数据出境合规实务50问(2025版)(英)_152页_3mb
报告摘要
-
Data Extransfer Compliance Overview
This guideline outlines the regulatory framework for outbound Cross-Border Data Transfer (CBDT) in China, particularly under the Cybersecurity Law (2017), Data Security Law (2021), and Personal Information Protection Law (2021). It provides a structured approach to ensure compliance while balancing data security and promoting cross-border data flow. -
Key Compliance Mechanisms
Three primary routes exist for fulfilling outbound data transfer obligations:
-
Submission of Outbound Cross-Border Data Transfer Security Assessment- CIIOs must submit security assessments.
- Others face stricter thresholds based on data type, quantity, and sensitivity.
- Submission can be done online via sjcj.cac.gov.cn or offline via provincial bodies.
-
Recordal of Standard Contract for Cross-Border Transfer of Personal Information- Applicable for processors not meeting assessment thresholds.
- Requires filing contract details through the Cross-Border Data Transfer Filing System.
-
Obtaining Personal Information Protection Certification- Voluntary but recognized as a compliance path.
- Validity period may be extended with approval (maximum 3 years).
- Key Exemptions
Scenarios exempt from the three compliance routes include:
- International trade or transport activities without personal data/important data.
- Necessary employee data transfer for cross-border HR management.
- Genuine necessity to protect personal life/property during emergencies.
- Cross-border transfer within the Guangdong-Hong Kong-Macao Greater Bay Area (GBA) using GBA Standard Contract.
-
Procedure and Timeline
-
Assessment submission involves checking completeness and regulatory review.
-
Deadline starts from receiving materials, with up to 7 working days for initial feedback and 45 working days (extendable) for final assessment approval.
-
Ongoing Supervision
-
Readiness for periodic self-assessment updates; compliance must be maintained for at least three years after approval.
-
Penalties for violations include fines (individuals: CNY 10k–100k; enterprises: CNY 50k–500k) and potential business suspension.
-
Cross-Border Data Dispute
-
Cross-border legal evidence submission requires prior approval from relevant authorities (e.g., Ministry of Justice).
Summary Notes
Do not use the documents listed in the related categories.
Ensure detailed data quantity calculations include cumulative aggregates.
Tailor policies based on regulatory clarification.
试读结束,高清完整版pdf/doc/ppt,请点下载