Promulgated by: Cyberspace Administration of China (CAC).
Document No.: None (published as an official policy and regulatory Q&A).
Published January 30, 2026.
Translation note — DCC. Translated in full from the official Chinese text published on the 网信中国 (Cyberspace China) WeChat channel on January 30, 2026. Terminology follows DCC’s bilingual glossary. The answers construe the Provisions on Promoting and Regulating Cross-border Data Flows and the two Greater Bay Area standard-contract implementing guidelines.
Policy and Regulatory Q&A on Data Export Security Management (January 2026)
The Cyberspace Administration of China continues to strengthen the promotion and explanation of the policies, laws and regulations on data export security management, and to guide and assist data processors in carrying out data export activities efficiently and in compliance. Having studied the consultation questions received recently, we now publish a number of representative questions and answers as follows.
Q1. How do the conclusion of a standard contract for the export of personal information, passing personal information export certification, and the declaration of a data export security assessment connect with one another?
A: Under the requirements of the Cybersecurity Law, the Personal Information Protection Law, the Regulations on Network Data Security Management, the Measures for Data Export Security Assessment, the Measures on Standard Contracts for the Export of Personal Information, the Provisions on Promoting and Regulating Cross-border Data Flows, the Measures for the Certification of Personal Information Export and other laws, administrative regulations and departmental rules, a data processor other than a critical information infrastructure operator that, cumulatively from January 1 of the current year, has provided abroad the personal information of 100,000 or more but fewer than 1 million individuals (excluding sensitive personal information), or the sensitive personal information of fewer than 10,000 individuals, may export personal information by concluding a standard contract for the export of personal information or by passing personal information export certification. If the data processor declares the foregoing personal information export matter for a data export security assessment, it shall carry out its personal information export activities in accordance with the result of the data export security assessment.
Where a data processor has concluded a standard contract for the export of personal information or has passed personal information export certification, but, cumulatively from January 1 of the current year, has exported the personal information of more than 1 million individuals (excluding sensitive personal information) or the sensitive personal information of more than 10,000 individuals, the data processor shall declare a data export security assessment to the national cyberspace administration through the provincial cyberspace administration of the place where it is located. When declaring the data export security assessment, the data processor shall include within the scope of the declared assessment the personal information exported since January 1 of the current year by way of a standard contract for the export of personal information or personal information export certification, and shall carry out its personal information export activities in accordance with the result of the data export security assessment.
Where a circumstance provided for in Article 3, Article 4, Article 5 or Article 6 of the Provisions on Promoting and Regulating Cross-border Data Flows applies, those provisions shall prevail.
Q2. Where a domestic data processor has concluded a Guangdong–Hong Kong–Macao Greater Bay Area standard contract for the cross-boundary flow of personal information and the circumstances of its personal information export subsequently change, how should it perform its compliance obligations?
A: A domestic data processor that has concluded and filed a Greater Bay Area standard contract for the cross-boundary flow of personal information shall carry out its cross-boundary data activities within the Greater Bay Area in accordance with the Implementing Guidelines for the Standard Contract for the Cross-boundary Flow of Personal Information in the Guangdong–Hong Kong–Macao Greater Bay Area (Mainland, Hong Kong) and the Implementing Guidelines for the Standard Contract for the Cross-boundary Flow of Personal Information in the Guangdong–Hong Kong–Macao Greater Bay Area (Mainland, Macao), and shall not unlawfully provide personal information to organizations or individuals outside the Greater Bay Area.
Where a domestic data processor that has filed a Greater Bay Area standard contract for the cross-boundary flow of personal information needs to provide personal information to organizations or individuals outside the Greater Bay Area, it shall, in accordance with the State’s provisions on data export security management, perform the compliance obligations applicable to the personal information it proposes to provide outside the Greater Bay Area — declaring a data export security assessment, concluding a standard contract for the export of personal information, or passing personal information export certification.
Source: 网信中国 (Cyberspace China) WeChat channel. Reviewed by Zhao Juan; edited by Wang Yutong; proofread by Mi Jiangxuan.