Determine whether a current trigger applies
Start with the actual outbound flow, exporter, data, recipients, and count period. Determine CIIO status through the applicable designation process. For , check relevant sector or regional catalogues, published identification, and authority notices. The 2024 provisions say data need not be submitted as important data when a relevant department or region has neither notified the processor nor publicly identified it as important.
Count personal information exported from January 1 of the current year. Count personal information excluding sensitive personal information against the 1 million threshold and count sensitive personal information separately against the 10,000 threshold.
- CIIO: security assessment for any export of personal information or , subject to the controlling exemptions.
- Non-CIIO : security assessment regardless of the number of individuals, subject to the controlling exemptions.
- Non-CIIO personal information: security assessment at 1 million or more individuals, excluding sensitive personal information, from January 1.
- Non-CIIO sensitive personal information: security assessment at 10,000 or more individuals from January 1.
- Below the assessment thresholds: an exemption may apply, or the exporter may need the CAC standard contract or certification. A below-threshold export is not automatically free of PIPL notice, separate-consent, PIPIA, or security duties.
Articles 38-40 establish PIPL's overseas-provision conditions, individual notice and separate consent, and the security-assessment duty for specified processors.
Use for the assessment process, self-assessment, application materials, review scope, and change triggers, subject to the 2024 provisions where inconsistent.
Articles 2-8 provide the current important-data treatment, exemptions, and assessment and alternative-route thresholds; Article 13 gives them priority over inconsistent older rules.