Compliance

PIPL Sensitive Data Export Thresholds: 2026 Guide

πŸ“… September 8, 2026 ⏱️ 9 min read βœ… Reviewed July 2026

Sensitive personal information is where China's cross-border data regime bites hardest: separate consent, impact assessments, and the lowest thresholds to a full CAC security assessment. This guide lays out the 2026 thresholds and how to classify your flows correctly.

What Is "Sensitive" Under PIPL

PIPL Article 28 draws a wide circle. Treat the following as sensitive by default:

  • Biometrics β€” face, fingerprint, voiceprint, iris. (Face recognition has additional dedicated rules.)
  • Medical and health data β€” diagnoses, prescriptions, health-monitoring app data.
  • Financial accounts β€” bank/card identifiers, transaction-level financial profiling.
  • Whereabouts and location tracking β€” continuous location data.
  • Religious beliefs, specific identities β€” ethnicity-linked and identity-sensitive attributes.
  • All data of minors under 14 β€” treated as sensitive regardless of content.
HR data warning: employee data flows (global HRIS, payroll consolidation) are the most common accidental sensitive-data export β€” medical/insurance records and sometimes biometric access control data ride along in "ordinary" HR datasets. Segment them out before threshold counting.

The 2026 Threshold Map

Since January 1 of the applicable measurement year, count individuals (not records) whose personal information you cumulatively transferred abroad:

ScenarioRequired Path
CIIO transferring any personal informationCAC security assessment
Any "important data" in the flowCAC security assessment
Non-sensitive PI of 1,000,000 or more individuals (cumulative since Jan 1)CAC security assessment
Sensitive PI of 10,000 or more individuals (cumulative since Jan 1)CAC security assessment
Non-sensitive PI of 100,000 – 1,000,000 individuals, or sensitive PI below 10,000SCC filing or certification (+ PIPIA, separate consent)
Non-sensitive PI below 100,000 individuals (no important data, non-CIIO)Exempt from filing β€” PIPIA and safeguards still required

The exact cutoffs are set by the Provisions on Promoting and Regulating Cross-Border Data Flows and related guidance β€” and they have been revised several times. Run your specific numbers through our Data Export Self-Checker, which encodes the current decision chain, and verify against the latest official text before filing.

Requirements That Apply Regardless of Threshold

  • Separate consent β€” cross-border transfer is its own processing purpose; blanket consent in a general privacy policy does not suffice.
  • PIPIA β€” a Personal Information Protection Impact Assessment completed before transfer and retained β‰₯ 3 years.
  • Overseas recipient contract β€” the PIPL standard contractual obligations (purpose limitation, security measures, breach notification, sub-processor control).
  • Transparency β€” recipient name, country, and contact details disclosed to individuals.

Practical Steps to Reduce Exposure

  1. De-identify aggressively. Properly anonymized data falls outside PIPL entirely; pseudonymized data does not. Most "sensitive" flows can be engineered down.
  2. Localize the sensitive layer. Keep biometric/medical processing in China; export only aggregates.
  3. Count individuals, not records. One customer with 50 transferred records counts once β€” but tracking this requires real instrumentation, not estimates.
  4. Use FTZ pilot lists. Free trade zone negative lists (Shanghai first) exempt certain flows from filing β€” check whether your data category is listed.

Decision Support

Get your path in two minutes with the Data Export Self-Checker. For the filing mechanics, read the SCC Filing Steps 2026; for sector context, see the Automotive CAC Checklist; and for the full framework, the Data Cross-Border Transfer Guide.

Informational only β€” verify with official sources; not legal advice.

Frequently Asked Questions

What counts as sensitive personal information under PIPL?
PIPL Article 28 defines sensitive personal information as biometrics, religious beliefs, specific identities, medical health, financial accounts, and whereabouts/location tracking β€” plus any personal information of minors under 14. Sensitive data requires separate (specific-purpose) consent and stricter transfer controls.
When does sensitive data export require a CAC security assessment?
Under the 2024 Provisions on Promoting and Regulating Cross-Border Data Flows, when an organization cumulatively transfers sensitive personal information of 10,000 or more individuals abroad since January 1 of the current year (from the date the provisions took effect, measured accordingly), a CAC security assessment is required. Below that threshold, SCC filing or certification generally applies. Always verify the current text before filing β€” thresholds have been revised repeatedly.
Is separate consent required for cross-border transfers of sensitive data?
Yes. Cross-border transfer is treated as a distinct processing purpose: PIPL requires specific, informed, separate consent from the individual (where consent is the legal basis), plus a Personal Information Protection Impact Assessment (PIPIA) and contractual safeguards with the overseas recipient.
What are the penalties for unlawful sensitive data exports?
PIPL penalties reach RMB 50 million or 5% of annual revenue, plus suspension of business, removal of responsible persons, and personal fines of up to RMB 1 million for executives. Data Security Law and Criminal Law exposure can stack on top for important data or state-secret categories.

Related Guides

Found this useful?

Stay Informed

Weekly Policy Briefing

Get a curated digest of the latest Chinese policy changes, investment insights, and regulatory updates β€” delivered every Monday morning. Choose what matters to you.

Customize your briefing

Industries

Cities / Regions

Frequency

No spam. Unsubscribe anytime. Update your preferences anytime.