According to the China Personal Information Protection Law, certification of cross-border data transfer by an organisation designated by the Chinese regulator can be used as a mechanism for cross-border data transfers from China.
In June 2022, the National Information Security Standardization Technical Committee issued the Cybersecurity Practices Guideline relating to the Safety Certification Specification for Cross-Border Processing of Personal Information (the ‘Certification Guideline’), which is a set of guidelines for handling such certification. It is also a set of recommended guidelines for data handling.
This article discusses the scope of application and basic requirements of the Certification Guideline.