A cross-border assessment should remain connected to how the business grows. A route selected for one volume and type of information may need to be reconsidered when the processing changes.
The development
Measures effective from 1 January 2026; Q&A published 11 September 2026
China’s personal-information export certification measures took effect on 1 January 2026. CAC’s September 2026 Q&A explains that certification does not replace a required security assessment as transfer volumes grow. It also rejects splitting volumes to avoid that assessment. The appropriate route depends on the data, exporter and applicable rules.
Build a transfer register that can be maintained
For an APAC business receiving information from China, the immediate operational task is to help the exporting organisation understand what is sent, to whom and for what purpose. Avoid treating a supplier’s general assurance as a substitute for a documented assessment of the actual transfer.
Actions to consider
- Identify the exporting entity, overseas recipients, systems and purposes for each data flow.
- Record data categories and establish a reliable method for tracking relevant transfer volumes.
- Assign someone to review changes before new datasets or recipients are added.
- Have appropriate China-law support assess the route, thresholds and any applicable exemptions.
- Keep the assessment, recipient commitments and review decisions together.
Scope and timing
Certification is not a universal requirement or a universal exemption. Important data, sensitive personal information and the exporter’s status can affect the analysis. This article does not calculate a business’s thresholds or decide its transfer route.
What to prepare
A maintained transfer register with clear review triggers, rather than a one-time entry in a supplier spreadsheet.
Official sources
General information, not a determination of your organisation’s legal obligations. The actions are Averisdata’s practical suggestions; check the cited rules against your circumstances.