Meaning
Evaluates and regulates the outbound transfer of important data and personal information generated by enterprise operations within China. Established under national security statutes, the process requires entities meeting statutory volume thresholds to pass a government review before transmitting data overseas. Passing a CAC Data Export Security Assessment grants a limited administrative clearance valid for two years.
Trigger Threshold
Operational triggers for mandatory government assessment depend on data volume and entity classification rather than corporate ownership structure. Critical information infrastructure operators sending any personal information overseas must submit to the procedure. Standard data handlers processing personal records of more than one million individuals, or exporting personal details of over one hundred thousand people since the prior calendar year, automatically fall under the mandate.
Important data transfers involving industrial telemetry, supply chain mapping, environmental metrics, or power grid parameters require government security clearing regardless of personal record counts.
Review Mechanism
Administrative scrutiny focuses on national security risks, legal risks of foreign court orders, and contractual protections established with overseas recipients. Submissions require a self-assessment report, cross-border transfer contracts, technical architecture diagrams, and system data flows. Provincial offices of the Cyberspace Administration of China perform initial completeness reviews before transmitting files to the national authority for substantive evaluation.
Technical review panels examine encryption protocols, storage locations, and third-party access rights to ensure exported datasets cannot be subverted, and applications failing to address foreign law exposure face prompt administrative rejection.
Operational Limit
Regulatory clearance under the framework does not grant permanent export privileges for changing data categories or growing transfer volumes. Material changes in transfer scope, recipient jurisdiction, data categorization, or security architecture trigger a new application requirement. Entities operating without approval face administrative suspensions, business license restrictions, confiscation of illegal gains, and fines up to five percent of annual turnover under the Data Security Law.
Overseas parent companies cannot override local compliance mandates through corporate policy, leaving China-based subsidiaries responsible for withholding data transfers until formal approvals are issued.