top of page

XL INSIGHTS+
Legal Alerts and News Updates

China Restricts Cross-Border Data Transfers in Hiring Decisions, Clarifies Other Obligations

  • On July 24, 2026, the CAC released a Q&A on Cross-Border Data Transfer Security

    Management that clarifies key compliance expectations. 

  • Of particular note, the CAC Q&A emphasizes the need for data minimization in cross-

    border transfers of job applicant resumes to overseas headquarters or affiliates.

 

On July 24, 2026, the Cyberspace Administration of China (CAC) released guidance clarifying

and heightening its compliance expectations in certain cross-border data transfer situations,

including with respect to data minimization for job candidate information that is transferred to an

overseas affiliate for review in a hiring process. In its Q&A on Cross-Border Data Transfer

Security Management Policy and Regulation (July 2026) (“Q&A”), the CAC also summarized

its responses to inquiries on notice and consent for overseas transfers of personal information and

the process for extension of CAC security assessments currently in place for existing data

exports.


Cross-Border Transfers of Personal Information for Job Recruitment


In a development that will be of interest to IHEs with programs or partnerships in China, the

Q&A applies the PIPL principle of data minimization to cross-border transfers of personal

information to overseas group headquarters or affiliated institutions in the context of job

recruitment.


Data Minimization. The CAC clarifies that principle of data minimization applies to transfers of

candidates’ personal information at two levels, depending upon the level of involvement of the

overseas affiliate’s involvement in the hiring decision.


  • If the overseas affiliate does not directly participate in the hiring decision, the cross-

    border transfer of personal information is not necessary.

  • If the overseas affiliate does directly participate in the hiring decision, the cross-border

    transfer of personal information must be limited to (1) the minimum number of applicants

    required for the overseas decision making and (2) the minimum number of categories or

    items of personal information necessary for the overseas decision making.


Additional Compliance Obligations. Moreover, where the cross-border transfer of personal

information is necessary for the hiring decision and where the transfer of personal information has been limited to the minimum amount necessary for the hiring decision, the transfer must still satisfy the following overarching regulatory obligations. 


  • As required by PIPL Article 38, the transferring entity must (1) pass a CAC security assessment, (2) obtain a personal information protection certification conducted by a specialized body, or (3) file the PIPL Standard Contractual Clauses (SCCs) with the CAC, unless statutory exemption applies (i.e., transfers of non-sensitive personal information, excluding Important Data, of 1-99,999 individuals per calendar year); and 

  • As required by PIPL Article 17, the exporter of personal information must also (1) provide the individual with the required notice (as outlined below), (2) conduct a personal information impact assessment, and (3) obtain separate consent from the individual or be able to demonstrate an alternative lawful basis. 


Notice and Consent Requirements for Cross-Border Transfers


The Q&A also addresses the notice and consent requirements for cross-border transfers of personal information under the PIPL.


Consent. The Q&A provides two important clarifications regarding the consent requirements for cross-border transfers.  


  • Where separate consent for a cross-border transfer is required, it must not be bundled with other personal information handling activities and shall not be obtained through a "blanket" authorization approach.  

  • Where a transfer proceeds on a lawful basis other than consent, such as the performance of a contract or the fulfillment of a legal obligation (as provided in items 2 through 7 of paragraph 1 of PIPL Article 13) consent or separate consent is not required. There are no exceptions, however, to the notice requirement.


Notice. The Q&A, however, reiterates the PIPL notice requirements for cross-border transfer of personal information.  


  • For all overseas transfers of personal information, the handler must notify the individuals of the name and contact information of the overseas recipient, the purposes for and means by which the handler will handle the individuals' personal information, the categories of personal information transferred, and the methods and procedures for individuals to exercise their rights under the PIPL. 

  • If sensitive personal information is transferred outside the PRC, the handler must also notify the individuals of the necessity of transferring such sensitive personal information overseas and the impact on the individual's rights and interests.


Extension of Security Assessments 


Finally, the Q&A reiterated the process and conditions for a data handler to renew an already existing security assessment.  To recall, security assessments from the CAC, which are valid for three years, are required in three situations: (1) Transfers of Important Data (as defined by the Regulation on Network Data Security Management and discussed in our XL Insights + Article China Releases Final Regulation on Network Data Security Management); (2) transfers of personal information (excluding sensitive personal information) of at least 1,000,000 individuals per calendar year; or (3) transfers of sensitive personal information of at least 10,000 individuals per calendar year. 


To extend a security assessment for another three years, the handler must apply through the local CAC within 60 business days before expiration and meet all the following criteria: (1) the transfer’s purpose and scope remain unchanged; (2) both the handler and the overseas recipient remain unchanged; (3) for transfer of personal information, the projected volume of individuals affected over the next three years does not exceed 120% of the volume approved in the prior 3-year period; (4) for transfer of Important Data, the projected data volume growth does not exceed 120% of the volume approved in the prior three-year period; (5) the legal instrument with the recipient continues to comply with Article 9 of the Security Assessment Measures; and (6) over the past three years, data transfer activities have been conducted in strict compliance with the findings set forth in the assessment notification, and no major data security incidents have occurred.


Implications for U.S. Higher Education Institutions


The most pressing implications of the Q&A are for IHEs in the United States are for those that receive transfers of personal information of job candidates from China to the U.S.  These IHEs should consider the following steps.  


  • Confirm that the job candidates receive the required notice, as this requirement applies even if the transfer is exempt from the consent requirement under PIPL. 

  • Confirm and document that the IHE participates in the hiring decision so that the transfer will not be deemed unnecessary.  

  • Assess the personal information the IHE does receive about job candidates to ensure that it reflects both the minimum number of candidates and the minimum number of data fields required for the decision. 

  • The institution’s HR office should also maintain written documentation that the assessment scope of personal information the IHE must review in order to participate effectively in the hiring decision was completed ahead of the overseas transfer of any personal information.


More generally, given that the CAC has found it necessary to reiterate especially the notice requirement for the overseas transfers of personal information, now is also a good time for IHEs to revisit their inventories of the personal information they receive from the PRC to ensure that (1) each transfer is conduct pursuant to an appropriate legal basis (whether consent or another legal basis) and (2) individuals receive the appropriate notice that is specific each transfer of their personal information, regardless of whether separate consent is also required.  




© 2024 XL Law & Consulting P.A. - A U.S. Corporation - Privacy Policy - Cookies Policy - Contact Us

 - 

The information provided on the XL Law & Consulting website is for educational purposes only. Nothing on this website should be construed as or relied upon as legal or other professional advice, nor does use of this website create an attorney-client relationship.

bottom of page