Medical Data Transfer from China: GDPR Compliance Guide
How to move Chinese medical records to your home doctor under GDPR, PIPL and HIPAA: encrypted transfer, patient consent and cross-border compliance.

The Dilemma: Your Medical Records Are Trapped in China
You've completed your treatment in China. Your Chinese hospital's oncology department has comprehensive records: pathology reports, genomic sequencing data, chemotherapy protocols, and follow-up imaging. Your home-country oncologist needs these records to continue your care seamlessly.
But when you ask the hospital to send the records, you're handed a USB drive with unencrypted files. Or you're told to download them from a Chinese cloud platform. Or your escort offers to WeChat them to you.
None of these methods are legally compliant or medically secure.
Cross-border medical data transfer sits at the intersection of three regulatory frameworks:
- China's Personal Information Protection Law (PIPL) — requires separate consent for cross-border health data transfer
- EU's General Data Protection Regulation (GDPR) — restricts transfer of personal data outside the EU
- US HIPAA Privacy Rule — governs protected health information of US persons
This guide explains how to navigate these requirements and ensure your medical data travels safely and legally across borders.
The Regulatory Landscape
China: Personal Information Protection Law (PIPL)
Effective since 2021, PIPL imposes specific requirements for cross-border transfer of "sensitive personal information" — which explicitly includes medical and health data.
Key Requirements:
| Requirement | What It Means for You |
|---|---|
| Separate consent | Standard consent for treatment is not enough. You must give separate, specific consent for cross-border data transfer |
| Purpose limitation | Data can only be transferred for the stated, specific purpose (e.g., "second opinion from Dr. Smith in the UK") |
| Minimum necessary | Only the specific records needed for the stated purpose — not your full medical history |
| Security assessment | For certain volumes of data, a government security assessment may be required |
| Contract with recipient | The overseas recipient must agree in writing to protect the data to Chinese standards |
Penalties for non-compliance: Up to 50 million RMB or a statutory share of annual revenue — and for patients, potential loss of data control and privacy rights.
EU: General Data Protection Regulation (GDPR)
If you are an EU citizen, your medical data is protected by GDPR even when transferred to China.
Key Requirements:
| Requirement | What It Means |
|---|---|
| Adequacy decision or SCCs | China is not covered by an EU adequacy decision. Data transfers must use Standard Contractual Clauses or Binding Corporate Rules |
| Data Processing Agreement | A written agreement between the Chinese hospital and the EU patient (or their representative) |
| Right to erasure | You can demand deletion of your data at any time — and the Chinese recipient must comply |
| Data Protection Impact Assessment | Required before transferring sensitive health data overseas |
Penalties for non-compliance: The greater of a statutory share of global annual turnover or 20 million EUR.
US: HIPAA Privacy Rule
If you are a US patient, HIPAA's Privacy Rule applies to your protected health information, with specific requirements for disclosures to overseas providers.
The Safe Transfer Protocol
ChinaCareVisit has implemented the following 7-step protocol for all cross-border medical data transfers.
Step 1: Determine What Needs to Be Transferred
Not all records need to cross borders. We work with your Chinese and home-country physicians to identify:
| Data Type | Transfer Needed? | Example |
|---|---|---|
| Current diagnosis and treatment plan | Yes — for continuity of care | Chemotherapy protocol, surgical report |
| Lab results and pathology reports | Yes — for ongoing management | Biopsy results, blood work trends |
| Imaging studies (DICOM) | Usually — for second opinion | CT, MRI, PET scans |
| Full historical medical record | No — only relevant sections | Prior visit notes from unrelated conditions |
| Billing and insurance documents | Yes — through separate secure channel | Itemized bills, diagnosis codes |
Step 2: Obtain Proper Consent
Before any data leaves China:
- PIPL-required consent: You sign a separate, specific consent form authorizing cross-border transfer for a stated purpose
- GDPR-compliant consent: If you are an EU resident, consent meets GDPR "freely given, specific, informed, unambiguous" standard
- Purpose-restricted: Consent specifies the recipient (by name and institution), the data scope, and the purpose
Step 3: Prepare Data for Secure Transfer
| Element | ChinaCareVisit Standard |
|---|---|
| Encryption | AES-256 encryption at rest and TLS 1.3 in transit |
| Format | PDF/A for documents, DICOM for imaging, CSV for lab data |
| De-identification | Patient name replaced with study code (reversible only by the patient) |
| Audit log | Every access and transfer logged with timestamp, IP, and user ID |
| Expiry | Download link expires after 7 days (configurable by patient) |
Step 4: Execute Transfer Through Approved Channel
We NEVER use:
- Unencrypted email attachments
- WeChat file transfer
- Consumer cloud storage (Google Drive, Dropbox, iCloud)
- USB drives or physical media sent by mail
We ALWAYS use:
- End-to-end encrypted, audit-logged secure portal
- Recipient identity verified (two-factor authentication)
- Transfer size capped at what the recipient specifically requested
- Confirmation of receipt tracked
Step 5: Confirm Receipt and Usability
After transfer, we confirm with the receiving physician that:
- Files opened successfully
- Medical imaging is readable in their standard viewer
- Lab data is in a usable format
- No additional information is needed
Step 6: Document the Transfer
A complete record of the transfer is maintained:
- What was sent (file manifest with checksums)
- When it was sent (timestamp)
- Who received it (verified identity)
- Legal basis for transfer (consent form reference)
- Patient confirmation of satisfaction
Step 7: Offer Data Deletion
After the purpose is accomplished, the patient is offered the option to:
- Request deletion of all transferred data from ChinaCareVisit systems
- Maintain archival storage (encrypted, access-limited) for future medical needs
- Set an automatic deletion date
Data Transfer Decision Matrix
| Your Situation | Recommended Method | Compliance Framework |
|---|---|---|
| EU resident sending records to EU doctor | Encrypted portal + SCCs + DPA | GDPR + PIPL |
| US resident sending records to US doctor | Encrypted portal + HIPAA BAA | PIPL + HIPAA |
| UK resident sending records to UK doctor | Encrypted portal + UK IDTA | UK DPA + PIPL |
| Sending records for second opinion | Purpose-limited consent + encrypted transfer | PIPL + home-country law |
| Insurance claim documentation | Separate billing channel (not medical data channel) | Insurance-specific framework |
Risks of Improper Data Transfer
| Method | Risk Level | Specific Risks |
|---|---|---|
| Email attachment | High | No encryption; server logs in multiple jurisdictions; no access control; permanent retention |
| WeChat / WhatsApp | High | Consumer platform not designed for health data; data stored on Chinese servers; limited control after sending |
| Consumer cloud (Google Drive, Dropbox) | Medium-High | Data stored in unknown jurisdictions; no patient consent documentation; hospital IT policies may prohibit |
| USB drive / physical media | Medium | Risk of loss or theft; no encryption standard; no audit trail; impractical for large datasets |
| ChinaCareVisit encrypted portal | Compliant | AES-256 encryption; PIPL/GDPR consent framework; full audit trail; expiry controls |
Your Rights as a Patient
Regardless of which country's law applies, you have the right to:
- Know what data is being transferred and to whom
- Consent specifically to the transfer (not bundled with treatment consent)
- Access a record of all transfers made
- Correct any errors in the transferred data
- Delete your data from our systems at any time
- Object to a specific transfer for legitimate reasons
- Port your data to a different provider if you choose
Need to send your Chinese medical records to your home doctor? ChinaCareVisit provides GDPR/PIPL-compliant encrypted data transfer with full consent management and audit logging. [Set up your secure transfer →]
