Meaning
Administrative rules issued by the Cyberspace Administration of China establish clear statutory thresholds for cross-border data movements originating within Mainland China. Under CAC Decree 16, enterprise operations gain explicit relief from formal security assessments or contract filings when handling low-volume personal data or necessary commercial information. The regulation sets an upper boundary where exporting over 1,000,000 non-sensitive personal records triggers compulsory state security reviews.
Regulatory Threshold
Quantitative limits under Chinese administrative law determine the compliance route for cross-border transfers. Transferring fewer than 100,000 personal records annually requires zero regulatory filings. Transferring between 100,000 and 1,000,000 personal records requires a standard contract filing, whereas exceeding 1,000,000 records requires a mandatory national security assessment.
Exemption Mechanism
Operational activities tied directly to international trade, cross-border procurement, and internal group human resource administration receive statutory relief from administrative filing burdens. Contractual performance for overseas purchasing orders allows the transmission of necessary employee or customer personal information without filing formal documentation to provincial authorities. Internal human resource transfers involving domestic workforce records similarly proceed without state approval when governed by lawful employment contracts or binding labor rules.
Statutory relief ends immediately if exported datasets contain sensitive personal information or items formally designated as important data by industrial regulators.
Enforcement Boundary
Provincial cyberspace administrations enforce compliance through regular system audits and data export reviews. Corporate claims of statutory exemption fail when technical logs reveal that transferred files contain critical operational metrics or unsegregated customer databases.