---
title: "China's data-exit rule: how the 2024 cross-border flow provisions reshaped compliance"
date: 2026-09-30
category: Policy & Governance
site: NeuroAI
canonical: https://neuroai.site/a/na-policy-data-cross-border
language: en
---

# China's data-exit rule: how the 2024 cross-border flow provisions reshaped compliance

> A 2024 CAC rule eased the path for data to leave China while tightening the rules that still matter — a quiet but consequential shift for any AI or cloud firm moving training data across borders.

For an AI company, data is the fuel — and moving that fuel across a border used to mean a heavy, slow security assessment in China. On March 22, 2024, the Cyberspace Administration of China (CAC, 国家网信办) issued the Provisions on Promoting and Regulating Cross-Border Data Flows (《促进和规范数据跨境流动规定》), effective the same day.

The headline is counterintuitive: a data-governance rule whose explicit goal was to make data exit easier, not harder.

## What the rule actually does

The provisions sit on top of China's three pillars of data law — the Cybersecurity Law (网络安全法), the Data Security Law (数据安全法), and the Personal Information Protection Law (PIPL, 个人信息保护法). Rather than rewriting them, the 2024 rule clarifies and narrows when the heavy-weight mechanisms apply.

It relaxes conditions for cross-border data flows and narrows the scope of data-export security assessments (数据出境安全评估), aiming to lower compliance cost while keeping a security floor.

## The free-trade-zone negative list

A notable mechanism the rule establishes is the free-trade-zone (自由贸易试验区, FTZ) negative-list system. FTZs can publish lists of data that still require assessment; everything outside the list can flow more freely.

In practice this meant, within a year, that FTZs in places like Tianjin, Beijing, Hainan, Shanghai, and Zhejiang had published negative lists covering sectors such as automotive, pharmaceuticals, retail, civil aviation, and reinsurance — giving companies a field-guide to what is restricted versus free.

## The one-year report card

In a March 2025 review, the CAC reported measurable effects after one year:

- Monthly filings for data-export security assessments fell by about 60%.

- Monthly filings for personal-information export standard contracts fell by about 50%.

- Average assessment time dropped below 30 working days, down from the statutory 45.

Those numbers describe a system that became lighter to use, not just differently written.

## Why AI and cloud firms should care

Training a model often means moving datasets, labels, and logs between regions. For foreign-invested enterprises and Chinese AI exporters alike, the rule's clarifications reduce the guesswork about when an assessment is even triggered.

The CAC also set up a green-channel mechanism for foreign-invested enterprises (including foreign R&D centers) and opened a cross-border data consultation line — practical, if bureaucratic, relief.

## What came after

The 2024 provisions were not the end. In October 2025 the CAC and the State Administration for Market Regulation issued the Measures for Certification of Cross-Border Personal Information Transfer (《个人信息出境认证办法》), which took effect on January 1, 2026, completing a three-pathway framework (security assessment, standard contract, certification) under PIPL.

## What no longer needs a heavy assessment

A practical part of the rule is the list of scenarios exempted from the full security assessment, standard contract, or certification: cross-border shopping, remittance, and payment; flight and hotel bookings; cross-border human-resources management; and overseas data processing. For a multinational running regional HR or booking systems, those carve-outs remove whole categories from the old burden.

The negative-list system then handles the rest by sector. Within a year, FTZs had published lists covering around 17 fields — automotive, retail, civil aviation, reinsurance, deep-sea industry, seed breeding, geospatial and meteorological data, and enterprise-credit information among them — letting companies in those zones move non-listed data freely while only the listed categories trigger assessment.

## Follow-on sector guides

The 2024 provisions were a framework; sectors filled in the detail:

- **Finance** — the People's Bank of China and partners issued a compliance guide for financial-data cross-border flows in April 2025, with a concrete list of transferable data items.

- **Automotive** — in February 2026, the Ministry of Industry and Information Technology issued a 2026 edition safety guide for vehicle-data export, clarifying important-data判定 (determination) rules for manufacturing and connected-operation scenarios.

That sector-by-sector layering is the actual operating environment: a general rule, then FTZ lists, then industry guides.

## Honest limitations

The core facts — issuing body, date (March 22, 2024), legal basis, and the FTZ negative-list mechanism — come from the CAC's official site, the primary and authoritative source. The one-year statistics (60% / 50% drops, sub-30-day average) are the CAC's own self-reported figures, not independently audited here. I did not verify how individual companies experienced the change, nor whether the relief is uniform across sectors. The January 2026 certification measures are noted from CAC statements but not detailed against the primary text in this review.

## What readers can do now

- If your organization moves data out of China, check whether your scenario falls under an FTZ negative list or a豁免 (exemption) before assuming a full security assessment is required.

- Distinguish the three pathways — security assessment, standard contract, and the new certification (effective Jan 1, 2026) — and match them to your data type and volume.

- For AI workloads specifically, document data provenance and classification early; the rule lowers friction for low-risk flows but raises the cost of getting classification wrong.

---

Published by NeuroAI (https://neuroai.site/) — https://neuroai.site/a/na-policy-data-cross-border
Free to quote with attribution and a link to the original.
