Draft: real corpus-derived content, automatically generated — not yet reviewed by an analyst (make_demo.md D8). Do not forward as a reviewed finding.
← All topics

Who may move data out of China — and who decides?

Data through 2026-07 · release DRAFT

Map data: Natural Earth

View as table
Cumulative matching documents by province, through 2026
ProvinceFirst appearanceCumulative documents (2026)
Beijing (北京市)201619
Guangdong (广东省)201618
Shanghai (上海市)20209
Liaoning (辽宁省)20226
Shandong (山东省)20156
Zhejiang (浙江省)20156
Guangxi (广西壮族自治区)20205
Hebei (河北省)20124
Hubei (湖北省)20163
Yunnan (云南省)20223
Guizhou (贵州省)20212
Sichuan (四川省)20202
Henan (河南省)20182
Tianjin (天津市)20202
Inner Mongol (内蒙古自治区)20122
Gansu (甘肃省)20251
Fujian (福建省)20201
Hainan (海南省)20121
Ningxia (宁夏回族自治区)20181
Hunan (湖南省)20251
Jiangxi (江西省)20181
Heilongjiang (黑龙江省)20241
010203040202120222023202437
View as table
Matching documents per year
YearDocumentsEvent
20121
20130
20140
20153
20169
20176
201820
201911
202016
202111Data Security Law takes effect
202211Measures for Security Assessment of Data Export
202311Standard Contract for personal information export
202426Regulations promoting and easing cross-border data flows
202537
202628
Replay of output generated by the live pipeline on 2026-07-19· original runtime 12s.

Establishment of the Dual-Track Data Export Framework

Early Chinese regulations focused on administrative oversight of specific cross-border information flows, such as technology export contract registration and the reporting of international flight passenger data for security and customs purposes. The definitive shift toward a security-centric framework occurred with the Data Security Law and Personal Information Protection Law, which established mandatory domestic storage for 'important data' and personal information collected by critical information infrastructure operators. Under these national laws, the state cyberspace authority, in coordination with other departments, assumed the role of deciding who may move data abroad through centralized security assessments.

Piloting Liberalization in Free Trade Zones

To mitigate the impact of strict security reviews on trade, the central government authorized Free Trade Zones in Shanghai, Beijing, and Guangdong to explore more flexible, categorized management models for data mobility. Policy implementation clarified specific thresholds, requiring formal security reviews only if a processor provides personal information of over one million individuals or ten thousand sensitive records within a year. Conversely, data that has not been explicitly designated or publicly released as 'important data' by relevant authorities is exempt from the high-level security assessment requirement.

Refinement through Negative Lists and Standardized Services

The most recent phase of policy development introduces 'negative lists' in pilot zones, effectively permitting any data not explicitly restricted to be exported without individual security reviews. Specific sectoral guidance has also emerged, such as specialized compliance manuals for the financial industry and directives to standardize 'important data' identification in fields like aviation and medicine. To ease compliance, local authorities in regions like Shenzhen and Beijing have established one-stop service platforms to assist enterprises with data exit certifications and risk assessments.