China China Cybersecurity Law data localisation

China Writes the Fine Print on Data Portability, Five Years After PIPL Promised It

Two national standards effective July 1, 2026 finally operationalize PIPL's Article 45 portability right and mandate audit methodology.

China Fills In PIPL's Portability Right People of Internet Research · China 2 Standards effective same day GB/T 46901 (portability) and GB/T … ~5 Years since PIPL created the right Article 45 created the portability… 10M+ User threshold for mandatory biennial au… Processors handling over 10 millio… peopleofinternet.com
China Fills In PIPL's Portability Righ… People of Internet Research · China 2 Standards effective same d… ~5 Years since PIPL created the right 10M+ User threshold for mandatory bi… peopleofinternet.com

Key Takeaways

A right that existed on paper since 2021

When China's Personal Information Protection Law (PIPL) took effect on November 1, 2021, Article 45 quietly created one of the most consequential — and least-used — rights in the statute: the ability of an individual to demand that a company transfer their personal information to a rival platform, provided the transfer met conditions the Cyberspace Administration of China (CAC) would later set (DigiChina, Stanford). For nearly five years, those conditions never arrived. Without a specified scope, process, or format, Article 45 was a right nobody could actually exercise.

That gap closed on July 1, 2026, when two standards drafted by the National Cybersecurity Standardization Technical Committee (TC260) and published by the State Administration for Market Regulation (SAMR) took effect: GB/T 46901-2025, Data Security Technology — Requirements for the Transfer of Personal Information Based on Individual Requests, and GB/T 46903-2025, Data Security Technology — Personal Information Protection Compliance Audit Requirements. Both were published December 31, 2025, with a standard six-month runway to implementation (SAMR national standards platform). MLex reported the pairing as China's first systematic attempt to fix scope, conditions, timelines, fee rules, and formats for personal-data transfers — precisely the machinery Article 45 lacked (MLex).

The steelman: this is genuinely pro-competition

The case for GB/T 46901 is stronger than the usual case for Chinese data rules, and it deserves to be stated plainly before any criticism. Portability rights are one of the few regulatory tools that lower switching costs without imposing a structural remedy — they let users route around lock-in rather than forcing regulators to break up incumbents. DigiChina's analysis of the original PIPL drafting noted this explicitly: Article 45 was written with antitrust intent, to reduce the walled-garden dynamics of China's super-app economy by letting users move their data between competing services. A national standard that finally specifies machine-readable formats and response timelines is what turns that intent into something a smaller challenger platform can actually invoke against a dominant one. Any publication that calls itself pro-competition should welcome a rule that makes exit costs from Alibaba's or Tencent's ecosystems lower, not higher.

The compliance-audit standard, GB/T 46903, similarly answers a real complaint from industry: the CAC's Measures for the Administration of Compliance Audits on Personal Information Protection, in force since May 1, 2025, imposed audit obligations — a biennial self-audit for processors handling more than 10 million individuals' data, with smaller processors given latitude to set their own cycle — without a standardized methodology for what an audit must cover (DLA Piper Privacy Matters). GB/T 46903 supplies that methodology: a five-stage process (preparation, execution, reporting, rectification, archiving) and defined audit scope. Predictability is worth something even under a regulatory model we would not have designed ourselves.

Where the design still falls short

The honest caveat is that neither standard is legally binding in the way a GDPR-style regulation would be. GB/T-prefixed standards are recommended (推荐性) national standards — TC260's own literature is explicit that they establish a technical baseline, not an enforceable mandate. That leaves two live risks. First, enforcement discretion: a portability right that a regulator can selectively invoke against a target of the week functions differently from a right a private plaintiff can litigate, and PIPL gives individuals no private right of action comparable to GDPR's. Second, the compliance-officer threshold — one million data subjects, per the underlying CAC Measures (CAC policy Q&A, January 2026) — is low enough that mid-sized firms, not just Alibaba-scale platforms, now carry a standing audit-governance burden. DigiChina's original 2021 analysis flagged exactly this risk for Article 45 more broadly: data isn't always machine-readable, portability format compliance falls disproportionately on firms without in-house standards teams, and personal information frequently overlaps across users (a contact list is one person's data and many people's information at once) — a technical problem the new standard's format requirements do not obviously solve.

What to watch

The test of GB/T 46901 will not be whether it exists but whether TC260 or CAC publishes a public log of transfer requests actually executed under it — the same way portability metrics under GDPR's Article 20 became a rough proxy for whether the right was real or symbolic. If Chinese platforms start advertising portability compliance the way EU platforms tout GDPR data-export tools, that is a genuine, measurable win for user choice. If the standard instead sits alongside the many TC260 practice guides that few companies implement absent an enforcement action, it will have been fine print without teeth. Either way, closing a five-year implementation gap on a pro-competition rule is a rare instance of Chinese data policy moving in a direction Western regulators should note approvingly, even as its enforcement architecture remains opaque by design.

Sources & Citations

  1. SAMR national standards platform — GB/T 46903-2025
  2. Cyberspace Administration of China — policy Q&A, Jan. 2026
  3. MLex — China issues new standards governing personal data portability
  4. DLA Piper Privacy Matters — mandatory compliance audits from 1 May 2025
  5. DigiChina, Stanford — Seven Major Changes in China's Finalized PIPL