Compliance · · 4 min read
China steps up enforcement of cross-border data rules
China’s data regulators have moved from establishing transfer rules to enforcing them, with penalties and new requirements affecting businesses that send personal information abroad.
Companies transferring personal information from China are facing a more demanding compliance environment as regulators turn their attention from designing the rules to testing whether businesses follow them. Mondaq.com reports that China’s cross-border data regime has been fully operational since 1 January 2026.
The system offers three routes for lawful transfers: a security assessment conducted by the Cyberspace Administration of China (CAC), filing under a Standard Contract, or Personal Information (PI) protection certification. Businesses that move employee records, customer information or application data outside China must determine which route applies to their activities and maintain the supporting compliance work.
That shift has already produced significant enforcement activity. The year has included a RMB 10 million penalty against Ctrip and a major case involving Dior. Regulators have also introduced separate measures for organisations processing data at very different scales, including both small operators and businesses handling information about more than 10 million people.
Exemptions do not remove core duties
The rules contain exemptions, but Mondaq.com says they are being interpreted narrowly. Even where a transfer may qualify for an exemption from a particular route, businesses must still address notice, consent and impact-assessment obligations.
A CAC question-and-answer document published on 24 July 2026 illustrated the risk. It said that sending the overseas resume of an applicant based in China is not treated as human-resources data management for the purpose of the relevant exemption. As a result, an employer cannot assume that forwarding recruitment materials abroad is automatically covered by the HR exception.
That interpretation creates a practical issue for multinational employers. A resume may be sent to an overseas recruitment team, hiring manager or group company as part of an ordinary application process, but the transfer still requires the organisation to examine the applicable mechanism and its broader privacy obligations. Automatic forwarding without that preparation could expose the business to serious enforcement risk.
The wider message is that businesses should not treat an exemption as a substitute for governance. They need to understand what information is leaving China, why it is being sent, who receives it and what records demonstrate compliance. The article stresses that the transfer framework must be considered alongside the more general requirements that remain in force.
Different rules for small and large processors
China is also adjusting its approach according to the volume of personal information handled. On 22 July 2026, the CAC and the Ministry of Public Security issued rules for small-scale personal information processors. Those measures took effect on 1 September 2026 and apply to processors handling data relating to fewer than 100,000 people.
The new regime provides those organisations with meaningful relief compared with the requirements facing larger processors. It does not, however, remove every safeguard. Protections concerning sensitive personal information and minors’ data remain in place. Small processors must also complete a simplified audit at least once every five years.
At the other end of the scale, the CAC published draft rules for public comment on 7 August 2026. The proposed provisions concern large personal information processors that handle data relating to more than 10 million people. The draft indicates that the largest data holders are a particular regulatory focus, although the article does not state when those provisions will become final.
Together, the measures show a framework that is becoming more differentiated while retaining baseline obligations. Smaller businesses may receive simplified treatment, but they cannot disregard sensitive information, children’s data or the need to review their practices. Larger processors should expect closer scrutiny as the authorities develop requirements specifically for their scale of operations.
A breach can trigger a wider investigation
The Dior case demonstrates why transfer compliance cannot be separated from incident response. Dior (Shanghai) received a penalty in September 2025 after a routine breach in May exposed customer information that had been sent to Paris. According to Mondaq.com, the transfer lacked a valid legal mechanism and was also criticised for inadequate notice, missing separate consent and insufficient encryption.
The case is important because the regulatory concern extended beyond the immediate security incident. A breach, complaint or official inquiry can prompt a broader examination of how a company manages personal information. That review may cover the organisation’s transfer mechanism, consent records, impact assessments and related controls rather than being limited to the event that first attracted attention.
For businesses, the practical priority is to map their China-related data flows before an incident forces the issue. Each transfer should be matched to the appropriate route, with the relevant notices, consents and assessments documented. Recruitment data deserves particular attention because the CAC’s July guidance makes clear that sending an applicant’s resume overseas may fall outside the expected HR exemption.
Mondaq.com’s report advises companies to assess their arrangements now rather than wait for a breach or regulatory inquiry to reveal a gap. The consequences of an investigation may reach well beyond one transfer, making a complete review of cross-border data practices more valuable than a narrow response to an isolated incident.