Meaning
Statutory limits based on data volume, classification, or entity type determine when a cross-border data transfer must undergo a mandatory security assessment by the state cyberspace administration. These security assessment thresholds act as the boundary between autonomous enterprise filing options and formal administrative approvals. In the regulatory framework of China, exceeding any of the designated limits triggers an obligation to secure national clearance before data leaves the jurisdiction.
The rules apply to all industries handling personal information or important data.
Trigger Metric
An administrative security assessment is activated when a processor handles the personal information of more than one million individuals. It is also triggered if an operator of critical information infrastructure transmits any personal data outbound. Cumulative transfers of personal data belonging to more than one hundred thousand individuals since January 1 of the preceding year also meet this standard.
These specific numbers are the primary administrative triggers.
Procedural Pathway
Once a threshold is crossed, the data processor must initiate a full security assessment rather than using the standard contract or certification pathways. The exporter submits a detailed application dossier to the provincial cyberspace administration, which performs a format check. After this initial screening, the dossier is forwarded to the national Cyberspace Administration of China for a final review.
This multi-stage review process requires extensive risk analyses and third-party security audits.
Operational Impact
Data transfers must be suspended until the formal approval is issued. This requirement extends the project timeline for international deployments by several months. Businesses must align their data storage architectures with these rules to minimize cross-border operational bottlenecks.