China Standard Contractual Clauses — when SCC is the transfer path
China Standard Contractual Clauses are the PIPL SCC transfer path — execute the CAC template, complete PIPIA, and file. EU SCCs do not clear a China SCC.
China Standard Contractual Clauses are the transfer path only when CAC rules put the outbound pipe on the PIPL SCC rail — not when Important Data, CIIO status, or current CAC thresholds force a security assessment. Execute the mandatory template, complete PIPIA, and file with provincial CAC. An incomplete file is not a cleared transfer. EU SCCs do not substitute. For the three-mechanism overview, use cross-border data transfer China.

What China Standard Contractual Clauses actually are
Hard names this SCC Decision Map uses — sibling to PIPL product gates for inventory and consent, and to cross-border data transfer for the three-mechanism overview:
- China Standard Contractual Clauses / China SCC — CAC Measures for the Standard Contract for Outbound Transfer of Personal Information (effective 1 June 2023) (CAC). Product language: PIPL SCC — execute the mandatory template, complete PIPIA, file with provincial CAC. Not an EU SCCs paste and not a silent HQ DPA.
- China CBDT SCC sits beside security assessment and certification. Current overlay: Provisions on Promoting and Regulating Cross-border Data Flows (CAC 2024-03-22). Where they conflict with earlier Measures, these Provisions control. Use current CAC thresholds with counsel — do not freeze stale numeric rows here.
- Filing surface — sjcj.cac.gov.cn, under CAC. File after the contract takes effect (Measures: generally 10 working days). Incomplete file ≠ transfer cleared.
- PIPIA is a pack ingredient — impact assessment + standard contract + filing. Sequence the assessment on PIPIA / Important Data.
- When SCC is the wrong path — Important Data outbound, CIIO, or volumes that trigger assessment. Stop and use the CBDT Guide’s assessment fork — do not “SCC anyway.”
- Common myth — “Privacy policy + EU SCCs = China SCC cleared.”
Vocabulary first. Next: what must exist before an SCC filing sprint is real work.
What must exist before an SCC filing sprint starts
Missing any of these stops your product team before a PIPL SCC pack is executable — not after legal pastes an EU exhibit into the DPA.
| Precondition | Why your process stalls |
|---|---|
| Honest outbound map — which personal information leaves Mainland China, to which recipient, for which purpose | Teams argue “only logs” while CRM, identity, and analytics already sync abroad |
| Path call locked — SCC vs assessment vs certification vs keep-in-country | Half the stack stays on a global SaaS default; the file never owns a calendar |
| PIPIA owner and evidence tied to named systems | The pack needs an impact assessment, not a slide arrow — see PIPIA |
| Mainland China entity or organizing path for provincial CAC | Overseas-only applicants cannot drive the Mandarin filing surface alone |
| Recipient schedule — identity, location, processing, retention, security measures | Template annexes reject unnamed “HQ / affiliates” |
| Timeline that separates SCC from ICP / store clocks | Store live ≠ outbound pipe filed |
Product teams without Mainland China ops rails usually cannot treat a China SCC as an English questionnaire finished from HQ.
From path check to template, PIPIA, and file
| Stage | Decision / outcome |
|---|---|
| 1. Confirm PI outbound is required | Must personal information leave Mainland China for the product to work? If not, keep residency and close this map |
| 2. Confirm SCC path vs assessment | Current CAC thresholds, CIIO, Important Data, and sensitive-PI facts — if assessment is required, stop |
| 3. Complete PIPIA | Impact assessment that matches the live architecture, not a generic privacy PDF |
| 4. Execute the template SCC | Mandatory CAC form + non-conflicting extra clauses; transfer only after the contract takes effect |
| 5. Provincial file | Submit contract + PIPIA on sjcj.cac.gov.cn — generally 10 working days after effect |
| 6. Operate / re-file on change | Purpose, volume, recipient, or architecture change → re-PIPIA, supplement or re-execute, re-file |
Do not treat stage 5 as “we emailed a PDF.” The filing surface is the CAC outbound system; provincial CAC is the counterparty, not your HQ counsel’s inbox.
Why EU SCCs do not clear a China SCC
EU exhibit pasted as the China contract → filing reject. The Measures require the CAC annex template. Extra clauses are allowed only when they do not conflict. A GDPR module with “China” in the header is still the wrong form.
Privacy policy updated, PIPIA skipped → pack incomplete. Notices help PIPL product gates. They do not replace the impact assessment the Standard Contract Measures require before outbound transfer.
“SCC anyway” on an assessment fact pattern → enforcement restart. Important Data outbound, CIIO, or current CAC thresholds that trigger assessment are a hard stop. The CBDT Guide owns that fork; this Guide does not invent a waiver.
Contract signed, file never opened → pipe not cleared. The Measures let transfer start after the contract takes effect, then impose a filing clock. Teams that stop at signature still owe provincial CAC the pack.
Keep-in-country slide, HQ admin still pulls PI → silent outbound. Operators, backups, and support tooling that retrieve Mainland China personal information reopen the transfer. Align hosting with China Product Hosting before you call the SCC path closed — or unnecessary.
2023 Measures read in isolation → stale threshold call. The 2024 Provisions control where they conflict. Confirm current CAC thresholds with counsel; do not freeze last year’s row counts in a launch deck.
Where SCC filing stalls
- No path owner — Engineering, legal, and China ops each hold a different export diagram.
- EU SCCs treated as a global standard — The China SCC is a CAC form plus PIPIA plus file.
- PIPIA treated as optional paperwork — It is a pack ingredient, not a nice-to-have memo.
- Filing surface ignored — Screenshot PDFs in a shared drive are not a provincial CAC file.
- Assessment facts waved through — CIIO, Important Data, and current volume rules are not a product guess.
- Free-trade-zone or exemption myths without counsel — Scenario easements exist in the 2024 Provisions; they are not a blanket launch waiver.
- No China landing partner when Mandarin portals are missing — Overseas-only teams stall at provincial CAC queues.
When a China landing partner owns the CAC file
Most product teams exploring Mainland China entry need a China landing partner (beside counsel) once the path call says personal information must leave on a China SCC — provincial CAC filing, Mandarin PIPIA evidence, and a coherent export map the CAC surface will actually accept. Your team still owns product architecture and the keep-versus-export decision; the partner does not invent an SCC path the 2024 Provisions do not allow.
What we can offer?
China Standard Contractual Clauses are a PIPL SCC pack — path check, template, PIPIA, and provincial file — before the outbound pipe is launch-ready. Chinaready helps your product team see whether China SCC is the right rail and what must exist before filing:
- China Readiness Assessment — Map which China features force outbound personal information, whether PIPL SCC is plausible versus assessment, and which launch date is fake until the path is locked.
- China Access Acceleration — Keep China-facing admin and critical deps reachable while the SCC pack is built — without silently reopening undeclared outbound PI pipes.
- China Product Hosting — Place China-critical workloads so “keep in Mainland China” is an architecture fact when SCC is the wrong path — or so the export map matches the live stack when SCC is required.
- Mobile App Distribution — Ship store launches on their own gates while privacy and outbound-transfer stories match the live app backends reviewers and CAC would test.
Contact us when your China launch depends on HQ sync, global CRM, or overseas analytics — and you need the China SCC path decided before marketing owns the date.
Frequently asked questions
What are China Standard Contractual Clauses?
China Standard Contractual Clauses are the CAC mandatory template for providing personal information from Mainland China operations to an overseas recipient when the PIPL SCC path applies. Product teams treat them as a pack — template contract, PIPIA, and provincial CAC filing — not as a renamed HQ DPA.
Is a China SCC the same as an EU SCC?
No. A China SCC is a CAC form that must be executed as published, then filed with provincial CAC together with a PIPIA report. EU SCCs, GDPR exhibits, and a silent HQ processor addendum do not clear the China path.
When is PIPL SCC the right outbound path?
PIPL SCC is the right path when personal information must leave Mainland China and current CAC rules put that transfer on the standard-contract rail rather than security assessment or certification. Important Data outbound, CIIO status, and current CAC thresholds can force assessment instead — confirm against the 2024 CAC Provisions with counsel.
What is China CBDT SCC versus security assessment?
China CBDT SCC is one of three outbound mechanisms beside CAC security assessment and personal-information protection certification. Use this Guide when the standard contract is the selected rail. Use the cross-border data transfer Guide for the three-mechanism overview. Do not “SCC anyway” when assessment is required.
Does filing the China SCC mean the transfer is cleared?
No. The contract must take effect first, then you file — generally within 10 working days under the Standard Contract Measures — on the CAC outbound system. An incomplete or rejected file is not a cleared pipe. Re-file when purpose, volume, recipient, or architecture changes.
Can product teams finish a China SCC filing without Mainland China ops?
Usually no. Provincial CAC channels, Mandarin packs, PIPIA evidence, and the filing surface need Mainland China ops or a China landing partner beside counsel.


