Modern ink-wash data flow from Chinese storage through classification, de-identification and review gates to an overseas network

INFORMATION ASYMMETRY 25 · DATA · CROSS-BORDER TRANSFER

数据出境安全评估、标准合同、个人信息保护认证与自贸区负面清单

When Can Data Leave China?

Separates security assessment, personal-information standard contracts, certification, FTZ negative lists and exemptions by important data, volume, processor type and necessity.

Cross-checked against Chinese primary, industry, research and media sources · August 3, 2026 · Currency basis: the latest CFETS rate available on August 3, 2026—USD/CNY 6.7894, published July 31, 2026 · monetary amounts shown only in U.S. dollars
Topic typeData × regulatory-risk

EDITORIAL THESIS

Core proposition

  1. 01

    Cross-border data is not just about server location. Data type, processor, volume, purpose, necessity, recipient and transfer path determine the compliance route.

Swipe sideways for detail; tap the graphic to open it full size.

Infographic of the concept, operating structure, constraints and Korean response for When Can Data Leave China?
25 · Operating structure — When Can Data Leave China?A Korean-language graphic summarizing the concept, China’s operating system, constraints and Korea’s decision question.Download high-resolution SVG

CHINA SYSTEM · OPERATING LOGIC

Read the concept through its operating structure

01

First identify the transfer and data type

Transfers to overseas headquarters, cloud or partners—and overseas remote access—may be outbound data activity. Classify personal, sensitive, important, core and ordinary business data first.

02

Security assessment covers important data and large-scale transfers

Security assessment applies to important data and transfers over volume thresholds, examining purpose, scope, recipient, contracts, safeguards and national and individual risk.

03

Standard contracts and certification are distinct routes

Standard contract and personal-information certification are different routes; neither replaces notice, consent, necessity, impact assessment, rights and incident response, nor can they bypass required security assessment.

04

The 2024 rules and FTZs simplify some transfers

The 2024 rules simplify certain trade, transport, academic, global production, HR and small-volume transfers. FTZ negative lists can exempt listed procedures outside the list, while core/important data and other laws remain.

05

Korean firms should map data flows before contracting

Korean firms should map China-origin customer, employee and equipment data through servers, APIs and remote access to Korea and third countries, then verify onward transfer, retention, deletion, government requests, incidents and controls.

FIELD CHECK · BEFORE DECISION

Questions to verify before applying this concept

  1. 01

    Were transfer, remote access and cloud outbound paths identified?

  2. 02

    Were personal, sensitive, important, core and ordinary data classified?

  3. 03

    Is the assessment, contract, certification or exemption route correct?

  4. 04

    Were recipient, onward transfer, deletion and response controls technically verified?

Primary, industry, research and media sources

The Korean primary report cross-checks Chinese official texts with industry, research and media evidence.

01Official促进和规范数据跨境流动规定02Official数据出境安全管理政策问答(2025年4月)03Official个人信息出境标准合同办法04Official数据出境安全评估办法
Back to Information Asymmetry