Personal Information Outbound Certification Measures effective 1 Jan 2026

Analysis

By UA Ledger staff2 min read

Personal Information Outbound Certification Measures effective 1 Jan 2026

CAC and SAMR Order No. 20 publishes the Personal Information Outbound Certification Measures, effective 1 January 2026. Certification is one lawful outbound path for non-CII processors within stated volume bands—not a free pass for important data.

China Government Network hosts Order No. 20 of CAC and the State Administration for Market Regulation: the 个人信息出境认证办法 (Personal Information Outbound Certification Measures). The order is dated 14 October 2025 and Article 19 states the measures take effect on 1 January 2026. The full text was opened on 20 September 2026.

Who may use certification (Article 5)

A personal-information processor may use certification to provide personal information overseas only if all of the following hold:

  1. It is not a critical information infrastructure operator.
  2. From 1 January of the year, cumulative outbound personal information is more than 100,000 and fewer than 1 million individuals (excluding sensitive PI), or fewer than 10,000 individuals’ sensitive personal information.
  3. The outbound set does not include important data.

Processors must not split volumes to dodge a security assessment. Before applying, Article 6 requires notice, separate consent where required, and a personal-information protection impact assessment covering purpose/necessity, scale/sensitivity, overseas recipient safeguards, and destination-country law risk.

Certification mechanics

Articles 7–10: apply to a qualified professional certification body; certificates last three years (re-apply from six months before expiry); bodies must report certificate status to the national certification information platform within five working days; certificates can be suspended or revoked if outbound activity no longer matches the certified scope.

What this is not

Certification is one PIPL Article 38 outbound path alongside security assessment and standard contracts. This order does not abolish those paths, does not authorise CII outbound via certification, and does not mean every MMP export of China player data is already certified. “Fully operational from 1 Jan 2026” in the commission title maps to this effective date; the order itself was published in October 2025.

Operator action

Reference table
FieldEvidence
Order date2025-10-14
Effective2026-01-01
Non-CII requiredYes (Art. 5)
Volume band (non-sensitive)>100k and <1M individuals YTD
Sensitive PI band<10k individuals YTD
Important dataExcluded from this path
Certificate validity3 years
UA implicationMMP/analytics exporting China PI need a documented SCC, security-assessment or certification path matched to volume and data type

Download the certification card. Prefer this gov.cn text over secondary legal blogs when updating China data-transfer runbooks.

Research checked 20 September 2026. Local draft; human editorial review pending.

Featured

Related posts

measurement

platforms

·

1 min read

When to turn rewarded ads off for payers (and how to measure the loss)

measurement

platforms

·

1 min read

When custom product pages need their own MMP campaign mapping

measurement

platforms

·

1 min read

Season pass refund rate versus standard IAP refund rate

measurement

platforms

·

1 min read

Pre-reg cohort quality vs post-launch paid cohort quality

More from the Measurement desk

measurement

platforms

·

2 min read

AppLovin Ad Review drops user-level journeys for aggregate-only reporting

measurement

platforms

·

2 min read

Apple adds an EU alternative ATT prompt from iOS 27.2 — mandatory in five markets

measurement

platforms

·

1 min read

Pity-adjusted expected value versus player-facing banner claims

measurement

platforms

·

1 min read

MMP install count vs store first-open: F2P reconciliation lab