Meaning
Administrative regulations governing the transfer of important data and personal information outside the borders of the People’s Republic of China establish a rigorous security review regime overseen by the national cyberspace authority. Promulgated by the Cyberspace Administration of China, cac order no 11 mandates that data processors who meet certain volume or criticality conditions must submit to a formal government security assessment before sending data overseas. The regulation targets data of domestic citizens and operates as a border control on the digital economy.
It applies to all cross-border transfers originating from domestic entities regardless of the recipient’s jurisdiction.
Regulatory Scope
Processors who handle the personal information of more than one million individuals are subject to this mandatory assessment before any outbound transfer occurs. Cumulative transfers that reach the designated statutory limits also activate this administrative duty. The regulation covers both important data and critical information infrastructure operator data.
Such classifications represent the boundaries where private contract options are superseded by state review.
Filing Protocol
The data processor must conduct a self-assessment of the risks associated with the outbound transfer before submitting the formal application. This file requires a detailed inventory of the data types, the transmission pathways, and the security measures of the overseas recipient. Applications are submitted to the provincial-level cyberspace administration for preliminary review.
They are then forwarded to the national Cyberspace Administration of China for a final decision.
Enforcement Mechanism
Failure to secure the required approval before initiating data transfers results in administrative fines, suspension of data operations, or the cessation of business activities. The authority can order the retrieval of transmitted data if the security conditions degrade. This gives the state a direct remedy against non-compliance.