AMT Sustainability · 全面可持续数字化
In Force · comply now

China Cross-Border Data Compliance

Three export routes: CAC security assessment / standard-contract filing / personal-information protection certification. The framework evolves on a rolling basis, with the Shanghai FTZ negative list easing overseas projects.

Industries: All overseas DPP / CBAM / CSRD

Key dates
  • 2021.09.01Data Security Law in force
  • 2021.11.01Personal Information Protection Law in force
  • 2022.09.01Measures on Security Assessment for Data Export in force
  • 2023.06Standard Contract takes effect
  • 2024.03Provisions on Promoting & Regulating Cross-Border Data Flows issued

AMT: Cross-border module · dual-node

Overview

Full name
Data Security Law + Personal Information Protection Law + Measures on Security Assessment for Data Export + Standard Contract + Shanghai FTZ negative list
Authority
Cyberspace Administration of China (CAC) + Shanghai and other FTZ authorities
Effective
Rolling (continuously refined since 2021)
Scope
All entities processing data within China and transferring it abroad (including foreign-invested firms)
Mechanism
Three export routes: CAC security assessment / standard-contract filing / PI-protection certification

China’s cross-border data compliance is a continuously refined framework anchored by the Data Security Law and Personal Information Protection Law, with supporting measures on security assessment for data export, the standard contract and more. Companies must first classify and grade data — identifying “important data,” “personal information” and “sensitive personal information” — then choose one of three export routes by data type and volume: CAC security assessment, standard-contract filing, or PI-protection certification. The 2024 Provisions on Promoting and Regulating Cross-Border Data Flows, plus FTZ negative-list pilots in Shanghai and elsewhere, give most overseas businesses clearer, easier channels. As a Chinese service provider, AMT has completed the full set of cross-border data filings.

Timeline

From entry into force to key milestones — every compliance checkpoint.

  1. 2021.09.01
    Data Security Law in force
  2. 2021.11.01
    Personal Information Protection Law in force
  3. 2022.09.01
    Measures on Security Assessment for Data Export in force
  4. 2023.06
    Standard Contract takes effect
  5. 2024.03
    Provisions on Promoting & Regulating Cross-Border Data Flows issued
  6. 2024–持续
    Shanghai & other FTZ negative-list pilots

Who must comply

Self-check across industry, scale and export scope.

Industry

All entities processing China-domestic data and transferring it abroad, including foreign and multinational groups.

Key test

Does any data — including DPP / CBAM / CSRD project data — leave China for abroad?

Data type

First identify “important data,” “personal information” and “sensitive PI,” then choose a route.

Industry solutions: Overseas-Compliance Solution

Key requirements

Meet these core requirements to comply and access the market.

1

Classify & grade: identify “important data” / “personal information” / “sensitive PI”.

2

Choose an export route: CAC assessment / standard-contract filing / PI-protection certification.

3

Security assessment: above the threshold, file a CAC data-export security assessment.

4

Standard contract: sign with the overseas recipient and file with the provincial CAC.

5

Negative list: data outside an FTZ negative list may flow abroad under the applicable rules; listed data remains subject to the national data-export regime.

FAQ

For DPP / CBAM projects, does sending data to the EU count as “data export”?

Yes. Transferring China-generated data abroad — to EU customers, platforms or verifiers — is data export, and you must pick a compliant route by data type. AMT’s dual-node data platform minimises what actually leaves China.

What is the Shanghai FTZ negative list for?

Data outside the negative list can be exported without a security assessment or standard-contract filing, sharply cutting cost and lead time for most overseas businesses.

How is AMT itself compliant?

AMT holds ISO 27001 certification, has completed CAC data-export filing and the standard contract, and aligns with the Shanghai FTZ negative list — see the Trust Center.

Subscribe to stay ahead of regulation