Back to Publications
Regulatory Brief · GDPR

China PIPL crossed with EU GDPR: cross-border transfers after Schrems II

17 May 2026By NexCyber Editorial GDPR

In the wake of Schrems II, EU companies operating in China face a complex landscape for cross-border data transfers. With the introduction of China's Personal Information Protection Law (PIPL), a third layer of compliance is added to the already intricate requirements of the EU General Data Protection Regulation (GDPR). As of 2025, a significant portion of EU multinationals—estimated at 75%—have yet to complete the necessary Cybersecurity Administration of China (CAC) and GDPR transfer documenta

In the wake of Schrems II, EU companies operating in China face a complex landscape for cross-border data transfers. With the introduction of China's Personal Information Protection Law (PIPL), a third layer of compliance is added to the already intricate requirements of the EU General Data Protection Regulation (GDPR). As of 2025, a significant portion of EU multinationals—estimated at 75%—have yet to complete the necessary Cybersecurity Administration of China (CAC) and GDPR transfer documentation. This article explores the mechanisms available under PIPL, their compatibility with GDPR, and provides a detailed mapping of scenarios to aid compliance.

Navigating PIPL Transfer Routes

China's PIPL introduces specific mechanisms for cross-border data transfers, which EU companies must navigate in conjunction with GDPR requirements. These mechanisms include CAC security assessments, standard contracts, and certifications.

CAC Security Assessment

The CAC security assessment is mandatory for certain categories of data transfers, particularly those involving critical information infrastructure operators or large volumes of personal data. This assessment evaluates the risks associated with the transfer and ensures that adequate protection measures are in place.

Standard Contractual Clauses (SCCs)

PIPL provides for the use of standard contractual clauses as a mechanism for data transfers. These clauses must be approved by the CAC and are designed to ensure that the data recipient outside China provides a level of protection equivalent to that within China.

Certification

Certification under PIPL is another route for compliance, allowing organizations to demonstrate that they adhere to recognized data protection standards. This mechanism is particularly useful for companies that engage in frequent data transfers and seek a streamlined compliance process.

GDPR to China Transfers: Article 46 SCC + Supplementary Measures

Under GDPR, cross-border data transfers to countries outside the EU, including China, must comply with Article 46. This typically involves the use of SCCs, supplemented by additional measures as recommended by the European Data Protection Board (EDPB).

Article 46 SCC

The GDPR's Article 46 provides for the use of SCCs to ensure that data transferred outside the EU is subject to adequate protection. These clauses are legally binding and enforceable, offering a framework for data protection that aligns with EU standards.

Supplementary Measures

Following the Schrems II ruling, the EDPB recommends supplementary measures to enhance the protection afforded by SCCs. These measures can include technical safeguards such as encryption, organizational policies like data minimization, and contractual obligations that require data importers to notify exporters of any access requests by public authorities.

Dual Compliance Template: Combined SCC + CAC SCC

For EU companies operating in China, achieving dual compliance with both PIPL and GDPR is crucial. A combined approach using both SCCs and CAC-approved clauses can streamline compliance efforts.

Mapping Scenarios

To assist organizations in navigating these requirements, we present a mapping table with five common scenarios:

  1. 1Scenario 1: Transfer of employee data from an EU subsidiary to a Chinese parent company. - Required: CAC security assessment + GDPR SCC with supplementary measures.
  1. 1Scenario 2: Transfer of customer data from an EU-based e-commerce platform to a Chinese logistics partner. - Required: PIPL SCC + GDPR SCC with encryption and access controls.
  1. 1Scenario 3: Transfer of R&D data from an EU research center to a Chinese university. - Required: Certification under PIPL + GDPR SCC with data minimization.
  1. 1Scenario 4: Transfer of marketing data from an EU marketing firm to a Chinese advertising agency. - Required: CAC security assessment + GDPR SCC with contractual transparency obligations.
  1. 1Scenario 5: Transfer of financial data from an EU bank to a Chinese fintech company. - Required: PIPL SCC + GDPR SCC with pseudonymization and audit rights.

Worked Examples

  • Example 1: An EU mid-cap manufacturer transferring design specifications to a Chinese supplier would need to conduct a CAC security assessment and implement GDPR SCCs with encryption as a supplementary measure.
  • Example 2: A European tech company sharing user analytics with a Chinese data center should use PIPL SCCs and GDPR SCCs, ensuring data is anonymized and access is restricted.
  • Example 3: A healthcare provider sending patient data to a Chinese research institute must obtain certification under PIPL and apply GDPR SCCs with strict data minimization policies.

Next Step with NexCyber

Navigating the dual compliance landscape of PIPL and GDPR for cross-border data transfers is complex, but essential for EU companies operating in China. NexCyber offers a comprehensive cross-border transfer register to streamline compliance efforts and ensure that your organization meets all regulatory requirements. For more information, visit [NexCyber's Cross-Border Transfer Register](https://www.nexcyber.eu/assess?utm_source=editorial&utm_campaign=china-pipl-eu-gdpr-post-schrems-ii).