Do cross-border data rules apply to a manufacturer?
Short answer
Yes when device or service records are read from outside the EU or outside China, including for support and diagnostics.
Read against the registers 2026-08-26.
Who the role is
Whoever makes the product, or puts a name or trademark on it, carries the first line of product duties.
What the topic covers
Moving records across a border is where the three regimes separate most. The EU relies on adequacy and contractual safeguards. China runs an assessment and filing route with volume thresholds. The United States has no single federal transfer rule.
The rows behind the answer
European Union
- GDPR — Regulation (EU) 2016/679: Chapter V allows a transfer on adequacy, standard contractual clauses or another named safeguard.
United States
- California Consumer Privacy Act, as amended by the CPRA: No general export restriction. Service provider contracts carry the duty instead of a transfer mechanism.
China
- Measures for the Security Assessment of Outbound Data Transfers: A security assessment by the regulator is required above the stated volume and category thresholds.
- Measures on the Standard Contract for Outbound Transfer of Personal Information: A filed standard contract is the route below the assessment thresholds, with an impact assessment attached.
- Provisions on Facilitating and Regulating Cross-border Data Flows: Names exemptions where neither the assessment nor the standard contract route is required.
Where companies usually start
- Draw the actual route of the records, including subprocessors and support access.
- Count the Chinese volume thresholds before choosing between the assessment and the contract route.
- Attach the transfer assessment to the contract, not to a separate slide deck.
This page reads published registers and describes common practice. It is not legal advice and it is not a compliance verdict.
Other questions for manufacturer
- Do ai governance rules apply to a manufacturer?
- Do personal data rules apply to a manufacturer?
- Do cybersecurity rules apply to a manufacturer?
- Do health data rules apply to a manufacturer?
- Do online platforms rules apply to a manufacturer?
- Do consumer rights rules apply to a manufacturer?
- Do product safety rules apply to a manufacturer?
- Do climate disclosure rules apply to a manufacturer?
- Do export controls rules apply to a manufacturer?
ExploreWorldAI is operated by Valkiv Ventures AB (Reg. no. 556995-1311), Kungsgatan 8, 111 43 Stockholm, Sweden. EU-hosted, with data processing assessed against the GDPR. Contact: hello@exploreworldai.com.
Machine-readable summaries for AI agents: /llms.txt and /llms-full.txt.