Before choosing a PIPL cross-border data transfer route, document the transfer itself: the personal information handler, overseas recipient, people and data involved, purpose, necessity, volume, systems, access, retention and safeguards. The applicable route cannot be selected from a company name or cloud region alone.

The Cyberspace Administration of China's current cross-border provisions include exemptions, thresholds and different routes for particular facts. Treat those rules as a decision framework for qualified review, not as a reason to choose a mechanism before the underlying record is complete.

1. Identify the handler and every overseas recipient

List the legal entity that decides why and how the personal information is handled. Then list each overseas affiliate, vendor, support team or administrator that receives or can remotely access it.

Reconcile those names against:

  • customer and employment contracts;
  • privacy notices and consent records;
  • cloud, analytics, support and AI accounts;
  • data processing and subprocessor terms; and
  • the entity that owns each system and account.

Do not substitute a brand name for a legal entity. Record conflicts instead of silently choosing one source.

2. Describe each transfer, not only each database

Create one row for every material flow. Record:

  • the people concerned and the source of their information;
  • ordinary and sensitive personal-information categories;
  • the business purpose and why the transfer is necessary;
  • the source, destination, storage location and remote-access path;
  • the overseas recipient and any onward recipient;
  • the expected annual volume and the evidence behind it;
  • retention, return and deletion behavior; and
  • the business and technical owners who can verify the row.

Include support tickets, attachments, logs, analytics, backups, employee systems and administrator access. A polished architecture diagram is not a substitute for a complete operating inventory.

3. Separate route questions from common obligations

Prepare a short route-assessment sheet that records whether important data, sensitive personal information, critical-information-infrastructure status, free-trade-zone rules, volume thresholds or a stated exemption may be relevant. Link every answer to a current source and a dated business fact.

Keep that analysis separate from obligations that may still need attention. The current CAC provisions expressly preserve requirements such as notice, separate consent where applicable, personal-information protection impact assessment and data-security safeguards. An exemption from one filing or contract route is not a general compliance certificate.

4. Collect the evidence a route review will need

Organize:

  • current notices, consent or other relied-on records;
  • the personal-information protection impact assessment and approvals;
  • recipient and subprocessor contracts;
  • security measures, access evidence and incident contacts;
  • rights-request, correction, deletion and complaint workflows;
  • retention and deletion tests; and
  • prior filings, standard contracts, certifications or assessment results, if any.

Date every item and name the owner who can confirm that it still matches production reality.

5. Make the output reviewable

The final preparation pack should contain an entity map, transfer inventory, volume record, route-question sheet, notice and consent evidence, assessment material, recipient contracts, safeguards and a list of unresolved facts. A qualified reviewer can then apply the current PIPL and cross-border rules to the actual flow instead of reconstructing the business first.

Open the PIPL cross-border data transfer checklist to build the first action map, or review JurisLane's data and AI compliance preparation scope for a bounded next step. JurisLane does not select a legal mechanism or certify compliance through a public page or tool.

Source review

The PIPL cross-border provisions are linked to the Supreme People’s Procuratorate’s reproduction of the NPC text, checked on 10 September 2026. The CAC source was reviewed on 2 September 2026. The rules and facts can change; confirm the current text and obtain qualified advice before acting.

Sources

Editorial note: This guide supports issue preparation and qualified review. Applicable requirements depend on the facts, entities, markets and current law.