Deep navy Chinaready Insights cover with a right-weighted sealed server vault, blue padlock, and severed outbound cable at a stop disc; left field open for title scrim; no headline text in the image.

Cross border data transfer China — when assessment blocks launch

Cross border data transfer China is a go-live fork — keep personal info in Mainland China, or clear CBDT security assessment, standard contract, or certification before export rails ship.

Compliance 7 min read cross-border-data-transfer, cbdt, pipl, data-export, cac, compliance, China

Frequently asked questions

What is cross-border data transfer (CBDT) in China?

China CBDT (cross-border data transfer) means providing personal information or important data collected or generated in Mainland China operations to a recipient outside Mainland China. Product teams treat it as an export / launch fork — keep processing in-country, or clear a lawful outbound mechanism before go-live on export rails.

When does a CAC security assessment block launch?

When your architecture must export personal information or important data outside Mainland China and the applicable path is a CAC-organized data export security assessment, launch marketing that depends on that outbound pipe should wait until the assessment path is real. Assessment clocks are separate from ICP, store, and app-filing clocks.

What are the main China CBDT mechanisms under PIPL?

PIPL cross border rules point to three primary mechanisms for providing personal information abroad — CAC security assessment, the personal information outbound standard contract (SCC), and personal information protection certification — plus other conditions the law allows. Current volume and scenario rules live in CAC implementing measures; confirm current thresholds with counsel / current CAC measures.

Can we avoid CBDT by hosting in Mainland China?

Often yes for the outbound-transfer gate — if personal information stays stored and processed in Mainland China and is not provided abroad, this Decision Map’s export fork may not open. You still need hosting, ICP, and product rails — see host in Mainland China and ICP peers — and PIPL product gates still apply in-country.

Is data export China the same as PIPL compliance?

No. PIPL covers lawful basis, notices, rights, and processors for personal information in scope. Data export China / CBDT is the outbound transfer layer that can freeze go-live when HQ sync, global CRM, or overseas analytics must leave Mainland China. Use the PIPL product-gates Guide for the broader privacy map; use this article for the export block.

Can product teams finish CBDT without Mainland China ops?

Usually no. Provincial CAC channels, Mandarin filing packs, standard-contract filing, certification bodies, and architecture evidence need Mainland China ops or a China landing partner beside counsel.

Tell us where you are stuck in China.

Share your product, stack, and timeline — we will point you to the next concrete step.