Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupport
Contact Us
Search
Close

China Unveils Two Approved Outbound Data Transfer Cases

By Wan Li, Leon Mao & Cece Zhang on April 5, 2023
Email this postTweet this postLike this postShare this post on LinkedIn

Under China’s data protection regulatory framework, data processors are required to pass a security assessment conducted by the cybersecurity regulator before transferring certain categories or volumes of data out of China. This January, six months after the Cyberspace Administration of China (“CAC”) released the Measures on Security Assessment of Outbound Data Transfers (“Measures”), the Beijing counterpart of CAC reported the first two cases where the data processors passed the security assessments led by CAC, which sheds some light on the uncertainty and complexity of the security assessment.

Link to Uncertainty of Reviewing Process and End of Grace Period Uncertainty of Reviewing Process and End of Grace Period

As disclosed by Beijing CAC, as of February 22, 2023, Beijing CAC has assisted more than 310 entities with their potential applications for the security assessment of outbound data transfers, and has received 48 formal applications from organizations in industries such as technology, e-commerce, healthcare, finance, automotive, and civil aviation, including multinational companies. Among many applications, CAC granted two organizations with the approval for transferring data out of China, namely the Beijing Friendship Hospital of the Capital Medical University and Air China.

Pursuant to the Measures, an application for the security assessment should first be submitted to the local CAC for review. Once approved at the local level, the application will be escalated to CAC for final approval.  Though the total processing time should be no longer than 57 working days as provided in the Measures, the Measures allow CAC to extend the reviewing period if necessary. Therefore, the total processing time is much longer. Given the 6-month grace period for data processors ended in March 2023, multinational companies with the necessity of transferring data out of China should prepare for the security assessment application to be compliant.

Link to For Multinational Companies: Challenging Yet Attainable For Multinational Companies: Challenging Yet Attainable

Given the details of the two cases approved by the CAC are not yet disclosed to the public, there isn’t guidance regarding how the security assessment is being processed now.

However, as disclosed by Beijing CAC, the applications from some multinational companies are currently under CAC’s review after being approved at the Beijing level. Additionally, Beijing CAC has completed the review process for six other companies; their applications will be provided to CAC for further review. While we will continue to keep an eye on CAC’s review process, we expect to see the first case of a multinational company getting through the review process soon.

Practically, more entities are likely to be subject to security assessment than as required by the Measures. For multinational companies with the needs to transfer data out of China, they should be aware that the CAC-led security assessment is time consuming and challenging under stringent regulations. They also should be prepared for the data security compliance requirements, such as conducting self-assessments, or seeking professional advice on alternative choices to a security assessment.

Photo of Leon Mao Leon Mao
Email
  • Posted in:
    Technology and AI
  • Blog:
    The Global Privacy Watch
  • Organization:
    Seyfarth Shaw LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
  • About LexBlog
  • The Field We Built
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo