ministry of Finance, National Administration of State Secrets Protection, National Archives AdministrationProvisions on confidentiality and archives administration for overseas listings — issuing bodies and 31 March 2023 commencement
gov.cn
Link checked 18 August 2026
- Official sourceChina Securities Regulatory CommissionCSRC announcement no. 44 of 2023 — regulator's own publication page
csrc.gov.cn
Link checked 18 August 2026
Health and social care data needs a copy kept in the country
Official name: 国家健康医疗大数据标准、安全和服务管理办法(试行) · National Health and Medical Big Data Standards, Security and Services Management Measures (Trial), document no. 23 of 2018, article 30 · Government rules
Health and medical big data must be held on secure servers inside China. If your business needs to send it abroad, it goes through a security assessment first. This is a trial health ministry document, not a full regulation. It is still the rule hospitals and health platforms are held to.
Enforced by National Health Commission
How this country controls where data goes: Approval each time · Accepted routes: Security review needed
What you have to do
- Keep the data in the countryHealth and medical big data must sit on secure and trusted servers inside China.
- Put a transfer safeguard in placeRun a security assessment and review before you send any of it abroad.
Sources
- Official sourceNational Health Commission, republished by the Cyberspace Administration of ChinaNational Health and Medical Big Data Standards, Security and Services Management Measures (Trial), article 30
cac.gov.cn
“应当存储在境内安全可信的服务器上,因业务需要确需向境外提供的,应当按照相关法律法规及有关要求进行安全评估审核”
Link checked 18 August 2026
- Official sourceNational Health CommissionHealth ministry's own publication of the measures
nhc.gov.cn
Health data rules
Official name: 人类遗传资源管理条例实施细则 · Implementing Rules for the Regulation on the Administration of Human Genetic Resources, Ministry of Science and Technology order no. 21, articles 36 and 37 · Government rules
Genetic information about Chinese people cannot leave without notice. You file with the science ministry in advance. You hand over a backup copy. You explain the risk to public health and national security. A full security review is needed for anything covering important family lines, particular regions, or the genomes of more than 500 people.
Enforced by Ministry of Science and Technology
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Security review needed
What you have to do
- Register or notifyFile with the science ministry in advance. Include a copy of the information being sent and a risk assessment.
- Put a transfer safeguard in placeA security review is needed where public health, national security or the public interest could be affected.
What it costs if you get it wrong
- Order to stopProviding human genetic resource information abroad without the required filing or review
Sources
- Official sourceMinistry of Science and TechnologyImplementing Rules for the Regulation on the Administration of Human Genetic Resources — full text
most.gov.cn
“人数大于500例的外显子组测序、基因组测序信息资源”
Link checked 18 August 2026
Mapping and location data must stay in the country
Official name: 地图管理条例 · Map Management Regulation, State Council order no. 664, article 34 · Directly binding regulation
If you provide an internet map service in China, the servers holding the map data must be inside China. You must also have a written data security system. There is no paperwork route around this one.
Enforced by Ministry of Natural Resources
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryServers holding map data must be inside China.
- Secure the data
Sources
- Official sourceState Council GazetteMap Management Regulation (State Council order no. 664), article 34
gov.cn
“互联网地图服务单位应当将存放地图数据的服务器设在中华人民共和国境内,并制定互联网地图数据安全管理制度和保障措施。”
Link checked 18 August 2026
Telecoms data needs a copy kept in the country
Official name: 工业和信息化领域数据安全管理办法(试行) · Administrative Measures for Data Security in the Field of Industry and Information Technology (Trial), document no. 166 of 2022, article 21 · Government rules
This covers factory, telecom and radio data. Important and core data stays in China wherever another law requires it. You need a security assessment before it goes abroad. You may not hand such data to a foreign telecom or industry regulator without the Chinese ministry's approval.
Enforced by Ministry of Industry and Information Technology
How this country controls where data goes: Approval each time · Accepted routes: Security review needed, Government sign-off needed
What you have to do
- Keep the data in the countryImportant and core data must be stored in China wherever a law or administrative regulation says so.
- Do not hand data to foreign authorities on demandYou may not give industry, telecom or radio data stored in China to a foreign industry, telecom or radio enforcement body. The industry ministry must approve it first.
Sources
- Official sourceMinistry of Industry and Information Technology, State Council policy databaseAdministrative Measures for Data Security in the Field of Industry and Information Technology (Trial), article 21
gov.cn
“非经工业和信息化部批准,工业和信息化领域数据处理者不得向外国工业、电信、无线电执法机构提供存储于中华人民共和国境内的工业和信息化领域数据。”
Link checked 18 August 2026
Government data rules (Mapping and location)
Official name: 汽车数据出境安全指引(2026版) · Automotive Data Export Security Guidelines (2026 edition), issued jointly by eight departments · Regulator guideline
Eight government departments published this guidance on 30 January 2026. It tells carmakers and connected-vehicle platforms how the national data export rules apply to vehicle data. It is guidance, not binding law. Regulators will still use it as their reference.
Enforced by Ministry of Industry and Information Technology
How this country controls where data goes: Approval each time · Accepted routes: Security review needed, Standard contract clauses, Certification scheme
What you have to do
- Put a transfer safeguard in placeSets out how carmakers and connected-vehicle platforms apply the national data export rules to vehicle data.
Sources
- Official sourceMinistry of Industry and Information Technology and seven other departmentsNotice issuing the Automotive Data Export Security Guidelines (2026 edition)
cac.gov.cn
Link checked 18 August 2026
Applies to every company5 rules
These bind you whatever business you are in, once the country's rules reach you.
General data protection law
Official name: 中华人民共和国个人信息保护法 · Personal Information Protection Law of the People's Republic of China · Act of parliament
China's main privacy law, fully in force since 1 November 2021. It applies to foreign companies that serve people in China. Before personal data leaves the country, you need one of the official routes plus each person's separate consent. Fines reach 50 million yuan (about 7 million US dollars) or 5 percent of the previous year's turnover. One part of the law is not yet active. It orders large companies to store data in China once they pass a size the regulator is meant to set. That number has never been published.
Enforced by Cyberspace Administration of China
How this country controls where data goes: Approval each time · Accepted routes: Security review needed, Standard contract clauses, Certification scheme, Explicit consent
What you have to do
- Get consent
- Tell people what you do
- Put a transfer safeguard in placeYou need each person's separate, specific consent as well as one of the official transfer routes.
- Appoint a representativeIf the law reaches you from outside China, you must set up a company there or name a representative.
- Get a parent's consent for children — applies at: under 14 years old
- Report breaches to the regulator
- Delete data after a period
- Do not hand data to foreign authorities on demandYou may not give data to a foreign court or police force without Chinese government approval.
What it costs if you get it wrong
- Fixed maximum fine: 50,000,000 CNY — about $7 millionSerious breach of the law
- Percentage of global turnover: 5% of prior-year turnoverSerious breach; applied as an alternative to the cash cap
- Order to stopOrder to suspend or terminate the service
Sources
- Official sourceCyberspace Administration of ChinaPersonal Information Protection Law — full text
cac.gov.cn
“关键信息基础设施运营者和处理个人信息达到国家网信部门规定数量的个人信息处理者,应当将在中华人民共和国境内收集和产生的个人信息存储在境内”
Link checked 18 August 2026
Government data rules
Official name: 促进和规范数据跨境流动规定 · Provisions on Promoting and Regulating Cross-Border Data Flows · Directly binding regulation
This rule decides which route you use. Ordinary personal data on fewer than 100,000 people a year needs nothing. Between 100,000 and one million people, you need the standard contract or a certificate. Above that, you need a full government security review. So does any important data. Free trade zones can set their own exemptions through published negative lists.
Enforced by Cyberspace Administration of China
How this country controls where data goes: Approval each time · Accepted routes: Security review needed, Standard contract clauses, Certification scheme, Needed for a contract, To save someone’s life, Nothing required
What you have to do
- Put a transfer safeguard in place — applies at: 100,000 to 1,000,000 people: standard contract or certification; above 1,000,000 people, above 10,000 sensitive records, any important data, or any transfer by a critical infrastructure operator: government security review
- Assess high-risk projectsWhichever route you use, you must also run a personal information protection impact assessment.
Sources
- Official sourceCyberspace Administration of ChinaProvisions on Promoting and Regulating Cross-Border Data Flows — full text
cac.gov.cn
Link checked 18 August 2026
- Official sourceCyberspace Administration of ChinaFree trade zone data export negative lists — official index
cac.gov.cn
Link checked 18 August 2026
Personal data needs a copy kept in the country
Official name: 中华人民共和国网络安全法(2025年修正) · Cybersecurity Law, article 39 (domestic storage by critical information infrastructure operators), as amended 28 October 2025 · Act of parliament
If the government names you critical national infrastructure, the rules tighten. Personal data and important data you collect in China must stay in China. A copy may go abroad only after passing a government security review. The amended law took effect on 1 January 2026. It raised the top fine to 10 million yuan (about 1.4 million US dollars).
Enforced by Cyberspace Administration of China
How this country controls where data goes: Approval each time · Accepted routes: Security review needed
What you have to do
- Keep the data in the countryYou must store personal data and important data collected or created in China inside China.
- Keep logs — 6 months
- Secure the data
What it costs if you get it wrong
- Fixed maximum fine: 10,000,000 CNY — about $1 millionSecurity failures causing a critical infrastructure operator to lose its main functions
- Loss of your licenceSerious cases: suspension of business, closure of the website, or revocation of permits and licences
Sources
- Official sourceCyberspace Administration of ChinaCybersecurity Law as amended, article 39 and article 61 penalties
cac.gov.cn
“关键信息基础设施的运营者在中华人民共和国境内运营中收集和产生的个人信息和重要数据应当在境内存储。因业务需要,确需向境外提供的,应当按照国家网信部门会同国务院有关部门制定的办法进行安全评估”
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: 网络数据安全管理条例 · Network Data Security Management Regulation, State Council order no. 790 · Directly binding regulation
The State Council rulebook that fills in the three data laws. It sets a 24-hour reporting deadline for incidents that could harm national security or the public interest. It requires you to identify important data and check its risks every year. It also controls how government systems can be outsourced.
Enforced by Cyberspace Administration of China
How this country controls where data goes: Approval each time · Accepted routes: Security review needed, Standard contract clauses, Certification scheme, Needed for a contract
What you have to do
- Report breaches to the regulator — within 24 hoursWhere the incident could harm national security or the public interest.
- Tell affected people
- Keep records of how you use dataYou must identify important data, list it and report it. You must also assess its risks every year.
- Written vendor contractGovernment bodies outsourcing electronic government systems must follow a strict approval process. The supplier may not touch the data without the government body's consent.
Sources
- Official sourceState CouncilNetwork Data Security Management Regulation (State Council order no. 790) — full text
mee.gov.cn
Link checked 18 August 2026
- Official sourceCyberspace Administration of ChinaMinistry of Justice and Cyberspace Administration Q&A on the Network Data Security Management Regulation
cac.gov.cn
Link checked 18 August 2026
Breach reporting rules
Official name: 国家网络安全事件报告管理办法 · National Cybersecurity Incident Reporting Measures · Directly binding regulation
This sets the shortest reporting deadlines. One hour to report a serious incident if you run critical national infrastructure. Two hours for central government bodies. Four hours for everyone else. This rule does not say where data must be stored. Reporting on time and following your incident plan can reduce or remove your liability.
Enforced by Cyberspace Administration of China
What you have to do
- Report cyber incidents — applies at: Critical information infrastructure operators — to the protecting department and public security, within 1 hour
- Report cyber incidents — applies at: All other network operators — to the provincial cyberspace office, within 4 hours
Sources
- Official sourceCyberspace Administration of ChinaNational Cybersecurity Incident Reporting Measures — full text
cac.gov.cn
“应当及时向属地省级网信部门报告,最迟不得超过4小时”
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The volume threshold that triggers the storage-in-China duty in the privacy law for processors that are NOT critical infrastructure
We could not confirm the size that triggers this duty. The law points to a number the national internet regulator is meant to publish, and we found no published notice setting it. Lawyers often assume it matches the one-million-person figure in the transfer rules. No government document confirms that. If you are near this size, check with a Chinese adviser before you rely on it.
That personal financial information held by ordinary banks must be stored in China
We found no rule requiring all personal financial data to be stored in China. We read the central bank's Financial Consumer Rights Protection Measures, in force 1 November 2020, and found no such article. The banking and insurance data rules of December 2024 contain no blanket storage duty either. The claim seems to rest on a 2011 central bank notice and a recommended, non-binding industry standard. We could not confirm that either is still current. If you are a bank or insurer, check before you rely on this.
The exact number of free trade zones with a published data export negative list
We could not confirm how many free trade zones have published negative lists. The regulator's March 2026 statement names nine. Its own list index also shows a Guangdong list dated 25 December 2025, which would make ten. Check the zone you care about directly.
The article-level text of the overseas-listing confidentiality and archives rules
We confirmed who issued this rule and that it started on 31 March 2023. We could not confirm the wording of the rule itself against a government source. Read the official text before you rely on the detail.
Whether accredited bodies are actually issuing cross-border personal information certificates in volume
We could not confirm how many data export certificates have been issued. The national standard took effect on 1 March 2026, and the certification centre lists approved audit firms. Ask the certification centre if the number matters to you.
The detailed content of the Automotive Data Export Security Guidelines (2026 edition)
We confirmed the eight departments that issued this guidance and the date of 30 January 2026. We could not confirm the wording of the guidance itself. Read the official text before you rely on the detail.
Whether any additional data export rule was published between 1 and 18 August 2026
We checked the regulator's data governance index on 18 August 2026. The newest items were a policy questions and answers page dated 12 August 2026 and the draft rules of 7 August 2026. Newer rules may exist without appearing in that index. Check the regulator's site for anything published since.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.