China File Sharing Regulations and Compliance
By early 2026, the Cyberspace Administration of China (CAC) had received over 3,200 cross-border data security assessment applications since the program began in 2022, but new filings in 2025 fell 22% compared to the previous year as foreign firms shifted toward data localization instead of waiting for the review process. The cause is clear: the average approval time now extends to 11 months, and the CAC rejected or required major revisions for 44% of submissions in 2025, up from 38% in 2023, according to China Gateway 360’s review of the assessment process. For a Western IT leader transferring files between a Shanghai office and a European or American headquarters, that statistic changes the entire tooling decision: compliance is no longer a formality, it is the main factor determining which file-sharing system can actually be used.
Key Takeaways:
- Three laws (PIPL, DSL, CSL) regulate cross-border file transfer; the amended Cybersecurity Law raised fines to RMB 10 million starting January 2026.
- The March 2024 Provisions raised the security-assessment threshold from 100,000 to 1 million individuals, pushing most mid-size exporters to the simpler Standard Contract route.
- Only 56% of CAC security assessment submissions pass on first attempt, and the average timeline is 11 months, so localization is often faster and cheaper.
- Enterprise platforms with China-based storage nodes are consistently 5-10x faster for users inside China than international-only services like Dropbox or Google Drive.
- Domestic cloud (Alibaba Cloud, Tencent Cloud) plus a self-hosted or China-node file tool is the practical default for compliant cross-border sharing.
The Three Laws Behind Every Cross-Border File
Cross-border file sharing in China is governed by three overlapping statutes, each with its own trigger and enforcement agency. The Personal Information Protection Law (PIPL, 个人信息保护法) covers personal information and applies extraterritorially under Article 3, meaning a Western company processing Chinese residents’ data on AWS servers in Oregon falls under its scope even without a physical presence in China. The Data Security Law (DSL, 数据安全法) categorizes data into normal, important, and core tiers, and any export of “important data” requires a CAC assessment regardless of volume. The Cybersecurity Law (CSL, 网络安全法) mandates that critical information infrastructure operators localize data and complete a security assessment before transferring it.

The penalty framework became stricter in 2026. The amended Cybersecurity Law, effective January 1, 2026, increased fines to RMB 10 million for serious violations, removed the prior warning requirement so regulators can fine immediately, and expanded extraterritorial reach. PIPL violations carry fines up to RMB 50 million or 5% of annual revenue, whichever is higher. The financial risks of mishandling file transfers rose significantly this year.
One detail often overlooked by Western teams is that Hong Kong is considered “outside Mainland China” under these rules, so syncing files from a Shanghai office to a Hong Kong server or cloud region counts as a cross-border transfer requiring an exemption or mechanism like any other export. This frequently surprises teams in our cross-border data rules guide, and it means routing everything through Hong Kong does not provide a compliance shortcut.
The Three Transfer Mechanisms and Where the Thresholds Land
Personal information can leave Mainland China through one of three legal routes, and the March 22, 2024 Provisions on Promoting and Regulating Cross-Border Data Flows changed which route applies to most companies. The thresholds accumulate from January 1 of each calendar year.
- CAC security assessment is required for critical information infrastructure operators, for “important data,” for non-sensitive personal information of more than 1,000,000 individuals, or for sensitive personal information of 10,000 or more individuals.
- Standard Contract (SCC) filing or certification applies to the mid-volume range: non-sensitive data of 100,000 to 1,000,000 individuals, or sensitive data below 10,000 individuals.
- No mechanism required for non-sensitive personal information of fewer than 100,000 individuals in a year.
The 2024 Provisions also created exemptions covering a large portion of routine business traffic. Transfers necessary to perform a contract with an individual, employee data needed for HR management under legally adopted policies, and emergency transfers do not require a mechanism, although PIPL consent and impact-assessment duties still apply. There is no general intra-group exemption, and exemptions never apply to “important data.”
The practical effect of the threshold change is detailed in China Gateway 360’s process review: the assessment is not automatic. Only 56% of initial submissions pass on the first try, and the CAC’s published 60-working-day processing window covers only the formal review phase after the application is complete. Reaching “complete” status typically takes three months of back-and-forth, which explains why the total time from first submission to approval reached 11 months in 2025. One German automotive supplier reported 14 months for a complex submission involving vehicle telematics data.
Speed Tests: What Actually Moves Across the Firewall
Connectivity and compliance are distinct issues that both influence tool choice. The Great Firewall inspects and slows cross-border traffic, so a tool that complies legally but is hosted entirely offshore can still be too slow for users in China. The speed difference between international-only storage and China-based nodes is the most important performance metric to understand.
| File sharing method | Download speed, China user to US/EU node | Download speed, China user to China node |
|---|---|---|
| FileCloud (China node) | 2-6 MB/s | 10-20 MB/s |
| Alibaba Cloud OSS | 1-4 MB/s | 10-18 MB/s |
| SFTP on China VPS | 0.5-2 MB/s | 5-10 MB/s |
These numbers come from vendor documentation and practitioner benchmarks compiled in our earlier file sharing compliance analysis, and they vary depending on your ISP, location, and time of day. An enterprise platform with a China-based storage node delivers 5-10 times the throughput of an international-only service for a user inside China because the file does not have to pass through the Firewall’s inspection layer. Congestion during peak business hours further reduces cross-border speeds.
Latency adds to the throughput problem. Cross-border connections often have 200-400ms round-trip times, which is acceptable for large sequential downloads but too slow for real-time collaboration tools that require responses under 100ms. This is why deciding where data resides and where users are located comes before choosing the tool.
Tools That Work: China Nodes, SFTP, and Compliant Transfer Services
Three main approaches dominate cross-border file sharing in practice, each balancing speed and compliance requirements differently.
Enterprise cloud storage with China nodes. FileCloud, Alibaba Cloud OSS (阿里云对象存储), and Tencent Cloud COS (腾讯云对象存储) store data physically inside China, meeting both speed needs and data localization rules. FileCloud is often recommended for secure collaboration and compliance across China borders without requiring a VPN, although its integration options are fewer than global providers and its per-user cost is higher than consumer-grade tools. Alibaba Cloud OSS and Tencent Cloud COS are the common domestic choices for object storage, but public-facing services hosted in China require ICP filing.
Dedicated SFTP/FTPS servers in China. Hosting an SFTP server on a China-based VPS (usually Alibaba Cloud or Tencent Cloud) allows direct transfers for batch processing and automated workflows, but you must handle ICP licensing, firewall management, and access controls yourself. This approach is unsuitable for real-time collaboration but works well for scheduled backups and system-to-system file transfers.
Compliant transfer services. Specialized providers like Sinosend route transfers through a Hong Kong node for direct mainland connectivity or store files in a Shanghai data center built on Alibaba Cloud infrastructure, managing compliance documentation and encryption so end users do not need a VPN. These services are better suited for occasional file delivery and client handoffs than for ongoing shared workspaces.
Consumer-grade Western tools (Dropbox, Google Drive, Box, OneDrive) are either blocked or too slow for business use, and even when accessed through a corporate VPN, they store Chinese personal data offshore in violation of PIPL. Using an unauthorized VPN for business traffic also carries legal risks under China’s 2017 VPN regulations, which we explain in our VPN regulations explainer.
The Localization Pivot and What It Costs
Faced with 11-month approval times and a 44% revision rate, more foreign-invested enterprises are choosing to localize data in China instead of pursuing a CAC assessment. By the end of 2025, about 35% of foreign businesses with cross-border data needs had moved at least one critical data category, usually employee HR records or customer support logs, onto China-based servers.
The cost difference is significant. China Gateway 360 reports that preparing and submitting a complete assessment application in 2025 cost an average of 2.5 million RMB, including legal fees, data mapping tools, and internal compliance time. Localizing HR records, by comparison, cost roughly 400,000 to 800,000 RMB. The trade-off is less global visibility: data stored in China cannot be accessed by global analytics teams without triggering a new assessment, which some companies address by aggregating anonymized insights before transferring data across borders.
Localization does not exempt companies from compliance. They must still follow data classification rules and protect localized data under Chinese cybersecurity standards. Also, localization is not an option for every sector: aviation, shipping, and financial services, where global data sharing is operationally necessary, continue to face the full assessment requirements.
A Compliance Checklist for File Transfer
Before implementing any file-sharing solution that crosses China and overseas, review these checkpoints. The sequence matters: classification determines the mechanism, the mechanism determines where data can reside, and that determines which tools are allowed.
- Map the data first. Identify every dataset involving China, where it is collected, stored, and transmitted, and classify it under all three laws: personal information (PIPL Art. 4), important data (DSL Art. 21), or core data (DSL Art. 25).
- Count your data subjects accurately. Thresholds accumulate per calendar year across your China operations. A small or medium enterprise with 200 China employees usually falls under 100,000 non-sensitive individuals and is exempt unless sensitive categories (health, financial accounts, minors) are involved.
- Choose the mechanism. Security assessment applies above 1 million individuals or for important data; Standard Contract or certification applies to the mid-volume range; no mechanism is needed for under 100,000 non-sensitive individuals. File executed SCCs with the provincial CAC within 10 working days.
- Localize when it is cheaper than assessing. For high-volume or sensitive data without a real-time global access need, domestic storage is faster and less expensive than an 11-month assessment.
- Document the HR exemption. If you rely on the HR-management exemption, your employment policies must clearly state what data crosses the border and why. That documentation serves as the exemption.
- Log everything. Keep logs of cross-border transfers for at least six months (CSL Art. 38, PIPL Art. 55) to show compliance during inspections.
- Secure ICP filing for any public-facing file server or web service hosted in China.
Since 2024, the CAC has consistently treated physical server location as the main compliance factor, and suspending transfer permissions causes more operational disruption than fines. A German automotive supplier whose HR data was found on a Frankfurt server during a routine audit had its cross-border transfer permissions suspended for months, leaving manufacturing quality data stranded and production lines in Stuttgart without access for a quarter, as described in our China data compliance guide.
Companies that manage this well treat China as a separate operating region with its own residency, identity, and transfer rules, not as part of the global infrastructure. A domestic cloud footprint for Chinese data, a China-node or self-hosted file tool for speed, and an approved mechanism for any data crossing the border is the setup that has held up through three years of active enforcement.
Related Reading
More in-depth coverage from this blog on closely related topics:
Sources and References
Sources cited while researching and writing this article:
Victor Zhao
Cross-border business consultant with deep expertise in China's technology landscape and regulatory environment.
