Personal Information Outbound Certification Measures effective 1 Jan 2026
Analysis
By UA Ledger staff — 2 min read

CAC and SAMR Order No. 20 publishes the Personal Information Outbound Certification Measures, effective 1 January 2026. Certification is one lawful outbound path for non-CII processors within stated volume bands—not a free pass for important data.
China Government Network hosts Order No. 20 of CAC and the State Administration for Market Regulation: the 个人信息出境认证办法 (Personal Information Outbound Certification Measures). The order is dated 14 October 2025 and Article 19 states the measures take effect on 1 January 2026. The full text was opened on 20 September 2026.
Who may use certification (Article 5)
A personal-information processor may use certification to provide personal information overseas only if all of the following hold:
- It is not a critical information infrastructure operator.
- From 1 January of the year, cumulative outbound personal information is more than 100,000 and fewer than 1 million individuals (excluding sensitive PI), or fewer than 10,000 individuals’ sensitive personal information.
- The outbound set does not include important data.
Processors must not split volumes to dodge a security assessment. Before applying, Article 6 requires notice, separate consent where required, and a personal-information protection impact assessment covering purpose/necessity, scale/sensitivity, overseas recipient safeguards, and destination-country law risk.
Certification mechanics
Articles 7–10: apply to a qualified professional certification body; certificates last three years (re-apply from six months before expiry); bodies must report certificate status to the national certification information platform within five working days; certificates can be suspended or revoked if outbound activity no longer matches the certified scope.
What this is not
Certification is one PIPL Article 38 outbound path alongside security assessment and standard contracts. This order does not abolish those paths, does not authorise CII outbound via certification, and does not mean every MMP export of China player data is already certified. “Fully operational from 1 Jan 2026” in the commission title maps to this effective date; the order itself was published in October 2025.
Operator action
| Field | Evidence |
|---|---|
| Order date | 2025-10-14 |
| Effective | 2026-01-01 |
| Non-CII required | Yes (Art. 5) |
| Volume band (non-sensitive) | >100k and <1M individuals YTD |
| Sensitive PI band | <10k individuals YTD |
| Important data | Excluded from this path |
| Certificate validity | 3 years |
| UA implication | MMP/analytics exporting China PI need a documented SCC, security-assessment or certification path matched to volume and data type |
Download the certification card. Prefer this gov.cn text over secondary legal blogs when updating China data-transfer runbooks.
Research checked 20 September 2026. Local draft; human editorial review pending.
Featured
Related posts
measurement
platforms
·1 min read
When to turn rewarded ads off for payers (and how to measure the loss)
measurement
platforms
·1 min read
When custom product pages need their own MMP campaign mapping
measurement
platforms
·1 min read
Season pass refund rate versus standard IAP refund rate
measurement
platforms
·1 min read
Pre-reg cohort quality vs post-launch paid cohort quality
More from the Measurement desk
measurement
platforms
·2 min read
AppLovin Ad Review drops user-level journeys for aggregate-only reporting
measurement
platforms
·2 min read
Apple adds an EU alternative ATT prompt from iOS 27.2 — mandatory in five markets
measurement
platforms
·1 min read
Pity-adjusted expected value versus player-facing banner claims
measurement
platforms
·1 min read