Money & workIdea 10 · 4 min read

Do not send user information abroad casually: cross-border transfers have legal conditions and numerical thresholds

Grade A evidenceValue: Moderate
In plain language

Sending information about mainland users to an overseas server is a cross-border transfer. Hosting the website overseas does not change that. China's Personal Information Protection Law provides routes through a cyberspace authority security assessment, professional certification, a standard contract, or another legally specified condition. Where the law requires it, tell users who receives their information abroad and why, and obtain separate consent for the transfer.

MoneyNo cost
TimeSome time
EffortLittle effort

What it takes

Keeping relevant user data in mainland China can simplify the arrangement. If transfer is necessary, assess the applicable contract, certification, assessment, or exemption route; these steps may entail implementation costs despite the source's zero-cost label.

What you may gain

Providing personal information to an overseas company or storing it on an overseas server is provision of personal information abroad. The law lists four qualifying routes: a security assessment organized by the cyberspace authorities, personal information protection certification by a professional body, a contract with the overseas recipient using the prescribed standard terms, or another condition specified by laws and administrative regulations. Users must be informed of the recipient's name and contact details, purpose and method of processing, categories of information, and how to exercise their rights, with separate consent as required by the cited provisions. For processors that are not critical information infrastructure operators, the 2024 rules exempt transfers of fewer than 100,000 people's nonsensitive personal information, cumulatively from January 1 of the current year, from security assessment, standard contract, and certification requirements. For at least 100,000 but fewer than 1 million people, the cited nonsensitive-information route requires a standard contract or certification. At least 1 million people's personal information, or at least 10,000 people's sensitive personal information, triggers security assessment, subject to the rules' applicable exemptions. These thresholds are Chinese rules introduced in March 2024.

Context & considerations

A mainland user registering with a site that sends their information overseas still involves a cross-border transfer. Certain necessary transfers for concluding or performing a contract to which the individual is a party, such as cross-border shopping, deliveries, flights, or hotels, are exempt from the three assessment, certification, and standard-contract mechanisms. Counts run cumulatively from January 1, not over a rolling twelve months. The source's threshold summary does not fully set out the treatment of sensitive information below 10,000 people; do not assume the under-100,000 exemption covers sensitive information. Exemption from these mechanisms is also not a blanket exemption from other personal-information duties.

Research & references

Standing Committee of the National People's Congress (2021). Personal Information Protection Law, Articles 38, 39, and 40. https://www.spp.gov.cn/spp/fl/202108/t20210820_527244.shtml; Cyberspace Administration of China (2024). Provisions on Promoting and Regulating Cross-border Data Flows, Order No. 16, Articles 3, 4, 5, 7, and 8. https://www.gov.cn/gongbao/2024/issue_11366/202405/content_6954192.html; Cyberspace Administration of China (2022). Measures for Security Assessment of Data Exports, Order No. 11, Article 4. https://www.cac.gov.cn/2022-07/07/c_1658811536396503.htm