Compliance

China Data Export: SCC Filing Steps 2026 (Standard Contractual Clauses)

📅 September 8, 2026 ⏱️ 10 min read ✅ Reviewed July 2026

For most foreign companies in China, Standard Contractual Clauses (SCC) filing is the workhorse of cross-border data compliance — the middle path between full exemption and the heavyweight CAC security assessment. This guide walks the 2026 filing process end to end.

Step 0: Confirm SCC Is Your Path

Before drafting anything, verify you are not in the assessment band and not exempt. The decision chain (CIIO status → important data → cumulative volumes since January 1 → sensitivity) is encoded in our Data Export Self-Checker — run it first. If your flows contain "important data" or exceed the volume thresholds, you need a CAC security assessment, not an SCC filing.

Step 1: Map Your Data Flows Precisely

Regulators reject filings for vague data inventories. For each transfer, document:

  • Data categories and fields — e.g. "name, work email, job title, performance rating" not "HR data".
  • Subject counts — individuals whose data has been/will be transferred cumulatively since January 1.
  • Purpose and processing operations abroad — what the recipient actually does with the data.
  • Recipient details — legal entity, country, contact, and whether further transfers (sub-processors) occur.
  • Retention and security measures — on both sides.

Step 2: Complete the PIPIA

The Personal Information Protection Impact Assessment must be completed before the contract takes effect and retained at least 3 years. The CAC template covers: legality/necessity of the transfer, volume sensitivity analysis, recipient-country legal environment, and contractual safeguards. Expect your biggest effort here: the recipient-country legal analysis (e.g. GDPR equivalence arguments for EU recipients) needs genuine substance.

Step 3: Execute the CAC Model Contract

  • Use the 2023 CAC model clauses verbatim — unmodified. Supplementary technical/commercial terms go in an annex.
  • Attach Schedule I (transfer details), Schedule II (safeguards), and Schedule III (other terms).
  • Both parties sign; the contract takes effect on the later signature date. The 10-working-day filing clock starts on effectiveness.

Step 4: File with the Provincial CAC

RequirementDetail
WhereProvincial cyberspace administration where the Chinese exporter is registered
DocumentsFiling form, signed SCC contract + annexes, PIPIA report, entity credentials, ID of responsible person
ClockFile within 10 working days of contract effectiveness; formal acceptance typically ~15 working days
OutcomeRecord number / acceptance confirmation — a filing, not an approval

Step 5: Maintain the Compliance Chain

  • Re-file on material change — new purpose, category, recipient, or retention change triggers a fresh contract + filing.
  • Annual PIPIA refresh — best practice; mandatory if circumstances change.
  • Individual rights — ensure the overseas recipient can support PIPL access/deletion requests.
  • Breach protocol — contractual breach-notification flows back to the Chinese exporter, who notifies authorities/individuals.
Top 3 rejection drivers: (1) inconsistent subject counts between the contract, PIPIA, and filing form; (2) generic data-field descriptions; (3) missing recipient-country legal analysis. All three are preparation failures, not form failures.

How Long Does It Really Take?

PhaseRealistic Duration
Data-flow mapping1-3 weeks
PIPIA (incl. recipient-country analysis)2-4 weeks
Contract negotiation with overseas recipient2-4 weeks
Provincial filing + acceptance~3-4 weeks
Total~2-3 months

Related Guides and Tools

Confirm your path with the Data Export Self-Checker; understand the sensitivity layer in PIPL Sensitive Data Export Thresholds 2026; see a sector application in the Automotive CAC Checklist; and the full framework in the Data Cross-Border Transfer Guide.

Informational only — verify with official sources; not legal advice.

Frequently Asked Questions

What is SCC filing for cross-border data transfer in China?
Standard Contractual Clauses (SCC) filing — based on the CAC's 2023 measures — is one of the three legal paths for transferring personal information out of China (alongside CAC security assessment and certification). The exporter signs the CAC-model contract with the overseas recipient, completes a Personal Information Protection Impact Assessment (PIPIA), and files both with the provincial cyberspace administration within 10 working days of taking effect.
When is SCC filing the right path instead of a CAC security assessment?
SCC filing applies when you are not a CIIO, transfer no important data, and your cumulative cross-border volumes of personal information fall within the middle band of the 2024 Provisions thresholds — for example, non-sensitive personal information in the hundred-thousands range, or sensitive personal information below the assessment threshold. Use our Data Export Self-Checker to confirm.
How long does SCC filing take?
The filing itself is a submission, not an approval: provincial CACs complete the formal acceptance process within roughly 15 working days for complete, correct filings. The heavy lifting is the contract negotiation with the overseas recipient and the PIPIA — budget 4-8 weeks for preparation.
Do I need to re-file every year?
No, but you must monitor changes. A new filing is required if the purpose, duration, data categories, or recipient changes materially, and the PIPIA must be reassessed. Keep records for at least 3 years; regulators increasingly ask for the full chain during inspections.

Related Guides

Found this useful?

Stay Informed

Weekly Policy Briefing

Get a curated digest of the latest Chinese policy changes, investment insights, and regulatory updates — delivered every Monday morning. Choose what matters to you.

Customize your briefing

Industries

Cities / Regions

Frequency

No spam. Unsubscribe anytime. Update your preferences anytime.