China Releases Updated Guidance on the Application for Security Assessment of Cross-border Data Transfers
Time 2 Minute Read

On June 27, 2025, the Cyberspace Administration of China (“CAC”) released the third version of the Guidance on the Application for Security Assessment of Cross-border Data Transfers (“Guidance”). The Guidance sought to optimize and simplify the relevant materials required for security assessment, providing more detailed operational guidance for data handlers.

A key area covered in the Guidance is the rules on the application for extension of the validity period of a security assessment. The validity period of a security assessment is three years. If the data handler meets the following conditions, they may apply for an extension 60 business days before the expiration of the validity period which, if approved, would extend the validity period by 3 years:

  • the purpose and scope of the cross-border transfer, and the relevant data handlers and overseas recipients, remain unchanged;
  • with regards a cross-border transfer of personal information, the increase in the number of individuals involved in the transfer over the next three years shall not exceed 20% of the number of individuals involved in the transfer for the past three years as approved by the original assessment;
  • with regards a cross-border transfer of important data, the increase in the scale of exported data (MB/GB/TB) over the next three years shall not exceed 20% of the scale of exported data in the past three years as approved by the original assessment;
  • the legal documents concluded with the overseas recipient comply with the provisions of Article 9 of the Measures for Security Assessment of Cross-border Data Transfers; and
  • the transfer activities have been carried out in strict compliance with the original security assessment and there has been no major incident in the past three years.

You May Also Be Interested In

Time 3 Minute Read

The Connecticut Attorney General recently issued a legal memorandum regarding the application of existing Connecticut laws, such as the Connecticut Data Privacy Act, to the use of artificial intelligence.

Time 3 Minute Read

On March 20, 2026, Oklahoma Governor Kevin Stitt signed SB 546 into law, enacting the Oklahoma Consumer Data Privacy Act, which will take effect on January 1, 2027.

Time 2 Minute Read

On March 23, 2026, the UK Information Commissioner's Office released new guidance clarifying the use of the new recognized legitimate interest lawful basis for processing personal information under UK data protection law.

Time 2 Minute Read

On March 5, 2026, the California Privacy Protection Agency announced that the agency had reached a settlement with Ford Motor Company resolving an enforcement action against the company that alleged noncompliance with the California Consumer Privacy Act’s opt-out of sale/sharing rights.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page