Updated on 2026-07-27 GMT+08:00

Performing a Cross-Border Transfer Assessment

Cross-border data transfer is a high-risk activity in privacy management. Managing these transfers is not only a regulatory compliance obligation but also an internal requirement for an organization. The business directors, business personnel, privacy officers, legal affairs personnel, and general managers (or authorized signatories) of both the data exporter and importer are responsible for cross-border data transfer compliance.

DIs serve as the foundation for recording personal information processing activities. Transfers involving cross-border personal data flows are subject to special management.

Creating a Cross-Border Transfer Assessment

Before data processors (or data controllers) export the personal information collected and generated in the Chinese mainland, they should conduct a security review in accordance with relevant laws to protect personal data privacy, public interests, and national security.

  1. Log in to the PCMC.
  2. In the navigation pane, choose Cross-Border Transfer > Cross-Border Transfer Assessment.
  3. Click Create in the upper left corner of the page. The Create Cross-border Transfer Assessment page is displayed.
  4. Configure basic information parameters based on Table 1.

    Table 1 Basic information parameters

    Parameter

    Description

    S Code

    Select an S code. If you open this page by clicking a to-do task, the S code in the task will be bound by default.

    Associate PIA

    Select a risk assessment report bound to the S code. If there are no such reports, you cannot go to the next step.

    Cross-border Assessment Name

    After the S code is selected, this name will be automatically generated. Recommended name format: S-Code Cross-border Assessment

    Legal Entity

    After the S code is selected, this legal entity information will be automatically generated.

    Country

    After the S code is selected, the country/region of the legal entity will be automatically generated.

    Data Exporter

    After the S code is selected, the data exporting country/region will be automatically generated. You can also select the legal entity and country/region from the drop-down list boxes. If the data exporter is an EU country, such as Germany or France, you will need to fill in a high-risk data exporter assessment questionnaire.

    Data Importer

    After the S code is selected, the data importing country/region will be automatically generated. You can also select the legal entity and country/region from the drop-down list boxes.

    Relationship between Exporter and Importer Roles

    • C2P (Controller To Processor)
    • C2C (Controller To Controller)
    • P2C (Processor To Controller)
    • P2P (Processor To Processor)

    Logic for determining the transfer security assessment

    Select the actual processing activities related to the S code. Options are provided under the following categories:

    • If involving processing A or B, meeting any item requires executing personal information export standard contract filing or personal information protection certification
    • If involving processing C-F, meeting any item requires executing data export security assessment
    • If involving processing behaviors G-J, meeting any item exempts from personal information export standard contract filing, personal information protection certification, and data export security assessment

  5. If any of A, B, or G through J is selected, click Next Step to go to Step 7.
  6. If any of C through F is selected, click Next Step. The Questionnaire Assessment page is displayed. The assessment questionnaire varies depending on the Data Exporter you configured.

    • Scenario 1: Assess the security of exporting personal information from the Chinese mainland. If China is selected under Data Exporter, fill in the questionnaire based on Table 2.
      Table 2 Questionnaire

      Module

      Parameter

      Description

      System Basic Information

      1.1 Please briefly describe the business scenario involved in the outbound transfer.

      Example: Collect employee information for management, including their names, phone numbers, and email addresses. Collect emergency contact information for urgent notifications.

      1.2 Please briefly describe the relevant systems involved in the outbound transfer.

      Example: Workday

      2 Please describe the department to which the outbound system belongs.

      Example: Human resource department

      3 Please describe the name of the legal entity to which the system belongs

      The legal entity is the owner of the system, for example, XXX Co., Ltd.

      Data Collection

      4 What personal information fields does the system collect?

      Enter the collected fields.

      5 Does the system collect sensitive personal information fields?

      Sensitive personal data refers to information that, if leaked, may lead to infringement on human dignity or pose a significant risk to personal and property safety. Examples include race or ethnicity, precise location data, and financial account information.

      6 What is the purpose of collection?

      Select a purpose based on actual conditions.

      7.1 If involving personal information transmission from other systems, please provide the system name.

      Example: Human resource system

      7.2 If involving personal information transmission from other systems, please provide the personal information fields.

      Example: names, phone numbers, and addresses

      7.3 If involving personal information transmission from other systems, please provide the transmission method.

      Example: Email transmission or system transmission

      7.4 If involving personal information transmission from other systems, please provide the transmission flow.

      Example: Current application system

      7.5 If involving personal information transmission from other systems, please provide additional notes (optional).

      Enter other systems, if any.

      8 Please provide the exact quantity of personal information collected. The quantity should be measured by unique cumulative items.

      Example: 100,201 personal information fields

      9 Please provide the estimated data volume (size) of personal information collected from mainland China. The unit of data volume is MB/GB/TB.

      Example: 5.2 GB

      Data Storage

      10.1 Please provide the name of the system's data center/cloud, including self-built data centers, hosted and/or cloud solutions.

      Enter a data center or cloud. Example: IDC

      10.2 Please provide the owner entity of the system's data center/cloud.

      Owner entity: XXX Co., Ltd.

      10.3 Please provide other information about the system's data center/cloud (optional).

      Other information about the data center or cloud.

      11 Please provide the location of the data center/cloud for the system in question 10, including internally owned and outsourced.

      Example: Germany

      12 How long is personal information retained in the system?

      Data fields and their retention periods.

      Names: 5 years; mobile numbers: 11 years

      13 How is personal information handled after the retention period expires?

      Provide information based on actual conditions. For example:

      • Physical deletion
      • Logical deletion
      • Anonymization/De-identification
      • Permanent retention

      Data Sharing

      14 Is there any data in the system shared with other overseas systems?

      If Yes is selected, answer questions 15 to 25.

      15.1 What systems, personal information fields, and corresponding purposes are involved in data sharing activities with other systems? Please list all involved system names.

      Example: Human resource system

      15.2 What systems, personal information fields, and corresponding purposes are involved in data sharing activities with other systems? Please list all involved personal information fields.

      Example: Name

      15.3 What systems, personal information fields, and corresponding purposes are involved in data sharing activities with other systems? Please list all involved purposes or functions.

      Enter the purpose or function of the data sharing activity. Example: Improve system efficiency.

      16 What is the data transmission method for the above data sharing?

      Select a value based on the actual situation:

      • Public Network Transmission
      • Dedicated Line Transmission
      • API

      17 Can any overseas third parties access personal information in the system?

      Name and location of the company, entity, or team, such as the supplier or international operations team.

      18 Please describe the purpose of third-party access in question 17.

      This parameter is displayed if Yes is selected for question 17.

      Select one or multiple purposes from the drop-down list box:

      • Operation and Maintenance Services
      • Debugging
      • Repair

      19 Please provide the exact number of information subjects (individuals) for the planned transmission or access of personal information.

      Note: Cumulative calculation from January 1 of the current year to the form filling date.

      • Less than 10,000 people
      • 10,000 to 100,000 people
      • 100,000 to 1 million people
      • More than 1 million people

      20 Please indicate whether a written agreement has been signed for the cross-border data scenario to ensure rights and obligations regarding data protection?

      • Data Protection Agreement
      • Confidentiality Agreement
      • Data Transfer Agreement
      • Contract agreement, including data protection/security clauses
      • Other

      21.1 Please describe the storage location of the data after receipt by the overseas recipient.

      Storage location: Amsterdam

      21.2 Please describe the storage method of the data after receipt by the overseas recipient.

      Storage: Huawei Cloud

      21.3 Please describe the data retention period after receipt by the overseas recipient.

      Data retention period: 5 years

      21.4 Please provide additional notes after receipt by the overseas recipient.

      For example, describe the entire data processing process of the recipient, including the data processing method and data re-transfer process.

      22 Situation of onward transfer after data export.

      Select whether the data is transferred again after being exported:

      • Involved
      • Not Involved

      23 Please describe the data security management capabilities of the overseas recipient, including the management organization system and institutional construction, full-process management, classification and grading, emergency response, risk assessment, personal information rights protection systems and their implementation.

      Example: The overseas recipient has established a security management system to provide full-process management, classification and grading, emergency response, risk assessment, personal information rights protection systems, and data cross-border transfer security operation process.

      24.1 Please describe the data security technical capabilities of the overseas recipient, the security technical measures taken for data collection.

      Example: When you use automatic methods to collect data, consider the data processing capabilities and network capacity of websites and public databases to ensure that their normal operations are not affected.

      24.2 Please describe the data security technical capabilities of the overseas recipient, the security technical measures taken for data storage.

      Example: Encryption, secure storage, access control, security audit, and more measures are taken to protect personal information storage. After the storage period expires, the data is anonymized or de-identified, and then deleted.

      24.3 Please describe the data security technical capabilities of the overseas recipient, the security technical measures taken for data usage.

      Example: Test the connected or embedded third-party applications (for example, SDKs) to ensure that they are used for service functions.

      24.4 Please describe the data security technical capabilities of the overseas recipient, the security technical measures taken for data transmission.

      Example: Transmission encryption, identity authentication, and more technical measures are taken to enhance security during the transmission of sensitive personal information.

      24.5 Please describe the data security technical capabilities of the overseas recipient, the security technical measures taken for data sharing.

      Example: Periodically perform security audit and log audit on shared data.

      24.6 Please describe the data security technical capabilities of the overseas recipient, additional security technical measures taken for the entire process (optional).

      Example: Data preprocessing and masking enable domestic organizations to perform joint modeling and analysis with overseas recipients without exchanging raw data.

      25 Apart from the above security control measures, has the overseas recipient taken other measures?

      • Yes. If it is selected, describe the measures in detail.
      • No

      Example: Yes. Regularly perform audits to enhance data security.

      Data Security Controls

      26 Please describe the data security management capabilities of the company as a data processor, including the management organization system and institutional construction, full-process management, classification and grading, emergency response, risk assessment, personal information rights protection systems and their implementation.

      Example: The company has established a security management system to provide full-process management, classification and grading, emergency response, risk assessment, personal information rights protection systems, and data cross-border transfer security operation process.

      27 Have relevant systems taken or plan to take data encryption measures?

      Yes. If it is selected, describe the measures in detail.

      Example: Yes. All Sensitive Personal Identity Information (SPII), including ID card numbers and medical certificates, is encrypted using AES-256 at the database level. The transmission channel is encrypted using HTTPS. All Personally identifiable information (PII), including names and email addresses, is transmitted using HTTPS.

      28 Have de-identification measures been taken or planned for the system?

      If Yes is selected, describe the measures in detail.

      Example: Yes. Personal information, including phone numbers and ID card numbers, will be de-identified before they are displayed on the interface.

      29 Have access control measures been taken or planned for the system?

      If Yes is selected, describe the measures in detail.

      Example: Yes. The roles that can access personal information are minimized, and only authorized personnel have the right to access it.

      30 Have measures to prevent data leakage been taken or planned for the system?

      If Yes is selected, describe the measures in detail.

      Example: Yes. Data leakage prevention tools are used for load balancing, anti-intrusion, and data leakage detection. An internal emergency response mechanism is established to handle data security events.

      31 Have log management measures been taken or planned for the system?

      If Yes is selected, describe the measures in detail.

      Example: Yes. Log retention management is implemented for key events, such as authorized data access, batch replication, destruction, and data interface calls. Logs are backed up periodically to prevent log deletion caused by data security incidents.

      32 Have security incident response measures been taken or planned for the system?

      If Yes is selected, describe the measures in detail.

      Example: Yes. Contingency plans and remedial measures are established for cross-border data transfer.

      33 Have other measures been taken or will be taken for the system?

      If Yes is selected, describe the measures in detail.

      Example: Yes. Regularly perform audits to enhance data security.

    • Scenario 2: Assess the security of exporting data from a highly regulated country, for example, set Data Exporter to Italy.

      Highly regulated countries and regions mainly refer to those subject to GDPR, which have strict requirements on cross-border data transfers and may impose significant penalties.

    • Scenario 3: Assess the security of exporting data from a moderately regulated country, for example, set Data Exporter to a country or region other than those described in scenario 2. Fill in the questionnaire by referring to Table 3.

      Moderately regulated countries and regions mainly refer to those not subject to GDPR, which have less stringent requirements on cross-border data transfers.

      Table 3 Risk assessment

      Questionnaire

      Description

      1 Data Processing Activity

      The processing purpose is obtained from DI. You can add detailed processing activities.

      2 Data Subject Type

      The value is obtained from DI, for example, a consumer or supplier.

      3 Personal Data Type

      Example: names, mobile numbers, nicknames, email addresses, and addresses

      4 Special/Sensitive Data

      Special data refers to the particularly sensitive data specified in the GDPR, including racial or ethnic origins, religious beliefs, and genetic data. Sensitive personal information refers to the personal information that once leaked or illegally used, may easily lead to the infringement of the personal dignity of a natural person or may endanger his personal safety or property, including information about race or ethnicity, location, and bank accounts.

      5 Protection Measures for Special/Sensitive Data

      Example: transmission encryption and anonymization

      6 Personal Data Storage Location

      Country or region where the collected personal data is stored.

      7 Processing Nature

      Select a processing nature from the drop-down list. The options are as follows:

      • Collection
      • Recording
      • Organization
      • Structuring
      • Storage
      • Erasure or Destruction
      • Retrieval
      • Use
      • Consultation

      8 Scenario Description

      Describe the data processing activities in detail as a supplement to Data Processing Activity.

      9 Does it involve sub-processors

      If Yes is selected, configure 10.1 Sub-processor Processing Subject Matter, 10.2 Sub-processor Processing Nature, and 10.3 Sub-processor Processing Duration.

      10.1 Sub-processor Processing Subject Matter

      This parameter is displayed if Yes is selected for parameter 9. Enter the processing subject matter.

      10.2 Sub-processor Processing Nature

      This parameter is displayed if Yes is selected for parameter 9. Enter the processing nature.

      10.3 Sub-processor Processing Duration

      This parameter is displayed if Yes is selected for parameter 9. Enter the duration.

      11 Cross-border Risk Mitigation Solution

      Select a cross-border mitigation solution.

      • Minimization & SCC: Implement a DTA to minimize the scope of cross-border data transfers.
      • Localization (No cross-border personal data/Remove personal data/Business termination or decommissioning): Stop cross-border personal data transfer, remove personal data, or terminate services.
      • Data Subject Consent: Obtain explicit and separate consent from data subjects.
      • Necessary for Contract Performance: Cross-border data transfer is necessary to fulfill contracts with customers and data subjects.
      • Regulatory Approval: Obtain approval from regulators for cross-border data transfer, such as passing the cross-border data security assessment by Chinese regulators.
      • Specific Certification: Obtain certifications, for example, Cross-Border Privacy Rules (CBPR) certification and China's Personal Data Protection Certification.
      • Adequacy Decision: countries or regions with an adequacy decision, or countries or regions in the whitelist
      • Other: Data may be processed for specific purposes, for example: establishing, exercising, or defending legal claims; protecting the vital interests of data subjects; fulfilling public interests via public registers; or implementing Binding Corporate Rules (BCRs).

      12 Supplementary Explanation for Cross-border Risk Mitigation Solution

      This parameter is displayed if a value other than Localization (No cross-border personal data/Remove personal data/Business termination or decommissioning) and Minimization & SCC is selected for 11 Cross-border Risk Mitigation Solution. Enter the details about the cross-border risk mitigation solution in the text box.

      13 Supporting Documents

      This parameter is displayed if a value other than Localization (No cross-border personal data/Remove personal data/Business termination or decommissioning) and Minimization & SCC is selected for 11 Cross-border Risk Mitigation Solution. Click Add File to upload the supporting document of the cross-border risk mitigation solution.

      14 Framework

      This parameter is displayed if a value other than Localization (No cross-border personal data/Remove personal data/Business termination or decommissioning) is selected for 11 Cross-border Risk Mitigation Solution. Select a framework from the drop-down list.

      • B2B
      • B2C
      • Internal

      15 Purpose of Transfer and Further Processing

      This parameter is displayed if a value other than Localization (No cross-border personal data/Remove personal data/Business termination or decommissioning) is selected for 11 Cross-border Risk Mitigation Solution. Enter the purpose and necessity of transfer in the text box.

      16 Transfer Frequency

      This parameter is displayed if a value other than Localization (No cross-border personal data/Remove personal data/Business termination or decommissioning) is selected for 11 Cross-border Risk Mitigation Solution. Select a frequency from the drop-down list.

      • One-time Transfer: A unique transaction that does not recur.
      • Continuous Transfer: Data is transferred continuously.

      17 Retention Period

      This parameter is displayed if a value other than Localization (No cross-border personal data/Remove personal data/Business termination or decommissioning) is selected for 11 Cross-border Risk Mitigation Solution. Select a retention period from the drop-down list as needed.

  7. The approval procedure varies depending on the cross-border risk mitigation solution:

    • If 11 Cross-border Risk Mitigation Solution is set to Localization (No cross-border personal data/Remove personal data/Business termination or decommissioning) in Step 6, after you click Submit Audit, the assessment will be submitted for approval based on the approval process.
    • If 11 Cross-border Risk Mitigation Solution is set to a value other than Localization (No cross-border personal data/Remove personal data/Business termination or decommissioning) in Step 6, click Next Step to go to the Cross-border Compliance Protection Measures page. Select protection measures by referring to Table 4. Click Submit for Approval. The assessment will be submitted for approval based on the approval process.
      Table 4 Parameters for cross-border compliance protection measures

      Parameter

      Description

      Is Transmission Encrypted

      Select Yes or No.

      Transmission Encryption Method

      If Is Transmission Encrypted is set to Yes, you need to enter the transmission encryption method.

      Transmission Encryption Plan and Protocol

      If Is Transmission Encrypted is set to No, you need to enter the transmission encryption plan and protocol.

      Is Storage Encrypted

      Select Yes or No.

      Storage Encryption Method

      If Is Storage Encrypted is set to Yes, you need to enter the storage encryption method.

      Storage Encryption Plan and Protocol

      If Is Storage Encrypted is set to No, you need to enter the storage encryption plan and protocol.

      Is De-identification Performed

      Select Yes or No.

      Remarks (Optional)

      Enter remarks in the text box.

Approval Process

The cross-border process is as follows. You can check it in Personal Center.