Regulation πŸ“„ In force β€” date not recorded πŸ‡¨πŸ‡³ National Trade
⚠ Verification pending

Cross-Border Data Transfer Regulations (Updated 2025)

Published: September 15, 2025

Sources & Verification

Primary Source

State Council of the PRC β€” Official document β†—

CPG Analysis

Editor summary based on the official source linked above.

Verification

Verification pending

No verification date has been recorded for this entry yet.

Report an issue with this policy β†—

⚑ Impact at a Glance

Who is affected

CIOs and data protection officers at multinational companies operating in China; HR directors transferring employee data; legal and compliance teams managing cross-border operations.

Cities / Agencies

Nationwide Β· State Council of the PRC

What to do now

Monitor for implementation details. No action required until official implementation documents are published.

Source & verification

Official source Β· Verification pending

Executive Summary

China relaxed its cross-border data transfer rules in September 2025, exempting many routine business data transfers from security assessments. The updated framework simplifies compliance for foreign companies handling HR, procurement, and non-sensitive operational data.

Key Points

1

Routine HR, procurement, and non-sensitive operational data transfers exempted from security assessment requirements

2

Data that does not contain "important data" or personal information of more than 100,000 individuals is exempt

3

Free trade zones granted additional flexibility for data exports in pilot programs

4

Negative list approach adopted: data categories requiring assessment are specified, everything else is permitted

5

Foreign companies still need to classify their data and maintain transfer records for compliance

6

Significant improvement from the strict 2022 framework β€” estimated 80% of routine business transfers now exempt