Cross-border data transfers
Assess the data type, processing facts, exemptions and the applicable security assessment, standard contract or certification route.
Topic research hubs
Follow a practical research question through current rules, timelines, version comparisons, action steps, tools and official sources.
Assess the data type, processing facts, exemptions and the applicable security assessment, standard contract or certification route.
The PIPL is central, but operational compliance also depends on audit, impact-assessment, security, sector and network-data rules.
Identification remains source- and sector-dependent; one public national list does not resolve every classification.
The governance stack combines service measures, algorithm and deep-synthesis rules, labeling duties, filing activity and topic-specific measures.
Compliance combines sector processing rules with the PIPL, data-security duties and cross-border mechanisms.
Healthcare data requires layered review of personal information, sensitive information, cybersecurity, sector rules and regional mechanisms.
This is a national-security review mechanism for specified procurement and data processing, distinct from routine assessment or MLPS work.
The route requires eligibility analysis, a personal information protection impact assessment, the prescribed contract and filing under current guidance.
The CAC-administered route applies when current triggers are met, read with later facilitation provisions and filing guidance.