Performing a Cross-Border Transfer Assessment
Cross-border data transfer is a high-risk activity in privacy management. Managing these transfers is not only a regulatory compliance obligation but also an internal requirement for an organization. The business directors, business personnel, privacy officers, legal affairs personnel, and general managers (or authorized signatories) of both the data exporter and importer are responsible for cross-border data transfer compliance.
DIs serve as the foundation for recording personal information processing activities. Transfers involving cross-border personal data flows are subject to special management.
Creating a Cross-Border Transfer Assessment
Before data processors (or data controllers) export the personal information collected and generated in the Chinese mainland, they should conduct a security review in accordance with relevant laws to protect personal data privacy, public interests, and national security.
- Log in to the PCMC.
- In the navigation pane, choose .
- Click Create in the upper left corner of the page. The Create Cross-border Transfer Assessment page is displayed.
- Configure basic information parameters based on Table 1.
Table 1 Basic information parameters Parameter
Description
S Code
Select an S code. If you open this page by clicking a to-do task, the S code in the task will be bound by default.
Associate PIA
Select a risk assessment report bound to the S code. If there are no such reports, you cannot go to the next step.
Cross-border Assessment Name
After the S code is selected, this name will be automatically generated. Recommended name format: S-Code Cross-border Assessment
Legal Entity
After the S code is selected, this legal entity information will be automatically generated.
Country
After the S code is selected, the country/region of the legal entity will be automatically generated.
Data Exporter
After the S code is selected, the data exporting country/region will be automatically generated. You can also select the legal entity and country/region from the drop-down list boxes. If the data exporter is an EU country, such as Germany or France, you will need to fill in a high-risk data exporter assessment questionnaire.
Data Importer
After the S code is selected, the data importing country/region will be automatically generated. You can also select the legal entity and country/region from the drop-down list boxes.
Relationship between Exporter and Importer Roles
- C2P (Controller To Processor)
- C2C (Controller To Controller)
- P2C (Processor To Controller)
- P2P (Processor To Processor)
Logic for determining the transfer security assessment
Select the actual processing activities related to the S code. Options are provided under the following categories:
- If involving processing A or B, meeting any item requires executing personal information export standard contract filing or personal information protection certification
- If involving processing C-F, meeting any item requires executing data export security assessment
- If involving processing behaviors G-J, meeting any item exempts from personal information export standard contract filing, personal information protection certification, and data export security assessment
- If any of A, B, or G through J is selected, click Next Step to go to Step 7.
- If any of C through F is selected, click Next Step. The Questionnaire Assessment page is displayed. The assessment questionnaire varies depending on the Data Exporter you configured.
- Scenario 1: Assess the security of exporting personal information from the Chinese mainland. If China is selected under Data Exporter, fill in the questionnaire based on Table 2.
Table 2 Questionnaire Module
Parameter
Description
System Basic Information
1.1 Please briefly describe the business scenario involved in the outbound transfer.
Example: Collect employee information for management, including their names, phone numbers, and email addresses. Collect emergency contact information for urgent notifications.
1.2 Please briefly describe the relevant systems involved in the outbound transfer.
Example: Workday
2 Please describe the department to which the outbound system belongs.
Example: Human resource department
3 Please describe the name of the legal entity to which the system belongs
The legal entity is the owner of the system, for example, XXX Co., Ltd.
Data Collection
4 What personal information fields does the system collect?
Enter the collected fields.
5 Does the system collect sensitive personal information fields?
Sensitive personal data refers to information that, if leaked, may lead to infringement on human dignity or pose a significant risk to personal and property safety. Examples include race or ethnicity, precise location data, and financial account information.
6 What is the purpose of collection?
Select a purpose based on actual conditions.
7.1 If involving personal information transmission from other systems, please provide the system name.
Example: Human resource system
7.2 If involving personal information transmission from other systems, please provide the personal information fields.
Example: names, phone numbers, and addresses
7.3 If involving personal information transmission from other systems, please provide the transmission method.
Example: Email transmission or system transmission
7.4 If involving personal information transmission from other systems, please provide the transmission flow.
Example: Current application system
7.5 If involving personal information transmission from other systems, please provide additional notes (optional).
Enter other systems, if any.
8 Please provide the exact quantity of personal information collected. The quantity should be measured by unique cumulative items.
Example: 100,201 personal information fields
9 Please provide the estimated data volume (size) of personal information collected from mainland China. The unit of data volume is MB/GB/TB.
Example: 5.2 GB
Data Storage
10.1 Please provide the name of the system's data center/cloud, including self-built data centers, hosted and/or cloud solutions.
Enter a data center or cloud. Example: IDC
10.2 Please provide the owner entity of the system's data center/cloud.
Owner entity: XXX Co., Ltd.
10.3 Please provide other information about the system's data center/cloud (optional).
Other information about the data center or cloud.
11 Please provide the location of the data center/cloud for the system in question 10, including internally owned and outsourced.
Example: Germany
12 How long is personal information retained in the system?
Data fields and their retention periods.
Names: 5 years; mobile numbers: 11 years
13 How is personal information handled after the retention period expires?
Provide information based on actual conditions. For example:
- Physical deletion
- Logical deletion
- Anonymization/De-identification
- Permanent retention
Data Sharing
14 Is there any data in the system shared with other overseas systems?
If Yes is selected, answer questions 15 to 25.
15.1 What systems, personal information fields, and corresponding purposes are involved in data sharing activities with other systems? Please list all involved system names.
Example: Human resource system
15.2 What systems, personal information fields, and corresponding purposes are involved in data sharing activities with other systems? Please list all involved personal information fields.
Example: Name
15.3 What systems, personal information fields, and corresponding purposes are involved in data sharing activities with other systems? Please list all involved purposes or functions.
Enter the purpose or function of the data sharing activity. Example: Improve system efficiency.
16 What is the data transmission method for the above data sharing?
Select a value based on the actual situation:
- Public Network Transmission
- Dedicated Line Transmission
- API
17 Can any overseas third parties access personal information in the system?
Name and location of the company, entity, or team, such as the supplier or international operations team.
18 Please describe the purpose of third-party access in question 17.
This parameter is displayed if Yes is selected for question 17.
Select one or multiple purposes from the drop-down list box:
- Operation and Maintenance Services
- Debugging
- Repair
19 Please provide the exact number of information subjects (individuals) for the planned transmission or access of personal information.
Note: Cumulative calculation from January 1 of the current year to the form filling date.
- Less than 10,000 people
- 10,000 to 100,000 people
- 100,000 to 1 million people
- More than 1 million people
20 Please indicate whether a written agreement has been signed for the cross-border data scenario to ensure rights and obligations regarding data protection?
- Data Protection Agreement
- Confidentiality Agreement
- Data Transfer Agreement
- Contract agreement, including data protection/security clauses
- Other
21.1 Please describe the storage location of the data after receipt by the overseas recipient.
Storage location: Amsterdam
21.2 Please describe the storage method of the data after receipt by the overseas recipient.
Storage: Huawei Cloud
21.3 Please describe the data retention period after receipt by the overseas recipient.
Data retention period: 5 years
21.4 Please provide additional notes after receipt by the overseas recipient.
For example, describe the entire data processing process of the recipient, including the data processing method and data re-transfer process.
22 Situation of onward transfer after data export.
Select whether the data is transferred again after being exported:
- Involved
- Not Involved
23 Please describe the data security management capabilities of the overseas recipient, including the management organization system and institutional construction, full-process management, classification and grading, emergency response, risk assessment, personal information rights protection systems and their implementation.
Example: The overseas recipient has established a security management system to provide full-process management, classification and grading, emergency response, risk assessment, personal information rights protection systems, and data cross-border transfer security operation process.
24.1 Please describe the data security technical capabilities of the overseas recipient, the security technical measures taken for data collection.
Example: When you use automatic methods to collect data, consider the data processing capabilities and network capacity of websites and public databases to ensure that their normal operations are not affected.
24.2 Please describe the data security technical capabilities of the overseas recipient, the security technical measures taken for data storage.
Example: Encryption, secure storage, access control, security audit, and more measures are taken to protect personal information storage. After the storage period expires, the data is anonymized or de-identified, and then deleted.
24.3 Please describe the data security technical capabilities of the overseas recipient, the security technical measures taken for data usage.
Example: Test the connected or embedded third-party applications (for example, SDKs) to ensure that they are used for service functions.
24.4 Please describe the data security technical capabilities of the overseas recipient, the security technical measures taken for data transmission.
Example: Transmission encryption, identity authentication, and more technical measures are taken to enhance security during the transmission of sensitive personal information.
24.5 Please describe the data security technical capabilities of the overseas recipient, the security technical measures taken for data sharing.
Example: Periodically perform security audit and log audit on shared data.
24.6 Please describe the data security technical capabilities of the overseas recipient, additional security technical measures taken for the entire process (optional).
Example: Data preprocessing and masking enable domestic organizations to perform joint modeling and analysis with overseas recipients without exchanging raw data.
25 Apart from the above security control measures, has the overseas recipient taken other measures?
- Yes. If it is selected, describe the measures in detail.
- No
Example: Yes. Regularly perform audits to enhance data security.
Data Security Controls
26 Please describe the data security management capabilities of the company as a data processor, including the management organization system and institutional construction, full-process management, classification and grading, emergency response, risk assessment, personal information rights protection systems and their implementation.
Example: The company has established a security management system to provide full-process management, classification and grading, emergency response, risk assessment, personal information rights protection systems, and data cross-border transfer security operation process.
27 Have relevant systems taken or plan to take data encryption measures?
Yes. If it is selected, describe the measures in detail.
Example: Yes. All Sensitive Personal Identity Information (SPII), including ID card numbers and medical certificates, is encrypted using AES-256 at the database level. The transmission channel is encrypted using HTTPS. All Personally identifiable information (PII), including names and email addresses, is transmitted using HTTPS.
28 Have de-identification measures been taken or planned for the system?
If Yes is selected, describe the measures in detail.
Example: Yes. Personal information, including phone numbers and ID card numbers, will be de-identified before they are displayed on the interface.
29 Have access control measures been taken or planned for the system?
If Yes is selected, describe the measures in detail.
Example: Yes. The roles that can access personal information are minimized, and only authorized personnel have the right to access it.
30 Have measures to prevent data leakage been taken or planned for the system?
If Yes is selected, describe the measures in detail.
Example: Yes. Data leakage prevention tools are used for load balancing, anti-intrusion, and data leakage detection. An internal emergency response mechanism is established to handle data security events.
31 Have log management measures been taken or planned for the system?
If Yes is selected, describe the measures in detail.
Example: Yes. Log retention management is implemented for key events, such as authorized data access, batch replication, destruction, and data interface calls. Logs are backed up periodically to prevent log deletion caused by data security incidents.
32 Have security incident response measures been taken or planned for the system?
If Yes is selected, describe the measures in detail.
Example: Yes. Contingency plans and remedial measures are established for cross-border data transfer.
33 Have other measures been taken or will be taken for the system?
If Yes is selected, describe the measures in detail.
Example: Yes. Regularly perform audits to enhance data security.
- Scenario 2: Assess the security of exporting data from a highly regulated country, for example, set Data Exporter to Italy.
Highly regulated countries and regions mainly refer to those subject to GDPR, which have strict requirements on cross-border data transfers and may impose significant penalties.
- Scenario 3: Assess the security of exporting data from a moderately regulated country, for example, set Data Exporter to a country or region other than those described in scenario 2. Fill in the questionnaire by referring to Table 3.
Moderately regulated countries and regions mainly refer to those not subject to GDPR, which have less stringent requirements on cross-border data transfers.
Table 3 Risk assessment Questionnaire
Description
1 Data Processing Activity
The processing purpose is obtained from DI. You can add detailed processing activities.
2 Data Subject Type
The value is obtained from DI, for example, a consumer or supplier.
3 Personal Data Type
Example: names, mobile numbers, nicknames, email addresses, and addresses
4 Special/Sensitive Data
Special data refers to the particularly sensitive data specified in the GDPR, including racial or ethnic origins, religious beliefs, and genetic data. Sensitive personal information refers to the personal information that once leaked or illegally used, may easily lead to the infringement of the personal dignity of a natural person or may endanger his personal safety or property, including information about race or ethnicity, location, and bank accounts.
5 Protection Measures for Special/Sensitive Data
Example: transmission encryption and anonymization
6 Personal Data Storage Location
Country or region where the collected personal data is stored.
7 Processing Nature
Select a processing nature from the drop-down list. The options are as follows:
- Collection
- Recording
- Organization
- Structuring
- Storage
- Erasure or Destruction
- Retrieval
- Use
- Consultation
8 Scenario Description
Describe the data processing activities in detail as a supplement to Data Processing Activity.
9 Does it involve sub-processors
If Yes is selected, configure 10.1 Sub-processor Processing Subject Matter, 10.2 Sub-processor Processing Nature, and 10.3 Sub-processor Processing Duration.
10.1 Sub-processor Processing Subject Matter
This parameter is displayed if Yes is selected for parameter 9. Enter the processing subject matter.
10.2 Sub-processor Processing Nature
This parameter is displayed if Yes is selected for parameter 9. Enter the processing nature.
10.3 Sub-processor Processing Duration
This parameter is displayed if Yes is selected for parameter 9. Enter the duration.
11 Cross-border Risk Mitigation Solution
Select a cross-border mitigation solution.
- Minimization & SCC: Implement a DTA to minimize the scope of cross-border data transfers.
- Localization (No cross-border personal data/Remove personal data/Business termination or decommissioning): Stop cross-border personal data transfer, remove personal data, or terminate services.
- Data Subject Consent: Obtain explicit and separate consent from data subjects.
- Necessary for Contract Performance: Cross-border data transfer is necessary to fulfill contracts with customers and data subjects.
- Regulatory Approval: Obtain approval from regulators for cross-border data transfer, such as passing the cross-border data security assessment by Chinese regulators.
- Specific Certification: Obtain certifications, for example, Cross-Border Privacy Rules (CBPR) certification and China's Personal Data Protection Certification.
- Adequacy Decision: countries or regions with an adequacy decision, or countries or regions in the whitelist
- Other: Data may be processed for specific purposes, for example: establishing, exercising, or defending legal claims; protecting the vital interests of data subjects; fulfilling public interests via public registers; or implementing Binding Corporate Rules (BCRs).
12 Supplementary Explanation for Cross-border Risk Mitigation Solution
This parameter is displayed if a value other than Localization (No cross-border personal data/Remove personal data/Business termination or decommissioning) and Minimization & SCC is selected for 11 Cross-border Risk Mitigation Solution. Enter the details about the cross-border risk mitigation solution in the text box.
13 Supporting Documents
This parameter is displayed if a value other than Localization (No cross-border personal data/Remove personal data/Business termination or decommissioning) and Minimization & SCC is selected for 11 Cross-border Risk Mitigation Solution. Click Add File to upload the supporting document of the cross-border risk mitigation solution.
14 Framework
This parameter is displayed if a value other than Localization (No cross-border personal data/Remove personal data/Business termination or decommissioning) is selected for 11 Cross-border Risk Mitigation Solution. Select a framework from the drop-down list.
- B2B
- B2C
- Internal
15 Purpose of Transfer and Further Processing
This parameter is displayed if a value other than Localization (No cross-border personal data/Remove personal data/Business termination or decommissioning) is selected for 11 Cross-border Risk Mitigation Solution. Enter the purpose and necessity of transfer in the text box.
16 Transfer Frequency
This parameter is displayed if a value other than Localization (No cross-border personal data/Remove personal data/Business termination or decommissioning) is selected for 11 Cross-border Risk Mitigation Solution. Select a frequency from the drop-down list.
- One-time Transfer: A unique transaction that does not recur.
- Continuous Transfer: Data is transferred continuously.
17 Retention Period
This parameter is displayed if a value other than Localization (No cross-border personal data/Remove personal data/Business termination or decommissioning) is selected for 11 Cross-border Risk Mitigation Solution. Select a retention period from the drop-down list as needed.
- Scenario 1: Assess the security of exporting personal information from the Chinese mainland. If China is selected under Data Exporter, fill in the questionnaire based on Table 2.
- The approval procedure varies depending on the cross-border risk mitigation solution:
- If 11 Cross-border Risk Mitigation Solution is set to Localization (No cross-border personal data/Remove personal data/Business termination or decommissioning) in Step 6, after you click Submit Audit, the assessment will be submitted for approval based on the approval process.
- If 11 Cross-border Risk Mitigation Solution is set to a value other than Localization (No cross-border personal data/Remove personal data/Business termination or decommissioning) in Step 6, click Next Step to go to the Cross-border Compliance Protection Measures page. Select protection measures by referring to Table 4. Click Submit for Approval. The assessment will be submitted for approval based on the approval process.
Table 4 Parameters for cross-border compliance protection measures Parameter
Description
Is Transmission Encrypted
Select Yes or No.
Transmission Encryption Method
If Is Transmission Encrypted is set to Yes, you need to enter the transmission encryption method.
Transmission Encryption Plan and Protocol
If Is Transmission Encrypted is set to No, you need to enter the transmission encryption plan and protocol.
Is Storage Encrypted
Select Yes or No.
Storage Encryption Method
If Is Storage Encrypted is set to Yes, you need to enter the storage encryption method.
Storage Encryption Plan and Protocol
If Is Storage Encrypted is set to No, you need to enter the storage encryption plan and protocol.
Is De-identification Performed
Select Yes or No.
Remarks (Optional)
Enter remarks in the text box.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot
