Question 1
Q1A Shanghai-based e-commerce platform processes the personal information of 2 million users. The company plans to migrate its customer database to a cloud server located in Singapore to improve regional latency. According to the Personal Information Protection Law (PIPL) and CAC measures, which compliance mechanism MUST the company adopt for this cross-border transfer?
Show answer & explanation
Correct answer: B
Under PIPL and the Measures for the Security Assessment of Outbound Data Transfers, a mandatory CAC Security Assessment is triggered if a data processor processes the personal information of more than 1 million individuals. Since the company has 2 million users, it exceeds this threshold, making the CAC Security Assessment the only valid mechanism, superseding SCCs or Certification.