Cross-border data transfer
In October 2025, China adopted rules simplifying cross-border data transfers through certification. As a general rule, data transfers to third countries are possible upon obtaining permission for such transfers. To this end, the Cybersecurity Administration of China assesses the security of export operations. The new certification procedure allows companies to transfer data abroad on the basis of
Из выпуска мониторинга No. 10 (22), October 2025 · выпуск целиком, PDF · на сайте Института Гайдара

The Experience of China
In October 2025, China adopted rules simplifying cross-border data transfers through certification. As a general rule, data transfers to third countries are possible upon obtaining permission for such transfers. To this end, the Cybersecurity Administration of China assesses the security of export operations. The new certification procedure allows companies to transfer data abroad on the basis of a certificate confirming that the company is taking all necessary measures to ensure security of data both during transfer and during processing in a third country. The procedure exempts Chinese companies from the need to obtain permission for each individual data operation. However, the procedure is available to companies that conform to the following criteria:
- Not be a critical information infrastructure operator.
- Transfer between 100,000 and 1 million personal data records or 10,000 sensitive data records per year.
- Not transfer data classified as “important information,” where a security breach poses risks to national security and the economy.
The certification is valid for three years and is aimed at small businesses with limited volumes of data to transfer. However, even certified companies are subject to government oversight, such as unscheduled inspections.
Russia’s experience
In Russia, the established procedure for cross-border data transfers does not provide for simplifications for any categories of data operators. The complexity of the notification procedure varies depending on the country of destination of the personal data export: for countries not included in Roskomnadzor's list of countries whose data protection legal regime is recognized as adequate to that of Russia, the data operator must prepare additional documents confirming the legal guarantees for data protection after its transfer to a third country. Therefore, Russian companies currently do not receive regulatory support for the development of businesses involving crossborder data flows. Data flows are a key condition for doing business in the digital economy. In 2025, the digital economy will already account for 24% of global GDP. Moreover, by 2026, the monthly data flow will reach 690 gigabytes per month, which is three times higher than in1 2020. Thus, maintaining the current regulatory regime creates risks of losing the competitiveness of Russian digital companies.
- Programs that control user access to devices through which the user undergoes identification and receives an account, such as the “smart home manager” program. ↑
- https://www.statista.com/topics/2637/internet-of-things/?srsltid=AfmBOooIhcQhRchsclMF9cdcgqkPfvr0NJrUZQ9ebDXllHZYn4AfncIS #topicOverview ↑
From the monitoring issue No. 10 (22), October 2025. Download the full issue (PDF) · issue page at the Gaidar Institute