Data compliance (PIPL / cross-border transfer)
Crew data, AIS positions and port/customs data heading to an overseas parent — first work out whether you actually need the security assessment.
- 2024.3.22New outbound rules in force
- The Provisions on Promoting and Regulating Cross-Border Data Flows eased the thresholds considerably — many companies do not in fact need the security assessment.
- 3+1Routes plus exemptions
- Three routes — security assessment / standard contract / protection certification — plus the exemptions. Determine the route first, then act.
- 55PIPL Article 55
- Before providing personal information abroad, the Personal Information Protection Impact Assessment (PIPIA) is a statutory step, not an option.
What it is
Helping companies lawfully transfer personal information/data abroad under China's three data laws (Cybersecurity Law CSL, Data Security Law DSL, Personal Information Protection Law PIPL) and the cross-border-transfer regime. The core is determining which outbound route the company falls into (CAC security assessment / standard-contract filing / protection certification, or an exemption) and completing the supporting compliance actions (data inventory, Personal Information Protection Impact Assessment PIPIA, route selection and material preparation/filing).
Who it's for
China-based shipping entities that need to share crew and operational data with overseas owners, managers, manning agencies and P&I — especially foreign-invested / foreign-flag structures.
How we do it
Cross-border data export isn't 'can we send it' but 'which compliance path applies' — under the 2024 thresholds, the decision lands on one of three branches: a CAC security assessment, a standard contract / protection certification, or eligibility for the three exemptions.
- A CIIO exporting personal information
- Exporting 'important data'
- ≥1,000,000 people/yr (non-sensitive) or ≥10,000 (sensitive)
- 100,000 to <1,000,000 people/yr (non-sensitive)
- or <10,000 (sensitive)
- <100,000 people/yr (non-sensitive, non-CIIO)
- or necessary to perform a contract to which the individual is a party, etc.
Per the Provisions on Promoting and Regulating Cross-Border Data Flows (2024-03-22); exemptions require case-by-case judgment and do not mean 'shipping is always exempt'.
Three outbound routes plus exemptions: which one are you on
| Route | When it's triggered (under the 2024-03-22 rules) | Core actions |
|---|---|---|
| CAC security assessment | A critical-information-infrastructure operator transferring personal information; any transfer of important data; or, cumulatively since 1 January of the year, personal information of 1,000,000+ individuals or sensitive personal information of 10,000+ | Outbound-risk self-assessment · assessment filing · legal documents with the overseas recipient |
| Standard-contract filing | Not a CII operator; cumulatively since 1 January, personal information of 100,000 to under 1,000,000 individuals, or sensitive personal information of under 10,000 | Sign the standard contract + PIPIA · file with the provincial cyberspace authority |
| Protection certification | An alternative in the same tier as the standard contract, common for intra-group transfers in multinationals (certification measures in force 2026-01-01) | Certification by an accredited body · keeping the certification valid |
| Exemptions | Necessary for performing a contract (ticketing / visas / cross-border remittance etc.), for cross-border HR management, in emergencies, or a non-CII operator under 100,000 individuals cumulatively in the year — judged case by case | Keep the reasoning on file · notification and protection duties still apply |
※ Thresholds and exemptions follow the Provisions on Promoting and Regulating Cross-Border Data Flows (in force 2024-03-22); applicability is judged case by case against your actual data flows.
What we do / deliverables
- Data inventory and data-flow mapping (which personal/important data, where it flows, the overseas recipients)
- Personal Information Protection Impact Assessment (PIPIA, required by PIPL Article 55)
- Outbound-route determination and selection (assessment / standard contract / certification / exemption)
- Drafting the standard contract for outbound personal information and support for filing with the provincial cyberspace authority
- Separate-consent mechanisms and refined privacy-notice text; building the compliance document system
Why choose us
Data compliance that understands shipping — translating the three data laws into shipping's concrete data scenarios (crew data, AIS/positions, port/customs, owner/manning/P&I flows), closer to the business than a general law firm.
Determine the route first, do only what's needed — the 2024 rules eased things considerably, and many companies can in fact use an exemption or the standard contract; we help you work it out first and avoid over-compliance.
How the engagement runs
Data inventory & flow map
Establish which personal information / important data leaves the country, to whom, and at what volume.
Route determination
Against the thresholds and exemptions, determine assessment / standard contract / certification / exemption.
PIPIA & materials
Complete the impact assessment and draft the contract and filing materials.
Filing & mechanisms
Support the filing process and land the separate-consent and notification mechanisms.
Standards & basis
FAQ
We only send crew data to our overseas parent — do we still need a CAC security assessment?
Does sending data to Hong Kong or Macau count as an outbound transfer?
Do AIS positions and voyage data count as personal information?
Tell us what you need
The message below is pre-filled with the solution you're viewing (you can still edit it). Haishide's compliance engineering team will get back to you within 1–2 business days.
Data compliance (PIPL / cross-border transfer)

