Skip to main content

Insights

China and EU Cross-Border Personal Data Transfers in 2026

Moving personal data between Europe and China means satisfying GDPR and PIPL at once, and neither recognises the other. Which route applies to your transfers.

August 19, 2026 · 17 min read

China and EU cross-border personal data transfer compliance under GDPR and PIPL

Moving employee, customer or supplier data between Europe and China means satisfying two regimes at once, and neither recognises the other.

Almost every foreign-invested company in China transfers personal data across borders as part of ordinary operations. Payroll and HR records flow to a group system. Customer contact details sit in a global CRM. Supplier contacts, visitor logs and expense claims travel through shared platforms. Each of these flows is regulated on both ends, by the General Data Protection Regulation in Europe and the Personal Information Protection Law in China.

The two frameworks share principles and diverge on mechanics. Understanding where they overlap and where they do not is what keeps a routine data flow from becoming a compliance incident.

Common ground

The GDPR and the PIPL look similar at a distance. Both apply extraterritorially, reaching processing carried out outside their territory where EU or Chinese personal data is involved. Both require a lawful basis for processing, transparency toward individuals, and appropriate security measures. Both grant individuals rights over their data and both impose accountability on the organisations handling it.

The underlying philosophies differ. The GDPR is built around accountability, placing the compliance burden on the organisation and relying on independent supervisory authorities to oversee it. The PIPL sits within a wider governance framework covering data security and digital sovereignty, in which regulatory approval plays a more central role. That difference explains most of the practical divergence.

Sending data from the EU to China

Under Chapter V of the GDPR, personal data may leave the EU only if one of the permitted conditions is met. The simplest is an adequacy decision by the European Commission confirming that the destination country provides essentially equivalent protection.

There is no adequacy decision for China, and none is in prospect. Transfers therefore rely on alternative safeguards, in practice Standard Contractual Clauses approved by the Commission, or Binding Corporate Rules within a multinational group.

Safeguards alone are not sufficient. Companies are generally expected to carry out a Transfer Impact Assessment examining whether laws in the destination country, particularly those enabling public authority access to data, undermine the protection the safeguards promise. For China this assessment requires honest engagement with the national security and data access provisions in Chinese law rather than a template conclusion.

The workable position for most groups is Standard Contractual Clauses plus a documented Transfer Impact Assessment, supported by supplementary measures such as minimisation, encryption, access restriction and defined retention periods.

Sending data out of China

The PIPL takes a different approach. Rather than adequacy and contractual safeguards, it sets out specific routes that a transfer out of China must follow.

A CAC security assessment. Required for larger volume transfers, important data, and critical information infrastructure operators. This is a regulatory review process, not a self-assessment, and it takes time.

The Chinese standard contract. A CAC-issued standard contract, executed with the overseas recipient and filed with the provincial cyberspace authority together with a personal information protection impact assessment.

Certification. Protection certification by an accredited body, used less often in practice but available.

The 2024 facilitation rules introduced volume thresholds and exemptions that removed many low-volume and routine flows from the heavier routes, including certain transfers necessary to perform a contract with the individual and some cross-border HR management transfers required by employment rules. These exemptions genuinely reduced the burden, but they are conditional and volume-sensitive, so they need to be assessed against your actual data volumes rather than assumed.

Two further obligations apply regardless of route. Individuals must receive specific notice about the overseas recipient and be given a route to exercise their rights, and separate consent is required where consent is the basis relied upon. Companies must also carry out and retain a personal information protection impact assessment.

The asymmetry that catches groups out

The two directions are not mirror images, and the same dataset can require entirely different work depending on which way it moves.

An EU to China transfer is largely a documentation exercise: contract, assessment, supplementary measures, records. A China to EU transfer may require a filing with a Chinese regulator, or a full security assessment, before the flow can lawfully continue.

A global HR platform shows the problem clearly. European employee data flowing to a shared system hosted or accessed in China needs SCCs and a Transfer Impact Assessment. Chinese employee data flowing to the same system needs a PIPL route, notice, and an impact assessment on the Chinese side. One platform, one apparent data flow, two separate compliance workstreams.

Which PIPL route applies to you

Because the Chinese routes are threshold driven, the first question is not which mechanism you prefer but which one your volumes and data types put you in. The framework works through a series of gates.

Important data and critical information infrastructure. If your transfer involves data classified as important data, or your entity is a critical information infrastructure operator transferring personal information, the security assessment route applies. There is no contractual alternative.

High-volume transfers. Above the higher personal information volume threshold, the security assessment route applies. This is the gate that catches large consumer businesses and companies running consolidated group systems covering substantial Chinese workforces or customer bases.

Mid-volume transfers. Between the lower and higher thresholds, the standard contract or certification routes are available. This band covers a large proportion of foreign-invested enterprises, and the standard contract is the mechanism most choose.

Low-volume transfers. Below the lower threshold, transfers may fall outside the formal mechanisms entirely, though the notice, consent and impact assessment obligations continue to apply.

Exemptions independent of volume. Certain transfers are exempted by nature rather than size, including transfers necessary to perform a contract to which the individual is a party, such as cross-border purchases, bookings and visa processing, transfers necessary for cross-border human resources management carried out in accordance with lawful employment rules and a collective contract, transfers necessary to protect life, health or property in an emergency, and data not containing personal information or important data at all.

Where the exemptions are misread

The HR exemption is the one most often over-relied upon. It is conditional on the transfer being necessary for human resources management conducted under lawful employment rules, which means the internal HR policies and collective documentation actually need to exist and to support the transfer. It also does not license the transfer of everything an HR system happens to hold. Performance data necessary for a global talent process may qualify; a full extract of employee records replicated to a group data warehouse for analytics purposes is a harder argument.

The contract necessity exemption is similarly narrower than it first appears. Necessary means necessary to perform the contract with that individual, not commercially convenient for the group. A hotel transferring booking details to fulfil a reservation is within it. The same hotel transferring the guest history to a global marketing platform is not.

Free trade zones add a further layer, with negative lists in several zones permitting transfers outside the general mechanisms for data not on the list. Where your entity is zone-registered, this is worth checking, since it can materially simplify the position.

The standard contract filing package

For companies in the mid-volume band, the standard contract route is the practical answer, and the filing is more substantial than the phrase suggests.

The executed standard contract. The CAC-issued template, signed with the overseas recipient. The core terms are fixed and cannot be varied, though additional terms may be added provided they do not conflict. For intra-group transfers this means your parent or affiliate is signing a Chinese-law instrument containing meaningful obligations, including submitting to the jurisdiction provisions in the template and accepting supervision-related commitments. Group legal teams sometimes need time to become comfortable with this, and that lead time should be planned for.

The personal information protection impact assessment. The substantive document. It needs to address the legality, legitimacy and necessity of the purpose, scope and method of processing on both the Chinese and overseas sides; the volume, scope, categories and sensitivity of the data and the risks the transfer poses to individuals' rights; the obligations the overseas recipient undertakes and whether its management and technical measures can fulfil them; the risk of the data being tampered with, destroyed, leaked, lost or misused after transfer, and whether individuals have accessible routes to protect their rights; and the effect of the legal environment and data protection policies in the recipient's country on performance of the contract.

Supporting materials. The filing form, the entity's business licence, the signatory's identification and authority, and supporting documentation on the technical and organisational measures relied upon.

Filing is with the provincial cyberspace administration where the entity is located, and practice varies between provinces on the level of detail expected and how actively files are reviewed. A filing is not a rubber stamp. Files are returned for further information, and the assessment is where that usually happens.

A refiling is required when circumstances change materially, including a change in purpose or scope, an increase in the categories or volume of data, a change in the overseas recipient, a change in the retention period, or a change in the legal environment of the recipient's country that affects the data. Growth alone can therefore trigger a fresh filing.

What a security assessment involves

For companies above the higher threshold or handling important data, the security assessment is a regulatory review rather than a filing, and it should be planned as a project.

The application goes to the provincial cyberspace department, which conducts a completeness check before passing it to the CAC for substantive review. The submission includes a self-assessment covering broadly the same ground as the impact assessment but in greater depth, the legal documents governing the transfer, and detailed material on the data, the systems and the security measures.

The review considers the necessity of the transfer, whether the volume and scope are proportionate to the stated purpose, the security capability of both parties, and the risk to national security and public interest as well as to individuals. Necessity is the criterion companies most consistently underestimate. A group accustomed to replicating all data to a central platform as a matter of architecture will struggle to explain why every field needs to cross the border.

Timelines run to several months in practice once preparation, the completeness stage, substantive review and any requests for further information are counted. An approval has a defined validity period, after which extension must be sought, and material changes require a fresh assessment. Companies that leave this until a business deadline is imminent generally find the calendar does not accommodate them.

A worked HR platform scenario

A German manufacturing group operates a global HR system hosted in Frankfurt. Its Chinese WFOE employs four hundred people. Employee master data, payroll inputs, performance records and organisational information are held centrally, and the China HR team accesses the system through a browser. Group HR in Germany can view Chinese employee records, and a shared services team in Poland processes payroll for several countries including China.

On the Chinese side, this is a transfer of personal information out of China even though no file is ever emailed anywhere. The data is stored overseas, so the flow is continuous. At four hundred employees the volume sits well below the higher threshold, so the standard contract route is available. The HR management exemption may be arguable for some of the flow, but only if supported by proper employment rules and a collective contract, and the group is unlikely to be comfortable resting the entire architecture on it.

The workable position is a standard contract with the German parent, a filed impact assessment, employee privacy notices naming the overseas recipients and the categories transferred, separate consent where consent is the basis relied upon, and defined access restrictions so that the Polish shared services team sees only the payroll fields it needs.

On the European side, the reverse flow also needs attention. European employee data visible to a China-based regional HR manager is a transfer to China, requiring Standard Contractual Clauses and a Transfer Impact Assessment. Two mechanisms, two assessments, one system.

A worked CRM scenario

A European consumer brand sells in China through its own store and platform partners, and holds customer records in a global CRM hosted outside China. It has around three hundred thousand Chinese customer records including contact details, purchase history and loyalty data, and it uses the platform for marketing automation.

This is a materially harder position than the HR case. The volume is high enough to require careful threshold analysis and may push the transfer into security assessment territory. The contract necessity exemption does not cover marketing use. Purchase history combined with contact detail and behavioural data is a rich dataset, and the necessity question is sharp: does the marketing platform need identified customer records, or would pseudonymised segments serve the purpose?

Many brands in this position restructure rather than seek approval for the existing architecture. Keeping the identified customer database in China, transferring only aggregated or pseudonymised data for group analytics, and running marketing execution locally reduces the transfer to something defensible. That is an architectural decision with cost implications, which is why it belongs in the systems roadmap rather than in a compliance review conducted after the platform is built.

Remote access is a transfer

The single most common gap in flow mapping is the assumption that data physically stored on a Chinese server is not being transferred.

Access from outside China to data held in China is treated as a cross-border transfer. That brings a long list of routine activities into scope. An overseas IT team administering a Chinese server. A group finance analyst querying a Chinese database for consolidated reporting. A software vendor providing remote support and troubleshooting a production issue. A group internal audit team reviewing Chinese records. Screen sharing during a video call in which Chinese personal data is displayed. Backups replicated to an overseas facility. Log and telemetry data from Chinese systems flowing to a monitoring platform hosted abroad.

Monitoring and log data deserves specific mention, because it is almost never mapped and frequently contains personal information such as usernames, device identifiers and IP addresses. Any modern observability stack hosted outside China is transferring data continuously.

The practical remedy is to treat access rights as a data transfer control. Who outside China can reach Chinese systems, what they can see, and under what documented basis. Role-based access with the China dataset scoped out by default, and support access granted on a time-limited and logged basis, is both better security practice and a cleaner compliance story.

Writing the China Transfer Impact Assessment honestly

For the European side of the equation, the Schrems II reasoning is what makes a China assessment demanding. The Court of Justice's conclusion was that contractual safeguards cannot bind a public authority in the destination country, so an exporter must assess whether local law and practice permit access that would undermine the protection the safeguards promise.

Applied to China, that means engaging with the national security, intelligence, cybersecurity and data security provisions that can require organisations to provide data or assistance to authorities, and with the practical availability of redress for a data subject. A template conclusion asserting that access is unlikely because it has never happened will not withstand scrutiny.

A credible assessment does four things. It describes the specific transfer accurately, since the analysis turns on what data, in what volume, held by whom. It identifies the relevant legal provisions rather than generalising. It assesses the realistic likelihood and impact of access for this dataset, which for a small set of business contact details is genuinely different from a large sensitive dataset. And it sets out supplementary measures and explains why they reduce risk to an acceptable level, or concludes honestly that they do not.

The supplementary measures that carry weight are those that reduce what is available to be accessed: strong minimisation, pseudonymisation where the purpose permits, encryption with keys held outside China for data at rest, short retention, tight access control and a documented process for handling government access requests, including a commitment to challenge where lawful and to notify the exporter where permitted.

Where the assessment cannot honestly conclude that risk is adequately mitigated, the answer is to change the transfer rather than the conclusion. Reduce the dataset, keep the sensitive elements local, or process in China.

Retention and deletion

Retention is the quiet lever that improves every part of this analysis, and it is usually the weakest control in a global system.

Both regimes require personal information to be kept no longer than necessary for the purpose, and the Chinese standard contract expects a defined retention period to be stated. Yet most group platforms retain indefinitely by default, which means the volume crossing the border compounds year on year. A company that was comfortably below a threshold when it filed can cross it simply by never deleting anything.

Three practices help. Set retention periods by data category and configure them in the system rather than recording them in a policy nobody implements. Include deletion or return obligations in the standard contract and in processor agreements, with evidence of completion. And check volumes against the thresholds annually, because the route you selected is only correct for the volumes you had at the time.

Building a defensible position

1. Map the flows, not the systems. List every flow of personal data into and out of China, including intra-group transfers, remote access from outside China, cloud hosting and third-party processors. Remote access counts, which surprises companies that assume data sitting on a Chinese server is not being transferred.

2. Categorise and quantify. Identify the data subjects, the categories of data, whether any of it is sensitive personal information or important data, and the volumes. PIPL routes are threshold driven, so volume determines the mechanism.

3. Select the route for each direction. Assign a GDPR mechanism for outbound EU flows and a PIPL mechanism for outbound China flows, and record why each was chosen.

4. Complete the assessments. A Transfer Impact Assessment on the European side and a personal information protection impact assessment on the Chinese side. These are the documents a regulator will ask for first.

5. Get the notices and consents right. Update privacy notices and employee documentation in China to name overseas recipients and explain rights. Where separate consent is required, collect it separately rather than bundling it into a general policy acknowledgement.

6. Apply supplementary measures. Minimise what crosses the border, restrict who can access it, encrypt in transit and at rest, and set retention limits. These strengthen both assessments.

7. Review annually and on change. Volumes grow, systems change and thresholds shift. A position that was correct at a lower volume may require a different route once the business scales.

Why this matters operationally

Cross-border data compliance is not only a legal risk. It is an operational dependency. If a transfer route is unavailable or a filing is incomplete, the flow that supports payroll, consolidated reporting or customer service is the thing that stops. Enforcement has also demonstrated that transfer compliance and incident handling are examined together, so a breach can expose transfer weaknesses that were previously untested.

Companies in a comfortable position tend to have done the unglamorous work: an accurate flow map, a chosen mechanism per direction, completed assessments, current notices, and a review cycle that catches growth before it crosses a threshold.

Acadia Advisory helps foreign-invested companies map cross-border data flows, select and document the appropriate PIPL route, prepare impact assessments and filings, and align China notices and consents with group privacy documentation. If you have never mapped what actually leaves your China entity, that is the place to start.

Related services