Back to list

Interpretation of the New Regulations on the Measures for Security Assessment of Data Cross-Border Transfer

2023-02-27 · Admin

I. Introduction

Data security is a critical component of national security. The cross-border transfer of data concerns not only the security of personal information but also national security and the public interest. On July 7, 2022, the Cyberspace Administration of China promulgated the Measures for Security Assessment of Data Cross-Border Transfer (hereinafter referred to as the “Assessment Measures”), effective as of September 1, 2022. The Assessment Measures are designed to implement the relevant provisions on data cross-border transfer under the Cybersecurity Law, the Data Security Law, and the Personal Information Protection Law, to regulate data cross-border transfer activities, protect personal information rights and interests, safeguard national security and the public interest, and promote the secure and free flow of data across borders. This article will interpret the Assessment Measures from an enterprise perspective.

II. Legal Provisions

The Assessment Measures clarify that these Measures apply to the security assessment of important data and personal information collected and generated during operations within the territory of the People’s Republic of China that are provided by data processors to overseas recipients. At the same time, the Assessment Measures stipulate the circumstances under which a declaration for data cross-border transfer security assessment shall be made, as well as the specific requirements, assessment procedures, supervision and management system, legal liabilities, and compliance rectification requirements for such assessments.

The following sections will interpret the legal provisions from three aspects: the scope of application, the circumstances of data cross-border transfer, and the security assessment of data cross-border transfer.

1.Scope of Application

Pursuant to the relevant provisions of the Assessment Measures[①], a data processor shall, under any of the following four circumstances, declare a data security assessment to the national cyberspace administration through the provincial-level cyberspace administration of its locality:

(1) A data processor provides important data to a party outside the territory of China;

Important data generally refers to data that, once tampered with, destroyed, leaked, or illegally obtained or used, may endanger national security, economic operation, social stability, public health, or public safety. However, the Data Security Law stipulates that the catalog of important data shall be determined by various regions and departments. Therefore, enterprises in different industries and sectors need to identify the important data subject to security assessment in accordance with the regulations of the relevant departments in their respective localities and industries.

(2) An operator of Critical Information Infrastructure and a data processor that processes the personal information of more than one million individuals provides personal information to a party outside the territory of China;

(3) A data processor that has provided the personal information of 100,000 individuals or the sensitive personal information of 10,000 individuals cumulatively to a party outside the territory of China since January 1 of the preceding year provides personal information to a party outside the territory of China;

(4) Other circumstances under which a declaration of a security assessment for outbound data transfer is required as stipulated by the national cyberspace administration.

The key points among these are the identification of important data, the identification of operators of Critical Information Infrastructure, and the identification of sensitive personal information.

ØImportant Data

This generally refers to data that, once tampered with, destroyed, leaked, or illegally obtained or used, may endanger national security, economic operation, social stability, public health, or public safety. However, the Data Security Law stipulates that the catalog of important data shall be determined by various regions and departments[ii]. Therefore, enterprises in different industries and sectors need to identify the important data subject to security assessment in accordance with the regulations of the relevant departments in their respective localities and industries.

ØOperators of Critical Information Infrastructure

Pursuant to the relevant provisions of the Regulations on the Security Protection of Critical Information Infrastructure, the competent authorities and supervisory authorities of key industries and sectors, acting as the departments responsible for security protection, shall identify the operators and notify the operators of the identification results in a timely manner[③]. Therefore, if an enterprise receives a notification from the security protection department, the enterprise shall be deemed an operator of critical information infrastructure.

ØSensitive Personal Information

The identification of sensitive personal information may be determined in accordance with the relevant definitions of sensitive personal information under the Personal Information Protection Law[④]. Additionally, reference may be made to the categories of sensitive personal information enumerated in the Information Security Technology — Personal Information Security Specification, such as personal financial information, personal health and physiological information, personal biometric information, and personal identification information. Sensitive personal information should also be identified based on the context in which it is used.

2.Scenarios of Data Export

According to the press interview on the Measures, data export activities primarily include: (i) the transfer or storage outside the territory of China of data collected and generated by a data processor during its operations within the territory of China; and (ii) where data collected and generated by a data processor is stored within the territory of China, but foreign institutions, organizations, or individuals are able to access or retrieve such data.

Meanwhile, in accordance with the relevant provisions of the Cybersecurity Review Measures, the Data Security Law, the Personal Information Protection Law, and the Cybersecurity Law[⑤], the specific circumstances of data cross-border transfer primarily include: (1) listing overseas; (2) access by foreign judicial or law enforcement agencies; (3) collection of domestic information abroad; (4) provision of data to overseas recipients; and (5) other circumstances involving the cross-border transfer of data.

III. Practice of Data Cross-Border Transfer Security Assessment

1.Procedure for Data Cross-Border Transfer Security Assessment

Pursuant to the relevant provisions of the Assessment Measures[⑥], after confirming that the intended cross-border transfer falls within the scope of application of the Assessment Measures, an enterprise must first conduct a self-assessment of the risks associated with the data cross-border transfer. The key matters to be assessed are as follows:

(1) The legality, legitimacy, and necessity of the purpose, scope, and methods of the data cross-border transfer and the processing of data by the overseas recipient;

(2) The volume, scope, type, and sensitivity of the data to be transferred, and the risks that such data cross-border transfer may pose to national security, the public interest, or the lawful rights and interests of individuals or organizations;

(3) Whether the responsibilities and obligations undertaken by the overseas recipient, as well as the management and technical measures and capabilities for fulfilling such responsibilities and obligations, can ensure the security of the transferred data;

(4) The risks of the data being tampered with, destroyed, leaked, lost, transferred, or illegally accessed or used during and after the cross-border transfer, and whether the channels for safeguarding the rights and interests of individuals with respect to their personal information are unobstructed;

(5) Whether the contract or other legally binding documents (hereinafter collectively referred to as "legal documents") to be entered into with the overseas recipient concerning the data cross-border transfer adequately stipulate the responsibilities and obligations for data security protection;

(6) Other matters that may affect the security of data cross-border transfer.

After completing the self-assessment, the enterprise shall submit the application materials to the provincial cyberspace administration. The provincial cyberspace administration shall complete a completeness review within five (5) working days from the date of receipt of the application materials. If the application materials are complete, they shall be forwarded to the national cyberspace administration; if the application materials are incomplete, they shall be returned to the data processor, and the data processor shall be informed at one time of the materials required to be supplemented. The national cyberspace administration shall, within seven (7) working days from the date of receipt of the application materials, determine whether to accept the application and notify the data processor in writing[⑦].

During the security assessment, if it is found that the application materials submitted by the data processor do not meet the requirements, the national cyberspace administration may request the data processor to supplement or correct them. If the data processor fails to supplement or correct them without justifiable reasons, the national cyberspace administration may terminate the security assessment. The national cyberspace administration shall complete the security assessment within forty-five (45) working days after acceptance; if the circumstances are complex or materials need to be supplemented or corrected, the timeline shall be extended, and the data processor shall be informed of the expected extension period[⑧].

The validity period of the data cross-border transfer security assessment result is two (2) years. If the data processor has any objection to the assessment result, it may apply to the national cyberspace administration for a re-assessment within fifteen (15) working days from the date of receipt of the assessment result. If the validity period expires but the enterprise needs to continue conducting data cross-border transfer activities, the enterprise shall re-submit an application for assessment at least sixty (60) working days prior to the expiration of the validity period[⑨].

2.Application Materials for Data Cross-Border Transfer Security Assessment

In accordance with the relevant provisions of the Assessment Measures[⑩], the following materials shall be submitted when applying for a security assessment of data cross-border transfer:

(1) Application Form (including the Letter of Commitment and the Declaration Form);

(2)Self-Assessment Report on the Risks of Data Cross-border Transfer (which must be completed within three months prior to the submission of the application);

(3) The legal documents to be entered into between the Data Processor and the Overseas Recipient (which may include contracts, internal company bylaws, etc.);

(4) Other materials required for the security assessment work (materials used to support the aforementioned three categories of materials).

IV. Conclusion

From the above interpretation of the Assessment Measures, it can be seen that the security assessment work for data cross-border transfer has been standardized and proceduralized. Relevant enterprises should plan for the security assessment in advance when conducting cross-border data transfers, and strengthen their own supervision to achieve a state of compliance, so as not to affect normal business operations. What the Assessment Measures safeguard is not only the security of personal information, but also national security and the public interest of society.


[①]Article 4 of the Measures for Security Assessment of Data Cross-border Transfer

[②]Article 21, Paragraphs 1 and 3 of the Data Security Law of the People's Republic of China

[③]Article 8 of the Regulations on the Security Protection of Critical Information Infrastructure

[④]Article 28 of the Personal Information Protection Law of the People's Republic of China

[⑤]Article 7 of the Cybersecurity Review Measures; Article 36 of the Data Security Law of the People's Republic of China; Article 3, Paragraph 2 of the Personal Information Protection Law of the People's Republic of China

[⑥]Article 5 of the Measures for Security Assessment of Cross-Border Data Transfer

[⑦]Article 7 of the Measures for Security Assessment of Cross-Border Data Transfer

[⑧]Articles 11 and 12 of the Measures for Security Assessment of Cross-Border Data Transfer

[⑨]Articles 13 and 14 of the Measures for Security Assessment of Cross-Border Data Transfer

[⑩]Article 6 of the Measures for Security Assessment of Cross-Border Data Transfer