Map data: Natural Earth
View as table
| Province | First appearance | Cumulative documents (2026) |
|---|---|---|
| Beijing (北京市) | 2016 | 19 |
| Guangdong (广东省) | 2016 | 18 |
| Shanghai (上海市) | 2020 | 9 |
| Liaoning (辽宁省) | 2022 | 6 |
| Shandong (山东省) | 2015 | 6 |
| Zhejiang (浙江省) | 2015 | 6 |
| Guangxi (广西壮族自治区) | 2020 | 5 |
| Hebei (河北省) | 2012 | 4 |
| Hubei (湖北省) | 2016 | 3 |
| Yunnan (云南省) | 2022 | 3 |
| Guizhou (贵州省) | 2021 | 2 |
| Sichuan (四川省) | 2020 | 2 |
| Henan (河南省) | 2018 | 2 |
| Tianjin (天津市) | 2020 | 2 |
| Inner Mongol (内蒙古自治区) | 2012 | 2 |
| Gansu (甘肃省) | 2025 | 1 |
| Fujian (福建省) | 2020 | 1 |
| Hainan (海南省) | 2012 | 1 |
| Ningxia (宁夏回族自治区) | 2018 | 1 |
| Hunan (湖南省) | 2025 | 1 |
| Jiangxi (江西省) | 2018 | 1 |
| Heilongjiang (黑龙江省) | 2024 | 1 |
View as table
| Year | Documents | Event |
|---|---|---|
| 2012 | 1 | |
| 2013 | 0 | |
| 2014 | 0 | |
| 2015 | 3 | |
| 2016 | 9 | |
| 2017 | 6 | |
| 2018 | 20 | |
| 2019 | 11 | |
| 2020 | 16 | |
| 2021 | 11 | Data Security Law takes effect |
| 2022 | 11 | Measures for Security Assessment of Data Export |
| 2023 | 11 | Standard Contract for personal information export |
| 2024 | 26 | Regulations promoting and easing cross-border data flows |
| 2025 | 37 | |
| 2026 | 28 |
Establishment of the Dual-Track Data Export Framework
Early Chinese regulations focused on administrative oversight of specific cross-border information flows, such as technology export contract registration and the reporting of international flight passenger data for security and customs purposes. The definitive shift toward a security-centric framework occurred with the Data Security Law and Personal Information Protection Law, which established mandatory domestic storage for 'important data' and personal information collected by critical information infrastructure operators. Under these national laws, the state cyberspace authority, in coordination with other departments, assumed the role of deciding who may move data abroad through centralized security assessments.
Piloting Liberalization in Free Trade Zones
To mitigate the impact of strict security reviews on trade, the central government authorized Free Trade Zones in Shanghai, Beijing, and Guangdong to explore more flexible, categorized management models for data mobility. Policy implementation clarified specific thresholds, requiring formal security reviews only if a processor provides personal information of over one million individuals or ten thousand sensitive records within a year. Conversely, data that has not been explicitly designated or publicly released as 'important data' by relevant authorities is exempt from the high-level security assessment requirement.
Refinement through Negative Lists and Standardized Services
The most recent phase of policy development introduces 'negative lists' in pilot zones, effectively permitting any data not explicitly restricted to be exported without individual security reviews. Specific sectoral guidance has also emerged, such as specialized compliance manuals for the financial industry and directives to standardize 'important data' identification in fields like aviation and medicine. To ease compliance, local authorities in regions like Shenzhen and Beijing have established one-stop service platforms to assist enterprises with data exit certifications and risk assessments.