On this page
Map the data before you choose analytics. Read the thresholds after you know what crosses the border.
The CAC’s 2024 Provisions on Promoting and Regulating Cross-Border Data Flows adjusted when certain data-export mechanisms apply. The official explanation distinguishes important data, personal information, and sensitive personal information; critical information infrastructure operators and other processors; and security assessment, standard-contract, certification, and exempted situations.
A game team can only use that framework after it knows what leaves mainland China, whose information it is, which entity sends and receives it, and why.
Thresholds, classifications, calculation, exceptions, and other obligations require current, fact-specific advice. Do not restructure processing to avoid a mechanism without addressing the underlying duties.
Read every threshold with its conditions attached
The official CAC explanation gives teams a current primary starting point. Among other points, it says a non-critical-information-infrastructure data processor exporting fewer than 100,000 individuals’ personal information from January 1 of the current year, excluding sensitive personal information, may fall within an exemption from the named security-assessment, standard-contract, and certification procedures. It sets different bands for 100,000 to fewer than one million individuals’ non-sensitive personal information, and for sensitive personal information below 10,000 individuals. It describes security-assessment conditions for higher volumes, important data, and critical information infrastructure operators.
The provisions also describe other exempted scenarios and say that data not identified or publicly notified as important data need not be declared as important data for a security assessment. Each statement has a narrow scope. Keep its conditions attached when you brief the team or compare vendors.
Put every outbound arrow on one diagram
Before comparing vendors, inventory every outbound flow from the mainland route: account, authentication, analytics, crash, anti-cheat, support, chat, voice, payment, attribution, server logs, and remote operations. Record fields, subject count method, sensitivity, purpose, sender, recipient, endpoint, storage, onward processors, retention, and deletion.
Cut the flows before you assess them. Keep analytics local or aggregated when that still answers the product question. Remove stable identifiers from events that work without them. Keep free text out of telemetry, separate crash diagnostics from account profiles, shorten retention, and restrict dashboard access.
Then ask qualified advisers to classify the operator and data, determine how counts are calculated from January 1, identify sensitive personal information and any important-data concern, and map the applicable transfer mechanism or exemption. Document the conclusion, assumptions, review date, and change triggers.
Choose the vendor only after that work. Require endpoint and subprocessor transparency, controllable regions, field filtering, export/deletion, incident duties, and a clean shutdown path. Test the actual binary; configuration promises are not evidence if another endpoint still receives data.
An exemption covers a mechanism, not the whole data system
Falling below a threshold may exempt a transfer from specified mechanism procedures. PIPL and other applicable data-security, cybersecurity, contract, platform, notice, consent, rights, and protection duties can still apply.
Your team still needs qualified, fact-specific classification. The source cannot decide whether a device or account identifier is anonymous, whether a free-text field contains sensitive information, whether a vendor is suitable, or whether an overseas endpoint will be reliable for mainland operations.
It also does not justify splitting systems, entities, identifiers, or time periods artificially to evade review. Architecture should follow a legitimate purpose and accurate operating model.
Bring a field inventory to vendor review
Read the CAC’s official publication and explanation of the 2024 provisions, including the linked full text. Bring a field-level inventory and entity/data-flow diagram to current professional review. Ask how little player data the route needs and which lawful, secure path it should take. Starting with “How can we keep our global analytics?” locks in the wrong assumption.