海仕德数据服务
Solutions

Data compliance (PIPL / cross-border transfer)

Crew data, AIS positions and port/customs data heading to an overseas parent — first work out whether you actually need the security assessment.

2024.3.22New outbound rules in force
The Provisions on Promoting and Regulating Cross-Border Data Flows eased the thresholds considerably — many companies do not in fact need the security assessment.
3+1Routes plus exemptions
Three routes — security assessment / standard contract / protection certification — plus the exemptions. Determine the route first, then act.
55PIPL Article 55
Before providing personal information abroad, the Personal Information Protection Impact Assessment (PIPIA) is a statutory step, not an option.

What it is

Helping companies lawfully transfer personal information/data abroad under China's three data laws (Cybersecurity Law CSL, Data Security Law DSL, Personal Information Protection Law PIPL) and the cross-border-transfer regime. The core is determining which outbound route the company falls into (CAC security assessment / standard-contract filing / protection certification, or an exemption) and completing the supporting compliance actions (data inventory, Personal Information Protection Impact Assessment PIPIA, route selection and material preparation/filing).

Who it's for

China-based shipping entities that need to share crew and operational data with overseas owners, managers, manning agencies and P&I — especially foreign-invested / foreign-flag structures.

Our method · made visible

How we do it

Cross-border data export isn't 'can we send it' but 'which compliance path applies' — under the 2024 thresholds, the decision lands on one of three branches: a CAC security assessment, a standard contract / protection certification, or eligibility for the three exemptions.

In one table

Three outbound routes plus exemptions: which one are you on

Three outbound routes plus exemptions: which one are you on
RouteWhen it's triggered (under the 2024-03-22 rules)Core actions
CAC security assessmentA critical-information-infrastructure operator transferring personal information; any transfer of important data; or, cumulatively since 1 January of the year, personal information of 1,000,000+ individuals or sensitive personal information of 10,000+Outbound-risk self-assessment · assessment filing · legal documents with the overseas recipient
Standard-contract filingNot a CII operator; cumulatively since 1 January, personal information of 100,000 to under 1,000,000 individuals, or sensitive personal information of under 10,000Sign the standard contract + PIPIA · file with the provincial cyberspace authority
Protection certificationAn alternative in the same tier as the standard contract, common for intra-group transfers in multinationals (certification measures in force 2026-01-01)Certification by an accredited body · keeping the certification valid
ExemptionsNecessary for performing a contract (ticketing / visas / cross-border remittance etc.), for cross-border HR management, in emergencies, or a non-CII operator under 100,000 individuals cumulatively in the year — judged case by caseKeep the reasoning on file · notification and protection duties still apply

Thresholds and exemptions follow the Provisions on Promoting and Regulating Cross-Border Data Flows (in force 2024-03-22); applicability is judged case by case against your actual data flows.

What we do / deliverables

  • Data inventory and data-flow mapping (which personal/important data, where it flows, the overseas recipients)
  • Personal Information Protection Impact Assessment (PIPIA, required by PIPL Article 55)
  • Outbound-route determination and selection (assessment / standard contract / certification / exemption)
  • Drafting the standard contract for outbound personal information and support for filing with the provincial cyberspace authority
  • Separate-consent mechanisms and refined privacy-notice text; building the compliance document system

Why choose us

  1. Data compliance that understands shipping — translating the three data laws into shipping's concrete data scenarios (crew data, AIS/positions, port/customs, owner/manning/P&I flows), closer to the business than a general law firm.

  2. Determine the route first, do only what's needed — the 2024 rules eased things considerably, and many companies can in fact use an exemption or the standard contract; we help you work it out first and avoid over-compliance.

From first call to close-out

How the engagement runs

  1. Data inventory & flow map

    Establish which personal information / important data leaves the country, to whom, and at what volume.

  2. Route determination

    Against the thresholds and exemptions, determine assessment / standard contract / certification / exemption.

  3. PIPIA & materials

    Complete the impact assessment and draft the contract and filing materials.

  4. Filing & mechanisms

    Support the filing process and land the separate-consent and notification mechanisms.

Standards & basis

PIPL 2021.11.1DSL 2021.9.1CSL 2017.6.1Cross-border data rules 2024.3.22Standard-contract measures 2023.6.1Certification measures 2026.1.1

FAQ

We only send crew data to our overseas parent — do we still need a CAC security assessment?
Not necessarily. The 2024 cross-border rules eased things considerably; whether you fall into the security assessment depends on whether you are a critical-information-infrastructure operator, whether you transfer important data, and the cumulative volume of personal information transferred in the year. Many companies can in fact use the standard-contract filing, or even fall into an exemption — we start with a data inventory to clarify your route.
Does sending data to Hong Kong or Macau count as an outbound transfer?
Yes. Under the current rules, providing data to Hong Kong, Macau or Taiwan is likewise an outbound transfer, subject to the same route determination — the point shipping companies (especially structures with a Hong Kong owner / manager) most often miss.
Do AIS positions and voyage data count as personal information?
Static ship and voyage data on its own is generally not personal information; once linked to identifiable individuals — a specific crew member, a pilot — it can become so. The key is a data inventory that clarifies the fields and linkages, which is exactly our first step.
Start an inquiry

Tell us what you need

The message below is pre-filled with the solution you're viewing (you can still edit it). Haishide's compliance engineering team will get back to you within 1–2 business days.

Data compliance (PIPL / cross-border transfer)

Provide at least a phone or an email so we can reach you.