Skip to the content
Global Data RulesData governance rules, country by country

China

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Yes, with paperworkWork: Very highEnforcement: Active

Data can leave China, but only through one of three official gates: a government security review, a government-written contract you file with the regulator, or a certificate from an approved body. Which gate you need depends on how many people's data you move, not on where you send it. Small exporters are exempt. Several industries are walled off entirely.

Eight questions about China

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do China's rules apply to my company?

Yes. China's privacy law reaches a company with no office and no staff in China if it offers goods or services to people in China, or analyses their behaviour. There is no revenue or headcount threshold that lets you out. If you are caught this way, you must set up a dedicated office in China or name a representative there, and give the regulator their details.

High confidenceNational rulesAppoint a local representativeRegister or notify

Can I store my users' data outside China?

In general yes, once you clear the right gate — but the gate is set by volume, not by destination. China has no list of banned or approved countries. Below 100,000 people a year you can usually send data abroad with no filing at all. Above that you need a contract filed with the regulator or a certificate; above a million people, or if you hold data the state calls 'important', you need a full government security review. Then come the industry walls, which override all of this.

High confidenceYes, with paperworkApproval each timeSecurity review neededStandard contract clausesCertification scheme

What do I need in place before data leaves China?

Three routes, and you do not get to pick freely — your volume picks for you. Route one is a government security review, run by the national internet regulator through your provincial office; an approval lasts three years and only covers the exact purpose, scope and method you declared. Route two is China's own standard contract, which you sign with the overseas recipient and file with the provincial regulator along with a risk assessment. Route three is a certificate from an accredited body, which since 1 March 2026 has a national standard behind it. You also need each person's separate, specific consent before their data goes abroad.

High confidenceApproval each timeSecurity review neededStandard contract clausesCertification schemeExplicit consentNeeded for a contract

Who enforces the rules in China, and what can they do?

The Cyberspace Administration of China leads, and it is fully staffed and busy. It runs a nationwide enforcement campaign every year, tests apps itself and publishes the names of the ones that fail, and puts out batches of worked enforcement cases. Police, the industry ministry and the market regulator enforce alongside it, and finance, health, mapping and securities regulators run their own rules. Fines are usually modest and paired with an order to fix things; the eye-watering penalties in the statute are rarely used.

High confidenceActive

How long do I have to keep the data?

Both directions apply, and they pull against each other. The floor: network logs must be kept for at least six months, and accounting records have their own long minimum periods set by a national schedule. The ceiling: personal data may only be kept for the shortest time needed for the purpose you collected it for, and must be deleted once that purpose is met, the service ends, or consent is withdrawn. Where a law sets a minimum, that minimum wins over the delete duty — you keep the record and stop using it for anything else.

High confidenceKeep data for a minimum periodDelete data after a periodKeep logs

What happens if there is a breach?

Three clocks, and they overlap. If you run critical national infrastructure you have ONE HOUR to report a serious incident to your supervising department and the police. Everyone else has four hours to tell the provincial internet office. On top of that, a network data incident that could harm national security or the public interest must be reported within 24 hours. You must also tell affected people immediately, by phone, text, message, email or public notice.

High confidenceReport cyber incidentsReport breaches to the regulatorTell affected people

What trips people up in China?

Five things that ruin weekends. (1) Sending data abroad needs each person's separate, specific consent — a line buried in a global privacy notice will not do. (2) A child is anyone under 14, and their data is treated as sensitive, so you need a parent's consent and a separate set of processing rules. (3) You may not hand data stored in China to a foreign court, police force or regulator without Chinese government approval — this catches routine legal discovery and overseas audit requests. (4) You have to work out for yourself whether you hold 'important data' and report it, because the official catalogues are incomplete. (5) The widely repeated claim that all personal financial data must be stored in China does not appear where people think it does.

High confidenceGet a parent's consent for childrenDo not hand data to foreign authorities on demandIndependent auditAppoint a data protection officerCriminal liability

What is changing soon in China?

The next twelve months are about size-based rules. A draft published on 7 August 2026 would create a heavy new tier for any company holding data on ten million people or more: store it in China, appoint a chief privacy officer, set up an outside supervision committee, publish an annual report and honour data portability requests within 30 working days. Comments closed on 7 September 2026 and it is not law yet. A companion draft going the other way would simplify life for small processors. Watch the dormant switches — several can flip with no consultation at all.

High confidenceProposedDraft law

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    National rules

    Added by this country on top of any bloc rules.

    5 rules here

  2. Layer 2

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    10 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

National rules5 rules

中华人民共和国个人信息保护法

Act of parliament · Personal Information Protection Law of the People's Republic of China

In forceYes, with paperwork

China's main privacy law, fully in force since 1 November 2021. It reaches foreign companies serving people in China, requires a named mechanism plus each person's separate consent before personal data leaves the country, and carries fines of up to 50 million yuan (about $7 million) or 5 percent of the previous year's turnover. One limb is dormant: the law orders large processors to store data in China once they pass a volume the regulator is meant to set, and that number has never been published.

In force since 1 November 2021

Enforced by Cyberspace Administration of China

Transfer model: Approval each time · Accepted routes: Security review needed, Standard contract clauses, Certification scheme, Explicit consent

High confidence

促进和规范数据跨境流动规定

Directly binding regulation · Provisions on Promoting and Regulating Cross-Border Data Flows

In forceYes, with paperwork

The rule that decides which gate you use. Fewer than 100,000 people's ordinary personal data a year needs no mechanism; between 100,000 and a million needs the standard contract or a certificate; above that, or any important data, needs a full government security review. Free trade zones can carve out their own exemptions through published negative lists.

In force since 22 March 2024

Enforced by Cyberspace Administration of China

Transfer model: Approval each time · Accepted routes: Security review needed, Standard contract clauses, Certification scheme, Needed for a contract, Someone's life is at risk, Nothing required

High confidence

中华人民共和国网络安全法(2025年修正)

Act of parliament · Cybersecurity Law, article 39 (domestic storage by critical information infrastructure operators), as amended 28 October 2025

In forceA copy must stay

If the government designates you critical national infrastructure, personal data and important data you collect in China must stay in China. A copy may go abroad only after passing a government security review. The amended law took effect on 1 January 2026 and raised the top fine to 10 million yuan (about $1.4 million).

In force since 1 June 2017But only enforceable from 1 January 2026

Enforced by Cyberspace Administration of China

Transfer model: Approval each time · Accepted routes: Security review needed

High confidence

Industry rules10 rules

非银行支付机构监督管理条例

Directly binding regulation · Regulation on the Supervision and Administration of Non-Bank Payment Institutions, State Council order no. 768, articles 18 and 33 · Payments

In forceA copy must stay

Payment firms cannot run China from abroad. Their business systems and backups must sit inside China, and personal data collected in China must be processed in China. Sending it out needs both a legal basis and the user's separate consent.

In force since 1 May 2024

Enforced by People's Bank of China

Transfer model: Approval each time · Accepted routes: Security review needed, Explicit consent

High confidence

征信业务管理办法

Directly binding regulation · Credit Reporting Business Management Measures, People's Bank of China order [2021] no. 4, articles 39 and 40 · Finance

In forceA copy must stay

Credit bureaus must store all company and personal credit information they collect in China inside China. Sending personal credit information abroad has to follow the national data export rules, and company credit information can only go to a checked recipient for cross-border trade or investment.

In force since 1 January 2022

Enforced by People's Bank of China

Transfer model: Approval each time · Accepted routes: Security review needed, Government sign-off needed

High confidence

中国人民银行业务领域数据安全管理办法

Directly binding regulation · Measures for Data Security Management in the Business Areas of the People's Bank of China, order [2025] no. 3, articles 22 and 24 · Banking

In forceA copy must stay

The central bank's own data rulebook, in force since 30 June 2025. If any other rule requires the data to be stored in China, sending a copy abroad does not release you from keeping one at home. Handing over the most sensitive category needs state approval, and splitting data up to dodge the threshold is banned.

In force since 30 June 2025

Enforced by People's Bank of China

Transfer model: Approval each time · Accepted routes: Security review needed, Government sign-off needed

High confidence

Who you would hear from

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The volume threshold that triggers the storage-in-China duty in the privacy law for processors that are NOT critical infrastructure

    The law says 'processors handling personal information reaching a quantity specified by the national internet regulator', but we could not find a published notification setting that number. Practitioners read it across from the one-million figure in the transfer rules; that reading is not confirmed by any government document we could open on 18 August 2026.

  • That personal financial information held by ordinary banks must be stored in China

    This is very widely repeated. We read the central bank's Financial Consumer Rights Protection Measures (in force 1 November 2020) and found no such article; the banking and insurance data measures of December 2024 also contain no blanket storage duty. The claim appears to rest on a 2011 central bank notice and a recommended, non-binding industry standard, neither of which we could verify as current.

  • The exact number of free trade zones with a published data export negative list

    The regulator's March 2026 statement names nine zones; its own negative-list index page also carries a Guangdong list dated 25 December 2025, which would make ten. We could not reconcile the two.

  • The article-level text of the overseas-listing confidentiality and archives rules

    The government pages we could open confirm the issuing bodies and the 31 March 2023 commencement, but the operative text sits in a PDF attachment we could not retrieve. The rule is therefore marked medium confidence.

  • Whether accredited bodies are actually issuing cross-border personal information certificates in volume

    The national standard took effect on 1 March 2026 and the certification centre's site lists accredited audit firms, but its pages blocked automated retrieval, so we could not verify how many export certificates have been issued.

  • The detailed content of the Automotive Data Export Security Guidelines (2026 edition)

    The regulator's notice confirms the eight issuing departments and the 30 January 2026 date, but the substantive text is in a linked PDF we could not open.

  • Whether any additional data export rule was published between 1 and 18 August 2026

    We checked the regulator's data governance index on 18 August 2026 and the most recent items were a policy Q&A of 12 August 2026 and the draft rules of 7 August 2026. We cannot prove a negative for unindexed items.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.