provisions shall prevail.
Article 9 The results of passing the security assessment shall be valid for three years, starting from the date
when the assessment results are issued. Upon expiration of the validity period, if the outbound data transfer
activities need to be continued and there is no circumstance requiring the security assessment, the data
processor may apply to the national cyberspace administration authority via the provincial-level cyberspace
administration authority at its location for extending the validity period of the security assessment results
within 60 working days before the expiration of the validity period. Upon approval of the national cyberspace
administration authority, the validity period of the security assessment results may be extended for three
years.
Article 10 To transfer any personal information overseas, data processors shall fulfill their obligations
pursuant to the provisions in laws and administrative regulations, such as notifying the individuals, seeking
separate individual consent, and carrying out personal information protection impact assessment.
Article 11 To transfer any data overseas, data processors shall abide by laws and regulations, fulfill their data
security protection obligations, adopt technical measures and other necessary measures, and ensure the
security of outbound data transfer. If a data security incident occurs or may occur, they shall adopt remedial
measures and promptly report the case to the cyberspace administration authority at or above the provincial
level and other relevant competent authorities.
Article 12 All local cyberspace administration authorities shall strengthen their guidance for and supervision
of the outbound data transfer activities carried out by data processors, establish a sound system for the
security assessment of outbound data transfer, and optimize the assessment procedures; enhance the
regulation before, during and after such activities throughout the chain and in all areas, and require data
processors to make rectification and eliminate any hidden danger once they find any major risk in the
outbound data transfer activities or when any security incident occurs; any data processor who refuses to
make rectification or causes serious consequences shall be held liable pursuant to the law.
Article 13 In the event of any inconsistency between these Provisions and the Measures for the Security
Assessment of Outbound Data Transfers (Order of the Cyberspace Administration of China No. 11)
promulgated on July 7, 2022, the Measures for the Standard Contract for Outbound Cross-Border Transfer of
Personal Information (Order of the Cyberspace Administration of China No. 13) promulgated on February 22,
2023, as well as other regulations, these Provisions shall prevail.
Article 14 These Provisions shall become effective as of the date of promulgation.
3