ChinaCareVisit
EN
Health guides

Medical Data Transfer from China: GDPR Compliance Guide

How to move Chinese medical records to your home doctor under GDPR, PIPL and HIPAA: encrypted transfer, patient consent and cross-border compliance.

Medical Data Transfer from China: GDPR Compliance Guide
Published by Chinacare VisitUpdated

The Dilemma: Your Medical Records Are Trapped in China

You've completed your treatment in China. Your Chinese hospital's oncology department has comprehensive records: pathology reports, genomic sequencing data, chemotherapy protocols, and follow-up imaging. Your home-country oncologist needs these records to continue your care seamlessly.

But when you ask the hospital to send the records, you're handed a USB drive with unencrypted files. Or you're told to download them from a Chinese cloud platform. Or your escort offers to WeChat them to you.

None of these methods are legally compliant or medically secure.

Cross-border medical data transfer sits at the intersection of three regulatory frameworks:

  • China's Personal Information Protection Law (PIPL) — requires separate consent for cross-border health data transfer
  • EU's General Data Protection Regulation (GDPR) — restricts transfer of personal data outside the EU
  • US HIPAA Privacy Rule — governs protected health information of US persons

This guide explains how to navigate these requirements and ensure your medical data travels safely and legally across borders.

The Regulatory Landscape

China: Personal Information Protection Law (PIPL)

Effective since 2021, PIPL imposes specific requirements for cross-border transfer of "sensitive personal information" — which explicitly includes medical and health data.

Key Requirements:

RequirementWhat It Means for You
Separate consentStandard consent for treatment is not enough. You must give separate, specific consent for cross-border data transfer
Purpose limitationData can only be transferred for the stated, specific purpose (e.g., "second opinion from Dr. Smith in the UK")
Minimum necessaryOnly the specific records needed for the stated purpose — not your full medical history
Security assessmentFor certain volumes of data, a government security assessment may be required
Contract with recipientThe overseas recipient must agree in writing to protect the data to Chinese standards

Penalties for non-compliance: Up to 50 million RMB or a statutory share of annual revenue — and for patients, potential loss of data control and privacy rights.

EU: General Data Protection Regulation (GDPR)

If you are an EU citizen, your medical data is protected by GDPR even when transferred to China.

Key Requirements:

RequirementWhat It Means
Adequacy decision or SCCsChina is not covered by an EU adequacy decision. Data transfers must use Standard Contractual Clauses or Binding Corporate Rules
Data Processing AgreementA written agreement between the Chinese hospital and the EU patient (or their representative)
Right to erasureYou can demand deletion of your data at any time — and the Chinese recipient must comply
Data Protection Impact AssessmentRequired before transferring sensitive health data overseas

Penalties for non-compliance: The greater of a statutory share of global annual turnover or 20 million EUR.

US: HIPAA Privacy Rule

If you are a US patient, HIPAA's Privacy Rule applies to your protected health information, with specific requirements for disclosures to overseas providers.

The Safe Transfer Protocol

ChinaCareVisit has implemented the following 7-step protocol for all cross-border medical data transfers.

Step 1: Determine What Needs to Be Transferred

Not all records need to cross borders. We work with your Chinese and home-country physicians to identify:

Data TypeTransfer Needed?Example
Current diagnosis and treatment planYes — for continuity of careChemotherapy protocol, surgical report
Lab results and pathology reportsYes — for ongoing managementBiopsy results, blood work trends
Imaging studies (DICOM)Usually — for second opinionCT, MRI, PET scans
Full historical medical recordNo — only relevant sectionsPrior visit notes from unrelated conditions
Billing and insurance documentsYes — through separate secure channelItemized bills, diagnosis codes

Step 2: Obtain Proper Consent

Before any data leaves China:

  • PIPL-required consent: You sign a separate, specific consent form authorizing cross-border transfer for a stated purpose
  • GDPR-compliant consent: If you are an EU resident, consent meets GDPR "freely given, specific, informed, unambiguous" standard
  • Purpose-restricted: Consent specifies the recipient (by name and institution), the data scope, and the purpose

Step 3: Prepare Data for Secure Transfer

ElementChinaCareVisit Standard
EncryptionAES-256 encryption at rest and TLS 1.3 in transit
FormatPDF/A for documents, DICOM for imaging, CSV for lab data
De-identificationPatient name replaced with study code (reversible only by the patient)
Audit logEvery access and transfer logged with timestamp, IP, and user ID
ExpiryDownload link expires after 7 days (configurable by patient)

Step 4: Execute Transfer Through Approved Channel

We NEVER use:

  • Unencrypted email attachments
  • WeChat file transfer
  • Consumer cloud storage (Google Drive, Dropbox, iCloud)
  • USB drives or physical media sent by mail

We ALWAYS use:

  • End-to-end encrypted, audit-logged secure portal
  • Recipient identity verified (two-factor authentication)
  • Transfer size capped at what the recipient specifically requested
  • Confirmation of receipt tracked

Step 5: Confirm Receipt and Usability

After transfer, we confirm with the receiving physician that:

  • Files opened successfully
  • Medical imaging is readable in their standard viewer
  • Lab data is in a usable format
  • No additional information is needed

Step 6: Document the Transfer

A complete record of the transfer is maintained:

  • What was sent (file manifest with checksums)
  • When it was sent (timestamp)
  • Who received it (verified identity)
  • Legal basis for transfer (consent form reference)
  • Patient confirmation of satisfaction

Step 7: Offer Data Deletion

After the purpose is accomplished, the patient is offered the option to:

  • Request deletion of all transferred data from ChinaCareVisit systems
  • Maintain archival storage (encrypted, access-limited) for future medical needs
  • Set an automatic deletion date

Data Transfer Decision Matrix

Your SituationRecommended MethodCompliance Framework
EU resident sending records to EU doctorEncrypted portal + SCCs + DPAGDPR + PIPL
US resident sending records to US doctorEncrypted portal + HIPAA BAAPIPL + HIPAA
UK resident sending records to UK doctorEncrypted portal + UK IDTAUK DPA + PIPL
Sending records for second opinionPurpose-limited consent + encrypted transferPIPL + home-country law
Insurance claim documentationSeparate billing channel (not medical data channel)Insurance-specific framework

Risks of Improper Data Transfer

MethodRisk LevelSpecific Risks
Email attachmentHighNo encryption; server logs in multiple jurisdictions; no access control; permanent retention
WeChat / WhatsAppHighConsumer platform not designed for health data; data stored on Chinese servers; limited control after sending
Consumer cloud (Google Drive, Dropbox)Medium-HighData stored in unknown jurisdictions; no patient consent documentation; hospital IT policies may prohibit
USB drive / physical mediaMediumRisk of loss or theft; no encryption standard; no audit trail; impractical for large datasets
ChinaCareVisit encrypted portalCompliantAES-256 encryption; PIPL/GDPR consent framework; full audit trail; expiry controls

Your Rights as a Patient

Regardless of which country's law applies, you have the right to:

  • Know what data is being transferred and to whom
  • Consent specifically to the transfer (not bundled with treatment consent)
  • Access a record of all transfers made
  • Correct any errors in the transferred data
  • Delete your data from our systems at any time
  • Object to a specific transfer for legitimate reasons
  • Port your data to a different provider if you choose

Need to send your Chinese medical records to your home doctor? ChinaCareVisit provides GDPR/PIPL-compliant encrypted data transfer with full consent management and audit logging. [Set up your secure transfer →]

Text Us / Consult