CAC explains China’s data-export certification and security-assessment routes
Key Takeaways
- 01The CAC issued guidance on 11 September 2026 on compliance mechanisms for exporting personal information from China.
- 02Personal-information protection certification is available for eligible cross-border transfers, but it does not displace a security assessment where that assessment is mandatory.
- 03Certification may be considered by the CAC during a required data-export security assessment.
- 04Organisations transferring data overseas should assess each outbound flow against China’s certification and security-assessment requirements.
China’s Cyberspace Administration (CAC) published policy guidance on 11 September 2026 addressing the compliance routes for exporting personal information from China. The guidance explains when organisations may use personal-information protection certification, when they must undergo a CAC data-export security assessment, and how certification may be treated during that assessment.
The clarification is relevant to organisations that transfer personal information outside mainland China, including multinational groups moving employee, customer, user, or other personal data to overseas affiliates or service providers. China’s cross-border data-transfer regime can require different mechanisms depending on the type and volume of data involved and the exporter’s status.
The CAC guidance confirms that certification is one available route for eligible personal-information exports. However, it does not replace a mandatory security assessment where an export falls within the statutory assessment thresholds or other circumstances requiring CAC review. Organisations subject to an assessment should therefore not assume that obtaining certification alone permits the transfer.
Certification may nevertheless be considered in the security-assessment process. This gives certified organisations a potential way to demonstrate elements of their data-protection governance and transfer safeguards, while leaving the CAC’s assessment requirement and substantive review in place.
Businesses planning or continuing overseas transfers should map their outbound data flows, identify whether they involve personal information or other regulated data, determine whether CAC security-assessment thresholds are triggered, and assess whether certification is an available supplementary or alternative transfer mechanism. The practical effect will depend on the final classification and scale of each transfer.