Cross-border data transfers compared: EU, United States and China
What is required to move personal data out of the EU, the US and China?
Moving records across a border is where the three regimes separate most. The EU relies on adequacy and contractual safeguards. China runs an assessment and filing route with volume thresholds. The United States has no single federal transfer rule.
Rows read against the registers 2026-08-26.
European Union
- GDPR — Regulation (EU) 2016/679, 32016R0679: Chapter V allows a transfer on adequacy, standard contractual clauses or another named safeguard.
Open the European Union register
United States
- California Consumer Privacy Act, as amended by the CPRA, Cal. Civ. Code § 1798.100 et seq.: No general export restriction. Service provider contracts carry the duty instead of a transfer mechanism.
Open the United States register
China
- Measures for the Security Assessment of Outbound Data Transfers, CAC Order No. 11 of 2022: A security assessment by the regulator is required above the stated volume and category thresholds.
- Measures on the Standard Contract for Outbound Transfer of Personal Information, CAC Order No. 13 of 2023: A filed standard contract is the route below the assessment thresholds, with an impact assessment attached.
- Provisions on Facilitating and Regulating Cross-border Data Flows, CAC Order No. 16 of 2024: Names exemptions where neither the assessment nor the standard contract route is required.
What they ask for in common
- All three ask who receives the data and under what written terms.
- All three expect a written assessment of the risk the transfer creates for the individual.
Where they differ
- China requires a filing or an assessment before the first transfer. The EU route is contractual and self-assessed.
- The EU counts the destination country. China counts the volume and the category of the records.
- The United States regulates the vendor relationship, not the border.
What companies usually do first
- Draw the actual route of the records, including subprocessors and support access.
- Count the Chinese volume thresholds before choosing between the assessment and the contract route.
- Attach the transfer assessment to the contract, not to a separate slide deck.
This page describes what the registers say and what is common practice. It is a reading of published sources, not legal advice, and it is not a compliance verdict.
Does this apply to us
- Do cross-border data rules apply to an online marketplace?
- Do cross-border data rules apply to an online seller?
- Do cross-border data rules apply to a manufacturer?
- Do cross-border data rules apply to an importer?
- Do cross-border data rules apply to a cloud provider?
Related comparisons
- AI rules compared: EU, United States and China
- Personal data compared: GDPR, CCPA/CPRA and PIPL
- Cybersecurity duties compared: EU, United States and China
- Health data compared: GDPR, HIPAA and PIPL
- Online platform duties compared: EU, United States and China
- Online consumer rights compared: EU and United States
- Product safety and market access compared: EU and China
- Climate and emissions reporting compared: United States and the EU
- Export controls compared: China and the EU market side
ExploreWorldAI is operated by Valkiv Ventures AB (Reg. no. 556995-1311), Kungsgatan 8, 111 43 Stockholm, Sweden. EU-hosted, with data processing assessed against the GDPR. Contact: hello@exploreworldai.com.
Machine-readable summaries for AI agents: /llms.txt and /llms-full.txt.