- Separate data-export risk self-assessment requirements where a CAC security assessment is required; this filing assessment does not replace the PIPL impact assessment.
References and citations
- Articles 5 and 8 add export-specific assessment subjects and reassessment triggers when the standard-contract route is used.
- Article 56 establishes the safeguards test and minimum three-year retention; Articles 51 and 57 support security controls and incident handling.