---
title: "Eight free-trade zones quietly redraw China's data-export red lines"
date: 2026-10-05
category: Policy & Governance
site: NeuroAI
canonical: https://neuroai.site/a/na-policy-data-export-negative-list
language: en
---

# Eight free-trade zones quietly redraw China's data-export red lines

> China's free-trade zones publish negative lists letting most business data exit without a security review, easing AI and cloud work for global firms.

A logistics engineer in Shanghai used to panic whenever a German client asked for a spreadsheet of shipment records. Moving that file offshore could trigger a months-long security review. Today, in several of China's free-trade zones, the same transfer can happen with little more than a checklist.

The shift did not come from a single dramatic law. It came from a 2024 rule that handed China's free-trade zones the power to write their own "negative lists" (负面清单) for cross-border data — and from a wave of local lists that now cover eight zones.

## The old wall

For years, China's outbound-data regime was built on three pillars: the Cybersecurity Law, the Data Security Law, and the Personal Information Protection Law (个人信息保护法). Under them, a company moving "important data" or large volumes of personal information out of the country generally had to clear one of three gates:

- a security assessment run by the Cyberspace Administration of China (国家网信办, CAC);

- a standard contract filed with the authorities; or

- a third-party personal-information protection certification.

The thresholds were tight. Before reforms, a company handling more than one million people's personal information could be pulled into the strictest assessment even if it moved only a single record abroad. Multinationals training models, running regional clouds, or simply syncing HR systems felt the weight most acutely.

## What changed in 2024

On March 22, 2024, the CAC published the Regulations on Promoting and Standardizing Cross-Border Data Flows (促进和规范数据跨境流动规定), effective the same day. Two moves mattered most.

First, it raised the volume thresholds. A non-critical-infrastructure company must now file a CAC security assessment only if it exports "important data," or cumulatively sends out more than one million individuals' personal information (excluding sensitive data) or more than 10,000 people's sensitive personal information from January 1 of that year.

Second — and this is the part that reshaped the map — it let each free-trade zone draft its own negative list. Data not on the list could leave with far lighter compliance. The zone's list still needs provincial approval and a national filing, but the principle was clear: regulate the sensitive, free the routine.

## How a negative list works

Think of it as the opposite of a permission list. Instead of asking "what may I send out?," a company asks "is my data on the banned-or-reviewed list?" If not, the transfer is largely cleared.

Most zones split flagged data into two tiers:

- **Tier I** — requires the full CAC security assessment. This covers critical-infrastructure operators and exporters of important data.

- **Tier II** — can be handled through a standard contract or third-party certification, usually applying to smaller volumes of personal information.

The lists are not uniform. Some cover a single industry; others span more than a dozen sectors.

## Tianjin and Beijing, up close

The Tianjin Pilot Free Trade Zone (天津自贸试验区) moved first, releasing China's inaugural data-export negative list on May 8, 2024. It names 45 categories of data across 13 sectors — petroleum and petrochemicals, rare earths, smart vehicles, banking, insurance, public health, internet services and more — that still require review. Everything else, in principle, moves more freely.

Beijing followed on August 30, 2024, with a different shape: a scenario-based, field-level list aimed at five industries — automotive, pharmaceuticals, retail, civil aviation, and artificial intelligence (人工智能). It breaks down 23 business scenarios into 198 specific data fields, giving companies unusual precision about exactly which cell in a spreadsheet is sensitive.

By late 2024, eight zones had published negative lists: Tianjin, Shanghai (Lingang), Beijing, Hainan, Zhejiang, Jiangsu, Chongqing, and Guangxi. In September 2024, the Ministry of Commerce (商务部), the CAC and seven other agencies issued service-export measures that went a step further, calling for exploration of a unified national negative list to replace the patchwork.

## Why this matters for AI

Training a large model (大模型) is a cross-border data problem as much as a compute problem. Annotation pipelines, multilingual corpora, and global product telemetry often live on both sides of a border. When routine transfers needed a security assessment, many AI teams simply kept data local or built duplicate stacks — slower and costlier.

The negative-list system does not erase the assessment; sensitive data still faces it. But by narrowing what counts as sensitive, it removes friction from the ordinary flows that AI development depends on. For foreign firms with Chinese operations, that can mean faster model iteration and lower legal overhead.

## What readers can do now

- If you run data across China's border, map your flows against the negative list of the specific free-trade zone where your entity sits — Tianjin's list and Beijing's field-level list are the most detailed published.

- Treat "important data" as undefined until a regulator tells you otherwise; the 2024 rule explicitly says data not notified or published as important need not be declared.

- Watch for a national negative list: the late-2024 service-export measures signal a move toward unification, which would simplify compliance for companies operating in multiple zones.

## Honest limitations

This article describes published national rules and the eight free-trade-zone negative lists identified in official and professional legal summaries; it is not a compliance opinion. Negative-list coverage varies by zone and is revised over time, so a specific data type's status should be confirmed against the latest provincial publication. Figures such as the Tianjin 45 categories and Beijing 198 fields come from government and legal-professional summaries, not an independent audit of every list entry. Enforcement practice and interpretation can differ from the text, and this piece does not cover sector-specific rules outside the cross-border data framework.

---

Published by NeuroAI (https://neuroai.site/) — https://neuroai.site/a/na-policy-data-export-negative-list
Free to quote with attribution and a link to the original.
