Sensitive personal information is where China's cross-border data regime bites hardest: separate consent, impact assessments, and the lowest thresholds to a full CAC security assessment. This guide lays out the 2026 thresholds and how to classify your flows correctly.
What Is "Sensitive" Under PIPL
PIPL Article 28 draws a wide circle. Treat the following as sensitive by default:
- Biometrics β face, fingerprint, voiceprint, iris. (Face recognition has additional dedicated rules.)
- Medical and health data β diagnoses, prescriptions, health-monitoring app data.
- Financial accounts β bank/card identifiers, transaction-level financial profiling.
- Whereabouts and location tracking β continuous location data.
- Religious beliefs, specific identities β ethnicity-linked and identity-sensitive attributes.
- All data of minors under 14 β treated as sensitive regardless of content.
The 2026 Threshold Map
Since January 1 of the applicable measurement year, count individuals (not records) whose personal information you cumulatively transferred abroad:
| Scenario | Required Path |
|---|---|
| CIIO transferring any personal information | CAC security assessment |
| Any "important data" in the flow | CAC security assessment |
| Non-sensitive PI of 1,000,000 or more individuals (cumulative since Jan 1) | CAC security assessment |
| Sensitive PI of 10,000 or more individuals (cumulative since Jan 1) | CAC security assessment |
| Non-sensitive PI of 100,000 β 1,000,000 individuals, or sensitive PI below 10,000 | SCC filing or certification (+ PIPIA, separate consent) |
| Non-sensitive PI below 100,000 individuals (no important data, non-CIIO) | Exempt from filing β PIPIA and safeguards still required |
The exact cutoffs are set by the Provisions on Promoting and Regulating Cross-Border Data Flows and related guidance β and they have been revised several times. Run your specific numbers through our Data Export Self-Checker, which encodes the current decision chain, and verify against the latest official text before filing.
Requirements That Apply Regardless of Threshold
- Separate consent β cross-border transfer is its own processing purpose; blanket consent in a general privacy policy does not suffice.
- PIPIA β a Personal Information Protection Impact Assessment completed before transfer and retained β₯ 3 years.
- Overseas recipient contract β the PIPL standard contractual obligations (purpose limitation, security measures, breach notification, sub-processor control).
- Transparency β recipient name, country, and contact details disclosed to individuals.
Practical Steps to Reduce Exposure
- De-identify aggressively. Properly anonymized data falls outside PIPL entirely; pseudonymized data does not. Most "sensitive" flows can be engineered down.
- Localize the sensitive layer. Keep biometric/medical processing in China; export only aggregates.
- Count individuals, not records. One customer with 50 transferred records counts once β but tracking this requires real instrumentation, not estimates.
- Use FTZ pilot lists. Free trade zone negative lists (Shanghai first) exempt certain flows from filing β check whether your data category is listed.
Decision Support
Get your path in two minutes with the Data Export Self-Checker. For the filing mechanics, read the SCC Filing Steps 2026; for sector context, see the Automotive CAC Checklist; and for the full framework, the Data Cross-Border Transfer Guide.
Informational only β verify with official sources; not legal advice.