Meaning
Legal instruments issued by the state cyberspace administration to govern the outbound transfer of personal information provide a standardized contractual path for non-critical data processors. Enacted as cac order no 13, this measure outlines the specific terms that must be included in agreements between domestic data exporters and overseas recipients. It provides a compliance alternative for entities that do not trigger the higher thresholds of mandatory security assessments.
The framework enforces strict protection standards on the personal data of Chinese citizens when transferred abroad.
Contractual Standard
The standard contract must be executed without modifications to its core clauses, ensuring uniform application across different business sectors. It establishes the rights of data subjects, the security obligations of the overseas recipient, and the choice of Chinese law for dispute resolution. Exporters must attach the finished contract to their administrative filings.
This ensures the commitments are legally binding.
Audit Procedure
Exporters must file the executed contract along with a personal information protection impact assessment report to the local cyberspace administration within ten working days of its effective date. This submission allows the authority to verify compliance with the national data protection laws. The filing acts as a record-keeping mechanism rather than a pre-approval process.
However, incomplete submissions can lead to administrative rejection.
Compliance Obligation
The exporter remains responsible for monitoring the recipient’s data handling practices during the life of the agreement. If the recipient cannot fulfill the contract, the transfer must be suspended immediately. This liability structure minimizes cross-border security risks.