---
title_en: "Guidelines for Compliance Assessment of Cross-border Data Transactions"
title_zh: "跨境数据交易合规评估指引"
abbreviation: "SZDEX Cross-border Trading Guidelines"
hierarchy: "handbook"
issuing_body: "Shenzhen Data Exchange (深圳数据交易所), under the guidance of the Cyberspace Administration of Shenzhen and the Shenzhen Municipal Administration of Government Services and Data"
effective_date: 2026-02-09
status: "effective"
related_laws: ["cs-joint-data-compliance-guide", "genai-service-transaction-compliance-assessment-guidelines", "cross-border-data-flows-provisions", "data-export-security-assessment-measures", "personal-info-standard-contract-measures", "cross-border-pi-certification-measures", "pipl", "dsl", "network-data-security-regulations", "automotive-data-export-security-guidelines", "hgr-regulation", "data-classification-grading-rules", "shenzhen-sez-data-regulations", "cybersecurity-review-measures"]
domains: ["cross-border", "data-economy", "personal-information", "data-security"]
url: https://datacompliancechina.com/laws/cross-border-data-transaction-compliance-assessment-guidelines/
summary: "A 53-page assessment guide from the Shenzhen Data Exchange covering the compliance review of cross-border data *transactions* — the sale or licensing of a data product for money across the PRC border, as distinct from the intra-group transfers the CAC export regime was built around. It classifies cross-border trading into six modes by data origin and counterparty location, rules four of them in and two out of scope, and then applies a three-stage assessment (subject → object → circulation) crossed with four dimensions (legality, security, integrity, rights protection). The value for overseas counsel is the offshore-counterparty checklist: what an offshore buyer or seller must itself demonstrate before a Chinese exchange or seller will clear the trade. Current as of 9 February 2026."
---

> **Source: Data Compliance China** — https://datacompliancechina.com/laws/cross-border-data-transaction-compliance-assessment-guidelines/ · English rendering and annotations by DCC; the Chinese original governs. Cite as: Data Compliance China, "Guidelines for Compliance Assessment of Cross-border Data Transactions", https://datacompliancechina.com/laws/cross-border-data-transaction-compliance-assessment-guidelines/
**Issued by:** Shenzhen Data Exchange (深圳数据交易所).
**Guiding organizations:** Cyberspace Administration of Shenzhen (深圳市互联网信息办公室) · Shenzhen Municipal Administration of Government Services and Data (深圳市政务服务和数据管理局).
**Editor-in-chief:** Wang Qinglan, General Manager, Compliance Department, Shenzhen Data Exchange.
**Drafting organizations include:** Shenzhen Data Exchange · Shenzhen Futian District Bureau of Justice · Futian District Administration of Government Services and Data · the Third Research Institute of the Ministry of Public Security · Shenzhen Institute of Standards and Technology · China Unicom Smart City Research Institute · ZTE · UBTECH · Shenzhen TCL New Technology.
**Current as of:** 9 February 2026.

> *Editor's Note — DCC.*
>
> Almost everything written in English about Chinese data export addresses one
> fact pattern: a multinational moving its own data out of China. This document
> addresses a different one — someone **selling** Chinese data, as a priced
> product, to a counterparty on the other side of the border.
>
> That distinction matters more than it sounds. In a transfer, one party owns the
> compliance problem. In a transaction there are at least three — seller, buyer,
> and the exchange or data dealer in the middle — and Chinese law has, until now,
> said very little about how the obligations divide. These Guidelines are the
> first operational attempt DCC has seen to allocate them.
>
> The document does not create law. It is exchange-level guidance from the
> institution that runs Shenzhen's data market, written under the supervision of
> the Shenzhen cyberspace and data authorities, and filed in 2024 as a Shenzhen
> local-standard project. Treat it as the best available statement of what a
> Chinese data exchange will actually ask for — not as a rule that binds a court.
>
> The summaries below are DCC's distillation. The Guidelines permit
> non-commercial reproduction with attribution; DCC does not reproduce the full
> text.

## Why this matters for overseas teams

The CAC cross-border regime — the [Security Assessment Measures](/laws/data-export-security-assessment-measures/), the [Standard Contract Measures](/laws/personal-info-standard-contract-measures/), the [Certification Measures](/laws/cross-border-pi-certification-measures/), and the relaxations in the [Provisions on Promoting and Regulating Cross-border Data Flows](/laws/cross-border-data-flows-provisions/) — answers the question *may this data leave China, and by which pathway*. It says almost nothing about the commercial layer sitting on top: who warranted the data's provenance, what the buyer is permitted to do with it, and what happens when the buyer is an entity with no presence in China at all.

These Guidelines fill that gap with three things overseas counsel can use directly:

- **A transaction taxonomy** that tells you, before anything else, whether Chinese rules reach your deal at all.
- **An offshore-party checklist** — the first DCC has seen — setting out what a non-Chinese buyer or seller must itself be able to evidence.
- **Sector annexes** for healthcare and human genetic resources, automotive, financial and AI data, each pointing at the specific instrument that governs it.

## The six trading modes — and the two that are out of scope

Everything in the document turns on this table. The classification is by **where the underlying data was collected** crossed with **where the counterparties sit**.

| Mode | Data source | Seller / data dealer | Buyer | In scope |
|:--:|---|---|---|:--:|
| **I** | PRC-domestic data | Domestic | Offshore | Yes |
| **II** | PRC-domestic data | Offshore | Offshore | Yes |
| **III** | PRC-domestic data | Offshore | Domestic | Yes |
| **IV** | Offshore data | Domestic | Offshore | No |
| **V** | Offshore data | Offshore | Offshore | No |
| **VI** | Offshore data | Offshore | Domestic | Yes |

Two exclusions are worth reading carefully:

- **Modes IV and V are excluded** because the data source is offshore, no domestic data is exported, and the resulting product is used or processed offshore. The Guidelines treat these as outside the reach of Chinese law and outside their own assessment scope.
- **A domestic-to-domestic trade is not a cross-border transaction** even where the data itself originated abroad — there is no border crossing in the circulation step.

The important carve-back: if a **domestic** party takes offshore data, mixes in domestic data, and then sells the combined product offshore, the Guidelines apply. Blending is what pulls Mode IV back into scope. For a foreign vendor building a China-inclusive dataset, this is the sentence that decides the compliance posture of the whole product.

Mode III deserves a note of its own — domestic-origin data, offshore seller, domestic buyer. That is Chinese data that has already left, been productized abroad, and is being sold back in. The Guidelines' answer is short but pointed: the offshore seller must establish a representative office or designate a representative in China for personal-information matters and report that representative to the authorities — the [PIPL](/laws/pipl/) Article 53 obligation, applied to a seller who might otherwise assume it has no China nexus.

## The assessment grid

The framework is a 3 × 4 matrix. Three sequential stages, each reviewed along four dimensions:

|  | **Legality** | **Security** | **Integrity** | **Rights protection** |
|---|:--:|:--:|:--:|:--:|
| **Subject** — the trading parties | · | · | · | · |
| **Object** — the data product | · | · | · | · |
| **Circulation** — the transfer itself | · | · | · | · |

Each cell resolves into a document request. Annex A lists the evidence expected per cell — business licences and sector permits, the data-security management system, classification and grading records, the export channel inventory, encryption schemes for each channel, CAC filing outcomes, receiving-party capability assessments, ISO 27001 and 27701 certificates, three years of enforcement history, and the data-subject rights notices for each jurisdiction whose residents appear in the data.

Assessment runs in three phases — preparation, execution, report — by a team with a defined role split (lead assessor, management assessor, technical assessor, quality controller). The security portion may be delegated to a third-party technical assessor whose opinion the legal assessor then relies on. Findings go back to the trading party for rectification, and rectification is re-confirmed before sign-off.

### Subject-side tiers

Domestic parties are graded by what they handle, and each tier inherits the one below it:

- **General data traders** — an A-grade security posture under the Shenzhen local standard DB4403/T 564-2024 (*Specification for Compliance Assessment of Data Transactions*), plus a named cross-border data security owner and team; written regimes for classification and grading, technical protection, access control, compliance review and audit; a risk-monitoring, contingency and regulator-response mechanism; per-scenario encryption schemes; and a maintained inventory of export channels (APIs, applications, email, datasets, FTP).
- **Personal-information traders** — add annual backup of exported PI with integrity verification, PI tagging, channel-level PI asset identification, volume monitoring against a **warning threshold set below the filing trigger**, log backup reconciled against transfer volumes, a **three-year** retention floor for both backups and channel logs, a cross-border PI ledger with scheduled deletion, and recorded, evaluated destruction.
- **Important-data traders** — add a passed CAC security assessment, an important-data identification regime kept current against national and sector rules, an important-data inventory procedure, a pre-transfer security assessment and approval workflow with **records retained three years or more**, contractual security obligations on the receiving party with supervision rights, full-process audit with traceability (tagging, digital watermarking, blockchain), plain-readable disclosure of exported types and scope on regulator verification, a hard bar on exceeding the scope declared in the CAC assessment, a stop-and-remediate duty if the regulator rules the data should not have left, and **no provision to foreign judicial or law-enforcement bodies without approval**.

### What the offshore party has to show

This is the part with no real analogue elsewhere in the Chinese corpus. An offshore counterparty must demonstrate that it:

- meets its home-jurisdiction data protection requirements **and reaches a network-security level equivalent to the PRC standard**;
- has appointed a PI protection officer and body, and published cross-border PI processing rules, where PI is involved;
- provides data-security capability **no lower than a domestic important-data trader** — organizationally, technically, and in personnel — where important data is involved;
- discloses recipient name and contact, data types, volumes and purpose, and the overseas storage location, retention period, scope and method;
- operates a destruction mechanism that disposes of important data and PI once the agreed period expires;
- runs periodic compliance re-assessment against Chinese legal and technical requirements.

Two further items are framed as *should* rather than *shall*: alignment with major international privacy standards (the Guidelines name GDPR and HIPAA), and ISO 27001 and ISO 27701 certification. For a foreign buyer, these are the cheapest credibility signals available — and the Guidelines say so explicitly.

On the wire, the circulation-stage security requirements are concrete: two-or-more-factor identity authentication at both ends with at least one factor cryptographic; encryption at industry best practice, with **TLS 1.3** named; monitoring on the transfer path with blocking and alerting; interface call logging with audit; cache clearing after settlement with verified effectiveness; automatic interdiction of data China prohibits from being imported; and — for offshore parties — a **sub-supplier regime**, with security investigation of any downstream third party that would re-export the data, and signed security and confidentiality undertakings with each.

## Object-side: where the data came from

The legality tests split by origin. For data sourced offshore and processed in China before resale, the assessment reaches back into the source jurisdiction: lawful collection under that jurisdiction's rules, a valid basis for any personal information, completed export formalities on the outbound leg from that country, and no breach of the source jurisdiction's competition, antitrust, trade-control, sanctions or security-review law. Content that is politically prohibited or terrorism-related under Chinese law is barred regardless of origin.

Where domestic data is blended in, the full [PIPL](/laws/pipl/) stack attaches — lawful basis, minimum-necessary retention, entrusted-processing terms, guardian consent for under-14s, and a personal information protection impact assessment for sensitive PI, automated decision-making, onward provision, publication or export. Where [important data](/posts/important-data-category-not-tier/) is blended in, its processing must be reflected in the risk-assessment report filed with the regulator, and industrial or energy sector catalogues must have been filed with the sector regulator, with changes re-filed within three months.

The content test bars, among others: data whose export could endanger national security or the public interest; data whose export would breach an undertaking to a third party; data that would infringe third-party IP, trade secrets or privacy; public data not lawfully opened; and unauthorized personal information or data that identifies a specific natural person without recourse to anything else.

## The sector annexes

Annex B is the fastest route from a business scenario to the governing instrument:

- **Healthcare and human genetic resources** — population census material, human genetic resources information and raw sequencing data are treated as important data. Clinical trials, telemedicine, international joint research and international medical insurance are named as export scenarios. HGR material export requires a certificate from the science and technology administration under the [HGR Regulation](/laws/hgr-regulation/) on five conditions including ethics review; providing HGR information to foreign parties requires filing plus an information backup.
- **Automotive** — an important-data catalogue (sensitive-area geographic and flow data, economic-activity flow data, charging-network operating data, exterior video and imagery containing faces or plates, PI on more than 100,000 subjects), the annual reporting package due by 15 December, and the nine exemptions from assessment, standard contract and certification. It routes to the [Automotive Data Export Security Guidelines (2026 Edition)](/laws/automotive-data-export-security-guidelines/).
- **Financial** — personal financial information collected in China is stored, processed and analysed in China; export to a group affiliate requires express consent of the subject, a sector-specific export security assessment, and contractual plus on-site supervision of the offshore recipient. Overseas securities regulators may not conduct evidence-gathering inside China, and no one may provide securities-business documents offshore without approval.
- **Artificial intelligence** — training-data provenance must be lawful, traceable and non-infringing, with at least one lawful basis for any personal information. Two accumulation warnings: a domestic firm piling data into an offshore model may cross into important data, and a provider serving users across the border must precisely identify PI collected in interaction. The volume triggers apply — **1,000,000 individuals' non-sensitive PI or 10,000 individuals' sensitive PI**, cumulative from 1 January — subject to free-trade-zone negative lists. Generated content must be labelled.

Across the sector annexes the same escape hatch recurs: where the data falls inside a **free-trade-zone negative list**, the FTZ's own rules displace the general trigger. DCC has covered how those lists are converging in [the 2026 national registry of data-export negative lists](/posts/data-export-negative-lists-2026-national-registry/).

## How to use it

If you act for a party on either side of a Chinese data trade, the practical sequence is:

1. **Locate the deal in the six-mode table.** Modes IV and V are out of scope; everything else pulls in the full framework, and blending domestic data into an offshore-sourced product moves you into scope.
2. **Check whether your client is the offshore party.** If so, the offshore checklist above is the shortest statement available of what a Chinese exchange will require — including the PIPL Article 53 representative in Modes II and III.
3. **Run the CAC pathway analysis separately.** These Guidelines assume the export pathway is resolved; they add the commercial layer, they do not replace it.
4. **Pull the sector annex.** Healthcare, automotive, financial and AI each carry requirements that the general framework does not surface.

DCC has covered the related question of impact assessment in data trading in [Personal information trading and PIA under the Network Data Regulations](/posts/pi-trading-pia-network-data-regulations/).

## Companion document

The Shenzhen Data Exchange published a parallel guide on the same day and to the same framework for AI transactions: the [Guidelines for Compliance Assessment of Transactions Involving Generative Artificial Intelligence Services](/laws/genai-service-transaction-compliance-assessment-guidelines/). Where a deal involves both — exporting training data, or licensing a model across the border — the two are meant to be read together.

Both descend from the [China–Singapore Joint Data Compliance Guide](/laws/cs-joint-data-compliance-guide/), which established the subject-versus-object framing these Guidelines extend with a third, circulation axis.

## Source

Original document: 《跨境数据交易合规评估指引》 (*Guidelines for Compliance Assessment of Cross-border Data Transactions*), Shenzhen Data Exchange, 53 pages, content current as of 9 February 2026. Guided by the Cyberspace Administration of Shenzhen and the Shenzhen Municipal Administration of Government Services and Data.

The Guidelines were filed as a Shenzhen local-standard project in the [2024 Shenzhen Local Standards Project Plan](http://zfsg.gd.gov.cn/xxfb/dtxw/content/post_4438566.html), alongside the generative-AI companion guide and a data-quality grading specification.

The document is a public-interest publication. It states that it is for informational reference only, is not to be used for commercial purposes, and must be attributed with a note of its public-interest character when quoted or circulated. DCC reproduces no full text; the above is distillation and commentary.
