China
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
Data can leave China, but only through one of three official gates: a government security review, a government-written contract you file with the regulator, or a certificate from an approved body. Which gate you need depends on how many people's data you move, not on where you send it. Small exporters are exempt. Several industries are walled off entirely.
Eight questions about China
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do China's rules apply to my company?
Yes. China's privacy law reaches a company with no office and no staff in China if it offers goods or services to people in China, or analyses their behaviour. There is no revenue or headcount threshold that lets you out. If you are caught this way, you must set up a dedicated office in China or name a representative there, and give the regulator their details.
Personal Information Protection Law, article 3 (extraterritorial reach) and article 53 (dedicated entity or designated representative, whose details must be reported to the regulator). The obligation bites again at the transfer stage: under the Personal Information Outbound Certification Measures, article 7, an overseas processor cannot even apply for a certificate on its own — a domestic entity or designated representative has to file for it. Separately, any processor holding personal information on more than one million people must file the name and contact details of its personal information protection officer with the municipal cyberspace office; the regulator opened an online filing system for this in July 2025 and set 29 August 2025 as the deadline for those already over the line.
Sources
- Official sourceCyberspace Administration of ChinaPersonal Information Protection Law of the People's Republic of China, articles 3 and 53
cac.gov.cn
“本法第三条第二款规定的中华人民共和国境外的个人信息处理者,应当在中华人民共和国境内设立专门机构或者指定代表”
Link checked 18 August 2026
- Official sourceCyberspace Administration of ChinaAnnouncement on filing personal information protection officer details (threshold: one million people), 18 July 2025
cac.gov.cn
Link checked 18 August 2026
Can I store my users' data outside China?
In general yes, once you clear the right gate — but the gate is set by volume, not by destination. China has no list of banned or approved countries. Below 100,000 people a year you can usually send data abroad with no filing at all. Above that you need a contract filed with the regulator or a certificate; above a million people, or if you hold data the state calls 'important', you need a full government security review. Then come the industry walls, which override all of this.
The volume ladder is set by the Provisions on Promoting and Regulating Cross-Border Data Flows, in force 22 March 2024. Government security review is required where a critical information infrastructure operator sends any personal information abroad, where anyone sends 'important data' abroad, or where a non-critical operator has cumulatively sent the ordinary personal information of more than one million people, or the sensitive personal information of more than 10,000 people, since 1 January of the current year. Between 100,000 and one million people (or under 10,000 sensitive), the standard contract or certification route applies. Under 100,000 people of ordinary personal information, no mechanism is needed. Free trade zones add a further carve-out: nine or more zones have published 'negative lists', and data not on the local list needs no mechanism at all — as of March 2026 the regulator said the lists cover 22 fields including cars, retail, civil aviation, reinsurance, deep-sea industry, seed breeding, geographic information and meteorology, and enterprise credit information. SECTOR OVERRIDES, each rated separately: critical information infrastructure (mirror); non-bank payments (mirror — systems and backups must sit in China); credit reporting (mirror); health and medical big data (mirror); human genetic resource information (case-by-case, with a security review above 500 sequenced genomes); internet map services (closed — map data servers must be in China); telecom, industrial and radio data (mirror where a law imposes storage, plus a ban on handing data to foreign industry regulators without ministry approval); overseas securities listings (audit working papers stay in China); banks and insurers (conditional — there is no absolute storage wall in the banking and insurance rules, contrary to common belief); government e-government systems (approval-gated outsourcing).
Sources
- Official sourceCyberspace Administration of ChinaProvisions on Promoting and Regulating Cross-Border Data Flows, articles 5 to 8 (volume thresholds and exemptions)
cac.gov.cn
“自当年1月1日起累计向境外提供100万人以上、不满1000万人个人信息(不含敏感个人信息)”
Link checked 18 August 2026
- Official sourceCyberspace Administration of ChinaFree trade zone data export negative lists — regulator's index page (Tianjin, Beijing, Shanghai, Hainan, Zhejiang, Jiangsu, Guangxi, Chongqing, Fujian, Guangdong)
cac.gov.cn
Link checked 18 August 2026
- Official sourceCyberspace Administration of ChinaTwo years of the Cross-Border Data Flow Provisions — official progress statement, 23 March 2026
cac.gov.cn
“对汽车、零售、民航、再保险、深海业、种业、地理信息与气象、企业信用信息等22个领域数据跨境流动发挥促进作用”
Link checked 18 August 2026
What do I need in place before data leaves China?
Three routes, and you do not get to pick freely — your volume picks for you. Route one is a government security review, run by the national internet regulator through your provincial office; an approval lasts three years and only covers the exact purpose, scope and method you declared. Route two is China's own standard contract, which you sign with the overseas recipient and file with the provincial regulator along with a risk assessment. Route three is a certificate from an accredited body, which since 1 March 2026 has a national standard behind it. You also need each person's separate, specific consent before their data goes abroad.
Personal Information Protection Law article 38 sets the three mechanisms; article 39 requires notice of the overseas recipient plus separate consent. The controlling instrument is the Provisions on Promoting and Regulating Cross-Border Data Flows (22 March 2024). There is no destination blocklist and no adequacy allowlist: China regulates the exporter, not the country of arrival. The regulator's April 2025 policy Q&A confirmed the security assessment result is now valid for three years rather than two, that an extension can be requested 60 working days before expiry, and that a corporate group may file one application covering several subsidiaries. The certification route was completed by the Personal Information Outbound Certification Measures (Cyberspace Administration and market regulator joint order no. 20, published 17 October 2025, in force 1 January 2026): certificates last three years, only non-critical-infrastructure processors in the 100,000-to-one-million band may use it, and an overseas applicant must apply through a domestic entity or designated representative. The supporting national standard GB/T 46068-2025 took effect on 1 March 2026.
Sources
- Official sourceCyberspace Administration of ChinaPersonal Information Protection Law, articles 38 and 39 (three mechanisms; separate consent)
cac.gov.cn
“个人信息处理者向中华人民共和国境外提供个人信息的,应当向个人告知境外接收方的名称或者姓名、联系方式、处理目的、处理方式、个人信息的种类……并取得个人的单独同意。”
Link checked 18 August 2026
- Official sourceCyberspace Administration of China and State Administration for Market RegulationPersonal Information Outbound Certification Measures (joint order no. 20), in force 1 January 2026
cac.gov.cn
“中华人民共和国境外的个人信息处理者申请个人信息出境认证的,应当由其在境内设立的专门机构或者指定代表协助进行申请”
Link checked 18 August 2026
- Official sourceCyberspace Administration of ChinaData export security management policy Q&A, April 2025 — three-year validity, extensions, group filings
cac.gov.cn
“数据出境安全评估结果有效期由原来的2年延长至3年”
Link checked 18 August 2026
- Official sourceState Administration for Market Regulation / national standards portalGB/T 46068-2025 Data security technology — security certification requirements for cross-border processing of personal information
openstd.samr.gov.cn
Who enforces the rules in China, and what can they do?
The Cyberspace Administration of China leads, and it is fully staffed and busy. It runs a nationwide enforcement campaign every year, tests apps itself and publishes the names of the ones that fail, and puts out batches of worked enforcement cases. Police, the industry ministry and the market regulator enforce alongside it, and finance, health, mapping and securities regulators run their own rules. Fines are usually modest and paired with an order to fix things; the eye-watering penalties in the statute are rarely used.
Observable evidence gathered on 18 August 2026: the internet regulator, industry ministry and Ministry of Public Security jointly announced the 2026 personal information protection campaigns on 2 April 2026, covering apps and software kits, internet advertising, education, transport, healthcare, finance, and criminal rings trading personal data, promising to deal severely with serious cases and refusals to rectify. Named-and-shamed app batches followed on 27 April 2026 (33 apps) and 11 June 2026 (30 apps). On 16 September 2025 the regulator published ten worked enforcement cases covering unpatched vulnerabilities, weak passwords, leaked databases, excessive collection, unlawful biometric collection and a deep-synthesis service launched without its required security review; outcomes were warnings, rectification orders, fines and one app removal. Provincial internet offices do the front-line work on data export filings, and eight more provinces were added as pre-assessment pilot sites during 2026. Rated active rather than aggressive: volume is high and the regulator clearly goes looking, but published penalty values are small and headline-scale fines remain rare.
Sources
- Official sourceCyberspace Administration of China, Ministry of Industry and Information Technology, Ministry of Public SecurityAnnouncement of the 2026 personal information protection special campaigns, 2 April 2026
cac.gov.cn
Link checked 18 August 2026
- Official sourceCyberspace Administration of ChinaNotice on personal information collection problems in 30 apps, 11 June 2026
cac.gov.cn
- Official sourceCyberspace Administration of ChinaRecent typical enforcement cases on network security, data security and personal information protection, 16 September 2025
cac.gov.cn
Link checked 18 August 2026
How long do I have to keep the data?
Both directions apply, and they pull against each other. The floor: network logs must be kept for at least six months, and accounting records have their own long minimum periods set by a national schedule. The ceiling: personal data may only be kept for the shortest time needed for the purpose you collected it for, and must be deleted once that purpose is met, the service ends, or consent is withdrawn. Where a law sets a minimum, that minimum wins over the delete duty — you keep the record and stop using it for anything else.
Floor: Cybersecurity Law article 23 (as renumbered by the amendment in force 1 January 2026) requires technical measures to monitor and record network operation and security events and to retain relevant network logs for not less than six months. The Accounting Archives Management Measures (Ministry of Finance and National Archives Administration order no. 79, in force 1 January 2016) set minimum retention periods by schedule and state expressly that those periods are minimums; article 25 requires compliance with national rules before accounting archives are carried or transmitted out of China. Ceiling: Personal Information Protection Law article 19 caps retention at the shortest time necessary to achieve the processing purpose unless another law says otherwise, and article 47 requires deletion when the purpose is achieved or can no longer be achieved, the service is terminated, the retention period expires, or consent is withdrawn — where deletion is technically impracticable the processor must stop all processing except storage and security. Conflict resolution is the standard 'unless laws or administrative regulations provide otherwise' carve-out in article 19.
Sources
- Official sourceCyberspace Administration of ChinaCybersecurity Law as amended, article 23 — six-month minimum network log retention
cac.gov.cn
“采取监测、记录网络运行状态、网络安全事件的技术措施,并按照规定留存相关的网络日志不少于六个月”
Link checked 18 August 2026
- Official sourceCyberspace Administration of ChinaPersonal Information Protection Law, articles 19 and 47 — shortest necessary retention and deletion duties
cac.gov.cn
“除法律、行政法规另有规定外,个人信息的保存期限应当为实现处理目的所必要的最短时间。”
Link checked 18 August 2026
- Official sourceState Council GazetteAccounting Archives Management Measures (order no. 79), retention schedule and article 25 on moving archives abroad
gov.cn
Link checked 18 August 2026
What happens if there is a breach?
Three clocks, and they overlap. If you run critical national infrastructure you have ONE HOUR to report a serious incident to your supervising department and the police. Everyone else has four hours to tell the provincial internet office. On top of that, a network data incident that could harm national security or the public interest must be reported within 24 hours. You must also tell affected people immediately, by phone, text, message, email or public notice.
The National Cybersecurity Incident Reporting Measures took effect on 1 November 2025. Article 4 sets the clocks: critical information infrastructure operators report to the protecting department and public security at once and no later than one hour; central and state organs report within two hours through their own cybersecurity office; everyone else reports to the provincial cyberspace office within four hours. Article 7 requires follow-up reports as the investigation develops, and article 11 offers leniency where the operator had reasonable protections in place, followed its incident plan and reported on time — a genuine incentive to report early. The 24-hour clock sits in the Network Data Security Management Regulation (State Council order no. 790, in force 1 January 2025), which also requires immediate activation of the incident plan and direct notification of affected individuals. Personal Information Protection Law article 57 adds an immediate duty to notify both the regulator and the individuals whenever personal data is leaked, altered or lost, or may have been. Banks and insurers report to their own regulator in parallel.
Sources
- Official sourceCyberspace Administration of ChinaNational Cybersecurity Incident Reporting Measures, article 4 — one, two and four hour clocks, in force 1 November 2025
cac.gov.cn
“第一时间向保护工作部门、公安机关报告,最迟不得超过1小时”
Link checked 18 August 2026
- Official sourceState Council, published by the Ministry of Ecology and EnvironmentNetwork Data Security Management Regulation (State Council order no. 790), incident articles 10 and 11 — 24-hour reporting and user notification
mee.gov.cn
Link checked 18 August 2026
- Official sourceCyberspace Administration of ChinaPersonal Information Protection Law, article 57 — immediate notification of regulator and individuals
cac.gov.cn
Link checked 18 August 2026
What trips people up in China?
Five things that ruin weekends. (1) Sending data abroad needs each person's separate, specific consent — a line buried in a global privacy notice will not do. (2) A child is anyone under 14, and their data is treated as sensitive, so you need a parent's consent and a separate set of processing rules. (3) You may not hand data stored in China to a foreign court, police force or regulator without Chinese government approval — this catches routine legal discovery and overseas audit requests. (4) You have to work out for yourself whether you hold 'important data' and report it, because the official catalogues are incomplete. (5) The widely repeated claim that all personal financial data must be stored in China does not appear where people think it does.
(1) Personal Information Protection Law article 39. (2) Article 28 makes information on minors under 14 sensitive personal information; article 31 requires guardian consent plus dedicated processing rules. Note this is lower than India's under-18 and different again from Europe's 13-to-16 range. (3) Data Security Law article 36 and Personal Information Protection Law article 41 both prohibit providing data stored in China to foreign judicial or law enforcement bodies without approval from the competent Chinese authority; Data Security Law article 48 sets fines of 100,000 to one million yuan (about $14,000 to $140,000), rising to one to five million yuan (about $140,000 to $700,000) with suspension or licence revocation in serious cases. The industry ministry has its own version: industrial, telecom and radio data stored in China may not be given to foreign industry, telecom or radio enforcement agencies without ministry approval. (4) 'Important data' triggers the heaviest gate — a full government security review — but identification is largely self-assessed against national standard GB/T 43697-2024 and regional and sector catalogues that are still being published; the regulator's October 2025 Q&A confirmed the two-month window for reporting newly identified important data cannot be extended. (5) We could find no domestic storage requirement for personal financial information in the People's Bank of China's Financial Consumer Rights Protection Measures (in force 1 November 2020). The belief traces to a 2011 central bank notice and to a recommended, non-mandatory industry standard; the binding walls we could verify are for non-bank payment institutions and credit reporting agencies, not for banks generally. Bonus trap: hold data on more than one million people and you must file your privacy officer with the regulator; hold data on more than ten million and you must run a compliance audit at least every two years.
Sources
- Official sourceCyberspace Administration of ChinaData Security Law, articles 36 and 48 — no data to foreign judicial or law enforcement bodies without approval
cac.gov.cn
“非经中华人民共和国主管机关批准,境内的组织、个人不得向外国司法或者执法机构提供存储于中华人民共和国境内的数据。”
Link checked 18 August 2026
- Official sourceCyberspace Administration of ChinaPersonal Information Protection Law, articles 31, 39 and 41 — under-14 consent, separate consent for export, foreign authority requests
cac.gov.cn
“个人信息处理者处理不满十四周岁未成年人个人信息的,应当取得未成年人的父母或者其他监护人的同意。”
Link checked 18 August 2026
- Official sourceCyberspace Administration of ChinaPersonal Information Protection Compliance Audit Measures (order no. 18), in force 1 May 2025 — audit every two years above ten million people
cac.gov.cn
“应当每两年至少开展一次个人信息保护合规审计”
Link checked 18 August 2026
- Official sourceCyberspace Administration of ChinaData export security management policy Q&A, October 2025 — exemptions, employee data, important data reporting window
cac.gov.cn
Link checked 18 August 2026
What is changing soon in China?
The next twelve months are about size-based rules. A draft published on 7 August 2026 would create a heavy new tier for any company holding data on ten million people or more: store it in China, appoint a chief privacy officer, set up an outside supervision committee, publish an annual report and honour data portability requests within 30 working days. Comments closed on 7 September 2026 and it is not law yet. A companion draft going the other way would simplify life for small processors. Watch the dormant switches — several can flip with no consultation at all.
In the pipeline, none of it binding today: draft Provisions on Personal Information Protection by Large Personal Information Processors, published for comment 7 August 2026, comment window to 7 September 2026, with the ten-million-person trigger and an express domestic storage duty; draft Simplified Personal Information Protection Measures for Small Processors, 3 April 2026; draft Provisions on Personal Information Collection and Use by Internet Applications, 10 January 2026; draft Provisions on Personal Information Protection by Large Network Platforms, 22 November 2025. Already landed and now biting: the amended Cybersecurity Law from 1 January 2026, which raises the top fine to ten million yuan (about $1.4 million) and adds an artificial intelligence article; the certification route from 1 January 2026 with its national standard from 1 March 2026. DORMANT SWITCHES, which matter more than the drafts: the government can designate you a critical information infrastructure operator at any time, which instantly converts you from 'paperwork' to 'the data stays'; regional and sector 'important data' catalogues are still being issued and each one can pull a new dataset into the security-review gate; free trade zone negative lists are revised zone by zone and can grow as easily as shrink; and a security assessment approval is limited to the exact purpose, scope, method and categories declared, so a product change can silently void it.
Sources
- Official sourceCyberspace Administration of ChinaConsultation on the draft Provisions on Personal Information Protection by Large Personal Information Processors, 7 August 2026
cac.gov.cn
Link checked 18 August 2026
- Official sourceCyberspace Administration of ChinaConsultation on the draft Simplified Personal Information Protection Measures for Small Processors, 3 April 2026
cac.gov.cn
- Official sourceCyberspace Administration of ChinaCybersecurity Law as amended by the decision of 28 October 2025, in force 1 January 2026
cac.gov.cn
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
National rules
Added by this country on top of any bloc rules.
5 rules here
Layer 2
Industry rules
Made by an industry regulator. These usually beat the general position.
10 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
National rules5 rules
中华人民共和国个人信息保护法
Act of parliament · Personal Information Protection Law of the People's Republic of China
China's main privacy law, fully in force since 1 November 2021. It reaches foreign companies serving people in China, requires a named mechanism plus each person's separate consent before personal data leaves the country, and carries fines of up to 50 million yuan (about $7 million) or 5 percent of the previous year's turnover. One limb is dormant: the law orders large processors to store data in China once they pass a volume the regulator is meant to set, and that number has never been published.
Enforced by Cyberspace Administration of China
Transfer model: Approval each time · Accepted routes: Security review needed, Standard contract clauses, Certification scheme, Explicit consent
What it makes you do
- Get consent
- Tell people what you do
- Put a transfer safeguard in placeSeparate, specific consent is needed in addition to the transfer mechanism.
- Appoint a local representativeOverseas processors caught by the extraterritorial rule must set up an entity or name a representative in China.
- Get a parent's consent for children — applies at: under 14 years old
- Report breaches to the regulator
- Delete data after a period
- Do not hand data to foreign authorities on demandNo data to foreign judicial or law enforcement bodies without Chinese government approval.
What it costs if you get it wrong
- Fixed maximum fine: 50,000,000 CNY — about $7 millionSerious breach of the law
- Percentage of global turnover: 5% of prior-year turnoverSerious breach; applied as an alternative to the cash cap
- Order to stopOrder to suspend or terminate the service
Sources
- Official sourceCyberspace Administration of ChinaPersonal Information Protection Law — full text
cac.gov.cn
“关键信息基础设施运营者和处理个人信息达到国家网信部门规定数量的个人信息处理者,应当将在中华人民共和国境内收集和产生的个人信息存储在境内”
Link checked 18 August 2026
促进和规范数据跨境流动规定
Directly binding regulation · Provisions on Promoting and Regulating Cross-Border Data Flows
The rule that decides which gate you use. Fewer than 100,000 people's ordinary personal data a year needs no mechanism; between 100,000 and a million needs the standard contract or a certificate; above that, or any important data, needs a full government security review. Free trade zones can carve out their own exemptions through published negative lists.
Enforced by Cyberspace Administration of China
Transfer model: Approval each time · Accepted routes: Security review needed, Standard contract clauses, Certification scheme, Needed for a contract, Someone's life is at risk, Nothing required
What it makes you do
- Put a transfer safeguard in place — applies at: 100,000 to 1,000,000 people: standard contract or certification; above 1,000,000 people, above 10,000 sensitive records, any important data, or any transfer by a critical infrastructure operator: government security review
- Assess high-risk projectsA personal information protection impact assessment must accompany every route.
Sources
- Official sourceCyberspace Administration of ChinaProvisions on Promoting and Regulating Cross-Border Data Flows — full text
cac.gov.cn
Link checked 18 August 2026
- Official sourceCyberspace Administration of ChinaFree trade zone data export negative lists — official index
cac.gov.cn
Link checked 18 August 2026
中华人民共和国网络安全法(2025年修正)
Act of parliament · Cybersecurity Law, article 39 (domestic storage by critical information infrastructure operators), as amended 28 October 2025
If the government designates you critical national infrastructure, personal data and important data you collect in China must stay in China. A copy may go abroad only after passing a government security review. The amended law took effect on 1 January 2026 and raised the top fine to 10 million yuan (about $1.4 million).
Enforced by Cyberspace Administration of China
Transfer model: Approval each time · Accepted routes: Security review needed
What it makes you do
- Keep the data in the countryPersonal information and important data collected or generated in China must be stored in China.
- Keep logs — 6 months
- Secure the data
What it costs if you get it wrong
- Fixed maximum fine: 10,000,000 CNY — about $1 millionSecurity failures causing a critical infrastructure operator to lose its main functions
- Loss of your licenceSerious cases: suspension of business, closure of the website, or revocation of permits and licences
Sources
- Official sourceCyberspace Administration of ChinaCybersecurity Law as amended, article 39 and article 61 penalties
cac.gov.cn
“关键信息基础设施的运营者在中华人民共和国境内运营中收集和产生的个人信息和重要数据应当在境内存储。因业务需要,确需向境外提供的,应当按照国家网信部门会同国务院有关部门制定的办法进行安全评估”
Link checked 18 August 2026
网络数据安全管理条例
Directly binding regulation · Network Data Security Management Regulation, State Council order no. 790
The State Council rulebook that fills in the three data laws. It sets a 24-hour report for incidents that could harm national security or the public interest, requires important data to be identified and risk-assessed every year, and gates the outsourcing of government systems.
Enforced by Cyberspace Administration of China
Transfer model: Approval each time · Accepted routes: Security review needed, Standard contract clauses, Certification scheme, Needed for a contract
What it makes you do
- Report breaches to the regulator — within 24 hoursWhere the incident could harm national security or the public interest.
- Tell affected people
- Keep records of processingImportant data must be identified, catalogued and reported; annual risk assessment required.
- Written vendor contractState organs outsourcing e-government systems must follow a strict approval process, and the supplier may not touch the data without the commissioning body's consent.
Sources
- Official sourceState CouncilNetwork Data Security Management Regulation (State Council order no. 790) — full text
mee.gov.cn
Link checked 18 August 2026
- Official sourceCyberspace Administration of ChinaMinistry of Justice and Cyberspace Administration Q&A on the Network Data Security Management Regulation
cac.gov.cn
Link checked 18 August 2026
国家网络安全事件报告管理办法
Directly binding regulation · National Cybersecurity Incident Reporting Measures
The fastest clock in the system: one hour to report a serious incident if you run critical national infrastructure, two hours for central government bodies, four hours for everyone else. This rule imposes no storage-location requirement of its own. Reporting on time and following your incident plan can reduce or remove liability.
Enforced by Cyberspace Administration of China
What it makes you do
- Report cyber incidents — applies at: Critical information infrastructure operators — to the protecting department and public security, within 1 hour
- Report cyber incidents — applies at: All other network operators — to the provincial cyberspace office, within 4 hours
Sources
- Official sourceCyberspace Administration of ChinaNational Cybersecurity Incident Reporting Measures — full text
cac.gov.cn
“应当及时向属地省级网信部门报告,最迟不得超过4小时”
Link checked 18 August 2026
Industry rules10 rules
非银行支付机构监督管理条例
Directly binding regulation · Regulation on the Supervision and Administration of Non-Bank Payment Institutions, State Council order no. 768, articles 18 and 33 · Payments
Payment firms cannot run China from abroad. Their business systems and backups must sit inside China, and personal data collected in China must be processed in China. Sending it out needs both a legal basis and the user's separate consent.
Enforced by People's Bank of China
Transfer model: Approval each time · Accepted routes: Security review needed, Explicit consent
What it makes you do
- Keep the data in the countryBusiness systems and their backups must be located in China; personal information collected in China must be processed in China.
- Get consentSeparate user consent is required before any outbound provision.
Sources
- Official sourceState Council, republished by a municipal government portalRegulation on the Supervision and Administration of Non-Bank Payment Institutions (State Council order no. 768) — full text
pds.gov.cn
“非银行支付机构的业务系统及其备份应当存放在境内。”
Link checked 18 August 2026
- Official sourcePeople's Bank of ChinaRegulation on the Supervision and Administration of Non-Bank Payment Institutions — central bank's own copy
pbc.gov.cn
征信业务管理办法
Directly binding regulation · Credit Reporting Business Management Measures, People's Bank of China order [2021] no. 4, articles 39 and 40 · Finance
Credit bureaus must store all company and personal credit information they collect in China inside China. Sending personal credit information abroad has to follow the national data export rules, and company credit information can only go to a checked recipient for cross-border trade or investment.
Enforced by People's Bank of China
Transfer model: Approval each time · Accepted routes: Security review needed, Government sign-off needed
What it makes you do
- Keep the data in the countryCompany and personal credit information collected in China must be stored in China.
- Put a transfer safeguard in placeBefore releasing company credit information abroad the agency must check the recipient's identity and purpose and satisfy itself the use is for cross-border trade or investment.
Sources
- Official sourceState Council policy database / People's Bank of ChinaCredit Reporting Business Management Measures — full text
gov.cn
“征信机构在中华人民共和国境内开展征信业务及其相关活动,采集的企业信用信息和个人信用信息应当存储在中华人民共和国境内。”
Link checked 18 August 2026
中国人民银行业务领域数据安全管理办法
Directly binding regulation · Measures for Data Security Management in the Business Areas of the People's Bank of China, order [2025] no. 3, articles 22 and 24 · Banking
The central bank's own data rulebook, in force since 30 June 2025. If any other rule requires the data to be stored in China, sending a copy abroad does not release you from keeping one at home. Handing over the most sensitive category needs state approval, and splitting data up to dodge the threshold is banned.
Enforced by People's Bank of China
Transfer model: Approval each time · Accepted routes: Security review needed, Government sign-off needed
What it makes you do
- Keep the data in the countryWhere any law or central bank rule imposes a domestic storage requirement, a copy must remain in China even when the data is also sent abroad.
- Assess high-risk projectsRisk assessment before important data is handed to anyone else; core data transfers need approval through the national data security mechanism.
Sources
- Official sourcePeople's Bank of China, republished by a municipal government portalMeasures for Data Security Management in the Business Areas of the People's Bank of China — full text
home.wuhan.gov.cn
“法律、行政法规和中国人民银行相关规定有境内存储要求的,业务数据还应当同时在中华人民共和国境内存储。”
Link checked 18 August 2026
- Official sourcePeople's Bank of ChinaMeasures for Data Security Management in the Business Areas of the People's Bank of China — central bank's own page
pbc.gov.cn
银行保险机构数据安全管理办法
Directly binding regulation · Measures for Data Security Management by Banking and Insurance Institutions, articles 24, 36 and 60 · Insurance
This is the rule people misquote. Banks and insurers must run a security assessment before important data or personal information leaves China, and need the regulator's consent to collect industry-level important data from other institutions — but these measures contain no blanket order to keep banking data inside China.
Enforced by National Financial Regulatory Administration
Transfer model: Approval each time · Accepted routes: Security review needed, Government sign-off needed
What it makes you do
- Put a transfer safeguard in placeSecurity assessment under national policy before important data or personal information collected in China goes abroad.
- Tell people what you doIndividuals must be told how to exercise their rights against the overseas recipient.
Sources
- Official sourceNational Financial Regulatory Administration, State Council policy databaseMeasures for Data Security Management by Banking and Insurance Institutions — full text
gov.cn
“向境外提供在中华人民共和国境内运营中收集和产生的重要数据和个人信息,应当承担数据安全主体责任,并按照国家有关政策要求进行安全评估。”
Link checked 18 August 2026
- Official sourceNational Financial Regulatory AdministrationRegulator's Q&A on the Measures for Data Security Management by Banking and Insurance Institutions
gov.cn
Link checked 18 August 2026
关于加强境内企业境外发行证券和上市相关保密和档案管理工作的规定
Directly binding regulation · Provisions on Strengthening Confidentiality and Archives Administration Relating to Overseas Securities Offering and Listing by Domestic Enterprises (CSRC announcement no. 44 of 2023) · Securities
If a Chinese company lists abroad, the working papers behind the listing stay in China. A foreign securities regulator that wants to inspect them or take evidence has to go through the Chinese authorities rather than straight to the company or its auditor.
Enforced by China Securities Regulatory Commission
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryAudit and advisory working papers produced in China for an overseas listing must be kept in China.
- Do not hand data to foreign authorities on demandInspection or evidence-gathering by an overseas securities regulator must go through Chinese authorities.
Sources
- Official sourceChina Securities Regulatory Commission, Ministry of Finance, National Administration of State Secrets Protection, National Archives AdministrationProvisions on confidentiality and archives administration for overseas listings — issuing bodies and 31 March 2023 commencement
gov.cn
Link checked 18 August 2026
- Official sourceChina Securities Regulatory CommissionCSRC announcement no. 44 of 2023 — regulator's own publication page
csrc.gov.cn
Link checked 18 August 2026
国家健康医疗大数据标准、安全和服务管理办法(试行)
Government rules · National Health and Medical Big Data Standards, Security and Services Management Measures (Trial), document no. 23 of 2018, article 30 · Health and social care
Health and medical big data must be held on secure servers inside China. If the business genuinely needs to send it abroad, it goes through a security assessment first. This is a trial-status health ministry document rather than a full regulation, but it is the operative rule hospitals and health platforms are held to.
Enforced by National Health Commission
Transfer model: Approval each time · Accepted routes: Security review needed
What it makes you do
- Keep the data in the countryHealth and medical big data must sit on secure and trusted servers inside China.
- Put a transfer safeguard in placeSecurity assessment and review before any outbound provision.
Sources
- Official sourceNational Health Commission, republished by the Cyberspace Administration of ChinaNational Health and Medical Big Data Standards, Security and Services Management Measures (Trial), article 30
cac.gov.cn
“应当存储在境内安全可信的服务器上,因业务需要确需向境外提供的,应当按照相关法律法规及有关要求进行安全评估审核”
Link checked 18 August 2026
- Official sourceNational Health CommissionHealth ministry's own publication of the measures
nhc.gov.cn
人类遗传资源管理条例实施细则
Government rules · Implementing Rules for the Regulation on the Administration of Human Genetic Resources, Ministry of Science and Technology order no. 21, articles 36 and 37 · Health and social care
Genetic information about Chinese people cannot quietly leave. You file with the science ministry in advance, hand over a backup copy, and explain the risk to public health and national security. Anything covering important family lines, particular regions, or the genomes of more than 500 people goes to a full security review.
Enforced by Ministry of Science and Technology
Transfer model: Approval each time · Accepted routes: Government sign-off needed, Security review needed
What it makes you do
- Register or notifyAdvance filing with the science ministry, including a copy of the information being sent and a risk assessment.
- Put a transfer safeguard in placeSecurity review where public health, national security or the public interest could be affected.
What it costs if you get it wrong
- Order to stopProviding human genetic resource information abroad without the required filing or review
Sources
- Official sourceMinistry of Science and TechnologyImplementing Rules for the Regulation on the Administration of Human Genetic Resources — full text
most.gov.cn
“人数大于500例的外显子组测序、基因组测序信息资源”
Link checked 18 August 2026
地图管理条例
Directly binding regulation · Map Management Regulation, State Council order no. 664, article 34 · Mapping and location
Anyone providing an internet map service in China must keep the servers holding the map data inside China, and must have a written data security system to go with them. There is no paperwork route around this one.
Enforced by Ministry of Natural Resources
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryServers holding map data must be inside China.
- Secure the data
Sources
- Official sourceState Council GazetteMap Management Regulation (State Council order no. 664), article 34
gov.cn
“互联网地图服务单位应当将存放地图数据的服务器设在中华人民共和国境内,并制定互联网地图数据安全管理制度和保障措施。”
Link checked 18 August 2026
工业和信息化领域数据安全管理办法(试行)
Government rules · Administrative Measures for Data Security in the Field of Industry and Information Technology (Trial), document no. 166 of 2022, article 21 · Telecoms
Covers factory, telecom and radio data. Important and core data stays in China wherever another law requires it, and a security assessment is needed before it goes abroad. Handing such data to a foreign telecom or industry regulator without the Chinese ministry's approval is banned outright.
Enforced by Ministry of Industry and Information Technology
Transfer model: Approval each time · Accepted routes: Security review needed, Government sign-off needed
What it makes you do
- Keep the data in the countryImportant and core data must be stored in China wherever a law or administrative regulation says so.
- Do not hand data to foreign authorities on demandIndustry, telecom and radio data stored in China may not be given to a foreign industry, telecom or radio enforcement body without the industry ministry's approval.
Sources
- Official sourceMinistry of Industry and Information Technology, State Council policy databaseAdministrative Measures for Data Security in the Field of Industry and Information Technology (Trial), article 21
gov.cn
“非经工业和信息化部批准,工业和信息化领域数据处理者不得向外国工业、电信、无线电执法机构提供存储于中华人民共和国境内的工业和信息化领域数据。”
Link checked 18 August 2026
汽车数据出境安全指引(2026版)
Regulator guideline · Automotive Data Export Security Guidelines (2026 edition), issued jointly by eight departments · Mapping and location
Guidance published on 30 January 2026 by eight government departments telling carmakers and connected-vehicle platforms exactly how the national data export rules apply to vehicle data. It is guidance rather than binding law, but it is the reference the regulators will use.
Enforced by Ministry of Industry and Information Technology
Transfer model: Approval each time · Accepted routes: Security review needed, Standard contract clauses, Certification scheme
What it makes you do
- Put a transfer safeguard in placeSets out how carmakers and connected-vehicle platforms apply the national data export rules to vehicle data.
Sources
- Official sourceMinistry of Industry and Information Technology and seven other departmentsNotice issuing the Automotive Data Export Security Guidelines (2026 edition)
cac.gov.cn
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The volume threshold that triggers the storage-in-China duty in the privacy law for processors that are NOT critical infrastructure
The law says 'processors handling personal information reaching a quantity specified by the national internet regulator', but we could not find a published notification setting that number. Practitioners read it across from the one-million figure in the transfer rules; that reading is not confirmed by any government document we could open on 18 August 2026.
That personal financial information held by ordinary banks must be stored in China
This is very widely repeated. We read the central bank's Financial Consumer Rights Protection Measures (in force 1 November 2020) and found no such article; the banking and insurance data measures of December 2024 also contain no blanket storage duty. The claim appears to rest on a 2011 central bank notice and a recommended, non-binding industry standard, neither of which we could verify as current.
The exact number of free trade zones with a published data export negative list
The regulator's March 2026 statement names nine zones; its own negative-list index page also carries a Guangdong list dated 25 December 2025, which would make ten. We could not reconcile the two.
The article-level text of the overseas-listing confidentiality and archives rules
The government pages we could open confirm the issuing bodies and the 31 March 2023 commencement, but the operative text sits in a PDF attachment we could not retrieve. The rule is therefore marked medium confidence.
Whether accredited bodies are actually issuing cross-border personal information certificates in volume
The national standard took effect on 1 March 2026 and the certification centre's site lists accredited audit firms, but its pages blocked automated retrieval, so we could not verify how many export certificates have been issued.
The detailed content of the Automotive Data Export Security Guidelines (2026 edition)
The regulator's notice confirms the eight issuing departments and the 30 January 2026 date, but the substantive text is in a linked PDF we could not open.
Whether any additional data export rule was published between 1 and 18 August 2026
We checked the regulator's data governance index on 18 August 2026 and the most recent items were a policy Q&A of 12 August 2026 and the draft rules of 7 August 2026. We cannot prove a negative for unindexed items.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.