( September 17, 2026, 09:10 GMT | Official Statement) -- MLex Summary: Personal-information handlers that have obtained cross-border transfer certification must still apply for a data-export security assessment if, from Jan. 1 of a given year, they have transferred personal information of at least 1 million individuals, excluding sensitive information, or sensitive personal data of at least 10,000 individuals, China’s internet regulator said in a policy briefing recently. Applicants may submit certification information with their assessment filing, including details on the level of personal-information protection provided by themselves and foreign recipients and safeguards for individuals’ rights. The regulator said it will consider that information during the assessment. It also warned that personal-information handlers must not split transfers by volume to use certification as a way to circumvent a legally required data-export security assessment.The statement follows (in Chinese). ...
Prepare for tomorrow’s regulatory change, today
MLex identifies risk to business wherever it emerges, with specialist reporters across the globe providing exclusive news and deep-dive analysis on the proposals, probes, enforcement actions and rulings that matter to your organization and clients, now and in the longer term.
Know what others in the room don’t, with features including:
- Daily newsletters for Antitrust, M&A, Trade, Data Privacy & Security, Technology, AI and more
- Custom alerts on specific filters including geographies, industries, topics and companies to suit your practice needs
- Predictive analysis from expert journalists across North America, the UK and Europe, Latin America and Asia-Pacific
- Curated case files bringing together news, analysis and source documents in a single timeline
Experience MLex today with a 14-day free trial.