---
title_en: "Policy and Regulatory Q&A on Data Export Security Management (July 2026)"
title_zh: "数据出境安全管理政策法规问答（2026年7月）"
abbreviation: "CAC Data Export Q&A (Jul 2026)"
hierarchy: "handbook"
issuing_body: "Cyberspace Administration of China (CAC)"
adopted_date: 2026-07-24
effective_date: 2026-07-24
status: "effective"
related_laws: ["cross-border-data-flows-provisions", "data-export-security-assessment-measures", "data-export-assessment-declaration-guide-v3", "personal-info-standard-contract-measures", "cross-border-pi-certification-measures", "gbt-42574-notification-consent-guide", "pipl", "cac-data-export-qa-2025-04", "cac-data-export-qa-2025-05", "cac-data-export-qa-2025-10", "cac-data-export-qa-2026-01", "cac-pi-protection-qa-2026"]
domains: ["cross-border", "personal-information"]
url: https://datacompliancechina.com/laws/cac-data-export-qa-2026-07/
summary: "Published by the Cyberspace Administration of China on July 24, 2026, this batch answers three practitioner questions. On notice and separate consent for personal information exports, it restates PIPL Articles 39 and 30 (overseas recipient identity and contact details, purpose, method, categories, and how individuals exercise rights against the recipient; for sensitive personal information, also necessity and impact), rules that separate consent must be specific and unbundled — no blanket authorization — and points to GB/T 42574-2023 for signature, pop-up or email/SMS mechanics, while confirming that the Article 13(2)–(7) lawful bases dispense with consent but not with notice. On extending a security-assessment result, it lists the six cumulative conditions from the Declaration Guidelines (Third Edition): unchanged purpose and scope, unchanged parties, no more than a 20% increase in individuals or in important-data volume over the coming three years against the prior approval, compliant legal documents under Article 9 of the Assessment Measures, and three years of compliant operation without a major data security incident, with the application filed within 60 working days before expiry. On recruitment, it holds that sending domestic candidates' résumés to an overseas headquarters is not necessary unless the overseas entity actually participates in hiring decisions, and even then only for the minimum number of candidates and data fields, routed through assessment, SCC or certification with separate consent and a PIPIA."
---

> **Source: Data Compliance China** — https://datacompliancechina.com/laws/cac-data-export-qa-2026-07/ · English rendering and annotations by DCC; the Chinese original governs. Cite as: Data Compliance China, "Policy and Regulatory Q&A on Data Export Security Management (July 2026)", https://datacompliancechina.com/laws/cac-data-export-qa-2026-07/
**Promulgated by:** Cyberspace Administration of China (CAC).  
**Document No.:** None (published as an official policy and regulatory Q&A).  
**Published July 24, 2026.**

> *Translation note — DCC. Translated in full from the official Chinese text
> published on the 网信中国 (Cyberspace China) WeChat channel on July 24,
> 2026. Terminology follows DCC's bilingual glossary. The second answer
> quotes Article 9 of the
> [Provisions on Promoting and Regulating Cross-border Data Flows](/laws/cross-border-data-flows-provisions/)
> and the extension conditions of the
> [Declaration Guidelines (Third Edition)](/laws/data-export-assessment-declaration-guide-v3/).*

---

# Policy and Regulatory Q&A on Data Export Security Management (July 2026)

The Cyberspace Administration of China continues to strengthen the promotion and explanation of the policies, laws and regulations on data export security management, and to guide and assist data processors in carrying out data export activities efficiently and in compliance. Having studied the consultation questions received recently, we now publish a number of representative questions and answers as follows.

**Q1.** When a personal information handler provides personal information abroad, how should it effectively perform its obligations of notice and consent?

**A:** Under Article 39 of the Personal Information Protection Law, a personal information handler that provides personal information outside the territory of the People's Republic of China shall perform the obligations of giving notice and obtaining the individual's separate consent. The notice shall cover the name or personal name of the overseas recipient, its contact details, the purpose of processing, the method of processing, the categories of personal information, and the means and procedures by which the individual may exercise against the overseas recipient the rights provided for in that Law. At the same time, under Article 30 of the Personal Information Protection Law, if the personal information provided abroad is sensitive personal information, the handler shall also inform the individual of the necessity of exporting the sensitive personal information and of the impact on the individual's rights and interests.

When a personal information handler obtains an individual's separate consent to the export of personal information, the consent shall be specific and explicit; it shall not be bundled with other personal information processing activities, and consent shall not be obtained by way of a "blanket" authorization. The manner of obtaining separate consent may follow GB/T 42574-2023, *Information Security Technology — Implementation Guidelines for Notice and Consent in Personal Information Processing*, using written signature, pop-up confirmation, reply by email or SMS, and similar methods. Where a personal information export activity falls within the circumstances set out in items (2) to (7) of paragraph 1 of Article 13 of the Personal Information Protection Law, the individual's consent is not required, but the obligation to give notice of the personal information export shall still be performed.

**Q2.** Where a data export security assessment has been passed, what conditions must be met to apply for an extension of the validity period of the assessment result?

**A:** Article 9 of the Provisions on Promoting and Regulating Cross-border Data Flows provides: "The result of a data export security assessment that has been passed is valid for three years, calculated from the date on which the assessment result is issued. Where, on expiry of the validity period, the data processor needs to continue carrying out data export activities and no circumstance requiring a fresh declaration of a data export security assessment has arisen, the data processor may, within 60 working days before the expiry of the validity period, apply to the national cyberspace administration through the provincial cyberspace administration of the place where it is located for an extension of the validity period of the assessment result. With the approval of the national cyberspace administration, the validity period of the assessment result may be extended by three years."

Under the Guidelines for the Declaration of Data Export Security Assessment (Third Edition), an application to extend the validity period of an assessment result shall satisfy all of the following conditions at the same time: first, the purpose, scope and other particulars of the data export have not changed; second, the data processor, the overseas recipient and the other parties have not changed; third, where personal information is exported, the increase in the number of natural persons involved over the coming three years does not exceed 20% of the export volume approved by the original assessment result for the preceding three years; fourth, where important data is exported, the increase in the scale of data exported over the coming three years does not exceed 20% of the scale of data export approved by the original assessment result for the preceding three years; fifth, the legal documents concluded with the overseas recipient comply with Article 9 of the Measures for Data Export Security Assessment; and sixth, the data export activities over the preceding three years have been carried out strictly in compliance with the notice of the assessment result, and no major data security incident has occurred.

**Q3.** In a recruitment scenario, how should the necessity of exporting the résumés of domestic job applicants be judged?

**A:** Article 6 of the Personal Information Protection Law provides: "The processing of personal information shall have a clear and reasonable purpose, shall be directly related to the purpose of processing, and shall adopt the method that has the least impact on the rights and interests of individuals. The collection of personal information shall be limited to the minimum scope necessary to achieve the purpose of processing, and personal information shall not be collected excessively." Article 5 of the Measures for Data Export Security Assessment, Article 5 of the Measures on Standard Contracts for the Export of Personal Information and Article 6 of the Measures for the Certification of Personal Information Export make clear that a personal information handler shall assess the necessity of the personal information export before providing personal information abroad.

In a recruitment scenario, where the résumés and other personal information of domestic job applicants are to be provided to an overseas group headquarters or affiliated institution, necessity shall be judged by reference to the degree of connection between the export activity and the recruitment matter, the number of natural persons involved, and the range of personal information data items exported. If the overseas headquarters or affiliated institution does not participate in the hiring decisions concerning domestic applicants, the data export lacks necessity. If the overseas headquarters or affiliated institution participates directly in the hiring decisions concerning domestic applicants, the number of applicants whose information is exported shall be the minimum needed for the overseas decision-making, and the personal information data items exported shall be the minimum scope needed for the overseas decision-making; the relevant personal information export activity shall be carried out in compliance with the Provisions on Promoting and Regulating Cross-border Data Flows by declaring a data export security assessment, concluding a standard contract for the export of personal information, or passing personal information export certification, and the handler shall, in accordance with laws and administrative regulations, give notice and obtain the individual's separate consent and conduct a personal information protection impact assessment.

*Source: 网信中国 (Cyberspace China) WeChat channel. Reviewed by Zhao Juan; edited by Yang Xi; proofread by Lü Yanfang.*
