(3) having provided personal information of fewer than 100,000 individuals in aggregate to overseas recipients since January 1 of the previous year; and (4) having provided sensitive personal information of fewer than 10,000 individuals in aggregate to any overseas recipients since January 1 of the previous year. Where it is otherwise provided in any law or administrative regulations, or by the national cyberspace authority, those provisions shall prevail. A personal information processor must not split up the amount of personal information to be transferred overseas or otherwise act in order to provide personal information,the outbound cross-border transfer of which should be subject to a security assessment according to the law, to an overseas recipient through a Standard Contract. Article 5 Before providing any personal information to an overseas recipient, a personal information processor shall conduct a personal information protection impact assessment focused on the following matters: (1) the legality, legitimacy, and necessity of the purpose, scope, and method of the personal information processing by the personal information processor and the overseas recipient; (2) the quantity, scope, type, and sensitivity of personal information to be transferred overseas, and the risk that the outbound cross-border transfer may pose to personal information rights and interests; (3) the responsibilities and obligations that the overseas recipient undertakes to assume, and whether the management and technical measures and capabilities of the overseas recipient to perform such responsibilities and obligations are sufficient to ensure the security of personal information to be transferred; (4) the risk of the personal information being tampered with, sabotaged, disclosed, lost, or illegally used after the it is transferred overseas, and whether there is a smooth channel for protecting the rights and interests in the personal information; (5) the impact of personal information protection policies and regulations in the country or region where the overseas recipient is located on the performance of the Standard Contract; and (6) other matters that may affect the security of personal information to be transferred overseas. Article 6 A Standard Contract shall be executed in strict accordance with the content of the annex of the Measures. The national cyberspace authority may adjust the content of the annex based on the actual situation. A personal information processor may agree on other terms with an overseas recipient, provided that such terms must not conflict with the terms of the Standard Contract. An outbound cross-border transfer of personal information can be carried out only after the Standard Contract for such transfer takes effect. Article 7 A personal information processor shall, within 10 working days from the effective date of a Standard Contract executed, file a record with the provincial cyberspace authority where it is domiciled by submitting the following materials: (1) the Standard Contract; and (2) a personal information protection impact assessment report. The personal information processor shall be responsible for the authenticity of the materials submitted. Article 8 If any of the following circumstances occurs during the validity term of a Standard Contract, the personal information processor shall conduct a personal information protection impact assessment again, and supplement the existing Standard Contract or execute a new Standard Contract, as well as file a record again: (1) 1. there is any change in the purpose, scope, category, sensitivity, method, or storage location of the personal information transferred overseas, or any change in the purpose or method of the personal information processing of the overseas recipient, or an extension of the overseas retention period of the personal information; 2

اختر الفقرة المستهدفة3