For most foreign companies in China, Standard Contractual Clauses (SCC) filing is the workhorse of cross-border data compliance — the middle path between full exemption and the heavyweight CAC security assessment. This guide walks the 2026 filing process end to end.
Step 0: Confirm SCC Is Your Path
Before drafting anything, verify you are not in the assessment band and not exempt. The decision chain (CIIO status → important data → cumulative volumes since January 1 → sensitivity) is encoded in our Data Export Self-Checker — run it first. If your flows contain "important data" or exceed the volume thresholds, you need a CAC security assessment, not an SCC filing.
Step 1: Map Your Data Flows Precisely
Regulators reject filings for vague data inventories. For each transfer, document:
- Data categories and fields — e.g. "name, work email, job title, performance rating" not "HR data".
- Subject counts — individuals whose data has been/will be transferred cumulatively since January 1.
- Purpose and processing operations abroad — what the recipient actually does with the data.
- Recipient details — legal entity, country, contact, and whether further transfers (sub-processors) occur.
- Retention and security measures — on both sides.
Step 2: Complete the PIPIA
The Personal Information Protection Impact Assessment must be completed before the contract takes effect and retained at least 3 years. The CAC template covers: legality/necessity of the transfer, volume sensitivity analysis, recipient-country legal environment, and contractual safeguards. Expect your biggest effort here: the recipient-country legal analysis (e.g. GDPR equivalence arguments for EU recipients) needs genuine substance.
Step 3: Execute the CAC Model Contract
- Use the 2023 CAC model clauses verbatim — unmodified. Supplementary technical/commercial terms go in an annex.
- Attach Schedule I (transfer details), Schedule II (safeguards), and Schedule III (other terms).
- Both parties sign; the contract takes effect on the later signature date. The 10-working-day filing clock starts on effectiveness.
Step 4: File with the Provincial CAC
| Requirement | Detail |
|---|---|
| Where | Provincial cyberspace administration where the Chinese exporter is registered |
| Documents | Filing form, signed SCC contract + annexes, PIPIA report, entity credentials, ID of responsible person |
| Clock | File within 10 working days of contract effectiveness; formal acceptance typically ~15 working days |
| Outcome | Record number / acceptance confirmation — a filing, not an approval |
Step 5: Maintain the Compliance Chain
- Re-file on material change — new purpose, category, recipient, or retention change triggers a fresh contract + filing.
- Annual PIPIA refresh — best practice; mandatory if circumstances change.
- Individual rights — ensure the overseas recipient can support PIPL access/deletion requests.
- Breach protocol — contractual breach-notification flows back to the Chinese exporter, who notifies authorities/individuals.
How Long Does It Really Take?
| Phase | Realistic Duration |
|---|---|
| Data-flow mapping | 1-3 weeks |
| PIPIA (incl. recipient-country analysis) | 2-4 weeks |
| Contract negotiation with overseas recipient | 2-4 weeks |
| Provincial filing + acceptance | ~3-4 weeks |
| Total | ~2-3 months |
Related Guides and Tools
Confirm your path with the Data Export Self-Checker; understand the sensitivity layer in PIPL Sensitive Data Export Thresholds 2026; see a sector application in the Automotive CAC Checklist; and the full framework in the Data Cross-Border Transfer Guide.
Informational only — verify with official sources; not legal advice.