---
title_en: "Policy Q&A on Data Export Security Management (October 2025)"
title_zh: "数据出境安全管理政策问答（2025年10月）"
abbreviation: "CAC Data Export Q&A (Oct 2025)"
hierarchy: "handbook"
issuing_body: "Cyberspace Administration of China (CAC)"
adopted_date: 2025-10-31
effective_date: 2025-10-31
status: "effective"
source_url: "https://www.cac.gov.cn/2025-10/31/c_1763633376984070.htm"
related_laws: ["cross-border-data-flows-provisions", "data-export-security-assessment-measures", "data-export-assessment-declaration-guide-v3", "personal-info-standard-contract-measures", "cross-border-pi-certification-measures", "pi-protection-certification-announcement", "gbt-46068-cross-border-pi-certification-requirements", "network-data-security-regulations", "gba-hongkong-cross-border-pi-standard-contract-guidelines", "pipl", "cac-data-export-qa-2025-04", "cac-data-export-qa-2025-05", "cac-data-export-qa-2026-01", "cac-data-export-qa-2026-07", "cac-pi-protection-qa-2026"]
domains: ["cross-border", "personal-information"]
url: https://datacompliancechina.com/laws/cac-data-export-qa-2025-10/
summary: "Published by the Cyberspace Administration of China on October 31, 2025, the third and longest batch (ten answers) works through the practical edges of the 2024 Cross-border Data Flows Provisions and the SCC Measures. It reads the 'etc.' in the Art. 5 contract-performance exemption as open-ended but subject to two cumulative conditions; rules that a domestic guest booking a domestic hotel is not an exempt scenario; explains that employee ID, passport and bank-account exports under the HR exemption must pass a scenario-specific necessity test; declines to extend the 2-month post-notification deadline for important-data assessments but suggests preparing materials in parallel; clarifies that 'abroad' in the Declaration Guidelines (Third Edition) means the access act occurs abroad, so overseas staff querying domestic data while in China is not an export; confirms that system upgrades alone do not trigger re-assessment under Art. 14; allows a single SCC filing per overseas recipient based on a reasonable annual volume forecast, with escalation to assessment once the January 1 cumulative thresholds are reached; explains when new scenarios require a fresh PIPIA and a supplementary or re-signed SCC; points to Appendix I (6) for onward transfers to overseas third parties; and names the November 2022 Certification Announcement and GB/T 46068-2025 as the reference bases for certification under the new Certification Measures."
---

> **Source: Data Compliance China** — https://datacompliancechina.com/laws/cac-data-export-qa-2025-10/ · English rendering and annotations by DCC; the Chinese original governs. Cite as: Data Compliance China, "Policy Q&A on Data Export Security Management (October 2025)", https://datacompliancechina.com/laws/cac-data-export-qa-2025-10/
**Promulgated by:** Cyberspace Administration of China (CAC).  
**Document No.:** None (published as an official policy Q&A).  
**Published October 31, 2025.**

> *Translation note — DCC. Translated in full from the official Chinese text
> published by the CAC on cac.gov.cn and on the 网信中国 (Cyberspace China)
> WeChat channel (October 31, 2025). Terminology follows DCC's bilingual
> glossary. The answers construe the
> [Provisions on Promoting and Regulating Cross-border Data Flows](/laws/cross-border-data-flows-provisions/)
> and the [SCC Measures](/laws/personal-info-standard-contract-measures/).*

---

The Cyberspace Administration of China continues to strengthen the dissemination of data export security management policy, guiding and helping data handlers carry out data export activities efficiently and in compliance. Having studied the inquiries received recently, it hereby publishes a number of representative questions and answers as follows.

**Q1.** The Provisions on Promoting and Regulating Cross-border Data Flows specify exempt scenarios such as "cross-border shopping, cross-border delivery, ..., examination services, etc." How should the word "etc." (等) be accurately understood?

**A:** Item (1) of paragraph 1 of Article 5 of the Provisions on Promoting and Regulating Cross-border Data Flows provides that "where it is genuinely necessary to provide personal information abroad in order to conclude or perform a contract to which the individual is a party, such as cross-border shopping, cross-border delivery, cross-border remittance, cross-border payment, cross-border account opening, air ticket and hotel booking, visa processing, examination services, etc.", the provision is exempt from security assessment, conclusion of a contract or certification. The word "etc." here is to be understood as meaning that the situations that may fall within the exemption are not limited to those listed above.

It should be noted, however, that an exempt scenario must satisfy two conditions at the same time:

1) the provision is for the conclusion or performance of a contract to which the individual is a party; and

2) it is genuinely necessary to provide the personal information abroad; here the scope of the minimum necessary personal information may be judged by reference to the relevant laws, regulations, rules, normative documents, national standards and the actual export scenario.

At the same time, under Article 10 of the Provisions on Promoting and Regulating Cross-border Data Flows, a data handler providing personal information abroad shall, in accordance with the provisions of laws and administrative regulations, fulfill obligations such as giving notice, obtaining the individual's separate consent and conducting a personal information protection impact assessment.

**Q2.** In the hotel industry, does the data of "a domestic individual booking a domestic hotel" fall within the exempt scenarios of Article 5 of the Provisions on Promoting and Regulating Cross-border Data Flows?

**A:** Under Article 5 of the Provisions on Promoting and Regulating Cross-border Data Flows, a hotel enterprise's export of personal information when a domestic individual books a domestic hotel does not fall within the circumstance of "genuinely needing to provide personal information abroad in order to conclude or perform a contract to which the individual is a party", and is not exempt from declaring a data export security assessment, concluding a standard contract for the export of personal information or passing personal information protection certification.

**Q3.** Does providing employees' identity card, passport and bank account information abroad fall within the exemption for "implementing cross-border human resources management in accordance with labor rules and regulations formulated according to law and a collective contract concluded according to law, where it is genuinely necessary to provide employees' personal information abroad"?

**A:** Under item (2) of paragraph 1 of Article 5 of the Provisions on Promoting and Regulating Cross-border Data Flows, the circumstance of "implementing cross-border human resources management in accordance with labor rules and regulations formulated according to law and a collective contract concluded according to law, where it is genuinely necessary to provide employees' personal information abroad" is exempt from declaring a data export security assessment, concluding a standard contract for the export of personal information or passing personal information protection certification. Where a data handler processes personal information that is necessary for implementing human resources management, it must do so in accordance with labor rules and regulations formulated according to law and a collective contract concluded according to law. The relevant provisions and agreements in the labor rules and regulations and the collective contract shall comply with the principles and rules for the processing of personal information, and in particular shall conform to the principles of necessity, clear purpose and minimized processing; only personal information directly related to the purpose of implementing human resources management may be processed, in the manner that has the least impact on individual rights and interests. Whether employee personal information such as identity cards, passports and bank accounts falls within the scope of what is "genuinely necessary" shall be judged specifically from the above perspectives.

**Q4.** After being notified that it holds "important data", a data handler must declare a data export security assessment to the national cyberspace administration through the provincial-level cyberspace administration of its locality within two months. Can more time and flexibility be provided?

**A:** After a data handler has been notified that it holds important data, or the data it holds has been publicly released as important data, if it needs to continue the relevant data export activities, it shall, within 2 months of being notified or of the public release, declare a data export security assessment to the national cyberspace administration through the provincial-level cyberspace administration of its locality. Where the export scenario is highly complex and preparing the assessment materials takes a long time, data handlers are advised, during the period in which important data is being identified and determined, to sort out their business scenarios in parallel and prepare the relevant declaration materials, and, once the important data has been determined and notified, to promptly declare a data export security assessment according to procedure.

**Q5.** In the Guidelines for the Declaration of Data Export Security Assessment (Third Edition), what does "abroad" (境外) mean in the phrase "data collected and generated by the data handler is stored within the territory, and institutions, organizations or individuals abroad can query, retrieve, download or export it"?

**A:** "Abroad" in "data collected and generated by the data handler is stored within the territory, and institutions, organizations or individuals abroad can query, retrieve, download or export it" means that the act of accessing or calling the data takes place abroad. Where staff of an overseas institution or organization, while within the territory, query, retrieve, download or export data that the data handler stores within the territory, without transmitting the data abroad, this does not constitute a data export activity.

**Q6.** Where the data export scenario and the recipient remain unchanged but the system may be upgraded or replaced, does the data handler need to re-declare a data export security assessment?

**A:** Under Article 14 of the Measures for the Security Assessment of Data Export, where any of the following circumstances arises within the validity period, the data handler shall re-declare for assessment: (1) a change in the purpose, method, scope or type of the data provided abroad, or in the purpose or method of the overseas recipient's processing of the data, that affects the security of the exported data, or an extension of the period for which personal information and important data are retained abroad; (2) a change in the data security protection policies and regulations or the cybersecurity environment of the country or region where the overseas recipient is located, the occurrence of other force majeure circumstances, a change in the actual control of the data handler or the overseas recipient, or an amendment of the legal documents between the data handler and the overseas recipient, that affects the security of the exported data; (3) other circumstances that affect the security of the exported data.

Where a data handler adjusts the systems related to the data export, it must make a judgment in accordance with the relevant provisions; if none of the above circumstances has arisen, there is no need to re-declare a data export security assessment.

**Q7.** Where a personal information handler's business activities involve the continuous export of personal information, does it need to file the standard contract for the export of personal information multiple times?

**A:** Where a personal information handler's business activities involve only the same overseas recipient, and the expected annual volume of personal information exported meets the prescribed conditions for concluding a standard contract, it may file the contract once on the basis of a reasonable forecast of the volume of personal information to be exported. If the cumulative volume of personal information exported since January 1 of the current year reaches the prescribed conditions for declaring a data export security assessment, the personal information handler shall declare a security assessment to the Cyberspace Administration of China through the provincial-level cyberspace administration of its locality.

**Q8.** After a personal information handler has completed the filing of the standard contract for the export of personal information, in what circumstances must it conclude a new standard contract, and how should it handle a small number of new personal information export scenarios that arise from business development after the filing is completed?

**A:** Article 8 of the Measures on the Standard Contract for the Outbound Transfer of Personal Information provides: "Where any of the following circumstances arises within the validity period of the standard contract, the personal information handler shall conduct a new personal information protection impact assessment, supplement or re-conclude the standard contract, and complete the corresponding filing formalities: (1) a change in the purpose, scope, type, sensitivity, method or storage location of the personal information provided abroad, or in the purpose or method of the overseas recipient's processing of the personal information, or an extension of the period for which the personal information is retained abroad; (2) a change in the personal information protection policies and regulations of the country or region where the overseas recipient is located, or other circumstances that may affect personal information rights and interests; (3) other circumstances that may affect personal information rights and interests."

After filing has been completed, if a newly added personal information export scenario falls within any of the above circumstances, the handler shall conduct a new personal information protection impact assessment, supplement or re-conclude the standard contract, and fulfill the filing obligation.

**Q9.** May the overseas recipient onward-provide to an overseas third party personal information that the personal information handler exported by concluding the standard contract for the export of personal information?

**A:** If the overseas recipient needs to provide to an overseas third party personal information that the personal information handler exported by concluding the standard contract for the export of personal information, the personal information handler and the overseas recipient shall, when concluding the standard contract for the export of personal information, state this in part "(6) The overseas recipient will provide personal information only to the following third parties outside the People's Republic of China (if applicable)" of Appendix I, "Description of the Export of Personal Information", of the standard contract template.

**Q10.** After the Measures for the Certification of the Cross-border Provision of Personal Information take effect, what are the main bases and standards to which the relevant certification refers?

**A:** The main bases and standards to which certification bodies refer in conducting certification of the cross-border provision of personal information (个人信息出境认证), and to which the relevant enterprises refer in applying for such certification, are the Announcement on the Implementation of Personal Information Protection Certification published in November 2022 and the national standard Data Security Technology — Security Certification Requirements for Cross-Border Processing of Personal Information (GB/T 46068-2025). In addition, in implementing the provisions of the Measures for the Certification of the Cross-border Provision of Personal Information, the Cyberspace Administration of China will publicly announce the relevant professional certification bodies according to procedure; for the specific announcements, please follow the China Cyberspace website (中国网信网) in a timely manner.
