On July 24, 2026, the Cyberspace Administration of China (“CAC”) published an official Q&A related to administrative policies on cross-border data transfers. Below is a list of the questions published by the CAC, each with a summary of the CAC’s response.
Q1. How should personal information handlers effectively fulfill the obligation of notification and separate consent when transferring data overseas?
Pursuant to Articles 30 and 39 of the Personal Information Protection Law of China (“PIPL”), data handlers transferring personal information outside of China must inform individuals of specific details, including the foreign recipient’s identity, the purpose of the transfer, data categories involved and procedures for exercising rights, as well as obtaining separate consent to the transfer from the individual through explicit means (e.g., pop-up confirmations or written consent). If sensitive personal information is involved, handlers must also disclose the necessity of the transfer and the impact it may have on individual rights.
- Separate consent must be specific and explicit; it must not be bundled with consent to other personal information processing activities, nor may it be obtained through a “blanket” authorization.
- Methods for obtaining separate consent are described in GB/T 42574-2023, Information Security Technology—Implementation Guidelines for Notification and Consent in the Processing of Personal Information, and may take the form of a signed written document, a pop-up window confirmation or a reply via email or text message.
- Where the cross-border transfer of personal information falls under any of the circumstances listed in Article 13, Paragraph 1, Items 2 through 7 of the PIPL, the individual’s consent is not required. However, the obligation to provide notice regarding the cross-border transfer must still be fulfilled.
Q2. What conditions must be met to apply for an extension of the valid period for passed security assessments?
Under existing regulations, specifically Article 9 of the Provisions on Promoting and Standardizing Cross-Border Data Flows, a passed CAC security assessment remains valid for three years. Data handlers may apply for a three-year extension within 60 working days before expiration if six cumulative conditions are met:
- the purpose and scope of data export remain unchanged;
- the data handler and foreign recipient remain unchanged;
- for transfers of personal information, the projected volume of personal information to be transferred over the next three years does not increase by more than 20% compared with the approved volume over the previous three years;
- for transfer of “important data”, the projected volume of important data does not increase by more than 20%;
- the legal documents entered into with the overseas recipient comply with Article 9 of the Measures for the Security Assessment of Data Transfer Abroad; and
- the handler strictly complied with the original assessment approval and experienced no major data security incidents over the past three years.
These conditions remain the same as those requirements for extension of the validity of a CAC security assessment under the dedicated chapter of the Guidelines for Filing Security Assessments for Data Transfers Overseas (Third Edition), which the CAC issued on June 27, 2025.
This extension mechanism relieves companies whose original three-year approvals are expiring from having to perform a redundant full reassessment. Crucially, the 20% threshold applies to projected future growth rather than current volume, providing data handlers flexibility to self-evaluate and streamline compliance filings.
Q3. In recruitment scenarios, how should the necessity of transferring domestic job applicants' resumes overseas be determined?
Under Article 6 of the PIPL, data processing must adhere to the principles of necessity and minimization.
- Where domestic job applicant resumes are shared with foreign headquarters or overseas affiliates, necessity depends on the degree of involvement in the hiring process, the number of individuals involved and the scope of personal information data items collected for use abroad.
- If the overseas entity does not participate in the local recruitment decision, transferring candidate resumes is not necessary and is therefore prohibited.
- If the foreign entity directly participates in the hiring decision, the transfer of candidates’ personal information is permitted only to the minimum extent needed and should be limited to data points strictly required for that decision. Any permissible export must follow appropriate legal mechanisms (e.g., CAC security assessment, standard contractual clauses or certification) and comply with notification, separate consent and Personal Information Protection Impact Assessment requirements.
Data handlers cannot rely on the legal basis of “HR management purpose” to export candidate resumes. Unlike existing employees, job applicants do not automatically fall under the cross-border HR exemption, requiring strict necessity evaluations for overseas candidate data flows.
Search
Recent Posts
Categories
- Behavioral Advertising
- Centre for Information Policy Leadership
- Children’s Privacy
- Cyber Insurance
- Cybersecurity
- Enforcement
- European Union
- Events
- FCRA
- Financial Privacy
- General
- Health Privacy
- Identity Theft
- Information Security
- International
- Marketing
- Multimedia Resources
- Online Privacy
- Security Breach
- U.S. Federal Law
- U.S. State Law
- Workplace Privacy
Tags
- Aaron P. Simpson
- Accountability
- Adequacy
- Advertisement
- Advertising
- Age Appropriate Design Code
- Age Verification
- Alabama
- American Privacy Rights Act
- Anna Pateraki
- Anonymization
- Anti-terrorism
- APEC
- Apple Inc.
- Argentina
- Arkansas
- Article 29 Working Party
- Artificial Intelligence (AI)
- Attorney General
- Audit
- Australia
- Austria
- Automated Decisionmaking
- Baltimore
- Bankruptcy
- Belgium
- Biden Administration
- Big Data
- Binding Corporate Rules
- Biometric Data
- Blockchain
- Bojana Bellamy
- Brazil
- Brexit
- British Columbia
- Brittany Bacon
- Brussels
- Business Associate Agreement
- BYOD
- California
- CalPrivacy
- CAN-SPAM
- Canada
- Cayman Islands
- CCPA
- CCTV
- Centre for Information Policy Leadership (CIPL)
- Chatbot
- Children’s Online Privacy Protection Act (COPPA)
- Chile
- China
- Chinese Taipei
- Christopher Graham
- CIPA
- Class Action
- Clinical Trial
- Cloud
- Cloud Computing
- CNIL
- Colombia
- Colorado
- Committee on Foreign Investment in the United States
- Commodity Futures Trading Commission
- Compliance
- Computer Fraud and Abuse Act
- Congress
- Connecticut
- Consent
- Consent Order
- Consumer Protection
- Consumer Rights
- Cookies
- COPPA
- Coronavirus/COVID-19
- Council of Europe
- Council of the European Union
- Court of Justice of the European Union
- CPPA
- CPRA
- Credit Monitoring
- Credit Report
- Criminal Law
- Critical Infrastructure
- Croatia
- Cross-Border Data Flow
- Cross-Border Data Transfer
- Cyber Attack
- Cybersecurity
- Cybersecurity and Infrastructure Security Agency
- Data Breach
- Data Brokers
- Data Controller
- Data Localization
- Data Minimization
- Data Privacy Framework
- Data Processor
- Data Protection Act
- Data Protection Authority
- Data Protection Impact Assessment
- Data Protection Officer
- Data Security
- Data Transfer
- David Dumont
- David Vladeck
- Deceptive Trade Practices
- Delaware
- Denmark
- Department of Commerce
- Department of Defense
- Department of Health and Human Services
- Department of Homeland Security (DHS)
- Department of Justice
- Department of the Treasury
- Design
- Digital Markets Act
- District of Columbia
- Do Not Call
- Do Not Track
- Dobbs
- Dodd-Frank Act
- DORA
- DPIA
- E-Privacy
- E-Privacy Directive
- Ecuador
- Ed Tech
- Edith Ramirez
- Electronic Communications Privacy Act
- Electronic Privacy Information Center
- Electronic Protected Health Information
- Elizabeth Denham
- Employee Monitoring
- Encryption
- ENISA
- EU Data Protection Directive
- EU General Data Protection Regulation (GDPR)
- EU Member States
- European Commission
- European Data Protection Board
- European Data Protection Supervisor
- European Parliament
- European Union
- Facial Recognition Technology
- FACTA
- Fair Credit Reporting Act
- Fair Information Practice Principles
- Federal Aviation Administration
- Federal Bureau of Investigation
- Federal Communications Commission
- Federal Data Protection Act
- Federal Trade Commission
- FERC
- Financial Data
- FinTech
- Florida
- Food and Drug Administration
- Foreign Intelligence Surveillance Act
- France
- Franchise
- Fred Cate
- Freedom of Information Act
- Freedom of Speech
- Fundamental Rights
- GDPR
- Genetic Data
- Geofencing
- Geolocation
- Geolocation Data
- Georgia
- Germany
- Global Privacy Assembly
- Global Privacy Enforcement Network
- Gramm Leach Bliley Act
- Grok
- Hacker
- Hawaii
- Health Data
- HIPAA
- HITECH Act
- Hong Kong
- House of Representatives
- Hungary
- Illinois
- India
- Indiana
- Indonesia
- Information Commissioners Office
- Information Sharing
- Insurance Provider
- Internal Revenue Service
- International Association of Privacy Professionals
- International Commissioners Office
- Internet
- Internet of Things
- Iowa
- IP Address
- Ireland
- Israel
- Italy
- Jacob Kohnstamm
- Japan
- Jason Beach
- Jay Rockefeller
- Jenna Rode
- Jennifer Stoddart
- Jersey
- Jessica Rich
- John Delionado
- John Edwards
- Kentucky
- Korea
- Large Language Model
- Latin America
- Laura Leonard
- Law Enforcement
- Lawrence Strickling
- Legislation
- Liability
- Lisa Sotto
- Litigation
- Location-Based Services
- London
- Louisiana
- Madrid Resolution
- Maine
- Malaysia
- Maryland
- Massachusetts
- Meta
- Mexico
- Michigan
- Microsoft
- Minnesota
- Missouri
- Mobile
- Mobile App
- Mobile Device
- Montana
- Morocco
- MySpace
- Natascha Gerlach
- National Institute of Standards and Technology
- National Labor Relations Board
- National Science and Technology Council
- National Security
- National Security Agency
- National Telecommunications and Information Administration
- Nebraska
- NEDPA
- Netherlands
- Nevada
- New Hampshire
- New Jersey
- New Mexico
- New York
- New Zealand
- Nigeria
- Ninth Circuit
- North Carolina
- North Dakota
- North Korea
- Norway
- Obama Administration
- OCPA
- OECD
- Office for Civil Rights (OCR)
- Office of Foreign Assets Control
- Ohio
- Oklahoma
- Online Behavioral Advertising
- Online Privacy
- Opt-In Consent
- Opt-Out
- Oregon
- Outsourcing
- Pakistan
- Parental Consent
- Payment Card
- PCI DSS
- Penalty
- Pennsylvania
- Personal Data
- Personal Health Information
- Personal Information
- Personally Identifiable Information
- Peru
- Philippines
- Poland
- PRISM
- Privacy
- Privacy and Information Security Law
- Privacy By Design
- Privacy Notice
- Privacy Policy
- Privacy Rights
- Privacy Rule
- Privacy Shield
- Profiling
- Protected Health Information
- Purpose Limitation
- Ransomware
- Record Retention
- Red Flags Rule
- Rhode Island
- Richard Thomas
- Right to Be Forgotten
- Right to Privacy
- Risk Assessment
- Risk-Based Approach
- ROSCA
- Rosemary Jay
- Russia
- Safe Harbor
- Salesforce
- Sanctions
- Schrems
- Scott Kimpel
- SECURE Data Act
- Securities and Exchange Commission
- Security Rule
- Senate
- Sensitive Data
- Serbia
- Service Provider
- Singapore
- Smart Grid
- Smart Metering
- Social Media
- Social Security Number
- South Africa
- South Carolina
- South Dakota
- South Korea
- Spain
- Spyware
- Standard Contractual Clauses
- State Attorneys General
- Steven Haas
- Stick With Security Series
- Stored Communications Act
- Student Data
- Supreme Court
- Surveillance
- Surveillance Pricing
- Sweden
- Switzerland
- Taiwan
- Targeted Advertising
- Telecommunications
- Telemarketing
- Telephone Consumer Protection Act
- Tennessee
- Terry McAuliffe
- Texas
- Text Message
- Thailand
- Transparency
- Transportation Security Administration
- Trump Administration
- United Arab Emirates
- United Kingdom
- United States
- Unmanned Aircraft Systems
- Uruguay
- Utah
- Vermont
- Video Privacy Protection Act
- Video Surveillance
- Virginia
- Viviane Reding
- Washington
- Whistleblowing
- Wireless Network
- Wiretap
- ZIP Code