BetaThis is a Beta (test) version. Content is being refined; the official release will prevail.
Global AI Agents · Hainan Hub Hotline 18913116626 / 13307508848
HNAIA Hainan Free Trade Port AI Agent Association (Preparatory) Hainan Free Trade Port AI Agent Association (Preparatory)Hainan Free Trade Port AI Agent Association (Preparatory)
Home/Policy & Standards/Cross-Border Data Compliance Guide

Cross-Border Data Compliance Guide

Let Skills Go Global Securely & Compliantly

Cross-border Skill delivery inevitably involves data export. This guide helps members judge the compliance path, prepare filing materials and control legal risk under the Hainan Free Trade Port cross-border data policy framework.

I. Three Basic Judgment Lines

  1. Does data leave the border? Providing data to overseas parties, allowing overseas access, or cross-border remote calls may all constitute export.
  2. Is it on the negative list? Listed data requires filing, assessment or certification per regulations; off-list data may use facilitation measures.
  3. Does it involve personal information or important data? Personal information requires separate consent and corresponding obligations; important data requires a risk assessment.

II. Four Common Compliance Paths

PathApplicable ScenarioKey Points
Off-List FacilitationGeneral business data, non-personal informationHandle under FTP facilitation measures; keep ledgers and traces
Standard ContractPersonal information export below a thresholdSign a standard contract and file it; conduct a personal-information protection impact assessment
Protection CertificationIntra-group cross-border, repeated continuous transferObtain professional personal-information protection certification
Security AssessmentImportant data, or personal information above the thresholdFile a data-export security assessment with the authority

III. Technical Compliance for Cross-Border Skill Delivery

  • Data classification & grading: a Skill description file must declare the data types and sensitivity levels it processes.
  • Minimization: transmit only fields necessary for the function; keep localizable data onshore.
  • De-identification & encryption: de-identify before export; encrypt in transit and at rest.
  • Auditable: retain complete call logs and data-flow records for traceability.
  • Controllable cutoff: possess the technical ability to emergency-stop cross-border transfer.

IV. Services the Association Provides

🧭

Compliance Path Diagnosis

Judge the applicable path from your business scenario; output a compliance plan recommendation.

📄

Filing Material Guidance

Assist in preparing assessment filings, standard-contract filings and impact assessments.

🌏

Cross-Border Data Space Access

Connect to DEPA rules and cross-border data-space construction; explore mutual-recognition mechanisms.

⚠️

Important Notice

This guide is general information, not legal advice. Compliance judgments for specific projects follow the requirements of the competent authority; professional legal counsel is recommended. The Association's Cross-Border Data Compliance Committee offers members preliminary consultation: info@hnaia.org