China's cyberspace regulator has published a dated policy Q&A stating that personal information handlers may not use volume splitting to route data around the mandatory cross-border security assessment

CAC Says Volume Splitting Cannot Dodge Export Review. The Leveraged Years regulation briefing card.

What makes this Q&A worth reading is one explanatory aside, aimed squarely at the structure a group would build if it optimised for the lower-friction export route.

The short version

Bottom line: Non-binding. This is the Cyberspace Administration of China answering questions it says it received, published on its own site on 11 September 2026. It states no new rule and sets no deadline. It tells you how the regulator reads duties that already sit elsewhere.

Who this affects: Cross-border transfer and privacy counsel at multinationals operating in mainland China, data protection officers and China compliance leads, and the platform and vendor-management teams that move personal data to offshore processing, including offshore model training and inference.

Issue date: Published 11 September 2026 at 17:20, sourced on the page to China Cyberspace (中国网信网). The page footer carries publishdate 2026/09/11 17:24:58. No compliance deadline or transition period is attached to the Q&A.

What changed: Nothing in law. CAC set out the volume band in which the personal information export certification route is available, named the two national standards a certification is assessed against, and said handlers may not use volume splitting to send abroad, by certification, personal information that should go through the security assessment.

Analysis: The anti-splitting sentence is the one to circulate internally. It is written as an aside rather than as a rule, and it describes exactly the arrangement a group would reach for if it sized each transfer to stay under the assessment threshold.

Primary sources: Q&A on Policies and Regulations for the Security Management of Cross-Border Data Transfers (September 2026), CAC

Instrument (EN)
Q&A on Policies and Regulations for the Security Management of Cross-Border Data Transfers (September 2026)
Authority
Cyberspace Administration of China (国家互联网信息办公室)
Jurisdiction
Mainland China
Status
Published on the authority's website on 11 September 2026 as a set of representative questions and answers
Bindingness
Non-binding. It is the regulator's own interpretation, not a regulation, and it carries no penalty, no filing duty and no deadline of its own
Issue date / next deadline
Published 11 September 2026. No deadline is running
Legal basis
Article 38, paragraph 1, item 2 of the Personal Information Protection Law, and the Measures for Personal Information Export Certification (个人信息出境认证办法), both cited in the Q&A itself
Document
Three questions and three answers on one page, in Chinese, with no document number
Primary source
https://www.cac.gov.cn/2026-09/11/c_1790876549989064.htm

Who can use the certification route, on CAC's account of it

The first answer defines personal information export certification as a conformity assessment carried out by a professional certification body holding personal information protection certification qualifications, confirming that a handler's provision of personal information outside the People's Republic of China complies with the relevant laws, administrative regulations, departmental rules, standards and technical specifications. CAC sources that definition to article 38, paragraph 1, item 2 of the Personal Information Protection Law.

The volume band comes next, set out in the same non-binding answer. As CAC states it, an operator that is not a critical information infrastructure operator, and that has cumulatively since 1 January of the year provided abroad the personal information of 100,000 or more but fewer than 1,000,000 individuals excluding sensitive personal information, or the sensitive personal information of fewer than 10,000 individuals, and that is not exporting important data, may discharge its cross-border compliance obligation through certification.

The same answer then opens a second, voluntary door. CAC says a handler with any cross-border activity, whatever the volume, may apply for certification to demonstrate conformity with GB/T 35273 (Information Security Technology, Personal Information Security Specification) and GB/T 46068 (Data Security Technology, Security Certification Requirements for Cross-Border Processing of Personal Information), and so raise its own compliance level. That limb is framed as something a handler may do, not something it owes.

The sentence on volume splitting

The operative point sits in a single sentence at the end of the first answer, in a Q&A that binds nobody. In the original: "需要说明的是,个人信息处理者不得采取数量拆分等手段,将依法应当通过数据出境安全评估的个人信息通过个人信息出境认证的方式向境外提供。"

Here is our translation of that sentence, offered as a translation and not as the verbatim text, and the sentence creates no duty of its own: it should be explained that a personal information handler may not adopt means such as splitting quantities in order to provide abroad, by way of personal information export certification, personal information that according to law should pass through the data export security assessment.

Read what the sentence targets. It is not aimed at a handler that sits genuinely inside the band. It is aimed at one that would otherwise sit above it and engineers its way down, by slicing a single flow into several, by allocating exports across group entities, or by any comparable device. The phrase CAC uses is open ended: splitting quantities is given as an example of the means caught, not as the only one.

As an interpretation and not a rule, it attaches no penalty of its own. What it does is remove the argument that the structure was never addressed.

What the Q&A says happens when the numbers grow

The second answer deals with the handler that has already been certified and then crosses the line, and it binds nobody either. CAC says that where cumulative exports since 1 January of the year reach 1,000,000 or more individuals' personal information excluding sensitive personal information, or 10,000 or more individuals' sensitive personal information, the handler should declare a data export security assessment to the national cyberspace authority through the provincial cyberspace department where it is located.

The certification is not wasted. CAC says the handler may attach the certification material to the assessment filing, explaining the level of personal information protection at the handler and at the overseas recipient and the safeguarding of personal information rights and interests, and that the cyberspace departments will take it into account during the assessment. Note the verb. CAC says the material will be referred to, and says nothing about weight, presumption or any shortened timetable.

The third answer restates what comes before an application. Under the Measures for Personal Information Export Certification, a handler applying for certification is to have performed the notification, separate individual consent and personal information protection impact assessment duties required by law and administrative regulation before providing personal information abroad. Those duties sit in the underlying instruments, and the Q&A restates them without creating them.

What this document does not do

A reader who treats these three answers as a rule change will be describing a webpage as legislation. The Q&A presents the duties it discusses as sitting in the Personal Information Protection Law and the certification measures, neither of which we opened for this piece.

It contains no reference to artificial intelligence. The words 人工智能 do not appear. The reason a technology reader should care is structural rather than textual, and the reading is ours: offshore training and inference pipelines are a route by which personal information leaves mainland China, and a group that runs model workloads abroad is exactly the kind of organisation that would be tempted to size each transfer beneath a threshold.

It also lists three filed certification bodies with telephone contacts: the China Cybersecurity Review, Certification and Market Regulation Big Data Center, the Data and Technology Support Center of the Central Cyberspace Affairs Office, and Beijing Saixi Certification Co., Ltd. CAC says a handler may apply to any body that has completed filing, which tells you the list is a snapshot rather than a closed set.

What we did not verify

What we opened: the CAC page itself, fetched live this session, read in Chinese end to end, including all three questions and answers, the dateline reading 2026年09月11日 17:20 and the source attribution to China Cyberspace. The page footer carries publishdate 2026/09/11 17:24:58.

What we did not open: the Personal Information Protection Law, the Measures for Personal Information Export Certification, the Measures for the Security Assessment of Data Exports, GB/T 35273 or GB/T 46068. We therefore describe those instruments only as the Q&A itself describes them, and we do not state what any of them require in their own terms. We did not contact the three certification bodies and did not verify their filing status independently.

What we refuse to claim: we do not say Chinese law was changed on 11 September 2026, because a published Q&A is not a legislative act. We do not say the anti-splitting sentence creates a prohibition, because the document that carries it binds nobody; what we say is that CAC has now put its position in writing on a dated page. We do not say the certification route is faster, cheaper or easier than the assessment route, because the Q&A makes no such comparison. We give no penalty exposure, because the Q&A states none. The Chinese text is reproduced as published; the surrounding English is our translation and is labelled as such.

Informational analysis for working professionals, not legal advice. Confirm how any rule applies to your situation with qualified counsel.

Key compliance takeaway

If your China data map was built around staying under 1,000,000 individuals a year, the question to ask your architects this week is whether the number stays under the line by accident or by design. CAC has now written down, on a dated page under its own name, that splitting quantities to reach the certification route is not how it reads the rules. The page binds nobody. It also makes it harder to argue that nobody had addressed the structure.

Source File

https://www.cac.gov.cn/2026-09/11/c_1790876549989064.htm

Open the CAC page and confirm three things: the volume band in the first answer (100,000 to under 1,000,000 non-sensitive, or under 10,000 sensitive, cumulative from 1 January, non-CIIO, no important data), the anti-splitting sentence that closes that same answer, and the escalation route in the second answer through the provincial cyberspace department.

需要说明的是,个人信息处理者不得采取数量拆分等手段,将依法应当通过数据出境安全评估的个人信息通过个人信息出境认证的方式向境外提供。 · 数据出境安全管理政策法规问答(2026年9月), answer to question 1, 11 September 2026

FAQ

Does this Q&A change Chinese data export law?

No. It is the regulator's own published answer to questions it says it received, and it binds nobody. The Q&A places the duties it discusses in the Personal Information Protection Law and the certification measures, which we did not open.

What volumes does CAC say the certification route covers?

CAC's non-binding statement of the band runs as follows. For an operator that is not a critical information infrastructure operator and is not exporting important data: cumulatively since 1 January of the year, the personal information of 100,000 or more but fewer than 1,000,000 individuals excluding sensitive personal information, or the sensitive personal information of fewer than 10,000 individuals.

What does CAC say about splitting transfers to stay under the threshold?

The first answer closes with a statement that a handler may not adopt means such as splitting quantities in order to provide personal information abroad by certification where the law requires the security assessment route. That is a statement of position in a non-binding document, not a penalty provision.

If we outgrow the band after certifying, is the certification useless?

In this non-binding Q&A, CAC says the handler should then declare a security assessment through its provincial cyberspace department, and may attach the certification material, which the cyberspace departments will take into account during the assessment. The Q&A says nothing about how much weight it carries or about any faster timetable.

Sponsored Training

Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.

."}}]}